2021.01.15 09:20

Trojan.winrule, BitCoinMiner

조회 수 271 추천 수 0 댓글 0
?

단축키

Prev이전 문서

Next다음 문서

크게 작게 위로 아래로 댓글로 가기 인쇄 첨부
?

단축키

Prev이전 문서

Next다음 문서

크게 작게 위로 아래로 댓글로 가기 인쇄 첨부

Trojan.winrule

 

*file
C:\Program Files\winrule\Uninstall.exe
C:\Program Files\winrule\WinRule.exe
C:\Program Files\winrule\WinRuleSync.exe
C:\Program Files\winrule\WinRuleSync_.exe
C:\Program Files\winrule\winruletask.exe
C:\Program Files\winrule\winruletask_.exe
C:\Program Files\winrule\WinRule_.exe

*reg_key
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Window Rules Manager
HKLM\SOFTWARE\okwinrule
HKLM\SYSTEM\CurrentControlSet\Services\WinRuleSvc
HKLM\SYSTEM\CurrentControlSet\Services\WinRuleSvc2

 

Trojan. BitCoinMiner

 

*file
c:\users\{USERNAME}\appdata\roaming\nscpucnminer\pools.txt
c:\users\{USERNAME}\appdata\roaming\nscpucnminer\nscpucnminer64.exe
c:\users\{USERNAME}\appdata\roaming\nscpucnminer\nscpucnminer32.exe
c:\users\{USERNAME}\appdata\roaming\img001.exe
c:\users\{USERNAME}\appdata\roaming\snappy\snappy.exe
c:\users\{USERNAME}\appdata\roaming\nsminer\img001.exe
c:\users\{USERNAME}\appdata\roaming\nsminer\img002.exe
c:\users\{USERNAME}\appdata\roaming\nsminer\nscpucnminer32.exe
c:\users\{USERNAME}\appdata\roaming\nsminer\pools.txt

*reg_key
HKCU\SOFTWARE\bifrost
HKCU\SOFTWARE\snappy

*reg_val
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\run | c:\users\{USERNAME}\appdata\roaming\nscpucnminer\img001.exe

 

11111.png

 


  1. Trojan.winrule, BitCoinMiner

    Trojan.winrule *file C:\Program Files\winrule\Uninstall.exe C:\Program Files\winrule\WinRule.exe C:\Program Files\winrule\WinRuleSync.exe C:\Program Files\winrule\WinRuleSync_.exe C:\Program Files\winrule\winruletask.exe C:\Program Files\win...
    Date2021.01.15 Byezclean Reply0 Views271 file
    Read More
Board Pagination Prev 1 Next
/ 1
XE Login