|
|
Tweet |
Descrição do Koobface
O Koobface é uma infecção por um vírus de computador, que tira proveito dos usuários, por meio de mensagens nas redes sociais Facebook, Twitter, MySpace e outras. O Koobface ataca os usuário das redes sociais enviando uma mensagem, pedindo para que eles assistam vídeos que os redireciona a sites maliciosos, projetados para espalhar a infecção do Koobface. Muitas das mensagens ilícitas, enviadas através das redes sociais, têm a linha de assunto “Você parece engraçado nesse novo vídeo” ou “Você parece maravilhoso nesse novo filme.” Se o link dentro da mensagem for clicado, então ele vai pedir que você atualize o seu flash player, o que leva ao download de malware. O Koobface é capaz de se infiltrar no sistema dos usuários, através de um falso arquivo de atualização do Flash Player, denominado flash_player.exe. Outras variantes do Koobface são conhecidas como W32.Koobface, W32/Koobface, Networm.Win32.Koobface.b e Boface.
Tipo: Worms
Como Você Pode Detectar o Koobface?
Relatório Técnico do Koobface
Quando novos detalhes sobre o Koobface forem informados por nossos clientes ou descobertos pelo nosso Centro de Pesquisa de Ameaças, esta seção será atualizada.
Os arquivos do Koobface que se seguem, juntamente com os seus respectivos MD5, foram criados dentro do sistema:
| Nome do Fichário | Tamanho de Fichário | MD5 |
|---|
| malware.exe | 16896 | d283e8f8d067de3c67fa8f7d9b1ddaa0 |
| bolivar28.exe | 27136 | a3a42ed2f682e1507b65808969a789a6 |
| che07.exe | 21504 | 9dfc5583555602f799c46229151482ee |
| bolivar30.exe | 26112 | 1f72c797e98b0a9bbfdf2c075eb82c96 |
| bolivar28.exe | 27136 | 3071f71fc14ba590ca73801e19e8f66d |
| pp1.exe | 10752 | 80342b7fd93dafb1c69e3ae7f4e659cb |
| ld02.exe | 12288 | 6cb80fc5c38774a3c160e5caecd2d9f4 |
| ld02.exe | 12288 | e4cdb2f5805440c030b672d8e467c6b5 |
| pp02.exe | 11776 | 7ef3e219c9b5fdee5030c7cf100a3d74 |
| pp03.exe | 11776 | 1c281b0da0ac1ee1a178f05641883886 |
| ld02.exe | 12288 | 4babe2810fbff7bf287cf8b5ec2cd03d |
| mstre12.exe | 23040 | 47b58f78189bfe48b9fe1266ac5a8e4d |
| ld02.exe | 12288 | ae4019b748ad7c940c5609463d7562c6 |
| pp04.exe | 11776 | 0a81d6084022641ce7378e98e08039e1 |
| ld02.exe | 14848 | 06a8c6c3fa5840282428a68a9432407f |
| pp04.exe | 11776 | e3a35f659652af215a0f7dad67a47202 |
| mstre15.exe | 24064 | 179a06510248e4615518fc8a1882a216 |
| ld02.exe | 12800 | 8a060cc355b58e52a99029b420e1f2e4 |
| pp05.exe | 11776 | 246fef8c674335b892d43ad9964b3c89 |
| ld03.exe | 15918 | df03f738864a3d3996c76e0d1e08c877 |
| jopaxx_1238002451.exe | 11776 | 13ad71f35bfc96305b3c412601a92d70 |
| ld03.exe | 14848 | 181725400cfa2fbbcf9f791f4f56cd7c |
| ld03.exe | 14848 | d5b62bbd6e3894864776d00c83a742b2 |
| freddy40.exe | 30720 | 01858c3563187892a9fa8cc8f9d5ea7d |
| ld02.exe | 14848 | bb67ac472c95998ead33fd64e11e4240 |
| pp06.exe | 11776 | a2664be62c4a96c7ae90864577177e96 |
| freddy40.exe | 34816 | 5f4e9d3d02b6d919de5bd6eaef49fd43 |
| mstre15.exe | 24576 | f7a0a7fa555dfbca0ecb14b03ca17c23 |
| mon32.dll | 13312 | bdb4ae092f4d1a75da48c719e5626e34 |
| ld03.exe | 13312 | 128c0b512d0f5c89f82372f383cb4f57 |
| pp06.exe | 11776 | 6b1b7c5cd75f614621f4dd9eb02e1c08 |
| ld02.exe | 15360 | 38010d426eb8abf3895688986ee597d0 |
| freddy40.exe | 27648 | 9ce01e61154b83fc223c51506c43a26a |
| ld07.exe | 13824 | 8d064033e30533ec1a6c859035abd4ea |
| ld07.exe | 13824 | ff84b0e3c74e12c4cb934f7acb636382 |
| pp06.exe | 11776 | cc98c0ecc36905ec2680ff02e5ce27a0 |
| mstre18.exe | 26112 | ea6ba563f950c62b3921afbcf00492a2 |
| freddy41.exe | 35328 | c699bbb6724f7db17d713d01676ab738 |
| ld08.exe | 16896 | 6f9a9e645619e280ed72c6f152edebc7 |
| ld08.exe | 16384 | f39b25ca4653376f4cbcfc95fcda336b |
| ld08.exe | 16896 | e096399e6ed1defdafc26c2a5a990922 |
| freddy41.exe | 35328 | 95b1ba35c15fe664e48b5fb3a424d414 |
| pp06.exe | 11776 | 7ebec2aa2642e8248bdd6806d3ada046 |
| freddy41.exe | 28672 | 17dd0d139315366766535b0773efe21c |
| ld08.exe | 16384 | d9362d909a3fbd26cbc36d138c46f938 |
| mstre18.exe | 26624 | 12abf91ec1a285f39738bb9f1429689b |
| ld08.exe | 14336 | 7a719e9cc2d7114d449f953e7307188b |
| pp06.exe | 10752 | 672b0a13b5d8bb169d69aea80113a9d8 |
| pp06.exe | 10752 | 880159999fac81c50e3bd9eac77c6a93 |
| pp06.exe | 10752 | 2cbf7c043cbceca2eaf7a80833da3991 |
| ld03.exe | 13312 | 1716a2903a2e404c1ce3e0ab6a3605b2 |
| ld08.exe | 14336 | b86fa8557b9e7fae7051d3061586710f |
| ld08.exe | 15872 | 297bd2054e585770b17f98f9f8e4436d |
| ld08.exe | 15872 | 9c43ccf3c327637d409e718b8271a5ad |
| ld08.exe | 15872 | 75b70564cd5cbcd4b60c74a66831272e |
| pp06.exe | 10752 | 74ed5804b9a15970daecd1e940ee72a0 |
| mstre18.exe | 27136 | b92f310eb59e56f4012e09f8381043a3 |
| ld08.exe | 15872 | f724a1c72540316c7d6ad4e37333283c |
| owner.exe | 88576 | bb5208189f45564af76d7810a2e8b59c |
| ld08.exe | 15872 | 0ad992bef94d31a2671b324b10b46a0a |
| freddy42.exe | 33792 | 693ad6797a44d5c945bf8bdc88825a54 |
| ld08.exe | 15872 | 01a67cc5a08b5ad6b7c7a5f0aaa8857d |
| freddy42.exe | 33792 | b05a532c70a0af7d56257765c4adf285 |
| tag11.exe | 23552 | 72513cc7beaed302f6234b08a4e007ec |
| pp07.exe | 11776 | a1f541e3fb3fc53eca236cd788c166fd |
| ld08.exe | 15360 | 9c69a69fafb43630674fd37112145c9b |
| ld08.exe | 15360 | 646886b07a7085efdebbc6335b42a489 |
| ld08.exe | 28672 | 82fd68c7d9ad17bbfc4839a2376c47fc |
| freddy43.exe | 41984 | 1a5f52f9e8b880e32d8b15af11f0712a |
| ld08.exe | 14848 | b5691b911e0b7cbd50f2ea1b53f50e71 |
| pp10.exe | 13824 | 79f0e1f00441c2c59add56892cd288ab |
| sysdll.exe | 16896 | 7ccf13f823e89ae3c838c26ef036712a |
| ld08.exe | 14848 | e4e1ff202fd653c3a7bee6ef2f3579e3 |
| pp10.exe | 13824 | 6517d234c3677fc46c23ba482f32326c |
| ld08.exe | 14848 | 3738c6ae234132d8c98bb4f91b110f22 |
| ld08.exe | 38400 | 78d329c16cf94fe3112104d3cbecbe1b |
| ld08.exe | 14848 | 536baa4ba090af40b8e7da14d20b9b00 |
| freddy43.exe | 41984 | 9eec68fbc9f010447019b906777d9734 |
| ld08.exe | 14848 | 823d3da4c3cd82a92f449a2ad0892af4 |
| ld08.exe | 14848 | e0117daa4784c15a0159b0ccb835a894 |
| ld08.exe | 28672 | 2ddeb53b4463f9ccae0514f7b3190f12 |
| pp10.exe | 13824 | fbbe5ae256b666a13c257deb6db309fc |
| ld08.exe | 14848 | a283238689f3744feb63f243e863b75a |
| mstre19.exe | 28160 | 10b6ba5f8b729e5d671f8dbd9f0c9d79 |
| freddy45.exe | 45056 | 5b5c49e29f156490de6075fde3b32214 |
| ld08.exe | 21504 | 8a583809d3e3ab2d59812e38c174259c |
| mstre19.exe | 28160 | 303676f661365b4152307dfbcdba1950 |
| ld09.exe | 15360 | d28a727544e76dc8efb8d9d31d1ee338 |
| freddy46.exe | 43520 | c6f9e10330f32a6ee398f964b99f87ac |
| pp10.exe | 14336 | 1b7528d0b42c160e68157cab2f1e12ba |
| ld08.exe | 15360 | 3cfb3d7e0ea1370adabe1fd874fe7438 |
| mstre19.exe | 29184 | d9d3f33ca20f169039f03576806ba3a4 |
| ld09.exe | 43008 | e65e0ac8e2046164fe67e9af494bd511 |
| romeo15.exe | 24064 | 3f75e1ea74d04e22095bf72bbf08e95b |
| ld09.exe | 15360 | bc863709c52dc054c2623905f7d564b2 |
| pp10.exe | 14336 | 2ec14048a4a0751274292f8830a78366 |
| ld08.exe | 15360 | e7f55feb47c69defac480e93421d5757 |
| ld08.exe | 14848 | 49d60f7f1c5f0ac73638bd87cd3faba9 |
| ld08.exe | 90112 | 1cbe07a26316280898c04368c149e4f7 |
| pp10.exe | 14336 | efdfc39b972aafc3697eda4b1427af38 |
| captcha7.dll | 16896 | db2e182013c69d8a76df35c18c7723d2 |
| captcha6[1].exe | 22016 | 38f06684141361548056bad6dfd5dac4 |
| ld09.exe | 30208 | acf8916a0bebef0e3ae355fccede5e7e |
| ld09.exe | 22528 | 211c5847f21b1001730cdfc9864b28f8 |
| ld09.exe | 15360 | 3a7248e75aeaa7b5675f588a79d0eacc |
| freddy46.exe | 43520 | ecc3a2670b09c633aff7edd2622a325f |
| mstre19.exe | 29184 | 9058133cc7b1bdb96d11aeab93fe9c6c |
| ld08.exe | 25088 | d1cddcf20555044f84261561accfacb4 |
| ld09.exe | 15872 | 6d9efb1f01a59925f2da52ac07111037 |
| ld09.exe | 15360 | 59b8392f4ed2d67ae561e79db60c6c20 |
| pp10.exe | 17408 | cb7623fcb631d5a89ff941efdca935b1 |
| ld09.exe | 15360 | f7e44e4d1fa2bcb58c7441039f071785 |
| freddy46.exe | 43520 | 1d5f5294f3219f681c546ce9635936e0 |
| ld09.exe | 15360 | 399af67958f5d93a45f8cb1f8545c1d3 |
| pp10.exe | 14336 | cad7ebe9f9332ee41b600ae97143154b |
| freddy46.exe | 44032 | 5a672be5d6cc0f1582d730cc6787e460 |
| pp10.exe | 14336 | fa73fd44260332c377bef917aaea1c8d |
| websrvx.exe | 12800 | 859460f39f1af10de497f7067f3ad4ce |
| SYSDLL.exe | 21504 | 08c9438abaa8e3d6937249f605d22c6d |
| pp10.exe | 14336 | c5de315e2906c699e61a5cd6f0844fa8 |
| ld09.exe | 15872 | 38f09dc3adeb9ec33fe6c49817318f5e |
| freddy46.exe | 43520 | 2b79bf02860d04b9402e51866cfd6ed4 |
| ld09.exe | 15360 | bbd101807ac3c6b3181ade8566d97c60 |
| ld08.exe | 25088 | 9b556a717dddf80039ffd83a9a108e27 |
| pp10.exe | 14336 | 40fca7777f2beca147e4f57c48bab51d |
| ld09.exe | 15872 | 77579a34e9f356affdf751e7fb360a70 |
| ld09.exe | 22528 | ca06174052f54ac410943c9fb4b3663b |
| ld09.exe | 15360 | f8242fd536d967f9ea6120b7df03212d |
| ld08.exe | 14848 | 5359813d34304040b310b80f7e118862 |
| ld09.exe | 15360 | 94c9e2785caf314a43e465002a58ea1a |
| ld08.exe | 24576 | fd9417f5ae9c6dcbbed1a222c7f081c4 |
| ld09.exe | 25600 | 272f56d0b07778f2fb3d4febeec5c719 |
| ld10.exe | 28672 | 3d6dff1503cd0a022c85e4ba773ab05a |
| romeo15.exe | 24576 | 1ecab047088b3298e5d3ab1237eb47a9 |
| ld09.exe | 15360 | 22bda603030f164adefa6301c1141f3e |
| freddy46.exe | 40960 | 938cd403f28cff887a10902f0a5021a7 |
| ld09.exe | 15872 | d7e32fddfd164ca5f316b962893ed54c |
| ld09.exe | 25600 | 53dd7c23e4317f1cd0b4ce7b835e5fdd |
| mstre19.exe | 31744 | 73cfbecc7574895433b61b6dbfc38c5a |
| freddy46.exe | 40448 | b61f6be1fe12387d202f5ed900ebd13a |
| ld09.exe | 15872 | fda02b418349ccc95de52c4bc9af5e9e |
| ld09.exe | 15360 | 0cd5053ef343488cff7659eba6322704 |
| pp10.exe | 13824 | e47b554ada4bc91ee4207e5b46b70632 |
| ld10.exe | 27648 | 09d9e9d0a31ac7eb058bd290e68aba83 |
| ld10.exe | 27648 | ac3a6010fe04be4f98d298f4de9c0ffe |
| freddy46.exe | 41472 | 7eed246e5f4e595bce1b9087cd9401d5 |
| mstre19.exe | 32256 | 40368d84eb56f5b7675149fe785f8ce7 |
| freddy46.exe | 41472 | 5b830d88853b0bb11ed06dc3668eeefa |
| ld10.exe | 28160 | f43a5add14f520dc476e1d11183fddd0 |
| mstre19.exe | 31744 | d3972734b65c6302b6da79dc3759b20f |
| ld10.exe | 14848 | 6357db8c4cdcee9f4c4561ec4869ed96 |
| ld10.exe | 14848 | fb71d7dd05c9cbc3e5d4c101f53f6c35 |
| ld10.exe | 27648 | aa0de4e6c4592a89570cc86b0a2f740f |
| ld10.exe | 14848 | 101f9db0db9d0c00bca9b79ecefa8394 |
| ld10.exe | 27648 | 1243e3ad72b6ac3051dabc639953f609 |
| ld10.exe | 14848 | d17617425b08591bd10c59fd55a1fcd9 |
| ld10.exe | 15360 | 29c043664525955cd0117997524d35b2 |
| romeo15.exe | 24576 | ea4c572b451b6c0bb58b441e9b247cc7 |
| pp10.exe | 14848 | eafeeb8c01a2afdbc1d407fdc07e2315 |
| 12464574.exe | 356925 | ed8037337958700bad092f83e39f7696 |
| ld10.exe | 14848 | 9f10460c06c18cbca67bbdad0c083681 |
| mstre19.exe | 32256 | 07f715ff1894def468e59113ffccff88 |
| romeo15.exe | 24576 | 531632b5724948dfbf5ec2a8cd039ea3 |
| freddy46.exe | 41472 | 86c7bf2af9d6dc041f127163d7d1bb83 |
| 18956874.exe | 355931 | e1ce5335e51d1235a0037a670aa0716a |
| ld08.exe | 15360 | c91a24a66472790f535b89474bb26b0d |
| 18546874.exe | 356908 | 6ea1242f083b2fb076be18f748ed3a54 |
| ld09.exe | 15872 | a2647d8c55ddacc2b48a8bf7c02678c6 |
| ld10.exe | 14336 | be612cd34ba05093501f9c6cc1d7f5cd |
| ld08.exe | 15872 | 5ebcafa6ea97c197f691376a14c3e62a |
| tag12.exe | 27648 | f9b3b0a3753adb63361308f6062f3348 |
| ld10.exe | 14848 | 5ff98b93a684424ab128a265fa32e629 |
| ld10.exe | 27648 | fa8a0b81c56626b4f38b625f6cca2cff |
| ld10.exe | 14848 | 4b98ebe26f9e99758e581b9792702326 |
| ld10.exe | 14848 | 0833a3b90584a083d4856b9a4139598c |
| ld10.exe | 14848 | 4b3af16c9525e33cc8e29226be38f9b9 |
| ld10.exe | 15360 | 0375f15e61f0154bf660ee0f3e021d93 |
| ld08.exe | 13824 | b0bf79ccae8b311d51a7914fbda51196 |
| mstre19.exe | 27136 | c3c28b201ad885fc285decee9d3f2b97 |
| mxvgautilc03.exe | 249856 | 19bcb527535a48469ce0d378d0fa979c |
| ld08.exe | 21504 | 4f10d08da250a0eb134aafd6cf3e1948 |
| ld10.exe | 14848 | 71bf9838f342ddac5a5007eb321a0ec3 |
| ld10.exe | 14848 | 96b3ab0d838707b2d918f3de08749cbe |
| ld10.exe | 14848 | d9dd1049a26839e76e73e5253423b413 |
| ld11.exe | 15360 | 29979b561460c80bc94e0374da419936 |
| ld10.exe | 21504 | 268fc888017f263c0f59cf993f1577dc |
| ld10.exe | 39424 | 4cb0c4bda065987ab134ef9cbb2fade6 |
| ld10.exe | 14848 | ef05bd2309b218c0e7af0e987a1fd344 |
| mstre19.exe | 56832 | 8a03bebcdfb9f76a44d1d2ac18b03236 |
| ld10.exe | 39424 | 8aeebe54ae2b4435bc88227e5a94f145 |
| ld09.exe | 38912 | 0cf80a4b1fffd3dd1d996cbfc897487d |
| pp10.exe | 15360 | 2ac2d41c6be5c57d9d9f7e219a50d720 |
| ld11.exe | 17408 | f7d2a559da160e309131e5de5c6c2a3a |
| freddy49.exe | 33792 | 9ee9e66586eb34fb949d8b14f0f9c859 |
| mstre19.exe | 32256 | 58270dfd18b345176026ff089ca42352 |
| ld11.exe | 28672 | 6b02029e70cbd61634bcf1b1c0520f22 |
| ld12.exe | 31232 | 692e4eaf9a0c6529290e2c881f864ef6 |
| freddy49.exe | 33792 | 3e20c886c1be95452aa040a78b36a1ac |
| ld11.exe | 28160 | 79ce8322b850966f0c64dfdf6189f809 |
| ld11.exe | 30720 | 54a9b720b000de81b0289d282a1c81b5 |
| msb.exe | 124416 | ee97c57484100dca3cff483048fc25ab |
| freddy49.exe | 65536 | 8df3e9016525fe75672aefcf0cc644ac |
| ld12.exe | 42496 | 55a19491a009f2e00da078eb7810e8f8 |
| ld12.exe | 17920 | 1da56acc8e2208f6039056fa0c8f65ea |
| mstre19.exe | 27136 | 8595535b946f18c37051d3a1e8cbac07 |
| ld10.exe | 14848 | 2351f0e2d83317c5d2ac86aed3dc2231 |
| sys.sys | 9344 | bb3a8ce0c32565b2eb3861cc96b12200 |
| ld10.exe | 28160 | 512b619e346688ac923250cc41efb642 |
| ld11.exe | 17408 | 3407c92cf8495e41cca9dd1451778bfa |
| twitty01.exe | 24064 | 82e01a79c4630cf48fb26c7b933496fb |
| freddy49.exe | 65536 | f924f0891538b7c6db359fa94dbc8071 |
| ld12.exe | 23552 | 3adad2a6c7ff94219e4a168ee49814da |
| ld12.exe | 28672 | ef7c6d49ea9b1e96431a077208daf7ab |
| mstre19.exe | 32768 | 1c06659ee72a69ecda84eb22a6e782f9 |
| ld12.exe | 31744 | e3faf3e3cee14355d82695a55b6006b3 |
| pp10.exe | 15360 | c3642a675ab218a287fa9eb0002bcb91 |
| freddy49.exe | 65536 | 54e4957fcdc84208635dce17e5e57333 |
| mstre19.exe | 86016 | 36e604f48553abaf24f408bfc6d5e86c |
| ld12.exe | 17920 | 8804be7160eae56c2220a14ab2ac845b |
| higeorge12.exe | 32256 | 4c5008b75f472744d3a24da2c3c0b077 |
| ld12.exe | 17408 | 3fda52f2d497eb28c436ba7ad171339e |
| ld12.exe | 26624 | b026b852edcd2c82a9bfce015040f4b8 |
| pp10.exe | 13824 | 3bb35e81a165c9d9a898a3980f1d2546 |
| ld12.exe | 28160 | 0e1b770cea28577f96a4fe9e6d3a16a5 |
| ld12.exe | 25600 | 6c3bf52fca0cfa3fa815854c167211de |
| ld12.exe | 28160 | 85e50679f819fe77288e6b0d5a3b0ed2 |
| freddy49.exe | 65536 | d592d592abe21b0d1a156fe52b44a573 |
| ld12.exe | 26624 | 86b8812c347f87de92f2fa5cf1121323 |
| ld08.exe | 14848 | 80da566a09dbf041ab6907ac2439d023 |
| mstre19.exe | 86016 | a13a78ec74cd6bb2cdfe93831fa7a0ef |
| ld12.exe | 25088 | f55359cdb778cf73fd23a2540da67dff |
| freddy49.exe | 65536 | ae10d8bbb91ffe4a40f4be1575983a15 |
| ld12.exe | 26112 | ccdd1fee17311b733fd1544e785897c4 |
| pp10.exe | 15360 | 55440f74c61e84766e21fa0753821c69 |
| freddy49.exe | 65536 | e724a12a82c82c4838cb49210cac3750 |
| ld12.exe | 23552 | 1b47576dee0def0866674886f35cd94b |
| mstre19.exe | 86016 | dbc75c9a74cb848dbb7574a16f0da6b8 |
| ld12.exe | 25600 | fde5ab3d37e176b79fa51bf9b6fa0ef8 |
| ld11.exe | 15360 | 7e68f0e5614d2dbfb7071b0cc306a4b7 |
| mstre19.exe | 86016 | 593d97d55369298a89f80164a0320e60 |
| ld12.exe | 24576 | 17a69cc3cef2b2a706302cc779245062 |
| ld12.exe | 27648 | 973869076a12d137c2ad7e8995478917 |
| ld12.exe | 15360 | 41c315d9ecb2f6fe6623c0675064781a |
| pp10.exe | 15360 | 8fc2e9e715ab829a68b0b8bef3a61b45 |
| freddy49.exe | 34304 | a7f630e74faea0cd9976560eba43e05a |
| mstre19.exe | 86016 | 978f0603a3c135ffb89e8bbea3342b42 |
| ld12.exe | 28672 | 8d24d1c87cb3b7a919a0a394955cf1f0 |
| ld12.exe | 28160 | 5d5f9955a08c0ea8e8483b048a0d399e |
| ld12.exe | 29184 | dde5521ba8508a9228830535da4a59de |
| ld12.exe | 25088 | acf3f3072f04ca1bee8553c0b0a5ea72 |
| pp10.exe | 15360 | 970b65393582a20bc1d0f1823e135831 |
| mstre19.exe | 86016 | 924e5cdb44931e14c99ea0ca1d1ddaef |
| higeorge12.exe | 32256 | 7a3286f980333edbec89e99ff9e3f628 |
| freddy49.exe | 34304 | c1d6b2c9c6065958f40d3e64371e3b4d |
| ld12.exe | 40960 | 91ebbc844c3cd0d49e92462e9476c027 |
| ld09.exe | 40448 | 8c91cf53590428623e1bc5653745f695 |
| ld12.exe | 27136 | d9c46d43deac6a72194d1812049a018d |
| mstre19.exe | 86016 | 5d06f9ed3c0307c8f89c809bbed2bf8d |
| ld08.exe | 14848 | c9f064a3ad8119310a78964004a427d4 |
| ld08.exe | 37888 | eaade7c4a5028a9a85f76686012175a2 |
| ld08.exe | 14848 | 6b8024c81192ecd5b43c538a68b949d7 |
| ld08.exe | 15872 | c82244fd364ffa495b3b31bc7ed4a093 |
| ld08.exe | 15360 | c4dc0a72583a645674467f15e2b1bc24 |
| ld08.exe | 16896 | 67c28aff9dae5d904c2855865e9eadf8 |
| ld08.exe | 38400 | 86035362c9f96bf348b0212511ff319f |
| ld08.exe | 38400 | 9ad620e9252823b9771a3c45db278589 |
| ld08.exe | 14848 | fdc727c51a841e2f6a7ef06bd68fb30c |
| ld08.exe | 38400 | 97e2f2690a75174aea7b671413edb1b5 |
| ld08.exe | 38400 | 7d1641d3c7f567ef12aef99afc15a973 |
| ld08.exe | 38400 | 723370e3d31359a50a07859186187101 |
| ld08.exe | 15360 | fa6ce1024a9c6f397879ff7fe636562e |
| ld08.exe | 38912 | f68dac76ffffbd9e7ad860c3fdde9369 |
| ld12.exe | 16384 | 1dd8d637779921e835c6681819061777 |
| pp10.exe | 15872 | 5a27e56291da40d655d5715f028d6720 |
| freddy53.exe | 35328 | 080c978161416e13fe4767775d7d2c0f |
| mstre19.exe | 86016 | 6e3574af1bb610fc74d54ba6d776fb9e |
| braviax.exe | 11264 | 008bd9eff90a7064dcd6db5854a78a54 |
| braviax.exe | 9216 | 2904512b7c22171e08e5dcd7f9f12af2 |
| freddy54.exe | 34816 | c77d8d34565d5d96b71d0f7f8f06ff8a |
| ld12.exe | 16384 | 7058fe46a59f6282cb026303880fe9e4 |
| freddy55.exe | 35328 | a1cbceccc8693f0ceb903f15d141f8c0 |
| freddy46.exe | 42496 | ad110dc7bb5a0bde0e2f2a717b3f621d |
| freddy46.exe | 42496 | 55f820eb861d74bfe7bfead0a3fce3ce |
| pp10.exe | 13824 | c4ec50a56ec056729e4fdad42028ca2a |
| pp10.exe | 38912 | c6535487d07e8bec88650b060a6f4294 |
| pp10.exe | 37888 | e3ee6a0210dd8b71e2251ddb5da7cf65 |
| pp10.exe | 25088 | 4c30e3089c3d899a16ce8748b4ab230a |
| pp10.exe | 37888 | 0d9ca3f5c5db3df77d6db83d37567dc4 |
| freddy49.exe | 56832 | 551f09578c5f638918f5d61f08f399fc |
| ld11.exe | 37888 | bf4d1bf050ca57252e1fd6eb4844c9b2 |
| freddy56.exe | 37888 | a486652fdd259938494a7e01c048d6de |
| ld12.exe | 25600 | b1ed73c9d8429164e98e502742277436 |
| ld12.exe | 26112 | 8861b090d30d5213359a2da6c64586e5 |
| ld12.exe | 36864 | 0cbdf1eacd4cd814975e143d08535955 |
| ld12.exe | 36864 | 4ebe0d48c1cb8307e788898e5274050c |
| freddy58.exe | 65536 | 29139eabdfe1bb17a5707608bd68c858 |
| pp11.exe | 32768 | 64a4e6737938715e31819a1900db9808 |
| ld12.exe | 27648 | d67a9ae4358e96917471c5f8559924fa |
| ld12.exe | 16384 | 14da5f57d0f88f6bc92aabe83e852998 |
| mstre21.exe | 86016 | 065555614f408f10802d41b8e85b471c |
| ld12.exe | 40960 | 108a48adfd8a1d6b0eca8860c5938777 |
| pp11.exe | 16384 | 12c4de51c5136f7544edf31f2c8cd562 |
| websrvx.exe | 13312 | c38f3c0892f4882f2849fb95165f1126 |
| BrowserCtl.sys | 9472 | f5b00a4f43439253eeab3b8cf62f5f62 |
| freddy58.exe | 65536 | ce10ac25d42f2d3e4a190f8b2981bfad |
| ld12.exe | 16384 | fbe0cf19ebca2e618315e75e8a9710f7 |
| ld12.exe | 40960 | 7f4f84d6931a8a01368662b7aa18800b |
| freddy58.exe | 65536 | 44c39fdc2c4fb500b18a2e4a072d8ebd |
| pp11.exe | 32768 | 96c2ece9fd8593f82669845852bcc363 |
| pp11.exe | 32768 | 9eae4f1bea403078c406b0cec13a54cf |
| ld12.exe | 40960 | 7404889cb1a9b6eb9b95d88301cdb278 |
| freddy58.exe | 65536 | 16a6b87068a0a37cdd35d601c5e258fa |
| pp11.exe | 32768 | e824626fe9aca1057722d2a848993ce8 |
| mstre21.exe | 86016 | f8a8925ba710e8572096f6b19174b1ed |
| ld12.exe | 36864 | 44897377610d4ee43aa9cfc0ca099572 |
| freddy58.exe | 65536 | bffba7ab80694e993d5cb97c7526722b |
| pp11.exe | 32768 | a587a5909053a791adf1adaf904e147a |
| pp10.exe | 15872 | 35a7bb88fa1bcfc04d1661213029685f |
| freddy58.exe | 65536 | a6bd16c36b190e304d9c6bda414eb9b6 |
| ld14.exe | 36864 | 573308d39d6e5321795ab8d895a8c022 |
| freddy59.exe | 69632 | 84db3c047b616e01d3e3e4a5e9662320 |
| freddy60.exe | 69632 | 52883eb2bbde5172d1e574b10af793b1 |
| ld08.exe | 15360 | 19edfe6391c9ac33279ddb88ac2b0709 |
| mstre19.exe | 29184 | 7abd3c00157ae04ca74ebed403eed5bf |
| ld09.exe | 39936 | 70f31546ac3d14eade50c86621276999 |
| ld09.exe | 39936 | 3980e3808bd200bbac55d3b66ec83bb6 |
| ld09.exe | 15360 | ffffae9e80c8bf4b3c8fb5f8881a36d9 |
| ld10.exe | 14848 | 368d91f1bf8cb5f06c5dd1e59fb76984 |
| ld10.exe | 39424 | 04fea78cfb49718bb5bc379c60f4572f |
| ld08.exe | 16384 | 7c422f7929e304b40606c30dbe2717aa |
| ld12.exe | 16384 | 97fa7594799eb654f68f1ca0812f0e92 |
| ld12.exe | 51200 | 5ec1eb15c2106fc42bfd22412f5a4152 |
| captcha7.dll | 16896 | 89c24cdb5370448c7335ecef89286197 |
| ld09.exe | 15872 | 13b6bec689bd63a893d2bde956fdb007 |
| freddy59.exe | 69632 | 84633c75a31afabdbb5c926d208668ef |
| pp11.exe | 32768 | b00017d1467eb1e9b49c39da91c4eae9 |
| websrvx.exe | 13824 | 106fcb0b3055bf8fcd1728617805efbe |
| pp11.exe | 36864 | 340bdaf2cbaa0041169cb45185885789 |
| freddy62.exe | 73728 | deb55e967ec1d6263b20c8f2f15634b1 |
| ld09.exe | 37376 | 9cd4eafe7986fa7a2d139bcc6001df33 |
| ld09.exe | 40448 | efc4b55323a63a56e6607166d88660e4 |
| ld09.exe | 38912 | b608712812d69ae7f0cbc46a96028e54 |
| ld10.exe | 39424 | 5cfa1fb15a801c98be69079cc2fd45fb |
| pp11.exe | 36864 | 25d5377930f61c39299b7ed85dec9489 |
| ld14.exe | 53248 | 6e17f342b9eb7f732e7149b6fed24e34 |
| ld14.exe | 36864 | 0e2d65f2fe186357e02aff78769748e4 |
| nl15.exe | 61440 | b837b9580ef771c8d2bb0843c3933141 |
| mstre21.exe | 86016 | c8c9113038bfab3e5ceb2cefbd5a17b7 |
| ld14.exe | 36864 | f323a442bc60a67253e7f94b6675ed1c |
| ld14.exe | 53248 | 0c46a11db46cba9cca4220bdd1684ea8 |
| freddy62.exe | 73728 | 395ccda1056e8a605a50a0ad7b5b0bd9 |
| freddy62.exe | 73728 | 99f4dcaf9a51b2f455c8e4f1dedfa5db |
| ld14.exe | 53248 | c5068d82f0bff6a7ef18738cbe2260f6 |
| pp10.exe | 15872 | b8af520daa1e2bccf18e2657469d41a2 |
| pp12.exe | 49152 | 313251aa982d4903993b41fe46233774 |
| ld14.exe | 53248 | 6f689c9894e4786c747c4d6136113078 |
| ld12.exe | 26112 | 6ac4cb9d5fed0593e5a0be7684dc2199 |
| mstre21.exe | 86016 | e0a969868b8c95b93388d4962d7bca5b |
| freddy61.exe | 69632 | 6f40a7c152df013caf650128afddbeb5 |
| ld14.exe | 53248 | 1f16770843dd136ab1d3cecfa1cf8f66 |
| freddy61.exe | 69632 | c0083c5440d75638a994a868dcc288d5 |
| ld08.exe | 16896 | b2a99084c06ed507b302fdcb25c8ee2e |
| ld14.exe | 53248 | 12087cabab49d34f22a6bd109ec4cf39 |
| freddy63.exe | 73728 | e798331cc9e57dd68e3f915dc2ecb967 |
| ld14.exe | 53248 | 9d8dec0fa833b9db29db2364f3afd8a3 |
| freddy63.exe | 73728 | fc33da07cd43190aec739e6099c62a0b |
| ld14.exe | 61440 | e4aec4c143eb64659bb56be94f024dc2 |
| freddy65.exe | 77824 | 33a6628624aa83ba96865db4a7ca8880 |
| pp12.exe | 49152 | 37cca234d9706d51f1963d078528344d |
| pp12.exe | 49152 | 4f1339d2b51d6a2a10541ba81cc03b0c |
| webserver.exe | 13824 | f35d37d087be67fe2b9ca6a5c1ba9348 |
| pp12.exe | 49152 | 8790a7b64916393894472f50dfca9cd6 |
| ld14.exe | 53248 | b272476288fe77eb449891bcdd968a46 |
| mstre22.exe | 77824 | 1aff4c1801c31b1d7ef0b59671e60faa |
| pp12.exe | 49152 | 41980035ed9092265b31c0977451f202 |
| ld14.exe | 53248 | 807c695b5e937b00d6e728179e1c009d |
| freddy63.exe | 73728 | f798e551a2e32c878f1b8fe6ae9cf692 |
| ld09.exe | 15872 | ca511203c83ff0371ea75a9efe992f56 |
| ld14.exe | 77312 | 3a32fbe2b704b6ae36fbd35637b2f46e |
| ld14.exe | 61440 | 1648ed2a0788491a30dee9983ea5d886 |
| freddy67.exe | 49152 | 9d83d17842451d6487ec33189e68f4d1 |
| ld15.exe | 39936 | 05e6680de9ae159742e347bfd25f5e78 |
| restorer32_a.exe | 46080 | 09fc0339068dad2e3a02e64a4d26c05f |
| ld11.exe | 15360 | 45c705e0862b6478d3ba84e1f6745822 |
| ld14.exe | 53248 | 167919c0be0d7c4a671af0e0725bb5f2 |
| ld14.exe | 64000 | a39d3ed9146c117f8fd7aefa989c77fc |
| freddy63.exe | 73728 | b24688bb8a35884cf5fd25d515a6eea0 |
| ld14.exe | 53248 | c882a2d0c6e60f66629ccb383bc454e2 |
| ld14.exe | 53248 | 502d94eece81ab655be288ee44b951a1 |
| freddy66.exe | 77824 | 61fc3ea094452f1bc8e626a96a33d9f8 |
| ld14.exe | 43008 | 09764ddd5b6fb4ce58ef491d1e669d8c |
| pp12.exe | 64512 | 98fa9f8a2b67d9d838b040a577d2cfaa |
| pp12.exe | 65024 | 8019f9b796d9a7a7ca599150e2b514aa |
| ld15.exe | 42496 | a4f1bc6634710467f9998db6eb064e75 |
| ld15.exe | 42496 | c8856c6e34125acd803c052a43759dc3 |
| ld15.exe | 42496 | 6cb3e417d7143c4488954729ed16c540 |
| freddy68.exe | 50688 | c2a6275782c2eb0d49bfbaa433fad402 |
| ld08.exe | 16384 | 5cea86dba99c0fe81e31b59f9832026d |
| ld08.exe | 16896 | a10aa3298d2d6d141d21918b0a658f5a |
| ld06.exe | 13824 | 760f48fe01ea394fcffa4327b93b4243 |
| ld08.exe | 28160 | c07945b070852e425acd120b47312c9e |
| ld08.exe | 15360 | 641b99673afd090429aa38adf3d76347 |
| ld08.exe | 28672 | 0d37be10a7a7d1aeb7fec44616c1a567 |
| ld08.exe | 27136 | c68707e73d0e40b4249b8e7de80c38d5 |
| ld08.exe | 30720 | 85d7fc27f5e0f72cf798f228c6eb34b7 |
| ld08.exe | 14848 | 8ad339ed3afc16618e61f46d06244d7f |
| ld12.exe | 16384 | 02e71be45c097b3af45c4802f422453a |
| ld12.exe | 36864 | ec8dfdfebca19460d6b768b9040fb07b |
| ld12.exe | 36864 | 5c5fbb76686bd7421a9a9cc77bef4a3d |
| mstre22.exe | 77824 | 73d0ac3b70673d0b0314b73172a979fa |
| freddy64.exe | 73728 | 94e1d81c5938216570c95e06f0f3b534 |
| freddy65.exe | 77824 | 5f0ba94c199ef01d80880041998e862d |
| sber17.exe | 69632 | be7e1c082a640610bdc62e914234e60b |
| freddy69.exe | 56320 | 66dc85ad06e4595588395b2300762660 |
| ld15.exe | 41472 | abaac343f2c9060614ba3efa502171fd |
| ld15.exe | 38912 | d5071af94a80792665e91a8433443a78 |
| freddy71.exe | 55296 | a3d5881897b4cdcc4d0e19b1efe19b6d |
| pp12.exe | 35328 | 4c77476a9e9124ce0156a2734577ec60 |
| mstre22.exe | 95744 | 57a1694cfed18f7af94a1b972f9283fb |
| pp12.exe | 64512 | eb6f51f48ea429a9966c60ac2975aa31 |
| ld15.exe | 39936 | 17a59dffdef877b0d9c7050dee1364cd |
| freddy70.exe | 56320 | 8282ea8e92f40ee13ab716daf2430145 |
| pp12.exe | 66048 | 201dcc7f7df3efbccc7c05c342a168a7 |
| ld15.exe | 40448 | 224b699ca313163a29eb941d02c6aaac |
| ld15.exe | 38912 | 3b9a8d791862f5539151e5c211a197f1 |
| sber18.exe | 69632 | 505991ed002c1af87937e69aefa7c2ff |
| ld15.exe | 41984 | 02add9660cd890d527bd8404260455ae |
| freddy70.exe | 57344 | 79ba29c855c1d0a2f16f7760cb7a3ad2 |
| ld15.exe | 38912 | 89469837f930899c428b4e5622eb15b8 |
| ld15.exe | 38912 | 5fada448a2c91d50df1f46c1f013e140 |
| freddy39.exe | 29184 | 6da3b29f7a1f43c82420ba1ccca190a3 |
| freddy48.exe | 41984 | 45c4b8abe0e5d1256d93c12e78679a74 |
| freddy56.exe | 37376 | 6d8a8b480507e7d1b21059ec473a3450 |
| freddy60.exe | 69632 | 8f8a143e51c1a600080e938ab843988d |
| ld15.exe | 41472 | 2ce0893f0921c77f61c212023b41eb94 |
| pp12.exe | 35328 | 00a717c22fbe961085183dae5b7a376f |
| tag14.exe | 47616 | 28b0c7a6fb0aa177039810d0d7f0781f |
| ld15.exe | 40960 | d4d7d79fd539fce54e0a56314654947f |
| pp12.exe | 36864 | 1363d7067535133dc2df4bc23dfe990b |
| pp12.exe | 36096 | c8c43d947f70eb2a239de6eceee31040 |
| freddy72.exe | 55552 | 37e1f4080031a48a85c1d09def21739d |
| ld15.exe | 40960 | ad89bdba03c6d10d15e54cf800005c39 |
| pp12.exe | 35328 | d741775326c1c7e663d42cf12669936f |
| freddy71.exe | 56832 | e3d7c61bc5a49b916af692402c7b5d18 |
| ld15.exe | 40704 | 79cf073618a9a72c24b376e43f2c6964 |
| pp12.exe | 38656 | 6cf1d5f1f760a54b97cec7b9dd5feaef |
| pp12.exe | 38144 | 8b7864a73388165bb7e41b9627bfdc23 |
| pp12.exe | 36352 | e5775ee4f18d390f4d9aa57964b8047f |
| freddy73.exe | 55808 | 95c4c6864b233db4173c0b72781494b0 |
| ld15.exe | 41984 | 1812a47e3dd751b270f33e614dfd5244 |
| freddy75.exe | 57856 | 801c5b181c8890e8bbe2fa97f17904c2 |
| ld15.exe | 41984 | 69ccf90fec56313c187eb1810bedefca |
| ld15.exe | 41984 | 4ea0fdff8a48cd9c9fad91cb1657cc17 |
| ld15.exe | 42496 | c1b0e05e814dbe983451c24eaa54b5fc |
| freddy75.exe | 55296 | b8664d0c6eaa236cd9ca03c501452eca |
| mstre24.exe | 49664 | 0b2654102546d76468c057155ccca13a |
| pp12.exe | 36352 | bd20ff7c6273e8f27e089e3d12b28306 |
| ld15.exe | 42496 | 22ddb20f5a3b8ee8d86f79ba8eea6142 |
| freddy73.exe | 58368 | 39749687032bd601433bdadc3f1bbfa7 |
| pp12.exe | 38912 | d70167b876e609c821aa063cf9561a0b |
| ld15.exe | 40960 | 5fa0959c5beeb42d267fbc65bf49090b |
| ld15.exe | 53248 | 7c62944babc7a656f17323deabaeba81 |
| ld15.exe | 40960 | 625a1d6c6e18b0ba261cb046ed87637a |
| ld15.exe | 40960 | 363afc41da920917eb6b4f7262e2181b |
| ld15.exe | 40960 | 8c6a8e94c3f7b18220a79a26e775494d |
| freddy74.exe | 57344 | b28e967136727edb5e8e285c4433214d |
| pp12.exe | 36352 | 5a57ef8732d5ef1bdeaf85e826089201 |
| ld15.exe | 41472 | 677f0415c0569e312adc1c738f0c3d24 |
| mstre23.exe | 53248 | 9effff1d92cf1edd113452efc159c035 |
| ld15.exe | 41472 | a1e8ef83ec20efdab384efd64f1b6718 |
| ld15.exe | 41472 | 95bc823b42fe5adabd02873cc90a4f6d |
| ld15.exe | 42240 | fdf1ce79e03dfec404e326e5ffd05fad |
| freddy73.exe | 56064 | e4ae121421c59e5419788779bf6c4417 |
| mstre24.exe | 53760 | 24f590d612f3be210603dee3c298ee28 |
| ld15.exe | 43008 | f62a51847c44849eeb2e0b37b934b28d |
| pp12.exe | 36352 | 4ca6e26e7e036ed662853699408f84ee |
| pp12.exe | 38400 | b805df94c52ba9a2f557922e564abbe1 |
| freddy75.exe | 58368 | b79bc24bf58fc5d50d4fa0ebe63c816a |
| mstre24.exe | 51712 | e007bea5e79c001f3a0383a8dcba9bdc |
| ld15.exe | 43008 | 91ecda20320c2764914aa810e4492262 |
| freddy75.exe | 38912 | 0b5a2e6227c9879fb21f62eec3223eed |
| tag14.exe | 43776 | 3067a205b055e6b417671b33ce9e867e |
| ld15.exe | 41472 | bcd7dff0eda9ed85945733cf7b051a6b |
| fio32.sys | 59520 | b5897245e34df833a207241a11c065f8 |
| ld15.exe | 41984 | 48c1599265b6a5135b9e3e04cbc9cac5 |
| pp12.exe | 36352 | 66ad9a3e57fc04bc9ab53ddda92a8dcd |
| freddy75.exe | 59904 | c39373d28fc6c133bd305e3cdd738d25 |
| mstre24.exe | 50688 | 8ba379f348882c4f985928e15dcab7e2 |
| pp12.exe | 38912 | ab28a26a31391f2e477a4090eb8f7421 |
| mstre24.exe | 53760 | ac30d68eaff97667631d1f958be22558 |
| ld15.exe | 41472 | 8ebc5979d2e71c2a894bcd39744e3bbc |
| fio32.sys | 37632 | 3ac9dd624ca70a34102e77a86463422c |
| fio32.sys | 35968 | a2c0d183868f63ffd7ddcddc9b0a1cec |
| fio32.sys | 35968 | 4085aff317574bb5def3920ffd38f4c9 |
| fio32.sys | 56064 | 57880f3dc0033b346021e46987917ce8 |
| fio32.sys | 59520 | 716486fd24fe7650a5a42794390e76c0 |
| mstre24.exe | 52736 | 87af8fdc87a2fb23f8088c9d4d0fed70 |
| pp12.exe | 38912 | 9bc9652e2e1c633bcbdcf9594956d74c |
| sber18.exe | 90112 | 26d50e9034d5983ae941601207bb50eb |
| ld15.exe | 41472 | a5b0f93a26de58a5e8e6ed37804a1f11 |
| ld15.exe | 43008 | 5cdef39df4850fe9d241490fe4305df2 |
| mstre25.exe | 58368 | 040ffef821932d55cea2c81b8f085274 |
| ld16.exe | 39936 | 73b443191756e5acfea400e17e1f0b8f |
| freddy77.exe | 56320 | 558479309dd8ff5b66455c4e33a319e1 |
| ld16.exe | 39936 | 8e86293682202752756bb27d77204051 |
| ld15.exe | 43008 | 6bdb0c0f5071fde81f602aa31e3ff96a |
| pp13.exe | 31232 | 80d55a2efe065b47cf5bff2d5486db99 |
| mstre26.exe | 55808 | 9d728770d2520b989d10a38038b857d8 |
| ld16.exe | 38400 | 8345964fb24b3c6e00cb9a22af02c57a |
| freddy75.exe | 55296 | b50a54b54e64f87ac1dc5d3efff0662f |
| ld16.exe | 39424 | daeb8f76e8b1b555917fb4cd8e1818e2 |
| hippy16.exe | 31232 | 2dd21bc186a3e29fd43bfe5239d4c8b8 |
| freddy79.exe | 57344 | e5a0c92e1708a3c8b260d64c1695b678 |
| pp13.exe | 32256 | da3aff4293fe251bcf06ba1c2d52d761 |
| mstre26.exe | 55296 | ca87c0e3581e0c968e394891af799128 |
| ld16.exe | 39424 | 3b076603329c1384db94c112e4888717 |
| freddy79.exe | 60928 | b99cc1b4cc4baad71bc271c90b447938 |
| mstre26.exe | 60416 | 2fdfa90344db75f1211594854961c063 |
| pp14.exe | 49152 | 0651f65c2afd804591c17c92e40ae405 |
| ld16.exe | 44544 | 45cca6bbdb223c84cbfcfe5592674825 |
| ld16.exe | 53248 | 62af1a8692cd78fec8402de3f08bceda |
| pp14.exe | 49152 | d641554b20c6dd169bc74dc5534380d7 |
| webserver.exe | 13312 | d34d684c93e8ea36631e650eb2e1854c |
| pp14.exe | 33792 | 51ab5c878892a48bd8ff4561bfd0bb2b |
| freddy79.exe | 39424 | 971e93d612beb14579784820ea1f340c |
| sber20.exe | 83968 | 45043f2c55f3566b2ad967c79a9e918c |
| ld16.exe | 38400 | 146c15c79c425217372e6bfc4e18b0d7 |
| pp14.exe | 39936 | 617791822bb6aceb2896647cc6b4e9a4 |
| freddy79.exe | 57344 | 76beebe269b357258e6124aa6f6c29ed |
| ld15.exe | 41472 | 75f2ab454cd8a9fb4cd35b8e12514eb1 |
| pp14.exe | 32256 | 4fa7b9c5d4e304ef7a72b3bb7fd8230a |
| freddy37.exe | 29696 | 1acbe1219efa9d2bbf206fd98f734bd9 |
| pp14.exe | 29696 | 18a7aea102a27fcf283dd3ba3c5b2e4b |
| ld16.exe | 33792 | af990351412ac6ded7963a96dc57a750 |
| freddy81.exe | 52736 | e73461386d4ab0c35db0fbe1b5173ea1 |
| pp14.exe | 34304 | 469a72801eac313ee4a10108a1324d7c |
| ld16.exe | 33280 | 972a3a703726fce606a21030ba9f12e5 |
| freddy80.exe | 52736 | fd65ffa25073c3173b70c9f0e8a26a6f |
| pp14.exe | 38400 | e50aacb512d6ff88deeb2a42bd8ef5c2 |
| pp14.exe | 31744 | 9f87ef8da42e93964d34bc413d2eb3b0 |
| ld16.exe | 36864 | 01c7fbce1d88ec552c9d397f6d4f9828 |
| ld16.exe | 36352 | c0e67df9ff1006d2524ab0adc80d484b |
| freddy82.exe | 54784 | 4480714ab2a9d008db4971e60c5f916d |
| pp14.exe | 31744 | c2fd5d4c719dd6350d039fad6c805df2 |
| ld16.exe | 42496 | 8c7a753310833c2ac59200a69105d5cb |
| freddy82.exe | 60928 | 83395e3bd7c80db76a78b80cfda4443a |
| pp14.exe | 39936 | 8ba8a235dbb6febace0e09e75efb049a |
| ld16.exe | 42496 | 45a9e2928ee5af7f1025abccfc987785 |
| pp14.exe | 39936 | 637693b8af05fe07d301d10470f2a3b6 |
| pp1.exe | 10752 | 191f1d254ea5a9278e9cde324e7cc342 |
| freddy81.exe | 55296 | ba0307264892acd0973c2ba2cf6e1e57 |
| Filter.sys | 37760 | 0fc4bb6fbd8bab893e779b79b7fce6d1 |
| pp14.exe | 40960 | 0663ffb6fa3e7195a10e30e3317df9fd |
| freddy101.exe | 53760 | 98013087ef53cb875ea86eb3bf2df6af |
| ld16.exe | 39936 | ded34526bedb0db9d8853dc7fd55e04e |
| freddy101.exe | 54272 | 4b5f34a85e19102c76f1647a55b0bea9 |
| pp14.exe | 34304 | 4bdc9d190698f608dcd2f3bbce961662 |
| freddy101.exe | 54272 | e4025e9a7323cd6d2419efa40a17a4e8 |
| freddy101.exe | 55808 | 2ee3630456390a956aefa85050871890 |
| ld16.exe | 41472 | 66b767298d5be474afd0cc7ec59fcb6b |
| pp14.exe | 40448 | e0428c2bd79c843c827b137c9f96bc9d |
| romeo15.exe | 23552 | a3695979a9f7eab2a55470d325d5bc1d |
| freddy101.exe | 58368 | 107c26dd443d7719ed1b0bc4c0441489 |
| mstre18.exe | 26624 | ba4cf680ee5cb44a57ef74814404ce70 |
| bill103.exe | 66560 | 3cb64c435c30ee0dc395496d79e98d23 |
| mstre21.exe | 86016 | 611d4368354ef1877d6244cffb0e89b1 |
| bill103.exe | 68608 | abdeafa16c61527208d762b042fa0dfd |
| freddy79.exe | 57856 | 4cfddaf3394fe489d3c6c593f737af81 |
| ld16.exe | 39936 | 8453078ec28542d60a880b029b081d61 |
| webserver.exe | 13824 | 6d32cc32a829887edb526ca76001b390 |
| webserver.exe | 13824 | 47b7441312b7e8b5f1571f15ca4a1f9b |
| webserver.exe | 13312 | 0eafb3eba01bea3c0910dd45458ce129 |
| webserver.exe | 13312 | 78ab5a0bb1e2c4fe203e86c61dc8675f |
| webserver.exe | 14336 | 3d46ce2b1ce36852f4808d1f2fc472cf |
| webserver.exe | 15360 | e831f7d2ee9c0905e94783bd8fc408b3 |
| bill103.exe | 67072 | f0f7ec03e6cd5be3b0367915ad5ee062 |
| bill103.exe | 67584 | f9d3cf1195a7a86a1adbb9dffa24176e |
| bill103.exe | 68096 | 51a811e116e04b2e7621896c46434b10 |
| kenny14.exe | 21504 | 6a4f4328cd6168a8cb20b9c473fb2607 |
| kenny14.exe | 21504 | 7bb3f62de80c2585516704dfb2c1f610 |
| kenny17.exe | 19456 | a5581a695cc8c52157aa9d413032bbb8 |
| mstre15.exe | 24064 | 52604861d80c0923972f25eed6fad6fd |
| bill103.exe | 67072 | 2d36da6fd4427086352fbcf327f5b628 |
| o6ko.sys | 32768 | 97422c4896c4ce5cf4ff38500918c069 |
| bill103.exe | 66560 | 5c1082d445565a52ec15c95f5e099c49 |
| bill104.exe | 65536 | 028e9f6c6ecc8c60986ff723b1fc3404 |
| fbtre6.exe | 17408 | 1fa5b4771e4d4e9f6dff52521b2d9bfd |
| che6.exe | 21504 | 8ea9e442bf3a56a171086a58d23a3aa3 |
| bolivar27.exe | 29696 | cbd1298e9c3a9d62e0404c18593479b3 |
| imapioko.sys | 32768 | c263d7ffd637f446fa9668337cb665aa |
| bill104.exe | 67584 | 0a69c51dfeb1db1a49c4d3a830eac2c6 |
| bill103.exe | 68096 | 7e55a7568775c0938e54beef4a52df18 |
| bill104.exe | 65536 | 78cae12b6183ec9c362906a4eea0b5b7 |
| bill104.exe | 65536 | 0e8206a4dbf6168c81ccd3e1e0068002 |
| bill104.exe | 65536 | 7650906d1508fc9536d4a039b3b57698 |
| bill104.exe | 65024 | dd43b4bf3effba60e3443483f841369c |
| bill105.exe | 62976 | f5927d6e2879c1ac0dddfe8876fadd99 |
| bill104.exe | 71680 | 7aab063c2b270f335ff91b288530bad0 |
| bill106.exe | 51712 | eb5b7849efbe793e13ebf102eecd77b9 |
| ld12.exe | 40960 | c61c7bc8dbd7cb4c9ab85788a53bfbf3 |
| ld15.exe | 41984 | d2ecdcd9e9af36f9c7de0e66ab210da0 |
| dl1.exe | 324096 | e9d1edceed62b10b8324d2ae46f8bc6f |
| freddy63.exe | 73728 | c75143ef25715f8bee5e0ea533b5abbc |
| freddy60.exe | 69632 | 6b12dd8fe4090f3032e9f225e5d2ff6f |
| ld14.exe | 36864 | 2eac50e4166221fb666ae269e21e66a3 |
| bill104.exe | 65536 | 135b81301b1b28702683de9c277dc8e5 |
| bill103.exe | 67072 | 0dcd44f83baa0d49300dbb8d6e07657b |
| imapioko.sys | 33280 | 68e8dc5dab5ab3f7b99ccade1ab8e7c6 |
| bill106.exe | 64512 | 702b9ecdb7ce5323afb8bb4e46bbe102 |
| mrxoko.sys | 32768 | c52a4b688b5ba67181cd809c5204a18c |
Vídeo de Demonstração do Koobface
Clique no vídeo “Como o Koobface Infecta o seu Computador” para ver a infecção do Koobface em ação! Veja através dos olhos de um usuário da Internet, que não faz a menor ideia de que está sendo vitimizado pelo Koobface.
No final desse vídeo, há um link para baixar o Escaner Gratuito do SpyHunter. O Escaner Gratuito do SpyHunter só é usado para detecção. Para remover o Koobface, você precisa comprar a versão completa do SpyHunter.
Dica: Ligue o som e assista o vídeo usando a tela inteira para entender melhor como o Koobface infecta um computador. Esse vídeo contém teclas que podem ser clicadas.
O Koobface tem normalmente na memória, os processos que se seguem:
- %WinDir%\bolivar28.exe
- %WinDir%\system32\nScan\ekrn.exe
- %WinDir%\system32\splm\lmfunit32.dll
- %WinDir%\system32\nScan\ekrnScan.dll
- che07.exe
- %SYSTEMROOT%\bolivar30.exe
- ld02.exe
- %SYSTEMROOT%\pp02.exe
- pp04.exe
- %SYSTEMROOT%\mstre15.exe
- ld03.exe
- pp06.exe
- %SYSTEMROOT%\pp06.exe
- ld08.exe
- %SYSTEMROOT%\freddy41.exe
- freddy42.exe
- %SYSTEMROOT%\pp07.exe
- %SYSTEMROOT%\system32\sysdll.exe
- mstre19.exe
- freddy46.exe
- captcha6[1].exe
- freddy49.exe
- pp11.exe
- ld14.exe
- freddy62.exe
- pp12.exe
- freddy65.exe
- freddy67.exe
- freddy69.exe
- ld06.exe
- tag14.exe
- freddy39.exe
- freddy73.exe
- mstre23.exe
- pp13.exe
- freddy79.exe
- freddy37.exe
- freddy80.exe
- bill104.exe
- kenny14.exe
- imapioko.sys
- C:\Windows\fbtre6.exe
- %WinDir%\system32\nScan\ecls.exe
- %WinDir%\system32\splm\mcaserv32.dll
- %WinDir%\system32\nScan\ekrnEpfw.dll
- bolivar28.exe
- bolivar30.exe
- %SYSTEMROOT%\pp1.exe
- pp02.exe
- %SYSTEMROOT%\pp03.exe
- %SYSTEMROOT%\pp04.exe
- %SYSTEMROOT%\pp05.exe
- %SYSTEMROOT%\freddy40.exe
- mstre15.exe
- %SYSTEMROOT%\ld07.exe
- %SYSTEMROOT%\ld08.exe
- %SYSTEMROOT%\mstre18.exe
- pp07.exe
- pp10.exe
- %SYSTEMROOT%\freddy43.exe
- ld09.exe
- captcha7.dll
- ld11.exe
- higeorge12.exe
- mstre21.exe
- freddy60.exe
- nl15.exe
- freddy61.exe
- ld15.exe
- freddy66.exe
- freddy64.exe
- sber18.exe
- freddy48.exe
- freddy71.exe
- mstre24.exe
- mstre25.exe
- hippy16.exe
- pp14.exe
- freddy81.exe
- bill103.exe
- kenny17.exe
- sber20.exe
- che6.exe
- bill106.exe
- %WinDir%\system32\splm\ncsjapi32.exe
- %WinDir%\system32\splm\kbdsapi.dll
- %WinDir%\system32\nScan\ekrnAmon.dll
- %WinDir%\system32\nScan\ekrnEmon.dll
- %SYSTEMROOT%\bolivar28.exe
- pp1.exe
- %SYSTEMROOT%\ld02.exe
- pp03.exe
- %SYSTEMROOT%\mstre12.exe
- pp05.exe
- %SYSTEMROOT%\ld03.exe
- freddy40.exe
- ld07.exe
- freddy41.exe
- mstre18.exe
- tag11.exe
- freddy43.exe
- %SYSTEMROOT%\pp10.exe
- freddy45.exe
- romeo15.exe
- ld10.exe
- ld12.exe
- freddy58.exe
- freddy59.exe
- websrvx.exe
- freddy63.exe
- mstre22.exe
- freddy68.exe
- sber17.exe
- freddy70.exe
- freddy56.exe
- freddy72.exe
- freddy75.exe
- fio32.sys
- mstre26.exe
- ld16.exe
- freddy54.exe
- freddy101.exe
- o6ko.sys
- fbtre6.exe
- bolivar27.exe
O Koobface criou as entradas de registro que se seguem:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\”systray” = “c:\windows\mstre6.exe”
- HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden: “2″
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Intelli Mouse Pro Version 2.0B\StubPath: “%WinDir% \System32\splm\ncsjapi32.exe”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\”systray” = “C:\Windows\fbtre6.exe”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\*Intelli Mouse Pro Version 2.0B*: “%WinDir% \System32\splm\ncsjapi32.exe”
- HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\RunOnce\*Intelli Mouse Pro Version 2.0B*: “%WinDir% \System32\splm\ncsjapi32.exe”
- HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\Navigating
- HKEY_USERS\Software\Microsoft\Windows\nScan32\ExecuteDate: “14\8\2008″
- HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run\Intelli Mouse Pro Version 2.0B: “%WinDir% \System32\splm\ncsjapi32.exe”


Koobface
Leave a Comment
Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.