Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%TEMP%\WinRing0x64.sys'
- 'WinRing0_1_2_0' %TEMP%\WinRing0x64.sys
- '%TEMP%\network02.exe' --donate-level 1 -o xmr.givemexyz.in:8080 -o 194.5.249.24:8080 -o 212.114.52.24:8080 -u 46E9UkTFqALXNh2mSbA7WGDoa2i6h4WVgUgPVdT9ZdtweLRvAhWmbvuY1dhEmfjHbsavKXo3eGf5ZRb4qJzFXLVHGYH4moQ
- '%TEMP%\cudas.exe' -pool stratum+tcp://192.99.69.170:9999 -wal 0x4095c6d8ff7c889d03f35d225aafd7a1a3d50953.x/c4kroot@protonmail.com
- %TEMP%\network02.exe
- %TEMP%\cudas.exe
- '20#.#41.40.190':80
- 'xm#.##vemexyz.in':8080
- http://20#.#41.40.190/cudas.exe
- DNS ASK xm#.##vemexyz.in
- '%TEMP%\network02.exe' --donate-level 1 -o xmr.givemexyz.in:8080 -o 194.5.249.24:8080 -o 212.114.52.24:8080 -u 46E9UkTFqALXNh2mSbA7WGDoa2i6h4WVgUgPVdT9ZdtweLRvAhWmbvuY1dhEmfjHbsavKXo3eGf5ZRb4qJzFXLVHGYH4moQ' (со скрытым окном)
- '%TEMP%\cudas.exe' -pool stratum+tcp://192.99.69.170:9999 -wal 0x4095c6d8ff7c889d03f35d225aafd7a1a3d50953.x/c4kroot@protonmail.com' (со скрытым окном)
- '<SYSTEM32>\setx.exe' GPU_FORCE_64BIT_PTR 0
- '<SYSTEM32>\setx.exe' GPU_MAX_HEAP_SIZE 100
- '<SYSTEM32>\setx.exe' GPU_USE_SYNC_OBJECTS 1
- '<SYSTEM32>\setx.exe' GPU_MAX_ALLOC_PERCENT 100
- '<SYSTEM32>\setx.exe' GPU_SINGLE_ALLOC_PERCENT 100