Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Startup' = '%APPDATA%\Mining\fethercoin.exe'
- '%APPDATA%\Mining\coin-miner.exe' /pid=6252
- '%APPDATA%\Mining\coin-miner.exe' /pid=6328
- '%APPDATA%\Mining\coin-miner.exe' /pid=6412
- '%APPDATA%\Mining\coin-miner.exe' /pid=6212
- '%APPDATA%\Mining\coin-miner.exe' /pid=4952
- '%APPDATA%\Mining\coin-miner.exe' /pid=4140
- '%APPDATA%\Mining\coin-miner.exe' /pid=6156
- '%APPDATA%\Mining\coin-miner.exe' /pid=6988
- '%APPDATA%\Mining\coin-miner.exe' /pid=7068
- '%APPDATA%\Mining\coin-miner.exe' /pid=7252
- '%APPDATA%\Mining\coin-miner.exe' /pid=6888
- '%APPDATA%\Mining\coin-miner.exe' /pid=6652
- '%APPDATA%\Mining\coin-miner.exe' /pid=6772
- '%APPDATA%\Mining\coin-miner.exe' /pid=6872
- '%APPDATA%\Mining\coin-miner.exe' /pid=6112
- '%APPDATA%\Mining\coin-miner.exe' /pid=264
- '%APPDATA%\Mining\coin-miner.exe' /pid=3364
- '%APPDATA%\Mining\coin-miner.exe' /pid=3544
- '%APPDATA%\Mining\coin-miner.exe' /pid=5832
- '%APPDATA%\Mining\coin-miner.exe' /pid=3664
- '%APPDATA%\Mining\coin-miner.exe' /pid=5484
- '%APPDATA%\Mining\coin-miner.exe' /pid=5624
- '%APPDATA%\Mining\coin-miner.exe' /pid=3964
- '%APPDATA%\Mining\coin-miner.exe' /pid=3344
- '%APPDATA%\Mining\coin-miner.exe' /pid=308
- '%APPDATA%\Mining\coin-miner.exe' /pid=5744
- '%APPDATA%\Mining\coin-miner.exe' /pid=4600
- '%APPDATA%\Mining\coin-miner.exe' /pid=3864
- '%APPDATA%\Mining\coin-miner.exe' /pid=988
- '%APPDATA%\Mining\coin-miner.exe' /pid=7076
- '%APPDATA%\Mining\coin-miner.exe' /pid=7056
- '%APPDATA%\Mining\coin-miner.exe' /pid=7152
- '%APPDATA%\Mining\coin-miner.exe' /pid=6876
- '%APPDATA%\Mining\coin-miner.exe' /pid=6556
- '%APPDATA%\Mining\coin-miner.exe' /pid=6716
- '%APPDATA%\Mining\coin-miner.exe' /pid=6588
- '%APPDATA%\Mining\coin-miner.exe' /pid=7736
- '%APPDATA%\Mining\coin-miner.exe' /pid=960
- '%APPDATA%\Mining\coin-miner.exe' /pid=7836
- '%APPDATA%\Mining\coin-miner.exe' /pid=7596
- '%APPDATA%\Mining\coin-miner.exe' /pid=7212
- '%APPDATA%\Mining\coin-miner.exe' /pid=7476
- '%APPDATA%\Mining\coin-miner.exe' /pid=7776
- '%APPDATA%\Mining\coin-miner.exe' /pid=6396
- '%APPDATA%\Mining\coin-miner.exe' /pid=7672
- '%APPDATA%\Mining\coin-miner.exe' /pid=7728
- '%APPDATA%\Mining\coin-miner.exe' /pid=7828
- '%APPDATA%\Mining\coin-miner.exe' /pid=7572
- '%APPDATA%\Mining\coin-miner.exe' /pid=7288
- '%APPDATA%\Mining\coin-miner.exe' /pid=7452
- '%APPDATA%\Mining\coin-miner.exe' /pid=7468
- '%APPDATA%\Mining\coin-miner.exe' /pid=8168
- '%APPDATA%\Mining\coin-miner.exe' /pid=6216
- '%APPDATA%\Mining\coin-miner.exe' /pid=6312
- '%APPDATA%\Mining\coin-miner.exe' /pid=5732
- '%APPDATA%\Mining\coin-miner.exe' /pid=7992
- '%APPDATA%\Mining\coin-miner.exe' /pid=8028
- '%APPDATA%\Mining\coin-miner.exe' /pid=8172
- '%APPDATA%\Mining\coin-miner.exe' /pid=1380
- '%APPDATA%\Mining\coin-miner.exe' /pid=5712
- '%APPDATA%\Mining\coin-miner.exe' /pid=5224
- '%APPDATA%\Mining\coin-miner.exe' /pid=5204
- '%APPDATA%\Mining\coin-miner.exe' /pid=5632
- '%APPDATA%\Mining\coin-miner.exe' /pid=112
- '%APPDATA%\Mining\coin-miner.exe' /pid=5144
- '%APPDATA%\Mining\coin-miner.exe' /pid=5324
- '%APPDATA%\Mining\coin-miner.exe' /pid=124
- '%APPDATA%\Mining\coin-miner.exe' /pid=3732
- '%APPDATA%\Mining\coin-miner.exe' /pid=4348
- '%APPDATA%\Mining\coin-miner.exe' /pid=4468
- '%APPDATA%\Mining\coin-miner.exe' /pid=5792
- '%APPDATA%\Mining\coin-miner.exe' /pid=5844
- '%APPDATA%\Mining\coin-miner.exe' /pid=4188
- '%APPDATA%\Mining\coin-miner.exe' /pid=4268
- '%APPDATA%\Mining\coin-miner.exe' /pid=4772
- '%APPDATA%\Mining\coin-miner.exe' /pid=1720
- '%APPDATA%\Mining\coin-miner.exe' /pid=3036
- '%APPDATA%\Mining\coin-miner.exe' -a scrypt -o http://bl######.##uecalf:x@fc.ltcoin.net:6666 -T 83 -l yes
- '%APPDATA%\Mining\coin-miner.exe' /pid=5072
- '%APPDATA%\Mining\coin-miner.exe' /pid=5504
- '%APPDATA%\Mining\coin-miner.exe' /pid=3592
- '%APPDATA%\Mining\coin-miner.exe' /pid=3104
- '%APPDATA%\Mining\coin-miner.exe' /pid=4924
- '%APPDATA%\Mining\coin-miner.exe' /pid=3944
- '%APPDATA%\Mining\coin-miner.exe' /pid=3784
- '%APPDATA%\Mining\coin-miner.exe' /pid=5112
- '%APPDATA%\Mining\coin-miner.exe' /pid=5044
- '%APPDATA%\Mining\coin-miner.exe' /pid=3272
- '%APPDATA%\Mining\coin-miner.exe' /pid=6004
- '%APPDATA%\Mining\coin-miner.exe' /pid=4588
- '%APPDATA%\Mining\coin-miner.exe' /pid=292
- '%APPDATA%\Mining\coin-miner.exe' /pid=5892
- '%APPDATA%\Mining\coin-miner.exe' /pid=5384
- '%APPDATA%\Mining\coin-miner.exe' /pid=6092
- '%APPDATA%\Mining\coin-miner.exe' /pid=1584
- '%APPDATA%\Mining\coin-miner.exe' /pid=3624
- '%APPDATA%\Mining\coin-miner.exe' /pid=5132
- '%APPDATA%\Mining\coin-miner.exe' /pid=5192
- '%APPDATA%\Mining\coin-miner.exe' /pid=4852
- '%APPDATA%\Mining\coin-miner.exe' /pid=4448
- '%APPDATA%\Mining\coin-miner.exe' /pid=5092
- '%APPDATA%\Mining\coin-miner.exe' /pid=4248
- '%APPDATA%\Mining\coin-miner.exe' /pid=392
- '%APPDATA%\Mining\coin-miner.exe' /pid=500
- '%APPDATA%\Mining\coin-miner.exe' /pid=4440
- '%APPDATA%\Mining\coin-miner.exe' /pid=3684
- '%APPDATA%\Mining\coin-miner.exe' /pid=4752
- '%APPDATA%\Mining\coin-miner.exe' /pid=5232
- '%APPDATA%\Mining\coin-miner.exe' /pid=3444
- '%APPDATA%\Mining\coin-miner.exe' /pid=5652
- '%APPDATA%\Mining\coin-miner.exe' /pid=1156
- '%APPDATA%\Mining\coin-miner.exe' /pid=5932
- '%APPDATA%\Mining\coin-miner.exe' /pid=2928
- '%APPDATA%\Mining\coin-miner.exe' /pid=2832
- '%APPDATA%\Mining\coin-miner.exe' /pid=5424
- '%APPDATA%\Mining\coin-miner.exe' /pid=3844
- '%APPDATA%\Mining\coin-miner.exe' (downloaded from the Internet)
- %APPDATA%\Mining\coin-miner.exe
- from <Full path to virus> to %APPDATA%\Mining\fethercoin.exe
- 'my####emshake.info':80
- 'wp#d':80
- my####emshake.info/UFA.exe
- wp#d/wpad.dat
- DNS ASK my####emshake.info
- DNS ASK wp#d
- ClassName: 'Indicator' WindowName: ''