Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'RegSvcs' = '%APPDATA%\RegSvcs.exe'
- %WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe
- %TEMP%\autcc78.tmp
- %TEMP%\vaccinators
- %TEMP%\autd0ce.tmp
- %TEMP%\konked
- %APPDATA%\regsvcs.exe
- %TEMP%\aba125d284820b765b59217a34bd84ff\chromium_cookies_umwjzqfaaucl_2025-10-17_15.49.43.json
- %TEMP%\aba125d284820b765b59217a34bd84ff\gecko_cookies_umwjzqfaaucl_2025-10-17_15.49.55.json
- %TEMP%\autcc78.tmp
- %TEMP%\autd0ce.tmp
- %TEMP%\aba125d284820b765b59217a34bd84ff\chromium_cookies_umwjzqfaaucl_2025-10-17_15.49.43.json
- %TEMP%\aba125d284820b765b59217a34bd84ff\gecko_cookies_umwjzqfaaucl_2025-10-17_15.49.55.json
- 'ap#.##legram.org':443
- 'ic###azip.com':80
- http://ic###azip.com/
- 'ap#.##legram.org':443
- DNS ASK ap#.##legram.org
- DNS ASK ic###azip.com
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe'