PUA_CORNERSUNSHINE.GA
Adware.CornerSunshine (Symantec)
Windows
Tipo de malware
Potentially Unwanted Application
Destructivo?
No
Cifrado
No
In the Wild:
Sí
Resumen y descripción
Puede haberlo instalado manualmente un usuario.
Se conecta a determinados sitios Web para enviar y recibir información.
Detalles técnicos
Detalles de entrada
Puede haberlo instalado manualmente un usuario.
Instalación
Crea las carpetas siguientes:
- %Program Files%\Corner Sunshine\res
- %Program Files%\Corner Sunshine\res\picture
- %Program Files%\Corner Sunshine\res\picture\uninstall
- %Program Files%\Corner Sunshine\res\CN
- %Program Files%\Corner Sunshine\res\DE
- %Program Files%\Corner Sunshine\res\EN
- %Program Files%\Corner Sunshine\res\FR
(Nota: %Program Files% es la carpeta Archivos de programa predeterminada, que suele estar en C:\Archivos de programa).
)Otras modificaciones del sistema
Agrega las siguientes entradas de registro como parte de la rutina de instalación:
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\
Corner Sunshine
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
Corner Sunshine
HKEY_LOCAL_MACHINE\SOFTWARE\Corner Sunshine
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
services\CornerSunshineSvc
Agrega las siguientes entradas de registro:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
Corner Sunshine
DisplayName = "Corner Sunshine"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
Corner Sunshine
DisplayIcon = "%Program Files%\Corner Sunshine\CornerSunshineInst.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
Corner Sunshine
UninstallString = "%Program Files%\Corner Sunshine\CornerSunshineInst.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
Corner Sunshine
ProductVersion = "1.0.2"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
Corner Sunshine
InstallLocation = "%Program Files%\Corner Sunshine"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
Corner Sunshine
DisplayVersion = "1.0.2"
HKEY_LOCAL_MACHINE\SOFTWARE\Corner Sunshine
path = "%Program Files%\Corner Sunshine\"
HKEY_LOCAL_MACHINE\SOFTWARE\Corner Sunshine
channel = "official"
HKEY_LOCAL_MACHINE\SOFTWARE\Corner Sunshine
guid = "{GUID}"
HKEY_LOCAL_MACHINE\SOFTWARE\Corner Sunshine
wheref = "from-self"
HKEY_LOCAL_MACHINE\SOFTWARE\Corner Sunshine
InstTime = "{install time}"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
services\CornerSunshineSvc
Description = "The CornerSunshine service that aims to offer weather forcast "
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
services\CornerSunshineSvc
DisplayName = "CornerSunshineSvc"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
services\CornerSunshineSvc
ErrorControl = "1"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
services\CornerSunshineSvc
FailureActions = "{hex values}"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
services\CornerSunshineSvc
ImagePath = ""%Program Files%\Corner Sunshine\CornerSunshineSvc.exe" {UID}"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
services\CornerSunshineSvc
ObjectName = "LocalSystem"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
services\CornerSunshineSvc
Start = "2" (SERVICE_AUTO_START)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
services\CornerSunshineSvc
Type = "272"
Rutina de infiltración
Infiltra los archivos siguientes:
- %Program Files%\Corner Sunshine\CornerSunshine.exe
- %Program Files%\Corner Sunshine\CornerSunshineDll.dll
- %Program Files%\Corner Sunshine\CornerSunshineInst.exe
- %Program Files%\Corner Sunshine\CornerSunshineSvc.exe
- %Program Files%\Corner Sunshine\main
- %Program Files%\Corner Sunshine\res\CN\city_list_item.xml
- %Program Files%\Corner Sunshine\res\CN\UISkin1.xml
- %Program Files%\Corner Sunshine\res\CN\UISkin2.xml
- %Program Files%\Corner Sunshine\res\DE\city_list_item.xml
- %Program Files%\Corner Sunshine\res\DE\UISkin1.xml
- %Program Files%\Corner Sunshine\res\DE\UISkin2.xml
- %Program Files%\Corner Sunshine\res\EN\city_list_item.xml
- %Program Files%\Corner Sunshine\res\EN\UISkin1.xml
- %Program Files%\Corner Sunshine\res\EN\UISkin2.xml
- %Program Files%\Corner Sunshine\res\FR\city_list_item.xml
- %Program Files%\Corner Sunshine\res\FR\UISkin1.xml
- %Program Files%\Corner Sunshine\res\FR\UISkin2.xml
- %Program Files%\Corner Sunshine\res\picture\bg_main.png
- %Program Files%\Corner Sunshine\res\picture\bg_menu.png
- %Program Files%\Corner Sunshine\res\picture\bg_search.png
- %Program Files%\Corner Sunshine\res\picture\bg_user_guide.png
- %Program Files%\Corner Sunshine\res\picture\btn_cancel.png
- %Program Files%\Corner Sunshine\res\picture\btn_delete.png
- %Program Files%\Corner Sunshine\res\picture\btn_menu.png
- %Program Files%\Corner Sunchine\res\picture\btn_radio.png
- %Program Files%\Corner Sunchine\res\picture\clear.png
- %Program Files%\Corner Sunchine\res\picture\cloudy.png
- %Program Files%\Corner Sunchine\res\picture\cloudy_fg.png
- %Program Files%\Corner Sunchine\res\picture\fog.png
- %Program Files%\Corner Sunchine\res\picture\Humidity.png
- %Program Files%\Corner Sunchine\res\picture\icn_add.png
- %Program Files%\Corner Sunchine\res\picture\icn_fail.png
- %Program Files%\Corner Sunchine\res\picture\icn_info_grey.png
- %Program Files%\Corner Sunchine\res\picture\icn_location_gray.png
- %Program Files%\Corner Sunchine\res\picture\icn_precipitation.png
- %Program Files%\Corner Sunchine\res\picture\icn_success.png
- %Program Files%\Corner Sunchine\res\picture\icn_thermo.png
- %Program Files%\Corner Sunchine\res\picture\icn_units.png
- %Program Files%\Corner Sunchine\res\picture\Icon24_layout.png
- %Program Files%\Corner Sunchine\res\picture\Icon48_layout.png
- %Program Files%\Corner Sunchine\res\picture\img_degree.png
- %Program Files%\Corner Sunchine\res\picture\img_dot_normal.png
- %Program Files%\Corner Sunchine\res\picture\img_dot_selected.png
- %Program Files%\Corner Sunchine\res\picture\img_minus.png
- %Program Files%\Corner Sunchine\res\picture\img_num_0.png
- %Program Files%\Corner Sunchine\res\picture\img_num_1.png
- %Program Files%\Corner Sunchine\res\picture\img_num_2.png
- %Program Files%\Corner Sunchine\res\picture\img_num_3.png
- %Program Files%\Corner Sunchine\res\picture\img_num_4.png
- %Program Files%\Corner Sunchine\res\picture\img_num_5.png
- %Program Files%\Corner Sunchine\res\picture\img_num_6.png
- %Program Files%\Corner Sunchine\res\picture\img_num_7.png
- %Program Files%\Corner Sunchine\res\picture\img_num_8.png
- %Program Files%\Corner Sunchine\res\picture\img_num_9.png
- %Program Files%\Corner Sunchine\res\picture\overcast.png
- %Program Files%\Corner Sunchine\res\picture\rain.png
- %Program Files%\Corner Sunchine\res\picture\Refresh.png
- %Program Files%\Corner Sunchine\res\picture\scrollbar.png
- %Program Files%\Corner Sunchine\res\picture\sequence.png
- %Program Files%\Corner Sunchine\res\picture\snow.png
- %Program Files%\Corner Sunchine\res\picture\sunny.png
- %Program Files%\Corner Sunchine\res\picture\tstorm.png
- %Program Files%\Corner Sunchine\res\picture\windy.png
- %Program Files%\Corner Sunshine\res\picture\uninstall\bg.png
- %Program Files%\Corner Sunshine\res\picture\uninstall\btn.png
- %Program Files%\Corner Sunshine\res\picture\uninstall\button.png
- %Program Files%\Corner Sunshine\res\picture\uninstall\buttondown.png
- %Program Files%\Corner Sunshine\res\picture\uninstall\checkbox.png
- %Program Files%\Corner Sunshine\res\picture\uninstall\click.png
- %Program Files%\Corner Sunshine\res\picture\uninstall\close.png
- %Program Files%\Corner Sunshine\res\picture\uninstall\hover.png
- %Program Files%\Corner Sunshine\res\picture\uninstall\normal.png
- %Program Files%\Corner Sunshine\res\picture\uninstall\page1.png
- %Program Files%\Corner Sunshine\res\picture\uninstall\page2.png
- %Program Files%\Corner Sunshine\res\picture\uninstall\page3.png
- %Program Files%\Corner Sunshine\res\picture\uninstall\page4.png
- %Program Files%\Corner Sunshine\res\picture\uninstall\progress_back.png
- %Program Files%\Corner Sunshine\res\picture\uninstall\progress_fore.png
- %Program Files%\Corner Sunshine\res\picture\uninstall\uninstall.png
- %Program Files%\Corner Sunshine\res\picture\uninstall\uninstalldown.png
(Nota: %Program Files% es la carpeta Archivos de programa predeterminada, que suele estar en C:\Archivos de programa).
)Otros detalles
Se conecta al sitio Web siguiente para enviar y recibir información:
- http://deo74dnlruyj.{BLOCKED}ront.net/plg/up?qd=CornerSunshine&day=&qv=1.0.2&pd=official&lan=&qu={GUID}&os={OS version}&pi=&it={install time}
- http://d1x98kyej8b0kj.{BLOCKED}ront.net/v4/sunshine/{GUID}?action=cornersunshine.upgrade.checkstart
- http://api.{BLOCKED}sunshine.com/?key=autoip&lang={language}
- http://api.{BLOCKED}sunshine.com/?q=&lang=EN
- http://download.{BLOCKED}ch100.net/weather_animate/cloudy_E17E6047CF929E7EA4C815F67132B949.zip
- http://d1x98kyej8b0kj.{BLOCKED}ront.net/v4/sunshine/{GUID}?action=uninstall.cornersunshine.start
- http://d1x98kyej8b0kj.{BLOCKED}ront.net/v4/sunshine/{GUID}?action=install.cornersunshine.start
Soluciones
Step 1
Los usuarios de Windows ME y XP, antes de llevar a cabo cualquier exploración, deben comprobar que tienen desactivada la opción Restaurar sistema para permitir la exploración completa del equipo.
Step 3
Desactivar este servicio de malware
-
- CornerSunshineSvc
Step 4
Eliminar esta clave del Registro
Importante: si modifica el Registro de Windows incorrectamente, podría hacer que el sistema funcione mal de manera irreversible. Lleve a cabo este paso solo si sabe cómo hacerlo o si puede contar con ayuda de su administrador del sistema. De lo contrario, lea este artículo de Microsoft antes de modificar el Registro del equipo.
- In HKEY_LOCAL_MACHINE\SOFTWARE\Clients
- Corner Sunshine
- Corner Sunshine
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
- Corner Sunshine
- Corner Sunshine
- In HKEY_LOCAL_MACHINE\SOFTWARE
- Corner Sunshine
- Corner Sunshine
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services
- CornerSunshineSvc
- CornerSunshineSvc
Step 5
Buscar y eliminar estas carpetas
- %Program Files%\Corner Sunshine
Step 6
Explorar el equipo con su producto de Trend Micro para eliminar los archivos detectados como PUA_CORNERSUNSHINE.GA En caso de que el producto de Trend Micro ya haya limpiado, eliminado o puesto en cuarentena los archivos detectados, no serán necesarios más pasos. Puede optar simplemente por eliminar los archivos en cuarentena. Consulte esta página de Base de conocimientos para obtener más información.
Rellene nuestra encuesta!