分析者: John Rainier Navato   

 :

PWS:MSIL/Stealgen.GA!MTB (MICROSOFT)

 平台:

Windows

 总体风险等级:
 潜在破坏:
 潜在分布:
 感染次数:
 信息暴露:

  • 恶意软件类型:
    Trojan Spy

  • 有破坏性?:
    没有

  • 加密?:
    没有

  • In the Wild:
    是的

  概要

感染途徑: 从互联网上下载, 下载了其他恶意软件

它以文件的形式出现在系统中,可能是其他恶意软件投放的,或者是用户在访问恶意网站时无意中下载的。

  技术详细信息

文件大小: 9,163,776 bytes
报告日期: EXE
内存驻留: 没有
初始樣本接收日期: 2024年8月28日
Payload: 植入文件, 连接到 URL/Ip, 窃取信息

新病毒详细信息

它以文件的形式出现在系统中,可能是其他恶意软件投放的,或者是用户在访问恶意网站时无意中下载的。

安装

它创建下列文件夹:

  • %AppDataLocal%\44_23
  • %AppDataLocal%\44_23\Browsers
  • %AppDataLocal%\44_23\Browsers\360Browser
  • %AppDataLocal%\44_23\Browsers\7Star
  • %AppDataLocal%\44_23\Browsers\Amigo
  • %AppDataLocal%\44_23\Browsers\BlackHaw
  • %AppDataLocal%\44_23\Browsers\BraveSoftware
  • %AppDataLocal%\44_23\Browsers\CatalinaGroup
  • %AppDataLocal%\44_23\Browsers\CentBrowser
  • %AppDataLocal%\44_23\Browsers\Chedot
  • %AppDataLocal%\44_23\Browsers\Chromium
  • %AppDataLocal%\44_23\Browsers\Chromodo
  • %AppDataLocal%\44_23\Browsers\CocCoc
  • %AppDataLocal%\44_23\Browsers\Comodo
  • %AppDataLocal%\44_23\Browsers\Coowon
  • %AppDataLocal%\44_23\Browsers\Cyberfox
  • %AppDataLocal%\44_23\Browsers\Edge
  • %AppDataLocal%\44_23\Browsers\Elements Browser
  • %AppDataLocal%\44_23\Browsers\Epic Privacy Browser
  • %AppDataLocal%\44_23\Browsers\Fenrir Inc
  • %AppDataLocal%\44_23\Browsers\Firefox
  • %AppDataLocal%\44_23\Browsers\Google
  • %AppDataLocal%\44_23\Browsers\Google(x86)
  • %AppDataLocal%\44_23\Browsers\IceDragon
  • %AppDataLocal%\44_23\Browsers\Iridium
  • %AppDataLocal%\44_23\Browsers\K-Meleon
  • %AppDataLocal%\44_23\Browsers\K-Melon
  • %AppDataLocal%\44_23\Browsers\Kometa
  • %AppDataLocal%\44_23\Browsers\liebao
  • %AppDataLocal%\44_23\Browsers\Mail.Ru
  • %AppDataLocal%\44_23\Browsers\MapleStudio
  • %AppDataLocal%\44_23\Browsers\Maxthon3
  • %AppDataLocal%\44_23\Browsers\Nichrome
  • %AppDataLocal%\44_23\Browsers\Opera
  • %AppDataLocal%\44_23\Browsers\Orbitum
  • %AppDataLocal%\44_23\Browsers\Pale Moon
  • %AppDataLocal%\44_23\Browsers\QIP Surf
  • %AppDataLocal%\44_23\Browsers\Sputnik
  • %AppDataLocal%\44_23\Browsers\Thunderbird
  • %AppDataLocal%\44_23\Browsers\Torch
  • %AppDataLocal%\44_23\Browsers\uCozMedia
  • %AppDataLocal%\44_23\Browsers\Uran
  • %AppDataLocal%\44_23\Browsers\Vivaldi
  • %AppDataLocal%\44_23\Browsers\Waterfox
  • %AppDataLocal%\44_23\Browsers\Yandex
  • %AppDataLocal%\44_23\Files
  • %AppDataLocal%\44_23\Files\{Folders Copied From %Desktop%}
  • %AppDataLocal%\44_23\Files\{Folders Copied From %User Profile%\Documents}
  • %AppDataLocal%\44_23\Files\{Folders Copied From %User Profile%\source}
  • %AppDataLocal%\44_23\Wallets
  • %AppDataLocal%\44_23\Wallets\Armory
  • %AppDataLocal%\44_23\Wallets\Atomic\Local Storage\leveldb\
  • %AppDataLocal%\44_23\Wallets\Bitcoin Core
  • %AppDataLocal%\44_23\Wallets\Bytecoin
  • %AppDataLocal%\44_23\Wallets\Dash Core
  • %AppDataLocal%\44_23\Wallets\Electrum
  • %AppDataLocal%\44_23\Wallets\Ethereum
  • %AppDataLocal%\44_23\Wallets\Exodus
  • %AppDataLocal%\44_23\Wallets\Jaxx\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\
  • %AppDataLocal%\44_23\Wallets\Litecoin Core
  • %AppDataLocal%\44_23\Wallets\Monero
  • %AppDataLocal%\44_23\Wallets\Zcash
  • %AppDataLocal%\44_23\VPN
  • %AppDataLocal%\44_23\VPN\Proton VPN
  • %AppDataLocal%\44_23\VPN\OpenVPN
  • %AppDataLocal%\44_23\VPN\NordVPN
  • %AppDataLocal%\44_23\Steam
  • %AppDataLocal%\44_23\Steam\ssnf
  • %AppDataLocal%\44_23\Steam\configs
  • %AppDataLocal%\44_23\Discord
  • %AppDataLocal%\44_23\Discord\{Folders from %Application Data%\Discord\Local Storage\leveldb}
  • %AppDataLocal%\44_23\Discord\{Folders from %Application Data%\Discord PTB\Local Storage\leveldb}
  • %AppDataLocal%\44_23\Discord\{Folders from %Application Data%\Discord Canary\leveldb}
  • %User Temp%leveldb → copy of Discord's leveldb folder, deleted afterwards
  • %AppDataLocal%\44_23\FileZilla
  • %AppDataLocal%\44_23\Telegram\{Folders from Telegram's tdata path}
  • %AppDataLocal%\44_23\VimeWorld
  • %AppDataLocal%\44_23\Browsers\New_Passwords
  • %AppDataLocal%\44_23\Browsers\New_Cookies

(注意: %Desktop% 是当前用户的桌面,通常位于 C:\Windows\Profiles\{user name}\Desktop (Windows 98 和 ME)、C:\WINNT\Profiles\{user name}\Desktop (Windows NT)、C:\Documents and Settings\{User Name}\桌面 (Windows 2000(32-bit)、XP 和 Server 2003(32-bit)) 和 C:\Users\{user name}\Desktop (Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit) 和 10(64-bit))。. %User Profile% 是当前用户的概要文件文件夹,通常位于 C:\Windows\Profiles\{user name} (Windows 98 和 ME)、C:\WINNT\Profiles\{user name} (Windows NT)、C:\Documents and Settings\{user name} (Windows 2000(32-bit)、XP 和 Server 2003(32-bit)) 和 C:\Users\{user name} (Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit) 和 10(64-bit))。. %Application Data% 是当前用户的 Application Data 文件夹,通常位于 C:\Windows\Profiles\{user name}\Application Data (Windows 98 和 ME)、C:\WINNT\Profiles\{user name}\Application Data (Windows NT)、C:\Documents and Settings\{user name}\Local Settings\Application Data (Windows 2000(32-bit)、XP 和 Server 2003(32-bit)) 和 C:\Users\{user name}\AppData\Roaming (Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit) 和 10(64-bit))。. %User Temp% 是当前用户的 Temp 文件夹。通常位于 C:\Documents and Settings\{user name}\Local Settings\Temp (Windows 2000(32-bit)、XP 和 Server 2003(32-bit))、C:\Users\{user name}\AppData\Local\Temp (Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit) 和 10(64-bit)。)

植入例程

它在保存收集信息的位置植入下列文件:

  • %AppDataLocal%\44_23\Browsers\{Browser Name}\CreditCards.txt
  • %AppDataLocal%\44_23\Browsers\{Browser Name}\Passwords.txt
  • %AppDataLocal%\44_23\Browsers\{Browser Name}\Autofill.txt
  • %AppDataLocal%\44_23\Browsers\{Browser Name}Bookmarks.txt
  • %AppDataLocal%\44_23\Browsers\Cookies_{Browser Name}{Random Number}.txt
  • %AppDataLocal%\44_23\Passwords.txt
  • %AppDataLocal%\44_23\Files\{Folders Copied From %Desktop%}\{.txt Files Copied From %Desktop%}
  • %AppDataLocal%\44_23\Files\{Folders Copied From %User Profile%\Documents}\{.txt Files Copied From %User Profile%\Documents}
  • %AppDataLocal%\44_23\Files\{Folders Copied From %User Profile%\source}\{.txt Files Copied From %User Profile%\source}
  • %AppDataLocal%\44_23\Wallets\Armory\{Files Copied from}
  • %AppDataLocal%\44_23\Wallets\Atomic\Local Storage\leveldb\{Files Copied from %AppData%\atomic\Local Storage\leveldb
  • %AppDataLocal%\44_23\Bitcoin Core\wallet.dat
  • %AppDataLocal%\44_23\Bytecoin\{.wallet Files Copied from %AppData%\bytecoin}
  • %AppDataLocal%\44_23\Dash Core\wallet.dat
  • %AppDataLocal%\44_23\Wallets\Electrum\{Files Copied from %AppData%\Electrum\wallets}
  • %AppDataLocal%\44_23\Wallets\Ethereum\{Files Copied from %AppData%\Ethereum\keystore}
  • %AppDataLocal%\44_23\Wallets\Exodus\{Files Copied from %AppData%\Exodus\exodus.wallet}
  • %AppDataLocal%\44_23\Wallets\Jaxx\{Files Copied from %AppData%\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\}
  • %AppDataLocal%\44_23\Litecoin Core\wallet.dat
  • %AppDataLocal%\44_23\Wallets\Monero\{stolen information file}
  • %AppDataLocal%\44_23\Wallets\Zcash\{Files Copied from %AppData%\Zcash}
  • %AppDataLocal%\44_23\Screen.png
  • %AppDataLocal%\44_23\Process.txt
  • %AppDataLocal%\44_23\Information.txt
  • %AppDataLocal%\44_23\VPN\Proton VPN\{Path to %AppDataLocal%ProtonVPN where user.config is found}\user.config
  • %AppDataLocal%\44_23\VPN\OpenVPN\{OVPN File Name}.ovpn
  • %AppDataLocal%\44_23\VPN\NordVPN\accounts.txt
  • %AppDataLocal%\44_23\Steam\AccountsList.txt
  • %AppDataLocal%\44_23\Steam\Games.txt
  • %AppDataLocal%\44_23\Steam\ssnf\{Steam ssnf Files}
  • %AppDataLocal%\44_23\Steam\configs\{Steam vdf Files}
  • %AppDataLocal%\44_23\Discord\Tokens.txt
  • %AppDataLocal%\44_23\Discord\{Folders and Files from %Application Data%\Discord\Local Storage\leveldb}
  • %AppDataLocal%\44_23\Discord\{Folders and Files from %Application Data%\Discord PTB\Local Storage\leveldb}
  • %AppDataLocal%\44_23\Discord\{Folders and Files from %Application Data%\Discord Canary\leveldb}
  • %User Temp%\leveldb\{Files From Discord's leveldb Folder} → deleted afterwards
  • %AppDataLocal%\44_23\FileZilla\FileZilla.log
  • %AppDataLocal%\44_23\Telegram\{Folders and Files from Telegram's tdata path}
  • %AppDataLocal%\44_23\VimeWorld\[{VimeWorld Rank}]{VimeWorld Level}{VimeWorld Username}
  • %AppDataLocal%\44_23\Browsers\New_Passwords\Chrome Passwords.txt
  • %AppDataLocal%\44_23\Browsers\New_Cookies\Chrome Cookies.txt
  • %AppDataLocal%\{Country Code}[{Date and Time When the Zip File is Created}]-{IP Address of Affected Machine}-{Username}.zip → contains all stolen information

(注意: %Desktop% 是当前用户的桌面,通常位于 C:\Windows\Profiles\{user name}\Desktop (Windows 98 和 ME)、C:\WINNT\Profiles\{user name}\Desktop (Windows NT)、C:\Documents and Settings\{User Name}\桌面 (Windows 2000(32-bit)、XP 和 Server 2003(32-bit)) 和 C:\Users\{user name}\Desktop (Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit) 和 10(64-bit))。. %User Profile% 是当前用户的概要文件文件夹,通常位于 C:\Windows\Profiles\{user name} (Windows 98 和 ME)、C:\WINNT\Profiles\{user name} (Windows NT)、C:\Documents and Settings\{user name} (Windows 2000(32-bit)、XP 和 Server 2003(32-bit)) 和 C:\Users\{user name} (Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit) 和 10(64-bit))。. %Application Data% 是当前用户的 Application Data 文件夹,通常位于 C:\Windows\Profiles\{user name}\Application Data (Windows 98 和 ME)、C:\WINNT\Profiles\{user name}\Application Data (Windows NT)、C:\Documents and Settings\{user name}\Local Settings\Application Data (Windows 2000(32-bit)、XP 和 Server 2003(32-bit)) 和 C:\Users\{user name}\AppData\Roaming (Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit) 和 10(64-bit))。. %User Temp% 是当前用户的 Temp 文件夹。通常位于 C:\Documents and Settings\{user name}\Local Settings\Temp (Windows 2000(32-bit)、XP 和 Server 2003(32-bit))、C:\Users\{user name}\AppData\Local\Temp (Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit) 和 10(64-bit)。)

信息窃取

它收集下列数据:

  • Browser data (such as Credit Card Information, Username, Passwords, Website Cookies, and Bookmarks) from the following browsers:
    • 360 Browser
    • 7Star
    • Amigo
    • Atom
    • BlackHawk
    • Brave-Browser
    • CentBrowser
    • Chedot
    • ChromePlus
    • Chromium
    • Chromodo
    • Citrio
    • CocCoc
    • Comodo Dragon
    • Comodo IceDragon
    • Coowon
    • Cyberfox
    • Elements Browser
    • Epic Privacy Browser
    • Firefox
    • Google Chrome
    • Iridium
    • K-Meleon
    • K-Melon
    • Kometa
    • Liebao
    • Maxthon3
    • Microsoft Edge
    • Nichrome
    • Opera
    • Opera GX
    • Orbitum
    • Pale Moon
    • QIP Surf
    • Sleipnir5
    • Sputnik
    • Thunderbird
    • Torch
    • Uran
    • Vivaldi
    • Waterfox
    • Yandex Browser
  • Cryptocurrency wallet data from the following applications:
    • Armory
    • Atomic Wallet
    • Bitcoin Core
    • Bytecoin
    • Dash Core
    • Electrum
    • Ethereum
    • Exodus
    • Jaxx
    • Litecoin Core
    • Monero
    • Zcash
  • Configuration files from the following VPN applications:
    • NordVPN
    • OpenVPN
    • Proton VPN
  • Online account information:
    • Discord
      • Files in Discord leveldb folders
      • Tokens
    • Steam
      • Account Names
      • Configuration Files
      • Games Acquired
      • SSNF Files
    • Telegram
      • Keys
      • Session Directories
      • Settings Files
      • User Data
      • User Tags
    • VimeWorld
      • Configuration File (contains username, passwords, rank, level, etc.)
      • OSSUID
  • Credentials for FileZilla:
    • Host
    • Port
    • Username
    • Password
  • System Information:
    • Basic Service Set Identifier
    • Clipboard Content
    • Computername
    • Country
    • CPU ID
    • CPU Name
    • Current Date and Time
    • Geolocation
    • GPU Name
    • IP Address
    • List of Running Processes
    • Log Date
    • Malware Current Working Directory
    • Operating System
    • Screen Resolution
    • Screenshot of Affected Machine
    • Total RAM
    • Username

窃取信息

它通过 HTTP POST 将收集的信息发送到下列 URL:

  • https://{BLOCKED}egram.org/bot7111654667:AAFkYkvnCsb8YVJsK4iKBRAyyQO9vyaJa7U/sendDocument?chat_id=1435200072&caption=\n{Contents of Log}

其他详细信息

该程序执行以下操作:

  • It copies .txt files from %Desktop%, %User Profile%\Documents, and %User Profile%\source that does not exceed 5000 bytes to %AppDataLocal%\44_23\Files while the folder does not exceed 25000 bytes.
  • It connects to the following URL to identify the affected machine's geolocation:
    • http://{BLOCKED}i.com/xml/
  • It connects to the following URL to retrieve online account information:
    • https://{BLOCKED}ommunity.com/profiles/{Steam Username}
    • https://{BLOCKED}eworld.ru/user/name/{VimeWorld Username}

  解决方案

最小扫描引擎: 9.800
First VSAPI Pattern File: 19.556.04
VSAPI 第一样式发布日期: 2024年8月28日
VSAPI OPR样式版本: 19.557.00
VSAPI OPR样式发布日期: 2024年8月29日

Step 2

对于Windows ME和XP用户,在扫描前,请确认已禁用系统还原功能,才可全面扫描计算机。

Step 3

注意:在此恶意软件/间谍软件/灰色软件执行期间,并非所有文件、文件夹和注册表键值和项都会安装到您的计算机上。这可能是由于不完整的安装或其他操作系统条件所致。如果您没有找到相同的文件/文件夹/注册表信息,请继续进行下一步操作。

Step 4

搜索和删除这些文件

[ 更多 ]
有些组件文件可能是隐藏的。请确认在"高级选项"中已选中搜索隐藏文件和文件夹复选框,使查找结果包括所有隐藏文件和文件夹。
  • %AppDataLocal%\44_23\Browsers\{Browser Name}\CreditCards.txt
  • %AppDataLocal%\44_23\Browsers\{Browser Name}\Passwords.txt
  • %AppDataLocal%\44_23\Browsers\{Browser Name}\Autofill.txt
  • %AppDataLocal%\44_23\Browsers\{Browser Name}Bookmarks.txt
  • %AppDataLocal%\44_23\Browsers\Cookies_{Browser Name}{Random Number}.txt
  • %AppDataLocal%\44_23\Passwords.txt
  • %AppDataLocal%\44_23\Files\{Folders Copied From %Desktop%}\{.txt Files Copied From %Desktop%}
  • %AppDataLocal%\44_23\Files\{Folders Copied From %User Profile%\Documents}\{.txt Files Copied From %User Profile%\Documents}
  • %AppDataLocal%\44_23\Files\{Folders Copied From %User Profile%\source}\{.txt Files Copied From %User Profile%\source}
  • %AppDataLocal%\44_23\Wallets\Armory\{Files Copied from}
  • %AppDataLocal%\44_23\Wallets\Atomic\Local Storage\leveldb\{Files Copied from %AppData%\atomic\Local Storage\leveldb
  • %AppDataLocal%\44_23\Bitcoin Core\wallet.dat
  • %AppDataLocal%\44_23\Bytecoin\{.wallet Files Copied from %AppData%\bytecoin}
  • %AppDataLocal%\44_23\Dash Core\wallet.dat
  • %AppDataLocal%\44_23\Wallets\Electrum\{Files Copied from %AppData%\Electrum\wallets}
  • %AppDataLocal%\44_23\Wallets\Ethereum\{Files Copied from %AppData%\Ethereum\keystore}
  • %AppDataLocal%\44_23\Wallets\Exodus\{Files Copied from %AppData%\Exodus\exodus.wallet}
  • %AppDataLocal%\44_23\Wallets\Jaxx\{Files Copied from %AppData%\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\}
  • %AppDataLocal%\44_23\Litecoin Core\wallet.dat
  • %AppDataLocal%\44_23\Wallets\Monero\{stolen information file}
  • %AppDataLocal%\44_23\Wallets\Zcash\{Files Copied from %AppData%\Zcash}
  • %AppDataLocal%\44_23\Screen.png
  • %AppDataLocal%\44_23\Process.txt
  • %AppDataLocal%\44_23\Information.txt
  • %AppDataLocal%\44_23\VPN\Proton VPN\{Path to %AppDataLocal%ProtonVPN where user.config is found}\user.config
  • %AppDataLocal%\44_23\VPN\OpenVPN\{OVPN File Name}.ovpn
  • %AppDataLocal%\44_23\VPN\NordVPN\accounts.txt
  • %AppDataLocal%\44_23\Steam\AccountsList.txt
  • %AppDataLocal%\44_23\Steam\Games.txt
  • %AppDataLocal%\44_23\Steam\ssnf\{Steam ssnf Files}
  • %AppDataLocal%\44_23\Steam\configs\{Steam vdf Files}
  • %AppDataLocal%\44_23\Discord\Tokens.txt
  • %AppDataLocal%\44_23\Discord\{Folders and Files from %Application Data%\Discord\Local Storage\leveldb}
  • %AppDataLocal%\44_23\Discord\{Folders and Files from %Application Data%\Discord PTB\Local Storage\leveldb}
  • %AppDataLocal%\44_23\Discord\{Folders and Files from %Application Data%\Discord Canary\leveldb}
  • %User Temp%\leveldb\{Files From Discord's leveldb Folder}
  • %AppDataLocal%\44_23\FileZilla\FileZilla.log
  • %AppDataLocal%\44_23\Telegram\{Folders and Files from Telegram's tdata path}
  • %AppDataLocal%\44_23\VimeWorld\[{VimeWorld Rank}]{VimeWorld Level}{VimeWorld Username}
  • %AppDataLocal%\44_23\Browsers\New_Passwords\Chrome Passwords.txt
  • %AppDataLocal%\44_23\Browsers\New_Cookies\Chrome Cookies.txt
  • %AppDataLocal%\{Country Code}[{Date and Time When the Zip File is Created}]-{IP Address of Affected Machine}-{Username}.zip
DATA_GENERIC_FILENAME_1
  • 查找范围下拉列表中,选择
  • 我的电脑然后回车确认。
  • 一旦找到,请选择文件,然后按下SHIFT+DELETE彻底删除文件。
  • 对剩余的文件重复第2到4步:
      • %AppDataLocal%\44_23\Browsers\{Browser Name}\CreditCards.txt
      • %AppDataLocal%\44_23\Browsers\{Browser Name}\Passwords.txt
      • %AppDataLocal%\44_23\Browsers\{Browser Name}\Autofill.txt
      • %AppDataLocal%\44_23\Browsers\{Browser Name}Bookmarks.txt
      • %AppDataLocal%\44_23\Browsers\Cookies_{Browser Name}{Random Number}.txt
      • %AppDataLocal%\44_23\Passwords.txt
      • %AppDataLocal%\44_23\Files\{Folders Copied From %Desktop%}\{.txt Files Copied From %Desktop%}
      • %AppDataLocal%\44_23\Files\{Folders Copied From %User Profile%\Documents}\{.txt Files Copied From %User Profile%\Documents}
      • %AppDataLocal%\44_23\Files\{Folders Copied From %User Profile%\source}\{.txt Files Copied From %User Profile%\source}
      • %AppDataLocal%\44_23\Wallets\Armory\{Files Copied from}
      • %AppDataLocal%\44_23\Wallets\Atomic\Local Storage\leveldb\{Files Copied from %AppData%\atomic\Local Storage\leveldb
      • %AppDataLocal%\44_23\Bitcoin Core\wallet.dat
      • %AppDataLocal%\44_23\Bytecoin\{.wallet Files Copied from %AppData%\bytecoin}
      • %AppDataLocal%\44_23\Dash Core\wallet.dat
      • %AppDataLocal%\44_23\Wallets\Electrum\{Files Copied from %AppData%\Electrum\wallets}
      • %AppDataLocal%\44_23\Wallets\Ethereum\{Files Copied from %AppData%\Ethereum\keystore}
      • %AppDataLocal%\44_23\Wallets\Exodus\{Files Copied from %AppData%\Exodus\exodus.wallet}
      • %AppDataLocal%\44_23\Wallets\Jaxx\{Files Copied from %AppData%\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\}
      • %AppDataLocal%\44_23\Litecoin Core\wallet.dat
      • %AppDataLocal%\44_23\Wallets\Monero\{stolen information file}
      • %AppDataLocal%\44_23\Wallets\Zcash\{Files Copied from %AppData%\Zcash}
      • %AppDataLocal%\44_23\Screen.png
      • %AppDataLocal%\44_23\Process.txt
      • %AppDataLocal%\44_23\Information.txt
      • %AppDataLocal%\44_23\VPN\Proton VPN\{Path to %AppDataLocal%ProtonVPN where user.config is found}\user.config
      • %AppDataLocal%\44_23\VPN\OpenVPN\{OVPN File Name}.ovpn
      • %AppDataLocal%\44_23\VPN\NordVPN\accounts.txt
      • %AppDataLocal%\44_23\Steam\AccountsList.txt
      • %AppDataLocal%\44_23\Steam\Games.txt
      • %AppDataLocal%\44_23\Steam\ssnf\{Steam ssnf Files}
      • %AppDataLocal%\44_23\Steam\configs\{Steam vdf Files}
      • %AppDataLocal%\44_23\Discord\Tokens.txt
      • %AppDataLocal%\44_23\Discord\{Folders and Files from %Application Data%\Discord\Local Storage\leveldb}
      • %AppDataLocal%\44_23\Discord\{Folders and Files from %Application Data%\Discord PTB\Local Storage\leveldb}
      • %AppDataLocal%\44_23\Discord\{Folders and Files from %Application Data%\Discord Canary\leveldb}
      • %User Temp%\leveldb\{Files From Discord's leveldb Folder}
      • %AppDataLocal%\44_23\FileZilla\FileZilla.log
      • %AppDataLocal%\44_23\Telegram\{Folders and Files from Telegram's tdata path}
      • %AppDataLocal%\44_23\VimeWorld\[{VimeWorld Rank}]{VimeWorld Level}{VimeWorld Username}
      • %AppDataLocal%\44_23\Browsers\New_Passwords\Chrome Passwords.txt
      • %AppDataLocal%\44_23\Browsers\New_Cookies\Chrome Cookies.txt
      • %AppDataLocal%\{Country Code}[{Date and Time When the Zip File is Created}]-{IP Address of Affected Machine}-{Username}.zip
  • Step 5

    搜索和删除这些文件夹

    [ 更多 ]
    请确认在高级选项中已选中搜索隐藏文件和文件夹复选框,使查找结果包括所有隐藏文件夹。;
    • %AppDataLocal%\44_23\Browsers\360Browser
    • %AppDataLocal%\44_23\Browsers\7Star
    • %AppDataLocal%\44_23\Browsers\Amigo
    • %AppDataLocal%\44_23\Browsers\BlackHaw
    • %AppDataLocal%\44_23\Browsers\BraveSoftware
    • %AppDataLocal%\44_23\Browsers\CatalinaGroup
    • %AppDataLocal%\44_23\Browsers\CentBrowser
    • %AppDataLocal%\44_23\Browsers\Chedot
    • %AppDataLocal%\44_23\Browsers\Chromium
    • %AppDataLocal%\44_23\Browsers\Chromodo
    • %AppDataLocal%\44_23\Browsers\CocCoc
    • %AppDataLocal%\44_23\Browsers\Comodo
    • %AppDataLocal%\44_23\Browsers\Coowon
    • %AppDataLocal%\44_23\Browsers\Cyberfox
    • %AppDataLocal%\44_23\Browsers\Edge
    • %AppDataLocal%\44_23\Browsers\Elements Browser
    • %AppDataLocal%\44_23\Browsers\Epic Privacy Browser
    • %AppDataLocal%\44_23\Browsers\Fenrir Inc
    • %AppDataLocal%\44_23\Browsers\Firefox
    • %AppDataLocal%\44_23\Browsers\Google
    • %AppDataLocal%\44_23\Browsers\Google(x86)
    • %AppDataLocal%\44_23\Browsers\IceDragon
    • %AppDataLocal%\44_23\Browsers\Iridium
    • %AppDataLocal%\44_23\Browsers\K-Meleon
    • %AppDataLocal%\44_23\Browsers\K-Melon
    • %AppDataLocal%\44_23\Browsers\Kometa
    • %AppDataLocal%\44_23\Browsers\liebao
    • %AppDataLocal%\44_23\Browsers\Mail.Ru
    • %AppDataLocal%\44_23\Browsers\MapleStudio
    • %AppDataLocal%\44_23\Browsers\Maxthon3
    • %AppDataLocal%\44_23\Browsers\Nichrome
    • %AppDataLocal%\44_23\Browsers\Opera
    • %AppDataLocal%\44_23\Browsers\Orbitum
    • %AppDataLocal%\44_23\Browsers\Pale Moon
    • %AppDataLocal%\44_23\Browsers\QIP Surf
    • %AppDataLocal%\44_23\Browsers\Sputnik
    • %AppDataLocal%\44_23\Browsers\Thunderbird
    • %AppDataLocal%\44_23\Browsers\Torch
    • %AppDataLocal%\44_23\Browsers\uCozMedia
    • %AppDataLocal%\44_23\Browsers\Uran
    • %AppDataLocal%\44_23\Browsers\Vivaldi
    • %AppDataLocal%\44_23\Browsers\Waterfox
    • %AppDataLocal%\44_23\Browsers\Yandex
    • %AppDataLocal%\44_23\Browsers\New_Cookies
    • %AppDataLocal%\44_23\Browsers\New_Passwords
    • %AppDataLocal%\44_23\Browsers
    • %AppDataLocal%\44_23\Files\{Folders Copied From %Desktop%}
    • %AppDataLocal%\44_23\Files\{Folders Copied From %User Profile%\Documents}
    • %AppDataLocal%\44_23\Files\{Folders Copied From %User Profile%\source}
    • %AppDataLocal%\44_23\Files
    • %AppDataLocal%\44_23\Wallets\Armory
    • %AppDataLocal%\44_23\Wallets\Atomic
    • %AppDataLocal%\44_23\Wallets\Bitcoin Core
    • %AppDataLocal%\44_23\Wallets\Bytecoin
    • %AppDataLocal%\44_23\Wallets\Dash Core
    • %AppDataLocal%\44_23\Wallets\Electrum
    • %AppDataLocal%\44_23\Wallets\Ethereum
    • %AppDataLocal%\44_23\Wallets\Exodus
    • %AppDataLocal%\44_23\Wallets\Jaxx
    • %AppDataLocal%\44_23\Wallets\Litecoin Core
    • %AppDataLocal%\44_23\Wallets\Monero
    • %AppDataLocal%\44_23\Wallets\Zcash
    • %AppDataLocal%\44_23\Wallets
    • %AppDataLocal%\44_23\VPN\Proton VPN
    • %AppDataLocal%\44_23\VPN\OpenVPN
    • %AppDataLocal%\44_23\VPN\NordVPN
    • %AppDataLocal%\44_23\VPN
    • %AppDataLocal%\44_23\Steam\ssnf
    • %AppDataLocal%\44_23\Steam\configs
    • %AppDataLocal%\44_23\Steam
    • %AppDataLocal%\44_23\Discord\{Folders from %Application Data%\Discord\Local Storage\leveldb}
    • %AppDataLocal%\44_23\Discord\{Folders from %Application Data%\Discord PTB\Local Storage\leveldb}
    • %AppDataLocal%\44_23\Discord\{Folders from %Application Data%\Discord Canary\leveldb}
    • %AppDataLocal%\44_23\Discord
    • %AppDataLocal%\44_23\FileZilla
    • %AppDataLocal%\44_23\Telegram\{Folders from Telegram's tdata path}
    • %AppDataLocal%\44_23\Telegram
    • %AppDataLocal%\44_23\VimeWorld
    • %AppDataLocal%\44_23
    • %User Temp%\leveldb

    Step 6

    使用亚信安全产品扫描计算机,并删除检测到的TrojanSpy.MSIL.ANGRYSTEALER.THHBHBD文件 如果检测到的文件已被亚信安全产品清除、删除或隔离,则无需采取进一步措施。可以选择直接删除隔离的文件。请参阅知识库页面了解详细信息。