Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'Rainmeter' = '%ALLUSERSPROFILE%\KE3ZVM8AC66TI8169YIK\Rainmeter.exe'
- %ALLUSERSPROFILE%\ke3zvm8ac66ti8169yik\rainmeter.dll
- %ALLUSERSPROFILE%\ke3zvm8ac66ti8169yik\rainmeter.exe
- %ALLUSERSPROFILE%\ke3zvm8ac66ti8169yik\rainmeter.txt
- %LOCALAPPDATA%\178bfbff000406f1
- %ALLUSERSPROFILE%\ke3zvm8ac66ti8169yik\key
- 'of###kef.com':3355
- 'of###kef.com':816
- http://of####ef.com:3355/9x.dll via of###kef.com
- 'of###kef.com':816
- DNS ASK of###kef.com
- ClassName: 'EDIT' WindowName: ''
- '%ALLUSERSPROFILE%\ke3zvm8ac66ti8169yik\rainmeter.exe'