2021.01.15 09:20

Trojan.winrule, BitCoinMiner

조회 수 271 추천 수 0 댓글 0
?

단축키

Prev이전 문서

Next다음 문서

크게 작게 위로 아래로 댓글로 가기 인쇄 첨부
?

단축키

Prev이전 문서

Next다음 문서

크게 작게 위로 아래로 댓글로 가기 인쇄 첨부

Trojan.winrule

 

*file
C:\Program Files\winrule\Uninstall.exe
C:\Program Files\winrule\WinRule.exe
C:\Program Files\winrule\WinRuleSync.exe
C:\Program Files\winrule\WinRuleSync_.exe
C:\Program Files\winrule\winruletask.exe
C:\Program Files\winrule\winruletask_.exe
C:\Program Files\winrule\WinRule_.exe

*reg_key
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Window Rules Manager
HKLM\SOFTWARE\okwinrule
HKLM\SYSTEM\CurrentControlSet\Services\WinRuleSvc
HKLM\SYSTEM\CurrentControlSet\Services\WinRuleSvc2

 

Trojan. BitCoinMiner

 

*file
c:\users\{USERNAME}\appdata\roaming\nscpucnminer\pools.txt
c:\users\{USERNAME}\appdata\roaming\nscpucnminer\nscpucnminer64.exe
c:\users\{USERNAME}\appdata\roaming\nscpucnminer\nscpucnminer32.exe
c:\users\{USERNAME}\appdata\roaming\img001.exe
c:\users\{USERNAME}\appdata\roaming\snappy\snappy.exe
c:\users\{USERNAME}\appdata\roaming\nsminer\img001.exe
c:\users\{USERNAME}\appdata\roaming\nsminer\img002.exe
c:\users\{USERNAME}\appdata\roaming\nsminer\nscpucnminer32.exe
c:\users\{USERNAME}\appdata\roaming\nsminer\pools.txt

*reg_key
HKCU\SOFTWARE\bifrost
HKCU\SOFTWARE\snappy

*reg_val
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\run | c:\users\{USERNAME}\appdata\roaming\nscpucnminer\img001.exe

 

11111.png

 


List of Articles
번호 제목 글쓴이 날짜 조회 수
79 Trojan.TechAgent, Ghapoly file ezclean 2021.01.08 68
78 PUP.DealPly, MinerGate file ezclean 2021.01.12 87
» Trojan.winrule, BitCoinMiner file ezclean 2021.01.15 271
76 Adware.dvdvideosoft, UniversalDriver file ezclean 2021.01.19 2195
75 Adware.CoolVerte, Grape file ezclean 2021.01.20 5069
74 Adware.DVDVideoSoft, FileRubber file ezclean 2021.01.21 804
73 PUP. Guffins, PriceLess file ezclean 2021.01.22 53
72 PUP.UCalendar, WebInternet file ezclean 2021.01.25 67
71 Trojan. RegistryTool, AdwareAlert file ezclean 2021.01.26 80
70 Adware.Linkury, Netfilter file ezclean 2021.01.27 913
69 PUP.HohoSearch, Popfreeka file ezclean 2021.01.28 361
68 PUP.TorrentSearch, RegEasy file ezclean 2021.01.29 130
67 Adware.HPProtector, WeatherTool file ezclean 2021.02.01 320
66 Adware.SpywareRemover, CloudGuard file ezclean 2021.02.03 58
65 PUP.DriverDoc, RinoReader file ezclean 2021.02.04 1733
64 PUP.PCPurifier, Catered file ezclean 2021.02.05 1932
63 PUP.Mallapp, professional cleaning Software file ezclean 2021.02.08 70
62 PUP. SoSoIm, MSNMonitor file ezclean 2021.02.09 285
61 PUP.YouTubeAdBlock, Grakat file ezclean 2021.02.10 21695
60 PUP.SimpleMalware file ezclean 2021.02.15 3311
Board Pagination Prev 1 ... 3 4 5 6 7 8 Next
/ 8
XE Login