Adware.CoolVerte, Grape

by ezclean posted Jan 20, 2021
?

단축키

Prev이전 문서

Next다음 문서

ESC닫기

크게 작게 위로 아래로 댓글로 가기 인쇄

Adware.CoolVerte

 


*file
C:\users\public\Desktop\coolverter.lnk
C:\programdata\microsoft\windows\start menu\programs\coolverter\coolverter.lnk
C:\program files\coolverter\updater.exe
C:\program files\coolverter\coolverter.exe

*reg_key
HKLM\software\classes\itva
HKLM\software\coolverter
HKLM\software\microsoft\windows\currentversion\uninstall\{e4e16044-384c-48b6-91f0-500c50b77d9e}}_is1

 


Adware.Grape

 


*file
C:\Users\{USERNAME}\AppData\Roaming\grape\data.db
C:\Users\{USERNAME}\AppData\Roaming\grape\grape.exe
C:\Users\{USERNAME}\AppData\Roaming\grape\grapeagent.exe
C:\Users\{USERNAME}\AppData\Roaming\grape\grapehost.exe
C:\Users\{USERNAME}\AppData\Roaming\grape\no23new.dll
C:\Users\{USERNAME}\AppData\Roaming\grape\smartpush.dll
C:\Users\{USERNAME}\AppData\Roaming\grape\uninst.exe

*reg_key
HKLM\software\microsoft\windows nt\currentversion\schedule\taskcache\tasks\{0cb68127-4f16-4eea-82af-263d33308010}
HKLM\software\microsoft\windows nt\currentversion\schedule\taskcache\tasks\{17ca3ca1-4bef-4551-83dc-004c85eaa08a}
HKLM\software\microsoft\windows nt\currentversion\schedule\taskcache\tasks\{92f04f18-637f-4338-ada3-babab5cb6910}
HKLM\software\microsoft\windows nt\currentversion\schedule\taskcache\tree\grape_agent
HKLM\software\microsoft\windows nt\currentversion\schedule\taskcache\tree\grape_client
HKLM\software\microsoft\windows nt\currentversion\schedule\taskcache\tree\grape_host
HKCU\software\smartpush_dll

*reg_val
HKCU\software\microsoft\windows\currentversion\run:grape_agent
HKCU\software\microsoft\windows\currentversion\run:grape_client

 

11111.png