Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\Skype.lnk
- '%APPDATA%\WindowsHelp\shell.exe' -a sha256 -o stratum+tcp://stratum.bitcoin.cz:3333 -u thebankslife.russia -p moscow123 -t 0 -I 10
- '%APPDATA%\WindowsHelp\macromedia.exe' -a scrypt -o http://mi##.#ool-x.eu:8080 -u Kingz.1 -p x -g no -t 7
- '<SYSTEM32>\ping.exe' -n 5 127.0.0.1
- '<SYSTEM32>\taskkill.exe' /im "shell.exe"
- '<SYSTEM32>\taskkill.exe' /f /im "svchost.exe.exe""
- '<SYSTEM32>\taskkill.exe' /im macromedia.exe
- '<SYSTEM32>\taskkill.exe' /im Shell.exe
- '<SYSTEM32>\cscript.exe' usft_ext.exe.vbs
- '<SYSTEM32>\taskkill.exe' /f /im "wscript.exe"
- '<SYSTEM32>\taskkill.exe' /im "Mousdurenekunox"
- '<SYSTEM32>\wscript.exe' puts.vbs
- '<SYSTEM32>\taskkill.exe' /f /im "njq8ishere.exe"
- '<SYSTEM32>\taskkill.exe' /f /im "macromedia.exe"
- '<SYSTEM32>\taskkill.exe' /f /im "cscript.exe"
- <SYSTEM32>\cscript.exe
- %APPDATA%\WindowsHelp\shel\shell.exe_part32
- %APPDATA%\WindowsHelp\shel\shell.exe_part31
- %APPDATA%\WindowsHelp\shel\shell.exe_part33
- %APPDATA%\WindowsHelp\shel\shell.exe_part35
- %APPDATA%\WindowsHelp\shel\shell.exe_part34
- %APPDATA%\WindowsHelp\shel\shell.exe_part28
- %APPDATA%\WindowsHelp\shel\shell.exe_part27
- %APPDATA%\WindowsHelp\shel\shell.exe_part29
- %APPDATA%\WindowsHelp\shel\shell.exe_part30
- %APPDATA%\WindowsHelp\shel\shell.exe_part3
- %APPDATA%\WindowsHelp\shel\shell.exe_part36
- %APPDATA%\WindowsHelp\shel\shell.exe_part42
- %APPDATA%\WindowsHelp\shel\shell.exe_part41
- %APPDATA%\WindowsHelp\shel\shell.exe_part43
- %APPDATA%\WindowsHelp\shel\shell.exe_part45
- %APPDATA%\WindowsHelp\shel\shell.exe_part44
- %APPDATA%\WindowsHelp\shel\shell.exe_part38
- %APPDATA%\WindowsHelp\shel\shell.exe_part37
- %APPDATA%\WindowsHelp\shel\shell.exe_part39
- %APPDATA%\WindowsHelp\shel\shell.exe_part40
- %APPDATA%\WindowsHelp\shel\shell.exe_part4
- %APPDATA%\WindowsHelp\shel\shell.exe_part26
- %APPDATA%\WindowsHelp\shel\shell.exe_part12
- %APPDATA%\WindowsHelp\shel\shell.exe_part11
- %APPDATA%\WindowsHelp\shel\shell.exe_part13
- %APPDATA%\WindowsHelp\shel\shell.exe_part15
- %APPDATA%\WindowsHelp\shel\shell.exe_part14
- %APPDATA%\WindowsHelp\puts.vbs
- %APPDATA%\WindowsHelp\phatk.ptx
- %APPDATA%\WindowsHelp\shel\compile.bat
- %APPDATA%\WindowsHelp\shel\shell.exe_part10
- %APPDATA%\WindowsHelp\shel\shell.exe_part1
- %APPDATA%\WindowsHelp\shel\shell.exe_part16
- %APPDATA%\WindowsHelp\shel\shell.exe_part22
- %APPDATA%\WindowsHelp\shel\shell.exe_part21
- %APPDATA%\WindowsHelp\shel\shell.exe_part23
- %APPDATA%\WindowsHelp\shel\shell.exe_part25
- %APPDATA%\WindowsHelp\shel\shell.exe_part24
- %APPDATA%\WindowsHelp\shel\shell.exe_part18
- %APPDATA%\WindowsHelp\shel\shell.exe_part17
- %APPDATA%\WindowsHelp\shel\shell.exe_part19
- %APPDATA%\WindowsHelp\shel\shell.exe_part20
- %APPDATA%\WindowsHelp\shel\shell.exe_part2
- %APPDATA%\WindowsHelp\shel\shell.exe_part46
- %APPDATA%\WindowsHelp\shel\shell.exe_part72
- %APPDATA%\WindowsHelp\shel\shell.exe_part71
- %APPDATA%\WindowsHelp\shel\shell.exe_part73
- %APPDATA%\WindowsHelp\shel\shell.exe_part75
- %APPDATA%\WindowsHelp\shel\shell.exe_part74
- %APPDATA%\WindowsHelp\shel\shell.exe_part68
- %APPDATA%\WindowsHelp\shel\shell.exe_part67
- %APPDATA%\WindowsHelp\shel\shell.exe_part69
- %APPDATA%\WindowsHelp\shel\shell.exe_part70
- %APPDATA%\WindowsHelp\shel\shell.exe_part7
- %APPDATA%\WindowsHelp\shel\shell.exe_part76
- %APPDATA%\WindowsHelp\shel\shell.exe_part82
- %APPDATA%\WindowsHelp\shel\shell.exe_part81
- %APPDATA%\WindowsHelp\shel\shell.exe_part9
- %APPDATA%\WindowsHelp\usft_ext.exe.vbs
- %APPDATA%\WindowsHelp\usft_ext.dll
- %APPDATA%\WindowsHelp\shel\shell.exe_part78
- %APPDATA%\WindowsHelp\shel\shell.exe_part77
- %APPDATA%\WindowsHelp\shel\shell.exe_part79
- %APPDATA%\WindowsHelp\shel\shell.exe_part80
- %APPDATA%\WindowsHelp\shel\shell.exe_part8
- %APPDATA%\WindowsHelp\shel\shell.exe_part66
- %APPDATA%\WindowsHelp\shel\shell.exe_part52
- %APPDATA%\WindowsHelp\shel\shell.exe_part51
- %APPDATA%\WindowsHelp\shel\shell.exe_part53
- %APPDATA%\WindowsHelp\shel\shell.exe_part55
- %APPDATA%\WindowsHelp\shel\shell.exe_part54
- %APPDATA%\WindowsHelp\shel\shell.exe_part48
- %APPDATA%\WindowsHelp\shel\shell.exe_part47
- %APPDATA%\WindowsHelp\shel\shell.exe_part49
- %APPDATA%\WindowsHelp\shel\shell.exe_part50
- %APPDATA%\WindowsHelp\shel\shell.exe_part5
- %APPDATA%\WindowsHelp\shel\shell.exe_part56
- %APPDATA%\WindowsHelp\shel\shell.exe_part62
- %APPDATA%\WindowsHelp\shel\shell.exe_part61
- %APPDATA%\WindowsHelp\shel\shell.exe_part63
- %APPDATA%\WindowsHelp\shel\shell.exe_part65
- %APPDATA%\WindowsHelp\shel\shell.exe_part64
- %APPDATA%\WindowsHelp\shel\shell.exe_part58
- %APPDATA%\WindowsHelp\shel\shell.exe_part57
- %APPDATA%\WindowsHelp\shel\shell.exe_part59
- %APPDATA%\WindowsHelp\shel\shell.exe_part60
- %APPDATA%\WindowsHelp\shel\shell.exe_part6
- %APPDATA%\WindowsHelp\phatk.cl
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part32
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part31
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part33
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part35
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part34
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part28
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part27
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part29
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part30
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part3
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part36
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part42
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part41
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part43
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part45
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part44
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part38
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part37
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part39
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part40
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part4
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part26
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part12
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part11
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part13
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part15
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part14
- %APPDATA%\WindowsHelp\killer.bat
- %APPDATA%\WindowsHelp\coinutil.dll
- %APPDATA%\WindowsHelp\macro\compile.bat
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part10
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part1
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part16
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part22
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part21
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part23
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part25
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part24
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part18
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part17
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part19
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part20
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part2
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part46
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part72
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part71
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part73
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part75
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part74
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part68
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part67
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part69
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part70
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part7
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part76
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part82
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part81
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part9
- %APPDATA%\WindowsHelp\openssl.dll
- %APPDATA%\WindowsHelp\miner.dll
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part78
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part77
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part79
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part80
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part8
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part66
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part52
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part51
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part53
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part55
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part54
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part48
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part47
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part49
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part50
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part5
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part56
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part62
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part61
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part63
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part65
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part64
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part58
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part57
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part59
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part60
- %APPDATA%\WindowsHelp\macro\macromedia.exe_part6
- from %APPDATA%\WindowsHelp\macro\macromedia.exe_part1 to %APPDATA%\WindowsHelp\macro\macromedia.exe
- from %APPDATA%\WindowsHelp\macro\macromedia.exe to %APPDATA%\WindowsHelp\macromedia.exe
- from %APPDATA%\WindowsHelp\shel\shell.exe_part1 to %APPDATA%\WindowsHelp\shel\shell.exe
- from %APPDATA%\WindowsHelp\shel\shell.exe to %APPDATA%\WindowsHelp\shell.exe
- 'mi##.pool-x.eu':8080
- DNS ASK st####m.bitcoin.cz
- DNS ASK mi##.pool-x.eu
- ClassName: '(null)' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'