paladin316

Troldesh_a50b463e02ecfba2ff256d57a95c6512_jpg_2019-08-21_21_00.txt

Aug 21st, 2019
2,226
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 21.65 KB | None | 0 0
  1.  
  2. * MalFamily: "Troldesh"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Troldesh_a50b463e02ecfba2ff256d57a95c6512.jpg"
  7. * File Size: 1391792
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "cf065f4290fe2391fa2bd6d30a12f5dc2cc3a298de58ae5bc8d0fd4856cd4580"
  10. * MD5: "a50b463e02ecfba2ff256d57a95c6512"
  11. * SHA1: "9195fab17ea1026e5dfbef0241a78c0e57e15580"
  12. * SHA512: "2860e9daad3522a64af9b322ca4bbe64d0e38b874e79571e52101bd65e931ee67b6499ea67a2f856759b2d955fd74069adf43c05a40b9ca4495e8db7f85e1fe6"
  13. * CRC32: "385CF000"
  14. * SSDEEP: "24576:WZpi1ZGIRtOi3PdD+qMVyC+N+Ahfv5Ya4nKrVm:BZGI7DdDaVP+NfuamKrVm"
  15.  
  16. * Process Execution:
  17. "Troldesh_a50b463e02ecfba2ff256d57a95c6512.jpg",
  18. "vssadmin.exe",
  19. "vssadmin.exe"
  20.  
  21.  
  22. * Executed Commands:
  23. "C:\\Windows\\system32\\vssadmin.exe List Shadows",
  24. "C:\\Windows\\system32\\vssadmin.exe Delete Shadows /All /Quiet"
  25.  
  26.  
  27. * Signatures Detected:
  28.  
  29. "Description": "Creates RWX memory",
  30. "Details":
  31.  
  32.  
  33. "Description": "Attempts to connect to a dead IP:Port (9 unique times)",
  34. "Details":
  35.  
  36. "IP": "208.83.223.34:80"
  37.  
  38.  
  39. "IP": "193.23.244.244:443"
  40.  
  41.  
  42. "IP": "109.236.90.209:443"
  43.  
  44.  
  45. "IP": "188.213.31.125:9001"
  46.  
  47.  
  48. "IP": "37.187.96.183:9001"
  49.  
  50.  
  51. "IP": "127.0.0.1:63109"
  52.  
  53.  
  54. "IP": "154.35.32.5:443"
  55.  
  56.  
  57. "IP": "194.109.206.212:443"
  58.  
  59.  
  60. "IP": "76.73.17.194:9090"
  61.  
  62.  
  63.  
  64.  
  65. "Description": "Starts servers listening on 127.0.0.1:63109",
  66. "Details":
  67.  
  68.  
  69. "Description": "Reads data out of its own binary image",
  70. "Details":
  71.  
  72. "self_read": "process: Troldesh_a50b463e02ecfba2ff256d57a95c6512.jpg, pid: 2328, offset: 0x00000000, length: 0x00153cb0"
  73.  
  74.  
  75.  
  76.  
  77. "Description": "Attempts to delete volume shadow copies",
  78. "Details":
  79.  
  80.  
  81. "Description": "Installs Tor on the infected machine",
  82. "Details":
  83.  
  84.  
  85. "Description": "Installs itself for autorun at Windows startup",
  86. "Details":
  87.  
  88. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Client Server Runtime Subsystem"
  89.  
  90.  
  91. "data": "\"C:\\ProgramData\\Windows\\csrss.exe\""
  92.  
  93.  
  94.  
  95.  
  96. "Description": "Exhibits possible ransomware file modification behavior",
  97. "Details":
  98.  
  99. "appends_new_extension": "Appends a new file extension to multiple modified files"
  100.  
  101.  
  102. "new_appended_file_extension": ".crypted000007"
  103.  
  104.  
  105.  
  106.  
  107. "Description": "Collects information about installed applications",
  108. "Details":
  109.  
  110. "Program": "Google Update Helper"
  111.  
  112.  
  113.  
  114.  
  115. "Program": "Microsoft Excel MUI 2013"
  116.  
  117.  
  118. "Program": "Microsoft Outlook MUI 2013"
  119.  
  120.  
  121.  
  122.  
  123. "Program": "Google Chrome"
  124.  
  125.  
  126. "Program": "Adobe Flash Player 29 NPAPI"
  127.  
  128.  
  129. "Program": "Adobe Flash Player 29 ActiveX"
  130.  
  131.  
  132. "Program": "Microsoft DCF MUI 2013"
  133.  
  134.  
  135. "Program": "Microsoft Access MUI 2013"
  136.  
  137.  
  138. "Program": "Microsoft Office Proofing Tools 2013 - English"
  139.  
  140.  
  141. "Program": "Adobe Acrobat Reader DC"
  142.  
  143.  
  144. "Program": "Microsoft Publisher MUI 2013"
  145.  
  146.  
  147. "Program": "Microsoft Office Shared MUI 2013"
  148.  
  149.  
  150. "Program": "Microsoft Office OSM MUI 2013"
  151.  
  152.  
  153. "Program": "Microsoft InfoPath MUI 2013"
  154.  
  155.  
  156. "Program": "Microsoft Office Shared Setup Metadata MUI 2013"
  157.  
  158.  
  159. "Program": "Outils de v\\xc3\\xa9rification linguistique 2013 de Microsoft Office\\xc2\\xa0- Fran\\xc3\\xa7ais"
  160.  
  161.  
  162. "Program": "Microsoft Word MUI 2013"
  163.  
  164.  
  165. "Program": "Microsoft OneDrive"
  166.  
  167.  
  168. "Program": "Microsoft Groove MUI 2013"
  169.  
  170.  
  171. "Program": "Microsoft Office Proofing Tools 2013 - Espa\\xc3\\xb1ol"
  172.  
  173.  
  174.  
  175.  
  176. "Program": "Microsoft Access Setup Metadata MUI 2013"
  177.  
  178.  
  179. "Program": "Microsoft Office OSM UX MUI 2013"
  180.  
  181.  
  182. "Program": "Java Auto Updater"
  183.  
  184.  
  185. "Program": "Microsoft PowerPoint MUI 2013"
  186.  
  187.  
  188. "Program": "Microsoft Office Professional Plus 2013"
  189.  
  190.  
  191. "Program": "Adobe Refresh Manager"
  192.  
  193.  
  194. "Program": "Microsoft Office Proofing 2013"
  195.  
  196.  
  197. "Program": "Microsoft Lync MUI 2013"
  198.  
  199.  
  200.  
  201.  
  202. "Program": "Microsoft OneNote MUI 2013"
  203.  
  204.  
  205.  
  206.  
  207. "Description": "Creates a hidden or system file",
  208. "Details":
  209.  
  210. "file": "C:\\ProgramData\\Windows\\"
  211.  
  212.  
  213.  
  214.  
  215. "Description": "File has been identified by 26 Antiviruses on VirusTotal as malicious",
  216. "Details":
  217.  
  218. "Cylance": "Unsafe"
  219.  
  220.  
  221. "K7AntiVirus": "Trojan ( 0054985e1 )"
  222.  
  223.  
  224. "K7GW": "Trojan ( 0054985e1 )"
  225.  
  226.  
  227. "Invincea": "heuristic"
  228.  
  229.  
  230. "F-Prot": "W32/Agent.BAE.gen!Eldorado"
  231.  
  232.  
  233. "Symantec": "Packed.Generic.459"
  234.  
  235.  
  236. "APEX": "Malicious"
  237.  
  238.  
  239. "Avast": "Win32:CrypterX-gen Trj"
  240.  
  241.  
  242. "Kaspersky": "UDS:DangerousObject.Multi.Generic"
  243.  
  244.  
  245. "Paloalto": "generic.ml"
  246.  
  247.  
  248. "Endgame": "malicious (high confidence)"
  249.  
  250.  
  251. "TrendMicro": "TrojanSpy.Win32.TRICKBOT.SMB.hp"
  252.  
  253.  
  254. "FireEye": "Generic.mg.a50b463e02ecfba2"
  255.  
  256.  
  257. "Emsisoft": "Trojan-Ransom.Shade (A)"
  258.  
  259.  
  260. "Cyren": "W32/Agent.BAE.gen!Eldorado"
  261.  
  262.  
  263. "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
  264.  
  265.  
  266. "Acronis": "suspicious"
  267.  
  268.  
  269. "VBA32": "BScope.Malware-Cryptor.Filecoder"
  270.  
  271.  
  272. "ESET-NOD32": "a variant of Win32/Kryptik.GVNS"
  273.  
  274.  
  275. "TrendMicro-HouseCall": "TrojanSpy.Win32.TRICKBOT.SMB.hp"
  276.  
  277.  
  278. "Rising": "[email protected] (RDML:G7pF+K7XMAeMXvyZHoynBA)"
  279.  
  280.  
  281. "eGambit": "PE.Heur.InvalidSig"
  282.  
  283.  
  284. "Fortinet": "W32/Generic.AP.1D3C286!tr"
  285.  
  286.  
  287. "AVG": "Win32:CrypterX-gen Trj"
  288.  
  289.  
  290. "CrowdStrike": "win/malicious_confidence_60% (W)"
  291.  
  292.  
  293. "Qihoo-360": "HEUR/QVM10.1.5C47.Malware.Gen"
  294.  
  295.  
  296.  
  297.  
  298. "Description": "Creates a copy of itself",
  299. "Details":
  300.  
  301. "copy": "C:\\ProgramData\\Windows\\csrss.exe"
  302.  
  303.  
  304.  
  305.  
  306. "Description": "Harvests information related to installed mail clients",
  307. "Details":
  308.  
  309. "file": "C:\\Users\\user\\Documents\\Outlook Files\\Outlook.pst"
  310.  
  311.  
  312.  
  313.  
  314. "Description": "Anomalous binary characteristics",
  315. "Details":
  316.  
  317. "anomaly": "Actual checksum does not match that reported in PE header"
  318.  
  319.  
  320.  
  321.  
  322.  
  323. * Started Service:
  324.  
  325. * Mutexes:
  326.  
  327. * Modified Files:
  328. "\\??\\PIPE\\wkssvc",
  329. "C:\\ProgramData\\Windows\\csrss.exe",
  330. "\\??\\PIPE\\srvsvc",
  331. "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\lock",
  332. "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\state.tmp",
  333. "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\state",
  334. "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\unverified-microdesc-consensus.tmp",
  335. "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\unverified-microdesc-consensus",
  336. "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\cached-certs.tmp",
  337. "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\cached-certs",
  338. "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\cached-microdesc-consensus.tmp",
  339. "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\cached-microdesc-consensus",
  340. "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\cached-microdescs.new",
  341. "C:\\README1.txt",
  342. "C:\\README2.txt",
  343. "C:\\README3.txt",
  344. "C:\\README4.txt",
  345. "C:\\README5.txt",
  346. "C:\\README6.txt",
  347. "C:\\README7.txt",
  348. "C:\\README8.txt",
  349. "C:\\README9.txt",
  350. "C:\\README10.txt",
  351. "C:\\Users\\user\\Pictures\\Host.zip",
  352. "C:\\Users\\user\\Pictures\\KbH5fPKWA2XyhSn+7syJJu-pYiQFwlDiNYI6x8F6Hno=.C30C4DA81AE308962B9A.crypted000007",
  353. "C:\\Users\\user\\Pictures\\Host.xls",
  354. "C:\\Users\\user\\Pictures\\pyknfSBU4tPSjn+kETdwGUZlyS6XvF3Q5Bb39I0vY1g=.C30C4DA81AE308962B9A.crypted000007",
  355. "C:\\Users\\user\\Pictures\\Host.pptx",
  356. "C:\\Users\\user\\Pictures\\C+XqaP5gxgKSwDBP7Ot9E7hkFX1LckvXYSBsxNx11So=.C30C4DA81AE308962B9A.crypted000007",
  357. "C:\\Users\\user\\Pictures\\Host.ppt",
  358. "C:\\Users\\user\\Pictures\\wQGtcNy39abJ1kILGUtxJUGgg0hQCDGPYCKTEFHTQtc=.C30C4DA81AE308962B9A.crypted000007",
  359. "C:\\Users\\user\\Pictures\\Host.pdf",
  360. "C:\\Users\\user\\Pictures\\IhkRMsPO4xM4dIqO63fRDTEeFw3bTvyzwg0Pb07S4gU=.C30C4DA81AE308962B9A.crypted000007",
  361. "C:\\Users\\user\\Pictures\\Host.jpg",
  362. "C:\\Users\\user\\Pictures\\r4+uM4S876j8aX9vzIcyWf7gJYbcrfT0yEJu59gcd0c=.C30C4DA81AE308962B9A.crypted000007",
  363. "C:\\Users\\user\\Pictures\\Host.html",
  364. "C:\\Users\\user\\Pictures\\7A1RXoZUOT2GAWuB7+btiYpqoGkK4pbtr+J31wNSxRA=.C30C4DA81AE308962B9A.crypted000007",
  365. "C:\\Users\\user\\Pictures\\Host.gif",
  366. "C:\\Users\\user\\Pictures\\QRbubM0kGiofMDWhYC6fOelUXF9PTQYDq9mEkMJT9+k=.C30C4DA81AE308962B9A.crypted000007",
  367. "C:\\Users\\user\\Pictures\\Host.doc",
  368. "C:\\Users\\user\\Pictures\\V3gKjhXZm7KSen0uiOdVmg9yR6wbBD2ZbW1hdoNDptI=.C30C4DA81AE308962B9A.crypted000007",
  369. "C:\\Users\\user\\Pictures\\.xls",
  370. "C:\\Users\\user\\Pictures\\+LuUUo72RkTiiNnMo2gZbg==.C30C4DA81AE308962B9A.crypted000007",
  371. "C:\\Users\\user\\Pictures\\.jpg",
  372. "C:\\Users\\user\\Pictures\\WJEEw0JlaHDk5pkX9sFkBQ==.C30C4DA81AE308962B9A.crypted000007",
  373. "C:\\Users\\user\\Pictures\\.html",
  374. "C:\\Users\\user\\Pictures\\61fOn7ZTyUDzII6+f3SZFA==.C30C4DA81AE308962B9A.crypted000007",
  375. "C:\\Users\\user\\Pictures\\.doc",
  376. "C:\\Users\\user\\Pictures\\xqOzKqf6eDOuLxBUjVe4Rw==.C30C4DA81AE308962B9A.crypted000007",
  377. "C:\\Users\\user\\Pictures\\.bmp",
  378. "C:\\Users\\user\\Pictures\\PgoS05C13+lOeiX1Dj2WDg==.C30C4DA81AE308962B9A.crypted000007",
  379. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\userDefineLangs\\userDefinedLang-markdown.default.modern.xml",
  380. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\userDefineLangs\\Xsl7P6cfy5SpOsJL6i+ewSuNW2Ti6jA3h7tuHVfRFcsKvPJw9NGUb7bQRF7+Df4D1NeVbqYWK9RJuAXGxVhdZ-ZjMnGzlaK+d8vo8oP+Riip-B8qAEmzR5Y5z2F7ZDwr.C30C4DA81AE308962B9A.crypted000007",
  381. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Zenburn.xml",
  382. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\PW2pG0+iITa32BipV8J0tNlwEHb99lNB8BZZTI-65cQ=.C30C4DA81AE308962B9A.crypted000007",
  383. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\vim Dark Blue.xml",
  384. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\PfGO8LhWls+fol5yEyXZ6nWXo+0yUPb2fisS-YyFPsewAbyFtD9SdgeGuEfQaqlK.C30C4DA81AE308962B9A.crypted000007",
  385. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Vibrant Ink.xml",
  386. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\scOjvx3uDrYF63v2S6ekLlKDBJ+Jnvy9s0egPclLmE0=.C30C4DA81AE308962B9A.crypted000007",
  387. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Twilight.xml",
  388. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\4FM4VQlCm2J7VxvOCCeVnky7IxKfYlZzX9higoKBvXI=.C30C4DA81AE308962B9A.crypted000007",
  389. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Solarized.xml",
  390. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\HXu+3Gnegjht8763x3fUJu-UPo8vGocGm2kmVabq8RI=.C30C4DA81AE308962B9A.crypted000007",
  391. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Solarized-light.xml",
  392. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\oBuTd+a4LVGlMVXlvZEDqMmJfWmuwjS5gGSZGwUe+ZAB+vZGlmA5X+e8cmFI+Z-w.C30C4DA81AE308962B9A.crypted000007",
  393. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Ruby Blue.xml",
  394. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\zJPy0KiGEt+2eLtehmk-2p3NArYL+4LxnnwRvUrbz44=.C30C4DA81AE308962B9A.crypted000007",
  395. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Plastic Code Wrap.xml",
  396. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\eZg0jfhaFpLvwSTO04cfTYSjXOaUn+xvcEk32HAMIbSL6A2WS9ysB7CbuuJB8lDw.C30C4DA81AE308962B9A.crypted000007",
  397. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Obsidian.xml",
  398. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\2JZ-AMFH1CgxyfUqLYeSREl4HtRHsFxlaaa9XjcDaik=.C30C4DA81AE308962B9A.crypted000007",
  399. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Navajo.xml",
  400. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\2eEeNVSRL4IfhPeGyvSl3a-XSciP-8XasQm9BdJMUFU=.C30C4DA81AE308962B9A.crypted000007",
  401. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\MossyLawn.xml",
  402. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\APdmnQu3eT-bVb-memxbuZJhbJCh6M1MM-HvetSug6U=.C30C4DA81AE308962B9A.crypted000007",
  403. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Monokai.xml",
  404. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\+O2b-2TTs63nkPiVabB59a3v04JZZN2+syOuq8IiTA4=.C30C4DA81AE308962B9A.crypted000007",
  405. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Mono Industrial.xml",
  406. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\pnmAR1dKMM0032Q4kSB5g+Bc8vHed8t5vV+ku-enIgprF6w7cXbJ3+q82PW0LuxY.C30C4DA81AE308962B9A.crypted000007",
  407. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\khaki.xml",
  408. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\157eaDwzF2SEYxE5udfk6d2OYJ5wk8re0p8r11Otfzw=.C30C4DA81AE308962B9A.crypted000007",
  409. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\HotFudgeSundae.xml",
  410. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\SfR1+iKIvekz8QBZGPCg6iLir76r8k2NAIKGZskFud8GAKkl1flFpZeedAtOoJkt.C30C4DA81AE308962B9A.crypted000007",
  411. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Hello Kitty.xml",
  412. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\-afgSlFkk4HWgTx0S-AOgIS2Q3bhsFTGLcOHIuXTwXY=.C30C4DA81AE308962B9A.crypted000007",
  413. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Deep Black.xml",
  414. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\e2cwL72qgw57Jbtd+uKQqGhMxJRwnyq-jC3-bP-yY60=.C30C4DA81AE308962B9A.crypted000007",
  415. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Choco.xml",
  416. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\xJAiANEWJku4PI2jPPlkuZu0y6JGNWFZpP2Oxhx1V1s=.C30C4DA81AE308962B9A.crypted000007",
  417. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Black board.xml",
  418. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\-iWSVf3CB2t1J9vfyfon-FjKQ0RtIgVA+YxlISpcOpo=.C30C4DA81AE308962B9A.crypted000007",
  419. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Bespin.xml",
  420. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\kP9bEPtzOP7rBrM2bf0pDnPKoafDhsvmbH80LrDbBuQ=.C30C4DA81AE308962B9A.crypted000007",
  421. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\plugins\\config\\converter.ini",
  422. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\plugins\\config\\+ycUfCL7d--zKU6sk7kIXzDotdh+GQPVO7TmaCW-tiI=.C30C4DA81AE308962B9A.crypted000007",
  423. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\stylers.xml",
  424. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\7A10ENtmvEscoAQUeEQA13O2AlK2V+NG8J48xZn5Sik=.C30C4DA81AE308962B9A.crypted000007",
  425. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\shortcuts.xml",
  426. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\mnSuaIlO+QIAw5K71ee6Acwy-LsD9xdLwqQSGidHLmg=.C30C4DA81AE308962B9A.crypted000007",
  427. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\session.xml",
  428. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\4KKxVsEgxO1KLtKh1jgudloiql4YCyK9j1CmdwuFt8Y=.C30C4DA81AE308962B9A.crypted000007",
  429. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\langs.xml",
  430. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\j88C0589GiXhas6uKO1bbxqcK2NIdCytMwS4bNTuUJE=.C30C4DA81AE308962B9A.crypted000007",
  431. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\functionList.xml",
  432. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\+lxfwKfX-kufrhLUkpArt0mEatk6+mUs4TUZBu4S8z0=.C30C4DA81AE308962B9A.crypted000007",
  433. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\contextMenu.xml"
  434.  
  435.  
  436. * Deleted Files:
  437. "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\state.tmp",
  438. "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\unverified-microdesc-consensus.tmp",
  439. "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\cached-certs.tmp",
  440. "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\unverified-microdesc-consensus",
  441. "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\cached-microdesc-consensus.tmp",
  442. "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\state",
  443. "C:\\Users\\user\\Pictures\\Host.zip",
  444. "C:\\Users\\user\\Pictures\\Host.xls",
  445. "C:\\Users\\user\\Pictures\\Host.pptx",
  446. "C:\\Users\\user\\Pictures\\Host.ppt",
  447. "C:\\Users\\user\\Pictures\\Host.pdf",
  448. "C:\\Users\\user\\Pictures\\Host.jpg",
  449. "C:\\Users\\user\\Pictures\\Host.html",
  450. "C:\\Users\\user\\Pictures\\Host.gif",
  451. "C:\\Users\\user\\Pictures\\Host.doc",
  452. "C:\\Users\\user\\Pictures\\.xls",
  453. "C:\\Users\\user\\Pictures\\.jpg",
  454. "C:\\Users\\user\\Pictures\\.html",
  455. "C:\\Users\\user\\Pictures\\.doc",
  456. "C:\\Users\\user\\Pictures\\.bmp",
  457. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\userDefineLangs\\userDefinedLang-markdown.default.modern.xml",
  458. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Zenburn.xml",
  459. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\vim Dark Blue.xml",
  460. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Vibrant Ink.xml",
  461. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Twilight.xml",
  462. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Solarized.xml",
  463. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Solarized-light.xml",
  464. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Ruby Blue.xml",
  465. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Plastic Code Wrap.xml",
  466. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Obsidian.xml",
  467. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Navajo.xml",
  468. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\MossyLawn.xml",
  469. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Monokai.xml",
  470. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Mono Industrial.xml",
  471. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\khaki.xml",
  472. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\HotFudgeSundae.xml",
  473. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Hello Kitty.xml",
  474. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Deep Black.xml",
  475. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Choco.xml",
  476. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Black board.xml",
  477. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\themes\\Bespin.xml",
  478. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\plugins\\config\\converter.ini",
  479. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\stylers.xml",
  480. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\shortcuts.xml",
  481. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\session.xml",
  482. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\langs.xml",
  483. "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\functionList.xml"
  484.  
  485.  
  486. * Modified Registry Keys:
  487. "HKEY_LOCAL_MACHINE\\SOFTWARE\\System32\\Configuration\\",
  488. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\System32\\Configuration\\xi",
  489. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Client Server Runtime Subsystem",
  490. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\System32\\Configuration\\xVersion",
  491. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\System32\\Configuration\\xmail",
  492. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\System32\\Configuration\\xmode",
  493. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\System32\\Configuration\\xpk",
  494. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\System32\\Configuration\\xstate",
  495. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\System32\\Configuration\\xcnt"
  496.  
  497.  
  498. * Deleted Registry Keys:
  499.  
  500. * DNS Communications:
  501.  
  502. * Domains:
  503.  
  504. * Network Communication - ICMP:
  505.  
  506. * Network Communication - HTTP:
  507.  
  508. * Network Communication - SMTP:
  509.  
  510. * Network Communication - Hosts:
  511.  
  512. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment