Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- .txt
- open
- Software
- For base!!!!!
- For base!!!!!
- For base!!!!!
- For base!!!!!
- Software\
- For base!!!!!
- For base!!!!!
- For base!!!!!
- http://%[^:]:%d/%s
- Mozilla/5.0 (Windows NT 6.1; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
- POST
- Content-Type: application/x-www-form-urlencoded
- svchost.exe
- Software\Microsoft\Windows\CurrentVersion\Run
- Software\Microsoft\Windows\CurrentVersion\Run
- ntdll.dll
- NtQueryInformationProcess
- NtReadVirtualMemory
- tjV8bTHo
- For base!!!!!
- %1024[^=]=%1024[^;]
- For base!!!!!
- For base!!!!!
- %1024[^=]=%1024[^;]
- ntdll.dll
- _stricmp
- strcat
- strlen
- strcpy
- sprintf
- sscanf
- memset
- memcpy
- NtQueryInformationProcess
- ZwReadVirtualMemory
- ZwMapViewOfSection
- NtCreateSection
- ZwUnmapViewOfSection
- ZwResumeThread
- 277YxuJ9
- Microsoft Base Cryptographic Provider v1.0
- .exe
- 2312s
- So1sDTqNiw
- <knock><id>%s</id><group>%s</group><src>%d</src><transport>%d</transport><time>%d</time><version>%d</version><status>%d</status><debug>%s</debug></knock>
- /index.php?r=gate
- .exe
- Software\
- %[^:]:%d
- Software\
- Software\Microsoft\Windows\CurrentVersion\Run
- 3)6{
- >`IsWow64Process
- kernel32
- %d.%d x%d
- antivirus0
- none
- firewall0
- none
- wireshark.exe
- Tfrmrpcap
- iptools.exe
- Iris - Version 5.59
- ProcessLasso_Notification_Class
- TSystemExplorerTrayForm.UnicodeClass
- PROCMON_WINDOW_CLASS
- PROCEXPL
- WdcWindow
- ProcessHacker
- 99929D61-1338-48B1-9433-D42A1D94F0D2-x64
- 99929D61-1338-48B1-9433-D42A1D94F0D2-x32
- 99929D61-1338-48B1-9433-D42A1D94F0D2
- Dumper
- Dumper64
- APISpy32Class
- VMwareDragDetWndClass
- VMwareSwitchUserControlClass
- vmtoolsd.exe
- prl_cc.exe
- prl_tools.exe
- SharedIntApp.exe
- VBoxTray.exe
- VBoxService.exe
- vmusrvc.exe
- vmsrvc.exe
- SYSTEM\CurrentControlSet\services\Disk\Enum
- VMware
- PTLTD
- Virtual
- HARDWARE\DESCRIPTION\System\BIOS
- VMware
- SystemProductName
- PTLTD
- SystemProductName
- VMware
- SystemManufacturer
- PTLTD
- SystemManufacturer
- HARDWARE\ACPI\DSDT\PTLTD__
- SYSTEM\CurrentControlSet\Enum\PCI\VEN_15AD&DEV_0774&SUBSYS_040515AD&REV_00
- SYSTEM\CurrentControlSet\services\Disk\Enum
- SYSTEM\CurrentControlSet\Enum\PCI\VEN_15AD&DEV_0774&SUBSYS_074015AD&REV_00
- Virtual
- SYSTEM\CurrentControlSet\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00
- PRLS
- HARDWARE\DESCRIPTION\System\BIOS
- Virtual
- SystemProductName
- PRLS
- SystemProductName
- Virtual
- SystemManufacturer
- PRLS
- SystemManufacturer
- SYSTEM\CurrentControlSet\services\Disk\Enum
- VBox
- HARDWARE\DESCRIPTION\System\BIOS
- VBox
- SystemProductName
- VBox
- SystemManufacturer
- HARDWARE\ACPI\DSDT\VBOX__
- SYSTEM\CurrentControlSet\services\Disk\Enum
- AMIBI
- HARDWARE\DESCRIPTION\System\BIOS
- AMIBI
- SystemProductName
- AMIBI
- SystemManufacturer
- SYSTEM\CurrentControlSet\Enum\PCI\VEN_5333&DEV_8811&SUBSYS_00000000&REV_00
- HARDWARE\ACPI\DSDT\AMIBI
- SYSTEM\CurrentControlSet\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00
- SYSTEM\CurrentControlSet\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00
- RtlDecompressBuffer
- ntdll.dll
- RtlGetCompressionWorkSpaceSize
- ntdll.dll
- RtlCompressBuffer
- ntdll.dll
- http://
- %[^:]:%d
- You fag!!!!!
- You fag!!!!!
- You fag!!!!!
- You fag!!!!!
- You fag!!!!!
- You fag!!!!!
- You fag!!!!!
- You fag!!!!!
- You fag!!!!!
- You fag!!!!!
- Software
- You fag!!!!!
- You fag!!!!!
- You fag!!!!!
- Software\
- Software
- For group!!!!!
- For group!!!!!
- For group!!!!!
- Software\
- For group!!!!!
- For group!!!!!
- For group!!!!!
- For group!!!!!
- advapi32.dll
- MD5Init
- MD5Update
- MD5Final
- Software\Microsoft\Windows NT\CurrentVersion
- InstallDate
- bb10bd00-c135-11e2-b7ac-005056c00008
- c540500f-c135-11e2-b348-005056c00008
- bb10bd00-c135-11e2-b7ac-005056c00008
- Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
- Hidden
- ShowSuperHidden
- CabinetWClass
- CabinetWClass
- <5IkQ
- s1q4
- <5IkQ
- <5IkQ
- HeapFree
- HeapAlloc
- CloseHandle
- WriteFile
- CreateFileA
- VirtualFree
- VirtualAlloc
- CreateProcessA
- ResumeThread
- SetEvent
- OpenEventA
- WideCharToMultiByte
- OpenProcess
- GetCurrentProcessId
- GetProcAddress
- GetModuleHandleA
- ReadFile
- GetFileInformationByHandle
- Sleep
- GetSystemTimeAsFileTime
- DeleteFileA
- GetTickCount
- TerminateProcess
- GetCurrentProcess
- GetLastError
- CreateMutexA
- HeapCreate
- GetVersionExA
- CreateThread
- LoadLibraryA
- GetProcessHeap
- CreateEventA
- CopyFileW
- GetVolumeInformationW
- FindClose
- FindNextFileW
- SetFileAttributesW
- FindFirstFileW
- ExitThread
- FindNextChangeNotification
- WaitForMultipleObjects
- FindFirstChangeNotificationW
- DeviceIoControl
- CreateFileW
- GetLogicalDrives
- GetDriveTypeW
- GetVolumePathNameW
- KERNEL32.dll
- FindWindowA
- DispatchMessageA
- TranslateMessage
- GetMessageA
- SetWindowLongA
- CreateWindowExA
- RegisterClassExA
- DefWindowProcA
- GetWindowLongA
- PostMessageA
- FindWindowExA
- USER32.dll
- RegCloseKey
- RegEnumValueA
- RegEnumKeyExA
- RegOpenKeyA
- RegSetValueExA
- RegCreateKeyA
- RegDeleteKeyA
- CryptDestroyHash
- CryptVerifySignatureA
- CryptHashData
- CryptCreateHash
- CryptEncrypt
- RegOpenKeyExA
- RegDeleteValueA
- RegQueryValueExA
- CryptAcquireContextA
- LookupAccountNameA
- GetUserNameA
- ADVAPI32.dll
- ShellExecuteA
- SHGetSpecialFolderPathA
- SHELL32.dll
- CoCreateInstance
- CoInitialize
- CoSetProxyBlanket
- ole32.dll
- OLEAUT32.dll
- WS2_32.dll
- InternetCloseHandle
- InternetReadFile
- HttpSendRequestA
- HttpOpenRequestA
- InternetConnectA
- InternetOpenA
- WININET.dll
- free
- malloc
- memset
- wcstombs
- _wcsicmp
- mbstowcs
- memcpy
- sprintf
- calloc
- strstr
- _wcsdup
- MSVCRT.dll
- CryptStringToBinaryA
- CryptImportPublicKeyInfo
- CryptDecodeObjectEx
- CRYPT32.dll
- dll.dll
- Work
- RSDS
- C:\Users\DmitryHELL\Documents\SysIQUA\loader_1.4 s\loader_v4\loader_v3\Release\dll.pdb
- -----BEGIN PUBLIC KEY-----
- MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCUAUdLJ1rmxx+bAndp+Cz6+5I
- Kmgap2hn2df/UiVglAvvg2US9qbk65ixqw3dGN/9O9B30q5RD+xtZ6gl4ChBquqw
- jwxzGTVqJeexn5RHjtFR9lmJMYIwzoc/kMG8e6C/GaS2FCgY8oBpcESVyT2woV7U
- 00SNFZ88nyVv33z9+wIDAQAB
- -----END PUBLIC KEY-----
- Unknown ERROR! Please wait and try again later.
- jjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj
- 1.0.6, 6-Sept-2010
- US]CQ
- ^(BM
- kZ;&
- :n<u<
- ='=.=R=Y=i=p=
- >0>W>n>t>
- ?@?_?k?r?}?
- 0"0>0D0`0~0
- 131d1
- 2G2[2z2
- 3:3d3n3x3
- 3&4<4
- 6i6v6
- 6-757d7
- 848o8
- <"<W<e<
- =/=H=x=
- > >*>3>G>r>
- >7?C?J?P?X?a?u?
- ,0:0[0a0r0
- 1/1b1
- 2.262@2Q2}2
- 30373C3J3U3\3~3
- 3 4(424C4K4U4b4t4
- 5-545C5J5Z5a5u5
- 6 606:6P6k6s6}6
- 747>7J7Q7\7c7o7v7
- 9_9}9
- 9b:h:
- :.;8;V;`;
- =>>a>y>
- U0m0~0
- 3 3%32373<3I3N3S3`3e3j3w3|3
- 4"4/44494F4K4W4\4b4m4y4
- 4<5l5{5
- 6,6<6G6\6e6k6
- 858<8V8l8y8
- :f:z:
- ;";>;W;k;x;
- <?<u<
- = >+?
- 0M1U1b1
- 354=4J4a4q4
- 6$6H6\6
- 6>7c7s7
- 81:6:<:C:c:
- ;-;E;M;U;a;k;t;{;
- <!<*<8<><D<K<R<a<
- 0%0/0=0G0a0
- 132@2R3Z3}3
- 4'4I4k4
- 575Y5{5
- 6%6G6i6
- 7/7N7m7
- 8"8-82878X8]8~8
- 9&919L9W9o9|9
- :#:D:I:j:o:
- ;!;E;R;];x;
- <*<5<M<X<p<{<
- =$=/=A=G=N=_=e=k=t=z=
- > >&>/>9>@>V>
- 0"030=0N0
- 1K1_1
- 1@2r2
- 3)313;3L3Y3k3
- 4)40484B4O4\4b4
- 5!5B5I5Y5`5h5r5
- 6+676>6J6Q6r6y6
- 7"7)7R7Y7i7p7
- 8C8Z8`8y8
- 8!9@9L9S9_9f9q9x9
- :O:i:
- ;$;9;f;
- <%</<@<\<c<s<z<
- =!=>=\=n=z=
- ? ?'?<?C?i?
- 0,0@0b0i0
- 2%2+242:2@2F2L2U2`2i2n2
- 323E3
- 4(4=4Q4j4
- 8K9d9
- :":,:
- ;M;w;
- <X=r=
- >)>0><>u>
- 2-696
- <!<%<)<-<1<5<9<=<A<E<I<M<Q<U<Y<]<a<e<i<m<q<u<y<}<
- S8]8r8
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement