Technical Information
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'svhost' = '%ALLUSERSPROFILE%\Sytstem\System.exe'
- <SYSTEM32>\tasks\svhost
- %ALLUSERSPROFILE%\sytstem\system.exe
- DNS ASK ap#.##legram.org
- '%ALLUSERSPROFILE%\sytstem\system.exe'
- '<SYSTEM32>\schtasks.exe' /create /tn svhost /tr "%ALLUSERSPROFILE%\Sytstem\System.exe" /st 23:26 /du 23:59 /sc daily /ri 1 /f