Potential leak of data: OTL Logfile


Detected 1 occurrence(s) of ‘OTL logfile created on’:
OTL logfile created on: 22.09.2012 17:50:52 - Run 2
OTL by OldTimer - Version 3.2.65.0     Folder = C:\Dokumente und Einstellungen\Bene\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18

Potential leak of data: Simple Password


Detected 1 occurrence(s) of ‘^\s*pass[word]+\s*[:=]+[ \t]*[a-z0-9\-_\!]+$’:
Backdoor:Win32/Poison.E by MalwareCenter

http://59.120.154.62/meeting/hi.exe

http://www.sendspace.com/file/tewo75 (password: infected)
Password: infected

Potential leak of data: Email Addresses List


Detected 54 occurrence(s) of ‘[\s\|,;']+[a-z0-9\-\._]+@[a-z0-9\-\.]+\.[a-z]{2,4}[\s\|,;:']+’:
/config/login_verify2 elmamdiop200091@yahoo. 201068 WFPSNAFU10 41.214.9.10 2012-09-18 04:17:39
 IE 7-9 https://login.yahoo.com/config/login_verify2 elm 201068 WFPSNAFU10 41.214.9.10 2012-09-18 04:17:37
 IE 7-9 https://login.yahoo.com/config/login_verify2 elmamdiop200091@yahoo.fr 201068 WFPSNAFU10 41.214.9.10 2012-09-18 04:17:36

Potential leak of data: Email Addresses List


Detected 74 occurrence(s) of ‘[\s\|,;']+[a-z0-9\-\._]+@[a-z0-9\-\.]+\.[a-z]{2,4}[\s\|,;:']+’:
ndirt.com/ Chrome - -
https://www.accountcentralonline.com/cmuser/login/show.do Chrome - -
http://kucampus.kaplan.edu Firefox Gregory Anderson Football-1
http://kucampus.kaplan.edu Firefox Gregory AndersonòÚÃw Football-1
https://www.netflix.com Firefox gdanderson77@gmail.com insane12</pre>

Potential leak of data: MD5/SHA1 Hashes


Detected 23 occurrence(s) of ‘[\s\|:;'"]+[0-9a-f]{32}(?:[0-9a-f]{8})?[\s\|:;'"]+’:
m 2^65 to 2^66, We1: 4CA55084, AID: 6612D75D6F019746BF24F5D602666143
[Sat Sep 22 19:09:58 2012]
Trial factoring M781490417 to 2^66 is 46.26% complete.
[Sat Sep 22 19:17:00 2012]
UID: kiwiboy/hp-p4-2600mhz, M781490417 has a factor: 67210061696844013543, AID: F28E8C5BAB82F66914038E7DF31E0DB4
[Sat Sep 22 19:25:51 2012]
Trial factoring M781489967 to 2^66 is 46.26% complete.