Техническая информация
- <SYSTEM32>\tasks\coccocupdatetaskmachinecore
- <SYSTEM32>\tasks\coccocupdatetaskmachineua
- [HKLM\System\CurrentControlSet\Services\coccoc] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\coccoc] 'ImagePath' = '"%ProgramFiles(x86)%\CocCoc\Update\CocCocUpdate.exe" /svc'
- [HKLM\System\CurrentControlSet\Services\coccocm] 'ImagePath' = '"%ProgramFiles(x86)%\CocCoc\Update\CocCocUpdate.exe" /medsvc'
- 'coccoc' "%ProgramFiles(x86)%\CocCoc\Update\CocCocUpdate.exe" /svc
- 'coccocm' "%ProgramFiles(x86)%\CocCoc\Update\CocCocUpdate.exe" /medsvc
- %TEMP%\71d5.tmp\71d6.tmp\71d7.bat
- %ProgramFiles(x86)%\coccoc\update\2.9.1.9\coccocupdateondemand.exe
- %WINDIR%\temp\cabfc77.tmp
- %WINDIR%\temp\tarfc78.tmp
- %WINDIR%\temp\cab12c7.tmp
- %WINDIR%\temp\tar12c8.tmp
- %WINDIR%\temp\cab1307.tmp
- %WINDIR%\temp\tar1308.tmp
- %WINDIR%\temp\cab280f.tmp
- %WINDIR%\temp\tar2810.tmp
- %WINDIR%\temp\cab4071.tmp
- %WINDIR%\temp\tar4072.tmp
- %WINDIR%\temp\cab4092.tmp
- %WINDIR%\temp\tar4093.tmp
- %WINDIR%\temp\cab558b.tmp
- %WINDIR%\temp\tar558c.tmp
- %WINDIR%\temp\cab55bb.tmp
- %WINDIR%\temp\tar55bc.tmp
- %WINDIR%\temp\tarb5d4.tmp
- %WINDIR%\temp\cabb5d3.tmp
- %WINDIR%\temp\tara0dc.tmp
- %WINDIR%\temp\caba0db.tmp
- %WINDIR%\temp\tara0ab.tmp
- %WINDIR%\temp\caba0aa.tmp
- %WINDIR%\temp\cab8bc1.tmp
- %WINDIR%\temp\tar8bc2.tmp
- %WINDIR%\temp\tar7fcf.tmp
- %WINDIR%\temp\cab7fce.tmp
- %WINDIR%\temp\tar6ad6.tmp
- %WINDIR%\temp\cab6ad5.tmp
- %WINDIR%\temp\tar6aa5.tmp
- %WINDIR%\temp\cab6aa4.tmp
- %WINDIR%\temp\cabb604.tmp
- %ProgramFiles(x86)%\coccoc\update\2.9.1.9\coccocupdatebroker.exe
- %ProgramFiles(x86)%\coccoc\update\2.9.1.9\coccocupdatesetup.exe
- %ProgramFiles(x86)%\coccoc\update\coccocupdate.exe
- %APPDATA%\portable_util.exe
- %APPDATA%\coccocsetup.exe
- %APPDATA%\setup.exe
- %ProgramFiles(x86)%\coccoc\temp\gut78b8.tmp
- %ProgramFiles(x86)%\coccoc\temp\gum77fc.tmp\coccocupdate.exe
- %ProgramFiles(x86)%\coccoc\temp\gum77fc.tmp\coccoccrashhandler.exe
- %ProgramFiles(x86)%\coccoc\temp\gum77fc.tmp\coccoccrashhandler64.exe
- %ProgramFiles(x86)%\coccoc\temp\gum77fc.tmp\coccocpdate.dll
- %ProgramFiles(x86)%\coccoc\temp\gum77fc.tmp\coccocupdatebroker.exe
- %ProgramFiles(x86)%\coccoc\temp\gum77fc.tmp\coccocupdateondemand.exe
- %ProgramFiles(x86)%\coccoc\temp\gum77fc.tmp\coccocupdatecomregistershell64.exe
- %ProgramFiles(x86)%\coccoc\temp\gum77fc.tmp\psmachine.dll
- %ProgramFiles(x86)%\coccoc\temp\gum77fc.tmp\psmachine_64.dll
- %ProgramFiles(x86)%\coccoc\temp\gum77fc.tmp\psuser.dll
- %ProgramFiles(x86)%\coccoc\temp\gum77fc.tmp\psuser_64.dll
- %ProgramFiles(x86)%\coccoc\temp\gum77fc.tmp\coccocupdatecore.exe
- %ProgramFiles(x86)%\coccoc\temp\gum77fc.tmp\coccocpdateres_en.dll
- %ProgramFiles(x86)%\coccoc\update\2.9.1.9\psmachine.dll
- %ProgramFiles(x86)%\coccoc\update\2.9.1.9\psuser_64.dll
- %ProgramFiles(x86)%\coccoc\update\2.9.1.9\psuser.dll
- %ProgramFiles(x86)%\coccoc\update\2.9.1.9\coccocpdateres_vi.dll
- %ProgramFiles(x86)%\coccoc\update\2.9.1.9\coccocpdateres_en.dll
- %ProgramFiles(x86)%\coccoc\update\2.9.1.9\coccocupdatecomregistershell64.exe
- %ProgramFiles(x86)%\coccoc\update\2.9.1.9\coccoccrashhandler.exe
- %ProgramFiles(x86)%\coccoc\update\2.9.1.9\coccoccrashhandler64.exe
- %ProgramFiles(x86)%\coccoc\update\2.9.1.9\coccocupdatecore.exe
- %ProgramFiles(x86)%\coccoc\update\2.9.1.9\coccocpdate.dll
- %ProgramFiles(x86)%\coccoc\update\2.9.1.9\coccocupdate.exe
- %ALLUSERSPROFILE%\coccoc\uid
- %ProgramFiles(x86)%\coccoc\temp\gum77fc.tmp\coccocupdatesetup.exe
- %ProgramFiles(x86)%\coccoc\temp\gum77fc.tmp\coccocpdateres_vi.dll
- %ProgramFiles(x86)%\coccoc\update\2.9.1.9\psmachine_64.dll
- %WINDIR%\temp\tarb605.tmp
- %WINDIR%\temp\cabfc77.tmp
- %WINDIR%\temp\tarb5d4.tmp
- %WINDIR%\temp\cabb5d3.tmp
- %WINDIR%\temp\tara0dc.tmp
- %WINDIR%\temp\caba0db.tmp
- %WINDIR%\temp\tara0ab.tmp
- %WINDIR%\temp\caba0aa.tmp
- %WINDIR%\temp\tar8bc2.tmp
- %WINDIR%\temp\cab8bc1.tmp
- %WINDIR%\temp\tar7fcf.tmp
- %WINDIR%\temp\cab7fce.tmp
- %WINDIR%\temp\tar6ad6.tmp
- %WINDIR%\temp\cab6ad5.tmp
- %WINDIR%\temp\tar6aa5.tmp
- %WINDIR%\temp\cab6aa4.tmp
- %WINDIR%\temp\tar55bc.tmp
- %WINDIR%\temp\cab55bb.tmp
- %WINDIR%\temp\tar558c.tmp
- %WINDIR%\temp\cab558b.tmp
- %WINDIR%\temp\tar4093.tmp
- %WINDIR%\temp\cab4092.tmp
- %WINDIR%\temp\tar4072.tmp
- %WINDIR%\temp\cab4071.tmp
- %WINDIR%\temp\tar2810.tmp
- %WINDIR%\temp\cab280f.tmp
- %WINDIR%\temp\tar1308.tmp
- %WINDIR%\temp\cab1307.tmp
- %WINDIR%\temp\tar12c8.tmp
- %WINDIR%\temp\cab12c7.tmp
- %WINDIR%\temp\tarfc78.tmp
- %WINDIR%\temp\cabb604.tmp
- %WINDIR%\temp\tarb605.tmp
- 'br####r.coccoc.com':80
- 'fi###.coccoc.com':443
- 'fi#####dnet.coccoc.com':443
- 'x1.#.lencr.org':80
- http://x1.#.lencr.org/
- http://br####r.coccoc.com/service/update2?cu############################################################################################
- http://br####r.coccoc.com/service/update2
- 'fi###.coccoc.com':443
- 'fi#####dnet.coccoc.com':443
- DNS ASK br####r.coccoc.com
- DNS ASK fi###.coccoc.com
- DNS ASK fi#####dnet.coccoc.com
- DNS ASK x1.#.lencr.org
- '%APPDATA%\coccocsetup.exe' /silent /install
- '%ProgramFiles(x86)%\coccoc\temp\gum77fc.tmp\coccocupdate.exe' /silent /install "appguid={C0CC0CBB-47DD-46FF-A04D-7011A06486E1}&appname=C%E1%BB%91c%20C%E1%BB%91c&needsadmin=prefers&usagestats=1&lang=vi&client={0A137B37-5CC3-881A-70E1-86CE2172C8D1}&utm=cmVm...
- '%ProgramFiles(x86)%\coccoc\update\coccocupdate.exe' /regsvc
- '%ProgramFiles(x86)%\coccoc\update\coccocupdate.exe' /regserver
- '%ProgramFiles(x86)%\coccoc\update\2.9.1.9\coccocupdatecomregistershell64.exe'
- '%ProgramFiles(x86)%\coccoc\update\coccocupdate.exe' /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjIuOS4xLjkiIHNoZWxsX3ZlcnNpb249IjIuOS4xLjkiIGlzbWFjaGluZT0iMSI...
- '%ProgramFiles(x86)%\coccoc\update\coccocupdate.exe' /handoff "appguid={C0CC0CBB-47DD-46FF-A04D-7011A06486E1}&appname=C%E1%BB%91c%20C%E1%BB%91c&needsadmin=prefers&usagestats=1&lang=vi&client={0A137B37-5CC3-881A-70E1-86CE2172C8D1}&utm=cmVmPXd3dy5n...
- '%ProgramFiles(x86)%\coccoc\update\coccocupdate.exe' /svc
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\71D5.tmp\71D6.tmp\71D7.bat <Полный путь к файлу>" (со скрытым окном)