FILE::
c:\users\Public\Documents\AppData\PoApp\PLauncher. exe
c:\users\Administrator\AppData\Local\PosService\Po s.exe
c:\users\Administrator\AppData\Local\ServUpdater\S erviceUpd.exe
folder::
c:\users\Public\Documents\AppData\PoApp
c:\users\Administrator\AppData\Local\PosService
c:\users\Administrator\AppData\Local\ServUpdater
registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"PosService"=-
driver::
PowerOffer Service
ServUpdater
DDS::
mStart Page = hxxp://search.findeer.com
TCP: Interfaces\{05D65E4B-308B-4C45-AD07-BC3FFFF65491}: NameServer = 176.31.229.24,176.31.229.25
TCP: Interfaces\{05D65E4B-308B-4C45-AD07-BC3FFFF65491}\6475D2D4830315555454E4: NameServer = 176.31.229.24,176.31.229.25
TCP: Interfaces\{34D489E8-74AF-40E2-BBC1-A2F539EBF19F}: NameServer = 176.31.229.24,176.31.229.25
TCP: Interfaces\{CB7E60C3-E6D6-4C02-A2FC-4D4EAA1A3843}: NameServer = 176.31.229.24,176.31.229.25