Static | ZeroBOX

PE Compile Time

2022-05-18 10:19:45

PDB Path

RegistryH.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00092724 0x00092800 7.78049872995
.rsrc 0x00096000 0x00003c74 0x00003e00 7.69075249609
.reloc 0x0009a000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000960e8 0x00003832 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x0009991c 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00099930 0x00000344 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
3$sK
3$sK
c6sK
3$sK
3$sK
3$sK
3$sK
3$sK
3$sK
3$sK
3$sK
3$sK
3$sK
3$sK
t3sK
@bsK
@'sK
@BsK
> sK
,JsK
}JsK
`(sB
H(sB
Z?_d
_b`*
UUUU_
UUUU_
v4.0.30319
#Strings
RegistryH
ExtensionAttribute
System.Runtime.CompilerServices
System.Core
System
mscorlib
CompilationRelaxationsAttribute
Boolean
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
System.Reflection
String
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
RegistryH.exe
<Module>
Object
MulticastDelegate
System.Windows.Forms
Resources
TemporalToolkit.Properties
Settings
ApplicationSettingsBase
System.Configuration
<PrivateImplementationDetails>
__StaticArrayInitTypeSize=12
ValueType
__StaticArrayInitTypeSize=48
<Module>{78748693-E7CA-40FA-9BD9-E6D614AADEF6}
Attribute
<PrivateImplementationDetails>{3F97167B-A485-4C5A-8F63-7352193B54A0}
__StaticArrayInitTypeSize=256
__StaticArrayInitTypeSize=40
__StaticArrayInitTypeSize=30
__StaticArrayInitTypeSize=32
__StaticArrayInitTypeSize=16
__StaticArrayInitTypeSize=64
__StaticArrayInitTypeSize=18
MessageBox
DialogResult
Qk.o3.trA
Decimal
op_Implicit
op_Multiply
IntPtr
Invoke
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
ToString
value__
IContainer
System.ComponentModel
Button
TextBox
GroupBox
ComboBox
EventArgs
Convert
ToInt32
Control
set_Text
get_Text
get_Length
KeyPressEventArgs
get_KeyChar
IsNumber
ToUpper
ToLower
GetTypeFromHandle
RuntimeTypeHandle
GetValues
set_DataSource
IEnumerable`1
System.Collections.Generic
IEnumerator`1
GetEnumerator
Enumerable
System.Linq
get_Current
IEnumerator
System.Collections
MoveNext
IDisposable
Dispose
Concat
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
Func`2
OrderBy
IOrderedEnumerable`1
Select
StreamReader
System.IO
OpenText
get_EndOfStream
TextReader
ReadToEnd
System.Drawing
set_Size
set_Name
ResumeLayout
EventHandler
add_Click
set_TabIndex
ButtonBase
set_UseVisualStyleBackColor
set_Location
add_Load
set_TabStop
ControlCollection
get_Controls
ContainerControl
set_AutoScaleMode
AutoScaleMode
SuspendLayout
set_ClientSize
PerformLayout
KeyPressEventHandler
add_KeyPress
Single
set_AutoScaleDimensions
TextBoxBase
set_ReadOnly
set_StartPosition
FormStartPosition
set_Handled
ListControl
set_FormattingEnabled
.cctor
Contains
Replace
set_SelectedIndex
op_Equality
get_SelectedItem
ToDouble
Double
KeyEventArgs
get_KeyCode
set_AutoSize
get_Items
ObjectCollection
AddRange
KeyEventHandler
add_KeyDown
set_DropDownStyle
ComboBoxStyle
ListBox
set_MinimumSize
set_MaximumSize
BindingSource
ListView
ColumnHeader
ListViewItemCollection
ListViewItem
get_SelectedIndex
set_View
ISupportInitialize
BeginInit
ColumnHeaderCollection
Container
set_UseCompatibleStateImageBehavior
set_Width
set_DataMember
get_Columns
EndInit
MenuStrip
ToolStripMenuItem
MethodInfo
LateBinding
Microsoft.VisualBasic.CompilerServices
Microsoft.VisualBasic
LateCall
GetMethods
set_MdiParent
ResourceManager
System.Resources
Assembly
get_Chars
GetType
ToolStripItem
set_WindowState
FormWindowState
set_IsMdiContainer
ToolStripDropDownItem
get_DropDownItems
ToolStripItemCollection
ToolStrip
GetObject
set_MainMenuStrip
set_FullRowSelect
set_MultiSelect
Application
SetCompatibleTextRenderingDefault
EnableVisualStyles
CultureInfo
System.Globalization
get_Assembly
Bitmap
defaultInstance
get_Default
get_dbSheetConnectionString
SettingsBase
get_Item
Synchronized
Default
dbSheetConnectionString
DateTime
op_GreaterThan
op_LessThan
Nullable`1
get_Day
get_Value
ArgumentException
get_Year
get_Month
DaysInMonth
get_HasValue
DayOfWeek
get_DayOfWeek
get_Hour
Enumerator
List`1
TimeSpan
op_Subtraction
get_Days
get_Seconds
NotImplementedException
get_Hours
get_Minutes
get_Minute
ArgumentOutOfRangeException
op_BitwiseAnd
op_BitwiseOr
get_Ticks
MaxValue
get_Count
GetValueOrDefault
op_LessThanOrEqual
get_Second
AddDays
op_Division
op_Explicit
Ceiling
IsLeapYear
4636993D3E1DA4E9D6B8F87B79E8F7C6D018580D52661950EABC3845C5897A4D
D2562FC95AD9314C85BB8498C779AB53ACEA1F13840F5505500ED76DA160E1A3
Module
x1AGCC
typemdt
FieldInfo
MemberInfo
get_MetadataToken
ResolveMethod
MethodBase
GetFields
ResolveType
Delegate
CreateDelegate
SetValue
get_ManifestModule
Dictionary`2
SortedList
Hashtable
RSACryptoServiceProvider
System.Security.Cryptography
UInt32
set_UseMachineKeyStore
l1AGC5
UInt64
BitConverter
GetBytes
UInt16
SymmetricAlgorithm
AesCryptoServiceProvider
RijndaelManaged
Activator
CreateInstance
ObjectHandle
System.Runtime.Remoting
Unwrap
CryptoConfig
get_AllowOnlyFipsAlgorithms
MD5CryptoServiceProvider
HashAlgorithm
ComputeHash
Stream
TransformBlock
BinaryReader
get_BaseStream
set_Position
ReadUInt32
ParameterInfo
DynamicMethod
System.Reflection.Emit
ILGenerator
Monitor
System.Threading
GetManifestResourceStream
ReadBytes
MemoryStream
BindingFlags
get_Module
GetGenericArguments
get_IsStatic
get_FieldType
GetParameters
get_DeclaringType
get_IsValueType
MakeByRefType
get_ParameterType
get_ReturnType
GetILGenerator
OpCode
OpCodes
Ldarg_0
Ldarg_1
Ldarg_2
Ldarg_3
Ldarg_S
Tailcall
Callvirt
Exception
ICryptoTransform
CryptoStream
CryptoStreamMode
FromBase64String
Encoding
System.Text
get_Unicode
GetString
Marshal
GetMethod
get_Location
Exists
GetName
AssemblyName
get_CodeBase
GetProperty
PropertyInfo
GetValue
LoadLibrary
kernel32
GetProcAddress
GetDelegateForFunctionPointer
umLocehuEC
FileStream
FileMode
FileAccess
FileShare
ToArray
set_Key
set_IV
CreateDecryptor
Reverse
GetPublicKeyToken
CipherMode
set_Mode
FlushFinalBlock
CreateEncryptor
ToBase64String
classthis
nativeEntry
nativeSizeOfCode
KDikMXewCI
ReadInt32
hModule
lpName
lpType
lpAddress
dwSize
flAllocationType
flProtect
hProcess
lpBaseAddress
buffer
lpNumberOfBytesWritten
flNewProtect
lpflOldProtect
dwDesiredAccess
bInheritHandle
dwProcessId
s1AGCz
DeflateStream
System.IO.Compression
CompressionMode
GetManifestResourceNames
ResolveEventArgs
get_Name
AppDomain
get_CurrentDomain
ResolveEventHandler
add_ResourceResolve
kLjw4iIsCLsZtxc4lksN0j
CopyTo
IsLittleEndian
$$method0x6000317-1
$$method0x6000332-1
$$method0x6000332-2
$$method0x6000340-1
$$method0x6000340-2
$$method0x6000353-1
$$method0x6000395-1
$$method0x60005b3-1
CompilerGeneratedAttribute
DebuggerBrowsableAttribute
DebuggerBrowsableState
STAThreadAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
EditorBrowsableAttribute
EditorBrowsableState
ApplicationScopedSettingAttribute
SpecialSettingAttribute
SpecialSetting
DefaultSettingValueAttribute
UnmanagedFunctionPointerAttribute
CallingConvention
CharSet
FlagsAttribute
xVESZfZ8bej3FPWlfd.OlPbviMZ4RlmK2qdmP
dJeL0JdCq1HWfOuE6x.sD3pe9xmVYsMxv2c4n
WrapNonExceptionThrows
Core Toolkit
Chandler's
Chandler's 2022 (C)
$f1515ad9-4b12-4820-a79c-311d5e9f9c46
1.1.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.0.0.0
HProvider=Microsoft.Jet.OLEDB.4.0;Data Source=|DataDirectory|\dbSheet.mdb
PmQk.WK+Oh+bH`1[[System.Object, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]][]
SUsSystem.Runtime.InteropServices.CharSet, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
CharSet
uHHIX9&
v Jfw6
$ZIh/'
_!]|ha
]6ZI?
Rs!Qbb
028\'
JbzYFz)i
ik7?z.
xMWlRx
wsjanGc
]9&3Qf
Iw|9Qo
'518zy
I&_HSo
RAJUaD
,<&$)Wv
?2`~{7~
9X4,M
C6.Tpa
KXP>/ab
CXvg]
omn0A
^4I]WQS
IE[.<(
1L#w`d
H%6~}^
:vr#pp
HD)9%;%Z
^= ,cQ
,&Uil[
>L5HYW
/)Dxs7;,
IghNKD2n
?ApdYt
tFe[h:
=gKJ;G
e0rLKq
Xrm9[_5
gbFC|a
>IpWvm
0E1UubG
Y4!oIt
DrMxiq
+wKYT*kA
5%mo4Ml
YE;>9R
L2=e%&
):KFv/
y%XtX<
Bxy}v;"cE
&wr Q6
!+P9'G
IN 5Q!
Uo-B!dt!
Y}eKgHp
{}zNKD
)Dmyx,
dy/DTq_Q
at3gzl|9u
`D'3Rr
k=i4gSR!
dhXQ9%C
TYlonG
Z.f?c
>cFx>"
Fk;!(|
U/ODJV
3:D19M
WC]2fH
ADbq\R
.7DU&{I
{;5NTB
PNn+;H
A:X"v;
MFq!^R
_~uyj:
b#.Eup
J6vhpP
zb.u"-7R^x>s
./a`xF
&6ExKE
%wTM}i
^A/S@Tp
Ja[_"w
{F@^d?
f=HH>Q
|{QOQQ
VI%o&NXm
EMid;,
=XO,hLd
OU&A"4
"R~DFA
C'zbfz
;s%@Yw%
]tdm,{SR1
FLCeHC3
]2*?dM
ike2rS4
l";5ql
U?eZz\
~2)L6}
ba!C7Qz
?qf- c$
I-4N'PKm
#Uvjt7
g.A&9E
39_XpT
vV]^Rbk
E(W9*
CB{_%De
Q>VF?Z
z"dQ>B
<R@W"A
MW8V:uP
}H&jYY
80?}MO
x~e7L!
p3(]N8
D-MO:
F4V{@DV
pk_6{Ub
UbI_1>
Hb$(jt
x4HL@I
%GWF.
p=ke]
g$xCY#
;m;J8
-F<<0
#Cig2|
-FZfi)/
y,\$sHm
Y7w^Jy
9NWaEK
I\}K!#EB
CppA6i
w?W442{
33A4L5)l
G>}>QA
Z{u='I
eZzlI0
N6Ucgb
7 |xJ$P
7qhx$],
]d-$Xj>Q
=CI[AB
1L ^Nil
?&CG4e
bh-%M>
|8oc (
CX6/roc{
O`@i*o2
O] @t4
8(~/t_
J7WB H
`1N,0e%
4VnAH2!
^VbDpd
jAW<n?
Da~SuV~y6
`c@4sN
Yc:#<$
XtsCb>5
h->AU&
XCB&V,
&jR-(
g[4 8@
oU9cIJ
ENQ\\N
f&}@=:
qSqk)G4x
9] |VfO
*M3trH
rD?uJQ#
Gzz,YUj
HJ,BdP
'+*LU\L
3X0e-J
Ca!HF9/
O'U:f
=o_# <
)c'1 I\
Gywoh>n-(
8i56?g
yGMM)S
VuiN\-0
}6<I>s
t{b&[l
'0@\,J
UVTOed
q_G;i
ck MYO
.G#pt[
_@wPXX\g
uWJ*G["E
IS&UWe8i
12/rT@
=wD9O
>!LKupI
{fp;F^
gNq666A
vp6Xd6
4m C`X
>C@}N5
~0/&El
#2:D \iNo
3ze`0v
3Ktpg-D
$&_dug
,]c!if,
~]:"7Y|/
BYK+FR:
l>kL@nD$
]n0U=j)
Dy/U%S
R]|Q#e
u J;p%
f2CVx%A
g6GwwQ
au81kQ
eZ:>wv
99\!{[!$k
NV9fyx
wb4mO
gC5Lo`
|TaIFK
fC@\LU
#i_8U+
gD'vkX
95Ty>W
rsnp!"
6U1&|mD
%0@mg8
9UUV2h
?RO6CU
Y6-#jT0
L$RL $
Nl-&_)'
c@rdYk
U ^"r0
%em!-Y
*jc7Yq
h{vzX./g
Lq%<P}R
t~do$v
!hn*S+
FjC1xg!
]?+C=(up
<l[:})X=
L^>/ [j
lsGyyV0>
{9-}!Z:z
tF*a,&
zZx^=]v
=HOX.SP\T<
m[8}dA
HjB)MU?
AqRg xT
*wKu`g
5 `s*>w
r4?J9Y
}/saBM
&_GbJWqNZM
)y#~Jo!
4Z{!E$
B-*m6|1
E e[N
zkQ({D
"E,j/fE
F_(2J85$
PcaiK!,?T
XA<+8bS
[y0.o
zjTG)k
_Y ^l!
@ll.)i
!pW]8F`'aT
+~"q0.v
/q2?k[
lLn=myt
-&y8Y'b
d0tm*
*6vaR$6
DE~j8+
]([5ZI"
:J7.50!
1d+GCK
C3wTFK
gZ8O5*
6GI\,j
\cJ|X$m
EPO,d;
L4+..C
c-t5VW#}
wA\ b=]
RG\T-:N
2+4;J~
3SLEA-,=
2*m"Ab
Ff8'<y
20A;B]3
)J(Z$p_
f#;ohO
#sulNP
w,[)\bUh
7pVH(i]
"q;-C\_0
X97O["
f=Dq,5
^:~Dc'
H30c.$
~6dl<
2g_Q%va
a|q[*L
-&MDJQi
xh6s'<ay
3(qs_u
2sS)vM
SGir[f
P.,3k%
c&>w(/J
i(Ob^]
sz!Vlm?
!)@K!_
.e0rIi
bYzOvg&
zp>)"0
K,}b3
1phYFf`
\[/5akiR
!"!rtJ
*yTR7Ke
0rSxb=
GNQC&D
{N3 e
h5XH?UfX
|xm\X^
RR!@.`
lT\!t$
cv*\8y
/F$Pn>
X@aS~l
b#@{c&
)BqW6\
Xr O@.
%r},yx
.%fc"p
e5][N71K
Z$F5q5O
Z&pnuA
@_S6Ckd
,AmGEf
EX-aFD
@a@)g4
2iB3D?,
y<E/75#5c%
fqFtP;-
f3s#8|
gd*.rq6`
P)EX\_
8wRcQpGB
w`8Due
yVx R
N)A7d~}
}S%L:o)
eRQ0&#
ondW8N
ILFI"b
dui+v0T
wJ4eaV
[N>HH?
gQWr\
pv<SwW
[I9+X+[
)V@"vs
{?\X:O
uG}Nj
<yy|D/
#8amPF
[@@(yI
$ -2^5
lSzW4tz
0G.b\C%p
A#W0~d
OS5TWS]f
M>6Wc
<c?L?2
o0w^12k
<F^2zQ
0d>0x
N0>mbR4
=7M}8n
?h.]na
p|QPIsf:
*eCk)z
3Om u[
j:'<f!
5LV}Z
r&^x=k
G U(6,
w^^?MI
3!\]!`]
bxYw&Bx
+Ii^O aHi
QI,E.Pq
-D*i]:^
DU.wA^
&I5Hy9
lmTx[2
}B;bAW|
iu?=L@-
*:JM)\
^<r+dd
?;gm7+
!akxLz
x!VPeeN
@yT (i
N(z,SS!
~a7fp{
YX;&$}
?TX]3H
$VL[fNH
jD`Rqp
!Y5P!^++[
;Wd Zk
cq0WOIr
t3U?]|
[v;)fc
ko]oI}
y8S3+n
vr"[ h
}#uxCt
<P/%Jj
O-d5nHM
f)~k-`
lD"(@F
T1g&#d
bOC<ds
5$zk)bt
mZeXl9
/o7>yg
rLA*mx)
%z R3;ge
~]%iA-2
&V8^#?Zns
)RWU)z
85qJ=:A
-__`P2
3ee5tQ"
oLc7YP(
tAp&"[5'45
e'YSh*z
d4=*X3
\fE?RI
AR$=:F
jb-T!(
/9xn#|
ng3<kB
LP>-|mZ+;
`m3k/C
?)lDud>
$\MBA9
t0l(5]^
{"@|Yx
GO~+2C
}P'`u'W
7`]y-l
rLxD9I
u`#[`P
x32)1>g
S]}*zf
XoAT~4
}"(o)(
kE1RAu
.,"/V{
QXo.\?
mB}Z4y
9%f"-k
48YZp@
3h|-xd
S%lbsL
dWbQ<)=$
EcXpf/
^"^!]Mz
=\?n ;
l%)<'S
~|][I)
6FVpiyK
RZ*MJD
q8b:)#
kM"k9;
}=|u:cI
U?a@]#u
[BnZs[
&Y,]vVD
3lKWM,t
![5yWu
dt))*Hl
U /*C~
,3H&,u
@,v4Tx0
rWQVxd[HN
4kNjJ1
blP:#If%
HO%{LPD
><Z^yv
&?G*D2
(}pl-m
9f7*9~
=>%-p,|
l(IAHzF
ViM CEv
"AOE8I
'`)_$l
3`?;.
IaROEB
o,1&bV
rI^(.~"*
?PIX5l6
,?l#U:
bU%&K]
zdWpwR
v0mxR\
!th&Hb
2{Myo
-vc~Xw
O}8ZEaW
If^'zn
,ymqIsb
d:QRNk,x)
JOZ;Rc
=29!dF
$CRQWf
*fE`f(o
T{9pxfU
q]g:Fq0F
9]t]CM
3QT?lD
zN64dA
NqU{~j
'Jm8r!
U4:jq([9_
&~~>fc
AuF#K]
gZ4)m
l],}uSB*
oRTJ`j!Z
jO.}lvK1X
i,Ml`M'
Cmw 9r
BC%9`iJGb
lz[~ -gF
?1#>"y
!go dj
ryZcWwX
-GVO#R
*!70]{
`,o;Pee'
:g.{]6
.f?-?E
H|p[|5
6oSKlZr%
rHOr
UIj,BxM
N\4^6(U
?u^~9r
vK8(Fvp
@k)Y9^
2iN)}qG
#>/gr
vPWGlV
,w2Q0=FJ4L
F!t~S**Y8i
nt.[So
B9FLz:
j"9\)X3
Sg"kq%
boa]A1m
Ma)8dylc+
e([F[(tX
]#FGzbc4
"-tXiS
LKEbY7
Gqf:Tc
-x {SkT
|`8$1i
qAF#p
58C30u
Z/aGwIL
K>Op\Unedtxo
"t\;(a
#ryQ-# 9
$"h0|e
XBI+)n
&d0NX
R4Wsz}
#gHJ#r
G%, TF
VX+yY-
%W =jq
6qY@~7
."jSP{
-hF(rN\J
#M{k,t
VuUf;E
0:\+.<
iuolqC,E
u-(XrMV
\0)QTz
cic!#p
0^O[Cc
J{r=jGB
Z;;{P6P
)m0lrx
>RgEo$
fUsh5
.L!/R"F
r|n:gd
}?5vmf
~pP-[gP
R!.fSd
5 BZe#
,S45 LYam
drb|d
Ddm6At
l1rVgJ
FY0.Wk
hVzbgk
O3bdh<
"t#SQg
KUA3RM
.}*Y}C
[*/jxt#I
|2oPJd
<(L9>v
^lP}Kq
E96IG J$
`-[\k(
K17<Jt\CpT
7cW:i8{-
mxs>uP
B;Z;M5x
iutc]]
%~6r^
el5}QE
,9hz9dC
*i3bd+6>
A"^w""
uaMn,S
lB >C>
Su~Kv)
~0T]'XY
.g+X]'
dk<[.<
L<K:LpQ
44b9ZltY
0\jj}z
oz[|R;
Xz&~u%
?\@V]l]
=G> "CT
G2d q|w
}-Jd5XSk
mH+8i(,
Bt6YHC
1/+8,y
PL4`Eo
QRjZmD
)2ufJl
#74j,@_B
hE@D4a
lhHkOd3
tD`lw
Tuln7e
G\<<#
Nj[JD&3
0;==H`
Jxu %r
'I=%sJc
~N+Q^ Q
Q-E0{{
;4Nh"7
c#?z="w
=8B]-@{6
PUJ$rhR+
$`Ancz
x/fcMB
C?PUm0
f7cq>j~i
cmt.G
g-vW5<
p`c,8|
J8u%/X"
F_pD \
t^7d488|I"
/W42j@,
,Q%4Jj
FdwT*p
Qn2?2YG
%?9B #t
>X.0yo
](&o`Js
L/1zi3
Ct=$v
v".(+]
e}Ao4z
vqtM]N
GcDQ"jmEN
u3/~Bo87
q({X4(
`=/uJe^
[q96pZ
rn`8`6Jp?#0
j<<%_&
6)6)dW
y[YGbo
>Yn24wq
j'n/Tw
*&aJTE,
u\V-u\
b)}?`
x<[hmY
HOm\3Z&
vH)(u{
t|mNB1
?ZI!%v
!3|Mmi"
Kwunm;G@
s*Nl$+
hUn'gvs
wi[4y2k
mvG|Io
Jg@#}U]
4_;)PX
M$0VxC
I9VUR3
y}OMgT
)#d'%"
%u5wp6'
di];>.
iP(0v{K
o[<N&.
V?"O:p
!uL3eFt#
<e#?{B
iX>Wwz
+?bM?[
0o!b'@
A_jobOO86R
=4"efR
iW:5458&
_ujk'W
6<cTV7
^VBl>f
&71[Dw
{G6Z4|n
gh94c)
:h'nzj$
?RVD1O>
~ #0pv
2xUCB<D
2f&C~&J
1CDa>k
}!Z/_
Diyijb
j[5J{T
|ZjT^;
3I%aJ_\
'@fsqo
?U-?7H5
~P|N8s
~^;swR
L*$ICu
x~W*qf
y-:.u\4
P.Z@T3
3/LRe>
-MiiYS
hLK&>~
$qd<mU
e.m4C
Bve;m?D
:8X;2E
BiM0eD
B:b)l:)
O)ylND
8SIZ,v
+xPH)}F
'sFOzh
+Mg#P"
aMaKQZ
NWK-.5|x
D%t`t
.~s>'`
&hIP6-
9{rVJt
mh+ "t
wJyy;I
Qc33V3U
Fx!!C6x
wvV&'H
I(X(Eu
Opf7G(D
LpY0U0
ErKbVg
6Y\!99
4Ss&P%
Owwo-Z^
U$SI{1y
d/ChDk
?c['.5
lD)+ITJ
IT9[/I
}J,q/-
QKWsIh
"W'%n~
J"C%MP
>7";>}
Y/QdC20
q Dfj^
#3@O04m
+NTL53
ppE$Jv
|ljZ2<
^]Y"n
<(H.>w
[l$i|0i
~oUXQ.
*NT"!{L
$%P2_A
nywx+g%
91V'>M2(
Lg!i"/
HV7|"D
e&W39P
_d'=XDwx
M8eY;C
eFV)<g-
HZa3jGu
xS({V^_alRXcJ
V.;Uh*_Y
FU8G@Z:[PF1{
m?'I(?r
S!/MN++
b12V`z
GgT^T}
YOf&_L
3 {n<<
/I]C=r(
$eO] 6
s#*p:t
ZGyf2n
-o6r1m`
tIA T@
PsoOSv7
r;>mRT
[v7yEc
5Lw{)D[
wgaDhE4
NIRfhn M
RegistryH.pdb
_CorExeMain
mscoree.dll
,pZEz=
^WA&PtU
RKO=T'
EIITN6
s(H\E:W
gYnp7
%Egaui2
b`Ya<D]KFaOc
P&* y-5
P!:Dzm
H_cNjcE
H_sNh}y
~a&Us!
P>6\)q
zb9~~Az
/K<Fz]
$HPZU
9JIIJaYJaaJaiJaqJayJa
.[f.S|.KO.cf.{
.#@.;f.3f.+OI
8797<;>=?=@?A=B=C=D=E=F=G=H=I=J=K=L=ONPNRQSQTQUQVQWQXQ
TemporalToolkit.Properties.Resources
System.Core, Version=3.5.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
System.Security.Cryptography.AesCryptoServiceProvider
HIsn7wS3OFGOTlEkls.gbOeRpsoxVijt41DxG
{11111-22222-10009-11112}
dJeL0JdCq1HWfOuE6x.sD3pe9xmVYsMxv2c4n
{11111-22222-50001-00000}
GetDelegateForFunctionPointer
file:///
Location
ResourceA
Virtual
Write
Process
Memory
Protect
Process
Close
Handle
kernel
32.dll
{11111-22222-20001-00001}
{11111-22222-20001-00002}
{11111-22222-30001-00001}
{11111-22222-30001-00002}
{11111-22222-40001-00001}
{11111-22222-40001-00002}
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
Chandler's
FileDescription
Core Toolkit
FileVersion
1.1.0.0
InternalName
RegistryH.exe
LegalCopyright
Chandler's 2022 (C)
LegalTrademarks
OriginalFilename
RegistryH.exe
ProductName
Core Toolkit
ProductVersion
1.1.0.0
Assembly Version
1.1.0.0
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.MSIL.Noon.l!c
Elastic malicious (high confidence)
DrWeb Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!4C64CF8753A3
Cylance Unsafe
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.MSILHeracles.38451
K7GW Clean
Cybereason Clean
BitDefenderTheta Clean
VirIT Clean
Cyren W32/MSIL_Kryptik.HGQ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Kryptik.AFDJ
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Spy.MSIL.Noon.gen
Alibaba Trojan:Win32/runner.ali1000123
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Gen:Variant.MSILHeracles.38451
Rising Clean
Ad-Aware Gen:Variant.MSILHeracles.38451
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
FireEye Generic.mg.4c64cf8753a33ad0
Emsisoft Gen:Variant.MSILHeracles.38451 (B)
SentinelOne Static AI - Malicious PE
GData Win32.Trojan-Stealer.LokiBot.WBOR6I
Jiangmin Clean
Webroot Clean
Avira TR/Kryptik.gpfdn
MAX malware (ai score=99)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.MSILHeracles.D9633
ViRobot Clean
ZoneAlarm HEUR:Trojan-Spy.MSIL.Noon.gen
Microsoft Trojan:Win32/Pwsteal.Q!bit
AhnLab-V3 Trojan/Win.Injection.R492964
Acronis suspicious
VBA32 Clean
ALYac Clean
TACHYON Clean
Malwarebytes Spyware.RedLineStealer
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Win32.Outbreak
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/GenKryptik.FUMC!tr
AVG PWSX-gen [Trj]
Avast PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.