2016.09.28 13:55

[Adware] CloudGuard

조회 수 183 추천 수 0 댓글 0
?

단축키

Prev이전 문서

Next다음 문서

크게 작게 위로 아래로 댓글로 가기 인쇄

 

Adware.CloudGuard

 

 

* Registry path

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F281C29C-8BF6-4C4D-8984-B28ECD661AF5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GTFPOQUOTT
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\oaocmnfllndpbbmjmniielgaanaifehp
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.oaocmnfllndpbbmjmniielgaanaifehp.uid
HKEY_LOCAL_MACHINE\SOFTWARE\GTFPOQUOTT Updater
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GTFPOQUOTT Updater_is1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GTFPOQUOTT Updater

 

 

 

 

* Files path

 

C\Users\Ad\AppData\Local\Google\Chrome\User Data\Default\Extensions\oaocmnfllndpbbmjmniielgaanaifehp\0.3_0\_metadata\verified_contents.json
C\Users\Ad\AppData\Local\Google\Chrome\User Data\Default\Extensions\oaocmnfllndpbbmjmniielgaanaifehp\0.3_0\manifest.json
C\Program Files\GTFPOQUOTT\gtfpoquott.exe
C\Windows\System32\Tasks\GTFPOQUOTT
C\Users\Ad\AppData\Local\Google\Chrome\User Data\Default\Extensions\oaocmnfllndpbbmjmniielgaanaifehp\0.3_0\Ghostify 48pix.png
C\Users\Ad\AppData\Local\Google\Chrome\User Data\Default\Extensions\oaocmnfllndpbbmjmniielgaanaifehp\0.3_0\Ghostify 16pix.png
C\Users\Ad\AppData\Local\Google\Chrome\User Data\Default\Extensions\oaocmnfllndpbbmjmniielgaanaifehp\0.3_0\Ghostify 128pix.png
C\Users\Ad\AppData\Local\Google\Chrome\User Data\Default\Extensions\oaocmnfllndpbbmjmniielgaanaifehp\0.3_0\back.js
C\Users\Ad\AppData\Local\Google\Chrome\User Data\Default\Extensions\oaocmnfllndpbbmjmniielgaanaifehp
C\Users\Ad\AppData\Local\Google\Chrome\User Data\Default\Extensions\oaocmnfllndpbbmjmniielgaanaifehp\0.3_0\_metadata
C\Users\Ad\AppData\Local\Google\Chrome\User Data\Default\Extensions\oaocmnfllndpbbmjmniielgaanaifehp\0.3_0