Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows' = '%ALLUSERSPROFILE%\Application Data\Microsoft\SMSS.EXE'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%ALLUSERSPROFILE%\Application Data\Microsoft\SMSS.EXE' = '%ALLUSERSPROFILE%\Application Data\Microsoft\SMSS.EXE:*:Enabled:Служба Windows'
- %TEMP%\${07F12108-10EF-2319-BDA4-9B62B12-10-2012-00-02-108A3D}
- %TEMP%\${07F53838-10EF-5598-BDA4-9B62B12-10-2012-00-01-408A3D}
- %ALLUSERSPROFILE%\Application Data\Microsoft\SMSS.EXE
- %TEMP%\${07F53838-10EF-5598-BDA4-9B62B12-10-2012-00-01-408A3D}
- 'localhost':1037