Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'sjxIqq' = '%APPDATA%\drivers\lYzWiw.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'audiodrivers' = '%APPDATA%\drivers\Loader.exe'
- '%APPDATA%\drivers\UFASoft.exe' /pid=5532
- '%APPDATA%\drivers\UFASoft.exe' /pid=3076
- '%APPDATA%\drivers\UFASoft.exe' /pid=2372
- '%APPDATA%\drivers\UFASoft.exe' /pid=4604
- '%APPDATA%\drivers\UFASoft.exe' /pid=4972
- '%APPDATA%\drivers\UFASoft.exe' /pid=2580
- '%APPDATA%\drivers\UFASoft.exe' /pid=2564
- '%APPDATA%\drivers\UFASoft.exe' /pid=3148
- '%APPDATA%\drivers\UFASoft.exe' /pid=3048
- '%APPDATA%\drivers\UFASoft.exe' /pid=5712
- '%APPDATA%\drivers\UFASoft.exe' /pid=2388
- '%APPDATA%\drivers\UFASoft.exe' /pid=2712
- '%APPDATA%\drivers\UFASoft.exe' /pid=3952
- '%APPDATA%\drivers\UFASoft.exe' /pid=2652
- '%APPDATA%\drivers\UFASoft.exe' /pid=5284
- '%APPDATA%\drivers\UFASoft.exe' /pid=1064
- '%APPDATA%\drivers\UFASoft.exe' /pid=6088
- '%APPDATA%\drivers\UFASoft.exe' /pid=640
- '%APPDATA%\drivers\UFASoft.exe' /pid=1780
- '%APPDATA%\drivers\UFASoft.exe' /pid=3356
- '%APPDATA%\drivers\UFASoft.exe' /pid=3548
- '%APPDATA%\drivers\UFASoft.exe' /pid=5968
- '%APPDATA%\drivers\UFASoft.exe' /pid=4192
- '%APPDATA%\drivers\UFASoft.exe' /pid=5644
- '%APPDATA%\drivers\UFASoft.exe' /pid=3208
- '%APPDATA%\drivers\UFASoft.exe' /pid=8188
- '%APPDATA%\drivers\UFASoft.exe' /pid=4020
- '%APPDATA%\drivers\UFASoft.exe' /pid=5988
- '%APPDATA%\drivers\UFASoft.exe' /pid=6368
- '%APPDATA%\drivers\UFASoft.exe' /pid=6388
- '%APPDATA%\drivers\UFASoft.exe' /pid=6164
- '%APPDATA%\drivers\UFASoft.exe' /pid=6148
- '%APPDATA%\drivers\UFASoft.exe' /pid=6272
- '%APPDATA%\drivers\UFASoft.exe' /pid=5104
- '%APPDATA%\drivers\UFASoft.exe' /pid=4964
- '%APPDATA%\drivers\UFASoft.exe' /pid=1048
- '%APPDATA%\drivers\UFASoft.exe' /pid=4692
- '%APPDATA%\drivers\UFASoft.exe' /pid=5684
- '%APPDATA%\drivers\UFASoft.exe' /pid=4904
- '%APPDATA%\drivers\UFASoft.exe' /pid=2596
- '%APPDATA%\drivers\UFASoft.exe' /pid=3456
- '%APPDATA%\drivers\UFASoft.exe' /pid=4184
- '%APPDATA%\drivers\UFASoft.exe' /pid=3416
- '%APPDATA%\drivers\UFASoft.exe' /pid=5084
- '%APPDATA%\drivers\UFASoft.exe' /pid=4684
- '%APPDATA%\drivers\UFASoft.exe' /pid=5224
- '%APPDATA%\drivers\UFASoft.exe' /pid=5004
- '%APPDATA%\drivers\UFASoft.exe' /pid=2484
- '%APPDATA%\drivers\UFASoft.exe' /pid=4172
- '%APPDATA%\drivers\UFASoft.exe' /pid=5344
- '%APPDATA%\drivers\UFASoft.exe' /pid=6016
- '%APPDATA%\drivers\UFASoft.exe' /pid=5364
- '%APPDATA%\drivers\UFASoft.exe' /pid=5572
- '%APPDATA%\drivers\UFASoft.exe' /pid=5332
- '%APPDATA%\drivers\UFASoft.exe' /pid=4772
- '%APPDATA%\drivers\UFASoft.exe' /pid=5624
- '%APPDATA%\drivers\UFASoft.exe' /pid=268
- '%APPDATA%\drivers\UFASoft.exe' /pid=5304
- '%APPDATA%\drivers\UFASoft.exe' -a scrypt -g no -o http://mi##.pool-x.eu: -u Nines.1 -p x -t 2
- '%APPDATA%\drivers\UFASoft.exe' /pid=5152
- '%APPDATA%\drivers\UFASoft.exe' /pid=2544
- '%APPDATA%\drivers\UFASoft.exe' /pid=1160
- '%APPDATA%\drivers\UFASoft.exe' /pid=1724
- '%APPDATA%\drivers\UFASoft.exe' /pid=3028
- '%APPDATA%\drivers\UFASoft.exe' /pid=4032
- '%APPDATA%\drivers\UFASoft.exe' /pid=5524
- '%APPDATA%\drivers\UFASoft.exe' /pid=4872
- '%APPDATA%\drivers\UFASoft.exe' /pid=4504
- '%APPDATA%\drivers\UFASoft.exe' /pid=428
- '%APPDATA%\drivers\UFASoft.exe' /pid=5312
- '%APPDATA%\drivers\UFASoft.exe' /pid=3328
- '%APPDATA%\drivers\UFASoft.exe' /pid=5432
- '%APPDATA%\drivers\UFASoft.exe' /pid=5372
- '%APPDATA%\drivers\UFASoft.exe' /pid=3920
- '%APPDATA%\drivers\UFASoft.exe' /pid=4752
- '%APPDATA%\drivers\UFASoft.exe' /pid=3308
- '%APPDATA%\drivers\UFASoft.exe' /pid=636
- '%APPDATA%\drivers\UFASoft.exe' /pid=4292
- '%APPDATA%\drivers\UFASoft.exe' /pid=5172
- '%APPDATA%\drivers\UFASoft.exe' /pid=5504
- '%APPDATA%\drivers\UFASoft.exe' /pid=6132
- '%APPDATA%\drivers\UFASoft.exe' /pid=4892
- '%APPDATA%\drivers\UFASoft.exe' /pid=3932
- '%APPDATA%\drivers\UFASoft.exe' /pid=3728
- '%APPDATA%\drivers\UFASoft.exe' /pid=5868
- '%APPDATA%\drivers\UFASoft.exe' /pid=3852
- '%APPDATA%\drivers\UFASoft.exe' /pid=5664
- '%APPDATA%\drivers\UFASoft.exe' (downloaded from the Internet)
- %APPDATA%\drivers\miner.dll
- %APPDATA%\drivers\coinutil.dll
- %APPDATA%\drivers\phatk.cl
- %APPDATA%\drivers\usft_ext.dll
- %APPDATA%\drivers\phatk.ptx
- %APPDATA%\drivers\btc-evergreen.il
- %APPDATA%\drivers\lYzWiw.exe:ZONE.identifier
- %APPDATA%\drivers\lYzWiw.exe
- %APPDATA%\drivers\UFASoft.exe
- %APPDATA%\drivers\btc.il
- %APPDATA%\drivers\bdb.dll
- %APPDATA%\drivers\lYzWiw.exe
- from <Full path to virus> to %APPDATA%\drivers\Loader.exe
- '19#.#0.57.179':80
- 'wp#d':80
- 19#.#0.57.179/sov1001/miner.dll
- 19#.#0.57.179/sov1001/coinutil.dll
- 19#.#0.57.179/sov1001/phatk.cl
- 19#.#0.57.179/sov1001/usft_ext.dll
- 19#.#0.57.179/sov1001/phatk.ptx
- 19#.#0.57.179/sov1001/coin-miner.exe
- wp#d/wpad.dat
- 19#.#0.57.179/sov1001/bdb.dll
- 19#.#0.57.179/sov1001/btc-evergreen.il
- 19#.#0.57.179/sov1001/btc.il
- DNS ASK wp#d
- ClassName: 'Indicator' WindowName: '(null)'