Technical Information
- '%PROGRAM_FILES%\phpnuke\phpnuke\1.8.18.5\phpnukesrv.exe' /RegServer
- '%TEMP%\phpnuke\phpnuke\1.8.18.5\phpnuke4ffx.exe'
- '%TEMP%\phpnuke\phpnuke\1.8.18.5\phpnuke4ie.exe'
- chrome.exe
- <LS_APPDATA>\Google\Chrome\User Data\default\extensions\cngompmodgafkkffefbfbghhciijojjh\1.0_0\json2.min.js
- <LS_APPDATA>\Google\Chrome\User Data\default\extensions\cngompmodgafkkffefbfbghhciijojjh\1.0_0\logo.png
- <LS_APPDATA>\Google\Chrome\User Data\default\extensions\cngompmodgafkkffefbfbghhciijojjh\1.0_0\hprtkMsg.htm
- <LS_APPDATA>\Google\Chrome\User Data\default\extensions\cngompmodgafkkffefbfbghhciijojjh\1.0_0\hprtkMsg.js
- %PROGRAM_FILES%\phpnuke\phpnuke\1.8.18.5\uninstall.exe
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsnF.tmp
- <LS_APPDATA>\Google\Chrome\User Data\default\extensions\cngompmodgafkkffefbfbghhciijojjh\1.0_0\manifest.json
- <LS_APPDATA>\Google\Chrome\User Data\default\extensions\cngompmodgafkkffefbfbghhciijojjh\1.0_0\pref.json
- <LS_APPDATA>\Google\Chrome\User Data\default\extensions\cngompmodgafkkffefbfbghhciijojjh\1.0_0\dpk.js
- <LS_APPDATA>\Google\Chrome\User Data\default\extensions\cngompmodgafkkffefbfbghhciijojjh\1.0_0\CrmAdpt.dll
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsvE.tmp
- %PROGRAM_FILES%\phpnuke\phpnuke\1.8.18.5\phpnuke.crx
- <LS_APPDATA>\Google\Chrome\User Data\default\extensions\cngompmodgafkkffefbfbghhciijojjh\1.0_0\CTB.dll
- <LS_APPDATA>\Google\Chrome\User Data\default\extensions\cngompmodgafkkffefbfbghhciijojjh\1.0_0\bg.js
- <LS_APPDATA>\Google\Chrome\User Data\default\extensions\cngompmodgafkkffefbfbghhciijojjh\1.0_0\ct.js
- <LS_APPDATA>\Google\Chrome\User Data\default\extensions\cngompmodgafkkffefbfbghhciijojjh\1.0_0\appCntrl.js
- <LS_APPDATA>\Google\Chrome\User Data\default\extensions\cngompmodgafkkffefbfbghhciijojjh\1.0_0\bg.html
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsf10.tmp
- C:\user.js
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsf1C.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsg1A.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsk1B.tmp
- <Current directory>\nsq1F.tmp
- %TEMP%\nsz2.tmp\InetLoad.dll
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsf1D.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsa1E.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsn19.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsh13.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsq14.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsx11.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsu12.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsl17.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsj18.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nse15.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nss16.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\phpnuke4ie.exe
- %TEMP%\phpnuke\phpnuke\1.8.18.5\phpnuke4ffx.exe
- <Current directory>\nsq4.tmp
- %TEMP%\nsz2.tmp\Processes.dll
- %TEMP%\nsg7.tmp\nsisos.dll
- %TEMP%\nsg8.tmp\System.dll
- %TEMP%\nsg7.tmp\System.dll
- %TEMP%\nsg8.tmp\UserInfo.dll
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\searchplugins\phpnuke.xml
- %TEMP%\nsz2.tmp\nsisos.dll
- %TEMP%\nsz2.tmp\chrmPref.dll
- %TEMP%\nsz2.tmp\UserInfo.dll
- %TEMP%\nsz2.tmp\System.dll
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\user.js
- <Current directory>\nsg3.tmp
- %TEMP%\nsz2.tmp\mt.dll
- %TEMP%\nsz2.tmp\Time.dll
- %TEMP%\nsg7.tmp\mt.dll
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsdA.tmp
- %PROGRAM_FILES%\phpnuke\phpnuke\1.8.18.5\phpnukesrv.exe
- %PROGRAM_FILES%\phpnuke\phpnuke\1.8.18.5\escortShld.dll
- %PROGRAM_FILES%\phpnuke\phpnuke\1.8.18.5\phpnukeTlbr.dll
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsyD.tmp
- %TEMP%\nsg8.tmp\md5dll.dll
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nszB.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsrC.tmp
- %PROGRAM_FILES%\phpnuke\phpnuke\1.8.18.5\phpnukeApp.dll
- %TEMP%\nsg8.tmp\mt.dll
- %TEMP%\mt_ffx\phpnuke\phpnuke\1.8.18.5\phpnuke.xpi
- %TEMP%\nsg8.tmp\nsisos.dll
- %TEMP%\nsg7.tmp\Time.dll
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsc9.tmp
- %PROGRAM_FILES%\phpnuke\phpnuke\1.8.18.5\bh\phpnuke.dll
- %TEMP%\nsg8.tmp\Time.dll
- %PROGRAM_FILES%\phpnuke\phpnuke\1.8.18.5\phpnukeEng.dll
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nss16.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nse15.tmp
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\user.js
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsl17.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsu12.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsx11.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsq14.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsh13.tmp
- %TEMP%\nsg7.tmp\System.dll
- %TEMP%\nsg7.tmp\nsisos.dll
- <Current directory>\nsq1F.tmp
- %TEMP%\nsg7.tmp\Time.dll
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsg1A.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsn19.tmp
- %TEMP%\nsg7.tmp\mt.dll
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsk1B.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsrC.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nszB.tmp
- %TEMP%\nsg8.tmp\md5dll.dll
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsyD.tmp
- <Current directory>\nsq4.tmp
- <Current directory>\nsg3.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsdA.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsc9.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsvE.tmp
- %TEMP%\nsg8.tmp\UserInfo.dll
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsf10.tmp
- %TEMP%\phpnuke\phpnuke\1.8.18.5\nsnF.tmp
- %TEMP%\nsg8.tmp\nsisos.dll
- %TEMP%\nsg8.tmp\mt.dll
- %TEMP%\nsg8.tmp\Time.dll
- %TEMP%\nsg8.tmp\System.dll
- from %TEMP%\phpnuke\phpnuke\1.8.18.5\nsf1D.tmp to %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\user.js
- from %TEMP%\phpnuke\phpnuke\1.8.18.5\nsa1E.tmp to %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\user.js
- from %TEMP%\phpnuke\phpnuke\1.8.18.5\nsj18.tmp to %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\user.js
- from %TEMP%\phpnuke\phpnuke\1.8.18.5\nsf1C.tmp to %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\user.js
- 're#####.montiera.com':80
- re#####.montiera.com/reports/jsRprt.srf?ri######################################################################################################################################################################################################
- DNS ASK re#####.montiera.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: 'Shell_TrayWnd'