Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Bet New Raddr' = '<Full path to file>'
- C:\ProgramData\Microsoft\splwow64.exe
- C:\ProgramData\Microsoft\splwow64.exe
- 'C:\ProgramData\Microsoft\splwow64.exe' -o stratum+tcp://monerohash.com:3333 -u 42EetHfNVbnDB41b1PskiCNpvhcTJ6NEJjZPYTB6vDqjHzg5hkfRDy6DoyPjKY1QrHD5AhZdq4oCviv1s3hw3iLLDzqzN7M -p x -k -t 2