Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'PCRPopup' = '%PROGRAM_FILES%\PC-Radar\PCRPopup.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'PC-Radar' = '%PROGRAM_FILES%\PC-Radar\PC_Radar.exe Icon'
- %PROGRAM_FILES%\PC-Radar\NeoSetup.exe (загружен из сети Интернет)
- %PROGRAM_FILES%\PC-Radar\PCRPopup.exe (загружен из сети Интернет)
- %PROGRAM_FILES%\PC-Radar\PC_Radar.exe (загружен из сети Интернет) Icon
- %HOMEPATH%\Start Menu\Programs\PC-Radar\PC-Radar A¦°A.lnk
- %HOMEPATH%\Start Menu\Programs\PC-Radar\PC-Radar.lnk
- %PROGRAM_FILES%\PC-Radar\NeoSetup.exe
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\PC-Radar.lnk
- %HOMEPATH%\Desktop\PC-Radar.lnk
- %PROGRAM_FILES%\PC-Radar\PC_Radar.dll2
- %PROGRAM_FILES%\PC-Radar\PC_Radar.exe2
- <SYSTEM32>\PCRremover.exe
- %PROGRAM_FILES%\PC-Radar\PCRPopup.exe2
- 'pc###ar.co.kr':80
- pc###ar.co.kr/PCRadar/PCRremover.exe
- pc###ar.co.kr/api_result.php?mo##################################
- pc###ar.co.kr/PCRadar/NeoSetup.exe
- pc###ar.co.kr/PCRadar/PC_Radar.exe
- pc###ar.co.kr/PCRadar/PC_Radar.dll
- pc###ar.co.kr/PCRadar/PCRPopup.exe
- DNS ASK www.pc###ar.co.kr
- DNS ASK pc###ar.co.kr
- '<IP-адрес в локальной сети>':1036
- ClassName: '' WindowName: 'PCRPopup '
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: 'PC-Radar '