Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ChekAniTool' = '\Default Folder\PresentationFontCache.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ChekAniTool' = '%LOCALAPPDATA%\Default Folder\PresentationFontCache.exe'
- C:\default folder\presentationfontcache.exe
- %LOCALAPPDATA%\default folder\presentationfontcache.exe
- %APPDATA%\imminent\logs\21-08-2020
- %APPDATA%\imminent\path.dat
- %APPDATA%\imminent\geo.dat
- <Полный путь к файлу>
- http://www.ip####keronline.com/
- DNS ASK to#####lebang.ddns.net
- DNS ASK ip####keronline.com