Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- delete C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\XQNeFQv.tmp fab903520f10e95c1f9d22e19680979e
- delete C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3558273304-2305715256-1486658336-1000\0f5007522459c86e95ffcc62f32308f1_47eed6b8-38a8-4d3b-9db3-44c44c24b1cd d898504a722bff1524134c6ab6a5eaa5
- delete C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3558273304-2305715256-1486658336-1000\0f5007522459c86e95ffcc62f32308f1_qszzabpjjijlkinripuhwzmgjcmvxyozmira d898504a722bff1524134c6ab6a5eaa5
- delete C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\45640C\C940AB.lck c4ca4238a0b923820dcc509a6f75849b
- delete C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3558273304-2305715256-1486658336-1000\0f5007522459c86e95ffcc62f32308f1_qszzabpjjijlkinripuhwzmgjcmvxyozmira d898504a722bff1524134c6ab6a5eaa5
- delete Unknown C:\gfidja\lgiwj.exe
- create C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\gfidja\aspr_keys.ini
- create C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\XQNeFQv.tmp fab903520f10e95c1f9d22e19680979e
- create C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3558273304-2305715256-1486658336-1000\0f5007522459c86e95ffcc62f32308f1_qszzabpjjijlkinripuhwzmgjcmvxyozmira d898504a722bff1524134c6ab6a5eaa5
- create C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3558273304-2305715256-1486658336-1000\0f5007522459c86e95ffcc62f32308f1_qszzabpjjijlkinripuhwzmgjcmvxyozmira d898504a722bff1524134c6ab6a5eaa5
- create C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\45640C\C940AB.lck c4ca4238a0b923820dcc509a6f75849b
- create C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3558273304-2305715256-1486658336-1000\0f5007522459c86e95ffcc62f32308f1_qszzabpjjijlkinripuhwzmgjcmvxyozmira d898504a722bff1524134c6ab6a5eaa5
- create C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\45640C\C940AB.exe 269d69a3e8c8d6cdb90f544fc04c1bd6 exe
- create C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3558273304-2305715256-1486658336-1000\0f5007522459c86e95ffcc62f32308f1_qszzabpjjijlkinripuhwzmgjcmvxyozmira d898504a722bff1524134c6ab6a5eaa5
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) \Device\Harddisk0\DR0
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\profiles.ini f48f4bcbcb832e99a8ffd3273ae602b6
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\bq1w4dgl.default\secmod.db 20dd08de675cf453305843ef4af6521e
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\bq1w4dgl.default\cert8.db a5ae49867124ac75f029a9a33af31bad
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\bq1w4dgl.default\key3.db 2a18ceff8578f65d40f7df934c582577
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\bq1w4dgl.default\nssckbi.dll
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\bq1w4dgl.default\signons.sqlite c5dd9d0688e0321ef18963e0a29456fa
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\bq1w4dgl.default\signons.sqlite-journal
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\bq1w4dgl.default\signons.sqlite-wal
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\bq1w4dgl.default\signons.sqlite c5dd9d0688e0321ef18963e0a29456fa
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\bq1w4dgl.default\signons.sqlite-journal
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\bq1w4dgl.default\signons.sqlite c5dd9d0688e0321ef18963e0a29456fa
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\bq1w4dgl.default\signons.sqlite-wal
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\bq1w4dgl.default\signons.sqlite c5dd9d0688e0321ef18963e0a29456fa
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\bq1w4dgl.default\logins.json
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\bq1w4dgl.default\signons.txt
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\bq1w4dgl.default\signons2.txt
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\bq1w4dgl.default\signons3.txt
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\profiles.ini f48f4bcbcb832e99a8ffd3273ae602b6
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Local\Comodo\Dragon\User Data\Default\Login Data
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Local\Comodo\Dragon\User Data\Default\Web Data
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Opera\Opera Next\data\User Data\Default\Login Data
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Opera\Opera Next\data\User Data\Default\Web Data
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Opera\Opera Next\data\Login Data
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Opera\Opera Next\data\Default\Login Data
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Opera Software\Opera Stable\User Data\Default\Login Data
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Opera Software\Opera Stable\User Data\Default\Web Data
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Opera Software\Opera Stable\Login Data 905076ed0c0f642b6853f1adf654f9a6
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Opera
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\.purple\accounts.xml
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Program Files\FTPShell\ftpshell.fsi
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Notepad++\plugins\config\NppFTP\NppFTP.xml
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Program Files\oZone3D\MyFTP\myftp.ini
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\FTPBox\profiles.conf
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Program Files\FTP Now\sites.xml
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Program Files\NexusFile\userdata\ftpsite.ini
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\NexusFile\ftpsite.ini
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\.config\fullsync\profiles.xml
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\FTPInfo\ServerList.xml
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\FTPInfo\ServerList.cfg
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Program Files\FileZilla\Filezilla.xml
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\FileZilla\filezilla.xml
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\FileZilla\recentservers.xml
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\FileZilla\sitemanager.xml
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Program Files\Staff-FTP\sites.ini
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Program Files\Fastream NETFile\My FTP Links
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Program Files\GoFTP\settings\Connections.txt
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Estsoft\ALFTP\ESTdb2.dat
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Program Files\DeluxeFTP\sites.xml
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Windows\wcx_ftp.ini
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\wcx_ftp.ini
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\wcx_ftp.ini
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\GHISLER\wcx_ftp.ini
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Program Files\FTPGetter\Profile\servers.xml
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\FTPGetter\servers.xml
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Local\INSoftware\NovaFTP\NovaFTP.db
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\NetDrive\NDSites.ini
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\NetDrive2\drives.dat
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\ProgramData\NetDrive2\drives.dat
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Windows\wcx_ftp.ini
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\wcx_ftp.ini
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\wcx_ftp.ini
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\GHISLER\wcx_ftp.ini
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Program Files\FreshWebmaster\FreshFTP\FtpSites.SMF
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\BitKinex\bitkinex.ds
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\FTP Now\sites.xml
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Program Files\Odin Secure FTP Expert\QFDefault.QFQ
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Program Files\Odin Secure FTP Expert\SiteInfo.QFP
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Pocomail\accounts.ini
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\Documents\Pocomail\accounts.ini
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Windows\32BitFtp.TMP
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Windows\32BitFtp.ini
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\FTP Navigator\Ftplist.txt
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Softwarenetz\Mailing\Daten\mailing.vdt
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Opera Mail\Opera Mail\wand.dat
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\Documents\yMail2\POP3.xml
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\Documents\yMail2\SMTP.xml
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\Documents\yMail2\Accounts.xml
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\Documents\yMail\ymail.ini
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\TrulyMail\Data\Settings\user.config
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\To-Do DeskList\tasks.db
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\stickies\rtf
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\NoteFly\notes
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Conceptworld\Notezilla\Notes8.db
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Microsoft\Sticky Notes\StickyNotes.snt
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\Documents\My RoboForm Data
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Microsoft\Credentials
- read C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Local\Microsoft\Credentials
- hide C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\45640C\C940AB.exe 269d69a3e8c8d6cdb90f544fc04c1bd6 exe
- hide C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\45640C
- write C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\XQNeFQv.tmp fab903520f10e95c1f9d22e19680979e
- write C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3558273304-2305715256-1486658336-1000\0f5007522459c86e95ffcc62f32308f1_47eed6b8-38a8-4d3b-9db3-44c44c24b1cd d898504a722bff1524134c6ab6a5eaa5
- write C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3558273304-2305715256-1486658336-1000\0f5007522459c86e95ffcc62f32308f1_qszzabpjjijlkinripuhwzmgjcmvxyozmira d898504a722bff1524134c6ab6a5eaa5
- write C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3558273304-2305715256-1486658336-1000\0f5007522459c86e95ffcc62f32308f1_qszzabpjjijlkinripuhwzmgjcmvxyozmira d898504a722bff1524134c6ab6a5eaa5
- write C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\45640C\C940AB.lck c4ca4238a0b923820dcc509a6f75849b
- write C:\gfidja\lgiwj.exe (v. 7.15.0.0) C:\Users\Admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3558273304-2305715256-1486658336-1000\0f5007522459c86e95ffcc62f32308f1_qszzabpjjijlkinripuhwzmgjcmvxyozmira d898504a722bff1524134c6ab6a5eaa5
Add Comment
Please, Sign In to add comment