Technical Information
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%ALLUSERSPROFILE%\Win64'
- 'WinRing0_1_2_0' %ALLUSERSPROFILE%\Win64
- %ALLUSERSPROFILE%\wininie.exe
- %ALLUSERSPROFILE%\win64
- %WINDIR%\temp\udd9646.tmp
- %WINDIR%\temp\udd9646.tmp
- 'po##.#upportxmr.com':3333
- DNS ASK po##.#upportxmr.com
- '%ALLUSERSPROFILE%\wininie.exe'
- '%ALLUSERSPROFILE%\wininie.exe' ' (with hidden window)