Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Bench Communicator Watcher' = '%PROGRAM_FILES%\Bench\Proxy\pwdg.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Bench Settings Cleaner' = '%PROGRAM_FILES%\Bench\Proxy\cl.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'Coupon Caddy' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'Coupon Caddy-repairJob' = 'wscript.exe "<LS_APPDATA>\Coupon Caddy\repair.js" "Coupon Caddy-repairJob"'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'BService' = '%PROGRAM_FILES%\Bench\BService\bservice.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Wd' = '%PROGRAM_FILES%\Bench\Wd\wd.exe'
- %WINDIR%\Tasks\bench-S-1-5-21-2052111302-484763869-725345543-1003.job
- %WINDIR%\Tasks\bench-sys.job
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%PROGRAM_FILES%\Bench\Proxy\pwdg.exe' = '%PROGRAM_FILES%\Bench\Proxy\pwdg.exe:*:Enabled:Proxy'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%PROGRAM_FILES%\Bench\Proxy\proc.exe' = '%PROGRAM_FILES%\Bench\Proxy\proc.exe:*:Enabled:Proxy'
- '%TEMP%\nsx3.tmp\nsC.tmp' netsh firewall add allowedprogram "%PROGRAM_FILES%\Bench\Proxy\proc.exe" Proxy ENABLE
- '%TEMP%\nsx3.tmp\nsD.tmp' netsh firewall add allowedprogram "%PROGRAM_FILES%\Bench\Proxy\pwdg.exe" Proxy ENABLE
- '%PROGRAM_FILES%\Bench\Wd\wd.exe'
- '%TEMP%\nsx3.tmp\nsB.tmp' cscript.exe //Nologo "chrome_gp_update.js" /product-name="Coupon Caddy" /installation-time="1398273728" /pid="1806" /zone="486312" /czoneid="" /nmhost-dir="%PROGRAM_FILES%\Bench\NmHost" /app-id="38907" /updateip="54.204.28.26" /version="1.0" /enable-extensions /chrome-id="eimgjelekcnjmlhdngkpoibbhpifpmap" /chrome-update-url="http://ei########njmlhdngkpoibbhpifpmap/check/.eJwNyUkKgDAMQNG7ZF1Et72MdIg2HUNaRRDvbpf__ReG6Qk0uCCtICi4UTq1Omlb1tlU-zA5o4AecqECfMZOfn6kckbMmFyNJQdfz8SNrA1MBxfD8P3evSFA.5nWdtB9rPAL_UvTa4o9n27txurM" /close-chrome
- '%PROGRAM_FILES%\Bench\BService\bservice.exe'
- '%PROGRAM_FILES%\Bench\Updater\1.7.0.0\updater.exe' -runmode=addproduct -info="<LS_APPDATA>\Coupon Caddy\info.xml"
- '%TEMP%\nsx3.tmp\nsE.tmp' cscript.exe //Nologo "ping.js" "http://www.in####lping5.info/tbi-ping/fa6a340517d9de2515e3ebda9d325458/66f9d2b6a353c00dfb2dfe9d09ca1920/xriderexe/486312/?pi##################################################" ""
- '%PROGRAM_FILES%\Bench\Updater\updater.exe' -runmode=addproduct -info="<LS_APPDATA>\Coupon Caddy\info.xml"
- '%PROGRAM_FILES%\Bench\Proxy\pwdg.exe'
- '%PROGRAM_FILES%\Bench\Proxy\proc.exe'
- '%TEMP%\nsx3.tmp\nsA.tmp' cscript.exe //Nologo "installer.js" install chrome "" /product-name="Coupon Caddy" /installation-time="1398273728" /pid="1806" /zone="486312" /czoneid="" /nmhost-dir="%PROGRAM_FILES%\Bench\NmHost" /app-id="38907" /updateip="54.204.28.26" /version="1.0" /enable-extensions /chrome-id="eimgjelekcnjmlhdngkpoibbhpifpmap" /chrome-update-url="http://ei########njmlhdngkpoibbhpifpmap/check/.eJwNyUkKgDAMQNG7ZF1Et72MdIg2HUNaRRDvbpf__ReG6Qk0uCCtICi4UTq1Omlb1tlU-zA5o4AecqECfMZOfn6kckbMmFyNJQdfz8SNrA1MBxfD8P3evSFA.5nWdtB9rPAL_UvTa4o9n27txurM" /close-chrome
- '%TEMP%\nsx3.tmp\ns8.tmp' net.exe start schedule
- '%PROGRAM_FILES%\Bench\Updater\1.7.0.0\updater.exe' -runmode=addsystask
- '<LS_APPDATA>\Coupon Caddy\SoftwareDetector.exe'
- '%TEMP%\nsx3.tmp\ns4.tmp' cscript.exe //Nologo "ping.js" "http://www.in####lping5.info/installer-run/fa6a340517d9de2515e3ebda9d325458/66f9d2b6a353c00dfb2dfe9d09ca1920/xriderexe/486312/?pi##################################################" "%TEMP%\nsx3.tmp\pz_info"
- '%TEMP%\nsx3.tmp\ns5.tmp' cscript.exe //Nologo "migrate.js" /iversion=20140505 /programfiles="%PROGRAM_FILES%" /localapps="<LS_APPDATA>" /chrome-dir="" /product-name="Coupon Caddy" /installation-time="1398273728" /pid="1806" /zone="486312" /czoneid="" /nmhost-dir="%PROGRAM_FILES%\Bench\NmHost" /app-id="38907" /updateip="54.204.28.26" /version="1.0" /enable-extensions /chrome-id="eimgjelekcnjmlhdngkpoibbhpifpmap" /chrome-update-url="http://ei########njmlhdngkpoibbhpifpmap/check/.eJwNyUkKgDAMQNG7ZF1Et72MdIg2HUNaRRDvbpf__ReG6Qk0uCCtICi4UTq1Omlb1tlU-zA5o4AecqECfMZOfn6kckbMmFyNJQdfz8SNrA1MBxfD8P3evSFA.5nWdtB9rPAL_UvTa4o9n27txurM" /close-chrome
- '%PROGRAM_FILES%\Bench\Updater\1.7.0.0\updater.exe' -runmode=addproduct -info="%TEMP%\nsq7.tmp"
- '%TEMP%\nsx3.tmp\ns9.tmp' cscript.exe //Nologo "main_installer.js" install /product-name="Coupon Caddy" /installation-time="1398273728" /pid="1806" /zone="486312" /czoneid="" /nmhost-dir="%PROGRAM_FILES%\Bench\NmHost" /app-id="38907" /updateip="54.204.28.26" /version="1.0" /enable-extensions /chrome-id="eimgjelekcnjmlhdngkpoibbhpifpmap" /chrome-update-url="http://ei########njmlhdngkpoibbhpifpmap/check/.eJwNyUkKgDAMQNG7ZF1Et72MdIg2HUNaRRDvbpf__ReG6Qk0uCCtICi4UTq1Omlb1tlU-zA5o4AecqECfMZOfn6kckbMmFyNJQdfz8SNrA1MBxfD8P3evSFA.5nWdtB9rPAL_UvTa4o9n27txurM" /close-chrome
- '%PROGRAM_FILES%\Bench\Updater\updater.exe' -runmode=addproduct -info="%TEMP%\nsq7.tmp"
- '%PROGRAM_FILES%\Bench\Updater\updater.exe' -runmode=addtask
- '%PROGRAM_FILES%\Bench\Updater\1.7.0.0\updater.exe' -runmode=addtask
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%PROGRAM_FILES%\Bench\Proxy\proc.exe" Proxy ENABLE
- '<SYSTEM32>\cscript.exe' //Nologo "chrome_gp_update.js" /product-name="Coupon Caddy" /installation-time="1398273728" /pid="1806" /zone="486312" /czoneid="" /nmhost-dir="%PROGRAM_FILES%\Bench\NmHost" /app-id="38907" /updateip="54.204.28.26" /version="1.0" /enable-extensions /chrome-id="eimgjelekcnjmlhdngkpoibbhpifpmap" /chrome-update-url="http://ei########njmlhdngkpoibbhpifpmap/check/.eJwNyUkKgDAMQNG7ZF1Et72MdIg2HUNaRRDvbpf__ReG6Qk0uCCtICi4UTq1Omlb1tlU-zA5o4AecqECfMZOfn6kckbMmFyNJQdfz8SNrA1MBxfD8P3evSFA.5nWdtB9rPAL_UvTa4o9n27txurM" /close-chrome
- '<SYSTEM32>\cscript.exe' //Nologo "ping.js" "http://www.in####lping5.info/tbi-ping/fa6a340517d9de2515e3ebda9d325458/66f9d2b6a353c00dfb2dfe9d09ca1920/xriderexe/486312/?pi##################################################" ""
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%PROGRAM_FILES%\Bench\Proxy\pwdg.exe" Proxy ENABLE
- '<SYSTEM32>\cscript.exe' //Nologo "installer.js" install chrome "" /product-name="Coupon Caddy" /installation-time="1398273728" /pid="1806" /zone="486312" /czoneid="" /nmhost-dir="%PROGRAM_FILES%\Bench\NmHost" /app-id="38907" /updateip="54.204.28.26" /version="1.0" /enable-extensions /chrome-id="eimgjelekcnjmlhdngkpoibbhpifpmap" /chrome-update-url="http://ei########njmlhdngkpoibbhpifpmap/check/.eJwNyUkKgDAMQNG7ZF1Et72MdIg2HUNaRRDvbpf__ReG6Qk0uCCtICi4UTq1Omlb1tlU-zA5o4AecqECfMZOfn6kckbMmFyNJQdfz8SNrA1MBxfD8P3evSFA.5nWdtB9rPAL_UvTa4o9n27txurM" /close-chrome
- '<SYSTEM32>\cscript.exe' //Nologo "migrate.js" /iversion=20140505 /programfiles="%PROGRAM_FILES%" /localapps="<LS_APPDATA>" /chrome-dir="" /product-name="Coupon Caddy" /installation-time="1398273728" /pid="1806" /zone="486312" /czoneid="" /nmhost-dir="%PROGRAM_FILES%\Bench\NmHost" /app-id="38907" /updateip="54.204.28.26" /version="1.0" /enable-extensions /chrome-id="eimgjelekcnjmlhdngkpoibbhpifpmap" /chrome-update-url="http://ei########njmlhdngkpoibbhpifpmap/check/.eJwNyUkKgDAMQNG7ZF1Et72MdIg2HUNaRRDvbpf__ReG6Qk0uCCtICi4UTq1Omlb1tlU-zA5o4AecqECfMZOfn6kckbMmFyNJQdfz8SNrA1MBxfD8P3evSFA.5nWdtB9rPAL_UvTa4o9n27txurM" /close-chrome
- '<SYSTEM32>\cscript.exe' //Nologo "ping.js" "http://www.in####lping5.info/installer-run/fa6a340517d9de2515e3ebda9d325458/66f9d2b6a353c00dfb2dfe9d09ca1920/xriderexe/486312/?pi##################################################" "%TEMP%\nsx3.tmp\pz_info"
- '<SYSTEM32>\cscript.exe' //Nologo "main_installer.js" install /product-name="Coupon Caddy" /installation-time="1398273728" /pid="1806" /zone="486312" /czoneid="" /nmhost-dir="%PROGRAM_FILES%\Bench\NmHost" /app-id="38907" /updateip="54.204.28.26" /version="1.0" /enable-extensions /chrome-id="eimgjelekcnjmlhdngkpoibbhpifpmap" /chrome-update-url="http://ei########njmlhdngkpoibbhpifpmap/check/.eJwNyUkKgDAMQNG7ZF1Et72MdIg2HUNaRRDvbpf__ReG6Qk0uCCtICi4UTq1Omlb1tlU-zA5o4AecqECfMZOfn6kckbMmFyNJQdfz8SNrA1MBxfD8P3evSFA.5nWdtB9rPAL_UvTa4o9n27txurM" /close-chrome
- '<SYSTEM32>\net1.exe' start schedule
- chrome.exe
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyServer' = 'http=127.0.0.1:3128'
- [<HKLM>\SYSTEM\ControlSet001\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings] 'ProxyEnable' = '00000001'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyEnable' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyEnable' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyServer' = 'http=127.0.0.1:3128'
- <LS_APPDATA>\Coupon Caddy\uninstall.exe
- %PROGRAM_FILES%\Bench\Wd\wd.exe
- %PROGRAM_FILES%\Bench\BService\bservice.exe
- %PROGRAM_FILES%\Bench\Proxy\icon.ico
- %PROGRAM_FILES%\Bench\Proxy\pwdg.exe
- %PROGRAM_FILES%\Bench\Proxy\proc.exe
- %PROGRAM_FILES%\Bench\BService\bhelper.dll
- %PROGRAM_FILES%\Bench\NmHost\nmhost.exe
- %TEMP%\nsx3.tmp\nsProcess.dll
- %PROGRAM_FILES%\Bench\Updater\products.xml
- %TEMP%\nsx3.tmp\nsB.tmp
- %TEMP%\nsx3.tmp\nsA.tmp
- %PROGRAM_FILES%\Bench\NmHost\manifest.json
- %APPDATA%\CanvasProc\2b9967fc5df442d326053c15a3a31808
- %TEMP%\nsx3.tmp\nsE.tmp
- %APPDATA%\CanvasProc\89b4c67965980fd11818aa6480b90244
- <LS_APPDATA>\BenchUpdater\products.xml
- <LS_APPDATA>\proxy.log
- %APPDATA%\CanvasProc\b1a0488e22fe48475e7392172e91de9a
- %APPDATA%\CanvasProc\abb3b8b3368d6d70ab9da841c5e39324
- %TEMP%\nsx3.tmp\nsD.tmp
- %TEMP%\nsx3.tmp\nsC.tmp
- %PROGRAM_FILES%\Bench\Proxy\cl.exe
- %APPDATA%\CanvasProc\0ec2ded50566385e4a682c554061eeca
- %HOMEPATH%\Start Menu\Programs\Coupon Caddy\Uninstall.lnk
- %HOMEPATH%\Start Menu\Programs\Coupon Caddy\Proxy Settings.url
- %TEMP%\nsx3.tmp\ns9.tmp
- <LS_APPDATA>\Coupon Caddy\installer.js
- <LS_APPDATA>\Coupon Caddy\projectInstaller.js
- <LS_APPDATA>\Coupon Caddy\SoftwareDetector.exe
- <LS_APPDATA>\Coupon Caddy\main_installer.js
- <LS_APPDATA>\Coupon Caddy\icon.ico
- <LS_APPDATA>\Coupon Caddy\common.js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\486312[1]
- %TEMP%\nsx3.tmp\System.dll
- %TEMP%\nsx3.tmp\ping.js
- %TEMP%\nsm2.tmp
- %TEMP%\nsx3.tmp\ns4.tmp
- %TEMP%\nsx3.tmp\nsExec.dll
- %TEMP%\nsx3.tmp\md5dll.dll
- %PROGRAM_FILES%\Bench\Updater\1.7.0.0\updater.exe
- %PROGRAM_FILES%\Bench\Updater\updater.exe
- %TEMP%\nsx3.tmp\ns5.tmp
- %TEMP%\nsx3.tmp\ns8.tmp
- %TEMP%\nsq7.tmp
- %TEMP%\nsb6.tmp
- <LS_APPDATA>\Coupon Caddy\chrome_gp_update.js
- <LS_APPDATA>\Coupon Caddy\repair.js
- <LS_APPDATA>\Coupon Caddy\migrate.js
- <LS_APPDATA>\Coupon Caddy\info.xml
- <LS_APPDATA>\Coupon Caddy\sqlite3.exe
- <LS_APPDATA>\Coupon Caddy\chrome_installer.js
- <LS_APPDATA>\Coupon Caddy\gpedit.exe
- %TEMP%\nsx3.tmp\nsB.tmp
- %TEMP%\nsx3.tmp\nsA.tmp
- %TEMP%\nsx3.tmp\nsC.tmp
- <LS_APPDATA>\Coupon Caddy\info.xml
- %TEMP%\nsx3.tmp\nsD.tmp
- %TEMP%\nsx3.tmp\ns5.tmp
- %TEMP%\nsx3.tmp\ns4.tmp
- %TEMP%\nsx3.tmp\ns8.tmp
- %TEMP%\nsx3.tmp\ns9.tmp
- %TEMP%\nsq7.tmp
- 'localhost':1042
- 'co######ache-a.akamaihd.net':80
- 'cd#####-a.akamaihd.net':80
- 'localhost':1036
- 'www.in####lping5.info':80
- 'localhost':3128
- www.in####lping5.info/tbi-ping/fa6a340517d9de2515e3ebda9d325458/66f9d2b6a353c00dfb2dfe9d09ca1920/xriderexe/486312/?pi##################################################
- cd#####-a.akamaihd.net/tb/gz.php?ke#############################################################
- www.in####lping5.info/installer-run/fa6a340517d9de2515e3ebda9d325458/66f9d2b6a353c00dfb2dfe9d09ca1920/xriderexe/486312/?pi##################################################
- co######ache-a.akamaihd.net/check
- DNS ASK cd#####-a.akamaihd.net
- DNS ASK co######ache-a.akamaihd.net
- DNS ASK www.in####lping5.info
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'