Amonetize

Categoria: Adware e PUA Opzioni di protezione ora disponibili:12 mag 2013 07:08:39 (GMT)
Tipo: Unspecified PUA Ultimo aggiornamento:19 set 2014 05:52:59 (GMT)

Download Scaricate il nostro Virus Removal Tool: è gratis! - Scoprite le minacce che sono sfuggite al vostro antivirus

Examples of Amonetize include:

Example 1

File Information

Size
324K
SHA-1
00200228867be2b25cbda298b1df7b10cb9d0d35
MD5
771bf29b5c52b088bb3fd32d777a9ad0
CRC-32
f26f8af9
File type
application/x-ms-dos-executable
First seen
2014-06-03

Example 2

File Information

Size
330K
SHA-1
003b6f2c157463068a7a8ab9638380609b95c62e
MD5
95beb4e99d9248e5fd763957857c5b48
CRC-32
5564e3f6
File type
Windows executable
First seen
2013-11-24

Runtime Analysis

Registry Keys Created
  • HKCR\CLSID\{A6FEED89-3BCD-4D19-9DC2-3E613A80A2A4}\ProgID
    (Default)
    AmiBs.Installer.1
  • HKCR\CLSID\{A6FEED89-3BCD-4D19-9DC2-3E613A80A2A4}\VersionIndependentProgID
    (Default)
    AmiBs.Installer
  • HKCR\CLSID\{A6FEED89-3BCD-4D19-9DC2-3E613A80A2A4}\Version
    (Default)
    1.0
  • HKCR\CLSID\{A6FEED89-3BCD-4D19-9DC2-3E613A80A2A4}\TypeLib
    (Default)
    {1C1356DA-1E98-4810-A9F6-18D89BD1C0C0}
  • HKCR\TypeLib\{1C1356DA-1E98-4810-A9F6-18D89BD1C0C0}\1.0\FLAGS
    (Default)
  • HKCR\AmiBs.Installer\CurVer
    (Default)
    AmiBs.Installer.1
  • HKCR\CLSID\{A6FEED89-3BCD-4D19-9DC2-3E613A80A2A4}\LocalServer32
    ServerExecutable
    c:\test_item.exe
  • HKCR\TypeLib\{1C1356DA-1E98-4810-A9F6-18D89BD1C0C0}\1.0
    (Default)
    InstallerLib
  • HKLM\SOFTWARE\Microsoft\ESENT\Process\sample\DEBUG
    Trace Level
  • HKCR\TypeLib\{1C1356DA-1E98-4810-A9F6-18D89BD1C0C0}\1.0\HELPDIR
    (Default)
    c:
  • HKCR\AmiBs.Installer.1\CLSID
    (Default)
    {A6FEED89-3BCD-4D19-9DC2-3E613A80A2A4}
  • HKCR\TypeLib\{1C1356DA-1E98-4810-A9F6-18D89BD1C0C0}\1.0\0\win32
    (Default)
    c:\test_item.exe
  • HKCR\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}\TypeLib
    Version
    1.0
  • HKCR\CLSID\{A6FEED89-3BCD-4D19-9DC2-3E613A80A2A4}
    (Default)
    Installer Class
  • HKCR\AmiBs.Installer.1
    (Default)
    Installer Class
  • HKCR\AmiBs.Installer
    (Default)
    Installer Class
  • HKCR\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}\ProxyStubClsid32
    (Default)
    {00020424-0000-0000-C000-000000000046}
  • HKCR\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}\ProxyStubClsid
    (Default)
    {00020424-0000-0000-C000-000000000046}
  • HKCR\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}
    (Default)
    IBoot
HTTP Requests
  • http://www.keenondownload.com/FailedToInstall.php
DNS Requests
  • www.keenondownload.com

Example 3

File Information

Size
339K
SHA-1
003d88a4a37af8ca59533108dabbf04d7e0e93ef
MD5
472e8409ae09a28fc4b704787ec29ddc
CRC-32
f78a2ace
File type
Windows executable
First seen
2014-06-21

Runtime Analysis

Registry Keys Created
  • HKLM\SOFTWARE\Client
    i
    20140625165445
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\inethnfd
    NoRepair
    0x00000001
Processes Created
  • c:\docume~1\support\locals~1\temp\nsv4.tmp\ns5.tmp
  • c:\docume~1\support\locals~1\temp\nsv4.tmp\ns6.tmp
  • c:\docume~1\support\locals~1\temp\nsv4.tmp\ns7.tmp
  • c:\docume~1\support\locals~1\temp\nsv4.tmp\ns8.tmp
  • c:\windows\system32\installd.exe
  • c:\windows\system32\net.exe
  • c:\windows\system32\net1.exe
  • c:\windows\system32\nethtsrv.exe
  • c:\windows\system32\netupdsrv.exe

scarica Prova gratuita dei prodotti Sophos
Scarica subito