Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'idxneviwjakxlcpgthuh' = '%ALLUSERSPROFILE%\hmxvnhbtdrakbrfsmakxlymznaobpcqdveuivjwkkovsttqostkaoes\idxneviwja...
- %TEMP%\e_n60005\krnln.fnr
- %ALLUSERSPROFILE%\hmxvnhbtdrakbrfsmakxlymznaobpcqdveuivjwkkovsttqostkaoes\idxneviwjakxlcpgthuh.exe
- %ALLUSERSPROFILE%\hmxvnhbtdrakbrfsmakxlymznaobpcqdveuivjwkkovsttqostkaoes\rainmeter.dll
- %ALLUSERSPROFILE%\hmxvnhbtdrakbrfsmakxlymznaobpcqdveuivjwkkovsttqostkaoes\idxneviwjakxlcpgthuh.txt
- %LOCALAPPDATA%\178bfbff000406f1
- %ALLUSERSPROFILE%\hmxvnhbtdrakbrfsmakxlymznaobpcqdveuivjwkkovsttqostkaoes\key
- 'of###kef.com':3355
- 'of###kef.com':816
- http://of####ef.com:3355/9x.dll via of###kef.com
- 'of###kef.com':816
- DNS ASK of###kef.com
- '%ALLUSERSPROFILE%\hmxvnhbtdrakbrfsmakxlymznaobpcqdveuivjwkkovsttqostkaoes\idxneviwjakxlcpgthuh.exe'