Trojan.Win32.DOWNLOADER.CC
Trojan-Downloader.Win64.Rugmi (IKARUS)
Windows

マルウェアタイプ:
トロイの木馬型
破壊活動の有無:
なし
暗号化:
感染報告の有無 :
はい
概要
マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。
詳細
侵入方法
マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。
インストール
マルウェアは、以下のファイルを作成します。
- %System Root%\Config.Msi\{Random}.rbs
- %System Root%\Config.Msi\{Random}.tmp
- %User Temp%\{Random}
- %Windows%\Installer\inprogressinstallinfo.ipi
- %Windows%\Installer\SourceHash{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- %Windows%\Installer\{Random}.msi
- %Windows%\Installer\{Random}.tmp
- %Windows%\Temp\{Random}.TMP
- %AppDataLocal%\Terpene\OISGRAPH.DLL
- %AppDataLocal%\Terpene\CDLMSO.DLL
- %AppDataLocal%\Terpene\gynoecium.mp3
- %AppDataLocal%\Terpene\incendiary.accdb
- %AppDataLocal%\Terpene\MSOCF.DLL
- %AppDataLocal%\Terpene\msvcr90.dll
- %AppDataLocal%\Terpene\OIS.EXE
- %AppDataLocal%\Terpene\OISAPP.DLL
- %Application Data%\bqe_auth_debug\OISGRAPH.DLL
- %Application Data%\bqe_auth_debug\CDLMSO.DLL
- %Application Data%\bqe_auth_debug\gynoecium.mp3
- %Application Data%\bqe_auth_debug\incendiary.accdb
- %Application Data%\bqe_auth_debug\MSOCF.DLL
- %Application Data%\bqe_auth_debug\msvcr90.dll
- %Application Data%\bqe_auth_debug\OIS.EXE
- %Application Data%\bqe_auth_debug\OISAPP.DLL
(註:%System Root%フォルダは、オペレーティングシステム(OS)が存在する場所で、いずれのOSでも通常、 "C:" です。.. %User Temp%フォルダは、現在ログオンしているユーザの一時フォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザー名>\Local Settings\Temp"です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local\Temp" です。. %Windows%フォルダは、Windowsが利用するフォルダで、いずれのオペレーティングシステム(OS)でも通常、"C:\Windows" です。.. %AppDataLocal%フォルダは、ローカルアプリケーションデータフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>\Local Settings\Application Data" です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local" です。. %Application Data%フォルダは、現在ログオンしているユーザのアプリケーションデータフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>\Local Settings\Application Data" です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Roaming" です。)
マルウェアは、以下のプロセスを追加します。
- %AppDataLocal%\Terpene\OIS.EXE
(註:%AppDataLocal%フォルダは、ローカルアプリケーションデータフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>\Local Settings\Application Data" です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local" です。)
マルウェアは、以下のフォルダを作成します。
- %Application Data%\bqe_auth_debug
- %AppDataLocal%\Terpene
(註:%Application Data%フォルダは、現在ログオンしているユーザのアプリケーションデータフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>\Local Settings\Application Data" です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Roaming" です。. %AppDataLocal%フォルダは、ローカルアプリケーションデータフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>\Local Settings\Application Data" です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local" です。)
他のシステム変更
マルウェアは、インストールの過程で、以下のレジストリ値を追加します。
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
Rollback\Scripts\%System Root%\
Config.Msi
{Random}.rbs = 1db9841
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
Rollback\Scripts\%System Root%\
Config.Msi
{Random}.rbsLow = 1f8815f0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
2CEADA21D6152635F91D9B5643A7E895
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\gynoecium.mp3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
790E56DDF79C8D054AA18446C6FFDBB8
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\CDLMSO.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
8210B086290129658A040BEA48866791
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\incendiary.accdb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
508082EC935D2915FBD3E24E05547A55
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\MSOCF.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
DABF5CE521953E152B0A374A93F5A1C8
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\msvcr90.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
3ABB7D407B41A2B55B7A526C924BCBCD
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\OIS.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
CF82AF740863F295DB122CBAED52520B
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\OISAPP.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
CE599440A6BD39853B0AEDF38005C9AF
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\OISGRAPH.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
Folders
%System Root%\Users\Administrator\AppData\Local\Terpene\ =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
LocalPackage = %Windows%\Installer\{Random}.msi
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
AuthorizedCDFPrefix =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
Comments =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
Contact =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
DisplayName = Photogene
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
DisplayVersion = 1.10.7.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
HelpLink =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
HelpTelephone =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
InstallDate = {Malware Execution Date}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
InstallLocation =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
InstallSource = {Malware File Path}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
ModifyPath = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
Publisher = Bund Xylem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
Readme =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
Size =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
EstimatedSize = 119c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
UninstallString = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
URLInfoAbout =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
URLUpdateInfo =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
VersionMajor = 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
VersionMinor = a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
WindowsInstaller = 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
Version = 10a0007
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
Language = 409
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
AuthorizedCDFPrefix =
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
Comments =
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
Contact =
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
DisplayVersion = 1.10.7.0
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
HelpLink =
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
HelpTelephone =
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
InstallDate = {Malware Execution Date]
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
InstallLocation =
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
InstallSource = {Malware File Path}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
ModifyPath = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
Publisher = Bund Xylem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
Readme =
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
Size =
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
EstimatedSize = 119c
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
UninstallString = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
URLInfoAbout =
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
URLUpdateInfo =
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
VersionMajor = 1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
VersionMinor = a
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
WindowsInstaller = 1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
Version = 10a0007
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
Language = 409
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
DisplayName = Photogene
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UpgradeCodes\BFB0AB28F6C50464E8707EB10AFACCC7
E5624C9DEDF6A674C96142A7F8461B52 =
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Features\E5624C9DEDF6A674C96142A7F8461B52
PardaloteFeature =
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
ProductName = Photogene
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
PackageCode = DB91AD3C325DF374098783841AF005BF
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
Language = 409
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
Version = 10a0007
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
Assignment = 0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
AdvertiseFlags = 184
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
InstanceType = 0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
AuthorizedLUAApp = 0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
DeploymentFlags = 2
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
Clients = :\0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\UpgradeCodes\BFB0AB28F6C50464E8707EB10AFACCC7
E5624C9DEDF6A674C96142A7F8461B52 =
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\
SourceList
PackageName = {Malware File Name}.msi
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\
SourceList
LastUsedSource = n;1;{Malware File Path}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\
SourceList\Net
1 = {Malware File Path}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\
SourceList\Media
1 = ;
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\Features
PardaloteFeature = YD?!)G]zlBd6&dHjmYkD5UE1pEu_}A=_Y7H.1[vTppDMI_%$oCq3A0aOd[3+'zz9kqOR6B4]_Drf?zTCKn+OFtl*CB=6_q]h'O%Ud?AW$zESAErV1chJ!Ayo6aD.?hcKaDv&95`W]*]aMu-H$ZRpODE)qT8nGJVy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\Patches
AllPatches =
その他
マルウェアは、以下のレジストリキーを追加します。
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
2CEADA21D6152635F91D9B5643A7E895
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
790E56DDF79C8D054AA18446C6FFDBB8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
8210B086290129658A040BEA48866791
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
508082EC935D2915FBD3E24E05547A55
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
DABF5CE521953E152B0A374A93F5A1C8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
3ABB7D407B41A2B55B7A526C924BCBCD
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
CF82AF740863F295DB122CBAED52520B
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
CE599440A6BD39853B0AEDF38005C9AF
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UpgradeCodes\BFB0AB28F6C50464E8707EB10AFACCC7
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Features\E5624C9DEDF6A674C96142A7F8461B52
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\UpgradeCodes\BFB0AB28F6C50464E8707EB10AFACCC7
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\
SourceList
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\
SourceList\Net
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\
SourceList\Media
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\Features
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\Patches
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\Usage
対応方法
手順 1
Windows 7、Windows 8、Windows 8.1、および Windows 10 のユーザは、コンピュータからマルウェアもしくはアドウェア等を完全に削除するために、ウイルス検索の実行前には必ず「システムの復元」を無効にしてください。
手順 2
このマルウェアもしくはアドウェア等の実行により、手順中に記載されたすべてのファイル、フォルダおよびレジストリキーや値がコンピュータにインストールされるとは限りません。インストールが不完全である場合の他、オペレーティングシステム(OS)の条件によりインストールがされない場合が考えられます。手順中に記載されたファイル/フォルダ/レジストリ情報が確認されない場合、該当の手順の操作は不要ですので、次の手順に進んでください。
手順 3
このレジストリ値を削除します。
警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts\%System Root%\Config.Msi
- {Random}.rbs = 1db9841
- {Random}.rbs = 1db9841
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts\%System Root%\Config.Msi
- {Random}.rbsLow = 1f8815f0
- {Random}.rbsLow = 1f8815f0
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\2CEADA21D6152635F91D9B5643A7E895
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\gynoecium.mp3
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\gynoecium.mp3
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\790E56DDF79C8D054AA18446C6FFDBB8
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\CDLMSO.DLL
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\CDLMSO.DLL
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\8210B086290129658A040BEA48866791
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\incendiary.accdb
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\incendiary.accdb
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\508082EC935D2915FBD3E24E05547A55
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\MSOCF.DLL
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\MSOCF.DLL
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\DABF5CE521953E152B0A374A93F5A1C8
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\msvcr90.dll
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\msvcr90.dll
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\3ABB7D407B41A2B55B7A526C924BCBCD
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\OIS.EXE
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\OIS.EXE
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\CF82AF740863F295DB122CBAED52520B
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\OISAPP.DLL
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\OISAPP.DLL
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\CE599440A6BD39853B0AEDF38005C9AF
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\OISGRAPH.DLL
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\OISGRAPH.DLL
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
- %System Root%\Users\Administrator\AppData\Local\Terpene\
- %System Root%\Users\Administrator\AppData\Local\Terpene\
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- LocalPackage = %Windows%\Installer\{Random}.msi
- LocalPackage = %Windows%\Installer\{Random}.msi
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- AuthorizedCDFPrefix
- AuthorizedCDFPrefix
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- Comments
- Comments
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- Contact
- Contact
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- DisplayName = Photogene
- DisplayName = Photogene
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- DisplayVersion = 1.10.7.0
- DisplayVersion = 1.10.7.0
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- HelpLink
- HelpLink
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- HelpTelephone
- HelpTelephone
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- InstallDate = {Malware Execution Date}
- InstallDate = {Malware Execution Date}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- InstallLocation
- InstallLocation
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- InstallSource = {Malware File Path}
- InstallSource = {Malware File Path}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- ModifyPath = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- ModifyPath = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- Publisher = Bund Xylem
- Publisher = Bund Xylem
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- Readme
- Readme
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- Size
- Size
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- EstimatedSize = 119c
- EstimatedSize = 119c
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- UninstallString = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- UninstallString = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- URLInfoAbout
- URLInfoAbout
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- URLUpdateInfo
- URLUpdateInfo
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- VersionMajor = 1
- VersionMajor = 1
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- VersionMinor = a
- VersionMinor = a
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- WindowsInstaller = 1
- WindowsInstaller = 1
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- Version = 10a0007
- Version = 10a0007
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- Language = 409
- Language = 409
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- AuthorizedCDFPrefix
- AuthorizedCDFPrefix
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- Comments
- Comments
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- Contact
- Contact
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- DisplayVersion = 1.10.7.0
- DisplayVersion = 1.10.7.0
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- HelpLink
- HelpLink
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- HelpTelephone
- HelpTelephone
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- InstallDate = {Malware Execution Date}
- InstallDate = {Malware Execution Date}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- InstallLocation
- InstallLocation
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- InstallSource = {Malware File path}
- InstallSource = {Malware File path}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- ModifyPath = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- ModifyPath = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- Publisher = Bund Xylem
- Publisher = Bund Xylem
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- Readme
- Readme
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- Size
- Size
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- EstimatedSize = 119c
- EstimatedSize = 119c
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- UninstallString = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- UninstallString = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- URLInfoAbout
- URLInfoAbout
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- URLUpdateInfo
- URLUpdateInfo
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- VersionMajor = 1
- VersionMajor = 1
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- VersionMinor = a
- VersionMinor = a
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- WindowsInstaller = 1
- WindowsInstaller = 1
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- Version = 10a0007
- Version = 10a0007
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- Language = 409
- Language = 409
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- DisplayName = Photogene
- DisplayName = Photogene
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\BFB0AB28F6C50464E8707EB10AFACCC7
- E5624C9DEDF6A674C96142A7F8461B52
- E5624C9DEDF6A674C96142A7F8461B52
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Features\E5624C9DEDF6A674C96142A7F8461B52
- PardaloteFeature
- PardaloteFeature
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
- ProductName = Photogene
- ProductName = Photogene
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
- PackageCode = DB91AD3C325DF374098783841AF005BF
- PackageCode = DB91AD3C325DF374098783841AF005BF
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
- Language = 409
- Language = 409
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
- Version = 10a0007
- Version = 10a0007
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
- Assignment = 0
- Assignment = 0
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
- AdvertiseFlags = 184
- AdvertiseFlags = 184
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
- InstanceType = 0
- InstanceType = 0
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
- AuthorizedLUAApp = 0
- AuthorizedLUAApp = 0
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
- DeploymentFlags = 2
- DeploymentFlags = 2
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
- Clients = :\0
- Clients = :\0
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\UpgradeCodes\BFB0AB28F6C50464E8707EB10AFACCC7
- E5624C9DEDF6A674C96142A7F8461B52
- E5624C9DEDF6A674C96142A7F8461B52
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\SourceList
- PackageName = {Malware File Name}.msi
- PackageName = {Malware File Name}.msi
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\SourceList
- LastUsedSource = n;1;{Malware File Path}
- LastUsedSource = n;1;{Malware File Path}
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\SourceList\Net
- 1 = {Malware File Path}
- 1 = {Malware File Path}
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\SourceList\Media
- 1 = ;
- 1 = ;
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\Features
- PardaloteFeature = YD?!)G]zlBd6&dHjmYkD5UE1pEu_}A=_Y7H.1[vTppDMI_%$oCq3A0aOd[3+'zz9kqOR6B4]_Drf?zTCKn+OFtl*CB=6_q]h'O%Ud?AW$zESAErV1chJ!Ayo6aD.?hcKaDv&95`W]*]aMu-H$ZRpODE)qT8nGJVy
- PardaloteFeature = YD?!)G]zlBd6&dHjmYkD5UE1pEu_}A=_Y7H.1[vTppDMI_%$oCq3A0aOd[3+'zz9kqOR6B4]_Drf?zTCKn+OFtl*CB=6_q]h'O%Ud?AW$zESAErV1chJ!Ayo6aD.?hcKaDv&95`W]*]aMu-H$ZRpODE)qT8nGJVy
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\Patches
- AllPatches
- AllPatches
手順 4
このレジストリキーを削除します。
警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components
- 2CEADA21D6152635F91D9B5643A7E895
- 2CEADA21D6152635F91D9B5643A7E895
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components
- 790E56DDF79C8D054AA18446C6FFDBB8
- 790E56DDF79C8D054AA18446C6FFDBB8
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components
- 8210B086290129658A040BEA48866791
- 8210B086290129658A040BEA48866791
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components
- 508082EC935D2915FBD3E24E05547A55
- 508082EC935D2915FBD3E24E05547A55
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components
- DABF5CE521953E152B0A374A93F5A1C8
- DABF5CE521953E152B0A374A93F5A1C8
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components
- 3ABB7D407B41A2B55B7A526C924BCBCD
- 3ABB7D407B41A2B55B7A526C924BCBCD
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components
- CF82AF740863F295DB122CBAED52520B
- CF82AF740863F295DB122CBAED52520B
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components
- CE599440A6BD39853B0AEDF38005C9AF
- CE599440A6BD39853B0AEDF38005C9AF
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall
- {D9C4265E-6FDE-476A-9C16-247A8F64B125}
- {D9C4265E-6FDE-476A-9C16-247A8F64B125}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes
- BFB0AB28F6C50464E8707EB10AFACCC7
- BFB0AB28F6C50464E8707EB10AFACCC7
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Features
- E5624C9DEDF6A674C96142A7F8461B52
- E5624C9DEDF6A674C96142A7F8461B52
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products
- E5624C9DEDF6A674C96142A7F8461B52
- E5624C9DEDF6A674C96142A7F8461B52
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\UpgradeCodes
- BFB0AB28F6C50464E8707EB10AFACCC7
- BFB0AB28F6C50464E8707EB10AFACCC7
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\SourceList
- Net
- Net
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\SourceList
- Media
- Media
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
- SourceList
- SourceList
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52
- Features
- Features
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52
- InstallProperties
- InstallProperties
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52
- Patches
- Patches
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52
- Usage
- Usage
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products
- E5624C9DEDF6A674C96142A7F8461B52
- E5624C9DEDF6A674C96142A7F8461B52
手順 5
以下のファイルを検索し削除します。
- %System Root%\Config.Msi\{Random}.rbs
- %System Root%\Config.Msi\{Random}.tmp
- %User Temp%\{Random}
- %Windows%\Installer\inprogressinstallinfo.ipi
- %Windows%\Installer\SourceHash{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- %Windows%\Installer\{Random}.msi
- %Windows%\Installer\{Random}.tmp
- %Windows%\Temp\{Random}.TMP
- %AppDataLocal%\Terpene\OISGRAPH.DLL
- %AppDataLocal%\Terpene\CDLMSO.DLL
- %AppDataLocal%\Terpene\gynoecium.mp3
- %AppDataLocal%\Terpene\incendiary.accdb
- %AppDataLocal%\Terpene\MSOCF.DLL
- %AppDataLocal%\Terpene\msvcr90.dll
- %AppDataLocal%\Terpene\OIS.EXE
- %AppDataLocal%\Terpene\OISAPP.DLL
- %Application Data%\bqe_auth_debug\OISGRAPH.DLL
- %Application Data%\bqe_auth_debug\CDLMSO.DLL
- %Application Data%\bqe_auth_debug\gynoecium.mp3
- %Application Data%\bqe_auth_debug\incendiary.accdb
- %Application Data%\bqe_auth_debug\MSOCF.DLL
- %Application Data%\bqe_auth_debug\msvcr90.dll
- %Application Data%\bqe_auth_debug\OIS.EXE
- %Application Data%\bqe_auth_debug\OISAPP.DLL
手順 6
以下のフォルダを検索し削除します。
- %Application Data%\bqe_auth_debug
- %AppDataLocal%\Terpene
手順 7
最新のバージョン(エンジン、パターンファイル)を導入したウイルス対策製品を用い、ウイルス検索を実行してください。「Trojan.Win32.DOWNLOADER.CC」と検出したファイルはすべて削除してください。 検出されたファイルが、弊社ウイルス対策製品により既に駆除、隔離またはファイル削除の処理が実行された場合、ウイルスの処理は完了しており、他の削除手順は特にありません。
ご利用はいかがでしたか? アンケートにご協力ください