Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%APPDATA%\Google\Libs\WR64.sys'
- 'WinRing0_1_2_0' %APPDATA%\Google\Libs\WR64.sys
- <SYSTEM32>\svchost.exe
- %TEMP%\content\796-1908-<File name>.exe-17-18-35-637.dump
- %TEMP%\content\796-1908-<File name>.exe-17-18-36-069.dump
- %TEMP%\content\796-1908-<File name>.exe-17-18-36-179.dump
- %APPDATA%\google\libs\wr64.sys
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\<File name>.exe.log
- %APPDATA%\google\libs\g.log
- %TEMP%\ltvlbubx.tmp
- 'xm#.#miners.com':12222
- 'mi#####ftrpgserver.com':443
- 'mi#####ftrpgserver.com':27039
- 'mi#####ftrpgserver.com':27039
- DNS ASK xm#.#miners.com
- DNS ASK mi#####ftrpgserver.com
- '<SYSTEM32>\cmd.exe' /c wmic PATH Win32_VideoController GET Name, VideoProcessor > "%APPDATA%\Google\Libs\g.log"
- '<SYSTEM32>\wbem\wmic.exe' PATH Win32_VideoController GET Name, VideoProcessor
- '<SYSTEM32>\svchost.exe' oaeujgaofoavkmqi 6E3sjfZq2rJQaxvLPmXgsA4f0StS9pic9Xw++oZ1mnbMNdSoXP4ts/KtNDhUPQkUfZN9DuEgllx4nisTvbxFunMfE63/wfj9DRS/1bpX0+vNWJvaIiD6hTmGpemnPPBdDKqYHBh/pWK88wRs78vgTeb1gji7xqOFjJHivBgpWaGKsjhV...