Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'KeApplet' = '"%TEMP%\ke64cleszfi.exe"'
- %WINDIR%\Explorer.EXE
- iexplore.exe
- opera.exe
- chrome.exe
- firefox.exe
- %TEMP%\2.m.log
- %TEMP%\1.m.log
- %APPDATA%\Help\ceptr.tll
- %TEMP%\ke64cleszfi.exe
- %APPDATA%\Help\comm.tll
- 'co########on-claims-helpline.com':80
- 'www.al####akillah.com':80
- co########on-claims-helpline.com/in2/g.php
- www.al####akillah.com/tmp/g.php
- DNS ASK co########on-claims-helpline.com
- DNS ASK www.al####akillah.com