Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\run.lnk
- %TEMP%\ixp000.tmp\minerf~1.exe
- %TEMP%\_mei11162\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei11162\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei11162\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei11162\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei11162\unicodedata.pyd
- %TEMP%\_mei11162\ucrtbase.dll
- %TEMP%\_mei11162\select.pyd
- %TEMP%\_mei11162\python37.dll
- %TEMP%\_mei11162\pyexpat.pyd
- %TEMP%\_mei11162\libssl-1_1-x64.dll
- %TEMP%\_mei11162\libcrypto-1_1-x64.dll
- %TEMP%\_mei11162\hellminer.exe.manifest
- %TEMP%\_mei11162\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei11162\base_library.zip
- %TEMP%\_mei11162\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-core-file-l1-2-0.dll
- %APPDATA%\antimalware\run.vbs
- %APPDATA%\antimalware\run.lnk
- %APPDATA%\antimalware\libegl.exe
- %APPDATA%\antimalware\libegl.bat
- %TEMP%\rarsfx0\ressources\verus-solver.exe
- %TEMP%\rarsfx0\ressources\shortcut.bat
- %TEMP%\rarsfx0\ressources\runshortcutbat.vbs
- %APPDATA%\antimalware\runshortcutbat.vbs
- %TEMP%\rarsfx0\ressources\run.vbs
- %TEMP%\rarsfx0\ressources\libegl.exe
- %TEMP%\rarsfx0\ressources\libegl.bat
- %TEMP%\rarsfx0\runshortcutbat.lnk
- %TEMP%\rarsfx0\run.lnk
- %TEMP%\rarsfx0\mk.vbs
- %TEMP%\rarsfx0\mk.bat
- %TEMP%\rarsfx0\bind.vbs
- %TEMP%\rarsfx0\ressources\run.lnk
- %APPDATA%\antimalware\shortcut.bat
- %APPDATA%\antimalware\verus-solver.exe
- %TEMP%\_mei11162\vcruntime140.dll
- %TEMP%\_mei11162\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\_mei11162\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei11162\_ssl.pyd
- %TEMP%\_mei11162\_socket.pyd
- %TEMP%\_mei11162\_queue.pyd
- %TEMP%\_mei11162\_overlapped.pyd
- %TEMP%\_mei11162\_multiprocessing.pyd
- %TEMP%\_mei11162\_lzma.pyd
- %TEMP%\_mei11162\_hashlib.pyd
- %TEMP%\_mei11162\_decimal.pyd
- %TEMP%\_mei11162\_ctypes.pyd
- %TEMP%\_mei11162\_contextvars.pyd
- %TEMP%\_mei11162\_bz2.pyd
- %TEMP%\_mei11162\_asyncio.pyd
- %TEMP%\_mei11162\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\jfb7v2bs
- %TEMP%\jfb7v2bs
- %TEMP%\rarsfx0\bind.vbs
- %TEMP%\rarsfx0\mk.bat
- %TEMP%\rarsfx0\mk.vbs
- %TEMP%\rarsfx0\run.lnk
- %TEMP%\rarsfx0\runshortcutbat.lnk
- %TEMP%\rarsfx0\ressources\libegl.bat
- %TEMP%\rarsfx0\ressources\libegl.exe
- %TEMP%\rarsfx0\ressources\run.lnk
- %TEMP%\rarsfx0\ressources\run.vbs
- %TEMP%\rarsfx0\ressources\runshortcutbat.vbs
- %TEMP%\rarsfx0\ressources\shortcut.bat
- %TEMP%\rarsfx0\ressources\verus-solver.exe
- %TEMP%\ixp000.tmp\minerf~1.exe
- '79.##7.70.48':3956
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\ixp000.tmp\minerf~1.exe'
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\RarSFX0\bind.vbs"
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\RarSFX0\mk.vbs"
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\antimalware\run.vbs"
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\antimalware\runshortcutbat.vbs"
- '%APPDATA%\antimalware\libegl.exe' -c stratum+tcp://eu.luckpool.net:3956#xnsub -u RBB75RJFmtpucRBnM5JjxpHFbwhTGQL5VG.amdcpus -p x --cpu 1
- '%APPDATA%\antimalware\verus-solver.exe' -verus2 --cpu 0
- '%TEMP%\ixp000.tmp\minerf~1.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c mk.bat' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c libegl.bat' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c shortcut.bat' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c mk.bat
- '%WINDIR%\syswow64\cmd.exe' /c libegl.bat
- '%WINDIR%\syswow64\cmd.exe' /c shortcut.bat