Техническая информация
- [HKLM\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%TEMP%\aedmhwoiacqa.sys'
- 'WinRing0_1_2_0' %TEMP%\aedmhwoiacqa.sys
- <SYSTEM32>\svchost.exe
- %TEMP%\aedmhwoiacqa.sys
- 'us.##pool.com':13333
- 'pa###bin.com':443
- 'pa####.paulmaney.info':4521
- 'us.##pool.com':13333
- 'pa###bin.com':443
- DNS ASK us.##pool.com
- DNS ASK pa###bin.com
- DNS ASK pa####.paulmaney.info
- DNS ASK pa####.danzimmer.space
- '<SYSTEM32>\powercfg.exe' /x -hibernate-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' /x -standby-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' /x -hibernate-timeout-dc 0
- '<SYSTEM32>\powercfg.exe' /x -standby-timeout-dc 0
- '<SYSTEM32>\svchost.exe'