2020.12.23 10:11

Trojan.HaoTuKanKan, HPMonkey

조회 수 2 추천 수 0 댓글 0
?

단축키

Prev이전 문서

Next다음 문서

크게 작게 위로 아래로 댓글로 가기 인쇄 첨부
?

단축키

Prev이전 문서

Next다음 문서

크게 작게 위로 아래로 댓글로 가기 인쇄 첨부

Trojan.HaoTuKanKan


*file
C\Users\{USERNAME}\AppData\Local\HaoTuKanKan\HaoTuKanKan.exe
C\Users\{USERNAME}\AppData\Local\HaoTuKanKan\haotu_update.dll
C\Users\{USERNAME}\AppData\Local\HaoTuKanKan\uninstall.exe

*reg_key
HKCU\Software\HaoTuKanKan
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{01EB3F15-6569-4FCD-A1AA-913E906E2194}
HKLM\SYSTEM\CurrentControlSet\Services\HaoTuKanKan_UpdateSvc

*reg_val
HKCU\Software\Classes\.bmp\OpenWithProgids | HaoTuKanKan.bmp
HKCU\Software\Classes\.gif\OpenWithProgids | HaoTuKanKan.gif
HKCU\Software\Classes\.ico\OpenWithProgids | HaoTuKanKan.ico
HKCU\Software\Classes\.jpeg\OpenWithProgids | HaoTuKanKan.jpeg
HKCU\Software\Classes\.jpg\OpenWithProgids | HaoTuKanKan.jpg
HKCU\Software\Classes\.jxr\OpenWithProgids | HaoTuKanKan.jxr
HKCU\Software\Classes\.png\OpenWithProgids | HaoTuKanKan.png
HKCU\Software\Classes\.tga\OpenWithProgids | HaoTuKanKan.tga
HKCU\Software\Classes\.tif\OpenWithProgids | HaoTuKanKan.tif
HKCU\Software\Classes\.tiff\OpenWithProgids | HaoTuKanKan.tiff
HKCU\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts | HaoTuKanKan.bmp_.bmp
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3fr\OpenWithProgids | HaoTuKanKan.3fr
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\OpenWithProgids | HaoTuKanKan.bmp
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cut\OpenWithProgids | HaoTuKanKan.cut
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dds\OpenWithProgids | HaoTuKanKan.dds
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exr\OpenWithProgids | HaoTuKanKan.exr
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.g3\OpenWithProgids | HaoTuKanKan.g3
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\OpenWithProgids | HaoTuKanKan.gif
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdp\OpenWithProgids | HaoTuKanKan.hdp
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\OpenWithProgids | HaoTuKanKan.hdr
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ico\OpenWithProgids | HaoTuKanKan.ico
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff\OpenWithProgids | HaoTuKanKan.iff
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\OpenWithProgids | HaoTuKanKan.j2k
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jng\OpenWithProgids | HaoTuKanKan.jng
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\OpenWithProgids | HaoTuKanKan.jp2
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\OpenWithProgids | HaoTuKanKan.jpeg
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\OpenWithProgids | HaoTuKanKan.jpg
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jxr\OpenWithProgids | HaoTuKanKan.jxr
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.koa\OpenWithProgids | HaoTuKanKan.koa
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mng\OpenWithProgids | HaoTuKanKan.mng
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbm\OpenWithProgids | HaoTuKanKan.pbm
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcd\OpenWithProgids | HaoTuKanKan.pcd
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\OpenWithProgids | HaoTuKanKan.pct
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\OpenWithProgids | HaoTuKanKan.pcx
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pfm\OpenWithProgids | HaoTuKanKan.pfm
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgm\OpenWithProgids | HaoTuKanKan.pgm
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\OpenWithProgids | HaoTuKanKan.png
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppm\OpenWithProgids | HaoTuKanKan.ppm
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd\OpenWithProgids | HaoTuKanKan.psd
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras\OpenWithProgids | HaoTuKanKan.ras
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sgi\OpenWithProgids | HaoTuKanKan.sgi
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\OpenWithProgids | HaoTuKanKan.tga
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\OpenWithProgids | HaoTuKanKan.tif
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\OpenWithProgids | HaoTuKanKan.tiff
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wap\OpenWithProgids | HaoTuKanKan.wap
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webp\OpenWithProgids | HaoTuKanKan.webp
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xbm\OpenWithProgids | HaoTuKanKan.xbm
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xpm\OpenWithProgids | HaoTuKanKan.xpm
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost | HaoTuKanKan_UpdateSvc

 

Trojan.HPMonkey

 
*file
C:\Users\{USERNAME}\AppData\Roaming\hpmonkey\HPMonkeySrv.exe
C:\Users\{USERNAME}\AppData\Roaming\HPMonkey\MonkeyStarter.exe
C:\Users\{USERNAME}\AppData\Roaming\HPMonkey\uninstaller.exe

*reg_key
HKLM\SOFTWARE\HPMonkey
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HPMonkey

 

11111.png

 


  1. PUP.HohoSearch, Popfreeka

    PUP.HohoSearch *file C:\windows\System32\tasks\coacuiedclernege module C:\Prorogram files\ckotersequzight\vercolystecuyconfiguration.dll C:\Prorogram files\ckotersequzight\coacuiedclernegemodulejedeentsherwusy.exe C:\Prorogram files\ckoterse...
    Date2021.01.28 Byezclean Reply0 Views1 file
    Read More
  2. Adware.Linkury, Netfilter

    Adware.Linkury *reg_key HKCU\software\microsoft\internet explorer\main\featurecontrol\feature_browser_emulation:linkury.exe HKLM\software\microsoft\windows\currentversion\run:linkury chrome smartbar HKLM\software\microsoft\tracing\linkury_ra...
    Date2021.01.27 Byezclean Reply0 Views6 file
    Read More
  3. Trojan. RegistryTool, AdwareAlert

    Trojan. RegistryTool * File path C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegistryTool\Uninstall RegistryTool.lnk C:\Program Files\Downloaded Installers\{954FB8FF-7FCF-46F2-869F-1B61D1212904}\setup.msi C:\Users\Public\Desktop\Reg...
    Date2021.01.26 Byezclean Reply0 Views6 file
    Read More
  4. PUP.UCalendar, WebInternet

    PUP.UCalendar *file C:\Users\{USERNAME}\AppData\Local\ucalendar\desktopcalendar.dll C:\Users\{USERNAME}\AppData\Local\ucalendar\huangli.xml C:\Users\{USERNAME}\AppData\Local\ucalendar\icolog C:\Users\{USERNAME}\AppData\Local\ucalendar\niaoji...
    Date2021.01.25 Byezclean Reply0 Views1 file
    Read More
  5. PUP. Guffins, PriceLess

    PUP. Guffins *file C:\Program Files\Guffins\bar\1.bin\chrome\u4ffxtbr.jar C:\Program Files\Guffins\bar\1.bin\assists\ie_default_search_provider\CONFIG.XML C:\Program Files\Guffins\bar\1.bin\assists\ie_default_search_provider\ASSIST.EXE C:\Pr...
    Date2021.01.22 Byezclean Reply0 Views1 file
    Read More
  6. Adware.DVDVideoSoft, FileRubber

    Adware.DVDVideoSoft *file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\DVDVideoSoft Free Studio.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Log Report.lnk C:\ProgramData\Microsoft\Windows\Start ...
    Date2021.01.21 Byezclean Reply0 Views3 file
    Read More
  7. Adware.CoolVerte, Grape

    Adware.CoolVerte *file C:\users\public\Desktop\coolverter.lnk C:\programdata\microsoft\windows\start menu\programs\coolverter\coolverter.lnk C:\program files\coolverter\updater.exe C:\program files\coolverter\coolverter.exe *reg_key HKLM\sof...
    Date2021.01.20 Byezclean Reply0 Views11 file
    Read More
  8. Adware.dvdvideosoft, UniversalDriver

    Adware.dvdvideosoft *file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\dvdvideosoft free studio.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\log report.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\premium memb...
    Date2021.01.19 Byezclean Reply0 Views4 file
    Read More
  9. Trojan.winrule, BitCoinMiner

    Trojan.winrule *file C:\Program Files\winrule\Uninstall.exe C:\Program Files\winrule\WinRule.exe C:\Program Files\winrule\WinRuleSync.exe C:\Program Files\winrule\WinRuleSync_.exe C:\Program Files\winrule\winruletask.exe C:\Program Files\win...
    Date2021.01.15 Byezclean Reply0 Views14 file
    Read More
  10. PUP.DealPly, MinerGate

    PUP. DealPly *file C:\windows\tasks\dealplyliveupdatetaskmachinecore.job C:\program files\dealplylive\update\1.3.23.0\psuser.dll C:\program files\dealplylive\update\1.3.23.0\psmachine.dll C:\program files\dealplylive\update\1.3.23.0\npgoogle...
    Date2021.01.12 Byezclean Reply0 Views16 file
    Read More
  11. Trojan.TechAgent, Ghapoly

    Trojan.TechAgent *file C:\Windows\System32\Tasks\TechAgentTask C:\Windows\System32\Tasks\TechAgent Task C:\Users\Public\Desktop\TechAgent.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechAgent\TechAgent.lnk C:\ProgramData\Microso...
    Date2021.01.08 Byezclean Reply0 Views7 file
    Read More
  12. Adware.BlueMoon, FileSubmit

    Adware.Agent *file C:\Program Files\ZPA7NKFZ6Y\uninstaller.exe C:\Program Files\ZPA7NKFZ6Y\ZPA7NKFZ6.exe C:\Program Files\1CW6G366CO\E13LO2C7B.exe C:\Program Files\1CW6G366CO\uninstaller.exe *reg_key HKLM\SOFTWARE\Microsoft\Tracing\E13LO2C7B...
    Date2021.01.07 Byezclean Reply0 Views3 file
    Read More
  13. PUP.MarvelSound, CalendarTool

    PUP.MarvelSound *reg_key HKLM\SOFTWARE\Classes\MarvelSound.Media.1 HKLM\SOFTWARE\Classes\SystemFileAssociations\audio\OpenWithList\marvelsound.exe HKLM\SOFTWARE\Classes\SystemFileAssociations\video\OpenWithList\marvelsound.exe *reg_val HKLM\...
    Date2021.01.06 Byezclean Reply0 Views7 file
    Read More
  14. Trojan.Ghapoly, BestCleaner

    Trojan.Ghapoly *file C:\Program Files\ghapoly\Release_21.dll C:\Program Files\Ghapoly\Proxy32.dll C:\Program Files\Ghapoly\libvlc.dll C:\Program Files\Ghapoly\launcher_2.dll C:\Program Files\Ghapoly\drizutainshupkCld.dll2428453 C:\Program Fi...
    Date2021.01.05 Byezclean Reply0 Views7 file
    Read More
  15. Adware.Ebuyer, SmartCloud

    Adware.Ebuyer *file C\Windows\System32\Tasks\e-Buyer Updater C\Users\{USERNAME}\AppData\Local\ebuyer\ebuyer\1.4.4.4\res.dll C\Users\{USERNAME}\AppData\Local\ebuyer\ebuyer\1.4.4.4\fobkbCag.dll C\Users\{USERNAME}\AppData\Local\ebuyer\ebuyer\1....
    Date2021.01.04 Byezclean Reply0 Views6 file
    Read More
  16. Trojan.TCClock, PDFCracker

    Trojan.TCClock *file C:\Users\{USERNAME}\AppData\Roaming\RAF\coffeeclock\TCC-ClockFace.exe C:\Users\{USERNAME}\AppData\Roaming\RAF\coffeeclock\TCCalEvents.exe C:\Users\{USERNAME}\AppData\Roaming\RAF\coffeeclock\TCClock.exe C:\Users\{USERNAME...
    Date2020.12.29 Byezclean Reply0 Views15 file
    Read More
  17. PUP.GrassValley, Heinote

    PUP.GrassValley *file C\Users\{USERNAME}\Desktop\EDIUS7_LO{USERNAME}ER.lnk C\Users\{USERNAME}\Desktop\EDIUS6_5_LO{USERNAME}ER.lnk C\Program Files\Grass Valley\EDIUS 7\Uninstall.exe C\Program Files\Grass Valley\EDIUS 7\LO{USERNAME}ER_7.40 488...
    Date2020.12.28 Byezclean Reply0 Views4 file
    Read More
  18. PUP.YoutubeMusic, DealPly

    PUP.YoutubeMusic *file C\Users\{USERNAME}\Desktop\Youtube Music Downlo{USERNAME}er.lnk C\Users\{USERNAME}\AppData\Local\Temp\is-AP0D1.tmp\Youtube_Music_Downlo{USERNAME}er_Setup.exe C\ProgramData\Microsoft\Windows\Start Menu\Programs\youtube ...
    Date2020.12.24 Byezclean Reply0 Views9 file
    Read More
  19. PUP.WinZipDiskTool

    PUP.WinZipDiskTool *files %appdata%\wzdt\lci.lci %appdata%\wzdt\uid.txt %programfiles%\winzip disk tools\wzdthelper.dll %programfiles%\winzip disk tools\asores.dll %programfiles%\winzip disk tools\wzdtdefragsrv64.exe %programfiles%\winzip di...
    Date2020.12.23 Byezclean Reply0 Views10 file
    Read More
  20. Trojan.HaoTuKanKan, HPMonkey

    Trojan.HaoTuKanKan *file C\Users\{USERNAME}\AppData\Local\HaoTuKanKan\HaoTuKanKan.exe C\Users\{USERNAME}\AppData\Local\HaoTuKanKan\haotu_update.dll C\Users\{USERNAME}\AppData\Local\HaoTuKanKan\uninstall.exe *reg_key HKCU\Software\HaoTuKanKan...
    Date2020.12.23 Byezclean Reply0 Views2 file
    Read More
Board Pagination Prev 1 2 3 4 5 6 Next
/ 6
XE Login