Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Viewsystem.exe' = '%PROGRAM_FILES%\Viewsystem\Viewsystem.exe'
- '%PROGRAM_FILES%\Viewsystem\Viewsystem.exe'
- '%PROGRAM_FILES%\Viewsystem\Viewsystem.exe' (downloaded from the Internet)
- '<SYSTEM32>\cmd.exe' /c <Current directory>\$$ssb34rd.bat
- '<SYSTEM32>\schtasks.exe' /create /sc onlogon /tn "Media vision" /tr "\"%PROGRAM_FILES%\Viewsystem\Viewsystem.exe"\" /rl highest
- <Current directory>\$$ssb34rd.bat
- %PROGRAM_FILES%\Viewsystem\Viewsystem.exe
- 'www.mo####d.comcontrol':80
- 'www.mo##nad.com':80
- http://www.mo##nad.com/control/pgm/Viewsystem.exe
- http://www.mo##nad.com/control/control_install.php?ma###############################
- http://www.mo####d.comcontrol/pgmver.php
- http://www.mo##nad.com/control/iconsrc.php
- http://www.mo##nad.com/control/src.php
- http://www.mo##nad.com/control/deny.php
- http://www.mo##nad.com/control/process.php
- DNS ASK www.mo####d.comcontrol
- DNS ASK www.mo##nad.com