I contacted the cheatseller support about this incident and I was blamed the fault. They are rude and show no sign of being helpful at all! After confronting them with proofs they stopped responding at all, this even hardens my concern about their knoweldege about this!
I completly wiped the system and tried recreating this, and no wonder: It worked flawless, the same files have been created again and started using my pc as a crypto farm
The loader dropped of multiple files obfuscated by .NetReactor heavily virtualized under:
C:\Windows\Temp
C:\Users\USERNAME\AppData\Local\Temp
with names like:
m.exe
TypeId.exe
Proofs:







