2020.12.23 10:11

Trojan.HaoTuKanKan, HPMonkey

조회 수 112 추천 수 0 댓글 0
?

단축키

Prev이전 문서

Next다음 문서

크게 작게 위로 아래로 댓글로 가기 인쇄 첨부
?

단축키

Prev이전 문서

Next다음 문서

크게 작게 위로 아래로 댓글로 가기 인쇄 첨부

Trojan.HaoTuKanKan


*file
C\Users\{USERNAME}\AppData\Local\HaoTuKanKan\HaoTuKanKan.exe
C\Users\{USERNAME}\AppData\Local\HaoTuKanKan\haotu_update.dll
C\Users\{USERNAME}\AppData\Local\HaoTuKanKan\uninstall.exe

*reg_key
HKCU\Software\HaoTuKanKan
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{01EB3F15-6569-4FCD-A1AA-913E906E2194}
HKLM\SYSTEM\CurrentControlSet\Services\HaoTuKanKan_UpdateSvc

*reg_val
HKCU\Software\Classes\.bmp\OpenWithProgids | HaoTuKanKan.bmp
HKCU\Software\Classes\.gif\OpenWithProgids | HaoTuKanKan.gif
HKCU\Software\Classes\.ico\OpenWithProgids | HaoTuKanKan.ico
HKCU\Software\Classes\.jpeg\OpenWithProgids | HaoTuKanKan.jpeg
HKCU\Software\Classes\.jpg\OpenWithProgids | HaoTuKanKan.jpg
HKCU\Software\Classes\.jxr\OpenWithProgids | HaoTuKanKan.jxr
HKCU\Software\Classes\.png\OpenWithProgids | HaoTuKanKan.png
HKCU\Software\Classes\.tga\OpenWithProgids | HaoTuKanKan.tga
HKCU\Software\Classes\.tif\OpenWithProgids | HaoTuKanKan.tif
HKCU\Software\Classes\.tiff\OpenWithProgids | HaoTuKanKan.tiff
HKCU\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts | HaoTuKanKan.bmp_.bmp
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3fr\OpenWithProgids | HaoTuKanKan.3fr
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\OpenWithProgids | HaoTuKanKan.bmp
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cut\OpenWithProgids | HaoTuKanKan.cut
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dds\OpenWithProgids | HaoTuKanKan.dds
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exr\OpenWithProgids | HaoTuKanKan.exr
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.g3\OpenWithProgids | HaoTuKanKan.g3
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\OpenWithProgids | HaoTuKanKan.gif
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdp\OpenWithProgids | HaoTuKanKan.hdp
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\OpenWithProgids | HaoTuKanKan.hdr
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ico\OpenWithProgids | HaoTuKanKan.ico
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff\OpenWithProgids | HaoTuKanKan.iff
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\OpenWithProgids | HaoTuKanKan.j2k
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jng\OpenWithProgids | HaoTuKanKan.jng
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\OpenWithProgids | HaoTuKanKan.jp2
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\OpenWithProgids | HaoTuKanKan.jpeg
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\OpenWithProgids | HaoTuKanKan.jpg
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jxr\OpenWithProgids | HaoTuKanKan.jxr
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.koa\OpenWithProgids | HaoTuKanKan.koa
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mng\OpenWithProgids | HaoTuKanKan.mng
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbm\OpenWithProgids | HaoTuKanKan.pbm
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcd\OpenWithProgids | HaoTuKanKan.pcd
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\OpenWithProgids | HaoTuKanKan.pct
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\OpenWithProgids | HaoTuKanKan.pcx
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pfm\OpenWithProgids | HaoTuKanKan.pfm
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgm\OpenWithProgids | HaoTuKanKan.pgm
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\OpenWithProgids | HaoTuKanKan.png
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppm\OpenWithProgids | HaoTuKanKan.ppm
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd\OpenWithProgids | HaoTuKanKan.psd
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras\OpenWithProgids | HaoTuKanKan.ras
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sgi\OpenWithProgids | HaoTuKanKan.sgi
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\OpenWithProgids | HaoTuKanKan.tga
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\OpenWithProgids | HaoTuKanKan.tif
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\OpenWithProgids | HaoTuKanKan.tiff
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wap\OpenWithProgids | HaoTuKanKan.wap
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webp\OpenWithProgids | HaoTuKanKan.webp
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xbm\OpenWithProgids | HaoTuKanKan.xbm
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xpm\OpenWithProgids | HaoTuKanKan.xpm
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost | HaoTuKanKan_UpdateSvc

 

Trojan.HPMonkey

 
*file
C:\Users\{USERNAME}\AppData\Roaming\hpmonkey\HPMonkeySrv.exe
C:\Users\{USERNAME}\AppData\Roaming\HPMonkey\MonkeyStarter.exe
C:\Users\{USERNAME}\AppData\Roaming\HPMonkey\uninstaller.exe

*reg_key
HKLM\SOFTWARE\HPMonkey
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HPMonkey

 

11111.png

 


  1. PUP.MarvelSound, CalendarTool

    PUP.MarvelSound *reg_key HKLM\SOFTWARE\Classes\MarvelSound.Media.1 HKLM\SOFTWARE\Classes\SystemFileAssociations\audio\OpenWithList\marvelsound.exe HKLM\SOFTWARE\Classes\SystemFileAssociations\video\OpenWithList\marvelsound.exe *reg_val HKLM\...
    Date2021.01.06 Byezclean Reply0 Views2259 file
    Read More
  2. Trojan.Ghapoly, BestCleaner

    Trojan.Ghapoly *file C:\Program Files\ghapoly\Release_21.dll C:\Program Files\Ghapoly\Proxy32.dll C:\Program Files\Ghapoly\libvlc.dll C:\Program Files\Ghapoly\launcher_2.dll C:\Program Files\Ghapoly\drizutainshupkCld.dll2428453 C:\Program Fi...
    Date2021.01.05 Byezclean Reply0 Views872 file
    Read More
  3. Adware.Ebuyer, SmartCloud

    Adware.Ebuyer *file C\Windows\System32\Tasks\e-Buyer Updater C\Users\{USERNAME}\AppData\Local\ebuyer\ebuyer\1.4.4.4\res.dll C\Users\{USERNAME}\AppData\Local\ebuyer\ebuyer\1.4.4.4\fobkbCag.dll C\Users\{USERNAME}\AppData\Local\ebuyer\ebuyer\1....
    Date2021.01.04 Byezclean Reply0 Views662 file
    Read More
  4. Trojan.TCClock, PDFCracker

    Trojan.TCClock *file C:\Users\{USERNAME}\AppData\Roaming\RAF\coffeeclock\TCC-ClockFace.exe C:\Users\{USERNAME}\AppData\Roaming\RAF\coffeeclock\TCCalEvents.exe C:\Users\{USERNAME}\AppData\Roaming\RAF\coffeeclock\TCClock.exe C:\Users\{USERNAME...
    Date2020.12.29 Byezclean Reply0 Views2435 file
    Read More
  5. PUP.GrassValley, Heinote

    PUP.GrassValley *file C\Users\{USERNAME}\Desktop\EDIUS7_LO{USERNAME}ER.lnk C\Users\{USERNAME}\Desktop\EDIUS6_5_LO{USERNAME}ER.lnk C\Program Files\Grass Valley\EDIUS 7\Uninstall.exe C\Program Files\Grass Valley\EDIUS 7\LO{USERNAME}ER_7.40 488...
    Date2020.12.28 Byezclean Reply0 Views214 file
    Read More
  6. PUP.YoutubeMusic, DealPly

    PUP.YoutubeMusic *file C\Users\{USERNAME}\Desktop\Youtube Music Downlo{USERNAME}er.lnk C\Users\{USERNAME}\AppData\Local\Temp\is-AP0D1.tmp\Youtube_Music_Downlo{USERNAME}er_Setup.exe C\ProgramData\Microsoft\Windows\Start Menu\Programs\youtube ...
    Date2020.12.24 Byezclean Reply0 Views97 file
    Read More
  7. PUP.WinZipDiskTool

    PUP.WinZipDiskTool *files %appdata%\wzdt\lci.lci %appdata%\wzdt\uid.txt %programfiles%\winzip disk tools\wzdthelper.dll %programfiles%\winzip disk tools\asores.dll %programfiles%\winzip disk tools\wzdtdefragsrv64.exe %programfiles%\winzip di...
    Date2020.12.23 Byezclean Reply0 Views746 file
    Read More
  8. Trojan.HaoTuKanKan, HPMonkey

    Trojan.HaoTuKanKan *file C\Users\{USERNAME}\AppData\Local\HaoTuKanKan\HaoTuKanKan.exe C\Users\{USERNAME}\AppData\Local\HaoTuKanKan\haotu_update.dll C\Users\{USERNAME}\AppData\Local\HaoTuKanKan\uninstall.exe *reg_key HKCU\Software\HaoTuKanKan...
    Date2020.12.23 Byezclean Reply0 Views112 file
    Read More
  9. PUP.ChromeEX, Homply

    PUP.ChromeEX *file %localappdata%\Google\Chrome\User Data\Default\Extensions\hmnbcmfnnpbhiljneemgbickgiakmclj\12.303.10.20796_0\native\libs %localappdata%\Google\Chrome\User Data\Default\Extensions\hmnbcmfnnpbhiljneemgbickgiakmclj\12.303.10....
    Date2020.12.22 Byezclean Reply0 Views116 file
    Read More
  10. Adware.ReimageRepair, Searchestoy, Netfilter

    Adware.ReimageRepair *file C:\programdata\reimage protector\av\avupdate.exe C:\programdata\reimage protector\av\savapi3_restart.exe C:\programdata\reimage protector\av\savapi3_start.exe C:\programdata\reimage protector\av\savapi3_stop.exe C:...
    Date2020.12.21 Byezclean Reply0 Views7840 file
    Read More
  11. PUP.AdvanceSystem, MineApp

    PUP.AdvanceSystem *file C:\Windows\System32\tasks\advance-system care_logon C:\ProgramData\Microsoft\Windows\Start Menu\Programs\advance-system care\uninstall advance-system care.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\advan...
    Date2020.12.17 Byezclean Reply0 Views1034 file
    Read More
  12. PUP.AdvancePCProtector, AdvancedSP

    PUP.AdvancePCProtector *file c:\program files\akick\advance pc protector\savapi\aecore.dll c:\program files\akick\advance pc protector\savapi\aehelp.dll c:\program files\akick\advance pc protector\savapi\aerdl.dll c:\program files\akick\adva...
    Date2020.12.16 Byezclean Reply0 Views73 file
    Read More
  13. PUP.Catalina, BrowseFox

    PUP.Catalina *file c:\users\{USERNAME}\appdata\local\catalinagroup\update\1.3.25.225\goopdate.dll c:\users\{USERNAME}\appdata\local\catalinagroup\update\1.3.25.225\catalinacrashhandler.exe c:\users\{USERNAME}\appdata\local\catalinagroup\upda...
    Date2020.12.14 Byezclean Reply0 Views1372 file
    Read More
  14. PUP.Carambis, PUP.AppMaster

    PUP.Carambis *file c:\users\{USERNAME}\appdata\local\carambis\cleaner.ini c:\users\{USERNAME}\desktop\cleaner.lnk c:\program files\carambis\cleaner\imageformats\qico.dll c:\program files\carambis\cleaner\imageformats\qjpeg.dll c:\program fil...
    Date2020.12.11 Byezclean Reply0 Views84 file
    Read More
  15. Trojan.DMA, PCBooster

    Trojan.DMA C:\Users\{USERNAME}\AppData\Roaming\Desktop Management Agent\9giyumuw.exe C:\ProgramData\desktop management Agent\135cc5sig.exe C:\ProgramData\Desktop Management Agent\1u15919i3ye.exe C:\ProgramData\Desktop Management Agent\3ag117...
    Date2020.12.10 Byezclean Reply0 Views60 file
    Read More
  16. PUP.SAntivirus, Spigot

    PUP.SAntivirus *file c:\program files\santivirus\santivirusic.exe c:\program files\santivirus\santiviruskd.sys c:\program files\santivirus\santivirusservice.exe c:\programdata\microsoft\windows\start menu\programs\santivirus\santivirus produ...
    Date2020.12.09 Byezclean Reply0 Views18863 file
    Read More
  17. PUP.MaxUnInstaller, Monterix

    PUP.MaxUnInstaller *file c:\program files\max uninstaller\almu.exe c:\program files\max uninstaller\installedsoftware.txt c:\program files\max uninstaller\j_fixcs.dll c:\program files\max uninstaller\license.txt c:\program files\max uninstal...
    Date2020.12.08 Byezclean Reply0 Views482 file
    Read More
  18. Adware.AnySend, Linkury

    Adware.AnySend *file C:\Users\{USERNAME}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnySend\AnySend.lnk C:\Users\{USERNAME}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnySend\AnySend Show Tutorial.lnk C:\Users\{USERNAME...
    Date2020.12.07 Byezclean Reply0 Views109 file
    Read More
  19. Trojan. CalculatemPro, KGBKeyLogger

    Trojan. CalculatemPro *file C:\Program Files\CalculatemPro\affil.txt C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Calculatem Pro\Calculatem Pro.lnk C:\Users\{USERNAME}\Desktop\Calculatem Pro.lnk C:\Program Files\CalculatemPro\Calcula...
    Date2020.12.04 Byezclean Reply0 Views283 file
    Read More
  20. PUP.DriverXYZ, LiveSupport

    PUP.DriverXYZ *file c:\users\public\desktop\driverxyz.lnk c:\programdata\microsoft\windows\start menu\programs\driverxyz\driverxyz.lnk c:\programdata\microsoft\windows\start menu\programs\driverxyz\register driverxyz.lnk c:\programdata\micro...
    Date2020.12.02 Byezclean Reply0 Views52 file
    Read More
Board Pagination Prev 1 ... 3 4 5 6 7 8 Next
/ 8
XE Login