Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'b3dfdd5ad7a4f322cb59f704703b35f1' = '"%TEMP%\smsss.exe" ..'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'b3dfdd5ad7a4f322cb59f704703b35f1' = '"%TEMP%\smsss.exe" ..'
- %HOMEPATH%\Start Menu\Programs\Startup\b3dfdd5ad7a4f322cb59f704703b35f1.exe
- %HOMEPATH%\Start Menu\Programs\Startup\hauri.exe
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\smsss.exe' = '%TEMP%\smsss.exe:*:Enabled:smsss.exe'
- '%TEMP%\614.exe'
- '%TEMP%\smsss.exe'
- '%TEMP%\hauri.exe'
- '%TEMP%\JopieK_s_CrusaderTrainer___1_1_.0.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%TEMP%\smsss.exe" "smsss.exe" ENABLE
- %TEMP%\JopieK_s_CrusaderTrainer___1_1_.0.exe
- %TEMP%\614.exe
- %TEMP%\smsss.exe
- %TEMP%\aut1.tmp
- %TEMP%\hauri.exe
- %TEMP%\aut2.tmp
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- 'am####991.zapto.org':1177
- DNS ASK am####991.zapto.org
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'