Kaspersky says 90+ spoofed domains use malicious installers and SEO to deliver AsyncRAT to Windows systems through ScreenConnect.
A clean uninstall should not require detective work, yet here we are with folders and suspicion.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results