MultiPlug

Categoria: Adware e PUA Opzioni di protezione ora disponibili:28 feb 2014 23:59:11 (GMT)
Tipo: Adware Ultimo aggiornamento:03 lug 2015 14:52:36 (GMT)

Download Scaricate il nostro Virus Removal Tool: è gratis! - Scoprite le minacce che sono sfuggite al vostro antivirus

Examples of MultiPlug include:

Example 1

File Information

Size
1.2M
SHA-1
000021812b49d69a136fdd93fe215df11cdaa111
MD5
ccabf0e804965d42e20ca2b16c1c2a2d
CRC-32
6dda5a5d
File type
Windows executable
First seen
2014-12-31

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Local Settings\Temp\03ad83ba\temp\test_item.exe
Dropped Files
  • c:\Documents and Settings\test user\Local Settings\Temp\03ad83ba\temp\bg.ca
  • C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
  • c:\Documents and Settings\test user\Local Settings\Temp\03ad83ba\images\progressbar.gif
  • C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
  • c:\Documents and Settings\test user\Application Data\Microsoft\Protect\S-1-5-21-1202660629-1454471165-1275210071-1003\bc2a25fb-c392-478a-af77-d48a7c683e9c
  • c:\Documents and Settings\test user\Desktop\sample.lnk
  • c:\Documents and Settings\test user\Local Settings\Temp\03ad83ba\images\loader.gif
Modified Files
  • %PROFILE%\Application Data\Microsoft\Protect\S-1-5-21-1202660629-1454471165-1275210071-1003\Preferred
Registry Keys Created
  • HKCU_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}
    (Default)
    TinyJSObject Class
  • HKCU\Software\WebApp\Styles
    MaxScriptStatements
    0xffffffff
  • HKCU_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\LocalServer32
    ServerExecutable
    c:\test_item.exe
  • HKCU_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\Version
    (Default)
    1.0
  • HKCU\Software\Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\Version
    (Default)
    1.0
  • HKCU\Software\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}\ProxyStubClsid
    (Default)
    {00020424-0000-0000-C000-000000000046}
  • HKCU_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\TypeLib
    (Default)
    {7E77E9F2-D76B-4D54-B515-9A7F93DF03DF}
  • HKCU_Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}\TypeLib
    Version
    1.0
  • HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
    GlobalMaxTcpWindowSize
    0x00ffffff
  • HKCU\Software\Classes\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}\1.0
    (Default)
    JSIELib
  • HKCU\Software\Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\LocalServer32
    ServerExecutable
    c:\test_item.exe
  • HKCU_Classes\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}\1.0\HELPDIR
    (Default)
    c:
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS
    StateIndex
    0x00000001
  • HKLM\SYSTEM\CurrentControlSet\Control\BackupRestore\FilesNotToBackup
    BITS_metadata
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\*
  • HKCU_Classes\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}\1.0
    (Default)
    JSIELib
  • HKCU\Software\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}\ProxyStubClsid32
    (Default)
    {00020424-0000-0000-C000-000000000046}
  • HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\BITS
    ControlFlags
    0x00000001
  • HKCU\Software\Classes\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}\1.0\HELPDIR
    (Default)
    c:
  • HKCU\Software\Classes\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}\1.0\0\win32
    (Default)
    c:\test_item.exe
  • HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\BITS\CtlGuid
    BitNames
    LogFlagInfo LogFlagWarning LogFlagError LogFlagFunction LogFlagRefCount LogFlagSerialize LogFlagDownload LogFlagTask LogFlagLock LogFlagService LogFlagDataBytes LogFlagTransferDetails
  • HKCU\Software\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}
    (Default)
    ITinyJSObject
  • HKCU_Classes\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}\1.0\0\win32
    (Default)
    c:\test_item.exe
  • HKCU\Software\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}\TypeLib
    Version
    1.0
  • HKCU_Classes\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}\1.0\FLAGS
    (Default)
  • HKCU_Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}
    (Default)
    ITinyJSObject
  • HKCU\Software\Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}
    (Default)
    TinyJSObject Class
  • HKCU\Software\Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\TypeLib
    (Default)
    {7E77E9F2-D76B-4D54-B515-9A7F93DF03DF}
  • HKLM\SYSTEM\CurrentControlSet\Services\BITS\Enum
    NextInstance
    0x00000001
  • HKCU_Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}\ProxyStubClsid32
    (Default)
    {00020424-0000-0000-C000-000000000046}
  • HKCU_Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}\ProxyStubClsid
    (Default)
    {00020424-0000-0000-C000-000000000046}
  • HKCU\Software\Classes\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}\1.0\FLAGS
    (Default)
Registry Keys Modified
  • HKLM\SYSTEM\CurrentControlSet\Services\BITS
    Start
    0x00000002
HTTP Requests
  • http://c1.starvel.org/
  • http://c2.winnered.net/
DNS Requests
  • c1.starvel.org
  • c2.winnered.net
  • r1.profficing.org

Example 2

File Information

Size
704K
SHA-1
00003e3910362dd635470c2ecd8ff8f733a85a16
MD5
f797a822d7c6d379122db88cdbc673b4
CRC-32
0a996631
File type
Windows executable
First seen
2014-08-22

Runtime Analysis

Dropped Files
  • c:\Documents and Settings\test user\Local Settings\Temp\sho\images\progressbar.gif
  • c:\Documents and Settings\test user\Local Settings\Temp\sho\steps\2_0.ini
  • c:\Documents and Settings\test user\Local Settings\Temp\sho\steps\1.ini
  • c:\Documents and Settings\test user\Local Settings\Temp\sho\images\loader.gif
Registry Keys Created
  • HKCU_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\LocalServer32
    ServerExecutable
    c:\test_item.exe
  • HKCU_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}
    (Default)
    TinyJSObject Class
  • HKCR\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}\1.0\HELPDIR
    (Default)
    c:
  • HKCU\Software\WebApp\Styles
    MaxScriptStatements
    0xffffffff
  • HKCU_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\Version
    (Default)
    1.0
  • HKCR\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}\1.0\0\win32
    (Default)
    c:\test_item.exe
  • HKCR\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}
    (Default)
    ITinyJSObject
  • HKCU\Software\Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\Version
    (Default)
    1.0
  • HKCU_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\TypeLib
    (Default)
    {7E77E9F2-D76B-4D54-B515-9A7F93DF03DF}
  • HKCR\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}\ProxyStubClsid
    (Default)
    {00020424-0000-0000-C000-000000000046}
  • HKCU\Software\Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\TypeLib
    (Default)
    {7E77E9F2-D76B-4D54-B515-9A7F93DF03DF}
  • HKCU\Software\Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}
    (Default)
    TinyJSObject Class
  • HKCR\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}\TypeLib
    Version
    1.0
  • HKCR\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}\1.0\FLAGS
    (Default)
  • HKCR\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}\1.0
    (Default)
    JSIELib
  • HKCU\Software\Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\LocalServer32
    ServerExecutable
    c:\test_item.exe
  • HKCR\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}\ProxyStubClsid32
    (Default)
    {00020424-0000-0000-C000-000000000046}
HTTP Requests
  • http://c1.epicbookallguard.net/
  • http://i1.nicedataget.com/images/next.png
  • http://i1.nicedataget.com/images/sidebar.jpg
  • http://i1.nicedataget.com/images/titlebar.png
DNS Requests
  • c1.epicbookallguard.net
  • i1.nicedataget.com
  • r1.sunusadirall.net

Example 3

File Information

Size
1.6M
SHA-1
0000730b724bab077eb7111b7867e5f3fe13a139
MD5
32d436b2c9d8ed70c700ff5438a90e9b
CRC-32
242a6f84
File type
application/x-ms-dos-executable
First seen
2007-09-18

Runtime Analysis

Dropped Files
  • C:\Documents and Settings\All Users\Application Data\DOwenLoad akeeepero\00eqaqQUf6n.exe
  • C:\Program Files\DOwenLoad akeeepero\scBqoW03O6.dat
  • C:\Program Files\DOwenLoad akeeepero\scBqoW03O6.tlb
  • C:\Documents and Settings\All Users\Application Data\5d5d60c3d6235bf2\{C1A27135-69EB-8D44-7358-34727DD7B820}
  • C:\Program Files\DOwenLoad akeeepero\scBqoW03O6.dll
  • C:\Documents and Settings\All Users\Application Data\DOwenLoad akeeepero\00eqaqQUf6n.dat
  • c:\Documents and Settings\test user\AppData\LocalLow\{8A8E4B5F-D4CE-D1B2-897F-36759B11D218}\DOwenLoad akeeepero.2.9.dat
  • C:\Program Files\DOwenLoad akeeepero\scBqoW03O6.x64.dll
Registry Keys Created
  • HKCR\CLSID\{8A8E4B5F-D4CE-D1B2-897F-36759B11D218}
    (Default)
    DOwenLoad akeeepero
  • HKCR\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}\ProxyStubClsid
    (Default)
    {00020424-0000-0000-C000-000000000046}
  • HKCR\Interface\{9B41579A-1996-42F9-8F84-7B7786818CEF}\ProxyStubClsid32
    (Default)
    {00020424-0000-0000-C000-000000000046}
  • HKCR\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}\TypeLib
    Version
    1.0
  • HKCR\Interface\{7041156A-0D2B-4DCD-A8EE-D0608BFCB2D0}
    (Default)
    ILocalStorage
  • HKCR\keeeperr.1.6
    (Default)
    DOwenLoad akeeepero
  • HKCR\CLSID\{8A8E4B5F-D4CE-D1B2-897F-36759B11D218}\VersionIndependentProgID
    (Default)
    DoweNload keeeperr
  • HKCU\Software\RegisteredApplicationsEx
    c9ac633d08059ed085a5430611eafd95
    1
  • HKCR\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}\1.0\HELPDIR
    (Default)
    C:\Program Files\DOwenLoad akeeepero
  • HKCR\CLSID\{8A8E4B5F-D4CE-D1B2-897F-36759B11D218}\ProgID
    (Default)
    DoweNload keeeperr.1.6
  • HKCR\Interface\{9B41579A-1996-42F9-8F84-7B7786818CEF}
    (Default)
    IPlaghinMein
  • HKCR\Interface\{9B41579A-1996-42F9-8F84-7B7786818CEF}\ProxyStubClsid
    (Default)
    {00020424-0000-0000-C000-000000000046}
  • HKCR\Interface\{7041156A-0D2B-4DCD-A8EE-D0608BFCB2D0}\ProxyStubClsid
    (Default)
    {00020424-0000-0000-C000-000000000046}
  • HKCR\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}\1.0\FLAGS
    (Default)
  • HKCR\Interface\{9B41579A-1996-42F9-8F84-7B7786818CEF}\TypeLib
    Version
    1.0
  • HKCR\keeeperr\CLSID
    (Default)
    {8A8E4B5F-D4CE-D1B2-897F-36759B11D218}
  • HKCR\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}\1.0
    (Default)
    IEPluginLib
  • HKCR\keeeperr
    (Default)
    DOwenLoad akeeepero
  • HKCR\CLSID\{8A8E4B5F-D4CE-D1B2-897F-36759B11D218}\InprocServer32
    ThreadingModel
    Apartment
  • HKCR\keeeperr\CurVer
    (Default)
    DoweNload keeeperr.1.6
  • HKCR\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}\ProxyStubClsid32
    (Default)
    {00020424-0000-0000-C000-000000000046}
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C1A27135-69EB-8D44-7358-34727DD7B820}
    _In
    20140604
  • HKCR\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}\1.0\0\win32
    (Default)
    C:\Program Files\DOwenLoad akeeepero\scBqoW03O6.tlb
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID
    {8A8E4B5F-D4CE-D1B2-897F-36759B11D218}
    1
  • HKCR\Interface\{7041156A-0D2B-4DCD-A8EE-D0608BFCB2D0}\TypeLib
    Version
    1.0
  • HKCR\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
    (Default)
    IRegistry
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A8E4B5F-D4CE-D1B2-897F-36759B11D218}
    NoExplorer
    0x00000001
  • HKCR\keeeperr.1.6\CLSID
    (Default)
    {8A8E4B5F-D4CE-D1B2-897F-36759B11D218}
  • HKCR\Interface\{7041156A-0D2B-4DCD-A8EE-D0608BFCB2D0}\ProxyStubClsid32
    (Default)
    {00020424-0000-0000-C000-000000000046}
Processes Created
  • c:\docume~1\support\locals~1\temp\5c28189c\00eqaqquf6n.exe
  • c:\windows\system32\regsvr32.exe

scarica Prova gratuita dei prodotti Sophos
Scarica subito