MalwareMustDie

#MalwareMustDie - Trojan Parfeit Data 20121222

Dec 22nd, 2012
3,733
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 19.55 KB | None | 0 0
  1. #MalwareMustDie - Trojan Parfeit Data
  2. #2012 Dec 21 | @unixfreaxjp
  3.  
  4. !This program cannot be run in DOS mode.
  5. .text
  6. `.rdata
  7. @.data
  8. aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
  9. jjj
  10. jjj
  11. jjjj
  12. jjjj
  13. CEPh
  14. jjjjjj
  15. kEP
  16. jjjj
  17. JEh
  18. jjjj
  19. jjjj
  20. jjjj
  21. jjjj
  22. jjjj
  23. KWk
  24. jjjj
  25. jjjj
  26. jjjj
  27. jjjj
  28. jjjj
  29. jjjj
  30. jjjj
  31. jjjj
  32. jjjj
  33. EPEPE
  34. jjh
  35. jjjj
  36. jjjj
  37. jjjj
  38. Ejj
  39. jjjj
  40. EPE
  41. jjjj
  42. jjjj
  43. EPE
  44. EPE
  45. EPEPE
  46. PEPE
  47. jjjj
  48. EPEPE
  49. EPEPE
  50. EPEPE
  51. EPEPE
  52. Ejj
  53. Ejj
  54. EPE
  55. jjjj
  56. jjjj
  57. jjjj
  58. jjjj
  59. jjjj
  60. jjjj
  61. Ejh
  62. jjjj
  63. jjjj
  64. jjjj
  65. jjjj
  66. ]hR"J
  67. ]hg#J
  68. ]hD$J
  69. ]hP%J
  70. VWSh
  71. SVW
  72. PRj
  73. PWj
  74. t*PP
  75. v;PP
  76. WVj
  77. VSW
  78. h:MK
  79. hjJK
  80. h*JK
  81. hhLK
  82. WVS
  83. SWV
  84. Pj R
  85. VWS
  86. WSU
  87. PSQRWV
  88. ^_ZY[X
  89. VWPSQR
  90. ZY[X_^
  91. tTjZ
  92. tgjZ
  93. SWh
  94. B,Ph
  95. B,Ph
  96. R,RP
  97. SVW+
  98. SVWh
  99. SWj
  100. h:QK
  101. hZQK
  102. h>RK
  103. hIRK
  104. h>RK
  105. hIRK
  106. h>RK
  107. hlRK
  108. h>RK
  109. hlRK
  110. h*RK
  111. h*RK
  112. h*RK
  113. h3RK
  114. hIRK
  115. h>RK
  116. hIRK
  117. h3RK
  118. hlRK
  119. h>RK
  120. hlRK
  121. h3RK
  122. hIRK
  123. h>RK
  124. hIRK
  125. h3RK
  126. hlRK
  127. h>RK
  128. hlRK
  129. B,Ph
  130. B,Ph
  131. R,RP
  132. tFh
  133. B,Ph
  134. B,Ph
  135. Ph^TK
  136. h"TK
  137. Ph^TK
  138. h;TK
  139. Ph^TK
  140. hUTK
  141. Ph^TK
  142. Ph^TK
  143. hESK
  144. hsSK
  145. hfTK
  146. hzTK
  147. hfTK
  148. hfTK
  149. hfTK
  150. hzTK
  151. hfTK
  152. hfTK
  153. tch
  154. h&UK
  155. h9UK
  156. hAVK
  157. h0VK
  158. hHUK
  159. huUK
  160. hHUK
  161. h[UK
  162. huUK
  163. hHUK
  164. h[UK
  165. VWj
  166. tshRVK
  167. hnVK
  168. h`VK
  169. hnVK
  170. hzVK
  171. hmWK
  172. hmWK
  173. h}WK
  174. h}WK
  175. h!WK
  176. h^WK
  177. tNh
  178. PPPh
  179. hGXK
  180. hYXK
  181. hPXK
  182. hbXK
  183. PhlXK
  184. tSh
  185. h+XK
  186. hqXK
  187. hzXK
  188. tSh
  189. tYh
  190. Ph\YK
  191. h YK
  192. hdYK
  193. VWj
  194. tKh
  195. h"ZK
  196. h6ZK
  197. h-ZK
  198. hSZK
  199. hCZK
  200. hJZK
  201. Ph\ZK
  202. tEh
  203. hdZK
  204. tlj
  205. tKh
  206. hG[K
  207. tSh
  208. hQ[K
  209. hQ[K
  210. tSh
  211. tNh1\K
  212. PPPh
  213. hL\K
  214. hz\K
  215. PPh
  216. VWj
  217. PPh
  218. PPh
  219. PhL]K
  220. PhW]K
  221. hb]K
  222. hb]K
  223. w%hz]K
  224. tgh
  225. VWj
  226. tah
  227. VWS
  228. PVV
  229. t)PP
  230. QSV
  231. t?h6^K
  232. B,Ph
  233. B,Ph
  234. R,RP
  235. B,Ph
  236. B,Ph
  237. Ph=^K
  238. hC^K
  239. he^K
  240. hM^K
  241. PhC^K
  242. hu^K
  243. hM^K
  244. PhC^K
  245. t$PP
  246. PhC^K
  247. tcP
  248. tHh
  249. hQ_K
  250. ha_K
  251. PPh
  252. hm_K
  253. DaK
  254. DaK
  255. =DaK
  256. 5DaK
  257. 5DaK
  258. DaK
  259. =DaK
  260. 5DaK
  261. DaK
  262. =DaK
  263. h(aK
  264. h(aK
  265. hI`K
  266. h6bK
  267. Ph6bK
  268. h=bK
  269. Ph=bK
  270. h6bK
  271. Ph6bK
  272. h=bK
  273. Ph=bK
  274. h2bK
  275. B,Ph
  276. B,Ph
  277. R,RP
  278. uFhwaK
  279. hHaK
  280. hUaK
  281. hhaK
  282. h]aK
  283. tWj
  284. hmaK
  285. tAPP
  286. h!bK
  287. h!bK
  288. hBbK
  289. h!bK
  290. h!bK
  291. h]bK
  292. hSbK
  293. h!bK
  294. h]bK
  295. hSbK
  296. h!bK
  297. hwbK
  298. hqbK
  299. h!bK
  300. hwbK
  301. hqbK
  302. h!bK
  303. h!bK
  304. h!bK
  305. VWj
  306. tEh
  307. VWj
  308. tEh
  309. h=cK
  310. hIcK
  311. hTcK
  312. hicK
  313. h_cK
  314. hicK
  315. h6dK
  316. h6dK
  317. PPP
  318. VWS
  319. h-eK
  320. h9eK
  321. toh
  322. VWj
  323. tEhLeK
  324. hVeK
  325. VWh
  326. uEh
  327. hteK
  328. PhD
  329. h`eK
  330. hieK
  331. h`eK
  332. hieK
  333. h`eK
  334. hieK
  335. h)fK
  336. h`eK
  337. hieK
  338. h5fK
  339. h>fK
  340. hHfK
  341. hPfK
  342. hcfK
  343. t|hZfK
  344. hmfK
  345. h|fK
  346. tYhwfK
  347. tGh
  348. tGh
  349. hSgK
  350. h.gK
  351. h.gK
  352. h.gK
  353. Ph%gK
  354. h.gK
  355. hbgK
  356. h]gK
  357. h[hK
  358. ueh]hK
  359. h]hK
  360. h&hK
  361. t5PP
  362. h?hK
  363. h0hK
  364. hKhK
  365. h!hK
  366. tQhnhK
  367. hfhK
  368. huhK
  369. tdh
  370. tkP
  371. VWj
  372. h-iK
  373. h0iK
  374. h:iK
  375. hfiK
  376. hkiK
  377. hpiK
  378. huiK
  379. hziK
  380. tSh
  381. hGiK
  382. tYh
  383. hEjK
  384. h\jK
  385. hqjK
  386. tYh
  387. h)jK
  388. h)jK
  389. VWj
  390. tEh
  391. VWj
  392. tEh
  393. h$kK
  394. VWj
  395. tEh0kK
  396. hBkK
  397. hMkK
  398. tGh
  399. hekK
  400. hekK
  401. VWj
  402. tEh
  403. h/lK
  404. h:lK
  405. klK
  406. hflK
  407. hhlK
  408. 5blK
  409. hNlK
  410. hNlK
  411. hNlK
  412. hblK
  413. hYlK
  414. hGmK
  415. h*mK
  416. hZmK
  417. hGmK
  418. h*mK
  419. hZmK
  420. hOmK
  421. h*mK
  422. hZmK
  423. hOmK
  424. h*mK
  425. hZmK
  426. tSh
  427. PPh
  428. hfmK
  429. hfmK
  430. h'nK
  431. Ph3nK
  432. h@nK
  433. hLnK
  434. h@nK
  435. hLnK
  436. hknK
  437. hknK
  438. h@nK
  439. hXnK
  440. hLnK
  441. hXnK
  442. h@nK
  443. hanK
  444. hLnK
  445. hanK
  446. WVS+
  447. tZP
  448. 7horK
  449. h(rK
  450. hBrK
  451. hdrK
  452. PPP
  453. PPh
  454. huqK
  455. h!bK
  456. EPEP
  457. SEPp
  458. SEP
  459. EPG
  460. VEP
  461. VEP
  462. EPo
  463. EPa
  464. VEP
  465. PEPw
  466. VEPj
  467. pSettings
  468. JTJ
  469. JZJ
  470. JGJ
  471. JCJ
  472. JDJuJ
  473. JGJ}J
  474. jwN
  475. h!bK
  476. h!bK
  477. h!bK
  478. VWj
  479. tEh
  480. YtK
  481. UPh
  482. 5YtK
  483. 5YtK
  484. hutK
  485. hyIK
  486. PhitK
  487. UhVGK
  488. SWU
  489. aGK
  490. PhitK
  491. 5atK
  492. atK
  493. SWU
  494. atK
  495. =etK
  496. 5etK
  497. etK
  498. 5etK
  499. 5etK
  500. etK
  501. hVGK
  502. UVW3
  503. trS
  504. tJO@
  505. ri)D$
  506. vGSQ
  507. uFSQ
  508. +L$PR
  509. +T$PQ
  510. L$\RQ
  511. PSQ
  512. 9D$(ub
  513. L$8WQ
  514. D$ HP
  515. QBR
  516. D$LP
  517. D$DPQ
  518. D$@RP
  519. v89l$D|0
  520. L$(UQ
  521. D$@RP
  522. uM9l$D}G
  523. D$@RP
  524. L$(UQ
  525. D$(UP
  526. D$(UP
  527. T$0PR
  528. D$(UP
  529. T$0PR
  530. D$(UP
  531. T$0WR
  532. D$8WP
  533. WSP
  534. L$8WQ
  535. WRP
  536. D$8WP
  537. L$8WQ
  538. USP
  539. L$(UQ
  540. D$(UP
  541. T$0WR
  542. D$8WP
  543. WUP
  544. L$8WQ
  545. D$TCH
  546. T$8WR
  547. +T$PQ
  548. +L$PRQW
  549. SVW
  550. SVW
  551. PPS
  552. SVW
  553. PPS
  554. SVW
  555. SVW
  556. SVW
  557. SVW
  558. PPSV
  559. aPLib v1.01 - the smaller the better :)
  560. Copyright (c) 1998-2009 by Joergen Ibsen, All Rights Reserved.
  561. More information: http://www.ibsensoftware.com/
  562. HzS
  563. password
  564. phpbb
  565. qwerty
  566. jesus
  567. abc123
  568. letmein
  569. test
  570. love
  571. password1
  572. hello
  573. monkey
  574. dragon
  575. trustno1
  576. iloveyou
  577. shadow
  578. christ
  579. sunshine
  580. master
  581. computer
  582. princess
  583. tigger
  584. football
  585. angel
  586. jesus1
  587. whatever
  588. freedom
  589. killer
  590. asdf
  591. soccer
  592. superman
  593. michael
  594. cheese
  595. internet
  596. joshua
  597. fuckyou
  598. blessed
  599. baseball
  600. starwars
  601. purple
  602. jordan
  603. faith
  604. summer
  605. ashley
  606. buster
  607. heaven
  608. pepper
  609. hunter
  610. lovely
  611. andrew
  612. thomas
  613. angels
  614. charlie
  615. daniel
  616. jennifer
  617. single
  618. hannah
  619. qazwsx
  620. happy
  621. matrix
  622. pass
  623. aaaaaa
  624. amanda
  625. nothing
  626. ginger
  627. mother
  628. snoopy
  629. jessica
  630. welcome
  631. pokemon
  632. iloveyou1
  633. mustang
  634. helpme
  635. justin
  636. jasmine
  637. orange
  638. testing
  639. apple
  640. michelle
  641. peace
  642. secret
  643. grace
  644. william
  645. iloveyou2
  646. nicole
  647. muffin
  648. gateway
  649. fuckyou1
  650. asshole
  651. hahaha
  652. poop
  653. blessing
  654. blahblah
  655. myspace1
  656. matthew
  657. canada
  658. silver
  659. robert
  660. forever
  661. asdfgh
  662. rachel
  663. rainbow
  664. guitar
  665. peanut
  666. batman
  667. cookie
  668. bailey
  669. soccer1
  670. mickey
  671. biteme
  672. hello1
  673. eminem
  674. dakota
  675. samantha
  676. compaq
  677. diamond
  678. taylor
  679. forum
  680. john316
  681. richard
  682. blink182
  683. peaches
  684. cool
  685. flower
  686. scooter
  687. banana
  688. james
  689. asdfasdf
  690. victory
  691. london
  692. 123qwe
  693. startrek
  694. george
  695. winner
  696. maggie
  697. trinity
  698. online
  699. 123abc
  700. chicken
  701. junior
  702. chris
  703. passw0rd
  704. austin
  705. sparky
  706. admin
  707. merlin
  708. google
  709. friends
  710. hope
  711. shalom
  712. nintendo
  713. looking
  714. harley
  715. smokey
  716. joseph
  717. lucky
  718. digital
  719. thunder
  720. spirit
  721. bandit
  722. enter
  723. anthony
  724. corvette
  725. hockey
  726. power
  727. benjamin
  728. iloveyou!
  729. 1q2w3e
  730. viper
  731. genesis
  732. knight
  733. qwerty1
  734. creative
  735. foobar
  736. adidas
  737. rotimi
  738. slayer
  739. wisdom
  740. praise
  741. zxcvbnm
  742. samuel
  743. mike
  744. dallas
  745. green
  746. testtest
  747. maverick
  748. onelove
  749. david
  750. mylove
  751. church
  752. friend
  753. god
  754. destiny
  755. none
  756. microsoft
  757. bubbles
  758. cocacola
  759. jordan23
  760. ilovegod
  761. football1
  762. loving
  763. nathan
  764. emmanuel
  765. scooby
  766. fuckoff
  767. sammy
  768. maxwell
  769. jason
  770. john
  771. 1q2w3e4r
  772. baby
  773. red123
  774. blabla
  775. prince
  776. qwert
  777. chelsea
  778. angel1
  779. hardcore
  780. dexter
  781. saved
  782. hallo
  783. jasper
  784. danielle
  785. kitten
  786. cassie
  787. stella
  788. prayer
  789. hotdog
  790. windows
  791. mustdie
  792. gates
  793. billgates
  794. ghbdtn
  795. gfhjkm
  796. hgTYDOMium
  797. http://132.248.49.112:8080/asp/intro.php
  798. http://113.130.65.77:8080/asp/intro.php
  799. http://203.113.98.131:8080/asp/intro.php
  800. http://110.164.58.250:8080/asp/intro.php
  801. http://200.108.18.158:8080/asp/intro.php
  802. http://207.182.144.115:8080/asp/intro.php
  803. http://148.208.216.70:8080/asp/intro.php
  804. http://203.172.252.26:8080/asp/intro.php
  805. http://202.6.120.103:8080/asp/intro.php
  806. http://203.146.208.180:8080/asp/intro.php
  807. http://207.126.57.208:8080/asp/intro.php
  808. http://203.80.16.81:8080/asp/intro.php
  809. http://202.180.221.186:8080/asp/intro.php
  810. YUIPWDFILE0YUIPKDFILE0YUICRYPTED0YUI1.0
  811. MODU
  812. SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
  813. UninstallString
  814. DisplayName
  815. .exe
  816. Software\WinRAR
  817. open
  818. kernel32.dll
  819. WTSGetActiveConsoleSessionId
  820. ProcessIdToSessionId
  821. netapi32.dll
  822. NetApiBufferFree
  823. NetUserEnum
  824. ole32.dll
  825. StgOpenStorage
  826. advapi32.dll
  827. AllocateAndInitializeSid
  828. CheckTokenMembership
  829. FreeSid
  830. CredEnumerateA
  831. CredFree
  832. CryptGetUserKey
  833. CryptExportKey
  834. CryptDestroyKey
  835. CryptReleaseContext
  836. RevertToSelf
  837. OpenProcessToken
  838. ImpersonateLoggedOnUser
  839. GetTokenInformation
  840. ConvertSidToStringSidA
  841. LogonUserA
  842. LookupPrivilegeValueA
  843. AdjustTokenPrivileges
  844. crypt32.dll
  845. CryptUnprotectData
  846. CertOpenSystemStoreA
  847. CertEnumCertificatesInStore
  848. CertCloseStore
  849. CryptAcquireCertificatePrivateKey
  850. msi.dll
  851. MsiGetComponentPathA
  852. pstorec.dll
  853. PStoreCreateInstance
  854. z%Y]I(Y
  855. [shell32.dll
  856. SHGetFolderPathA
  857. a}vMK
  858. yNK
  859. My Documents
  860. AppData
  861. Local AppData
  862. Cache
  863. Cookies
  864. History
  865. My Documents
  866. Common AppData
  867. My Pictures
  868. Common Documents
  869. Common Administrative Tools
  870. Administrative Tools
  871. Personal
  872. Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
  873. explorer.exe
  874. SeImpersonatePrivilege
  875. SeTcbPrivilege
  876. SeChangeNotifyPrivilege
  877. SeCreateTokenPrivilege
  878. SeBackupPrivilege
  879. SeRestorePrivilege
  880. SeIncreaseQuotaPrivilege
  881. SeAssignPrimaryTokenPrivilege
  882. POST %s HTTP/1.0
  883. Host: %s
  884. Accept: */*
  885. Accept-Encoding: identity, *;q=0
  886. Content-Length: %lu
  887. Connection: close
  888. Content-Type: application/octet-stream
  889. Content-Encoding: binary
  890. User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows 98)
  891. Content-Length:
  892. Location:
  893. HWID
  894. {%08X-%04X-%04X-%02X%02X-%02X%02X%02X%02X%02X%02X}
  895. GetNativeSystemInfo
  896. kernel32.dll
  897. IsWow64Process
  898. Software\Far\Plugins\FTP\Hosts
  899. Software\Far2\Plugins\FTP\Hosts
  900. Software\Far Manager\Plugins\FTP\Hosts
  901. Software\Far\SavedDialogHistory\FTPHost
  902. Software\Far2\SavedDialogHistory\FTPHost
  903. Software\Far Manager\SavedDialogHistory\FTPHost
  904. Password
  905. HostName
  906. User
  907. Line
  908. wcx_ftp.ini
  909. \GHISLER
  910. InstallDir
  911. FtpIniName
  912. Software\Ghisler\Windows Commander
  913. Software\Ghisler\Total Commander
  914. \Ipswitch
  915. Sites\
  916. \Ipswitch\WS_FTP
  917. \win.ini
  918. .ini
  919. WS_FTP
  920. DIR
  921. DEFDIR
  922. CUTEFTP
  923. QCHistory
  924. Software\GlobalSCAPE\CuteFTP 6 Home\QCToolbar
  925. Software\GlobalSCAPE\CuteFTP 6 Professional\QCToolbar
  926. Software\GlobalSCAPE\CuteFTP 7 Home\QCToolbar
  927. Software\GlobalSCAPE\CuteFTP 7 Professional\QCToolbar
  928. Software\GlobalSCAPE\CuteFTP 8 Home\QCToolbar
  929. Software\GlobalSCAPE\CuteFTP 8 Professional\QCToolbar
  930. \GlobalSCAPE\CuteFTP
  931. \GlobalSCAPE\CuteFTP Pro
  932. \GlobalSCAPE\CuteFTP Lite
  933. \CuteFTP
  934. \sm.dat
  935. Software\FlashFXP\3
  936. Software\FlashFXP
  937. Software\FlashFXP\4
  938. InstallerDathPath
  939. path
  940. Install Path
  941. DataFolder
  942. \Sites.dat
  943. \Quick.dat
  944. \History.dat
  945. \FlashFXP\3
  946. \FlashFXP\4
  947. \FileZilla
  948. \sitemanager.xml
  949. \recentservers.xml
  950. \filezilla.xml
  951. Software\FileZilla
  952. Software\FileZilla Client
  953. Install_Dir
  954. Host
  955. User
  956. Pass
  957. Port
  958. Remote Dir
  959. Server Type
  960. Server.Host
  961. Server.User
  962. Server.Pass
  963. Server.Port
  964. Path
  965. ServerType
  966. Last Server Host
  967. Last Server User
  968. Last Server Pass
  969. Last Server Port
  970. Last Server Path
  971. Last Server Type
  972. FTP Navigator
  973. FTP Commander
  974. ftplist.txt
  975. \BulletProof Software
  976. .dat
  977. .bps
  978. Software\BPFTP\Bullet Proof FTP\Main
  979. Software\BulletProof Software\BulletProof FTP Client\Main
  980. Software\BPFTP\Bullet Proof FTP\Options
  981. Software\BulletProof Software\BulletProof FTP Client\Options
  982. Software\BPFTP
  983. LastSessionFile
  984. SitesDir
  985. InstallDir1
  986. .xml
  987. \SmartFTP
  988. Favorites.dat
  989. History.dat
  990. addrbk.dat
  991. quick.dat
  992. \TurboFTP
  993. Software\TurboFTP
  994. installpath
  995. Software\Sota\FFFTP
  996. CredentialSalt
  997. CredentialCheck
  998. Software\Sota\FFFTP\Options
  999. Password
  1000. UserName
  1001. HostAdrs
  1002. RemoteDir
  1003. Port
  1004. HostName
  1005. Port
  1006. Username
  1007. Password
  1008. HostDirName
  1009. Software\CoffeeCup Software\Internet\Profiles
  1010. Software\FTPWare\COREFTP\Sites
  1011. Host
  1012. User
  1013. Port
  1014. PthR
  1015. SSH
  1016. profiles.xml
  1017. \FTP Explorer
  1018. Software\FTP Explorer\FTP Explorer\Workspace\MFCToolBar-224
  1019. Buttons
  1020. Software\FTP Explorer\Profiles
  1021. Password
  1022. PasswordType
  1023. Host
  1024. Login
  1025. Port
  1026. InitialPath
  1027. FtpSite.xml
  1028. \Frigate3
  1029. .ini
  1030. \VanDyke\Config\Sessions
  1031. \Sessions
  1032. Software\VanDyke\SecureFX
  1033. Config Path
  1034. UltraFXP
  1035. \sites.xml
  1036. \FTPRush
  1037. RushSite.xml
  1038. Server
  1039. Username
  1040. Password
  1041. FtpPort
  1042. Software\Cryer\WebSitePublisher
  1043. \BitKinex
  1044. bitkinex.ds
  1045. Hostname
  1046. Username
  1047. Password
  1048. Port
  1049. Software\ExpanDrive\Sessions
  1050. \ExpanDrive
  1051. \drives.js
  1052. "password" : "
  1053. Software\ExpanDrive
  1054. ExpanDrive_Home
  1055. Server
  1056. UserName
  1057. Password
  1058. _Password
  1059. Directory
  1060. Software\NCH Software\ClassicFTP\FTPAccounts
  1061. FtpServer
  1062. FtpUserName
  1063. FtpPassword
  1064. _FtpPassword
  1065. FtpDirectory
  1066. SOFTWARE\NCH Software\Fling\Accounts
  1067. Software\FTPClient\Sites
  1068. Software\SoftX.org\FTPClient\Sites
  1069. .oxc
  1070. .oll
  1071. ftplast.osd
  1072. \GPSoftware\Directory Opus
  1073. \SharedSettings.ccs
  1074. \SharedSettings_1_0_5.ccs
  1075. \SharedSettings.sqlite
  1076. \SharedSettings_1_0_5.sqlite
  1077. \CoffeeCup Software
  1078. leapftp
  1079. unleap.exe
  1080. sites.dat
  1081. sites.ini
  1082. \LeapWare\LeapFTP
  1083. SOFTWARE\LeapWare
  1084. InstallPath
  1085. DataDir
  1086. Password
  1087. HostName
  1088. UserName
  1089. RemoteDirectory
  1090. PortNumber
  1091. FSProtocol
  1092. Software\Martin Prikryl
  1093. \32BitFtp.ini
  1094. NDSites.ini
  1095. \NetDrive
  1096. PassWord
  1097. Url
  1098. UserName
  1099. RootDirectory
  1100. Port
  1101. Software\South River Technologies\WebDrive\Connections
  1102. ServerType
  1103. FTP CONTROL
  1104. FTPCON
  1105. .prf
  1106. \Profiles
  1107. ftp://
  1108. opera
  1109. wand.dat
  1110. _Software\Opera Software
  1111. Last Directory3
  1112. Last Install Path
  1113. Opera.HTML\shell\open\command
  1114. wiseftpsrvs.bin
  1115. \AceBIT
  1116. Software\AceBIT
  1117. MRU
  1118. SOFTWARE\Classes\TypeLib\{CB1F2C0F-8094-4AAC-BCF5-41A64E27F777}
  1119. SOFTWARE\Classes\TypeLib\{9EA55529-E122-4757-BC79-E4825F80732C}
  1120. wiseftpsrvs.ini
  1121. wiseftp.ini
  1122. FTPVoyager.ftp
  1123. FTPVoyager.qc
  1124. \RhinoSoft.com
  1125. nss3.dll
  1126. NSS_Init
  1127. NSS_Shutdown
  1128. NSSBase64_DecodeBuffer
  1129. SECITEM_FreeItem
  1130. PK11_GetInternalKeySlot
  1131. PK11_Authenticate
  1132. PK11SDR_Decrypt
  1133. PK11_FreeSlot
  1134. sqlite3.dll
  1135. sqlite3_open
  1136. sqlite3_close
  1137. sqlite3_prepare
  1138. sqlite3_step
  1139. sqlite3_column_bytes
  1140. sqlite3_column_blob
  1141. mozsqlite3.dll
  1142. sqlite3_open
  1143. sqlite3_close
  1144. sqlite3_prepare
  1145. sqlite3_step
  1146. sqlite3_column_bytes
  1147. sqlite3_column_blob
  1148. profiles.ini
  1149. Profile
  1150. IsRelative
  1151. Path
  1152. PathToExe
  1153. prefs.js
  1154. signons.sqlite
  1155. signons.txt
  1156. signons2.txt
  1157. signons3.txt
  1158. SELECT hostname, encryptedUsername, encryptedPassword FROM moz_logins
  1159. Firefox
  1160. \Mozilla\Firefox\
  1161. Software\Mozilla
  1162. ftp://
  1163. ftp.
  1164. fireFTPsites.dat
  1165. SeaMonkey
  1166. \Mozilla\SeaMonkey\
  1167. Flock
  1168. \Flock\Browser\
  1169. Mozilla
  1170. \Mozilla\Profiles\
  1171. Software\LeechFTP
  1172. AppDir
  1173. LocalDir
  1174. bookmark.dat
  1175. SiteInfo.QFP
  1176. Odin
  1177. Favorites.dat
  1178. WinFTP
  1179. sites.db
  1180. CLSID\{11C1D741-A95B-11d2-8A80-0080ADB32FF4}\InProcServer32
  1181. servers.xml
  1182. \FTPGetter
  1183. ESTdb2.dat
  1184. QData.dat
  1185. \Estsoft\ALFTP
  1186. Internet Explorer
  1187. WininetCacheCredentials
  1188. MS IE FTP Passwords
  1189. DPAPI:
  1190. Software\Microsoft\Internet Explorer\IntelliForms\Storage2
  1191. Microsoft_WinInet_*
  1192. ftp://
  1193. Software\Adobe\Common
  1194. SiteServers
  1195. SiteServer %d\Host
  1196. SiteServer %d\WebUrl
  1197. SiteServer %d\Remote Directory
  1198. SiteServer %d-User
  1199. SiteServer %d-User PW
  1200. %s\Keychain
  1201. SiteServer %d\SFTP
  1202. DeluxeFTP
  1203. sites.xml
  1204. Web Data
  1205. Login Data
  1206. SQLite format 3
  1207. table
  1208. CONSTRAINT
  1209. PRIMARY
  1210. UNIQUE
  1211. CHECK
  1212. FOREIGN
  1213. logins
  1214. origin_url
  1215. password_value
  1216. username_value
  1217. ftp://
  1218. \Google\Chrome
  1219. \Chromium
  1220. \ChromePlus
  1221. Software\ChromePlus
  1222. Install_Dir
  1223. \Bromium
  1224. \Nichrome
  1225. \Comodo
  1226. \RockMelt
  1227. K-Meleon
  1228. \K-Meleon
  1229. \Profiles
  1230. Epic
  1231. \Epic\Epic
  1232. Staff-FTP
  1233. sites.ini
  1234. \Sites
  1235. \Visicom Media
  1236. .ftp
  1237. \Global Downloader
  1238. SM.arch
  1239. FreshFTP
  1240. .SMF
  1241. BlazeFtp
  1242. site.dat
  1243. LastPassword
  1244. LastAddress
  1245. LastUser
  1246. LastPort
  1247. Software\FlashPeak\BlazeFtp\Settings
  1248. \BlazeFtp
  1249. .fpl
  1250. FTP++.Link\shell\open\command
  1251. GoFTP
  1252. Connections.txt
  1253. 3D-FTP
  1254. sites.ini
  1255. \3D-FTP
  1256. \SiteDesigner
  1257. SOFTWARE\Classes\TypeLib\{F9043C88-F6F2-101A-A3C9-08002B2F49FB}\1.2\0\win32
  1258. EasyFTP
  1259. \NetSarang
  1260. .xfp
  1261. .rdp
  1262. TERMSRV/*
  1263. password 51:b:
  1264. username:s:
  1265. full address:s:
  1266. TERMSRV/
  1267. FTP Now
  1268. FTPNow
  1269. sites.xml
  1270. SOFTWARE\Robo-FTP 3.7\Scripts
  1271. SOFTWARE\Robo-FTP 3.7\FTPServers
  1272. FTP Count
  1273. FTP File%d
  1274. Password
  1275. ServerName
  1276. UserID
  1277. InitialDirectory
  1278. PortNumber
  1279. ServerType
  1280. fMY
  1281. Software\LinasFTP\Site Manager
  1282. Host
  1283. User
  1284. Pass
  1285. Port
  1286. Remote Dir
  1287. \Cyberduck
  1288. .duck
  1289. user.config
  1290. <setting name="
  1291. value="
  1292. Software\SimonTatham\PuTTY\Sessions
  1293. HostName
  1294. UserName
  1295. Password
  1296. PortNumber
  1297. TerminalType
  1298. NppFTP.xml
  1299. \Notepad++
  1300. Software\CoffeeCup Software
  1301. FTP destination server
  1302. FTP destination user
  1303. FTP destination password
  1304. FTP destination port
  1305. FTP destination catalog
  1306. FTP profiles
  1307. FTPShell
  1308. ftpshell.fsi
  1309. Software\MAS-Soft\FTPInfo\Setup
  1310. DataDir
  1311. \FTPInfo
  1312. ServerList.xml
  1313. NexusFile
  1314. ftpsite.ini
  1315. FastStone Browser
  1316. FTPList.db
  1317. \MapleStudio\ChromePlus
  1318. Software\Nico Mak Computing\WinZip\FTP
  1319. Software\Nico Mak Computing\WinZip\mru\jobs
  1320. Site
  1321. UserID
  1322. xflags
  1323. Port
  1324. Folder
  1325. .wjf
  1326. winex="
  1327. \Yandex
  1328. My FTP
  1329. project.ini
  1330. .xml
  1331. {74FF1730-B1F2-4D88-926B-1568FAE61DB7}
  1332. NovaFTP.db
  1333. \INSoftware\NovaFTP
  1334. .oeaccount
  1335. Salt
  1336. <POP3_Password2
  1337. <SMTP_Password2
  1338. <IMAP_Password2
  1339. <HTTPMail_Password2
  1340. \Microsoft\Windows Live Mail
  1341. Software\Microsoft\Windows Live Mail
  1342. \Microsoft\Windows Mail
  1343. Software\Microsoft\Windows Mail
  1344. Software\RimArts\B2\Settings
  1345. DataDir
  1346. DataDirBak
  1347. Mailbox.ini
  1348. Software\Poco Systems Inc
  1349. Path
  1350. \PocoSystem.ini
  1351. Program
  1352. DataPath
  1353. accounts.ini
  1354. \Pocomail
  1355. Software\IncrediMail
  1356. EmailAddress
  1357. Technology
  1358. PopServer
  1359. PopPort
  1360. PopAccount
  1361. PopPassword
  1362. SmtpServer
  1363. SmtpPort
  1364. SmtpAccount
  1365. SmtpPassword
  1366. account.cfg
  1367. account.cfn
  1368. \BatMail
  1369. \The Bat!
  1370. Software\RIT\The Bat!
  1371. Software\RIT\The Bat!\Users depot
  1372. Working Directory
  1373. ProgramDir
  1374. Count
  1375. Default
  1376. Dir #%d
  1377. SMTP Email Address
  1378. SMTP Server
  1379. POP3 Server
  1380. POP3 User Name
  1381. SMTP User Name
  1382. NNTP Email Address
  1383. NNTP User Name
  1384. NNTP Server
  1385. IMAP Server
  1386. IMAP User Name
  1387. Email
  1388. HTTP User
  1389. HTTP Server URL
  1390. POP3 User
  1391. IMAP User
  1392. HTTPMail User Name
  1393. HTTPMail Server
  1394. SMTP User
  1395. POP3 Port
  1396. SMTP Port
  1397. IMAP Port
  1398. POP3 Password2
  1399. IMAP Password2
  1400. NNTP Password2
  1401. HTTPMail Password2
  1402. SMTP Password2
  1403. POP3 Password
  1404. IMAP Password
  1405. NNTP Password
  1406. HTTP Password
  1407. SMTP Password
  1408. Software\Microsoft\Internet Account Manager\Accounts
  1409. Identities
  1410. Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts
  1411. Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Microsoft Outlook Internet Settings
  1412. Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook
  1413. Software\Microsoft\Internet Account Manager
  1414. Outlook
  1415. \Accounts
  1416. identification
  1417. identitymgr
  1418. inetcomm server passwords
  1419. outlook account manager passwords
  1420. identities
  1421. {%08X-%04X-%04X-%02X%02X-%02X%02X%02X%02X%02X%02X}
  1422. Thunderbird
  1423. \Thunderbird
  1424. FastTrack
  1425. ftplist.txt
  1426. YfJ
  1427. NgJ
  1428. XhJ
  1429. ZoJ
  1430. iuJ
  1431. nvJ
  1432. qxJ
  1433. Client Hash
  1434. STATUS-IMPORT-OK
  1435. IugvO%gv
  1436. qUS
  1437. qUj
  1438. KERNEL32.DLL
  1439. advapi32.dll
  1440. ole32.dll
  1441. shlwapi.dll
  1442. user32.dll
  1443. userenv.dll
  1444. wininet.dll
  1445. wsock32.dll
  1446. CreateFileA
  1447. ReadFile
  1448. CloseHandle
  1449. WriteFile
  1450. lstrlenA
  1451. GlobalLock
  1452. GlobalUnlock
  1453. LocalFree
  1454. LocalAlloc
  1455. lstrcpyA
  1456. lstrcatA
  1457. GetFileAttributesA
  1458. ExpandEnvironmentStringsA
  1459. GetFileSize
  1460. CreateFileMappingA
  1461. MapViewOfFile
  1462. UnmapViewOfFile
  1463. LoadLibraryA
  1464. GetProcAddress
  1465. GetTempPathA
  1466. CreateDirectoryA
  1467. DeleteFileA
  1468. GetCurrentProcess
  1469. WideCharToMultiByte
  1470. GetLastError
  1471. lstrcmpA
  1472. CreateToolhelp32Snapshot
  1473. Process32First
  1474. OpenProcess
  1475. Process32Next
  1476. FindFirstFileA
  1477. lstrcmpiA
  1478. FindNextFileA
  1479. FindClose
  1480. GetModuleHandleA
  1481. GetVersionExA
  1482. GetLocaleInfoA
  1483. GetSystemInfo
  1484. GetWindowsDirectoryA
  1485. GetPrivateProfileStringA
  1486. SetCurrentDirectoryA
  1487. GetPrivateProfileSectionNamesA
  1488. GetPrivateProfileIntA
  1489. GetCurrentDirectoryA
  1490. lstrlenW
  1491. MultiByteToWideChar
  1492. GetTickCount
  1493. Sleep
  1494. LCMapStringA
  1495. ExitProcess
  1496. SetUnhandledExceptionFilter
  1497. RegOpenKeyExA
  1498. RegQueryValueExA
  1499. RegCloseKey
  1500. RegOpenKeyA
  1501. RegEnumKeyExA
  1502. RegCreateKeyA
  1503. RegSetValueExA
  1504. IsTextUnicode
  1505. RegOpenCurrentUser
  1506. RegEnumValueA
  1507. GetUserNameA
  1508. CreateStreamOnHGlobal
  1509. GetHGlobalFromStream
  1510. CoCreateGuid
  1511. CoTaskMemFree
  1512. OleInitialize
  1513. StrStrIA
  1514. StrRChrIA
  1515. StrToIntA
  1516. StrStrA
  1517. StrCmpNIA
  1518. wsprintfA
  1519. LoadUserProfileA
  1520. UnloadUserProfile
  1521. InternetCrackUrlA
  1522. InternetCreateUrlA
  1523. inet_addr
  1524. gethostbyname
  1525. socket
  1526. connect
  1527. closesocket
  1528. send
  1529. select
  1530. recv
  1531. setsockopt
  1532. WSAStartup
  1533. jHq
  1534. kdz
  1535. rqg
  1536. LhX
  1537. Qkkbal
  1538. Zjz
  1539. i]Wb
  1540. knv
  1541. owG
  1542. kaE
  1543. MGiI
  1544. wn>Jj
  1545. Invalid filename.
  1546. Failed to open document.
  1547. Failed to save document.
  1548. Save changes to %1? Failed to create empty document.
  1549. The file is too large to open.
  1550. Could not start print job.
  1551. Failed to launch help.
  1552. Internal application error.
  1553. Command failed.)Insufficient memory to perform operation.PSystem registry entries have
  1554. VS_VERSION_INFO
  1555. StringFileInfo
  1556. CompanyName
  1557. Sun Microsystems, Inc.
  1558. FileDescription
  1559. Java(TM) Platform SE binary
  1560. FileVersion
  1561. Full Version
  1562. InternalName
  1563. java
  1564. LegalCopyright
  1565. Copyright
  1566. OriginalFilename
  1567. java.exe
  1568. ProductName
  1569. Java(TM) Platform SE 6 U37
  1570. ProductVersion
  1571. VarFileInfo
  1572. Translation
  1573. wwwwwww
  1574. wwwwwwwwwww
  1575. wwwx
  1576. www
  1577. wwwww
  1578. wwwwwwx
  1579. wwx
  1580. wwwwwww
  1581. wwwwwwwx
  1582. wwwwwx
  1583. wwwx
  1584. wwww
  1585. xww
  1586. wwwww
  1587. wwx
  1588. www
  1589. wwww
  1590. wwww
  1591. www
  1592. -------
  1593. #MalwareMustDie!!!!!
Add Comment
Please, Sign In to add comment