Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Fn service] 'Start' = '00000002'
- %APPDATA%\filepds\pdscnt.exe ins
- %APPDATA%\filepds\pdssvc.exe -s
- <SYSTEM32>\cmd.exe /c \DelUS.bat
- %APPDATA%\filepds\uninst.exe
- %TEMP%\nsb2.tmp\SelfDelete.dll
- C:\DelUS.bat
- %APPDATA%\filepds\pdsup.exe
- %APPDATA%\filepds\pdscnt.exe
- %APPDATA%\filepds\pdssvc.exe
- %TEMP%\nsb2.tmp\SelfDelete.dll
- 'www.mo###ell.com':80
- www.mo###ell.com/v2/log/install.php?ma############################
- DNS ASK www.mo###ell.com
- '<IP-адрес в локальной сети>':1035