Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 40 bit mutex: DB5EF2571295BF213219AF7DBF41710F5CDF9721
- persistence:
- C:\Users\user1\AppData\Roaming\Microsoft\Windows\usfvwcfh\ftuwjhcb.exe
- C:\Users\user1\AppData\Roaming\Microsoft\Windows\usfvwcfh
- C:\Users\user1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\usfvwcfh.lnk
- C:\Windows\System32\Tasks\Opera scheduled Autoupdate 874468711
- regkeys set:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2\ProgramsCache
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera scheduled Autoupdate 874468711\Id
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera scheduled Autoupdate 874468711\Index
- domains:
- keamreddlo.bit
- ua: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E; InfoPath.3)
- hex POST data:
- 0000 4b c3 53 0a 9f 0a 28 7c 1a 00 58 d8 9e 30 2e d8
- 0010 80 b8 c0 d0 c1 da fa 65 47 78 ba 63 b6 6f b5 18
- 0020 12 89 13 33 72 2a b4 13 86 2c 38 cb 84 0f 33 e7
- 0030 0f 64 b5 f8 49 2e d3 16 c5 63 33 eb dd df 5d
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement