Trojan.Win32.DOWNLOADER.CC
Trojan-Downloader.Win64.Rugmi (IKARUS)
Windows


恶意软件类型:
Trojan
有破坏性?:
没有
加密?:

In the Wild:
是的
概要
该木马通过两种途径进入系统:一是被其他恶意软件作为文件释放到系统中,二是用户访问恶意网站时在不知情的情况下下载的文件。
技术详细信息
Arrival Details
该木马通过两种途径进入系统:一是被其他恶意软件作为文件释放到系统中,二是用户访问恶意网站时在不知情的情况下下载的文件。
Installation
该木马程序会释放以下文件:
- %System Root%\Config.Msi\{Random}.rbs
- %System Root%\Config.Msi\{Random}.tmp
- %User Temp%\{Random}
- %Windows%\Installer\inprogressinstallinfo.ipi
- %Windows%\Installer\SourceHash{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- %Windows%\Installer\{Random}.msi
- %Windows%\Installer\{Random}.tmp
- %Windows%\Temp\{Random}.TMP
- %AppDataLocal%\Terpene\OISGRAPH.DLL
- %AppDataLocal%\Terpene\CDLMSO.DLL
- %AppDataLocal%\Terpene\gynoecium.mp3
- %AppDataLocal%\Terpene\incendiary.accdb
- %AppDataLocal%\Terpene\MSOCF.DLL
- %AppDataLocal%\Terpene\msvcr90.dll
- %AppDataLocal%\Terpene\OIS.EXE
- %AppDataLocal%\Terpene\OISAPP.DLL
- %Application Data%\bqe_auth_debug\OISGRAPH.DLL
- %Application Data%\bqe_auth_debug\CDLMSO.DLL
- %Application Data%\bqe_auth_debug\gynoecium.mp3
- %Application Data%\bqe_auth_debug\incendiary.accdb
- %Application Data%\bqe_auth_debug\MSOCF.DLL
- %Application Data%\bqe_auth_debug\msvcr90.dll
- %Application Data%\bqe_auth_debug\OIS.EXE
- %Application Data%\bqe_auth_debug\OISAPP.DLL
(Note: %System Root% 此处指Windows系统根目录,其通常位于 C:\ 适用于所有Windows操作系统版本。 %User Temp% 是当前用户的临时文件夹,通常位于此路径 C:\Documents and Settings\{user name}\Local Settings\Temp 在Windows 2000(32位)、XP及Server 2003(32位)系统上,或 C:\Users\{user name}\AppData\Local\Temp on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %Windows% 是Windows文件夹, 通常位于此路径 C:\Windows 适用于所有Windows操作系统版本。 %AppDataLocal% 是本地应用程序数据文件夹, 通常位于此路径 C:\Documents and Settings\{user name}\Local Settings\Application Data 在Windows 2000(32位)、XP及Server 2003(32位)系统上,或 C:\Users\{user name}\AppData\Local on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %Application Data% 是当前用户的 Application Data 文件夹,通常路径为:C:\Documents and Settings\{user name}\Application Data 在Windows 2000(32位)、XP及Server 2003(32位)系统上,或 C:\Users\{user name}\AppData\Roaming 在Windows Vista、7、8、8.1、2008(64位)、2012(64位)及10(64位)系统上。)
它会添加以下进程:
- %AppDataLocal%\Terpene\OIS.EXE
(Note: %AppDataLocal% 是本地应用程序数据文件夹, 通常位于此路径 C:\Documents and Settings\{user name}\Local Settings\Application Data 在Windows 2000(32位)、XP及Server 2003(32位)系统上,或 C:\Users\{user name}\AppData\Local 在Windows Vista、7、8、8.1、2008(64位)、2012(64位)及10(64位)系统上。)
它会创建以下文件夹:
- %Application Data%\bqe_auth_debug
- %AppDataLocal%\Terpene
(Note: %Application Data% 是当前用户的 Application Data 文件夹,通常路径为:C:\Documents and Settings\{user name}\Application Data 在Windows 2000(32位)、XP及Server 2003(32位)系统上,或 C:\Users\{user name}\AppData\Roaming on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %AppDataLocal% 是本地应用程序数据文件夹, 通常位于此路径 C:\Documents and Settings\{user name}\Local Settings\Application Data 在Windows 2000(32位)、XP及Server 2003(32位)系统上,或 C:\Users\{user name}\AppData\Local 在Windows Vista、7、8、8.1、2008(64位)、2012(64位)及10(64位)系统上。)
其他系统修改
该木马程序会添加以下注册表项作为其安装例程的一部分:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
Rollback\Scripts\%System Root%\
Config.Msi
{Random}.rbs = 1db9841
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
Rollback\Scripts\%System Root%\
Config.Msi
{Random}.rbsLow = 1f8815f0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
2CEADA21D6152635F91D9B5643A7E895
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\gynoecium.mp3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
790E56DDF79C8D054AA18446C6FFDBB8
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\CDLMSO.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
8210B086290129658A040BEA48866791
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\incendiary.accdb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
508082EC935D2915FBD3E24E05547A55
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\MSOCF.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
DABF5CE521953E152B0A374A93F5A1C8
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\msvcr90.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
3ABB7D407B41A2B55B7A526C924BCBCD
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\OIS.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
CF82AF740863F295DB122CBAED52520B
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\OISAPP.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
CE599440A6BD39853B0AEDF38005C9AF
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\OISGRAPH.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
Folders
%System Root%\Users\Administrator\AppData\Local\Terpene\ =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
LocalPackage = %Windows%\Installer\{Random}.msi
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
AuthorizedCDFPrefix =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
Comments =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
Contact =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
DisplayName = Photogene
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
DisplayVersion = 1.10.7.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
HelpLink =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
HelpTelephone =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
InstallDate = {Malware Execution Date}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
InstallLocation =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
InstallSource = {Malware File Path}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
ModifyPath = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
Publisher = Bund Xylem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
Readme =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
Size =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
EstimatedSize = 119c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
UninstallString = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
URLInfoAbout =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
URLUpdateInfo =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
VersionMajor = 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
VersionMinor = a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
WindowsInstaller = 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
Version = 10a0007
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
Language = 409
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
AuthorizedCDFPrefix =
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
Comments =
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
Contact =
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
DisplayVersion = 1.10.7.0
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
HelpLink =
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
HelpTelephone =
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
InstallDate = {Malware Execution Date]
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
InstallLocation =
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
InstallSource = {Malware File Path}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
ModifyPath = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
Publisher = Bund Xylem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
Readme =
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
Size =
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
EstimatedSize = 119c
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
UninstallString = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
URLInfoAbout =
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
URLUpdateInfo =
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
VersionMajor = 1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
VersionMinor = a
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
WindowsInstaller = 1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
Version = 10a0007
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
Language = 409
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
DisplayName = Photogene
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UpgradeCodes\BFB0AB28F6C50464E8707EB10AFACCC7
E5624C9DEDF6A674C96142A7F8461B52 =
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Features\E5624C9DEDF6A674C96142A7F8461B52
PardaloteFeature =
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
ProductName = Photogene
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
PackageCode = DB91AD3C325DF374098783841AF005BF
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
Language = 409
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
Version = 10a0007
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
Assignment = 0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
AdvertiseFlags = 184
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
InstanceType = 0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
AuthorizedLUAApp = 0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
DeploymentFlags = 2
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
Clients = :\0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\UpgradeCodes\BFB0AB28F6C50464E8707EB10AFACCC7
E5624C9DEDF6A674C96142A7F8461B52 =
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\
SourceList
PackageName = {Malware File Name}.msi
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\
SourceList
LastUsedSource = n;1;{Malware File Path}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\
SourceList\Net
1 = {Malware File Path}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\
SourceList\Media
1 = ;
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\Features
PardaloteFeature = YD?!)G]zlBd6&dHjmYkD5UE1pEu_}A=_Y7H.1[vTppDMI_%$oCq3A0aOd[3+'zz9kqOR6B4]_Drf?zTCKn+OFtl*CB=6_q]h'O%Ud?AW$zESAErV1chJ!Ayo6aD.?hcKaDv&95`W]*]aMu-H$ZRpODE)qT8nGJVy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\Patches
AllPatches =
其他信息
该木马程序会添加以下注册表键值:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
2CEADA21D6152635F91D9B5643A7E895
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
790E56DDF79C8D054AA18446C6FFDBB8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
8210B086290129658A040BEA48866791
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
508082EC935D2915FBD3E24E05547A55
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
DABF5CE521953E152B0A374A93F5A1C8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
3ABB7D407B41A2B55B7A526C924BCBCD
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
CF82AF740863F295DB122CBAED52520B
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\
CE599440A6BD39853B0AEDF38005C9AF
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UpgradeCodes\BFB0AB28F6C50464E8707EB10AFACCC7
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Features\E5624C9DEDF6A674C96142A7F8461B52
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\UpgradeCodes\BFB0AB28F6C50464E8707EB10AFACCC7
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\
SourceList
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\
SourceList\Net
HKEY_CURRENT_USER\SOFTWARE\Microsoft\
Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\
SourceList\Media
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\Features
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\Patches
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\
E5624C9DEDF6A674C96142A7F8461B52\Usage
解决方案
Step 1
在进行任何扫描之前,Windows 7、Windows 8、Windows 8.1 和 Windows 10 用户必须先执行以下操作: 禁用 系统还原 以便对电脑进行全面扫描。
Step 2
注意:在此恶意软件/间谍软件/灰色软件执行期间,并非所有文件、文件夹和注册表键值和项都会安装到您的计算机上。这可能是由于不完整的安装或其他操作系统条件所致。如果您没有找到相同的文件/文件夹/注册表信息,请继续进行下一步操作。
Step 3
删除此注册表值
Important: 编辑 Windows Registry 操作不当可能导致系统出现无法恢复的故障。请务必仅在您熟悉相关步骤的情况下执行;如有疑问,可寻求系统管理员的协助。否则,请查看下方链接。 Microsoft article 修改计算机注册表前请务必先进行此操作.
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts\%System Root%\Config.Msi
- {Random}.rbs = 1db9841
- {Random}.rbs = 1db9841
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts\%System Root%\Config.Msi
- {Random}.rbsLow = 1f8815f0
- {Random}.rbsLow = 1f8815f0
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\2CEADA21D6152635F91D9B5643A7E895
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\gynoecium.mp3
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\gynoecium.mp3
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\790E56DDF79C8D054AA18446C6FFDBB8
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\CDLMSO.DLL
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\CDLMSO.DLL
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\8210B086290129658A040BEA48866791
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\incendiary.accdb
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\incendiary.accdb
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\508082EC935D2915FBD3E24E05547A55
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\MSOCF.DLL
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\MSOCF.DLL
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\DABF5CE521953E152B0A374A93F5A1C8
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\msvcr90.dll
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\msvcr90.dll
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\3ABB7D407B41A2B55B7A526C924BCBCD
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\OIS.EXE
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\OIS.EXE
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\CF82AF740863F295DB122CBAED52520B
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\OISAPP.DLL
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\OISAPP.DLL
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components\CE599440A6BD39853B0AEDF38005C9AF
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\OISGRAPH.DLL
- E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\OISGRAPH.DLL
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
- %System Root%\Users\Administrator\AppData\Local\Terpene\
- %System Root%\Users\Administrator\AppData\Local\Terpene\
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- LocalPackage = %Windows%\Installer\{Random}.msi
- LocalPackage = %Windows%\Installer\{Random}.msi
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- AuthorizedCDFPrefix
- AuthorizedCDFPrefix
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- Comments
- Comments
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- Contact
- Contact
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- DisplayName = Photogene
- DisplayName = Photogene
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- DisplayVersion = 1.10.7.0
- DisplayVersion = 1.10.7.0
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- HelpLink
- HelpLink
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- HelpTelephone
- HelpTelephone
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- InstallDate = {Malware Execution Date}
- InstallDate = {Malware Execution Date}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- InstallLocation
- InstallLocation
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- InstallSource = {Malware File Path}
- InstallSource = {Malware File Path}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- ModifyPath = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- ModifyPath = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- Publisher = Bund Xylem
- Publisher = Bund Xylem
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- Readme
- Readme
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- Size
- Size
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- EstimatedSize = 119c
- EstimatedSize = 119c
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- UninstallString = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- UninstallString = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- URLInfoAbout
- URLInfoAbout
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- URLUpdateInfo
- URLUpdateInfo
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- VersionMajor = 1
- VersionMajor = 1
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- VersionMinor = a
- VersionMinor = a
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- WindowsInstaller = 1
- WindowsInstaller = 1
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- Version = 10a0007
- Version = 10a0007
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\InstallProperties
- Language = 409
- Language = 409
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- AuthorizedCDFPrefix
- AuthorizedCDFPrefix
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- Comments
- Comments
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- Contact
- Contact
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- DisplayVersion = 1.10.7.0
- DisplayVersion = 1.10.7.0
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- HelpLink
- HelpLink
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- HelpTelephone
- HelpTelephone
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- InstallDate = {Malware Execution Date}
- InstallDate = {Malware Execution Date}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- InstallLocation
- InstallLocation
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- InstallSource = {Malware File path}
- InstallSource = {Malware File path}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- ModifyPath = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- ModifyPath = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- Publisher = Bund Xylem
- Publisher = Bund Xylem
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- Readme
- Readme
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- Size
- Size
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- EstimatedSize = 119c
- EstimatedSize = 119c
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- UninstallString = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- UninstallString = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- URLInfoAbout
- URLInfoAbout
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- URLUpdateInfo
- URLUpdateInfo
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- VersionMajor = 1
- VersionMajor = 1
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- VersionMinor = a
- VersionMinor = a
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- WindowsInstaller = 1
- WindowsInstaller = 1
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- Version = 10a0007
- Version = 10a0007
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- Language = 409
- Language = 409
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- DisplayName = Photogene
- DisplayName = Photogene
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\BFB0AB28F6C50464E8707EB10AFACCC7
- E5624C9DEDF6A674C96142A7F8461B52
- E5624C9DEDF6A674C96142A7F8461B52
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Features\E5624C9DEDF6A674C96142A7F8461B52
- PardaloteFeature
- PardaloteFeature
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
- ProductName = Photogene
- ProductName = Photogene
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
- PackageCode = DB91AD3C325DF374098783841AF005BF
- PackageCode = DB91AD3C325DF374098783841AF005BF
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
- Language = 409
- Language = 409
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
- Version = 10a0007
- Version = 10a0007
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
- Assignment = 0
- Assignment = 0
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
- AdvertiseFlags = 184
- AdvertiseFlags = 184
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
- InstanceType = 0
- InstanceType = 0
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
- AuthorizedLUAApp = 0
- AuthorizedLUAApp = 0
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
- DeploymentFlags = 2
- DeploymentFlags = 2
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
- Clients = :\0
- Clients = :\0
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\UpgradeCodes\BFB0AB28F6C50464E8707EB10AFACCC7
- E5624C9DEDF6A674C96142A7F8461B52
- E5624C9DEDF6A674C96142A7F8461B52
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\SourceList
- PackageName = {Malware File Name}.msi
- PackageName = {Malware File Name}.msi
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\SourceList
- LastUsedSource = n;1;{Malware File Path}
- LastUsedSource = n;1;{Malware File Path}
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\SourceList\Net
- 1 = {Malware File Path}
- 1 = {Malware File Path}
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\SourceList\Media
- 1 = ;
- 1 = ;
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\Features
- PardaloteFeature = YD?!)G]zlBd6&dHjmYkD5UE1pEu_}A=_Y7H.1[vTppDMI_%$oCq3A0aOd[3+'zz9kqOR6B4]_Drf?zTCKn+OFtl*CB=6_q]h'O%Ud?AW$zESAErV1chJ!Ayo6aD.?hcKaDv&95`W]*]aMu-H$ZRpODE)qT8nGJVy
- PardaloteFeature = YD?!)G]zlBd6&dHjmYkD5UE1pEu_}A=_Y7H.1[vTppDMI_%$oCq3A0aOd[3+'zz9kqOR6B4]_Drf?zTCKn+OFtl*CB=6_q]h'O%Ud?AW$zESAErV1chJ!Ayo6aD.?hcKaDv&95`W]*]aMu-H$ZRpODE)qT8nGJVy
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52\Patches
- AllPatches
- AllPatches
要删除该恶意/灰色软件创建的注册表值,请执行以下操作:
- 打开注册表编辑器。
» 对于 Windows 7 和 Windows Server 2008 (R2) 用户,请点击 Start button, type regedit in the Search输入字段,然后按下Enter.
» 对于 Windows 8、Windows 8.1、Windows 10 和 Windows Server 2012 (R2) 用户,请右键点击 屏幕左下角,点击Run, type regedit 在提供的文本框中,然后点击 Enter. - 在左侧面板中,双击以下项目:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows>CurrentVersion>Installer>Rollback>Scripts>%System Root%>Config.Msi - 在右侧面板中,找到并删除以下条目:
{Random}.rbs = 1db9841 - Again 在右侧面板中,找到并删除以下条目:
{Random}.rbsLow = 1f8815f0 - 在左侧面板中,双击以下项目:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows>CurrentVersion>Installer>UserData>S-1-5-21-2674318124-2743851293-4242590628-500>Components>2CEADA21D6152635F91D9B5643A7E895 - 在右侧面板中,找到并删除以下条目:
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\gynoecium.mp3 - 在左侧面板中,双击以下项目:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows>CurrentVersion>Installer>UserData>S-1-5-21-2674318124-2743851293-4242590628-500>Components>790E56DDF79C8D054AA18446C6FFDBB8 - 在右侧面板中,找到并删除以下条目:
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\CDLMSO.DLL - 在左侧面板中,双击以下项目:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows>CurrentVersion>Installer>UserData>S-1-5-21-2674318124-2743851293-4242590628-500>Components>8210B086290129658A040BEA48866791 - 在右侧面板中,找到并删除以下条目:
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\incendiary.accdb - 在左侧面板中,双击以下项目:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows>CurrentVersion>Installer>UserData>S-1-5-21-2674318124-2743851293-4242590628-500>Components>508082EC935D2915FBD3E24E05547A55 - 在右侧面板中,找到并删除以下条目:
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\MSOCF.DLL - 在左侧面板中,双击以下项目:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows>CurrentVersion>Installer>UserData>S-1-5-21-2674318124-2743851293-4242590628-500>Components>DABF5CE521953E152B0A374A93F5A1C8 - 在右侧面板中,找到并删除以下条目:
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\msvcr90.dll - 在左侧面板中,双击以下项目:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows>CurrentVersion>Installer>UserData>S-1-5-21-2674318124-2743851293-4242590628-500>Components>3ABB7D407B41A2B55B7A526C924BCBCD - 在右侧面板中,找到并删除以下条目:
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\OIS.EXE - 在左侧面板中,双击以下项目:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows>CurrentVersion>Installer>UserData>S-1-5-21-2674318124-2743851293-4242590628-500>Components>CF82AF740863F295DB122CBAED52520B - 在右侧面板中,找到并删除以下条目:
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\OISAPP.DLL - 在左侧面板中,双击以下项目:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows>CurrentVersion>Installer>UserData>S-1-5-21-2674318124-2743851293-4242590628-500>Components>CE599440A6BD39853B0AEDF38005C9AF - 在右侧面板中,找到并删除以下条目:
E5624C9DEDF6A674C96142A7F8461B52 = %AppDataLocal%\Terpene\OISGRAPH.DLL - 在左侧面板中,双击以下项目:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows>CurrentVersion>Installer>Folders - 在右侧面板中,找到并删除以下条目:
%System Root%\Users\Administrator\AppData\Local\Terpene\ = - 在左侧面板中,双击以下项目:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows>CurrentVersion>Installer>UserData>S-1-5-21-2674318124-2743851293-4242590628-500>Products>E5624C9DEDF6A674C96142A7F8461B52>InstallProperties - 在右侧面板中,找到并删除以下条目:
LocalPackage = %Windows%\Installer\{Random}.msi - Again 在右侧面板中,找到并删除以下条目:
AuthorizedCDFPrefix = - Again 在右侧面板中,找到并删除以下条目:
Comments = - Again 在右侧面板中,找到并删除以下条目:
Contact = - Again 在右侧面板中,找到并删除以下条目:
DisplayName = Photogene - Again 在右侧面板中,找到并删除以下条目:
DisplayVersion = 1.10.7.0 - Again 在右侧面板中,找到并删除以下条目:
HelpLink = - Again 在右侧面板中,找到并删除以下条目:
HelpTelephone = - Again 在右侧面板中,找到并删除以下条目:
InstallDate = {Malware Execution Date} - Again 在右侧面板中,找到并删除以下条目:
InstallLocation = - Again 在右侧面板中,找到并删除以下条目:
InstallSource = {Malware File Path} - Again 在右侧面板中,找到并删除以下条目:
ModifyPath = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125} - Again 在右侧面板中,找到并删除以下条目:
Publisher = Bund Xylem - Again 在右侧面板中,找到并删除以下条目:
Readme = - Again 在右侧面板中,找到并删除以下条目:
Size = - Again 在右侧面板中,找到并删除以下条目:
EstimatedSize = 119c - Again 在右侧面板中,找到并删除以下条目:
UninstallString = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125} - Again 在右侧面板中,找到并删除以下条目:
URLInfoAbout = - Again 在右侧面板中,找到并删除以下条目:
URLUpdateInfo = - Again 在右侧面板中,找到并删除以下条目:
VersionMajor = 1 - Again 在右侧面板中,找到并删除以下条目:
VersionMinor = a - Again 在右侧面板中,找到并删除以下条目:
WindowsInstaller = 1 - Again 在右侧面板中,找到并删除以下条目:
Version = 10a0007 - Again 在右侧面板中,找到并删除以下条目:
Language = 409 - 在左侧面板中,双击以下项目:
HKEY_LOCAL_MACHINE>SOFTWARE>Wow6432Node>Microsoft>Windows>CurrentVersion>Uninstall>{D9C4265E-6FDE-476A-9C16-247A8F64B125} - 在右侧面板中,找到并删除以下条目:
AuthorizedCDFPrefix = - Again 在右侧面板中,找到并删除以下条目:
Comments = - Again 在右侧面板中,找到并删除以下条目:
Contact = - Again 在右侧面板中,找到并删除以下条目:
DisplayVersion = 1.10.7.0 - Again 在右侧面板中,找到并删除以下条目:
HelpLink = - Again 在右侧面板中,找到并删除以下条目:
HelpTelephone = - Again 在右侧面板中,找到并删除以下条目:
InstallDate = {Malware Execution Date} - Again 在右侧面板中,找到并删除以下条目:
InstallLocation = - Again 在右侧面板中,找到并删除以下条目:
InstallSource = {Malware File path} - Again 在右侧面板中,找到并删除以下条目:
ModifyPath = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125} - Again 在右侧面板中,找到并删除以下条目:
Publisher = Bund Xylem - Again 在右侧面板中,找到并删除以下条目:
Readme = - Again 在右侧面板中,找到并删除以下条目:
Size = - Again 在右侧面板中,找到并删除以下条目:
EstimatedSize = 119c - Again 在右侧面板中,找到并删除以下条目:
UninstallString = MsiExec.exe /I{D9C4265E-6FDE-476A-9C16-247A8F64B125} - Again 在右侧面板中,找到并删除以下条目:
URLInfoAbout = - Again 在右侧面板中,找到并删除以下条目:
URLUpdateInfo = - Again 在右侧面板中,找到并删除以下条目:
VersionMajor = 1 - Again 在右侧面板中,找到并删除以下条目:
VersionMinor = a - Again 在右侧面板中,找到并删除以下条目:
WindowsInstaller = 1 - Again 在右侧面板中,找到并删除以下条目:
Version = 10a0007 - Again 在右侧面板中,找到并删除以下条目:
Language = 409 - Again 在右侧面板中,找到并删除以下条目:
DisplayName = Photogene - 在左侧面板中,双击以下项目:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows>CurrentVersion>Installer>UpgradeCodes>BFB0AB28F6C50464E8707EB10AFACCC7 - 在右侧面板中,找到并删除以下条目:
E5624C9DEDF6A674C96142A7F8461B52 = - 在左侧面板中,双击以下项目:
HKEY_CURRENT_USER>SOFTWARE>Microsoft>Installer>Features>E5624C9DEDF6A674C96142A7F8461B52 - 在右侧面板中,找到并删除以下条目:
PardaloteFeature = - 在左侧面板中,双击以下项目:
HKEY_CURRENT_USER>SOFTWARE>Microsoft>Installer>Products>E5624C9DEDF6A674C96142A7F8461B52 - 在右侧面板中,找到并删除以下条目:
ProductName = Photogene - Again 在右侧面板中,找到并删除以下条目:
PackageCode = DB91AD3C325DF374098783841AF005BF - Again 在右侧面板中,找到并删除以下条目:
Language = 409 - Again 在右侧面板中,找到并删除以下条目:
Version = 10a0007 - Again 在右侧面板中,找到并删除以下条目:
Assignment = 0 - Again 在右侧面板中,找到并删除以下条目:
AdvertiseFlags = 184 - Again 在右侧面板中,找到并删除以下条目:
InstanceType = 0 - Again 在右侧面板中,找到并删除以下条目:
AuthorizedLUAApp = 0 - Again 在右侧面板中,找到并删除以下条目:
DeploymentFlags = 2 - Again 在右侧面板中,找到并删除以下条目:
Clients = :\0 - 在左侧面板中,双击以下项目:
HKEY_CURRENT_USER>SOFTWARE>Microsoft>Installer>UpgradeCodes>BFB0AB28F6C50464E8707EB10AFACCC7 - 在右侧面板中,找到并删除以下条目:
E5624C9DEDF6A674C96142A7F8461B52 = - 在左侧面板中,双击以下项目:
HKEY_CURRENT_USER>SOFTWARE>Microsoft>Installer>Products>E5624C9DEDF6A674C96142A7F8461B52>SourceList - 在右侧面板中,找到并删除以下条目:
PackageName = {Malware File Name}.msi - Again 在右侧面板中,找到并删除以下条目:
LastUsedSource = n;1;{Malware File Path} - 在左侧面板中,双击以下项目:
HKEY_CURRENT_USER>SOFTWARE>Microsoft>Installer>Products>E5624C9DEDF6A674C96142A7F8461B52>SourceList>Net - 在右侧面板中,找到并删除以下条目:
1 = {Malware File Path} - 在左侧面板中,双击以下项目:
HKEY_CURRENT_USER>SOFTWARE>Microsoft>Installer>Products>E5624C9DEDF6A674C96142A7F8461B52>SourceList>Media - 在右侧面板中,找到并删除以下条目:
1 = ; - 在左侧面板中,双击以下项目:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows>CurrentVersion>Installer>UserData>S-1-5-21-2674318124-2743851293-4242590628-500>Products>E5624C9DEDF6A674C96142A7F8461B52>Features - 在右侧面板中,找到并删除以下条目:
PardaloteFeature = YD?!)G]zlBd6&dHjmYkD5UE1pEu_}A - 在左侧面板中,双击以下项目:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows>CurrentVersion>Installer>UserData>S-1-5-21-2674318124-2743851293-4242590628-500>Products>E5624C9DEDF6A674C96142A7F8461B52>Patches - 在右侧面板中,找到并删除以下条目:
AllPatches = - 关闭注册表编辑器。
Step 4
删除此注册表项
Important: 编辑 Windows Registry 操作不当可能导致系统出现无法恢复的故障。请务必仅在您熟悉相关步骤的情况下执行;如有疑问,可寻求系统管理员的协助。否则,请查看下方链接。 Microsoft article 修改计算机注册表前请务必先进行此操作.
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components
- 2CEADA21D6152635F91D9B5643A7E895
- 2CEADA21D6152635F91D9B5643A7E895
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components
- 790E56DDF79C8D054AA18446C6FFDBB8
- 790E56DDF79C8D054AA18446C6FFDBB8
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components
- 8210B086290129658A040BEA48866791
- 8210B086290129658A040BEA48866791
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components
- 508082EC935D2915FBD3E24E05547A55
- 508082EC935D2915FBD3E24E05547A55
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components
- DABF5CE521953E152B0A374A93F5A1C8
- DABF5CE521953E152B0A374A93F5A1C8
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components
- 3ABB7D407B41A2B55B7A526C924BCBCD
- 3ABB7D407B41A2B55B7A526C924BCBCD
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components
- CF82AF740863F295DB122CBAED52520B
- CF82AF740863F295DB122CBAED52520B
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Components
- CE599440A6BD39853B0AEDF38005C9AF
- CE599440A6BD39853B0AEDF38005C9AF
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall
- {D9C4265E-6FDE-476A-9C16-247A8F64B125}
- {D9C4265E-6FDE-476A-9C16-247A8F64B125}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes
- BFB0AB28F6C50464E8707EB10AFACCC7
- BFB0AB28F6C50464E8707EB10AFACCC7
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Features
- E5624C9DEDF6A674C96142A7F8461B52
- E5624C9DEDF6A674C96142A7F8461B52
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products
- E5624C9DEDF6A674C96142A7F8461B52
- E5624C9DEDF6A674C96142A7F8461B52
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\UpgradeCodes
- BFB0AB28F6C50464E8707EB10AFACCC7
- BFB0AB28F6C50464E8707EB10AFACCC7
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\SourceList
- Net
- Net
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52\SourceList
- Media
- Media
- In HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\E5624C9DEDF6A674C96142A7F8461B52
- SourceList
- SourceList
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52
- Features
- Features
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52
- InstallProperties
- InstallProperties
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52
- Patches
- Patches
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products\E5624C9DEDF6A674C96142A7F8461B52
- Usage
- Usage
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2674318124-2743851293-4242590628-500\Products
- E5624C9DEDF6A674C96142A7F8461B52
- E5624C9DEDF6A674C96142A7F8461B52
要删除此恶意软件/灰色软件创建的注册表项:
- 打开注册表编辑器。 为此,请执行以下操作:
» 对于 Windows 7 和 Server 2008 (R2) 用户,请点击 Start button, type regedit in the Search输入字段,然后按下Enter.
» 对于 Windows 8、8.1、10 及 Server 2012 (R2) 用户,请右键单击屏幕左下角,点击 Run, type regedit 在提供的文本框中,然后点击 Enter. - 在注册表编辑器窗口的左侧面板中,双击以下项目:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows>CurrentVersion>Installer>UserData>S-1-5-21-2674318124-2743851293-4242590628-500>Components - 仍在左侧面板中,找到并删除以下注册表项:
2CEADA21D6152635F91D9B5643A7E895 - Again 仍在左侧面板中,找到并删除以下注册表项:
790E56DDF79C8D054AA18446C6FFDBB8 - Again 仍在左侧面板中,找到并删除以下注册表项:
8210B086290129658A040BEA48866791 - Again 仍在左侧面板中,找到并删除以下注册表项:
508082EC935D2915FBD3E24E05547A55 - Again 仍在左侧面板中,找到并删除以下注册表项:
DABF5CE521953E152B0A374A93F5A1C8 - Again 仍在左侧面板中,找到并删除以下注册表项:
3ABB7D407B41A2B55B7A526C924BCBCD - Again 仍在左侧面板中,找到并删除以下注册表项:
CF82AF740863F295DB122CBAED52520B - Again 仍在左侧面板中,找到并删除以下注册表项:
CE599440A6BD39853B0AEDF38005C9AF - 在注册表编辑器窗口的左侧面板中,双击以下项目:
HKEY_LOCAL_MACHINE>SOFTWARE>Wow6432Node>Microsoft>Windows>CurrentVersion>Uninstall - 仍在左侧面板中,找到并删除以下注册表项:
{D9C4265E-6FDE-476A-9C16-247A8F64B125} - 在注册表编辑器窗口的左侧面板中,双击以下项目:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows>CurrentVersion>Installer>UpgradeCodes - 仍在左侧面板中,找到并删除以下注册表项:
BFB0AB28F6C50464E8707EB10AFACCC7 - 在注册表编辑器窗口的左侧面板中,双击以下项目:
HKEY_CURRENT_USER>SOFTWARE>Microsoft>Installer>Features - 仍在左侧面板中,找到并删除以下注册表项:
E5624C9DEDF6A674C96142A7F8461B52 - 在注册表编辑器窗口的左侧面板中,双击以下项目:
HKEY_CURRENT_USER>SOFTWARE>Microsoft>Installer>Products - 仍在左侧面板中,找到并删除以下注册表项:
E5624C9DEDF6A674C96142A7F8461B52 - 在注册表编辑器窗口的左侧面板中,双击以下项目:
HKEY_CURRENT_USER>SOFTWARE>Microsoft>Installer>UpgradeCodes - 仍在左侧面板中,找到并删除以下注册表项:
BFB0AB28F6C50464E8707EB10AFACCC7 - 在注册表编辑器窗口的左侧面板中,双击以下项目:
HKEY_CURRENT_USER>SOFTWARE>Microsoft>Installer>Products>E5624C9DEDF6A674C96142A7F8461B52>SourceList - 仍在左侧面板中,找到并删除以下注册表项:
Net - Again 仍在左侧面板中,找到并删除以下注册表项:
Media - 在注册表编辑器窗口的左侧面板中,双击以下项目:
HKEY_CURRENT_USER>SOFTWARE>Microsoft>Installer>Products>E5624C9DEDF6A674C96142A7F8461B52 - 仍在左侧面板中,找到并删除以下注册表项:
SourceList - 在注册表编辑器窗口的左侧面板中,双击以下项目:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows>CurrentVersion>Installer>UserData>S-1-5-21-2674318124-2743851293-4242590628-500>Products>E5624C9DEDF6A674C96142A7F8461B52 - 仍在左侧面板中,找到并删除以下注册表项:
Features - Again 仍在左侧面板中,找到并删除以下注册表项:
InstallProperties - Again 仍在左侧面板中,找到并删除以下注册表项:
Patches - Again 仍在左侧面板中,找到并删除以下注册表项:
Usage - 在注册表编辑器窗口的左侧面板中,双击以下项目:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows>CurrentVersion>Installer>UserData>S-1-5-21-2674318124-2743851293-4242590628-500>Products - 仍在左侧面板中,找到并删除以下注册表项:
E5624C9DEDF6A674C96142A7F8461B52 - 关闭注册表编辑器。
Step 5
搜索并删除这些文件
- %System Root%\Config.Msi\{Random}.rbs
- %System Root%\Config.Msi\{Random}.tmp
- %User Temp%\{Random}
- %Windows%\Installer\inprogressinstallinfo.ipi
- %Windows%\Installer\SourceHash{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- %Windows%\Installer\{Random}.msi
- %Windows%\Installer\{Random}.tmp
- %Windows%\Temp\{Random}.TMP
- %AppDataLocal%\Terpene\OISGRAPH.DLL
- %AppDataLocal%\Terpene\CDLMSO.DLL
- %AppDataLocal%\Terpene\gynoecium.mp3
- %AppDataLocal%\Terpene\incendiary.accdb
- %AppDataLocal%\Terpene\MSOCF.DLL
- %AppDataLocal%\Terpene\msvcr90.dll
- %AppDataLocal%\Terpene\OIS.EXE
- %AppDataLocal%\Terpene\OISAPP.DLL
- %Application Data%\bqe_auth_debug\OISGRAPH.DLL
- %Application Data%\bqe_auth_debug\CDLMSO.DLL
- %Application Data%\bqe_auth_debug\gynoecium.mp3
- %Application Data%\bqe_auth_debug\incendiary.accdb
- %Application Data%\bqe_auth_debug\MSOCF.DLL
- %Application Data%\bqe_auth_debug\msvcr90.dll
- %Application Data%\bqe_auth_debug\OIS.EXE
- %Application Data%\bqe_auth_debug\OISAPP.DLL
要删除恶意软件/灰色软件文件:
适用于 Windows 7、Server 2008 (R2)、8、8.1、10 及 Server 2012 (R2) 系统:
- 打开 Windows 资源管理器窗口。
- 对于 Windows 7 和 Server 2008 (R2) 用户:点击Start>Computer.
- 对于Windows 8、8.1、10及Server 2012用户, 右键单击屏幕左下角,然后点击 File Explorer.
- 在搜索计算机/此电脑输入框中,键入:
- %System Root%\Config.Msi\{Random}.rbs
- %System Root%\Config.Msi\{Random}.tmp
- %User Temp%\{Random}
- %Windows%\Installer\inprogressinstallinfo.ipi
- %Windows%\Installer\SourceHash{D9C4265E-6FDE-476A-9C16-247A8F64B125}
- %Windows%\Installer\{Random}.msi
- %Windows%\Installer\{Random}.tmp
- %Windows%\Temp\{Random}.TMP
- %AppDataLocal%\Terpene\OISGRAPH.DLL
- %AppDataLocal%\Terpene\CDLMSO.DLL
- %AppDataLocal%\Terpene\gynoecium.mp3
- %AppDataLocal%\Terpene\incendiary.accdb
- %AppDataLocal%\Terpene\MSOCF.DLL
- %AppDataLocal%\Terpene\msvcr90.dll
- %AppDataLocal%\Terpene\OIS.EXE
- %AppDataLocal%\Terpene\OISAPP.DLL
- %Application Data%\bqe_auth_debug\OISGRAPH.DLL
- %Application Data%\bqe_auth_debug\CDLMSO.DLL
- %Application Data%\bqe_auth_debug\gynoecium.mp3
- %Application Data%\bqe_auth_debug\incendiary.accdb
- %Application Data%\bqe_auth_debug\MSOCF.DLL
- %Application Data%\bqe_auth_debug\msvcr90.dll
- %Application Data%\bqe_auth_debug\OIS.EXE
- %Application Data%\bqe_auth_debug\OISAPP.DLL
- 定位到该文件后,选中并按 SHIFT+DELETE 将其删除。
- 对所有列出的文件重复上述步骤。
*Note:阅读以下微软官方页面 若上述步骤在 Windows 7 和 Server 2008 (R2) 系统上无效:
Step 6
请搜索并删除以下文件夹:
- %Application Data%\bqe_auth_debug
- %AppDataLocal%\Terpene
要删除恶意软件/灰色软件/间谍软件文件夹:
适用于 Windows 7、Windows Server 2008 (R2)、Windows 8、Windows 8.1、Windows 10 及 Windows Server 2012 (R2):
- 打开 Windows 资源管理器窗口。
- 对于 Windows 7 和 Server 2008 (R2) 用户:点击Start>Computer.
- 对于 Windows 8、8.1、10 及 Server 2012 (R2) 用户: 右键单击 屏幕左下角,然后点击File Explorer.
- 在搜索计算机/此电脑输入框中,键入:
- %Application Data%\bqe_auth_debug
- %AppDataLocal%\Terpene
- 定位到该文件后,选中并按 SHIFT+DELETE 以永久删除该文件夹。
- 对剩余文件夹重复步骤2-3:
- %Application Data%\bqe_auth_debug
- %AppDataLocal%\Terpene
Step 7
使用您的亚信安全产品扫描电脑,删除被检测为以下名称的文件 Trojan.Win32.DOWNLOADER.CC. 若亚信安全产品已将检测到的文件清除、删除或隔离,则无需再执行任何额外步骤;您也可选择直接删除隔离区中的文件。更多信息请访问以下亚信安全支持页面:


