TrojanSpy.MSIL.ANGRYSTEALER.THHBHBD
PWS:MSIL/Stealgen.GA!MTB (MICROSOFT)
Windows

恶意软件类型:
Trojan Spy
有破坏性?:
没有
加密?:
没有
In the Wild:
是的
概要
它以文件的形式出现在系统中,可能是其他恶意软件投放的,或者是用户在访问恶意网站时无意中下载的。
技术详细信息
新病毒详细信息
它以文件的形式出现在系统中,可能是其他恶意软件投放的,或者是用户在访问恶意网站时无意中下载的。
安装
它创建下列文件夹:
- %AppDataLocal%\44_23
- %AppDataLocal%\44_23\Browsers
- %AppDataLocal%\44_23\Browsers\360Browser
- %AppDataLocal%\44_23\Browsers\7Star
- %AppDataLocal%\44_23\Browsers\Amigo
- %AppDataLocal%\44_23\Browsers\BlackHaw
- %AppDataLocal%\44_23\Browsers\BraveSoftware
- %AppDataLocal%\44_23\Browsers\CatalinaGroup
- %AppDataLocal%\44_23\Browsers\CentBrowser
- %AppDataLocal%\44_23\Browsers\Chedot
- %AppDataLocal%\44_23\Browsers\Chromium
- %AppDataLocal%\44_23\Browsers\Chromodo
- %AppDataLocal%\44_23\Browsers\CocCoc
- %AppDataLocal%\44_23\Browsers\Comodo
- %AppDataLocal%\44_23\Browsers\Coowon
- %AppDataLocal%\44_23\Browsers\Cyberfox
- %AppDataLocal%\44_23\Browsers\Edge
- %AppDataLocal%\44_23\Browsers\Elements Browser
- %AppDataLocal%\44_23\Browsers\Epic Privacy Browser
- %AppDataLocal%\44_23\Browsers\Fenrir Inc
- %AppDataLocal%\44_23\Browsers\Firefox
- %AppDataLocal%\44_23\Browsers\Google
- %AppDataLocal%\44_23\Browsers\Google(x86)
- %AppDataLocal%\44_23\Browsers\IceDragon
- %AppDataLocal%\44_23\Browsers\Iridium
- %AppDataLocal%\44_23\Browsers\K-Meleon
- %AppDataLocal%\44_23\Browsers\K-Melon
- %AppDataLocal%\44_23\Browsers\Kometa
- %AppDataLocal%\44_23\Browsers\liebao
- %AppDataLocal%\44_23\Browsers\Mail.Ru
- %AppDataLocal%\44_23\Browsers\MapleStudio
- %AppDataLocal%\44_23\Browsers\Maxthon3
- %AppDataLocal%\44_23\Browsers\Nichrome
- %AppDataLocal%\44_23\Browsers\Opera
- %AppDataLocal%\44_23\Browsers\Orbitum
- %AppDataLocal%\44_23\Browsers\Pale Moon
- %AppDataLocal%\44_23\Browsers\QIP Surf
- %AppDataLocal%\44_23\Browsers\Sputnik
- %AppDataLocal%\44_23\Browsers\Thunderbird
- %AppDataLocal%\44_23\Browsers\Torch
- %AppDataLocal%\44_23\Browsers\uCozMedia
- %AppDataLocal%\44_23\Browsers\Uran
- %AppDataLocal%\44_23\Browsers\Vivaldi
- %AppDataLocal%\44_23\Browsers\Waterfox
- %AppDataLocal%\44_23\Browsers\Yandex
- %AppDataLocal%\44_23\Files
- %AppDataLocal%\44_23\Files\{Folders Copied From %Desktop%}
- %AppDataLocal%\44_23\Files\{Folders Copied From %User Profile%\Documents}
- %AppDataLocal%\44_23\Files\{Folders Copied From %User Profile%\source}
- %AppDataLocal%\44_23\Wallets
- %AppDataLocal%\44_23\Wallets\Armory
- %AppDataLocal%\44_23\Wallets\Atomic\Local Storage\leveldb\
- %AppDataLocal%\44_23\Wallets\Bitcoin Core
- %AppDataLocal%\44_23\Wallets\Bytecoin
- %AppDataLocal%\44_23\Wallets\Dash Core
- %AppDataLocal%\44_23\Wallets\Electrum
- %AppDataLocal%\44_23\Wallets\Ethereum
- %AppDataLocal%\44_23\Wallets\Exodus
- %AppDataLocal%\44_23\Wallets\Jaxx\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\
- %AppDataLocal%\44_23\Wallets\Litecoin Core
- %AppDataLocal%\44_23\Wallets\Monero
- %AppDataLocal%\44_23\Wallets\Zcash
- %AppDataLocal%\44_23\VPN
- %AppDataLocal%\44_23\VPN\Proton VPN
- %AppDataLocal%\44_23\VPN\OpenVPN
- %AppDataLocal%\44_23\VPN\NordVPN
- %AppDataLocal%\44_23\Steam
- %AppDataLocal%\44_23\Steam\ssnf
- %AppDataLocal%\44_23\Steam\configs
- %AppDataLocal%\44_23\Discord
- %AppDataLocal%\44_23\Discord\{Folders from %Application Data%\Discord\Local Storage\leveldb}
- %AppDataLocal%\44_23\Discord\{Folders from %Application Data%\Discord PTB\Local Storage\leveldb}
- %AppDataLocal%\44_23\Discord\{Folders from %Application Data%\Discord Canary\leveldb}
- %User Temp%leveldb → copy of Discord's leveldb folder, deleted afterwards
- %AppDataLocal%\44_23\FileZilla
- %AppDataLocal%\44_23\Telegram\{Folders from Telegram's tdata path}
- %AppDataLocal%\44_23\VimeWorld
- %AppDataLocal%\44_23\Browsers\New_Passwords
- %AppDataLocal%\44_23\Browsers\New_Cookies
(注意: %Desktop% 是当前用户的桌面,通常位于 C:\Windows\Profiles\{user name}\Desktop (Windows 98 和 ME)、C:\WINNT\Profiles\{user name}\Desktop (Windows NT)、C:\Documents and Settings\{User Name}\桌面 (Windows 2000(32-bit)、XP 和 Server 2003(32-bit)) 和 C:\Users\{user name}\Desktop (Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit) 和 10(64-bit))。. %User Profile% 是当前用户的概要文件文件夹,通常位于 C:\Windows\Profiles\{user name} (Windows 98 和 ME)、C:\WINNT\Profiles\{user name} (Windows NT)、C:\Documents and Settings\{user name} (Windows 2000(32-bit)、XP 和 Server 2003(32-bit)) 和 C:\Users\{user name} (Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit) 和 10(64-bit))。. %Application Data% 是当前用户的 Application Data 文件夹,通常位于 C:\Windows\Profiles\{user name}\Application Data (Windows 98 和 ME)、C:\WINNT\Profiles\{user name}\Application Data (Windows NT)、C:\Documents and Settings\{user name}\Local Settings\Application Data (Windows 2000(32-bit)、XP 和 Server 2003(32-bit)) 和 C:\Users\{user name}\AppData\Roaming (Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit) 和 10(64-bit))。. %User Temp% 是当前用户的 Temp 文件夹。通常位于 C:\Documents and Settings\{user name}\Local Settings\Temp (Windows 2000(32-bit)、XP 和 Server 2003(32-bit))、C:\Users\{user name}\AppData\Local\Temp (Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit) 和 10(64-bit)。)
植入例程
它在保存收集信息的位置植入下列文件:
- %AppDataLocal%\44_23\Browsers\{Browser Name}\CreditCards.txt
- %AppDataLocal%\44_23\Browsers\{Browser Name}\Passwords.txt
- %AppDataLocal%\44_23\Browsers\{Browser Name}\Autofill.txt
- %AppDataLocal%\44_23\Browsers\{Browser Name}Bookmarks.txt
- %AppDataLocal%\44_23\Browsers\Cookies_{Browser Name}{Random Number}.txt
- %AppDataLocal%\44_23\Passwords.txt
- %AppDataLocal%\44_23\Files\{Folders Copied From %Desktop%}\{.txt Files Copied From %Desktop%}
- %AppDataLocal%\44_23\Files\{Folders Copied From %User Profile%\Documents}\{.txt Files Copied From %User Profile%\Documents}
- %AppDataLocal%\44_23\Files\{Folders Copied From %User Profile%\source}\{.txt Files Copied From %User Profile%\source}
- %AppDataLocal%\44_23\Wallets\Armory\{Files Copied from}
- %AppDataLocal%\44_23\Wallets\Atomic\Local Storage\leveldb\{Files Copied from %AppData%\atomic\Local Storage\leveldb
- %AppDataLocal%\44_23\Bitcoin Core\wallet.dat
- %AppDataLocal%\44_23\Bytecoin\{.wallet Files Copied from %AppData%\bytecoin}
- %AppDataLocal%\44_23\Dash Core\wallet.dat
- %AppDataLocal%\44_23\Wallets\Electrum\{Files Copied from %AppData%\Electrum\wallets}
- %AppDataLocal%\44_23\Wallets\Ethereum\{Files Copied from %AppData%\Ethereum\keystore}
- %AppDataLocal%\44_23\Wallets\Exodus\{Files Copied from %AppData%\Exodus\exodus.wallet}
- %AppDataLocal%\44_23\Wallets\Jaxx\{Files Copied from %AppData%\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\}
- %AppDataLocal%\44_23\Litecoin Core\wallet.dat
- %AppDataLocal%\44_23\Wallets\Monero\{stolen information file}
- %AppDataLocal%\44_23\Wallets\Zcash\{Files Copied from %AppData%\Zcash}
- %AppDataLocal%\44_23\Screen.png
- %AppDataLocal%\44_23\Process.txt
- %AppDataLocal%\44_23\Information.txt
- %AppDataLocal%\44_23\VPN\Proton VPN\{Path to %AppDataLocal%ProtonVPN where user.config is found}\user.config
- %AppDataLocal%\44_23\VPN\OpenVPN\{OVPN File Name}.ovpn
- %AppDataLocal%\44_23\VPN\NordVPN\accounts.txt
- %AppDataLocal%\44_23\Steam\AccountsList.txt
- %AppDataLocal%\44_23\Steam\Games.txt
- %AppDataLocal%\44_23\Steam\ssnf\{Steam ssnf Files}
- %AppDataLocal%\44_23\Steam\configs\{Steam vdf Files}
- %AppDataLocal%\44_23\Discord\Tokens.txt
- %AppDataLocal%\44_23\Discord\{Folders and Files from %Application Data%\Discord\Local Storage\leveldb}
- %AppDataLocal%\44_23\Discord\{Folders and Files from %Application Data%\Discord PTB\Local Storage\leveldb}
- %AppDataLocal%\44_23\Discord\{Folders and Files from %Application Data%\Discord Canary\leveldb}
- %User Temp%\leveldb\{Files From Discord's leveldb Folder} → deleted afterwards
- %AppDataLocal%\44_23\FileZilla\FileZilla.log
- %AppDataLocal%\44_23\Telegram\{Folders and Files from Telegram's tdata path}
- %AppDataLocal%\44_23\VimeWorld\[{VimeWorld Rank}]{VimeWorld Level}{VimeWorld Username}
- %AppDataLocal%\44_23\Browsers\New_Passwords\Chrome Passwords.txt
- %AppDataLocal%\44_23\Browsers\New_Cookies\Chrome Cookies.txt
- %AppDataLocal%\{Country Code}[{Date and Time When the Zip File is Created}]-{IP Address of Affected Machine}-{Username}.zip → contains all stolen information
(注意: %Desktop% 是当前用户的桌面,通常位于 C:\Windows\Profiles\{user name}\Desktop (Windows 98 和 ME)、C:\WINNT\Profiles\{user name}\Desktop (Windows NT)、C:\Documents and Settings\{User Name}\桌面 (Windows 2000(32-bit)、XP 和 Server 2003(32-bit)) 和 C:\Users\{user name}\Desktop (Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit) 和 10(64-bit))。. %User Profile% 是当前用户的概要文件文件夹,通常位于 C:\Windows\Profiles\{user name} (Windows 98 和 ME)、C:\WINNT\Profiles\{user name} (Windows NT)、C:\Documents and Settings\{user name} (Windows 2000(32-bit)、XP 和 Server 2003(32-bit)) 和 C:\Users\{user name} (Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit) 和 10(64-bit))。. %Application Data% 是当前用户的 Application Data 文件夹,通常位于 C:\Windows\Profiles\{user name}\Application Data (Windows 98 和 ME)、C:\WINNT\Profiles\{user name}\Application Data (Windows NT)、C:\Documents and Settings\{user name}\Local Settings\Application Data (Windows 2000(32-bit)、XP 和 Server 2003(32-bit)) 和 C:\Users\{user name}\AppData\Roaming (Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit) 和 10(64-bit))。. %User Temp% 是当前用户的 Temp 文件夹。通常位于 C:\Documents and Settings\{user name}\Local Settings\Temp (Windows 2000(32-bit)、XP 和 Server 2003(32-bit))、C:\Users\{user name}\AppData\Local\Temp (Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit) 和 10(64-bit)。)
信息窃取
它收集下列数据:
- Browser data (such as Credit Card Information, Username, Passwords, Website Cookies, and Bookmarks) from the following browsers:
- 360 Browser
- 7Star
- Amigo
- Atom
- BlackHawk
- Brave-Browser
- CentBrowser
- Chedot
- ChromePlus
- Chromium
- Chromodo
- Citrio
- CocCoc
- Comodo Dragon
- Comodo IceDragon
- Coowon
- Cyberfox
- Elements Browser
- Epic Privacy Browser
- Firefox
- Google Chrome
- Iridium
- K-Meleon
- K-Melon
- Kometa
- Liebao
- Maxthon3
- Microsoft Edge
- Nichrome
- Opera
- Opera GX
- Orbitum
- Pale Moon
- QIP Surf
- Sleipnir5
- Sputnik
- Thunderbird
- Torch
- Uran
- Vivaldi
- Waterfox
- Yandex Browser
- Cryptocurrency wallet data from the following applications:
- Armory
- Atomic Wallet
- Bitcoin Core
- Bytecoin
- Dash Core
- Electrum
- Ethereum
- Exodus
- Jaxx
- Litecoin Core
- Monero
- Zcash
- Configuration files from the following VPN applications:
- NordVPN
- OpenVPN
- Proton VPN
- Online account information:
- Discord
- Files in Discord leveldb folders
- Tokens
- Steam
- Account Names
- Configuration Files
- Games Acquired
- SSNF Files
- Telegram
- Keys
- Session Directories
- Settings Files
- User Data
- User Tags
- VimeWorld
- Configuration File (contains username, passwords, rank, level, etc.)
- OSSUID
- Discord
- Credentials for FileZilla:
- Host
- Port
- Username
- Password
- System Information:
- Basic Service Set Identifier
- Clipboard Content
- Computername
- Country
- CPU ID
- CPU Name
- Current Date and Time
- Geolocation
- GPU Name
- IP Address
- List of Running Processes
- Log Date
- Malware Current Working Directory
- Operating System
- Screen Resolution
- Screenshot of Affected Machine
- Total RAM
- Username
窃取信息
它通过 HTTP POST 将收集的信息发送到下列 URL:
- https://{BLOCKED}egram.org/bot7111654667:AAFkYkvnCsb8YVJsK4iKBRAyyQO9vyaJa7U/sendDocument?chat_id=1435200072&caption=\n{Contents of Log}
其他详细信息
该程序执行以下操作:
- It copies .txt files from %Desktop%, %User Profile%\Documents, and %User Profile%\source that does not exceed 5000 bytes to %AppDataLocal%\44_23\Files while the folder does not exceed 25000 bytes.
- It connects to the following URL to identify the affected machine's geolocation:
- http://{BLOCKED}i.com/xml/
- It connects to the following URL to retrieve online account information:
- https://{BLOCKED}ommunity.com/profiles/{Steam Username}
- https://{BLOCKED}eworld.ru/user/name/{VimeWorld Username}
解决方案
Step 2
对于Windows ME和XP用户,在扫描前,请确认已禁用系统还原功能,才可全面扫描计算机。
Step 3
注意:在此恶意软件/间谍软件/灰色软件执行期间,并非所有文件、文件夹和注册表键值和项都会安装到您的计算机上。这可能是由于不完整的安装或其他操作系统条件所致。如果您没有找到相同的文件/文件夹/注册表信息,请继续进行下一步操作。
Step 4
搜索和删除这些文件
- %AppDataLocal%\44_23\Browsers\{Browser Name}\CreditCards.txt
- %AppDataLocal%\44_23\Browsers\{Browser Name}\Passwords.txt
- %AppDataLocal%\44_23\Browsers\{Browser Name}\Autofill.txt
- %AppDataLocal%\44_23\Browsers\{Browser Name}Bookmarks.txt
- %AppDataLocal%\44_23\Browsers\Cookies_{Browser Name}{Random Number}.txt
- %AppDataLocal%\44_23\Passwords.txt
- %AppDataLocal%\44_23\Files\{Folders Copied From %Desktop%}\{.txt Files Copied From %Desktop%}
- %AppDataLocal%\44_23\Files\{Folders Copied From %User Profile%\Documents}\{.txt Files Copied From %User Profile%\Documents}
- %AppDataLocal%\44_23\Files\{Folders Copied From %User Profile%\source}\{.txt Files Copied From %User Profile%\source}
- %AppDataLocal%\44_23\Wallets\Armory\{Files Copied from}
- %AppDataLocal%\44_23\Wallets\Atomic\Local Storage\leveldb\{Files Copied from %AppData%\atomic\Local Storage\leveldb
- %AppDataLocal%\44_23\Bitcoin Core\wallet.dat
- %AppDataLocal%\44_23\Bytecoin\{.wallet Files Copied from %AppData%\bytecoin}
- %AppDataLocal%\44_23\Dash Core\wallet.dat
- %AppDataLocal%\44_23\Wallets\Electrum\{Files Copied from %AppData%\Electrum\wallets}
- %AppDataLocal%\44_23\Wallets\Ethereum\{Files Copied from %AppData%\Ethereum\keystore}
- %AppDataLocal%\44_23\Wallets\Exodus\{Files Copied from %AppData%\Exodus\exodus.wallet}
- %AppDataLocal%\44_23\Wallets\Jaxx\{Files Copied from %AppData%\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\}
- %AppDataLocal%\44_23\Litecoin Core\wallet.dat
- %AppDataLocal%\44_23\Wallets\Monero\{stolen information file}
- %AppDataLocal%\44_23\Wallets\Zcash\{Files Copied from %AppData%\Zcash}
- %AppDataLocal%\44_23\Screen.png
- %AppDataLocal%\44_23\Process.txt
- %AppDataLocal%\44_23\Information.txt
- %AppDataLocal%\44_23\VPN\Proton VPN\{Path to %AppDataLocal%ProtonVPN where user.config is found}\user.config
- %AppDataLocal%\44_23\VPN\OpenVPN\{OVPN File Name}.ovpn
- %AppDataLocal%\44_23\VPN\NordVPN\accounts.txt
- %AppDataLocal%\44_23\Steam\AccountsList.txt
- %AppDataLocal%\44_23\Steam\Games.txt
- %AppDataLocal%\44_23\Steam\ssnf\{Steam ssnf Files}
- %AppDataLocal%\44_23\Steam\configs\{Steam vdf Files}
- %AppDataLocal%\44_23\Discord\Tokens.txt
- %AppDataLocal%\44_23\Discord\{Folders and Files from %Application Data%\Discord\Local Storage\leveldb}
- %AppDataLocal%\44_23\Discord\{Folders and Files from %Application Data%\Discord PTB\Local Storage\leveldb}
- %AppDataLocal%\44_23\Discord\{Folders and Files from %Application Data%\Discord Canary\leveldb}
- %User Temp%\leveldb\{Files From Discord's leveldb Folder}
- %AppDataLocal%\44_23\FileZilla\FileZilla.log
- %AppDataLocal%\44_23\Telegram\{Folders and Files from Telegram's tdata path}
- %AppDataLocal%\44_23\VimeWorld\[{VimeWorld Rank}]{VimeWorld Level}{VimeWorld Username}
- %AppDataLocal%\44_23\Browsers\New_Passwords\Chrome Passwords.txt
- %AppDataLocal%\44_23\Browsers\New_Cookies\Chrome Cookies.txt
- %AppDataLocal%\{Country Code}[{Date and Time When the Zip File is Created}]-{IP Address of Affected Machine}-{Username}.zip
- %AppDataLocal%\44_23\Browsers\{Browser Name}\CreditCards.txt
- %AppDataLocal%\44_23\Browsers\{Browser Name}\Passwords.txt
- %AppDataLocal%\44_23\Browsers\{Browser Name}\Autofill.txt
- %AppDataLocal%\44_23\Browsers\{Browser Name}Bookmarks.txt
- %AppDataLocal%\44_23\Browsers\Cookies_{Browser Name}{Random Number}.txt
- %AppDataLocal%\44_23\Passwords.txt
- %AppDataLocal%\44_23\Files\{Folders Copied From %Desktop%}\{.txt Files Copied From %Desktop%}
- %AppDataLocal%\44_23\Files\{Folders Copied From %User Profile%\Documents}\{.txt Files Copied From %User Profile%\Documents}
- %AppDataLocal%\44_23\Files\{Folders Copied From %User Profile%\source}\{.txt Files Copied From %User Profile%\source}
- %AppDataLocal%\44_23\Wallets\Armory\{Files Copied from}
- %AppDataLocal%\44_23\Wallets\Atomic\Local Storage\leveldb\{Files Copied from %AppData%\atomic\Local Storage\leveldb
- %AppDataLocal%\44_23\Bitcoin Core\wallet.dat
- %AppDataLocal%\44_23\Bytecoin\{.wallet Files Copied from %AppData%\bytecoin}
- %AppDataLocal%\44_23\Dash Core\wallet.dat
- %AppDataLocal%\44_23\Wallets\Electrum\{Files Copied from %AppData%\Electrum\wallets}
- %AppDataLocal%\44_23\Wallets\Ethereum\{Files Copied from %AppData%\Ethereum\keystore}
- %AppDataLocal%\44_23\Wallets\Exodus\{Files Copied from %AppData%\Exodus\exodus.wallet}
- %AppDataLocal%\44_23\Wallets\Jaxx\{Files Copied from %AppData%\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\}
- %AppDataLocal%\44_23\Litecoin Core\wallet.dat
- %AppDataLocal%\44_23\Wallets\Monero\{stolen information file}
- %AppDataLocal%\44_23\Wallets\Zcash\{Files Copied from %AppData%\Zcash}
- %AppDataLocal%\44_23\Screen.png
- %AppDataLocal%\44_23\Process.txt
- %AppDataLocal%\44_23\Information.txt
- %AppDataLocal%\44_23\VPN\Proton VPN\{Path to %AppDataLocal%ProtonVPN where user.config is found}\user.config
- %AppDataLocal%\44_23\VPN\OpenVPN\{OVPN File Name}.ovpn
- %AppDataLocal%\44_23\VPN\NordVPN\accounts.txt
- %AppDataLocal%\44_23\Steam\AccountsList.txt
- %AppDataLocal%\44_23\Steam\Games.txt
- %AppDataLocal%\44_23\Steam\ssnf\{Steam ssnf Files}
- %AppDataLocal%\44_23\Steam\configs\{Steam vdf Files}
- %AppDataLocal%\44_23\Discord\Tokens.txt
- %AppDataLocal%\44_23\Discord\{Folders and Files from %Application Data%\Discord\Local Storage\leveldb}
- %AppDataLocal%\44_23\Discord\{Folders and Files from %Application Data%\Discord PTB\Local Storage\leveldb}
- %AppDataLocal%\44_23\Discord\{Folders and Files from %Application Data%\Discord Canary\leveldb}
- %User Temp%\leveldb\{Files From Discord's leveldb Folder}
- %AppDataLocal%\44_23\FileZilla\FileZilla.log
- %AppDataLocal%\44_23\Telegram\{Folders and Files from Telegram's tdata path}
- %AppDataLocal%\44_23\VimeWorld\[{VimeWorld Rank}]{VimeWorld Level}{VimeWorld Username}
- %AppDataLocal%\44_23\Browsers\New_Passwords\Chrome Passwords.txt
- %AppDataLocal%\44_23\Browsers\New_Cookies\Chrome Cookies.txt
- %AppDataLocal%\{Country Code}[{Date and Time When the Zip File is Created}]-{IP Address of Affected Machine}-{Username}.zip
Step 5
搜索和删除这些文件夹
- %AppDataLocal%\44_23\Browsers\360Browser
- %AppDataLocal%\44_23\Browsers\7Star
- %AppDataLocal%\44_23\Browsers\Amigo
- %AppDataLocal%\44_23\Browsers\BlackHaw
- %AppDataLocal%\44_23\Browsers\BraveSoftware
- %AppDataLocal%\44_23\Browsers\CatalinaGroup
- %AppDataLocal%\44_23\Browsers\CentBrowser
- %AppDataLocal%\44_23\Browsers\Chedot
- %AppDataLocal%\44_23\Browsers\Chromium
- %AppDataLocal%\44_23\Browsers\Chromodo
- %AppDataLocal%\44_23\Browsers\CocCoc
- %AppDataLocal%\44_23\Browsers\Comodo
- %AppDataLocal%\44_23\Browsers\Coowon
- %AppDataLocal%\44_23\Browsers\Cyberfox
- %AppDataLocal%\44_23\Browsers\Edge
- %AppDataLocal%\44_23\Browsers\Elements Browser
- %AppDataLocal%\44_23\Browsers\Epic Privacy Browser
- %AppDataLocal%\44_23\Browsers\Fenrir Inc
- %AppDataLocal%\44_23\Browsers\Firefox
- %AppDataLocal%\44_23\Browsers\Google
- %AppDataLocal%\44_23\Browsers\Google(x86)
- %AppDataLocal%\44_23\Browsers\IceDragon
- %AppDataLocal%\44_23\Browsers\Iridium
- %AppDataLocal%\44_23\Browsers\K-Meleon
- %AppDataLocal%\44_23\Browsers\K-Melon
- %AppDataLocal%\44_23\Browsers\Kometa
- %AppDataLocal%\44_23\Browsers\liebao
- %AppDataLocal%\44_23\Browsers\Mail.Ru
- %AppDataLocal%\44_23\Browsers\MapleStudio
- %AppDataLocal%\44_23\Browsers\Maxthon3
- %AppDataLocal%\44_23\Browsers\Nichrome
- %AppDataLocal%\44_23\Browsers\Opera
- %AppDataLocal%\44_23\Browsers\Orbitum
- %AppDataLocal%\44_23\Browsers\Pale Moon
- %AppDataLocal%\44_23\Browsers\QIP Surf
- %AppDataLocal%\44_23\Browsers\Sputnik
- %AppDataLocal%\44_23\Browsers\Thunderbird
- %AppDataLocal%\44_23\Browsers\Torch
- %AppDataLocal%\44_23\Browsers\uCozMedia
- %AppDataLocal%\44_23\Browsers\Uran
- %AppDataLocal%\44_23\Browsers\Vivaldi
- %AppDataLocal%\44_23\Browsers\Waterfox
- %AppDataLocal%\44_23\Browsers\Yandex
- %AppDataLocal%\44_23\Browsers\New_Cookies
- %AppDataLocal%\44_23\Browsers\New_Passwords
- %AppDataLocal%\44_23\Browsers
- %AppDataLocal%\44_23\Files\{Folders Copied From %Desktop%}
- %AppDataLocal%\44_23\Files\{Folders Copied From %User Profile%\Documents}
- %AppDataLocal%\44_23\Files\{Folders Copied From %User Profile%\source}
- %AppDataLocal%\44_23\Files
- %AppDataLocal%\44_23\Wallets\Armory
- %AppDataLocal%\44_23\Wallets\Atomic
- %AppDataLocal%\44_23\Wallets\Bitcoin Core
- %AppDataLocal%\44_23\Wallets\Bytecoin
- %AppDataLocal%\44_23\Wallets\Dash Core
- %AppDataLocal%\44_23\Wallets\Electrum
- %AppDataLocal%\44_23\Wallets\Ethereum
- %AppDataLocal%\44_23\Wallets\Exodus
- %AppDataLocal%\44_23\Wallets\Jaxx
- %AppDataLocal%\44_23\Wallets\Litecoin Core
- %AppDataLocal%\44_23\Wallets\Monero
- %AppDataLocal%\44_23\Wallets\Zcash
- %AppDataLocal%\44_23\Wallets
- %AppDataLocal%\44_23\VPN\Proton VPN
- %AppDataLocal%\44_23\VPN\OpenVPN
- %AppDataLocal%\44_23\VPN\NordVPN
- %AppDataLocal%\44_23\VPN
- %AppDataLocal%\44_23\Steam\ssnf
- %AppDataLocal%\44_23\Steam\configs
- %AppDataLocal%\44_23\Steam
- %AppDataLocal%\44_23\Discord\{Folders from %Application Data%\Discord\Local Storage\leveldb}
- %AppDataLocal%\44_23\Discord\{Folders from %Application Data%\Discord PTB\Local Storage\leveldb}
- %AppDataLocal%\44_23\Discord\{Folders from %Application Data%\Discord Canary\leveldb}
- %AppDataLocal%\44_23\Discord
- %AppDataLocal%\44_23\FileZilla
- %AppDataLocal%\44_23\Telegram\{Folders from Telegram's tdata path}
- %AppDataLocal%\44_23\Telegram
- %AppDataLocal%\44_23\VimeWorld
- %AppDataLocal%\44_23
- %User Temp%\leveldb
Step 6
使用亚信安全产品扫描计算机,并删除检测到的TrojanSpy.MSIL.ANGRYSTEALER.THHBHBD文件 如果检测到的文件已被亚信安全产品清除、删除或隔离,则无需采取进一步措施。可以选择直接删除隔离的文件。请参阅知识库页面了解详细信息。