TROJ_AGENT_037401.TOMB
Adware:Win32/GameVance (Microsoft); GameVance.gen.g. (McAfee); Gamevance LLC (v) (Sunbelt); Application:W32/GameVance.L (FSecure)
Windows 2000, Windows XP, Windows Server 2003

マルウェアタイプ:
トロイの木馬型
破壊活動の有無:
なし
暗号化:
感染報告の有無 :
はい
概要
マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。
詳細
侵入方法
マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。
インストール
マルウェアは、以下のフォルダを作成します。
- %Program Files%\Gamevance
- %User Profile%\Application Data\Mozilla
- %User Profile%\Mozilla\Extensions
- %User Profile%\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
- %User Profile%\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@gamevance.com
- %User Profile%\textlinks@gamevance.com\components
- %User Profile%\textlinks@gamevance.com\chrome
- %System Root%\DOCUME~1
- %System Root%\DOCUME~1\ADMINI~1
- %User Profile%\LOCALS~1
- %User Temp%\nsa2.tmp
- %Program Files%\Dogpile Bundle Toolbar
- %Program Files%\Dogpile Bundle Toolbar\images
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox
- %Program Files%\Dogpile Bundle Toolbar\images\ticker
- %Program Files%\Dogpile Bundle Toolbar\images\weather
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png
- %Program Files%\Dogpile Bundle Toolbar\skins
- %Program Files%\Dogpile Bundle Toolbar\skins\radio
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03
自動実行方法
マルウェアは、自身のコピーがWindows起動時に自動実行されるよう以下のレジストリ値を追加します。
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
Gamevance = "%Program Files%\Gamevance\gamevance32.exe a"
マルウェアは、以下のレジストリキーを追加し、自身をBrowser Helper Object(BHO)として登録します。これにより、Internet Explorer(IE)が起動するとマルウェアが自動実行されます。
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\
Browser Helper Objects\{0ED403E8-470A-4a8a-85A4-D7688CFE39A3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\
Browser Helper Objects\{beaC7DC8-E106-4C6A-931E-5A42E7362883}
他のシステム変更
マルウェアは、以下のファイルを削除します。
- %Program Files%\Gamevance\arsplg.dll
- %Desktop%\ArcadeRockstar.lnk
- %Application Data%\IconCache.db
- %User Temp%\nsk1.tmp
- %User Temp%\nsa2.tmp
- %User Temp%\nsa2.tmp\ns3.tmp
(註:%Program Files%フォルダは、Windows 2000、Server 2003、XP (32ビット)、通常 Vista (32ビット) および 7 (32ビット) の場合、通常 "C:\Program Files"、Windows XP (64ビット)、Vista (64ビット) および 7 (64ビット) の場合、通常 "C:\Program Files (x86)" です。. %Desktop%フォルダは、Windows 2000、XP および Server 2003 の場合、通常 "C:\Documents and Settings\<ユーザ名>\デスクトップ"、Windows Vista および 7 の場合、"C:\Users\<ユーザ名>\デスクトップ" です。. %Application Data%フォルダは、Windows 2000、XP および Server 2003 の場合、通常 "C:\Documents and Settings\<ユーザ名>\Local Settings\Application Data"、Windows Vista および 7 の場合、"C:\Users\<ユーザ名>\AppData\Roaming" です。. %User Temp%フォルダはWindowsの種類とインストール時の設定などにより異なります。標準設定では、Windows 2000、XP および Server 2003 の場合、"C:\Documents and Settings\<ユーザー名>\Local Settings\Temp"、Windows Vista および 7 の場合、"C:\Users\<ユーザ名>\AppData\Local\Temp" です。)
マルウェアは、以下のレジストリキーを追加します。
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Uninstall\
Gamevance
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\
Browser Helper Objects
HKEY_CLASSES_ROOT\CLSID\{0ED403E8-470A-4a8a-85A4-D7688CFE39A3}
HKEY_CLASSES_ROOT\CLSID\{0ED403E8-470A-4a8a-85A4-D7688CFE39A3}\
InprocServer32
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Uninstall\
Google Chrome
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Uninstall\
Google Chrome
HKEY_CURRENT_USER\Software\AppDataLow\
gvtl
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\
System\BIOS
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Ext\
Settings\{0ED403E8-470A-4a8a-85A4-D7688CFE39A3}
HKEY_CLASSES_ROOT\AppID\GamevanceText.DLL
HKEY_CLASSES_ROOT\GamevanceText.Linker.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GamevanceText.Linker.1\CLSID
HKEY_CLASSES_ROOT\GamevanceText.Linker
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GamevanceText.Linker\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GamevanceText.Linker\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{beaC7DC8-E106-4C6A-931E-5A42E7362883}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{beaC7DC8-E106-4C6A-931E-5A42E7362883}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{beaC7DC8-E106-4C6A-931E-5A42E7362883}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{beaC7DC8-E106-4C6A-931E-5A42E7362883}\Programmable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{beaC7DC8-E106-4C6A-931E-5A42E7362883}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{beaC7DC8-E106-4C6A-931E-5A42E7362883}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\FCTB000060231
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\International\CpMRU
マルウェアは、以下のレジストリ値を追加します。
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
Gamevance
DisplayName = "Gamevance"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
Gamevance
UninstallString = "%Program Files%\Gamevance\gvun.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
Gamevance
DisplayIcon = "%Program Files%\Gamevance\gvun.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\
Browser Helper Objects\{0ED403E8-470A-4a8a-85A4-D7688CFE39A3}
NoExplorer = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0ED403E8-470A-4a8a-85A4-D7688CFE39A3}\InprocServer32
ThreadingModel = "Apartment"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\GamevanceText.DLL
AppID = "{beaC7DC8-E106-4C6A-931E-5A42E7362883}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{beaC7DC8-E106-4C6A-931E-5A42E7362883}\InprocServer32
ThreadingModel = "Apartment"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\
Browser Helper Objects\{beaC7DC8-E106-4C6A-931E-5A42E7362883}
NoExplorer = "1"
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Main
Enable Browser Extensions = "yes"
HKEY_LOCAL_MACHINE\SOFTWARE\FCTB000060231
FirstLaunch = "0"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Services\SharedAccess\Parameters\
FirewallPolicy\StandardProfile\AuthorizedApplications\
List
%Program Files%\Dogpile Bundle Toolbar\TroubleShooter.exe = "{random characters}"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Services\SharedAccess\Parameters\
FirewallPolicy\StandardProfile\AuthorizedApplications\
List
%Program Files%\Dogpile Bundle Toolbar\ToolbarUpdate.exe = "{random characters}"
HKEY_CURRENT_USER\Software\AppDataLow\
gvtl
uid = "f02077db-a718-4786-afb7-68628b3404a0-XX"
HKEY_CURRENT_USER\Software\AppDataLow\
gvtl
cid = "0"
HKEY_CURRENT_USER\Software\AppDataLow\
gvtl
ct = "{random values}"
HKEY_CURRENT_USER\Software\AppDataLow\
gvtl
ci = "e1"
HKEY_CURRENT_USER\Software\AppDataLow\
gvtl
cid = "11d6a4"
HKEY_CURRENT_USER\Software\AppDataLow\
gvtl
sc1u = "{random characters}"
HKEY_CURRENT_USER\Software\AppDataLow\
gvtl
d = "0"
HKEY_CURRENT_USER\Software\AppDataLow\
gvtl
esint = "5"
HKEY_CURRENT_USER\Software\AppDataLow\
gvtl
domfqc = "1f4"
HKEY_CURRENT_USER\Software\AppDataLow\
gvtl
domfqt = "258"
HKEY_CURRENT_USER\Software\AppDataLow\
gvtl
sc2u = "http://tt.{BLOCKED}nce.com/acttr?v=0&a=OLDCLI&t=1"
HKEY_CURRENT_USER\Software\AppDataLow\
gvtl
nos2 = "1"
HKEY_CURRENT_USER\Software\AppDataLow\
gvtl
scr1 = "{random values}"
HKEY_CURRENT_USER\Software\AppDataLow\
gvtl
eu = "{random values}"
HKEY_CURRENT_USER\Software\AppDataLow\
gvtl
eus = "d8"
HKEY_CURRENT_USER\Software\AppDataLow\
gvtl
jss = "1"
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\International\CpMRU
Enable = "1"
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\International\CpMRU
Size = "a"
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\International\CpMRU
InitHits = "64"
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\International\CpMRU
Factor = "14"
マルウェアは、以下のレジストリ値を変更します。
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
DirectDraw\MostRecentApplication
Name = "iexplore.exe"
(註:変更前の上記レジストリ値は、「iexplore.exe」となります。)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
DirectDraw\MostRecentApplication
ID = "4117b81"
(註:変更前の上記レジストリ値は、「41107b81」となります。)
作成活動
マルウェアは、以下のファイルを作成します。
- %Program Files%\Gamevance\gamevancelib32.dll
- %Program Files%\Gamevance\gamevance32.exe
- %Program Files%\Gamevance\gvun.exe
- %Program Files%\Gamevance\ars.cfg
- %Program Files%\Gamevance\icon.ico
- %Program Files%\Gamevance\gvtl.dll
- %Program Files%\Gamevance\gvff.tmp
- %User Profile%\textlinks@gamevance.com\chrome.manifest
- %User Profile%\textlinks@gamevance.com\install.rdf
- %User Profile%\components\gvtlf.dll
- %User Profile%\components\gvtlf.xpt
- %User Profile%\chrome\gvtextlinks.jar
- %User Temp%\dplinst.exe
- %User Temp%\nsa2.tmp\UserInfo.dll
- %User Temp%\nsa2.tmp\options.ini
- %User Temp%\nsa2.tmp\gplunger.dll
- %User Temp%\nsa2.tmp\nsisFirewall.dll
- %User Temp%\nsa2.tmp\InetLoad.dll
- %User Temp%\nsa2.tmp\frtb_static_files.cab
- %User Temp%\nsa2.tmp\CABSetup.dll
- %Program Files%\Dogpile Bundle Toolbar\aboutTabs.7.js
- %Program Files%\Dogpile Bundle Toolbar\aboutTabs.8.js
- %Program Files%\Dogpile Bundle Toolbar\arrow.png
- %Program Files%\Dogpile Bundle Toolbar\audio.bmp
- %Program Files%\Dogpile Bundle Toolbar\banner_container.html
- %Program Files%\Dogpile Bundle Toolbar\bookmarksplugin.dll
- %Program Files%\Dogpile Bundle Toolbar\bookmark_off.bmp
- %Program Files%\Dogpile Bundle Toolbar\bookmark_on.bmp
- %Program Files%\Dogpile Bundle Toolbar\bubble_permissions.html
- %Program Files%\Dogpile Bundle Toolbar\caching_banner.html
- %Program Files%\Dogpile Bundle Toolbar\chevron.bmp
- %Program Files%\Dogpile Bundle Toolbar\component.xsl
- %Program Files%\Dogpile Bundle Toolbar\efolder.bmp
- %Program Files%\Dogpile Bundle Toolbar\email.bmp
- %Program Files%\Dogpile Bundle Toolbar\email2.bmp
- %Program Files%\Dogpile Bundle Toolbar\email3.bmp
- %Program Files%\Dogpile Bundle Toolbar\emailchecker_plugin.dll
- %Program Files%\Dogpile Bundle Toolbar\facebook.feature
- %Program Files%\Dogpile Bundle Toolbar\fbrss.xsl
- %Program Files%\Dogpile Bundle Toolbar\FixToolbar1163.bat
- %Program Files%\Dogpile Bundle Toolbar\folder.bmp
- %Program Files%\Dogpile Bundle Toolbar\iefavelem.bmp
- %Program Files%\Dogpile Bundle Toolbar\location.xsl
- %Program Files%\Dogpile Bundle Toolbar\magglass.ico
- %Program Files%\Dogpile Bundle Toolbar\manage_bookmarks.html
- %Program Files%\Dogpile Bundle Toolbar\marquee.html
- %Program Files%\Dogpile Bundle Toolbar\marquee_permissions.html
- %Program Files%\Dogpile Bundle Toolbar\messaging.bmp
- %Program Files%\Dogpile Bundle Toolbar\minus.bmp
- %Program Files%\Dogpile Bundle Toolbar\msgboxplugin.dll
- %Program Files%\Dogpile Bundle Toolbar\msgbox_bubble.tmpl
- %Program Files%\Dogpile Bundle Toolbar\msgbox_openmsg.tmpl
- %Program Files%\Dogpile Bundle Toolbar\offline.html
- %Program Files%\Dogpile Bundle Toolbar\plus.bmp
- %Program Files%\Dogpile Bundle Toolbar\podcast.bmp
- %Program Files%\Dogpile Bundle Toolbar\podcast.xsl
- %Program Files%\Dogpile Bundle Toolbar\radio.bmp
- %Program Files%\Dogpile Bundle Toolbar\RadioPlugin.dll
- %Program Files%\Dogpile Bundle Toolbar\resize.bmp
- %Program Files%\Dogpile Bundle Toolbar\rssfeed.bmp
- %Program Files%\Dogpile Bundle Toolbar\RSSReader_plugin.dll
- %Program Files%\Dogpile Bundle Toolbar\search.xsl
- %Program Files%\Dogpile Bundle Toolbar\SearchComponent.dll
- %Program Files%\Dogpile Bundle Toolbar\star_on.gif
- %Program Files%\Dogpile Bundle Toolbar\update_progress.html
- %Program Files%\Dogpile Bundle Toolbar\version.xsl
- %Program Files%\Dogpile Bundle Toolbar\weatherplugin.dll
- %Program Files%\Dogpile Bundle Toolbar\weather_bubble.tmpl
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\down.gif
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\hr.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\mark.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\mark_do.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\mark_na.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\navbg.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\refresh.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\refresh_do.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\refresh_na.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\trash.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\trash_do.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\trash_na.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\unmark.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\unmark_do.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\unmark_na.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\up.gif
- %Program Files%\Dogpile Bundle Toolbar\images\ticker\left.gif
- %Program Files%\Dogpile Bundle Toolbar\images\ticker\right.gif
- %Program Files%\Dogpile Bundle Toolbar\images\weather\0.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\1.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\10.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\11.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\12.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\13.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\14.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\15.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\16.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\17.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\18.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\19.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\2.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\20.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\21.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\22.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\23.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\24.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\25.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\26.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\27.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\28.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\29.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\3.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\30.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\31.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\32.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\33.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\34.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\35.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\36.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\37.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\38.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\39.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\4.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\40.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\41.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\42.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\43.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\44.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\45.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\46.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\47.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\5.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\6.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\7.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\8.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\9.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\hr.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\na.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\0.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\1.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\10.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\11.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\12.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\13.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\14.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\15.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\16.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\17.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\18.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\19.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\2.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\20.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\21.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\22.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\23.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\24.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\25.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\26.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\27.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\28.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\29.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\3.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\30.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\31.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\32.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\33.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\34.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\35.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\36.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\37.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\38.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\39.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\4.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\40.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\41.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\42.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\43.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\44.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\45.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\46.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\47.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\5.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\6.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\7.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\8.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\9.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\na.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\Thumbs.db
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_dropdwn_down.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_dropdwn_over.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_dropdwn_up.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_max_down.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_max_over.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_max_up.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_min_down.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_min_over.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_min_up.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_pause_down.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_pause_over.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_pause_up.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_playcntrl_over.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_playcntrl_up.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_play_down.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_play_over.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_play_up.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_stop_down.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_stop_over.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_stop_up.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_volcntrl_over.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_volcntrl_up.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\Equalizer1.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\Equalizer2.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\Equalizer3.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\Equalizer4.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\Equalizer5.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\Equalizer6.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\playcntrl_bg.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\radio.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\radio_mask.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\radio_minimalized.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\radio_minimalized_mask.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\station.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\volslide_bg.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\volslide_track.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\vol_01.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\vol_02.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\vol_03.bmp
- %Program Files%\Dogpile Bundle Toolbar\gedit.exe
- %Program Files%\Dogpile Bundle Toolbar\Helper.dll
- %Program Files%\Dogpile Bundle Toolbar\Toolbar.dll
- %Program Files%\Dogpile Bundle Toolbar\ff.xsl
- %Program Files%\Dogpile Bundle Toolbar\build
- %Program Files%\Dogpile Bundle Toolbar\TroubleShooter.exe
- %Program Files%\Dogpile Bundle Toolbar\version.txt
- %Program Files%\Dogpile Bundle Toolbar\default.xml
- %Program Files%\Dogpile Bundle Toolbar\icons.bmp
- %Program Files%\Dogpile Bundle Toolbar\localization.xml
- %Program Files%\Dogpile Bundle Toolbar\patch.bat
- %Program Files%\Dogpile Bundle Toolbar\settings
- %Program Files%\Dogpile Bundle Toolbar\ticker.html
- %Program Files%\Dogpile Bundle Toolbar\images\amazon.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\ebay.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\email.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\email2.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\wikipedia.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\yahoo.bmp
- %Program Files%\Dogpile Bundle Toolbar\ToolbarUpdate.exe
- %User Temp%\nsa2.tmp\nsExec.dll
- %User Temp%\nsa2.tmp\textreplace.dll
- %User Temp%\nsa2.tmp\ns3.tmp
その他
マルウェアは、以下の不正なWebサイトにアクセスします。
- http://www.{BLOCKED}nce.com/aj/inst.php?{random characters}
- http://af.{BLOCKED}{BLOCKED}.facdn.com/{BLOCKED}{BLOCKED}/download/dogpiletoolbar/Dogpile_Toolbar.exe
- http://www.{BLOCKED}nce.com/aj/bund.php?{random characters}
- http://update.{BLOCKED}nce.com/m/updcnt.asp?{random characters}
- http://cf.{BLOCKED}nce.com/m/elist.asp?grsl=167&grsid=16897700&snum=0
- http://tt.{BLOCKED}nce.com/bar/{BLOCKED}nce.bmp
- http://update.{BLOCKED}nce.com/frtb_static_files.cab
- http://update.{BLOCKED}nce.com/config.php?{random characters}
- http://update.{BLOCKED}nce.com/cmn?{random characters}
- http://update.{BLOCKED}nce.com/eurls.php
このウイルス情報は、自動解析システムにより作成されました。
対応方法
手順 1
Windows XP、Windows Vista および Windows 7 のユーザは、コンピュータからマルウェアもしくはアドウェア等を完全に削除するために、ウイルス検索の実行前には必ず「システムの復元」を無効にしてください。
手順 2
Windowsをセーフモードで再起動します。
手順 3
起動中ブラウザのウインドウを全て閉じてください。
手順 4
このレジストリキーを削除します。
警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。
- In HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall
- Gamevance
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
- Browser Helper Objects
- In HKEY_CLASSES_ROOT\CLSID
- {0ED403E8-470A-4a8a-85A4-D7688CFE39A3}
- In HKEY_CLASSES_ROOT\CLSID\{0ED403E8-470A-4a8a-85A4-D7688CFE39A3}
- InprocServer32
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall
- Google Chrome
- In HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall
- Google Chrome
- In HKEY_CURRENT_USER\Software\AppDataLow
- gvtl
- In HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System
- BIOS
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings
- {0ED403E8-470A-4a8a-85A4-D7688CFE39A3}
- In HKEY_CLASSES_ROOT\AppID
- GamevanceText.DLL
- In HKEY_CLASSES_ROOT
- GamevanceText.Linker.1
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GamevanceText.Linker.1
- CLSID
- In HKEY_CLASSES_ROOT
- GamevanceText.Linker
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GamevanceText.Linker
- CLSID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GamevanceText.Linker
- CurVer
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
- {beaC7DC8-E106-4C6A-931E-5A42E7362883}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{beaC7DC8-E106-4C6A-931E-5A42E7362883}
- ProgID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{beaC7DC8-E106-4C6A-931E-5A42E7362883}
- VersionIndependentProgID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{beaC7DC8-E106-4C6A-931E-5A42E7362883}
- Programmable
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{beaC7DC8-E106-4C6A-931E-5A42E7362883}
- InprocServer32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{beaC7DC8-E106-4C6A-931E-5A42E7362883}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE
- FCTB000060231
- In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International
- CpMRU
手順 5
このレジストリ値を削除します。
警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Gamevance = "%Program Files%\Gamevance\gamevance32.exe a"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gamevance
- DisplayName = "Gamevance"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gamevance
- UninstallString = "%Program Files%\Gamevance\gvun.exe"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gamevance
- DisplayIcon = "%Program Files%\Gamevance\gvun.exe"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0ED403E8-470A-4a8a-85A4-D7688CFE39A3}
- NoExplorer = "1"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ED403E8-470A-4a8a-85A4-D7688CFE39A3}\InprocServer32
- ThreadingModel = "Apartment"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\GamevanceText.DLL
- AppID = "{beaC7DC8-E106-4C6A-931E-5A42E7362883}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{beaC7DC8-E106-4C6A-931E-5A42E7362883}\InprocServer32
- ThreadingModel = "Apartment"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{beaC7DC8-E106-4C6A-931E-5A42E7362883}
- NoExplorer = "1"
- In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
- Enable Browser Extensions = "yes"
- In HKEY_LOCAL_MACHINE\SOFTWARE\FCTB000060231
- FirstLaunch = "0"
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
- %Program Files%\Dogpile Bundle Toolbar\TroubleShooter.exe = "{random characters}"
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
- %Program Files%\Dogpile Bundle Toolbar\ToolbarUpdate.exe = "{random characters}"
- In HKEY_CURRENT_USER\Software\AppDataLow\gvtl
- uid = "f02077db-a718-4786-afb7-68628b3404a0-XX"
- In HKEY_CURRENT_USER\Software\AppDataLow\gvtl
- cid = "0"
- In HKEY_CURRENT_USER\Software\AppDataLow\gvtl
- ct = "{random values}"
- In HKEY_CURRENT_USER\Software\AppDataLow\gvtl
- ci = "e1"
- In HKEY_CURRENT_USER\Software\AppDataLow\gvtl
- cid = "11d6a4"
- In HKEY_CURRENT_USER\Software\AppDataLow\gvtl
- sc1u = "{random characters}"
- In HKEY_CURRENT_USER\Software\AppDataLow\gvtl
- d = "0"
- In HKEY_CURRENT_USER\Software\AppDataLow\gvtl
- esint = "5"
- In HKEY_CURRENT_USER\Software\AppDataLow\gvtl
- domfqc = "1f4"
- In HKEY_CURRENT_USER\Software\AppDataLow\gvtl
- domfqt = "258"
- In HKEY_CURRENT_USER\Software\AppDataLow\gvtl
- sc2u = "http://tt.{BLOCKED}nce.com/acttr?v=0&a=OLDCLI&t=1"
- In HKEY_CURRENT_USER\Software\AppDataLow\gvtl
- nos2 = "1"
- In HKEY_CURRENT_USER\Software\AppDataLow\gvtl
- scr1 = "{random values}"
- In HKEY_CURRENT_USER\Software\AppDataLow\gvtl
- eu = "{random values}"
- In HKEY_CURRENT_USER\Software\AppDataLow\gvtl
- eus = "d8"
- In HKEY_CURRENT_USER\Software\AppDataLow\gvtl
- jss = "1"
- In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\CpMRU
- Enable = "1"
- In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\CpMRU
- Size = "a"
- In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\CpMRU
- InitHits = "64"
- In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\CpMRU
- Factor = "14"
手順 6
変更されたレジストリ値を修正します。
警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
- From: Name = "iexplore.exe"
To: Name = ""iexplore.exe""
- From: Name = "iexplore.exe"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
- From: ID = "4117b81"
To: ID = ""41107b81""
- From: ID = "4117b81"
手順 7
以下のファイルを検索し削除します。
- %Program Files%\Gamevance\gamevancelib32.dll
- %Program Files%\Gamevance\gamevance32.exe
- %Program Files%\Gamevance\gvun.exe
- %Program Files%\Gamevance\ars.cfg
- %Program Files%\Gamevance\icon.ico
- %Program Files%\Gamevance\gvtl.dll
- %Program Files%\Gamevance\gvff.tmp
- %User Profile%\textlinks@gamevance.com\chrome.manifest
- %User Profile%\textlinks@gamevance.com\install.rdf
- %User Profile%\components\gvtlf.dll
- %User Profile%\components\gvtlf.xpt
- %User Profile%\chrome\gvtextlinks.jar
- %User Temp%\dplinst.exe
- %User Temp%\nsa2.tmp\UserInfo.dll
- %User Temp%\nsa2.tmp\options.ini
- %User Temp%\nsa2.tmp\gplunger.dll
- %User Temp%\nsa2.tmp\nsisFirewall.dll
- %User Temp%\nsa2.tmp\InetLoad.dll
- %User Temp%\nsa2.tmp\frtb_static_files.cab
- %User Temp%\nsa2.tmp\CABSetup.dll
- %Program Files%\Dogpile Bundle Toolbar\aboutTabs.7.js
- %Program Files%\Dogpile Bundle Toolbar\aboutTabs.8.js
- %Program Files%\Dogpile Bundle Toolbar\arrow.png
- %Program Files%\Dogpile Bundle Toolbar\audio.bmp
- %Program Files%\Dogpile Bundle Toolbar\banner_container.html
- %Program Files%\Dogpile Bundle Toolbar\bookmarksplugin.dll
- %Program Files%\Dogpile Bundle Toolbar\bookmark_off.bmp
- %Program Files%\Dogpile Bundle Toolbar\bookmark_on.bmp
- %Program Files%\Dogpile Bundle Toolbar\bubble_permissions.html
- %Program Files%\Dogpile Bundle Toolbar\caching_banner.html
- %Program Files%\Dogpile Bundle Toolbar\chevron.bmp
- %Program Files%\Dogpile Bundle Toolbar\component.xsl
- %Program Files%\Dogpile Bundle Toolbar\efolder.bmp
- %Program Files%\Dogpile Bundle Toolbar\email.bmp
- %Program Files%\Dogpile Bundle Toolbar\email2.bmp
- %Program Files%\Dogpile Bundle Toolbar\email3.bmp
- %Program Files%\Dogpile Bundle Toolbar\emailchecker_plugin.dll
- %Program Files%\Dogpile Bundle Toolbar\facebook.feature
- %Program Files%\Dogpile Bundle Toolbar\fbrss.xsl
- %Program Files%\Dogpile Bundle Toolbar\FixToolbar1163.bat
- %Program Files%\Dogpile Bundle Toolbar\folder.bmp
- %Program Files%\Dogpile Bundle Toolbar\iefavelem.bmp
- %Program Files%\Dogpile Bundle Toolbar\location.xsl
- %Program Files%\Dogpile Bundle Toolbar\magglass.ico
- %Program Files%\Dogpile Bundle Toolbar\manage_bookmarks.html
- %Program Files%\Dogpile Bundle Toolbar\marquee.html
- %Program Files%\Dogpile Bundle Toolbar\marquee_permissions.html
- %Program Files%\Dogpile Bundle Toolbar\messaging.bmp
- %Program Files%\Dogpile Bundle Toolbar\minus.bmp
- %Program Files%\Dogpile Bundle Toolbar\msgboxplugin.dll
- %Program Files%\Dogpile Bundle Toolbar\msgbox_bubble.tmpl
- %Program Files%\Dogpile Bundle Toolbar\msgbox_openmsg.tmpl
- %Program Files%\Dogpile Bundle Toolbar\offline.html
- %Program Files%\Dogpile Bundle Toolbar\plus.bmp
- %Program Files%\Dogpile Bundle Toolbar\podcast.bmp
- %Program Files%\Dogpile Bundle Toolbar\podcast.xsl
- %Program Files%\Dogpile Bundle Toolbar\radio.bmp
- %Program Files%\Dogpile Bundle Toolbar\RadioPlugin.dll
- %Program Files%\Dogpile Bundle Toolbar\resize.bmp
- %Program Files%\Dogpile Bundle Toolbar\rssfeed.bmp
- %Program Files%\Dogpile Bundle Toolbar\RSSReader_plugin.dll
- %Program Files%\Dogpile Bundle Toolbar\search.xsl
- %Program Files%\Dogpile Bundle Toolbar\SearchComponent.dll
- %Program Files%\Dogpile Bundle Toolbar\star_on.gif
- %Program Files%\Dogpile Bundle Toolbar\update_progress.html
- %Program Files%\Dogpile Bundle Toolbar\version.xsl
- %Program Files%\Dogpile Bundle Toolbar\weatherplugin.dll
- %Program Files%\Dogpile Bundle Toolbar\weather_bubble.tmpl
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\down.gif
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\hr.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\mark.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\mark_do.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\mark_na.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\navbg.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\refresh.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\refresh_do.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\refresh_na.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\trash.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\trash_do.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\trash_na.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\unmark.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\unmark_do.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\unmark_na.png
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox\up.gif
- %Program Files%\Dogpile Bundle Toolbar\images\ticker\left.gif
- %Program Files%\Dogpile Bundle Toolbar\images\ticker\right.gif
- %Program Files%\Dogpile Bundle Toolbar\images\weather\0.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\1.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\10.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\11.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\12.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\13.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\14.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\15.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\16.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\17.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\18.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\19.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\2.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\20.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\21.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\22.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\23.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\24.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\25.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\26.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\27.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\28.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\29.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\3.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\30.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\31.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\32.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\33.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\34.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\35.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\36.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\37.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\38.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\39.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\4.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\40.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\41.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\42.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\43.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\44.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\45.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\46.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\47.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\5.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\6.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\7.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\8.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\9.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\hr.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\na.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\0.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\1.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\10.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\11.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\12.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\13.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\14.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\15.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\16.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\17.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\18.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\19.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\2.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\20.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\21.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\22.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\23.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\24.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\25.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\26.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\27.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\28.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\29.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\3.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\30.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\31.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\32.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\33.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\34.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\35.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\36.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\37.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\38.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\39.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\4.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\40.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\41.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\42.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\43.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\44.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\45.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\46.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\47.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\5.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\6.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\7.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\8.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\9.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\na.png
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png\Thumbs.db
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_dropdwn_down.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_dropdwn_over.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_dropdwn_up.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_max_down.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_max_over.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_max_up.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_min_down.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_min_over.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_min_up.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_pause_down.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_pause_over.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_pause_up.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_playcntrl_over.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_playcntrl_up.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_play_down.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_play_over.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_play_up.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_stop_down.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_stop_over.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_stop_up.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_volcntrl_over.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\btn_volcntrl_up.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\Equalizer1.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\Equalizer2.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\Equalizer3.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\Equalizer4.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\Equalizer5.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\Equalizer6.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\playcntrl_bg.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\radio.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\radio_mask.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\radio_minimalized.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\radio_minimalized_mask.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\station.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\volslide_bg.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\volslide_track.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\vol_01.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\vol_02.bmp
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03\vol_03.bmp
- %Program Files%\Dogpile Bundle Toolbar\gedit.exe
- %Program Files%\Dogpile Bundle Toolbar\Helper.dll
- %Program Files%\Dogpile Bundle Toolbar\Toolbar.dll
- %Program Files%\Dogpile Bundle Toolbar\ff.xsl
- %Program Files%\Dogpile Bundle Toolbar\build
- %Program Files%\Dogpile Bundle Toolbar\TroubleShooter.exe
- %Program Files%\Dogpile Bundle Toolbar\version.txt
- %Program Files%\Dogpile Bundle Toolbar\default.xml
- %Program Files%\Dogpile Bundle Toolbar\icons.bmp
- %Program Files%\Dogpile Bundle Toolbar\localization.xml
- %Program Files%\Dogpile Bundle Toolbar\patch.bat
- %Program Files%\Dogpile Bundle Toolbar\settings
- %Program Files%\Dogpile Bundle Toolbar\ticker.html
- %Program Files%\Dogpile Bundle Toolbar\images\amazon.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\ebay.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\email.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\email2.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\wikipedia.bmp
- %Program Files%\Dogpile Bundle Toolbar\images\yahoo.bmp
- %Program Files%\Dogpile Bundle Toolbar\ToolbarUpdate.exe
- %User Temp%\nsa2.tmp\nsExec.dll
- %User Temp%\nsa2.tmp\textreplace.dll
- %User Temp%\nsa2.tmp\ns3.tmp
手順 8
以下のフォルダを検索し削除します。
- %Program Files%\Gamevance
- %User Profile%\Application Data\Mozilla
- %User Profile%\Mozilla\Extensions
- %User Profile%\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
- %User Profile%\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@gamevance.com
- %User Profile%\textlinks@gamevance.com\components
- %User Profile%\textlinks@gamevance.com\chrome
- %System Root%\DOCUME~1
- %System Root%\DOCUME~1\ADMINI~1
- %User Profile%\LOCALS~1
- %User Temp%\nsa2.tmp
- %Program Files%\Dogpile Bundle Toolbar
- %Program Files%\Dogpile Bundle Toolbar\images
- %Program Files%\Dogpile Bundle Toolbar\images\msgbox
- %Program Files%\Dogpile Bundle Toolbar\images\ticker
- %Program Files%\Dogpile Bundle Toolbar\images\weather
- %Program Files%\Dogpile Bundle Toolbar\images\weather\png
- %Program Files%\Dogpile Bundle Toolbar\skins
- %Program Files%\Dogpile Bundle Toolbar\skins\radio
- %Program Files%\Dogpile Bundle Toolbar\skins\radio\gray03
手順 9
コンピュータを通常モードで再起動し、最新のバージョン(エンジン、パターンファイル)を導入したウイルス対策製品を用い、「TROJ_AGENT_037401.TOMB」と検出したファイルの検索を実行してください。 検出されたファイルが、弊社ウイルス対策製品により既に駆除、隔離またはファイル削除の処理が実行された場合、ウイルスの処理は完了しており、他の削除手順は特にありません。
手順 10
以下のファイルをバックアップを用いて修復します。なお、マイクロソフト製品に関連したファイルのみ修復されます。このマルウェア/グレイウェア/スパイウェアが同社製品以外のプログラムをも削除した場合には、該当プログラムを再度インストールする必要があります。
- %Program Files%\Gamevance\arsplg.dll
- %Desktop%\ArcadeRockstar.lnk
- %Application Data%\IconCache.db
- %User Temp%\nsk1.tmp
- %User Temp%\nsa2.tmp
- %User Temp%\nsa2.tmp\ns3.tmp
ご利用はいかがでしたか? アンケートにご協力ください