Техническая информация
- [HKLM\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%TEMP%\vclluexpyltc.sys'
- 'WinRing0_1_2_0' %TEMP%\vclluexpyltc.sys
- %WINDIR%\explorer.exe
- %TEMP%\vclluexpyltc.sys
- %TEMP%\adxnphjtnpno.tmp
- 'po##.#upportxmr.com':3333
- 'pr####txx.ddns.net':80
- http://pr####txx.ddns.net/api/endpoint.php
- 'po##.#upportxmr.com':3333
- DNS ASK po##.#upportxmr.com
- DNS ASK pr####txx.ddns.net
- '%WINDIR%\explorer.exe'