Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'admin' = '%WINDIR%\Temp\smss.exe'
- %WINDIR%\win.ini
- C:\kss.ini
- %WINDIR%\win.exe
- %WINDIR%\win.exe
- %WINDIR%\win.exe в %WINDIR%\temp\smss.exe
- 'sm##oy.com':80
- '4s.##t579.com':16840
- http://www.sm##oy.com/kss_api/io.php?a=#######################################################################
- DNS ASK sm##oy.com
- DNS ASK 4s.##t579.com
- '%WINDIR%\win.exe'