Technical Information
- [HKLM\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%TEMP%\terzfardvkrs.sys'
- 'WinRing0_1_2_0' %TEMP%\terzfardvkrs.sys
- <SYSTEM32>\svchost.exe
- %TEMP%\terzfardvkrs.sys
- 'ge##ert.net':443
- 'xm#####a1.nanopool.org':10343
- 'ge##ert.net':443
- 'xm#####a1.nanopool.org':10343
- DNS ASK xm#####a1.nanopool.org
- DNS ASK ge##ert.net
- '<SYSTEM32>\sc.exe' stop UsoSvc
- '<SYSTEM32>\sc.exe' stop WaaSMedicSvc
- '<SYSTEM32>\sc.exe' stop wuauserv
- '<SYSTEM32>\sc.exe' stop bits
- '<SYSTEM32>\sc.exe' stop dosvc
- '<SYSTEM32>\powercfg.exe' /x -hibernate-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' /x -hibernate-timeout-dc 0
- '<SYSTEM32>\powercfg.exe' /x -standby-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' /x -standby-timeout-dc 0
- '<SYSTEM32>\svchost.exe'