Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'svchost2.exe' = '%TEMP%\win32\svchost2.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'svchost1.exe' = '%APPDATA%\win32\svchost1.exe'
- %TEMP%\win32\svchost2.exe
- %APPDATA%\win32\svchost1.exe
- firefox.exe
- %TEMP%\grabber_pages.txt
- %TEMP%\ts-grabber.dll
- %APPDATA%\win32\svchost1.exe
- %TEMP%\win32\svchost2.exe
- '92.##1.168.214':80
- 92.##1.168.214/TSB/addons/grabber.dll
- 92.##1.168.214/TSB/grabber-connect.php
- 92.##1.168.214/TSB/connect.php?hw########################
- ClassName: 'Indicator' WindowName: ''