Техническая информация
- <SYSTEM32>\tasks\google chrome
- [HKLM\SYSTEM\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%TEMP%\WinRing0x64.sys'
- 'WinRing0_1_2_0' %TEMP%\WinRing0x64.sys
- %WINDIR%\explorer.exe
- %ALLUSERSPROFILE%\google\chrome.exe
- %TEMP%\winring0x64.sys
- 'ht##bin.org':80
- 'po##.#upportxmr.com':3333
- http://ht##bin.org/ip
- 'po##.#upportxmr.com':3333
- DNS ASK ht##bin.org
- DNS ASK po##.#upportxmr.com
- '%ALLUSERSPROFILE%\google\chrome.exe'
- '<SYSTEM32>\schtasks.exe' /create /sc minute /mo 1 /tn "Google Chrome" /rl HIGHEST /tr %ALLUSERSPROFILE%\Google\chrome.exe
- '%WINDIR%\explorer.exe' --donate-level 0 --cpu-max-threads-hint 40 -o pool.supportxmr.com:3333 -u 45XQiu9A9vmVd5Cy6X35M12NocUr2Hx69X4ZNNu2BsKJYkdksefg2gXJyvBUeEJyDWTfLD6GWmAu4Tab1w4tycfcFMqy8yH -p magic-cpu (со скрытым окном)