Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'svchost2.exe' = '%TEMP%\win32\svchost2.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'svchost1.exe' = '%APPDATA%\win32\svchost1.exe'
- %TEMP%\win32\svchost2.exe
- %APPDATA%\win32\svchost1.exe
- %TEMP%\4tbd31ck.exe
- %APPDATA%\win32\svchost1.exe
- %TEMP%\win32\svchost2.exe
- %TEMP%\4tbd31ck.exe
- %TEMP%\cscomp.dll
- ClassName: 'Indicator' WindowName: ''