Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Leadhillite' = '%TEMP%\Cadencies\svvenes.exe'
- Процесс jtviqwpz.exe, модуль ntdll.dll
- %TEMP%\nsr73da.tmp
- %APPDATA%\microsoft\windows\templates\typecheckes\treven
- %APPDATA%\microsoft\windows\templates\typecheckes\foremark.bor
- %APPDATA%\microsoft\windows\templates\typecheckes\pomes
- %APPDATA%\microsoft\windows\templates\typecheckes\friskest.aba
- %APPDATA%\microsoft\windows\templates\typecheckes\jua.sus
- %APPDATA%\microsoft\windows\templates\typecheckes\nordvestligt.bie
- %APPDATA%\microsoft\windows\templates\typecheckes\phoroscope.pac
- %APPDATA%\microsoft\windows\templates\typecheckes\skrslipperne.kri
- %TEMP%\nsn7850.tmp\system.dll
- %TEMP%\cadencies\svvenes.exe
- 'drive.google.com':443
- '19#.#58.198.23':80
- 'drive.usercontent.google.com':443
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?66##############
- 'drive.google.com':443
- 'drive.usercontent.google.com':443
- DNS ASK drive.google.com
- DNS ASK drive.usercontent.google.com
- ClassName: '#32770' WindowName: ''