Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Client Server Runtime Process' = '%LOCALAPPDATA%\csr_hostsvc.exe'
- %LOCALAPPDATA%\csr_hostsvc.exe
- %TEMP%\evb908f.tmp
- %TEMP%\evb90b0.tmp
- %LOCALAPPDATA%\screenshot.png
- %LOCALAPPDATA%\csr_hostsvc.exe
- 'ap#.#pify.org':443
- 'ap#.##legram.org':443
- 'ap#.#pify.org':443
- 'ap#.##legram.org':443
- DNS ASK ap#.#pify.org
- DNS ASK ap#.##legram.org
- '%LOCALAPPDATA%\csr_hostsvc.exe'
- '%WINDIR%\syswow64\cmd.exe' /c start "" "%LOCALAPPDATA%\csr_hostsvc.exe"