Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Host Process' = '"<LS_APPDATA>\FlashContainer\rundll32.exe"'
- '<LS_APPDATA>\FlashContainer\rundll32.exe'
- Handler for all processes: <LS_APPDATA>\FlashContainer\dll\hookdll.dll
- <LS_APPDATA>\FlashContainer\bin\bfg64\bfgminer.exe
- <LS_APPDATA>\FlashContainer\bin\bfg64\backtrace.dll
- <LS_APPDATA>\FlashContainer\bin\bfg64\libblkmaker_jansson-0.1-0.dll
- <LS_APPDATA>\FlashContainer\bin\bfg64\bfgminer-rpc.exe
- <LS_APPDATA>\FlashContainer\bin\bfg32\pthreadGC2.dll
- <LS_APPDATA>\FlashContainer\bin\bfg32\pdcurses.dll
- <LS_APPDATA>\FlashContainer\bin\bfg32\scrypt130511.cl
- <LS_APPDATA>\FlashContainer\bin\bfg32\zlib1.dll
- <LS_APPDATA>\FlashContainer\bin\bfg64\pthreadGC2.dll
- <LS_APPDATA>\FlashContainer\bin\bfg64\pdcurses.dll
- <LS_APPDATA>\FlashContainer\bin\bfg64\scrypt130511.cl
- <LS_APPDATA>\FlashContainer\bin\bfg64\zlib1.dll
- <LS_APPDATA>\FlashContainer\bin\bfg64\libcurl-4.dll
- <LS_APPDATA>\FlashContainer\bin\bfg64\libblkmaker-0.1-0.dll
- <LS_APPDATA>\FlashContainer\bin\bfg64\libjansson-4.dll
- <LS_APPDATA>\FlashContainer\bin\bfg64\libusb-1.0.dll
- <LS_APPDATA>\FlashContainer\bin\miderd\libcurl-4.dll
- <LS_APPDATA>\FlashContainer\bin\miderd\minerd.exe
- <LS_APPDATA>\FlashContainer\bin\miderd\zlib1.dll
- <LS_APPDATA>\FlashContainer\bin\miderd\pthreadGC2.dll
- <LS_APPDATA>\FlashContainer\taskhost.exe
- <LS_APPDATA>\FlashContainer\rundll32.exe
- <LS_APPDATA>\FlashContainer\dll\hookdll64.dll
- <LS_APPDATA>\FlashContainer\dll\hookdll.dll
- <LS_APPDATA>\FlashContainer\bin\bfg32\libcurl-4.dll
- <LS_APPDATA>\FlashContainer\bin\bfg32\libblkmaker-0.1-0.dll
- <LS_APPDATA>\FlashContainer\bin\bfg32\libjansson-4.dll
- <LS_APPDATA>\FlashContainer\bin\bfg32\libusb-1.0.dll
- <LS_APPDATA>\FlashContainer\bin\bfg32\bfgminer.exe
- <LS_APPDATA>\FlashContainer\bin\bfg32\backtrace.dll
- <LS_APPDATA>\FlashContainer\bin\bfg32\libblkmaker_jansson-0.1-0.dll
- <LS_APPDATA>\FlashContainer\bin\bfg32\bfgminer-rpc.exe
- '22#.#55.185.2':123
- ClassName: 'Indicator' WindowName: '(null)'