Technical Information
- [HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'GrpConv' = 'grpconv -o'
- <SYSTEM32>\tasks\spyhunter4startup
- [HKLM\System\CurrentControlSet\Services\EsgScanner] 'ImagePath' = 'system32\DRIVERS\EsgScanner.sys'
- [HKLM\System\CurrentControlSet\Services\SpyHunter 4 Service] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\SpyHunter 4 Service] 'ImagePath' = '"%ProgramFiles%\Enigma Software Group\SpyHunter\Sh4Service.exe"'
- 'EsgScanner' system32\DRIVERS\EsgScanner.sys
- 'SpyHunter 4 Service' "%ProgramFiles%\Enigma Software Group\SpyHunter\Sh4Service.exe"
- 'SpyHunter 4 Service' %ProgramFiles%\Enigma Software Group\SpyHunter\Sh4Service.exe
- [HKLM\System\CurrentControlSet\Services\EsgScanner] 'Group' = 'FSFilter Activity Monitor'
- %TEMP%\esg_setup.log
- %ProgramFiles%\enigma software group\spyhunter\chinese(simplified).lng
- %ProgramFiles%\enigma software group\spyhunter\croatian.lng
- %ProgramFiles%\enigma software group\spyhunter\greek.lng
- %ProgramFiles%\enigma software group\spyhunter\indonesian.lng
- %ProgramFiles%\enigma software group\spyhunter\polish.lng
- %ProgramFiles%\enigma software group\spyhunter\romanian.lng
- %ProgramFiles%\enigma software group\spyhunter\slovene.lng
- %ProgramFiles%\enigma software group\spyhunter\spyhunter4.com
- %ProgramFiles%\enigma software group\spyhunter\defs\def.dat
- %ProgramFiles%\enigma software group\spyhunter\purl.dat
- C:\sh4ldr\initrd.gz
- C:\sh4ldr\shldr.mbr
- %APPDATA%\enigma software group\sh_installer.exe
- C:\sh4ldr\vmlinuz
- %HOMEPATH%\desktop\spyhunter.lnk
- %APPDATA%\microsoft\windows\start menu\programs\spyhunter\spyhunter.lnk
- %APPDATA%\microsoft\windows\start menu\programs\spyhunter\spyhunter emergency startup.lnk
- %TEMP%\scan.hive
- %APPDATA%\microsoft\windows\start menu\programs\spyhunter\uninstall.lnk
- %TEMP%\esgscanner.sys
- %TEMP%\esgscanner.inf
- %TEMP%\esginstallerx64stub.exe
- <DRIVERS>\set470e.tmp
- %WINDIR%\temp\udd4b71.tmp
- %ProgramFiles%\enigma software group\spyhunter\chinese(traditional).lng
- C:\sh4ldr\shldr
- %ProgramFiles%\enigma software group\spyhunter\japanese.lng
- %ProgramFiles%\enigma software group\spyhunter\czech.lng
- %ProgramFiles%\enigma software group\spyhunter\common.dll
- %ProgramFiles%\enigma software group\spyhunter\defman.dll
- %ProgramFiles%\enigma software group\spyhunter\executionguard.dll
- %ProgramFiles%\enigma software group\spyhunter\shscanner.dll
- %ProgramFiles%\enigma software group\spyhunter\sh4service.exe
- %ProgramFiles%\enigma software group\spyhunter\spyhunter4.exe
- %ProgramFiles%\enigma software group\spyhunter\license.txt
- %ProgramFiles%\enigma software group\spyhunter\esgscanner.inf
- %ProgramFiles%\enigma software group\spyhunter\esgscanner.sys
- %ProgramFiles%\enigma software group\spyhunter\native.exe
- %ProgramFiles%\enigma software group\spyhunter\esgiguard.sys
- %ProgramFiles%\enigma software group\spyhunter\danish.lng
- %ProgramFiles%\enigma software group\spyhunter\brazilian.lng
- %ProgramFiles%\enigma software group\spyhunter\dutch.lng
- %ProgramFiles%\enigma software group\spyhunter\english.lng
- %ProgramFiles%\enigma software group\spyhunter\finnish.lng
- %ProgramFiles%\enigma software group\spyhunter\french.lng
- %ProgramFiles%\enigma software group\spyhunter\german.lng
- %ProgramFiles%\enigma software group\spyhunter\italian.lng
- %ProgramFiles%\enigma software group\spyhunter\lithuanian.lng
- %ProgramFiles%\enigma software group\spyhunter\norwegian.lng
- %ProgramFiles%\enigma software group\spyhunter\portuguese.lng
- %ProgramFiles%\enigma software group\spyhunter\spanish.lng
- %ProgramFiles%\enigma software group\spyhunter\swedish.lng
- %ProgramFiles%\enigma software group\spyhunter\russian.lng
- %TEMP%\esginstallerdelay_1e71bbf294f07658c4881bd2b4e979dc_0.exe
- %TEMP%\scan.hive
- %WINDIR%\temp\udd4b71.tmp
- %TEMP%\esgscanner.sys
- %TEMP%\esgscanner.inf
- %TEMP%\esginstallerx64stub.exe
- %TEMP%\esg_setup.log
- from <DRIVERS>\set470e.tmp to <DRIVERS>\esgscanner.sys
- %LOCALAPPDATA%\microsoft\windows\explorer\explorerstartuplog_runonce.etl
- %TEMP%\scan.hive
- 'google.com':80
- 'in#######.enigmasoftware.com':80
- 'in#######.enigmasoftware.com':443
- 'sh.####masoftware.com':80
- http://in#######.enigmasoftware.com/log_collect.cfg
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_norwegian.lng.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_portuguese.lng.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_spanish.lng.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_swedish.lng.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_brazilian.lng.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_russian.lng.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_japanese.lng.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_chinese(traditional).lng.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_x64_spyhunter4.exe.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_chinese(simplified).lng.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_greek.lng.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_indonesian.lng.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_polish.lng.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_romanian.lng.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_slovene.lng.ecf
- http://in#######.enigmasoftware.com/sh/def/2018032701.def.ecf
- http://in#######.enigmasoftware.com/shos/3.18.5.49/shos_initrd.gz.ecf
- http://in#######.enigmasoftware.com/shos/3.18.5.49/shos_shldr.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_italian.lng.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_lithuanian.lng.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_german.lng.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_french.lng.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_finnish.lng.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/filelist.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/setup.ecf
- http://in#######.enigmasoftware.com/sh/def/latest_def.ecf
- http://sh.####masoftware.com/callback_functions/tt_callback.php?pa###################################################################################
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_x64_common.dll.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_x64_defman.dll.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_x64_executionguard.dll.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_x64_shscanner.dll.ecf
- http://in#######.enigmasoftware.com/shos/3.18.5.49/shos_shldr.mbr.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_croatian.lng.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_x64_sh4service.exe.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_drivers_esgscanner.inf.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_drivers_esgscanner64.sys.ecf
- http://in#######.enigmasoftware.com/shos/3.18.5.49/shos_native64.exe.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_drivers_esgiguard_vista_64_sp1.sys.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_czech.lng.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_danish.lng.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_dutch.lng.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_english.lng.ecf
- http://in#######.enigmasoftware.com/sh/latest.ecf
- http://in#######.enigmasoftware.com/sh/4.28.7.4850/sh_common_license.txt.ecf
- http://in#######.enigmasoftware.com/shos/3.18.5.49/shos_vmlinuz.ecf
- 'in#######.enigmasoftware.com':443
- DNS ASK google.com
- DNS ASK in#######.enigmasoftware.com
- DNS ASK sh.####masoftware.com
- '%TEMP%\esginstallerx64stub.exe' -inf DefaultInstall -if "%ProgramFiles%\Enigma Software Group\SpyHunter\EsgScanner.inf" -wait -1
- '%TEMP%\esginstallerdelay_1e71bbf294f07658c4881bd2b4e979dc_0.exe' -exec CV4P+xygvPOFO/dCO2afl9/Gv0h/j7gpYm2O1knUWcBdGKgfSuDvRodBjRP7CVV4wTwHsG7aBWO7Qbn/v2X3Pg== -args yxLBkkwK+tN/g/lTFU7okMk01a8t+L6jhnEHJZP5MeU= -wait 300
- '<SYSTEM32>\schtasks.exe' /create /tn SpyHunter4Startup /rl highest /sc ONLOGON /tr "\"%ProgramFiles%\Enigma Software Group\SpyHunter\Spyhunter4.exe\" /s" /f' (with hidden window)
- '<SYSTEM32>\rundll32.exe' setupapi,InstallHinfSection DefaultInstall 132 %ProgramFiles%\Enigma Software Group\SpyHunter\EsgScanner.inf' (with hidden window)
- '<SYSTEM32>\sc.exe' create "SpyHunter 4 Service" binPath= "\"%ProgramFiles%\Enigma Software Group\SpyHunter\Sh4Service.exe\"" DisplayName= "SpyHunter4 Service" start= auto' (with hidden window)
- '%TEMP%\esginstallerdelay_1e71bbf294f07658c4881bd2b4e979dc_0.exe' -exec CV4P+xygvPOFO/dCO2afl9/Gv0h/j7gpYm2O1knUWcBdGKgfSuDvRodBjRP7CVV4wTwHsG7aBWO7Qbn/v2X3Pg== -args yxLBkkwK+tN/g/lTFU7okMk01a8t+L6jhnEHJZP5MeU= -wait 300' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /create /tn SpyHunter4Startup /rl highest /sc ONLOGON /tr "\"%ProgramFiles%\Enigma Software Group\SpyHunter\Spyhunter4.exe\" /s" /f
- '<SYSTEM32>\rundll32.exe' setupapi,InstallHinfSection DefaultInstall 132 %ProgramFiles%\Enigma Software Group\SpyHunter\EsgScanner.inf
- '<SYSTEM32>\runonce.exe' -r
- '<SYSTEM32>\grpconv.exe' -o
- '<SYSTEM32>\sc.exe' create "SpyHunter 4 Service" binPath= "\"%ProgramFiles%\Enigma Software Group\SpyHunter\Sh4Service.exe\"" DisplayName= "SpyHunter4 Service" start= auto