PUA.Win32.AutoPCSpeedup.F
Windows

マルウェアタイプ:
潜在的に迷惑なアプリケーション
破壊活動の有無:
なし
暗号化:
感染報告の有無 :
はい
概要
マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。
詳細
侵入方法
マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。
インストール
マルウェアは、以下のプロセスを追加します。
- taskkill.exe /f /im "iytr.exe"
- taskkill.exe /f /im "ASCValidatorService.exe"
- "%System Root%\Program Files\Auto ~PC~ Speedup for {computername}\iytr.exe" getwebparam
(註:%System Root%フォルダは、オペレーティングシステム(OS)が存在する場所で、いずれのOSでも通常、 "C:" です。.)
マルウェアは、以下のフォルダを作成します。
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\x64
- %Application Data%\Auto ~PC~ Speedup For {computername}
- %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Auto ~PC~ Speedup for {computername}
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}
- %User Temp%\is-SPD91.tmp\_isetup
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\x86
- %All Users Profile%\Auto ~PC~ Speedup for {computername}
- %Application Data%\Auto ~PC~ Speedup For {computername}\smico
(註:%System Root%フォルダは、オペレーティングシステム(OS)が存在する場所で、いずれのOSでも通常、 "C:" です。.. %Application Data%フォルダは、現在ログオンしているユーザのアプリケーションデータフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>\Local Settings\Application Data" です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Roaming" です。. %All Users Profile%フォルダは、ユーザの共通プロファイルフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\All Users” です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\ProgramData” です。. %User Temp%フォルダは、現在ログオンしているユーザの一時フォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザー名>\Local Settings\Temp"です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local\Temp" です。)
他のシステム変更
マルウェアは、以下のファイルを削除します。
- %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Auto ~PC~ Speedup for {computername}\Auto ~PC~ Speedup.url
- %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Auto ~PC~ Speedup for {computername}\Auto ~PC~ Speedup.pif
- %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Auto ~PC~ Speedup for {computername}\Buy Auto ~PC~ Speedup.pif
- %System Root%\Users\Public\Desktop\Auto ~PC~ Speedup.pif
- %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Auto ~PC~ Speedup for {computername}\Uninstall Auto ~PC~ Speedup.pif
- %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Auto ~PC~ Speedup for {computername}\Buy Auto ~PC~ Speedup.url
- %System Root%\Users\Public\Desktop\Auto ~PC~ Speedup.url
- %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Auto ~PC~ Speedup for {computername}\Uninstall Auto ~PC~ Speedup.url
(註:%All Users Profile%フォルダは、ユーザの共通プロファイルフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\All Users” です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\ProgramData” です。. %System Root%フォルダは、オペレーティングシステム(OS)が存在する場所で、いずれのOSでも通常、 "C:" です。.)
マルウェアは、以下のレジストリ値を追加します。
HKEY_CURRENT_USER\Software\Microsoft\
RestartManager\Session0000
Owner = "\xec\x05\x00\x00J\xeaR{#[\xd5\x01"
HKEY_CURRENT_USER\Software\Microsoft\
RestartManager\Session0000
SessionHash = "{random characters}"
HKEY_CURRENT_USER\Software\Microsoft\
RestartManager\Session0000
Sequence = "1"
HKEY_CURRENT_USER\Software\Microsoft\
RestartManager\Session0000
RegFiles0000 = "\x00\x00\x00gP\xef\xac\xbbM\xe5\x90\x90\xea\x80\x80\x05\xe1\x80\x80t\xe4\xb3\xa7"
HKEY_CURRENT_USER\Software\Microsoft\
RestartManager\Session0000
RegFilesHash = "{random characters}"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
TELNO = "(855)-332-0124"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
ISTELNO = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
apst = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
isshowng = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
issilent = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
affired = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
showwfo = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
ovoffdis = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
playsound = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
wfoset = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
country = ""
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
ipaddrurl = "http://www.{BLOCKED}iv.com/getip"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
prereg = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
showtn = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
cbkpoff = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
cta = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
showunins = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
delaytime = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
isiunidu = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
isavst = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
isprmjsn = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
runcam = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
runsrc = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
runpixel = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
stdismax = "4294967295"
HKEY_CURRENT_USER\Software\Auto ~PC~ Speedup For {computername}
utm_medium = ""
HKEY_CURRENT_USER\Software\Auto ~PC~ Speedup For {computername}
affiliateid = ""
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
utm_source = "msmsite"
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
utm_campaign = "msmsite"
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
utm_medium = ""
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
affiliateid = ""
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
pxl = "msmsite"
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
x-at = ""
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
x-context = ""
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
TELNO_us = "(855)-332-0124"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
TELNO_uk = "0800-031-5066"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
TELNO_gb = "0800-031-5066"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
TELNO_au = "(61)280-733403"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
TELNO_fr = "05 82 84 04 06"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
TELNO_de = "0800 1822 974"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
TELNO_at = "+43 (0)720 902 309"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
TELNO_ch = "+41 (0)44 508 70 37"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
TELNO_lu = "0800 1822 974"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
TELNO_no = "+47 21 95 01 97"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
TELNO_dk = "+45 78 73 09 26"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
TELNO_nl = "+31-08-58882839"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
TELNO_be = "+32-28085306"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
TELNO_se = "+46-08124-10298"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
TELNO_ja = ""
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
TELNO_br = "+55 21 2391 4319"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
TELNO_it = "+39 069 4802886"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
TELNO_es = "+34 951 203 537"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
TELNO_ar = "+54 11 5236 0324"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
TELNO_fi = "+358 (0)9 4270 4911"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
TELNO_pt = "+351 70 750 2094"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
pdtm = "30"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
PurchaseURL = "https://store.{BLOCKED}ysutils.net/aups/price?"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
RenewURL = "https://store.{BLOCKED}ysutils.net/aups/renewal?"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
WebURL = "https://www.{BLOCKED}ysutils.net"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
EmailURL = ""
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
supporturl = "http://www.{BLOCKED}ysutils.net/help"
HKEY_CURRENT_USER\Software\Auto ~PC~ Speedup For {computername}\
1.0.0.1
Installstring = "%System Root%\Program Files\Auto ~PC~ Speedup for {computername}"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
Installstring = "%System Root%\Program Files\Auto ~PC~ Speedup for {computername}"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
Inno Setup: Setup Version = "5.5.8 (u)"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
Inno Setup: App Path = "%System Root%\Program Files\Auto ~PC~ Speedup for {computername}"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
InstallLocation = "%System Root%\Program Files\Auto ~PC~ Speedup for {computername}"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
Inno Setup: Icon Group = "Auto ~PC~ Speedup for {computername}"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
Inno Setup: User = "{username}"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
Inno Setup: Language = "en"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
DisplayName = "Auto ~PC~ Speedup"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
DisplayIcon = "%System Root%\Program Files\Auto ~PC~ Speedup for {computername}\iytr.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
UninstallString = "%System Root%\Program Files\Auto ~PC~ Speedup for {computername}\unins000.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
QuietUninstallString = "{random characters}"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
DisplayVersion = "1.0.0.1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
NoModify = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
NoRepair = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
InstallDate = "20190825"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
MajorVersion = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
MinorVersion = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
EstimatedSize = "18182"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
paramurl = "http://trkr.{BLOCKED}iv.com/ipfiles"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
plurl = "http://pp.{BLOCKED}iv.com/ProductPrice.svc"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
buybowinapp = "http://store.{BLOCKED}ysutils.net/aups/plan?"
HKEY_CURRENT_USER\Software\Auto ~PC~ Speedup For {computername}
InstallString = "%System Root%\Program Files\Auto ~PC~ Speedup for {computername}"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
InstallString = "%System Root%\Program Files\Auto ~PC~ Speedup for {computername}"
HKEY_CURRENT_USER\Software\Auto ~PC~ Speedup For {computername}
LangCode = "en"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
LangCode = "en"
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
utm_source = ""
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
utm_campaign = ""
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
pxl = ""
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
utm_pubid = ""
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
LangCode = "en"
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
x-plt = ""
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
x-var1 = ""
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
lpid = ""
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
btnid = ""
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
x-var2 = ""
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
x-var3 = ""
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
referUrl = ""
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
afterInstallUrl = "http://ins1.{BLOCKED}iv.com/install/aups/?"
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
country = ""
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
TELNO = ""
HKEY_LOCAL_MACHINE\SOFTWARE\QXV0byB+UEN+IFNwZWVkdXA=\
ACT
data = "{random characters}"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
reg = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
expired = "0"
マルウェアは、以下のレジストリキーを削除します。
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run\
Auto ~PC~ Speedup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run\
Auto ~PC~ Speedup
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run\
Auto ~PC~ Speedup_logon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run\
Auto ~PC~ Speedup_logon
作成活動
マルウェアは、以下のファイルを作成します。
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\gmtrs.dll
- %All Users Profile%\Auto ~PC~ Speedup for {computername}\is-RTMFV.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\iytr.exe
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\x86\is-FA79V.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-QV92R.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\english_iss.ini
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\russian_iss.ini
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-8NEFO.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-RQVOD.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-5OV4I.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-8N7PL.tmp
- %All Users Profile%\Auto ~PC~ Speedup for {computername}\is-2I88B.tmp
- %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Auto ~PC~ Speedup for {computername}\Auto ~PC~ Speedup.lnk
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\TAFactory.IconPack.dll
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-B6B1F.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\x64\SQLite.Interop.dll
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-PSM4K.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-T85L5.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\norwegian_iss.ini
- %Application Data%\Auto ~PC~ Speedup For {computername}\smico\lizv0p05.png
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\x64\is-4SV5D.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\Newtonsoft.Json.dll
- %Application Data%\Auto ~PC~ Speedup For {computername}\Errorlog.txt
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-O32PU.tmp
- %All Users Profile%\Auto ~PC~ Speedup for {computername}\mdb.db
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-6TCQ3.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-UIRCB.tmp
- %All Users Profile%\Auto ~PC~ Speedup for {computername}\pcspstartrepair_en.mp3
- %User Temp%\is-SPD91.tmp\_isetup\_iscrypt.dll
- %Application Data%\Auto ~PC~ Speedup For {computername}\smico\4giql2n3.png
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\NAudio.dll
- %System Root%\Users\Public\Desktop\Auto ~PC~ Speedup.lnk
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\HtmlRenderer.dll
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-F8SK3.tmp
- %User Temp%\is-SPD91.tmp\setup_en.bmp
- %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Auto ~PC~ Speedup for {computername}\Buy Auto ~PC~ Speedup.lnk
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\finish_iss.ini
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-A1250.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\application.ico
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\iytr.exe.config
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-24VD6.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-S6TPB.tmp
- %AppDataLocal%\GDIPFONTCACHEV1.DAT
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\unins000.msg
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-FEUNA.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\Dutch_iss.ini
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\x86\SQLite.Interop.dll
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-R45J7.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\unins000.dat
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\italian_iss.ini
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\System.Data.SQLite.DLL
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\portuguese_iss.ini
- %Application Data%\Auto ~PC~ Speedup For {computername}\smico\xfh5e31d.png
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\langs.db
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-RIEOB.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\swedish_iss.ini
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\HtmlRenderer.WinForms.dll
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\unins000.exe
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-O9IBO.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\French_iss.ini
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\german_iss.ini
- %User Temp%\is-SPD91.tmp\_isetup\_shfoldr.dll
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\danish_iss.ini
- %Application Data%\Auto ~PC~ Speedup For {computername}\smico\m2ncwu1n.png
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-H083J.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\spanish_iss.ini
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-AFNA6.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-DH9O7.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-LE3IK.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\Interop.SHDocVw.dll
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-KQI40.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-ID1MG.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\japanese_iss.ini
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\Interop.IWshRuntimeLibrary.dll
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-VQNCO.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-TVS2T.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-F6L29.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-29M6V.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-45VLF.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\Microsoft.Win32.TaskScheduler.dll
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\PaddleCheckoutSDK.dll
- %Application Data%\Auto ~PC~ Speedup For {computername}\smico\lgia1tta.png
- %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Auto ~PC~ Speedup for {computername}\Uninstall Auto ~PC~ Speedup.lnk
(註:%System Root%フォルダは、オペレーティングシステム(OS)が存在する場所で、いずれのOSでも通常、 "C:" です。.. %All Users Profile%フォルダは、ユーザの共通プロファイルフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\All Users” です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\ProgramData” です。. %Application Data%フォルダは、現在ログオンしているユーザのアプリケーションデータフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>\Local Settings\Application Data" です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Roaming" です。. %User Temp%フォルダは、現在ログオンしているユーザの一時フォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザー名>\Local Settings\Temp"です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local\Temp" です。. %AppDataLocal%フォルダは、ローカルアプリケーションデータフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>\Local Settings\Application Data" です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local" です。)
その他
マルウェアは、以下の不正なWebサイトにアクセスします。
- http://cc.{BLOCKED}iv.com/productprice.svc/getcountrycode
このウイルス情報は、自動解析システムにより作成されました。
対応方法
手順 1
Windows XP、Windows Vista および Windows 7 のユーザは、コンピュータからマルウェアもしくはアドウェア等を完全に削除するために、ウイルス検索の実行前には必ず「システムの復元」を無効にしてください。
手順 2
「PUA.Win32.AutoPCSpeedup.F」で検出したファイル名を確認し、そのファイルを終了します。
- すべての実行中プロセスが、Windows のタスクマネージャに表示されない場合があります。この場合、"Process Explorer" などのツールを使用しマルウェアのファイルを終了してください。"Process Explorer" については、こちらをご参照下さい。
- 検出ファイルが、Windows のタスクマネージャまたは "Process Explorer" に表示されるものの、削除できない場合があります。この場合、コンピュータをセーフモードで再起動してください。
セーフモードについては、こちらをご参照下さい。 - 検出ファイルがタスクマネージャ上で表示されない場合、次の手順にお進みください。
手順 3
このレジストリ値を削除します。
警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。
- In HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
- Owner = "\xec\x05\x00\x00J\xeaR{#[\xd5\x01"
- In HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
- SessionHash = "{random characters}"
- In HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
- Sequence = "1"
- In HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
- RegFiles0000 = "\x00\x00\x00gP\xef\xac\xbbM\xe5\x90\x90\xea\x80\x80\x05\xe1\x80\x80t\xe4\xb3\xa7"
- In HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
- RegFilesHash = "{random characters}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- TELNO = "(855)-332-0124"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- ISTELNO = "1"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- apst = "0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- isshowng = "1"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- issilent = "0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- affired = "0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- showwfo = "0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- ovoffdis = "0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- playsound = "1"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- wfoset = "1"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- country = ""
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- ipaddrurl = "http://www.{BLOCKED}iv.com/getip"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- prereg = "0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- showtn = "0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- cbkpoff = "1"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- cta = "0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- showunins = "0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- delaytime = "0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- isiunidu = "1"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- isavst = "0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- isprmjsn = "0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- runcam = "1"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- runsrc = "1"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- runpixel = "1"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- stdismax = "4294967295"
- In HKEY_CURRENT_USER\Software\Auto ~PC~ Speedup For {computername}
- utm_medium = ""
- In HKEY_CURRENT_USER\Software\Auto ~PC~ Speedup For {computername}
- affiliateid = ""
- In HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
- utm_source = "msmsite"
- In HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
- utm_campaign = "msmsite"
- In HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
- utm_medium = ""
- In HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
- affiliateid = ""
- In HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
- pxl = "msmsite"
- In HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
- x-at = ""
- In HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
- x-context = ""
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- TELNO_us = "(855)-332-0124"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- TELNO_uk = "0800-031-5066"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- TELNO_gb = "0800-031-5066"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- TELNO_au = "(61)280-733403"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- TELNO_fr = "05 82 84 04 06"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- TELNO_de = "0800 1822 974"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- TELNO_at = "+43 (0)720 902 309"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- TELNO_ch = "+41 (0)44 508 70 37"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- TELNO_lu = "0800 1822 974"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- TELNO_no = "+47 21 95 01 97"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- TELNO_dk = "+45 78 73 09 26"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- TELNO_nl = "+31-08-58882839"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- TELNO_be = "+32-28085306"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- TELNO_se = "+46-08124-10298"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- TELNO_ja = ""
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- TELNO_br = "+55 21 2391 4319"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- TELNO_it = "+39 069 4802886"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- TELNO_es = "+34 951 203 537"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- TELNO_ar = "+54 11 5236 0324"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- TELNO_fi = "+358 (0)9 4270 4911"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- TELNO_pt = "+351 70 750 2094"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- pdtm = "30"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- PurchaseURL = "https://store.{BLOCKED}ysutils.net/aups/price?"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- RenewURL = "https://store.{BLOCKED}ysutils.net/aups/renewal?"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- WebURL = "https://www.{BLOCKED}ysutils.net"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- EmailURL = ""
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- supporturl = "http://www.{BLOCKED}ysutils.net/help"
- In HKEY_CURRENT_USER\Software\Auto ~PC~ Speedup For {computername}\1.0.0.1
- Installstring = "%System Root%\Program Files\Auto ~PC~ Speedup for {computername}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- Installstring = "%System Root%\Program Files\Auto ~PC~ Speedup for {computername}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
- Inno Setup: Setup Version = "5.5.8 (u)"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
- Inno Setup: App Path = "%System Root%\Program Files\Auto ~PC~ Speedup for {computername}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
- InstallLocation = "%System Root%\Program Files\Auto ~PC~ Speedup for {computername}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
- Inno Setup: Icon Group = "Auto ~PC~ Speedup for {computername}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
- Inno Setup: User = "{username}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
- Inno Setup: Language = "en"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
- DisplayName = "Auto ~PC~ Speedup"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
- DisplayIcon = "%System Root%\Program Files\Auto ~PC~ Speedup for {computername}\iytr.exe"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
- UninstallString = "%System Root%\Program Files\Auto ~PC~ Speedup for {computername}\unins000.exe"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
- QuietUninstallString = "{random characters}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
- DisplayVersion = "1.0.0.1"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
- NoModify = "1"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
- NoRepair = "1"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
- InstallDate = "20190825"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
- MajorVersion = "1"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
- MinorVersion = "0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F1F3B9F1-371B-4434-8C3B-90ADE9D6CFB6}_is1
- EstimatedSize = "18182"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- paramurl = "http://trkr.{BLOCKED}iv.com/ipfiles"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- plurl = "http://pp.{BLOCKED}iv.com/ProductPrice.svc"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- buybowinapp = "http://store.{BLOCKED}ysutils.net/aups/plan?"
- In HKEY_CURRENT_USER\Software\Auto ~PC~ Speedup For {computername}
- InstallString = "%System Root%\Program Files\Auto ~PC~ Speedup for {computername}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- InstallString = "%System Root%\Program Files\Auto ~PC~ Speedup for {computername}"
- In HKEY_CURRENT_USER\Software\Auto ~PC~ Speedup For {computername}
- LangCode = "en"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- LangCode = "en"
- In HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
- utm_source = ""
- In HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
- utm_campaign = ""
- In HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
- pxl = ""
- In HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
- utm_pubid = ""
- In HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
- LangCode = "en"
- In HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
- x-plt = ""
- In HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
- x-var1 = ""
- In HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
- lpid = ""
- In HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
- btnid = ""
- In HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
- x-var2 = ""
- In HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
- x-var3 = ""
- In HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
- referUrl = ""
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- afterInstallUrl = "http://ins1.{BLOCKED}iv.com/install/aups/?"
- In HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
- country = ""
- In HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
- TELNO = ""
- In HKEY_LOCAL_MACHINE\SOFTWARE\QXV0byB+UEN+IFNwZWVkdXA=\ACT
- data = "{random characters}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- reg = "0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Auto ~PC~ Speedup For {computername}
- expired = "0"
手順 4
以下のファイルを検索し削除します。
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\gmtrs.dll
- %All Users Profile%\Auto ~PC~ Speedup for {computername}\is-RTMFV.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\iytr.exe
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\x86\is-FA79V.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-QV92R.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\english_iss.ini
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\russian_iss.ini
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-8NEFO.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-RQVOD.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-5OV4I.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-8N7PL.tmp
- %All Users Profile%\Auto ~PC~ Speedup for {computername}\is-2I88B.tmp
- %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Auto ~PC~ Speedup for {computername}\Auto ~PC~ Speedup.lnk
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\TAFactory.IconPack.dll
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-B6B1F.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\x64\SQLite.Interop.dll
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-PSM4K.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-T85L5.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\norwegian_iss.ini
- %Application Data%\Auto ~PC~ Speedup For {computername}\smico\lizv0p05.png
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\x64\is-4SV5D.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\Newtonsoft.Json.dll
- %Application Data%\Auto ~PC~ Speedup For {computername}\Errorlog.txt
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-O32PU.tmp
- %All Users Profile%\Auto ~PC~ Speedup for {computername}\mdb.db
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-6TCQ3.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-UIRCB.tmp
- %All Users Profile%\Auto ~PC~ Speedup for {computername}\pcspstartrepair_en.mp3
- %User Temp%\is-SPD91.tmp\_isetup\_iscrypt.dll
- %Application Data%\Auto ~PC~ Speedup For {computername}\smico\4giql2n3.png
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\NAudio.dll
- %System Root%\Users\Public\Desktop\Auto ~PC~ Speedup.lnk
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\HtmlRenderer.dll
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-F8SK3.tmp
- %User Temp%\is-SPD91.tmp\setup_en.bmp
- %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Auto ~PC~ Speedup for {computername}\Buy Auto ~PC~ Speedup.lnk
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\finish_iss.ini
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-A1250.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\application.ico
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\iytr.exe.config
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-24VD6.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-S6TPB.tmp
- %AppDataLocal%\GDIPFONTCACHEV1.DAT
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\unins000.msg
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-FEUNA.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\Dutch_iss.ini
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\x86\SQLite.Interop.dll
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-R45J7.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\unins000.dat
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\italian_iss.ini
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\System.Data.SQLite.DLL
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\portuguese_iss.ini
- %Application Data%\Auto ~PC~ Speedup For {computername}\smico\xfh5e31d.png
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\langs.db
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-RIEOB.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\swedish_iss.ini
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\HtmlRenderer.WinForms.dll
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\unins000.exe
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-O9IBO.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\French_iss.ini
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\german_iss.ini
- %User Temp%\is-SPD91.tmp\_isetup\_shfoldr.dll
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\danish_iss.ini
- %Application Data%\Auto ~PC~ Speedup For {computername}\smico\m2ncwu1n.png
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-H083J.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\spanish_iss.ini
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-AFNA6.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-DH9O7.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-LE3IK.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\Interop.SHDocVw.dll
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-KQI40.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-ID1MG.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\japanese_iss.ini
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\Interop.IWshRuntimeLibrary.dll
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-VQNCO.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-TVS2T.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-F6L29.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-29M6V.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\is-45VLF.tmp
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\Microsoft.Win32.TaskScheduler.dll
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\PaddleCheckoutSDK.dll
- %Application Data%\Auto ~PC~ Speedup For {computername}\smico\lgia1tta.png
- %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Auto ~PC~ Speedup for {computername}\Uninstall Auto ~PC~ Speedup.lnk
手順 5
以下のフォルダを検索し削除します。
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\x64
- %Application Data%\Auto ~PC~ Speedup For {computername}
- %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Auto ~PC~ Speedup for {computername}
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}
- %User Temp%\is-SPD91.tmp\_isetup
- %System Root%\Program Files\Auto ~PC~ Speedup for {computername}\x86
- %All Users Profile%\Auto ~PC~ Speedup for {computername}
- %Application Data%\Auto ~PC~ Speedup For {computername}\smico
手順 6
最新のバージョン(エンジン、パターンファイル)を導入したウイルス対策製品を用い、ウイルス検索を実行してください。「PUA.Win32.AutoPCSpeedup.F」と検出したファイルはすべて削除してください。 検出されたファイルが、弊社ウイルス対策製品により既に駆除、隔離またはファイル削除の処理が実行された場合、ウイルスの処理は完了しており、他の削除手順は特にありません。
手順 7
以下のファイルをバックアップを用いて修復します。なお、マイクロソフト製品に関連したファイルのみ修復されます。このマルウェア/グレイウェア/スパイウェアが同社製品以外のプログラムをも削除した場合には、該当プログラムを再度インストールする必要があります。
- %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Auto ~PC~ Speedup for {computername}\Auto ~PC~ Speedup.url
- %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Auto ~PC~ Speedup for {computername}\Auto ~PC~ Speedup.pif
- %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Auto ~PC~ Speedup for {computername}\Buy Auto ~PC~ Speedup.pif
- %System Root%\Users\Public\Desktop\Auto ~PC~ Speedup.pif
- %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Auto ~PC~ Speedup for {computername}\Uninstall Auto ~PC~ Speedup.pif
- %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Auto ~PC~ Speedup for {computername}\Buy Auto ~PC~ Speedup.url
- %System Root%\Users\Public\Desktop\Auto ~PC~ Speedup.url
- %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Auto ~PC~ Speedup for {computername}\Uninstall Auto ~PC~ Speedup.url
手順 8
以下の削除されたレジストリキーまたはレジストリ値をバックアップを用いて修復します。
※註:マイクロソフト製品に関連したレジストリキーおよびレジストリ値のみが修復されます。このマルウェアもしくはアドウェア等が同社製品以外のプログラムも削除した場合には、該当プログラムを再度インストールする必要があります。
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
- Auto ~PC~ Speedup
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Auto ~PC~ Speedup
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
- Auto ~PC~ Speedup_logon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Auto ~PC~ Speedup_logon
ご利用はいかがでしたか? アンケートにご協力ください