PUP.aircraft_instruments
*file
C\Program Files\aircraft_instruments\aircraft_instrumentsToolbarHelper.exe
C\Program Files\aircraft_instruments\UNWISE.EXE
*reg_key
HKCU\Software\AppDataLow\Software\aircraft_instruments
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9CA9AA5F-8D88-4CE7-88CA-994511ACA89E}
HKLM\SOFTWARE\aircraft_instruments
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\aircraft_instruments Toolbar
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9ca9aa5f-8d88-4ce7-88ca-994511aca89e}
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks | {9ca9aa5f-8d88-4ce7-88ca-994511aca89e}
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar | {9ca9aa5f-8d88-4ce7-88ca-994511aca89e}
HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks | {9ca9aa5f-8d88-4ce7-88ca-994511aca89e}
*reg_val
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main | Start Page , http://search.conduit.com/
http://search.conduit.com -> use start page URL
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes : DefaultScope , {afdbddaa-5d3f-42ee-b79c-185a7020515b}
{afdbddaa-5d3f-42ee-b79c-185a7020515b} -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} : google search suggestions
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes | DefaultScope , {afdbddaa-5d3f-42ee-b79c-185a7020515b}
{afdbddaa-5d3f-42ee-b79c-185a7020515b} -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} : google search suggestions
PUP.Ask Toolbar Chrome.exe
*file
C:\Program Files\Google\Chrome\Application\Ask Toolbar Chrome.exe
C:\Program Files\Google\Chrome\Application\Ask Toolbar Chrome.lnk
*reg_val
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Ask Toolbar Chrome
'PC tips > 멀웨어 정보' 카테고리의 다른 글
Adware.Search New Window (0) | 2021.04.12 |
---|---|
Adware.Go My Media (0) | 2021.04.12 |
trojan.ASRF (0) | 2021.04.10 |
PUP.RemoteAdmin (0) | 2021.04.09 |
Trojan.BitcoinMiner (0) | 2021.04.09 |