Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'Rainmeter' = '%ALLUSERSPROFILE%\RM2P80RHS5ZUW94\Rainmeter.exe'
- %ALLUSERSPROFILE%\rm2p80rhs5zuw94\rainmeter.dll
- %ALLUSERSPROFILE%\rm2p80rhs5zuw94\rainmeter.exe
- %ALLUSERSPROFILE%\rm2p80rhs5zuw94\rainmeter.txt
- %LOCALAPPDATA%\178bfbff000406f1
- %ALLUSERSPROFILE%\rm2p80rhs5zuw94\key
- 'of###kef.com':3355
- 'of###kef.com':816
- http://of####ef.com:3355/9x.dll via of###kef.com
- 'of###kef.com':816
- DNS ASK of###kef.com
- ClassName: 'EDIT' WindowName: ''
- '%ALLUSERSPROFILE%\rm2p80rhs5zuw94\rainmeter.exe'