Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Services.exe' = '%APPDATA%\Services.exe'
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%APPDATA%\WinCFG\Libs\WinRing0x64.sys'
- 'WinRing0_1_2_0' %APPDATA%\WinCFG\Libs\WinRing0x64.sys
- <SYSTEM32>\svchost.exe
- %APPDATA%\services.exe
- %APPDATA%\wincfg\libs\winring0x64.sys
- %APPDATA%\wincfg\libs\ddb64.dll
- %APPDATA%\wincfg\libs\nvrtc-builtins64_101.dll
- %APPDATA%\wincfg\libs\nvrtc64_101_0.dll
- 'gu##.##neroocean.stream':10128
- DNS ASK gu##.##neroocean.stream
- '%APPDATA%\services.exe'
- '<SYSTEM32>\svchost.exe' --opencl --cuda --donate-level=4 -B --coin=monero --url=gulf.moneroocean.stream:10128 --user=4AA9YGzFAKPYKEcoGNp9cW763K3zVQprVWEWymRzY4n5AZPSKRnx3DY98nHbf3wkxEEWkuwzbi8sjLm6noozdeHQJtUHp26 --...