Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%WINDIR%\WinRing0x64.sys'
- 'WinRing0_1_2_0' %WINDIR%\WinRing0x64.sys
- %WINDIR%\explorer.exe
- nul
- 'do####.v2.xmrig.com':3333
- 'do####.v2.xmrig.com':3333
- DNS ASK do####.v2.xmrig.com
- '%WINDIR%\explorer.exe'