Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%APPDATA%\WinCFG\Libs\WinRing0x64.sys'
- 'WinRing0_1_2_0' %APPDATA%\WinCFG\Libs\WinRing0x64.sys
- %WINDIR%\explorer.exe
- %APPDATA%\wincfg\libs\winring0x64.sys
- %WINDIR%\temp\udd557f.tmp
- %WINDIR%\temp\udd557f.tmp
- 'xm#.##vemexyz.in':8080
- DNS ASK xm#.##vemexyz.in
- '%WINDIR%\explorer.exe' --donate-level=4 -B --coin=monero --url=xmr.givemexyz.in:8080 -o 66.70.218.40:8080 -o 209.141.35.17:8080 --user=46E9UkTFqALXNh2mSbA7WGDoa2i6h4WVgUgPVdT9ZdtweLRvAhWmbvuY1dhEmfjHbsavKXo3eGf5ZRb4...