Amonetize

Categoria: Adware e PUA Opzioni di protezione ora disponibili:12 mag 2013 07.08.39 (GMT)
Tipo: Unspecified PUA Ultimo aggiornamento:01 apr 2014 14.41.11 (GMT)

Download Scaricate il nostro Virus Removal Tool: è gratis! - Scoprite le minacce che sono sfuggite al vostro antivirus

Examples of Amonetize include:

Example 1

File Information

Size
330K
SHA-1
003b6f2c157463068a7a8ab9638380609b95c62e
MD5
95beb4e99d9248e5fd763957857c5b48
CRC-32
5564e3f6
File type
Windows executable
First seen
2013-11-24

Runtime Analysis

Registry Keys Created
  • HKCR\CLSID\{A6FEED89-3BCD-4D19-9DC2-3E613A80A2A4}\Version
    (Default)
    1.0
  • HKCR\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}\ProxyStubClsid32
    (Default)
    {00020424-0000-0000-C000-000000000046}
  • HKCR\CLSID\{A6FEED89-3BCD-4D19-9DC2-3E613A80A2A4}
    (Default)
    Installer Class
  • HKCR\AmiBs.Installer
    (Default)
    Installer Class
  • HKCR\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}\ProxyStubClsid
    (Default)
    {00020424-0000-0000-C000-000000000046}
  • HKCR\AmiBs.Installer\CurVer
    (Default)
    AmiBs.Installer.1
  • HKLM\SOFTWARE\Microsoft\ESENT\Process\sample\DEBUG
    Trace Level
  • HKCR\TypeLib\{1C1356DA-1E98-4810-A9F6-18D89BD1C0C0}\1.0
    (Default)
    InstallerLib
  • HKCR\TypeLib\{1C1356DA-1E98-4810-A9F6-18D89BD1C0C0}\1.0\FLAGS
    (Default)
  • HKCR\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}\TypeLib
    Version
    1.0
  • HKCR\CLSID\{A6FEED89-3BCD-4D19-9DC2-3E613A80A2A4}\VersionIndependentProgID
    (Default)
    AmiBs.Installer
  • HKCR\AmiBs.Installer.1
    (Default)
    Installer Class
  • HKCR\TypeLib\{1C1356DA-1E98-4810-A9F6-18D89BD1C0C0}\1.0\0\win32
    (Default)
    c:\test_item.exe
  • HKCR\AmiBs.Installer.1\CLSID
    (Default)
    {A6FEED89-3BCD-4D19-9DC2-3E613A80A2A4}
  • HKCR\CLSID\{A6FEED89-3BCD-4D19-9DC2-3E613A80A2A4}\TypeLib
    (Default)
    {1C1356DA-1E98-4810-A9F6-18D89BD1C0C0}
  • HKCR\CLSID\{A6FEED89-3BCD-4D19-9DC2-3E613A80A2A4}\ProgID
    (Default)
    AmiBs.Installer.1
  • HKCR\TypeLib\{1C1356DA-1E98-4810-A9F6-18D89BD1C0C0}\1.0\HELPDIR
    (Default)
    c:
  • HKCR\CLSID\{A6FEED89-3BCD-4D19-9DC2-3E613A80A2A4}\LocalServer32
    ServerExecutable
    c:\test_item.exe
  • HKCR\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}
    (Default)
    IBoot
HTTP Requests
  • http://www.keenondownload.com/FailedToInstall.php
DNS Requests
  • www.keenondownload.com

Example 2

File Information

Size
145K
SHA-1
00bad3b988bd77ab9b94e1050c7f0c8b5a86cd48
MD5
81aa31f29f0b9ee35b96db101f700380
CRC-32
cbc725c2
File type
Windows executable
First seen
2014-02-24

Runtime Analysis

Registry Keys Created
  • HKCR\CLSID\{A6FEED89-3BCD-4D19-9DC2-3E613A80A2A4}\VersionIndependentProgID
    (Default)
    AmiBs.Installer
  • HKCR\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}\ProxyStubClsid
    (Default)
    {00020424-0000-0000-C000-000000000046}
  • HKLM\SOFTWARE\Microsoft\ESENT\Process\sample\DEBUG
    Trace Level
  • HKCR\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}\TypeLib
    Version
    1.0
  • HKCR\CLSID\{A6FEED89-3BCD-4D19-9DC2-3E613A80A2A4}\ProgID
    (Default)
    AmiBs.Installer.1
  • HKCR\AmiBs.Installer
    (Default)
    Installer Class
  • HKCR\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}\ProxyStubClsid32
    (Default)
    {00020424-0000-0000-C000-000000000046}
  • HKCR\TypeLib\{1C1356DA-1E98-4810-A9F6-18D89BD1C0C0}\1.0\0\win32
    (Default)
    c:\test_item.exe
  • HKCR\AmiBs.Installer\CurVer
    (Default)
    AmiBs.Installer.1
  • HKCR\CLSID\{A6FEED89-3BCD-4D19-9DC2-3E613A80A2A4}\LocalServer32
    ServerExecutable
    c:\test_item.exe
  • HKCR\TypeLib\{1C1356DA-1E98-4810-A9F6-18D89BD1C0C0}\1.0
    (Default)
    InstallerLib
  • HKCR\CLSID\{A6FEED89-3BCD-4D19-9DC2-3E613A80A2A4}\TypeLib
    (Default)
    {1C1356DA-1E98-4810-A9F6-18D89BD1C0C0}
  • HKCR\CLSID\{A6FEED89-3BCD-4D19-9DC2-3E613A80A2A4}\Version
    (Default)
    1.0
  • HKCR\TypeLib\{1C1356DA-1E98-4810-A9F6-18D89BD1C0C0}\1.0\HELPDIR
    (Default)
    c:
  • HKCR\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}
    (Default)
    IBoot
  • HKCR\AmiBs.Installer.1\CLSID
    (Default)
    {A6FEED89-3BCD-4D19-9DC2-3E613A80A2A4}
  • HKCR\AmiBs.Installer.1
    (Default)
    Installer Class
  • HKCR\TypeLib\{1C1356DA-1E98-4810-A9F6-18D89BD1C0C0}\1.0\FLAGS
    (Default)
  • HKCR\CLSID\{A6FEED89-3BCD-4D19-9DC2-3E613A80A2A4}
    (Default)
    Installer Class
Registry Keys Modified
  • HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
    Name
    test_item.exe
HTTP Requests
  • http://cdn1.anotherdownload.com/amipb.js
  • http://cdn2.anotherdownload.com/ad24aef5-99d8-4429-826b-14e665fb72c6/accept.gif
  • http://cdn2.anotherdownload.com/ad24aef5-99d8-4429-826b-14e665fb72c6/back.gif
  • http://cdn2.anotherdownload.com/ad24aef5-99d8-4429-826b-14e665fb72c6/cancel.gif
  • http://cdn2.anotherdownload.com/ad24aef5-99d8-4429-826b-14e665fb72c6/decline.gif
  • http://cdn2.anotherdownload.com/ad24aef5-99d8-4429-826b-14e665fb72c6/finish.gif
  • http://cdn2.anotherdownload.com/ad24aef5-99d8-4429-826b-14e665fb72c6/footer_img.png
  • http://cdn2.anotherdownload.com/ad24aef5-99d8-4429-826b-14e665fb72c6/install.gif
  • http://cdn2.anotherdownload.com/ad24aef5-99d8-4429-826b-14e665fb72c6/main.css
  • http://cdn2.anotherdownload.com/ad24aef5-99d8-4429-826b-14e665fb72c6/next.gif
  • http://cdn2.anotherdownload.com/ad24aef5-99d8-4429-826b-14e665fb72c6/skip.gif
DNS Requests
  • cdn1.anotherdownload.com
  • cdn2.anotherdownload.com
  • www.brainydownload.com

Example 3

File Information

Size
323K
SHA-1
00ea2be6f9f193cfc6145ca1e1dd7e4284bca296
MD5
6737f5c55cb30f6d8233e6ff3715e641
CRC-32
f6f90f67
File type
application/x-ms-dos-executable
First seen
2014-03-22

Runtime Analysis

Registry Keys Created
  • HKCR\XmBsa.Inst\CurVer
    (Default)
    XmBsa.Inst.1
  • HKCR\TypeLib\{83829839-609D-4F6E-8C12-6D4AA7127A57}\1.0\HELPDIR
    (Default)
    c:
  • HKCR\TypeLib\{83829839-609D-4F6E-8C12-6D4AA7127A57}\1.0\FLAGS
    (Default)
  • HKCR\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}\ProxyStubClsid
    (Default)
    {00020424-0000-0000-C000-000000000046}
  • HKCR\CLSID\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}
    (Default)
    Inst Class
  • HKLM\SOFTWARE\Microsoft\ESENT\Process\sample\DEBUG
    Trace Level
  • HKCR\XmBsa.Inst.1\CLSID
    (Default)
    {FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}
  • HKCR\TypeLib\{83829839-609D-4F6E-8C12-6D4AA7127A57}\1.0
    (Default)
    InstallerLib
  • HKCR\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}\ProxyStubClsid32
    (Default)
    {00020424-0000-0000-C000-000000000046}
  • HKCR\CLSID\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\Version
    (Default)
    1.0
  • HKCR\CLSID\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\VersionIndependentProgID
    (Default)
    XmBsa.Inst
  • HKCR\XmBsa.Inst
    (Default)
    Inst Class
  • HKCR\CLSID\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\LocalServer32
    ServerExecutable
    c:\test_item.exe
  • HKCR\TypeLib\{83829839-609D-4F6E-8C12-6D4AA7127A57}\1.0\0\win32
    (Default)
    c:\test_item.exe
  • HKCR\CLSID\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\ProgID
    (Default)
    XmBsa.Inst.1
  • HKCR\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}
    (Default)
    IBoot
  • HKCR\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}\TypeLib
    Version
    1.0
  • HKCR\CLSID\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\TypeLib
    (Default)
    {83829839-609D-4F6E-8C12-6D4AA7127A57}
  • HKCR\XmBsa.Inst.1
    (Default)
    Inst Class
DNS Requests
  • www.idyllicdownload.com

scarica Prova gratuita dei prodotti Sophos
Scarica subito