Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%APPDATA%\WinCFG\Libs\WinRing0x64.sys'
- %WINDIR%\explorer.exe
- %APPDATA%\wincfg\libs\winring0x64.sys
- %APPDATA%\wincfg\libs\ddb64.dll
- %APPDATA%\wincfg\libs\nvrtc-builtins64_101.dll
- %APPDATA%\wincfg\libs\nvrtc64_101_0.dll
- 'fi.#####o.herominers.com':10191
- DNS ASK fi.#####o.herominers.com
- '%WINDIR%\explorer.exe' --opencl --cuda --donate-level=4 -B --coin=monero --url=fi.monero.herominers.com:10191 --user=49ecaBerzAcbKFupfaZp6hKQnEAf3Udx1DN5SxXLVyyb91nCGgVCPgGbWi1fBCSFC6g5fQcqPuQdaD3Mi49GhwprTHkBffq -...