Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SMSS' = '%ALLUSERSPROFILE%\Application Data\SMSS.EXE'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] 'param' = '%ALLUSERSPROFILE%\Application Data\SMSS.EXE:*:Enabled:Служба Windows'
- %TEMP%\${07F87498-10EF-2823-BDA4-9B62B04-07-2011-15-03-468A3D}.tmp
- %ALLUSERSPROFILE%\Application Data\SMSS.EXE
- 'localhost':1037
- DNS ASK am######.freehyperspace4.com