Техническая информация
- [HKLM\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%TEMP%\ikayzaxhgxsp.sys'
- 'WinRing0_1_2_0' %TEMP%\ikayzaxhgxsp.sys
- %WINDIR%\explorer.exe
- %TEMP%\ikayzaxhgxsp.sys
- '3.##.254.14':80
- 'ze##.#miners.com':12222
- http://3.##.254.14/api/endpoint.php
- 'ze##.#miners.com':12222
- DNS ASK ze##.#miners.com
- '<SYSTEM32>\powercfg.exe' /x -hibernate-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' /x -standby-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' /x -hibernate-timeout-dc 0
- '<SYSTEM32>\powercfg.exe' /x -standby-timeout-dc 0
- '%WINDIR%\explorer.exe'