Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'AdwarePlus PopUp' = '%PROGRAM_FILES%\AdwarePlus\ap_PopUp.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'AdwarePlus' = '%PROGRAM_FILES%\AdwarePlus\AdwarePlus.exe Icon'
- %PROGRAM_FILES%\AdwarePlus\ap_PopUp.exe
- %PROGRAM_FILES%\AdwarePlus\ap_PopUp.exe (загружен из сети Интернет)
- <SYSTEM32>\cmd.exe /c ap_install.bat
- <Текущая директория>\ap_install.bat
- <SYSTEM32>\ap_UnInstall.exe
- %HOMEPATH%\Start Menu\Programs\AdwarePlus\AdwarePlus A¦°A.lnk
- %HOMEPATH%\Start Menu\Programs\AdwarePlus\AdwarePlus.lnk
- %PROGRAM_FILES%\AdwarePlus\AdwarePlus.dll2
- %PROGRAM_FILES%\AdwarePlus\AdwarePlus.exe2
- %PROGRAM_FILES%\AdwarePlus\ap_Update.exe2
- %PROGRAM_FILES%\AdwarePlus\ap_PopUp.exe2
- 'mi###adplus.com':80
- 'pr#####.microadplus.com':80
- 've#.##croadplus.com':80
- pr#####.microadplus.com/ap_Update.exe
- pr#####.microadplus.com/ap_UnInstall.exe
- mi###adplus.com/api_result.php?mo#########################################
- pr#####.microadplus.com/ap_PopUp.exe
- ve#.##croadplus.com/PG
- pr#####.microadplus.com/AdwarePlus.exe
- pr#####.microadplus.com/AdwarePlus.dll
- DNS ASK mi###adplus.com
- DNS ASK pr#####.microadplus.com
- DNS ASK ve#.##croadplus.com
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: '' WindowName: 'AdwarePlus PopUp'
- ClassName: '' WindowName: 'ADWAREPlus '