Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%APPDATA%\WinCFG\Libs\WinRing0x64.sys'
- 'WinRing0_1_2_0' %APPDATA%\WinCFG\Libs\WinRing0x64.sys
- %WINDIR%\explorer.exe
- %APPDATA%\wincfg\libs\winring0x64.sys
- %WINDIR%\temp\udd8803.tmp
- %WINDIR%\temp\udd8803.tmp
- 'po##.#upportxmr.com':80
- DNS ASK po##.#upportxmr.com
- '%WINDIR%\explorer.exe' -B --coin=monero --url=pool.supportxmr.com:80 --user=484CbSEqzdsPFcBxVRUZJNhmsHRcWkHEg2hnJ75NAyVqG9BQzF2cyeEew27TmaDtEqiP27xDpREa9CFWfZU9gECgJqDiJos --pass=teste --cpu-max-threads-hint=90 --do...