Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SoundSystem' = '%APPDATA%\SoundSystem\SoundSystem.exe'
- %APPDATA%\SoundSystem\SoundSystem.exe
- 'wp#d':80
- 'do##it.me':443
- 'bd#s.at':443
- 'bd#s.by':443
- 'bd#s.bz':443
- 'bd#s.co':443
- 'bd#s.im':443
- 'bd#s.io':443
- 'bd##.name':443
- 'bd#s.us':443
- 'bd#s.ws':443
- 'pe###ame.com':443
- 'na##cha.in':443
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK wp#d
- DNS ASK do##it.me
- DNS ASK bd#s.at
- DNS ASK bd#s.by
- DNS ASK bd#s.bz
- DNS ASK bd#s.co
- DNS ASK bd#s.im
- DNS ASK bd#s.io
- DNS ASK bd##.name
- DNS ASK bd#s.us
- DNS ASK bd#s.ws
- DNS ASK pe###ame.com
- DNS ASK na##cha.in
- '%APPDATA%\SoundSystem\SoundSystem.exe'