Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'rnvzwvvr' = '%TEMP%\Hdcpvaokpe\lyzwzwrwvvr.exe'
- '%TEMP%\letjlxvetj.pre'
- '<SYSTEM32>\wermgr.exe' -queuereporting
- '<SYSTEM32>\taskhost.exe' $(Arg0)
- '<SYSTEM32>\svchost.exe'
- <SYSTEM32>\svchost.exe
- C:\ProgramData\Microsoft\RAC\Temp\sql8516.tmp
- C:\ProgramData\Microsoft\RAC\Temp\sqlC6B8.tmp
- C:\ProgramData\Microsoft\RAC\Temp\sqlC6D8.tmp
- %TEMP%\letjlxvetj.pre
- %TEMP%\Hdcpvaokpe\lyzwzwrwvvr.exe
- C:\ProgramData\Microsoft\RAC\Temp\sql8536.tmp
- %TEMP%\Hdcpvaokpe\lyzwzwrwvvr.exe
- C:\ProgramData\Microsoft\RAC\Temp\sql8516.tmp
- C:\ProgramData\Microsoft\RAC\Temp\sql8536.tmp
- %TEMP%\letjlxvetj.pre
- 'to#####nect-secure.com':80
- 'mi####work100.com':80
- DNS ASK to#####nect-secure.com
- DNS ASK mi####work100.com
- ClassName: 'Indicator' WindowName: '(null)'