Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%APPDATA%\Google\Libs\WR64.sys'
- 'WinRing0_1_2_0' %APPDATA%\Google\Libs\WR64.sys
- <SYSTEM32>\svchost.exe
- %APPDATA%\google\libs\wr64.sys
- %APPDATA%\931a.tmp
- 'po##.#upportxmr.com':3333
- 'po##.#upportxmr.com':3333
- DNS ASK po##.#upportxmr.com
- '<SYSTEM32>\svchost.exe' betcfcssfhx0 6E3sjfZq2rJQaxvLPmXgsCZAIMpmPntHEIWDH08V2Q38oDzy/Cqli7gBy2CefOtpHsALpgqtJfTdp6N8ontaSeKvIeEq/djsavvdVkyc6Q/1uggQNIaIpralxvUYcf+bGKmhEKQFnneUmKs24iV5qPDrvyhdZ+t+5cUHUHx7DL3NHx1/6rmb...