MalwareMustDie

#BHEK 2013-02-13- Trojan PWS Fareit Stolen Credential Lists

Feb 13th, 2013
1,561
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 10.25 KB | None | 0 0
  1. SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
  2. UninstallString
  3. DisplayName
  4. .exe
  5. Software\WinRAR
  6. open
  7. kernel32.dll
  8. WTSGetActiveConsoleSessionId
  9. ProcessIdToSessionId
  10. netapi32.dll
  11. NetApiBufferFree
  12. NetUserEnum
  13. ole32.dll
  14. StgOpenStorage
  15. advapi32.dll
  16. AllocateAndInitializeSid
  17. CheckTokenMembership
  18. FreeSid
  19. CredEnumerateA
  20. CredFree
  21. CryptGetUserKey
  22. CryptExportKey
  23. CryptDestroyKey
  24. CryptReleaseContext
  25. RevertToSelf
  26. OpenProcessToken
  27. ImpersonateLoggedOnUser
  28. GetTokenInformation
  29. ConvertSidToStringSidA
  30. LogonUserA
  31. LookupPrivilegeValueA
  32. AdjustTokenPrivileges
  33. crypt32.dll
  34. CryptUnprotectData
  35. CertOpenSystemStoreA
  36. CertEnumCertificatesInStore
  37. CertCloseStore
  38. CryptAcquireCertificatePrivateKey
  39. msi.dll
  40. MsiGetComponentPathA
  41. pstorec.dll
  42. PStoreCreateInstance
  43. z%Y]I(Y
  44. [shell32.dll
  45. SHGetFolderPathA
  46. DMK
  47. TMK
  48. dMK
  49. yMK
  50. My Documents
  51. AppData
  52. Local AppData
  53. Cache
  54. Cookies
  55. History
  56. My Documents
  57. Common AppData
  58. My Pictures
  59. Common Documents
  60. Common Administrative Tools
  61. Administrative Tools
  62. Personal
  63. Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
  64. explorer.exe
  65. SeImpersonatePrivilege
  66. SeTcbPrivilege
  67. SeChangeNotifyPrivilege
  68. SeCreateTokenPrivilege
  69. SeBackupPrivilege
  70. SeRestorePrivilege
  71. SeIncreaseQuotaPrivilege
  72. SeAssignPrimaryTokenPrivilege
  73. POST %s HTTP/1.0
  74. Host: %s
  75. Accept: */*
  76. Accept-Encoding: identity, *;q=0
  77. Content-Length: %lu
  78. Connection: close
  79. Content-Type: application/octet-stream
  80. Content-Encoding: binary
  81. User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows 98)
  82. Content-Length:
  83. Location:
  84. HWID
  85. {%08X-%04X-%04X-%02X%02X-%02X%02X%02X%02X%02X%02X}
  86. GetNativeSystemInfo
  87. kernel32.dll
  88. IsWow64Process
  89. Software\Far\Plugins\FTP\Hosts
  90. Software\Far2\Plugins\FTP\Hosts
  91. Software\Far Manager\Plugins\FTP\Hosts
  92. Software\Far\SavedDialogHistory\FTPHost
  93. Software\Far2\SavedDialogHistory\FTPHost
  94. Software\Far Manager\SavedDialogHistory\FTPHost
  95. Password
  96. HostName
  97. User
  98. Line
  99. wcx_ftp.ini
  100. \GHISLER
  101. InstallDir
  102. FtpIniName
  103. Software\Ghisler\Windows Commander
  104. Software\Ghisler\Total Commander
  105. \Ipswitch
  106. Sites\
  107. \Ipswitch\WS_FTP
  108. \win.ini
  109. .ini
  110. WS_FTP
  111. DIR
  112. DEFDIR
  113. CUTEFTP
  114. QCHistory
  115. Software\GlobalSCAPE\CuteFTP 6 Home\QCToolbar
  116. Software\GlobalSCAPE\CuteFTP 6 Professional\QCToolbar
  117. Software\GlobalSCAPE\CuteFTP 7 Home\QCToolbar
  118. Software\GlobalSCAPE\CuteFTP 7 Professional\QCToolbar
  119. Software\GlobalSCAPE\CuteFTP 8 Home\QCToolbar
  120. Software\GlobalSCAPE\CuteFTP 8 Professional\QCToolbar
  121. \GlobalSCAPE\CuteFTP
  122. \GlobalSCAPE\CuteFTP Pro
  123. \GlobalSCAPE\CuteFTP Lite
  124. \CuteFTP
  125. \sm.dat
  126. Software\FlashFXP\3
  127. Software\FlashFXP
  128. Software\FlashFXP\4
  129. InstallerDathPath
  130. path
  131. Install Path
  132. DataFolder
  133. \Sites.dat
  134. \Quick.dat
  135. \History.dat
  136. \FlashFXP\3
  137. \FlashFXP\4
  138. \FileZilla
  139. \sitemanager.xml
  140. \recentservers.xml
  141. \filezilla.xml
  142. Software\FileZilla
  143. Software\FileZilla Client
  144. Install_Dir
  145. Host
  146. User
  147. Pass
  148. Port
  149. Remote Dir
  150. Server Type
  151. Server.Host
  152. Server.User
  153. Server.Pass
  154. Server.Port
  155. Path
  156. ServerType
  157. Last Server Host
  158. Last Server User
  159. Last Server Pass
  160. Last Server Port
  161. Last Server Path
  162. Last Server Type
  163. FTP Navigator
  164. FTP Commander
  165. ftplist.txt
  166. \BulletProof Software
  167. .dat
  168. .bps
  169. Software\BPFTP\Bullet Proof FTP\Main
  170. Software\BulletProof Software\BulletProof FTP Client\Main
  171. Software\BPFTP\Bullet Proof FTP\Options
  172. Software\BulletProof Software\BulletProof FTP Client\Options
  173. Software\BPFTP
  174. LastSessionFile
  175. SitesDir
  176. InstallDir1
  177. .xml
  178. \SmartFTP
  179. Favorites.dat
  180. History.dat
  181. addrbk.dat
  182. quick.dat
  183. \TurboFTP
  184. Software\TurboFTP
  185. installpath
  186. Software\Sota\FFFTP
  187. CredentialSalt
  188. CredentialCheck
  189. Software\Sota\FFFTP\Options
  190. Password
  191. UserName
  192. HostAdrs
  193. RemoteDir
  194. Port
  195. HostName
  196. Port
  197. Username
  198. Password
  199. HostDirName
  200. Software\CoffeeCup Software\Internet\Profiles
  201. Software\FTPWare\COREFTP\Sites
  202. Host
  203. User
  204. Port
  205. PthR
  206. SSH
  207. profiles.xml
  208. \FTP Explorer
  209. Software\FTP Explorer\FTP Explorer\Workspace\MFCToolBar-224
  210. Buttons
  211. Software\FTP Explorer\Profiles
  212. Password
  213. PasswordType
  214. Host
  215. Login
  216. Port
  217. InitialPath
  218. FtpSite.xml
  219. \Frigate3
  220. .ini
  221. \VanDyke\Config\Sessions
  222. \Sessions
  223. Software\VanDyke\SecureFX
  224. Config Path
  225. UltraFXP
  226. \sites.xml
  227. \FTPRush
  228. RushSite.xml
  229. Server
  230. Username
  231. Password
  232. FtpPort
  233. Software\Cryer\WebSitePublisher
  234. \BitKinex
  235. bitkinex.ds
  236. Hostname
  237. Username
  238. Password
  239. Port
  240. Software\ExpanDrive\Sessions
  241. \ExpanDrive
  242. \drives.js
  243. "password" : "
  244. Software\ExpanDrive
  245. ExpanDrive_Home
  246. Server
  247. UserName
  248. Password
  249. _Password
  250. Directory
  251. Software\NCH Software\ClassicFTP\FTPAccounts
  252. FtpServer
  253. FtpUserName
  254. FtpPassword
  255. _FtpPassword
  256. FtpDirectory
  257. SOFTWARE\NCH Software\Fling\Accounts
  258. Software\FTPClient\Sites
  259. Software\SoftX.org\FTPClient\Sites
  260. .oxc
  261. .oll
  262. ftplast.osd
  263. \GPSoftware\Directory Opus
  264. \SharedSettings.ccs
  265. \SharedSettings_1_0_5.ccs
  266. \SharedSettings.sqlite
  267. \SharedSettings_1_0_5.sqlite
  268. \CoffeeCup Software
  269. leapftp
  270. unleap.exe
  271. sites.dat
  272. sites.ini
  273. \LeapWare\LeapFTP
  274. SOFTWARE\LeapWare
  275. InstallPath
  276. DataDir
  277. Password
  278. HostName
  279. UserName
  280. RemoteDirectory
  281. PortNumber
  282. FSProtocol
  283. Software\Martin Prikryl
  284. \32BitFtp.ini
  285. NDSites.ini
  286. \NetDrive
  287. PassWord
  288. Url
  289. UserName
  290. RootDirectory
  291. Port
  292. Software\South River Technologies\WebDrive\Connections
  293. ServerType
  294. FTP CONTROL
  295. FTPCON
  296. .prf
  297. \Profiles
  298. ftp://
  299. opera
  300. wand.dat
  301. _Software\Opera Software
  302. Last Directory3
  303. Last Install Path
  304. Opera.HTML\shell\open\command
  305. wiseftpsrvs.bin
  306. \AceBIT
  307. Software\AceBIT
  308. MRU
  309. SOFTWARE\Classes\TypeLib\{CB1F2C0F-8094-4AAC-BCF5-41A64E27F777}
  310. SOFTWARE\Classes\TypeLib\{9EA55529-E122-4757-BC79-E4825F80732C}
  311. wiseftpsrvs.ini
  312. wiseftp.ini
  313. FTPVoyager.ftp
  314. FTPVoyager.qc
  315. \RhinoSoft.com
  316. nss3.dll
  317. NSS_Init
  318. NSS_Shutdown
  319. NSSBase64_DecodeBuffer
  320. SECITEM_FreeItem
  321. PK11_GetInternalKeySlot
  322. PK11_Authenticate
  323. PK11SDR_Decrypt
  324. PK11_FreeSlot
  325. sqlite3.dll
  326. sqlite3_open
  327. sqlite3_close
  328. sqlite3_prepare
  329. sqlite3_step
  330. sqlite3_column_bytes
  331. sqlite3_column_blob
  332. mozsqlite3.dll
  333. sqlite3_open
  334. sqlite3_close
  335. sqlite3_prepare
  336. sqlite3_step
  337. sqlite3_column_bytes
  338. sqlite3_column_blob
  339. profiles.ini
  340. Profile
  341. IsRelative
  342. Path
  343. PathToExe
  344. prefs.js
  345. signons.sqlite
  346. signons.txt
  347. signons2.txt
  348. signons3.txt
  349. SELECT hostname, encryptedUsername, encryptedPassword FROM moz_logins
  350. Firefox
  351. \Mozilla\Firefox\
  352. Software\Mozilla
  353. ftp://
  354. ftp.
  355. fireFTPsites.dat
  356. SeaMonkey
  357. \Mozilla\SeaMonkey\
  358. Flock
  359. \Flock\Browser\
  360. Mozilla
  361. \Mozilla\Profiles\
  362. Software\LeechFTP
  363. AppDir
  364. LocalDir
  365. bookmark.dat
  366. SiteInfo.QFP
  367. Odin
  368. Favorites.dat
  369. WinFTP
  370. sites.db
  371. CLSID\{11C1D741-A95B-11d2-8A80-0080ADB32FF4}\InProcServer32
  372. servers.xml
  373. \FTPGetter
  374. ESTdb2.dat
  375. QData.dat
  376. \Estsoft\ALFTP
  377. Internet Explorer
  378. WininetCacheCredentials
  379. MS IE FTP Passwords
  380. DPAPI:
  381. Software\Microsoft\Internet Explorer\IntelliForms\Storage2
  382. Microsoft_WinInet_*
  383. ftp://
  384. Software\Adobe\Common
  385. SiteServers
  386. SiteServer %d\Host
  387. SiteServer %d\WebUrl
  388. SiteServer %d\Remote Directory
  389. SiteServer %d-User
  390. SiteServer %d-User PW
  391. %s\Keychain
  392. SiteServer %d\SFTP
  393. DeluxeFTP
  394. sites.xml
  395. Web Data
  396. Login Data
  397. SQLite format 3
  398. table
  399. CONSTRAINT
  400. PRIMARY
  401. UNIQUE
  402. CHECK
  403. FOREIGN
  404. logins
  405. origin_url
  406. password_value
  407. username_value
  408. ftp://
  409. \Google\Chrome
  410. \Chromium
  411. \ChromePlus
  412. Software\ChromePlus
  413. Install_Dir
  414. \Bromium
  415. \Nichrome
  416. \Comodo
  417. \RockMelt
  418. K-Meleon
  419. \K-Meleon
  420. \Profiles
  421. Epic
  422. \Epic\Epic
  423. Staff-FTP
  424. sites.ini
  425. \Sites
  426. \Visicom Media
  427. .ftp
  428. \Global Downloader
  429. SM.arch
  430. FreshFTP
  431. .SMF
  432. BlazeFtp
  433. site.dat
  434. LastPassword
  435. LastAddress
  436. LastUser
  437. LastPort
  438. Software\FlashPeak\BlazeFtp\Settings
  439. \BlazeFtp
  440. .fpl
  441. FTP++.Link\shell\open\command
  442. GoFTP
  443. Connections.txt
  444. 3D-FTP
  445. sites.ini
  446. \3D-FTP
  447. \SiteDesigner
  448. SOFTWARE\Classes\TypeLib\{F9043C88-F6F2-101A-A3C9-08002B2F49FB}\1.2\0\win32
  449. EasyFTP
  450. \NetSarang
  451. .xfp
  452. .rdp
  453. TERMSRV/*
  454. password 51:b:
  455. username:s:
  456. full address:s:
  457. TERMSRV/
  458. FTP Now
  459. FTPNow
  460. sites.xml
  461. SOFTWARE\Robo-FTP 3.7\Scripts
  462. SOFTWARE\Robo-FTP 3.7\FTPServers
  463. FTP Count
  464. FTP File%d
  465. Password
  466. ServerName
  467. UserID
  468. InitialDirectory
  469. PortNumber
  470. ServerType
  471. fMY
  472. Software\LinasFTP\Site Manager
  473. Host
  474. User
  475. Pass
  476. Port
  477. Remote Dir
  478. \Cyberduck
  479. .duck
  480. user.config
  481. <setting name="
  482. value="
  483. Software\SimonTatham\PuTTY\Sessions
  484. HostName
  485. UserName
  486. Password
  487. PortNumber
  488. TerminalType
  489. NppFTP.xml
  490. \Notepad++
  491. Software\CoffeeCup Software
  492. FTP destination server
  493. FTP destination user
  494. FTP destination password
  495. FTP destination port
  496. FTP destination catalog
  497. FTP profiles
  498. FTPShell
  499. ftpshell.fsi
  500. Software\MAS-Soft\FTPInfo\Setup
  501. DataDir
  502. \FTPInfo
  503. ServerList.xml
  504. NexusFile
  505. ftpsite.ini
  506. FastStone Browser
  507. FTPList.db
  508. \MapleStudio\ChromePlus
  509. Software\Nico Mak Computing\WinZip\FTP
  510. Software\Nico Mak Computing\WinZip\mru\jobs
  511. Site
  512. UserID
  513. xflags
  514. Port
  515. Folder
  516. .wjf
  517. winex="
  518. \Yandex
  519. My FTP
  520. project.ini
  521. .xml
  522. {74FF1730-B1F2-4D88-926B-1568FAE61DB7}
  523. NovaFTP.db
  524. \INSoftware\NovaFTP
  525. .oeaccount
  526. Salt
  527. <POP3_Password2
  528. <SMTP_Password2
  529. <IMAP_Password2
  530. <HTTPMail_Password2
  531. \Microsoft\Windows Live Mail
  532. Software\Microsoft\Windows Live Mail
  533. \Microsoft\Windows Mail
  534. Software\Microsoft\Windows Mail
  535. Software\RimArts\B2\Settings
  536. DataDir
  537. DataDirBak
  538. Mailbox.ini
  539. Software\Poco Systems Inc
  540. Path
  541. \PocoSystem.ini
  542. Program
  543. DataPath
  544. accounts.ini
  545. \Pocomail
  546. Software\IncrediMail
  547. EmailAddress
  548. Technology
  549. PopServer
  550. PopPort
  551. PopAccount
  552. PopPassword
  553. SmtpServer
  554. SmtpPort
  555. SmtpAccount
  556. SmtpPassword
  557. account.cfg
  558. account.cfn
  559. \BatMail
  560. \The Bat!
  561. Software\RIT\The Bat!
  562. Software\RIT\The Bat!\Users depot
  563. Working Directory
  564. ProgramDir
  565. Count
  566. Default
  567. Dir #%d
  568. SMTP Email Address
  569. SMTP Server
  570. POP3 Server
  571. POP3 User Name
  572. SMTP User Name
  573. NNTP Email Address
  574. NNTP User Name
  575. NNTP Server
  576. IMAP Server
  577. IMAP User Name
  578. Email
  579. HTTP User
  580. HTTP Server URL
  581. POP3 User
  582. IMAP User
  583. HTTPMail User Name
  584. HTTPMail Server
  585. SMTP User
  586. POP3 Port
  587. SMTP Port
  588. IMAP Port
  589. POP3 Password2
  590. IMAP Password2
  591. NNTP Password2
  592. HTTPMail Password2
  593. SMTP Password2
  594. POP3 Password
  595. IMAP Password
  596. NNTP Password
  597. HTTP Password
  598. SMTP Password
  599. Software\Microsoft\Internet Account Manager\Accounts
  600. Identities
  601. Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts
  602. Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Microsoft Outlook Internet Settings
  603. Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook
  604. Software\Microsoft\Internet Account Manager
  605. Outlook
  606. \Accounts
  607. identification
  608. identitymgr
  609. inetcomm server passwords
  610. outlook account manager passwords
  611. identities
  612. {%08X-%04X-%04X-%02X%02X-%02X%02X%02X%02X%02X%02X}
  613. Thunderbird
  614. \Thunderbird
  615. FastTrack
  616. ftplist.txt
Add Comment
Please, Sign In to add comment