Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Zeus/Pony Injected by Hancitor PE DLL: edd954f233c0f72ecf4beb0e63177969a297c6ee8e1da2bcc90924b922da0d88
- Ref: #OCJP-133
- // files - creds & privacy
- C:\DOCUME~1\GREGSC~1\LOCALS~1\Temp\HWID
- C:\WINDOWS\wcx_ftp.ini
- C:\Documents and Settings\...\wcx_ftp.ini
- C:\Documents and Settings\..\Application Data\GHISLER\wcx_ftp.ini
- C:\Documents and Settings\All Users\Application Data\GHISLER\wcx_ftp.ini
- C:\Documents and Settings\...\Local Settings\Application Data\GHISLER\wcx_ftp.ini
- C:\Documents and Settings\..\Application Data\GlobalSCAPE\CuteFTP\sm.dat
- C:\Documents and Settings\..\Application Data\GlobalSCAPE\CuteFTP Pro\sm.dat
- C:\Documents and Settings\..\Application Data\GlobalSCAPE\CuteFTP Lite\sm.dat
- C:\Documents and Settings\..\Application Data\CuteFTP\sm.dat
- C:\Documents and Settings\All Users\Application Data\GlobalSCAPE\CuteFTP\sm.dat
- C:\Documents and Settings\All Users\Application Data\GlobalSCAPE\CuteFTP Pro\sm.dat
- C:\Documents and Settings\All Users\Application Data\GlobalSCAPE\CuteFTP Lite\sm.dat
- C:\Documents and Settings\All Users\Application Data\CuteFTP\sm.dat
- C:\Documents and Settings\...\Local Settings\Application Data\GlobalSCAPE\CuteFTP\sm.dat
- C:\Documents and Settings\...\Local Settings\Application Data\GlobalSCAPE\CuteFTP Pro\sm.dat
- C:\Documents and Settings\...\Local Settings\Application Data\GlobalSCAPE\CuteFTP Lite\sm.dat
- C:\Documents and Settings\...\Local Settings\Application Data\CuteFTP\sm.dat
- C:\Program Files\GlobalSCAPE\CuteFTP\sm.dat
- C:\Program Files\GlobalSCAPE\CuteFTP Pro\sm.dat
- C:\Program Files\GlobalSCAPE\CuteFTP Lite\sm.dat
- C:\Program Files\CuteFTP\sm.dat
- C:\Documents and Settings\..\Application Data\FlashFXP\3\Sites.dat
- C:\Documents and Settings\..\Application Data\FlashFXP\4\Sites.dat
- C:\Documents and Settings\..\Application Data\FlashFXP\3\Quick.dat
- C:\Documents and Settings\..\Application Data\FlashFXP\4\Quick.dat
- C:\Documents and Settings\..\Application Data\FlashFXP\3\History.dat
- C:\Documents and Settings\..\Application Data\FlashFXP\4\History.dat
- C:\Documents and Settings\All Users\Application Data\FlashFXP\3\Sites.dat
- C:\Documents and Settings\All Users\Application Data\FlashFXP\4\Sites.dat
- C:\Documents and Settings\All Users\Application Data\FlashFXP\3\Quick.dat
- C:\Documents and Settings\All Users\Application Data\FlashFXP\4\Quick.dat
- C:\Documents and Settings\All Users\Application Data\FlashFXP\3\History.dat
- C:\Documents and Settings\All Users\Application Data\FlashFXP\4\History.dat
- C:\Documents and Settings\...\Local Settings\Application Data\FlashFXP\3\Sites.dat
- C:\Documents and Settings\...\Local Settings\Application Data\FlashFXP\4\Sites.dat
- C:\Documents and Settings\...\Local Settings\Application Data\FlashFXP\3\Quick.dat
- C:\Documents and Settings\...\Local Settings\Application Data\FlashFXP\4\Quick.dat
- C:\Documents and Settings\...\Local Settings\Application Data\FlashFXP\3\History.dat
- C:\Documents and Settings\...\Local Settings\Application Data\FlashFXP\4\History.dat
- C:\Documents and Settings\..\Application Data\FileZilla\sitemanager.xml
- C:\Documents and Settings\..\Application Data\FileZilla\recentservers.xml
- C:\Documents and Settings\..\Application Data\FileZilla\filezilla.xml
- C:\Documents and Settings\All Users\Application Data\FileZilla\sitemanager.xml
- C:\Documents and Settings\All Users\Application Data\FileZilla\recentservers.xml
- C:\Documents and Settings\All Users\Application Data\FileZilla\filezilla.xml
- C:\Documents and Settings\...\Local Settings\Application Data\FileZilla\sitemanager.xml
- C:\Documents and Settings\...\Local Settings\Application Data\FileZilla\recentservers.xml
- C:\Documents and Settings\...\Local Settings\Application Data\FileZilla\filezilla.xml
- C:\Documents and Settings\..\Application Data\Mozilla\Firefox\profiles.ini
- C:\Program Files\Common Files\Ipswitch\WS_FTP\
- C:\Documents and Settings\..\Application Data\Ipswitch\
- C:\Documents and Settings\All Users\Application Data\Ipswitch\
- C:\Documents and Settings\...\Local Settings\Application Data\Ipswitch\
- C:\Documents and Settings\..\Application Data\GlobalSCAPE\CuteFTP\
- C:\Documents and Settings\..\Application Data\GlobalSCAPE\CuteFTP Pro\
- C:\Documents and Settings\..\Application Data\GlobalSCAPE\CuteFTP Lite\
- C:\Documents and Settings\..\Application Data\CuteFTP\
- C:\Documents and Settings\All Users\Application Data\GlobalSCAPE\CuteFTP\
- C:\Documents and Settings\All Users\Application Data\GlobalSCAPE\CuteFTP Pro\
- C:\Documents and Settings\All Users\Application Data\GlobalSCAPE\CuteFTP Lite\
- C:\Documents and Settings\All Users\Application Data\CuteFTP\
- C:\Documents and Settings\...\Local Settings\Application Data\GlobalSCAPE\CuteFTP\
- C:\Documents and Settings\...\Local Settings\Application Data\GlobalSCAPE\CuteFTP Pro\
- C:\Documents and Settings\...\Local Settings\Application Data\GlobalSCAPE\CuteFTP Lite\
- C:\Documents and Settings\...\Local Settings\Application Data\CuteFTP\
- C:\Program Files\GlobalSCAPE\CuteFTP\
- C:\Program Files\GlobalSCAPE\CuteFTP Pro\
- C:\Program Files\GlobalSCAPE\CuteFTP Lite\
- C:\Program Files\CuteFTP\
- C:\Documents and Settings\...\Local Settings\Application Data\BulletProof Software\
- C:\Documents and Settings\..\Application Data\BulletProof Software\
- C:\Documents and Settings\All Users\Application Data\BulletProof Software\
- C:\Documents and Settings\..\Application Data\SmartFTP\
- C:\Documents and Settings\All Users\Application Data\SmartFTP\
- C:\Documents and Settings\...\Local Settings\Application Data\SmartFTP\
- C:\Documents and Settings\..\Application Data\VanDyke\Config\Sessions\
- C:\Documents and Settings\All Users\Application Data\VanDyke\Config\Sessions\
- C:\Documents and Settings\...\Local Settings\Application Data\VanDyke\Config\Sessions\
- C:\Documents and Settings\..\Application Data\
- C:\Documents and Settings\All Users\Application Data\
- C:\Documents and Settings\...\Local Settings\Application Data\
- C:\Documents and Settings\..\Application Data\Opera Software\
- C:\Documents and Settings\...\Local Settings\Application Data\Opera Software\
- C:\Documents and Settings\All Users\Application Data\Opera Software\
- C:\Documents and Settings\..\Application Data\Mozilla\Firefox\Profiles\..default\
- C:\Documents and Settings\..\Application Data\Mozilla\Firefox\Profiles\..default\bookmarkbackups\
- C:\Documents and Settings\..\Application Data\Mozilla\Firefox\Profiles\..default\crashes\
- C:\Documents and Settings\..\Application Data\Mozilla\Firefox\Profiles\..default\crashes\events\
- C:\Documents and Settings\..\Application Data\Mozilla\Firefox\Profiles\..default\datareporting\
- C:\Documents and Settings\..\Application Data\Mozilla\Firefox\Profiles\..default\healthreport\
- C:\Documents and Settings\..\Application Data\Mozilla\Firefox\Profiles\..default\minidumps\
- C:\Documents and Settings\..\Application Data\Mozilla\Firefox\Profiles\..default\sessionstore-backups\
- C:\Documents and Settings\..\Application Data\Mozilla\Firefox\Profiles\..default\storage\
- C:\Documents and Settings\..\Application Data\Mozilla\Firefox\Profiles\..default\storage\permanent\
- C:\Documents and Settings\..\Application Data\Mozilla\Firefox\Profiles\..default\storage\permanent\moz-safe-about+home\
- C:\Documents and Settings\..\Application Data\Mozilla\Firefox\Profiles\..default\storage\permanent\moz-safe-about+home\idb\
- C:\Documents and Settings\..\Application Data\Mozilla\Firefox\Profiles\..default\storage\permanent\moz-safe-about+home\idb\818200132aebmoouht.files\
- C:\Documents and Settings\..\Application Data\Mozilla\Firefox\Profiles\..default\webapps\
- C:\Documents and Settings\..\Application Data\Mozilla\Firefox\
- C:\Documents and Settings\..\Application Data\Mozilla\Firefox\Crash Reports\
- C:\Documents and Settings\..\Application Data\Mozilla\Firefox\Crash Reports\events\
- C:\Documents and Settings\..\Application Data\Mozilla\Firefox\Profiles\
- C:\Documents and Settings\..\Application Data\Google\Chrome\
- C:\Documents and Settings\...\Local Settings\Application Data\Google\Chrome\
- C:\Documents and Settings\...\Local Settings\Application Data\Google\Chrome\User Data\
- C:\Documents and Settings\All Users\Application Data\Google\Chrome\
- C:\Documents and Settings\..\Application Data\ChromePlus\
- C:\Documents and Settings\...\Local Settings\Application Data\ChromePlus\
- C:\Documents and Settings\All Users\Application Data\ChromePlus\
- C:\Documents and Settings\...\My Documents\
- C:\Documents and Settings\...\My Documents\My Music\
- C:\Documents and Settings\...\My Documents\My Pictures\
- // registry - creds & privacy
- HKEY_USERS\Software\WinRAR
- HKEY_USERS\Software\Ghisler\Windows Commander
- HKEY_LOCAL_MACHINE\Software\Ghisler\Windows Commander
- HKEY_USERS\Software\Ghisler\Total Commander
- HKEY_LOCAL_MACHINE\Software\Ghisler\Total Commander
- HKEY_USERS\Software\GlobalSCAPE\CuteFTP 6 Home\QCToolbar
- HKEY_USERS\Software\GlobalSCAPE\CuteFTP 6 Professional\QCToolbar
- HKEY_USERS\Software\GlobalSCAPE\CuteFTP 7 Home\QCToolbar
- HKEY_USERS\Software\GlobalSCAPE\CuteFTP 7 Professional\QCToolbar
- HKEY_USERS\Software\GlobalSCAPE\CuteFTP 8 Home\QCToolbar
- HKEY_USERS\Software\GlobalSCAPE\CuteFTP 8 Professional\QCToolbar
- HKEY_USERS\Software\GlobalSCAPE\CuteFTP 9\QCToolbar
- HKEY_USERS\Software\FlashFXP\3
- HKEY_USERS\Software\FlashFXP
- HKEY_USERS\Software\FlashFXP\4
- HKEY_LOCAL_MACHINE\Software\FlashFXP\3
- HKEY_LOCAL_MACHINE\Software\FlashFXP
- HKEY_LOCAL_MACHINE\Software\FlashFXP\4
- HKEY_USERS\Software\FileZilla
- HKEY_USERS\Software\FileZilla Client
- HKEY_LOCAL_MACHINE\Software\FileZilla
- HKEY_LOCAL_MACHINE\Software\FileZilla Client
- HKEY_USERS\Software\BPFTP\Bullet Proof FTP\Main
- HKEY_USERS\Software\BulletProof Software\BulletProof FTP Client\Main
- HKEY_USERS\Software\BPFTP\Bullet Proof FTP\Options
- HKEY_USERS\Software\BulletProof Software\BulletProof FTP Client\Options
- HKEY_USERS\Software\BPFTP
- HKEY_USERS\Software\FTPWare\COREFTP\Sites
- HKEY_USERS\Software\VanDyke\SecureFX
- HKEY_USERS\Software\Martin Prikryl
- HKEY_LOCAL_MACHINE\Software\Martin Prikryl
- HKEY_USERS\Software\Opera Software
- HKEY_USERS\Opera.HTML\shell\open\command
- HKEY_LOCAL_MACHINE\Software\Classes\Opera.HTML\shell\open\command
- HKEY_USERS\Software\Mozilla
- HKEY_LOCAL_MACHINE\Software\Mozilla
- HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox
- HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\extensions
- HKEY_LOCAL_MACHINE\Software\Mozilla\MaintenanceService
- HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox
- HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\xxx
- HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\xxx\Main
- HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\xxx\Uninstall
- HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox xxx\bin
- HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox xxx\extensions
- HKEY_USERS\Software\Microsoft\Internet Explorer\IntelliForms\Storage2
- HKEY_USERS\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\IntelliForms\FormData
- HKEY_USERS\Software\ChromePlus
- HKEY_USERS\Software\Microsoft\Windows Live Mail
- HKEY_USERS\Software\Microsoft\Windows Mail
- HKEY_USERS\Software\IncrediMail
- HKEY_LOCAL_MACHINE\Software\IncrediMail
- HKEY_USERS\Software\Microsoft\Internet Account Manager\Accounts
- HKEY_USERS\Identities
- HKEY_USERS\Identities\xxx\Microsoft\Internet Account Manager\Accounts
- HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Account Manager
- HKEY_USERS\Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts
- HKEY_USERS\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Microsoft Outlook Internet Settings
- HKEY_USERS\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook
- HKEY_USERS\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook
- HKEY_USERS\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook
- #MalwareMustDie | @unixfreaxjp
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement