Trojan.nscpucnminer
* Registry path
hcu_val\software\microsoft\windows\currentversion\run:##c:\users\사용자\appdata\roaming\nscpucnminer\img001.exe
hcu_key\software\bifrost
hcu_key\software\snappy
* Files path
c:\users\사용자\appdata\roaming\nscpucnminer\pools.txt
c:\users\사용자\appdata\roaming\nscpucnminer\nscpucnminer64.exe
c:\users\사용자\appdata\roaming\nscpucnminer\nscpucnminer32.exe
c:\\img001.exe
c:\users\사용자\appdata\roaming\microsoft\windows\start menu\programs\startup\run.lnk
c:\users\사용자\appdata\roaming\snappy\snappy.exe
c:\users\사용자\desktop\snappy.lnk
c:\users\사용자\appdata\roaming\nsminer\img001.exe
c:\users\사용자\appdata\roaming\nsminer\img002.exe
c:\users\사용자\appdata\roaming\nsminer\nscpucnminer32.exe
c:\users\사용자\appdata\roaming\nsminer\pools.txt
|
|