PUA.Win32.Softcnapp.GA
PUA:Win32/Softcnapp (Microsoft)
Windows
Type de grayware:
Trojan
Destructif:
Non
Chiffrement:
In the wild::
Oui
Overview
Détails techniques
Installation
Erstellt die folgenden Ordner:
- %Program Files%\Common Files\Clover
(Hinweis: %Program Files%ist der Standardordner 'Programme', normalerweise C:\Programme.)
Andere Systemänderungen
Fügt die folgenden Registrierungsschlüssel hinzu:
HKEY_LOCAl_MACHINE\Software
Clovermgr =
HKEY_LOCAL_MACHINE\CurrentControlSet001\Services
HCloverService =
HKEY_LOCAL_MACHINE\CurrentControlSet001\Services\
HCloverService
Parameters =
Fügt die folgenden Registrierungseinträge hinzu:
HKEY_LOCAl_MACHINE\Software\Clovermgr
ServiceDescription = "Clover 自动更新服务"
HKEY_LOCAl_MACHINE\Software\Clovermgr
ServiceDisplayName = "clover_service"
HKEY_LOCAl_MACHINE\Software\Clovermgr
ServiceDll = %Program Files%\Clover\CloverSvc.dll"
HKEY_LOCAl_MACHINE\Software\Clovermgr
ServiceName = "HCloverService"
HKEY_LOCAL_MACHINE\CurrentControlSet001\Services\
HCloverService
Description = "Clover 自动更新服务"
HKEY_LOCAL_MACHINE\CurrentControlSet001\Services\
HCloverService
DisplayName = "clover_service"
HKEY_LOCAL_MACHINE\CurrentControlSet001\Services\
HCloverService
ErrorControl = "1"
HKEY_LOCAL_MACHINE\CurrentControlSet001\Services\
HCloverService
ImagePath = "C:\Windows\system32\svchost.exe -k HCloverService"
HKEY_LOCAL_MACHINE\CurrentControlSet001\Services\
HCloverService
ObjectName = "LocalSystem"
HKEY_LOCAL_MACHINE\CurrentControlSet001\Services\
HCloverService
Start = "2"
HKEY_LOCAL_MACHINE\CurrentControlSet001\Services\
HCloverService
Type = "120"
HKEY_LOCAL_MACHINE\CurrentControlSet001\Services\
HCloverService\Parameters
ServiceDll = "%Program Files%\Clover\CloverSvc.dll"
Einschleusungsroutine
Schleust die folgenden Dateien ein:
- %Program Files%\Common Files\Clover\Clover.ini
- %User Temp%\my7xData.7z
- %AppDataLocalLow%\Clover\Config\UseVestige.ini
- %Program Files%\Clover\ico\baidu.png
- %Program Files%\Clover\ico\jd.png
- %Program Files%\Clover\ico\taobao.png
- %Program Files%\Clover\reg,dat
- %Program Files%\Clover\unreg.dat
- %Program Files%\Clover\lang\lang_index.xml
- %Program Files%\Clover\CloverInfo.ini
- %Program Files%\Clover\appconfig.dat
- %Program Files%\Clover\default.dat
- %Program Files%\Clover\data\_.dat
- %Program Files%\Clover\data\__.dat
- %Program Files%\Clover\Clover.exe
- %Program Files%\Clover\ClvAssist.exe
- %Program Files%\Clover\ClvHelper.exe
- %Program Files%\Clover\ClvUtil.exe
- %Program Files%\Clover\SoftUpd.exe
- %Program Files%\Clover\Uninst.exe
- %Program Files%\Clover\CloverFlush.dll
- %Program Files%\Clover\CLoverSvc.dll
- %Program Files%\Clover\clover_dll.dll
- %Program Files%\Clover\DuiLib_u.dll
- %Program Files%\Clover\libeay32.dll
- %Program Files%\Clover\login_ui.dll
- %Program Files%\Clover\ssleay32.dll
- %Program Files%\Clover\TabHelper32.dll
- %Program Files%\Clover\TabHelper64.dll
- %Program Files%\Clover\lang\uires_chs.dll
- %Program Files%\Clover\lang\uires_de.dll
- %Program Files%\Clover\lang\uires_en.dll
- %Program Files%\Clover\lang\uires_es.dll
- %Program Files%\Clover\lang\uires_fr.dll
- %Program Files%\Clover\lang\uires_id.dll
- %Program Files%\Clover\lang\uires_jp.dll
- %Program Files%\Clover\lang\uires_ko.dll
- %Program Files%\Clover\lang\uires_nl.dll
- %Program Files%\Clover\lang\uires_pl.dll
- %Program Files%\Clover\lang\uires_pt.dll
- %Program Files%\Clover\lang\uires_ru.dll
- %Program Files%\Clover\lang\uires_tw.dll
- %Program Files%\Clover\UtilWnd.dll
- %Program Files%\Clover官方网站.url
- %Program Files%\Clover\Temp.xml
- %Program Files%\Clover\temp.dat
- %Program Files%\Clover\config.ini
- %Common Programs%\Clover\官方网站.url
- %Common Programs%\Clover\在线升级.lnk
- %Common Programs%\Clover\Clover.lnk
- %Common Programs%\Clover\卸载.lnk
- %Desktop%\Clover.lnk
(Hinweis: %Program Files%ist der Standardordner 'Programme', normalerweise C:\Programme.. %User Temp% ist der Ordner 'Temp' des aktuellen Benutzers, normalerweise C:\Dokumente und Einstellungen\{Benutzername}\Lokale Einstellungen\Temp unter Windows 2000(32-bit), XP und Server 2003(32-bit) und C:\Users\{Benutzername}\AppData\Local\Temp unter Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) und 10(64-bit).. %Desktop% ist der Ordner 'Desktop' für den aktuellen Benutzer, normalerweise C:\Windows\Profile\{Benutzername}\Desktop unter Windows 98 und ME, C:\WINNT\Profile\{Benutzername}\Desktop unter Windows NT, C:\Dokumente und Einstellungen\{Benutzername}\Desktop unter Windows 2000(32-bit), XP und Server 2003(32-bit) und C:\Users\{Benutzername}\Desktop unter Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) und 10(64-bit).)