Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'PcBoanPlus' = '"%PROGRAM_FILES%\PcBoanPlus\launcher.exe" "%PROGRAM_FILES%\PcBoanPlus\PcBoanPlusUp.exe" /disk'
- %PROGRAM_FILES%\PcBoanPlus\PcBoanPlus.exe /disk /newupdater
- %PROGRAM_FILES%\PcBoanPlus\PcBoanPlusUp.exe /disk
- %PROGRAM_FILES%\PcBoanPlus\PcBoanPlus.exe /install
- %PROGRAM_FILES%\PcBoanPlus\uninstall.exe
- %HOMEPATH%\Start Menu\Programs\PcBoanPlus\PCєёѕИ PLUS.lnk
- %PROGRAM_FILES%\PcBoanPlus\launcher.exe
- %HOMEPATH%\Desktop\PCєёѕИ PLUS.lnk
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\update[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\install[1].php
- %PROGRAM_FILES%\PcBoanPlus\PcBoanPlusFunc.dll
- %PROGRAM_FILES%\PcBoanPlus\PcBoanPlus.exe
- %TEMP%\nss3.tmp\System.dll
- %TEMP%\nsn2.tmp
- %PROGRAM_FILES%\PcBoanPlus\PcBoanPlusRes.dll
- %PROGRAM_FILES%\PcBoanPlus\PcBoanPlusBlk.dll
- %PROGRAM_FILES%\PcBoanPlus\PcBoanPlusUp.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\update[1].htm
- %TEMP%\nss3.tmp\System.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\install[1].php
- 'www.pc###nplus.com':80
- '21#.#3.123.40':80
- www.pc###nplus.com/app/update.htm
- 21#.#3.123.40/pcboanplus/install.php?ma########################################
- DNS ASK www.pc###nplus.com
- ClassName: 'Indicator' WindowName: ''