Static | ZeroBOX

PE Compile Time

2024-03-26 15:46:30

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00010e14 0x00011000 6.13951979375
.rsrc 0x00014000 0x000004ce 0x00000600 3.7268640929
.reloc 0x00016000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000140a0 0x00000244 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000142e4 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
3j%(H
v4.0.30319
#Strings
_Lambda$__10
jLSQVYEfI0lgOq6PlSGainuxXca3tSNyWGplOMPWQqISc1lIbfQpxmyMfU1UtdyqJEAhskvSe5nPWGPU8aZ9XV40
7yT9XdekTPZnn61dIrwxuJOvS7gTbt0ZXCWtCMp3P1z21VCKDN16nfE0
_Lambda$__11
7hmO2fzF7hxtnAwbjJqIYRHtKd2BIEXK7WJ3sAs61CZ7d9HZtIT5MM21
LvXHfYrDifj8Wm51
UptidpPLayW4v7qF5hkPYdMZWw2BaLCuhGAjE1
j5RMNZAOsr478pIgbhn7kcEJ62Z1rZOIw0qEO1
_Closure$__1
IEnumerable`1
ThreadSafeObjectProvider`1
List`1
gu66fwiVz1YluSf1VRwhx5ZuZM1q0VZyQuaGAHKbBRgWN5NrrarBQV7nJT70k6uFShoAFh1
AdFW9fpDe2AxpzcdQ0uuxxTDWdjLikTeH1bfgDktagXnD5r0NyiKYKOQsdFV1Ey1mnLwqi1
42EsDg3huM0v4LkbwXxECTtHm39JRlA6zkjAn1
jt6Yw0NscECDVmu1
i0Mz7ScihhbZq3gHwHlxiSil8lVDA3zRSKi0nDaPJQy7KD7yoXqkVJv1
Microsoft.Win32
UInt32
ReadInt32
ToInt32
ntbBZGH2fAONZ96Sy6KrbhvproFVHZ7sjFXzNb93otByiH6LBIGehQg1EnoI3QKM6qdmJ0nrrLS5XSbyyTU20S72
oIOEw1cTMtNJBvOwd4d183TRTCRJXMekwAW5Hx01CortzvL5r3s4eqe1nEzuvNeuvrYqYC2
uZRy9aGQjiCyH4L2
OQpUAqMjrfA0rtLfbTvf6RJpyo0oibIVHQ3OZ2
2VLh9CQIWtAdOYe3MEDKktNjADeNiwoto0SeK42NPYtojltbZQqCZ2Vo0KJTZ1Aj6gfQXZ2
_Closure$__2
Func`2
je20Tm8NLPEOyJa2
01VVN63CtHF7bDc2
0hyteeUn3EG9iQt2
ZXS2ru3I9kbs60I3
_Closure$__3
A8z0b1BQhvNIJceaxACDV1UeXnbeLXEMl15LIvFah7Dt6RLHQ2P4o8f3
UInt64
S4XBnBkIWAvVDZInnMM4U4pGCHL5amQsAV1eUpN2rxQF8WpOItjtPAA4
P47LKMRt5mG3ybMCfLyOtU67xHKk1dC2nZbX57XPd51pH7VnC13PBIC4
RyUdWiUkKx0DXNT1Lwh649TOpaWZuUXqmLu0SElC8s9kEfliesmDyeBlWyiUw4ZDCqqD3H4
m2ox3ZKssibSywLBxES3BMj7Ih7eHQ1d7adVD4eF7cdWa9CpucA1CcZ4
FPZBGb5tlpxawSb4
uvdkmIbkbatxAF8xlW1IhdQvruruLVfzRatPx7WdqcAFpLql1UJS7IlPWwInbeOtibGZIQFHL66Kc6RVIFOgmkw4
IVSccT7dh7QjevJP9t5VXqQA651GGM1Te0uqwbMQ9wPgjVxb2GXgnqRaeiXirFWNo3oR655
MMUZngWMgiREKD55
eywuDXkucwLmRtHhbhRJVZkQnJoSlws1P4xPIG7TXdAwL7kgR6kQqKI86wwCgdgZCBkH465
TDqrWvPjHI5IXWJ4ANJi4gtviuWsiW2l8uLZM5
ycuGvQqQkzB21FO5
XxJUpWSwTaYAgig2nimI6APeWnFCD3hjjwFsU5
eekvgqp41P6TX5W5
yZHFyBLoVYawM1t5
eKvFgMXTaiRrs8u5
jgklD2VkSBsTkay5
ZWkeLNECnZQXj2z5
QijdKV8VqLcPj21qHxtSEHCWGsRlsfJMh88IezhzF6c0tecYbqogBBAXXPxVJ4yIvYemij4u6kSFK4r6QD33IFz5
XyWRBOt4a29o4WVsIR8w9l2w6FDgsHtjuJbfI1ZkiuiCITUBdRfrzE26
DMbZyZshq5hYqWU6
UlLSkG67KKXbyHY6
l9lvZ40G23KOuJ4rOCHHXRqu0Pm7mxo6qttiMCyo4ETKwdf2eGkxdRrwYIQKupw6AK2BP9vFpztMNC5jcpAe3zZ6
BkjqldaiLeRr1qFcAxdF4bEWRuod5iQDbVp0q6
FwLZOGmauRgp2hr6
sePOXSlUQuRNpJGsbaSSGsifTJ6Bl2TrKnhWyn1xuV0w2xCnRWBrpy8iQvDCVF4hFOUzLs6
KqZjmtqHAuyphqUlFY7sR3J5E2icRwxd86cE37
KC65F9bpRwuGl6ZhE9Gz2w6Oqh9Asx3P11PJE7
LukurvKW7NggqkG7
KswcxZ9IDAxnkrG7
5YOiArdoc7ravxdpUxAS44xB4vTJlJljjdoVK7
W6sGGWS4zwWIYMe7
EFUq4L0JTAcq8Ze7
bEsMOhQRdsMlbTlXO3wPEy4LFF2Frk9McUi8ocuBsnZTXLfD4FJHNumKf4iJOeU5BIlxi9ayVyQn89PT8828pAg7
DJlshbhctPtd0Hk7
Ohdpjj9pa7MRPTs7
py6FfdsupNAUpdt7
nLyGi1hi6ti8mb7rX0GiDlHpye4GyAsNBIsq8oOGTXTEfSHPPl2m8nymTS4fPAGwuJiTYx7
1P1BSH0cw8KmdXPNUev77CB3zraNtnA3nMDQiI7khRpaeEKiJYgWoW553b8btRpca29IfV2678
get_UTF8
CTpihGRZ0CS6QHWWIg2X4L8MEQoYa6z62iYA2sHmwe4F1zVVTIxQg9I8
4kxT5lT8boH6w3fUkGgamAsId7prlmwqJB39U8
W0v64OZqnjTJ2kr8
PpdzIjxRVCWolhaQAYkZjAMTe8qDB0pXIPopOpwSvbdDfyl8Ntk5ABv8
S2vWyzlMr1UIpuYdl2AlG3RBEkKno74m4m9A0fZ8lYsRI7EO9LK4lAqkhBmdPaJMNwjbH9NG1aXwAu2CC8AAmcA9
PJBv04wOaeitQsMmksV8T2vxkwwboZOP4wC5C9
zKGOcXqlxSQy8r1954pk947POfkFguCUNLgKOLS29LfE1B4TItD2gTWyNFEWUHGtIm7jE2tvQ5S0RmaD3mTeMTE9
MBiJu50lqJ3fo4K9
CsdwAG8gMfap3t8jtvSo0EoYAZGxDo42tYtZwp5zOFzPy0WVi3qWRPHkAVeu3fjYfKENnN9
_Lambda$__9
Py4qYVmaXBqUIAe9
JF7w2Wr4uGHz7kNb9Rv9OwvBgLkLwez1gmrJWuPS8zX6kNrhuXmpc5s9
s7kOiqSAYLfGoUv9
C7xMLXchhDUt9Cw9
<Module>
5YGe0suWpeEzX53A
4JXYbW6xtHGHq7jX8X3o463b7JDRMAnKYdkkdCJyMxDPTdRTfPwVNiXP1p7yiapUbDCeCl5HXkQWyWOu1IBX0S4A
QXZb2B6j4qWlodc5AatRnKqtqtybQE3MHSoCMS8Aruou5zxo49C2yIZcJUYQ19ov0TjsaEA
5xbsQbA3jv8xBd75Wo0Ks6DqbF82An8ahxppsg3PvS05ysd25zipO9UA
jmBrDihOehxt2aoaNbqrRnbPOU8ftSxhL2aEwOtI6thQn2eCcfSsl9hPpcvhFD4WBVhW0VA
capGetDriverDescriptionA
DFKlWPSYsKFYW51yFFMi6FJKi1GuT8gyFU4jSanGpYHk0IeEIz5u5LoA
capCreateCaptureWindowA
3GkbZ1GpRA7cLd3B
SfAsJ02pG5Oj6c5oZA9o7UtNdYUgeHBKz1tPH6Bcisp47UGpKBrtP9GB
ihQz46NCvV8JMIQB
z7hybowHTLNWeKUB
j0TUJjqZsl6oqImID0PAlP4yM3dHGbyGpn9XQGZSc82t57MbIXqiqhXB
sHRrbhp886aqY4vp56ZpeoKPVp78KoBIj5gc0wnfdTW2xWBngckUswiB
lCo6dDw2JDZ5Vza0HsdIptPmu0amOqBHPnDmjcyM5EsD9elfiNTTey0na24FArUkM5badUC
LAe9Y0ptZ6U6QoXC
4I909AjumZxd6CYC
dSw8Pup2RLIypnw3f1lF3vIWPZPDKqPKmMJWlEPih4afrSbro721eA8YV28Ci58yc4e1XYjWLx6f4IFu8jb7mVYC
6SAWS6KNWSWWPvhC
qVflFPYyhpwidez4aKwveuVGlTTFtacJBXmgSDWZ2H0Rw5cWbp15eRb9dl5jTWaaDS9XEyC
B74BRhmQ295YFRyC
ES_SYSTEM_REQUIRED
ES_DISPLAY_REQUIRED
HzpzY71BQvVUE0mFBR0zpuFNJbuHGPi5zDoVGVZKZELbY5qMFJNe92TxAlNap06u5CcyihT61SOR8rtLGsNLgJND
vvxOasnFCXALlSfI6zvEseVC7SAFPwJrFTBIYnrZ9r4yGUV53XAUaf3sb6cIEJGZetUvr3v3PIsEok5rgEn7YlND
RvdDZWi76DG5gXdvNbfGCzKh9iLxNlR0lD1YmOEiotKMfcNWWbIuC5s6be27C3IJPMLJtw9qtB8NznTV9SK71NRD
kSojOL2YU17ogniqRBoaQqSdNkfYSiRBT3tKKcp2MwF8kToxfE7wELQV5qfmAPYYioQpV35WTD
LpJWMJw5rmx4wg5osybVY8IbUYoQVu62K5nfDTKqmhCQ2Vw6foOcvQlLPThWbwBkhZQayHPVUD
QL9RIcXKgNDrONhD
QFG21tMVVDOitO3ZF1XMOvJ2iRHNcUjs8Yiq1OwXZyq9GbtHr2XRLzqD
svfleYhbCyX1aj2FG8HnocLRYeR7Vi6zspIDwD
juswHxyNGpdg5lvqHChzieZdzbPtsmhJ5jCKFXwABAnKVYHmORHlsexD
vS4fxUcwmsDFjk9E
EXECUTION_STATE
v82nr7swgqHLSVcE
3oTvEXDIG4XRL5411vj3FgT8uxGyYLsnVoEFdaUjcM5BQk7I8MKQju1p7UcV6MsS3erftiE
bsyQf2M7wfQnZipE
bUQlU7jSo4ES7uqU0GWOBrAJJp1WUbLy8UjyKnDdP39CpzyNVVDY7KzE
8mwAQ3wHJYRt18CF
m0xqeFAPGpt57vwpo4w5hiV8E1znTLaaKwAIB7xgXdhaRuogwxbqC6EF
QyUcvGYzbRSIvfRF
Q2m3tj2uMw46e52AOoktz6SrOmwBG9VYAmLE0Z2OfdTL7o7i64ebTVhF
Uc58J8hLksShBZjRBHJSYiePXcWIsbTn0eiEtF
Q4FBxusK6jlemEGG
xymWHShYVrMHNn5QepEg6JoChYmSFF3x15KYDC8XKxEyi32Jc2HViDOG
Nb4nD1Eo5yRnqyaG
mjLPQMNVtJS1RrFQXnPdn85LP9jcs8l2h9PxfG
Ewg4gHrycxUVz2eJIFotugVtQSFBKdiK4pJcLwNQLBOLPfoD9R8IiM2h6TCk8UKF134P9gG
vRSoBv23boYLq9HqET7mXnlvOnjyP9HZARtot5acx0FKg36cHR5sSuLhqgxG9cbpYv66liG
xETcm5tFi7Bt7Xjus7CSzKUSVRKJT24VZqvJmDKwX9DR1zNatiZeZ1hG16WCG6mf5B1ihoG
FCTGCEs2SLDGWkT51COog9rclL0V8lL4Ue09B4kq5nBDb5RdCH8pyXWTadibbegh7xzI2ib4DH
dsNd7rZD8HzS7LFH
E1NE2zF6isqyitgwItP10HqtodGOVq85qIxQvLfSKiwNncGoB0H04YLH
kpGLH7kaU8M2j2EWWihntCGizfmhsqHEPFeoHWVMuco2TGlHhSCTOi5a5d6jqPIJYrhjuQ6AbSOV0VrJWwmDpGWH
m64ux6dLXqS8uSWH
0qVqKjyyGizhmBYH
xI6EQkyMF2e4iG8EZHGYGpjo785WvUx70WaXiGEG8ot182YqioOJyGRUaqPHmEM7CufgncH
Cf2VFU7tVjWkx6gH
UfzemwQ1SgSv61jH
Ehs3OjYnQpIaeAoH
RBuuQCa3wwhscN9VJgqlBe5h1UAjGlzHZBpKnlLOBCptxkpKHN4oJ1vH
0edWkQmHCLhacdeSdS4RkrHLDdJECVuQJ9mSnTNktsfIQmX6UNouwnzH
Xn8PLQ9HFzjuSp2I
CqPKGrphEs04myO8891G5BvP3p8nNCFvcZves4ct3kjKyN8S6eBOkb5I
get_ASCII
IVop3UMfiZukkeKI
AgfkZn91GyNShULI
BqM85VZsizHe3pIODWNpwrac8cv9Tu0AUJMPQI
7TxwRxGcpglhchBiDEH9eDk67HxTW5sMYywmMyG2mBMDcQL3cQEsejSI
O0AZ0DQxv7heqWyiPhDoDFZkS56Wl91jSY0lyltlikKOadbL9450mzLeRWzwBeP2ePzEXUI
vZ9cq9KGzcFezxWFHHxafYWygPWPUiGkTIYSVI
wR0SihcF29M1CCdI
2REqG7vPQLmbFGeI
DJd4mx0lLiIMwmkehuIOj6HoFY2sGjbMsTN9vI
b0enJMZRgkH9g8xI
YS6Ufod2xfWRNRzI
hxb3OTabfrGJoazI
R2xU8BdcuyL9Br6J
AegdQt8elIDmZWE0dSklJYHsgBFkF332qiaQxG2TCRyPphaazggckMMxJHZcTLW2I8S1xOW3TodPPvcZA6xE5I9J
7e0jn8rcB3h9LRNJ
pH8hYPvExyaHvpPJ
z988sBJv1cLttNLwgaO1CE7T7ocEFVcFYWscIQxNeYog5ePX6J9pbbcJ
Xhu6yhTnKHsjBnKbaF0ItuTKC9w7WRuURXT7290BSWgTae6G3eRxZJeYznfS5tiGj5L6fvVSXJJUCxEwZW3cQAzJ
STBMs9Wjnumz2JcJFbgKE77no9At1F9GQjCEGTnWLkCRTCGpAfG5qilJkS28UZiXFoOXUzJ
OztYwHg2FTIi2Oo81NILILnp4a7jhnAzTiUx5FQWJljLktpLIqnrunTwDU0CjBs1LOzVB1K
DyGbyRhn1qKNCs5K
bObZK05xm6XEQYCK
byicRuMl1o23CAZK
iShp9IPKqh3et90WhFWUyOdeoaiNbQGGNJ4iz33ol1yDUfpCgrpYAcmTTHa94jgj2aYfNeK
IK6ph9BBVQiLOvSGHwynEPEHMKlxZDIbKbiv2vklVtwv6wyO3h7OuLtK
cZ16cooD2v56Dgwt2fbGD6KlWaTuBZlDQLKTtMGfHhmfk1P3Mse1fxpRzX1JszZgk2n2JuK
THHKHv9zIKUFUhVjk36qzDeAQmSvzwWUBCmP97M2vCbYNkH0J9EyuZxK
qTGRkFCe3jk89SsDFRpfWiLvOxDEJWMo5J4Fg6weEQuahil1PtJpboKu97BnuwHVJ0S3XeNwr9mRxABSeAucFAzK
63d6rIJDivGTnFCL
YL9xnbWra4PzIsPmQJRKknzR7inlPv3OMXPgAcATl8hJGmv5qUDAqiDL
VtGUw5cJm1KgBTHPl8M9HLP76ZJOf0HGzdaTalY0A38WtLDw55o4R6kckude7IJI9jCdnGkpUHn5fQ1pOq1SHeIL
tAbjZthqgSzY0MvkTB3ntQQV73qpgI4o1Lajor65BgMlmC7Fe44IwtJL
LH1BpfZs4Q625z2ezcs3UHpSxRnojrQWBhpII4CR7paCNy6pEbeTGZBoIFLmMie9ZBfEH6OgSL
MK7ViKq9RaoZ0E5UnS7R1OuMuxc2vy2BIw2YoqELY9f5J6iv7eVsWKaL
jk5TudEWJOWCPB9C5UYivliScEYQ7WfoJkeT2AyOfBXQZUDiBASNXVOfbND9tMNUwKqtdhL
0kdaVVmGAxH7NiUCp4HWPpg4imJgdFAe7G8DOBuFtshZAI3MDqe7jqPIbPmQyw9vGUqvowtgAguWNOaduJRzCOiL
v3lOgnrqbCwpV0mL
RfsgxSh1vRvQOuIAU9qyzF9we4bPtM84BvgL4L8H3BM4W7gb8NiFJo4z5BE5CSHmTW0e8USxMDoeIBXsWnwwOwqL
dlrQNaKRpwyBPqrL
Ag3InwBYvTrpqRlojAMLiwfLuGjXX2AcYivUCJeDFzwP85jLEAWNAPnb7owYz3GH3azVoumKxL
n8prRQYItC9myRrYhb2TtGBzIQK9jwaDIMtHZKozrXB2Y8dgoYXpI8AM
mYqi9CbnBr5advLM
Gvco4p129uX0nk2uNXn3efCglcV5k3xM0G5e4a1kFJb2c9o0c10kzTtQEzKFbQvLLy1fpTM
mk9LYKdh4XV2LQdTX8UXGB25QQTGwPeGnMTH2h3uiOaYKs8YGANiQ3j6hKaw3HnHXdWWV29P4N
E5uGB17uTC5do0gyeQNxvjnrX391hq2abSDUNXw1irYj0LfJUPERbiMZP5Al2URRt0NLK6N
7CUgQc35j5sYb49N
LRMrrxSmBh2SURJN
4lVgiNqIGRhVqcRN
dPhv4zGjTUt9spSN
Rm5OUMUWYjitsuiJlyCPEwQYaDECcoJc3AFWrRIeb1mEDON6T4iMutSN
yeMxIJwk6vvZewaN
KxYTlLkK9Gsup4bBui4fIy4822nlGrMMTXwgmjT6ATgsRxH5pihH0445rmo0qND0cunf1ZLijN
ZTpGy5rKNZ7rQ4lN
rZhywsYh7fv9mjqN
Mi808DQGqa4gk8b41n83bsbdahYMM1AILLgPtN
KNfoCtWtmUSPuCFZ04TrwdjY68FNeFF0armq3sPLYxpyhA8kUm0HFixN
iDWkp7OTHeQhzM3O
LASTINPUTINFO
System.IO
Z77rGVmjmiFfpOKO
D67VZukdIjfeKvQKSIAgbtIZWWVLQRAC6Rpj3TrjiSthSegh156xHBSO
rFBi12CAEMujcTjKDhEsYcPcpw7vzOl21Y1ylBPL0yLomVyb9ozPBGfO
lF64wGDsQE6ykVqO
oRyar6rOPTJQcHsO
QRpjW32CmMPEKD3P
2HEzl2vSnqqnICTCN8kpruEUP0yhJRQY8dzIoEVEZ7quUK3IDGxviZjA7wnHZRLP3lGnisP
ujmeqjhKAHQEIovP
c0GCZB9T34CkHwJSRbpvGFPKb2cW5hoFx6mlxhDqyrQim9u5d5LR5f8vFMdsZc5mOlhGawP
SOjWATlMM5NjBF3Q
Ut836PARZycE7VLQ
vIQZ8guYyBf7szQQ
VpSrKmfxqe2lqCm558BFOrQT8gfbHqZscgEEm7wp0q0tlkw5hjYqkGXCCzjl2Kt1cqacWZx3SQ
C1sCb4J2FPvGv9XQ
3F4AIP2wL2blISv3mKtLML8qHoVdlY79Ue0LjTX2K8DZWPlE7gXkFJZQ
r74aMUapXDpx2Y0fh3pIjbpAn8jqcerOa401VMwQASqkVGP6DP4tu5cQ
7LYX4dsvkpmx2CvYQ7tIFJblAW6XkBbgDy9IrivO5GMAKl97HXLjF1BpXUfeV2HnPOSC8mYzjMulTO6iTcK3kfqQ
WzWhm50ZPvbog1Jhyydsa0wVm9QKCz0numEKFR
w9aMgH5As4DL5zB4LrplM9jdOm3dtmmjxp3SXfgILxUniNQA3pSGDlhgkI2xe3iFamUMaP84cceHWUdjPlxWadPR
59eOYmnBWZLjARcsUtptuhxHB65mwwUHuk9rrcQxx5RwKXHOWHXGiaZK9YJPXttGNX8OxRR
PZEI6gsE9DlarqqeXCtqjg8xEgrhzXMP3Cn552Cdbek0orciTsiW6a8D43XJqEWJmMqr4EWKXR
ai085eUZY3wW27nLhoJ8OCdDmq8dLP99G95J5DHKau0aSJf2L0VurkcR
ucpy4xNZb1TouLdR
UQvHI9n2EdiHuRGrLbneKwMSoqquInqETRMcTK1R4Q4c4opMpjEQ9d7rL5fGK8KXk9M6ygR
ppwCFd2n2Dpfxo9S
Y0CtHxT4MOadVNIS
ES_CONTINUOUS
o4VWBEHeeXlOe66u0BmV2tjqUbU26GIF6YjkCWTem8G93LE4TE3VGy3L2hUj1UqfqQPSCPkllel6UdxaYunhgVUS
QVY7Jnjdo5aSad5W4BLRHM83gapvooEg1GhAR2ghvrnV2Fp6zJiJ8vYS
GgTo72t3587gbJjTuMTrvEgF2vMbzFGGDm7deS
CEIKm2Uuhuqb8mjS
Ku7J1UPcx7AmdNoMyXSh7SO0jc6Lzz1JCiRwVfWxLQVIBibhMHN76xmS
n9OchqJRGwxFDnXbTKfupU4Gc2iDeiJfZteog5EbCN1G728SpeiIpQwS
i399c4WuCute1jmQ7SMmezOaYUn39Q4EBhXmFT
Jng8A8A3eHXQq5DaA4wYsb1iDRcM6ep0Ee7UR2bFg5aL2E5EzDOXvWaT
u5A6cp4JDnlpaImnuERbt0gV7Q4rftq2FkVLFA2TJok5P772biw5xguT
tT91e9bAIC4p2TDU
403ZHjDBIxzt6P7ptwH6rRXdr3lsXErOhTmbRGTO75wgUmNv5BmIL9YU
4G5T61psl6y4IFI0JjL8Npz45SRXyJKaR8dRWodNyDKDSZ1ECckr77eU
9XhQmJyUrNQVW1oU
VZuXFKcRBGZO2FuU
S67yUtMK8DwOy6zU
86yCPlYrqpOBWDB5Uqhkeqhb1LkGhFgXjxhxeSfNzUzgBrU0VnF4fRPFhAP2tL9fOROmFzU
s2Jntv3bGeOVYV9V
RBiVGfxtMzorw6HLmO39rRshbliRKwbOu7LjsgNEs2Cfc4WLzv0RACm7Fu73Tu3Hwdhh5kO5IV
OQkWwxBUdoeHWbJV
ZO6Zi7Kmi1j35KUaVA9NcLVt0HwiUgaBJmX9RZP3hDINFabCTdg1wg9biWFPUxhsEkVpyzv4PV
SBEF5idsUuxADMdV
ZCSlhJdkogvMxoxNvNjUweQ7xmWIiL62qcEQ8MGVJbChnL4ObrbQ6lqV
VqAyqCGe7MWIhwZtEOOQTKO9MH2huFzX3u2Mf1dMPGOnkMCArvQKRjrETOyCgH8reBJ3ZHW
GhnD6HWwvn02Lz8bMwsg4zoC1zbylnGJxTgkLrbpXM0Ux0FDYm9kH9PW
qdvP9XErFlITZoGvAK3trvURblp9yjpQzSlONfatjG1z6uAcFiJ2EIJUmFZW8iJzMnPRKUW
uffbZEYqoQWQ2kVW
CZmFoIhJhztkUpXW
DjDNlfDNiZkXyNjW
WpEhbuZGMFBvA2gzqe1qj37ZPzuetjAgUM9TdvPMvtXW38zqeroyb52biH7FswwwzvtoMyW
nX1twSzTt9RtBE1X
Z30GlcvOilmYsOBPKdcYmecGJHZ84IXPimfTcS2SrfdR0hqzCg1wVLt7SplvdCDVJiPlk2X
NrAUiQJUP9PihEJZYc2vrVB13wYfYtbEJbxC1Kzffzi9XAQ4hzSX2NCX
D2c8fa5V2ZqC4gEX
lB2Db9vr9dbf2CbRGwbjz0ba4nevErHysnyH7xLj8iFpXNArj5dz1sOLsI6xDSJ742yfrNLKyrX7chLFESOAVXFX
o40nYpYfKEl1c5JX
oDQxaB7hAXLMTTeR5yOvcSk6K3Kf4Hx5OULKKX
qvK0Q5DeZKFcRzkwM3mXwk49qePPR6wYJBXLTX
KA9CkAipJECIIBmX
alXO4pefrqyzYxyX
ZYvZslTFPZ5vcL7Y
z8R11FYOA3i5lgQY
oDaiXKIe1BSJwz0mjqklGClM6TTEgl8crHYqfPk8F4N6Z8e7Cs7MCFkY
TXOcxS4pSd7NPOseeGKrDoxzmifu0vCus60tLRTlVb87iYN42ezzdLuY
Ik3J5lxlDKau6exY
RCUlpISSe7ctQeijfIMp8F8aaThJz6jpAIR8u9f8qjmGWs2WOUSsYd1Z
2xdYML6QfUO5cl8Z
eouUvo91O0onmmaZ
EgHdvstcxv8OEj70FjgsiQjVVaszHXMWGpftttt328bhkw3JoWkO0waZ
cxKKBX8Thp2UHOgcqgTX4HJK1bbmJKOU760pPzv3sRMmJvmgmqhTbNdZ
7eyvJyjzbd1ayyYqxpoIhsqe0DmxpyZRBio5yPJUxYL1HKuGcY5VJgdZ
QzoUJqiZ4isLkB6ssfFP6djMY3dbmuezyy3j8nUUp79HNBETp3fhygnZ
czU3Cvct6RsedFqZ
t6e0M9xZmjLtY6ytddGwTbUEwoJaE9iSOKCp0GPkH4MGKERoThmLRtm0UMuCL0Dg0As70tZ
DDtZUYrAc1aupFuZ
mi8MQ5SZMyz5r6wZ
Dispose__Instance__
Create__Instance__
value__
ZGbxOdXLx2eDcpvMoykgvSacPZ4b8Ds4BsdHJugkrKop8B0WKWtiqG4a
hvQ0I5uj0HRRfR6a
z1GxAKr6NAvucb79x2qzDTB1KsLGVrzG9my5RENIRMigrQSDnFCzg2Ba
sgfyGDXS2590biRa
ProjectData
GpTOiPavuuodRxctdftmimdDlb7LqBbuhkDyCb
SwbKlLI3TJwXDyDb
XTzB5w0k9P0Ov6YlRgLjytaXHOStTSDXe264lGzNZid7jPeVHx7aRftwMnuP1SJQm3cD3Kb
mRl4N5WSv4wIOuGoOQMUJMIfZeFYG2fRkDpHKb
RYdx5sWZgGYv60Lb
EZ1aN3vZdcI1PJihwkoDhPcFmX9ImPnoZaG5xI7HcXUvwWp3IaX8v0UBs2sQxfbMlixLBpbBLb
g6GQJi1lll2DqUZAZX6bcLI9npg1so390kVsBbkFu15jj8dmAqQOJeILKsgDFgiutqlhVMb
t9B3eVWire03KbRC2qgj98MgcHGNSF8bAHzLPb
7yac1RT6pMzokdIcTczfpv90dy4DStsmYLoHVsKP9nebOok355h4NDL4fEKc7ceU60VuMgmZuDlZoT8IQpJvtTTb
bDen6JxfwIMO0Evn056C3nDKclEVzj3M8X9rPkvNDnp0cREFjzOvhsOAc0KanPSjxRJsLcb
mscorlib
NFr5OyyJWfFcleMCLfp1K1BOW0sEWqv4Lft59Ky1yaFxjj9EDiDfOVrb
AJGTASu6RF38yo9c
WL8Ibn2ZqenlU2LE4XbPrXVhzE04fAtDQbnJEGCnVUqUpAWC2utnuujmZwB8C2V0LQK5lCc
System.Collections.Generic
Microsoft.VisualBasic
iWzi8BA51P7Ylb2fNspe0XR7ZPXDFNvkU8hKmc
70hPeiA1W77PDMqAIcqOfg1y2HOy4bXq2eWVuI8qSMEdD3upKv09Zhoc
WndProc
LowLevelKeyboardProc
5uk6nFI4TaGb2LPeqTrZDDNBZLF19acWlKn5E6ESy437NhdN3uNzMviHDVWUowUWEXxfYwx5uDQZSilsLMkxvuoc
chEBvYw711yS4dpc
ULO1Dk0bWwys4aZbMWTdQVVbojy9z4pqAWGEyc
NHT5gfvydVhEPI3d
zqwAOb6csStISU4d
nZ40RlUvmhvbOvHd
GetWindowThreadProcessId
GetProcessById
YpTgdAoGr2vyZOPqMdm1Q2x4Y16LVjBVy5KcYd
Thread
RijndaelManaged
get_Elapsed
hWndChild
EndSend
BeginSend
Append
RegistryValueKind
set_Method
CompareMethod
TargetMethod
QiNEozaGVM1JUkqUW6q8SUnIyzsFSOcFJ6FyWGfqlWByEKXayqBc9ood
wrKEjwj4I5XxWLrd
currentClipboard
BFVdGPzymOa1U1HT72mz9O5d5eiwtmBJUdmVLTLtaoJtWwMp3SBauhLnGeVE7j7P8cjJ0EN8td
jH5khingY6D7eGwd
KMAsFFK8HasGmcyd
DH0KsU7s9SJ8GBqt9tEQuoVXgXWbEbZMJ8O8Ge
P0ZMMHVYNvTb6SLe
Replace
IsNullOrWhiteSpace
CreateInstance
get_GetInstance
instance
GetHashCode
set_Mode
FileMode
EnterDebugMode
CompressionMode
CipherMode
SelectMode
FromImage
DrawImage
get_Message
UwTcVIKr22sVbGiYojVw5f5LEWC6pcRUCYFcge
EndInvoke
BeginInvoke
Enumerable
IDisposable
Double
get_Handle
GetModuleHandle
RuntimeTypeHandle
GetTypeFromHandle
EventWaitHandle
Rectangle
DownloadFile
IsInRole
WindowsBuiltInRole
get_MainWindowTitle
get_MainModule
ProcessModule
AppWinStyle
set_WindowStyle
ProcessWindowStyle
j83cA22xFaB6PNme
get_Name
get_FileName
set_FileName
GetTempFileName
GetFileName
get_ModuleName
get_MachineName
get_OSFullName
get_FullName
get_UserName
get_ProcessName
CheckHostName
DateTime
get_LastWriteTime
dwTime
WaitOne
WriteLine
get_NewLine
Combine
ChangeType
UriHostNameType
CheckForSyncLockOnValueType
SecurityProtocolType
GetType
SocketType
System.Core
MethodBase
ApplicationBase
HttpWebResponse
GetResponse
Dispose
QeIqsALZIvyIW6HcqvHsoI4HY8A2m252z6PDkKAveb8BRx4aVjTDk7te
Create
MulticastDelegate
DelegateAsyncState
GetKeyboardState
EditorBrowsableState
SetThreadExecutionState
SetApartmentState
GetKeyState
Delete
ThreadStaticAttribute
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
StandardModuleAttribute
HideModuleNameAttribute
DebuggerStepThroughAttribute
AssemblyTrademarkAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
MyGroupCollectionAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
DebuggerDisplayAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
WriteByte
m_ThreadStaticValue
DeleteValue
$VB$Local_ReturnValue
GetObjectValue
GetValue
SetValue
set_Expect100Continue
EndReceive
BeginReceive
Remove
XClient.exe
93iLQ0C0eYXOpybNxqmyCX65F3lQHH9GtKihsueCg3sBGvkAKZHEpnxe
cbSize
get_TotalSize
set_SendBufferSize
set_ReceiveBufferSize
dtWvwzLRTmJNQksiLoNIoZpN552ZZIqWM9gg73vG5QiGsgNmiBZNDPjCbQKP4DR3smUgY5f
b6EG3rvxe89Db27f
PVJOmCDj3I8AqZawjQGFQqGM0NuRgmh7Z6ctCUd6h1MJPQ2McpJFMiAf
bx9DZylCoHW4nuGf
SizeOf
c3MLYERaZuFgcelJJlAeYm9N3oWyZl6GzKz9mHl0KWm3Z5OnAR165rEy41ahNnOnTZKYURf
DNbvbZ8I1NsqSUzI08EtQodwxj8HzH5piH6orJBFFMFL8P9Ki2vFgoRf
SAUliUF0VoQOaCoh3y6jIQnsFFA7Gas66hfWBnHZs0B63pjZwEIPvGRGhi2C7TsktrRHcaf
mSt68kZM4ccj2MlizbmgkmX9ukvXXeMaw2Da585qgH5sALlSC09cvUdf
hdSAP9xKrqthXhpf
qaSGsOWc9hHjAUlZyzXIcsjdVHeBTp8cvanjbaLu4jK9hexLtCIm5CtS4dUpkDX5Np3uWo3vwa552vfxKuLWkcsf
Pe7k0nBGV7A6spsf
fUToKvlci1DPxC10QipDE4UmEN5gbgISRLTyJaxoRzSvCad0U2C4I3Mg
8GTkxzxMhOKTtTOg
4xbjBEdkfyn8JLRg
0PRN1CiodlhR3CUg
cn31MaSAiXNbbEWg
O39kCnPjl95ApkqVwCtmvPDPhr5G95JZ6hvHygoeDHjKQg17R6nS3ZXg
cUKYc5reK42W6ScKuWNiW74t2gW4kN2Zq8j3lD9rqlgd8LS71Rua47dg
get_Jpeg
5VpZPAKUHAub2gkg
System.Threading
add_SessionEnding
NewLateBinding
Encoding
System.Drawing.Imaging
FromBase64String
ToBase64String
CompareString
ToString
GetString
Substring
System.Drawing
ToLong
set_ErrorDialog
cyFe8bogX5tTeI620v2HldYKuHM1A46fMF8A6pICOV2uCL0xNsuzOKpg
get_Msg
adXZbWqCnsr6Qwvg
JheqX3hyw4dcKIjHcziG0OAqyASgv0VxyJkJEdOtr0UlwgR7udcemamaI9k6pd6yOEOVgUY3FMzUAbgxO22emGIh
2WPBcvJy94jTftIh
4tvUeI30Z8CuUqoHxbMfKm934IYyBWhMw4AWCeEDDB9TzWYaDnDqjcvgaxXi1m1MNo2YkLh
p2If3QqiVWZFePm3P512o1vkt6OpKI0ZGtNOSh
CS6yvcTg0HE2Onch
Stopwatch
BqbB5LbMuzvIHcfh
uV0PsrNiyVbUChGLPWl7H86cLHXejELsFMjnAO7rrceG6o6gmQORBVVw2elBl21yaTu7sfh
nlmGvWLoBGamspih
8oxDumYdTyCdvbgOWM38OHkaZghdqLz83bACjh
ComputeHash
get_ExecutablePath
GetTempPath
get_StartupPath
GetFolderPath
get_Width
get_Length
EndsWith
StartsWith
fnoLdyrMzf0yQt69WrbmJRcbluM3xqxfXN7xhhVXCdSh6rHZexb5106w7bKzluem3hTwBC1TLfak5XVNH9lg7u6i
4Qdt5zUpqGBXavAi
rZBLLgIpkEanJPBi
lQEQPqd00OIsXdBmyDAlMESrqv2UqjhfkbdNINJVa9ubTvXghVuxSF6rSJaEafVQDjU2CKi
xmDXDKsKnJrTbq6wW4MchjzCqKtuMRIEaqcoVvaV7Bd8geUyb0IChCaIQeP4lJFyNOejLsPxOjo2BNJA48tPDKMi
yjdzyvMuSne0TlHeQC8JOej5xq0caOJjPVbadtOiyNgheA6xxFBVgNXP1EJ82RH8uorDqii
2r5jgI0gh2eOyxthTrGO5Yxsechrcs3DY77CH2Juztx1qW1xSg0UmCiX3Z7SaxQFotlSgji
mvkSfjvuuZZbYQli
SXrE1cv60SniZkmi
JOWta3No420ma0si
F3Ve5cCiFCal6gRwndG6uSYk6xjAEis7K3IDJ4jNg4xMzwGo2qth4DuboqAn30BqxIvp4LFJFbHgXyNERuhZgkwi
aCzWasuKZeEq2BfOdU6rHbGd9qH0LJj8r3vFLn9htLLVshbm68ulqt7j
5c7nVyCgQljseERAESAwxz69hRIMNvADV0rEvmMDar4RRx3OBNZFdQa4IHc9TNa2mVEM8Bj
qjV7bzzy38EjePKNPUbWWLKF77hqHSfOuUilMEs3LPmPlT4HmU63HdxIGrxdEuHFL1d81Fj
U6gwZVDMlWCY2LrL8EQSbJzL70ibfAnCgeRCt0lEexmIuj83gxaSsv24CrQwaYqS7UNTDPj
IH6Ev0sSD2u1A6Vj
D8nI5XMwpwNicsnlS1XFSk2ELptYTCSDBGnjWj
sBJgLSdkZZuwSMZj
GfFAob7smDdRGYTL0IM9G9Efw0UEh3sOtUuROxFpj60Xf8dCRVOBpYqj
MlybbnfTLsunXmwiDOoCxu2gTSml9CPYMzNdNjaNST9tjjlPJVV0o4X4XnaHHuwAp9Pz34k
3KuHy5M3olITvYlvfRLf5muy6SBKhYAzxiNGjKSUpLREARZTTwqEpyCLeqI2nDYCC8MuFFk
g2rJivUxCpJzSkKk
suhl7mBeJuWNieFsnBMOo888LI0ypkHJ9TNYSiCx3snDnGj68BvITnWVk7zZgbv4ShcO4JLfv7fIwAcQ1gYctaOk
get_ServicePack
AsyncCallback
DelegateCallback
TimerCallback
RegistryKeyPermissionCheck
TransformFinalBlock
jym7bkTiyA0wcygk
zCT8AUlpQCpUtXwPGSzqkAOSyEVPcOWAXWuwUDboazmGlmLnjJ7pNnpk
1SFCaia4OknNtHvk
GXJRKBPQdi0GaPZ5aetDTiTOo2DGolE96sWwyk
hiswZuEznhlYMB1l
lJZXGFOc4ANj1h2l
rExX6KyRFxopdnkPWEYXNSzKvhfa0Nxwnm62WMaMynlPzDRaFbipaXxyLztqzU4c76pf78l
JHxJwTBw3iqkYBEl
WNNPjVcB9y46LDqc0lsAxLYTrmaomH7kvyhtktKOYV4R812DJCaje1xsmEiZnYMnF5vvjEl
xMjip6VZTFakXmFl
MgghoeGCQlm2RDJw8r5iSIaFDfsXvRy2GAgTk99naL9WUztlK0Srm0VqWK24uWK50pzE2Il
RiAKca2Csw9mMar6LaiYzy2Guav0OLiTiiXN5Ty4SeOMtqgyg9Oe9uiqbKJhnuO4df3ejf7e27qnr5DaQYXQp0Ml
5lHOr5WMUefPfSDdRgEtxpaF5CYwSXcBoDKOxJ7ZHJMD8TuWQV1SSFLBCThtDvIwASsg6dIIO3V4diX1e1ZSLASl
TBDwEdOLIIbRnBYN7pEM84ghufgpeE79xBQzTl
ef8YBtd82CoKi8oY2sICwNs21MJrWhKgvMmDF4ebyKwOXhaSSMOoCIVl
r9qYf8SfNW7xJlWl
RtlSetProcessIsCritical
Marshal
System.Security.Principal
WindowsPrincipal
ConditionalCompareObjectEqual
QhIoJiVVc0hxSSCglNwe8IgCmZVbX5IlHuknBkfLJiuNGTQW4PK8hFvzfq3mTj7Ktt1Fcel
System.ComponentModel
5GKtOvWngDMCPmhl
LateCall
kernel32.dll
avicap32.dll
user32.dll
SHCore.dll
NTdll.dll
set_SecurityProtocol
ObjectFlowControl
pMKdHOzFSDWP6PUTfZKJcmp3HiUJfnajCT4C7pNVnX3fud1PdIyRnrzAC1Alcd1Kd1qSaVBpJZ6gEWXp9etyZ34m
hPrLjYhFQOqKbdNWa31xBHYPR6Sa8s7raNZPwEnO5wY2vWrukGFRsozeyQdepRFNRABke6m
W8DwhzN6NSBRr8Em
Xqw4ZVDeVGHELatTsP4FMkqn8mXxvdPdRbT2Qm
t4hCRu7XnBrpBUzwXI9wykvAJMQOkgAk5iNoLbkFCSDoArjU1rOJo2nWUrVwPnzEVoLd94OkpG26qpBcYKVFIFam
FileStream
GZipStream
MemoryStream
lParam
wParam
VpZNnMyS27a8wicm
get_Item
get_Is64BitOperatingSystem
xMhP85jg4jEF7Ygm
RuO6mthHRrpfpcgm
SymmetricAlgorithm
HashAlgorithm
upPlIogVYPmM5zGkIfClKC9r68XV4RSICBKTpz7M5aKcnqw4Pcigrbkm
aj8P1ygqOZJnmglm
Random
NotificationForm
ICryptoTransform
VbkYK2rUKSMw7Csm
iLBddT3Dd8C9sFxQOqiEWQ6w1DpOi1wShgLBMl0BaccwQQBTfVAIvKsm
ngihNVRqKUxhVa1DMqAJuZzuf3QfLqGTMl4UXzQMb4IC1bCOSy4UAyzm
HIAf0PRgdnwSrkOn
ALdBi1nGphND3SA07KGYk9ypALK37pnvcyKw3dwUlH3f2vBvgypbhbqnz3nK6HoHaeBjrVn
ToBoolean
op_GreaterThan
TimeSpan
CopyFromScreen
get_PrimaryScreen
dLvrfuIkRwz62ofn
System.ComponentModel.Design
AppDomain
get_CurrentDomain
GetFileNameWithoutExtension
get_OSVersion
Conversion
System.IO.Compression
Application
CopyPixelOperation
Interaction
System.Reflection
ManagementObjectCollection
Exception
Environ
pattern
cZ6rcsdvNThQ6UR4LaDErLm7gV53xxxfLEsUODgp5WsWm8GNCxs4b0bV2Bxd3ZAaYcNo0SDns3BOmSj18QUyqasn
5ZsXwr2Cb9MOSrGlTnO1ThXKK9xc1UUp482nsn
E1myfi3FgcGdYztn
SocketShutdown
cMSPOuFP66ZMZAOo
bG4J0cq3IrEBTCbo
GDFyw6Ff8yNLDXo7nQMrMJVqs3wEb521v50cdupwfN4Q5v7GriMDjp3O4jrfagdgd11fSbo
get_Info
MethodInfo
FileInfo
DriveInfo
FileSystemInfo
MemberInfo
ParameterInfo
ComputerInfo
ProcessStartInfo
GetLastInputInfo
DirectoryInfo
SIUWyyST6JtsG1BZij0Ow57r8m3YhFxM31sFoo
pcyjLbXADTBMr6xcZtDEsCb6Pb1MhxB8TCC5xzjZ2iFHBkzLd0m0R3aQEe7JlydiG4AMnwcIIPmQAEX3orBn288p
JSft0IESAiYxg74RbTLrMThwvhg532VkdNAcEje0QsbJMjPh51sz5qPp
xj1J2BYLsVELoiUp
K9RTZTAOC6g9rwVp
RgAiW2CXJzMNpiLoamGF8bjZRo09sO40d19IXp
Bitmap
QBAIiBZulnkXLyYecmTfuJtHdK9nrAFbbaU0OWaPnI3VHlFZR90TR9fp
kDk8wzTGDkG5ablp
intpreclp
x1kYLCbGo624En1L8vc2gfmt8K0KP0eVUUPzN5NtXkQvm3LsNJgKwrFzsDJToDruOvrZGtp
yelShkntlDvaZijKHrjpLCiDVaJNTCFvV2xCKT3Z17XW2Sp43hZZDFi865V0VC32PNWmKxp
4iZ8N1ILsp8EyZcQHaK44qOyVtVX7Izmuov8Mq
IrndlX4PIheKYszYDdGz2HYL0M5EDflPFZWnNVAM7yIC1WZoewCcC0mq
System.Linq
1DFzpSQEsMduOtqq
iAtOVXUEmnZtSUpjsepKgDHS0PNt8vxEtD6QvlS7ZBhWT0Y3Jz6GeGyLf5h47sLEeY6R5bctBFNmCx126iAASDvq
jBz3Lqm7YtjAYtUSkE9U33WmEmfjNXwQS5gQKEgjX2A9jIZ79t1y4vXpn2J3AYcMl3UHJ10AsVNT5cQtBQKkAgwq
51xwEIUfR1nu7H8r
mheYsrajeWtIpNBr
qpGUGjmGMES3u8pFo0DOUmmY1BATr9wl0AbinONF5HftmDmi0mxyjyCr
slXa00QozcS6QNDr
8iqQjbu0rxT2iILFv2tDuiVAWntal38pVgmQwMjgwOzDcTC1T9XzH1br
MD5CryptoServiceProvider
StringBuilder
SpecialFolder
ServicePointManager
ToUInteger
ToInteger
ManagementObjectSearcher
SessionEndingEventHandler
System.CodeDom.Compiler
AddClipboardFormatListener
ToUpper
get_CurrentUser
StreamWriter
TextWriter
BitConverter
ServerComputer
ToLower
KptB17qVr1vxs0MsLpF6Ukr8TT2d7An9fqaKoj0oYU0A0boMnRCyUK5KWPPuc3envtjCJlr
aSs3VSGcQ2r4xrE96p1vFkupVLaH2OW7FQcblheGeNOfh286l3YQAelr
lQt5JWA9smV2JeYeKIHyBuKWIjF0v1am6AGzSCBLJuwgYeujvS1vUror
ClearProjectError
SetProjectError
ManagementObjectEnumerator
GetEnumerator
Activator
.cctor
Monitor
CreateDecryptor
CreateEncryptor
IntPtr
U95xwMk5FjdRxz0s
EvXkcuqKutnvpo0RhcVV0UnYv4omvqJ0i5USO4k9kdfrfHmZXc0eLaKeGtEKEQfxpIqjqsjRSMTwoEF3SPCz724s
0eT7oOe9RcwwgLgWBwjnz6INryNzHIMRv1Si5HnUrUBEw5bYddmAuXRaIpnppjFav1xhoBdFAs
HUF7QPggtFJNJHr9EUexkZwqGM4JDBYRT7cbQNeQjA5gut4ZryFVmrbHKdvlarGEhP3FIiS41gjHaj739idjxtEs
EZQpfcf4Dp1juqVs
Graphics
System.Diagnostics
FromSeconds
get_Bounds
NativeMethods
GetMethods
Microsoft.VisualBasic.Devices
MyWebServices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
Microsoft.VisualBasic.MyServices
ExpandEnvironmentVariables
GetTypes
GetProcesses
GetHostAddresses
ReadAllBytes
WriteAllBytes
GetBytes
EVf9pLGHpaw5ETfs
SocketFlags
Strings
SessionEndingEventArgs
Equals
get_CreateParams
System.Windows.Forms
Contains
Conversions
System.Text.RegularExpressions
qMiqkryUFhLx69rs
get_Chars
RuntimeHelpers
GetParameters
Operators
get_Success
GetCurrentProcess
SetProcessDpiAwareness
IPAddress
System.Net.Sockets
set_Arguments
SystemEvents
Exists
2JNs6EA2rX8mwoQ5uOVko0RRmWcIW4YNFFlMQEYsJC6nn6VYCOEKWwx3iKV39uAkUu008nIT8pxum1iWKUydR0xs
Se2nIfsR8HTVjRIkGaEOOCQk4dIuaOCHeGXphOue37r24RvqNMzIMM0zS4336HL8wqIY07HLHpfkgidOgfDulM7t
F4ZPWhU5twiPt67U4cEP4kH4Q5shFylPB7OWJStth75Yn3JoMwuuycvmpBSkZnkNRskAOBt
q8KegMH7vyY3i3Zt
Concat
ImageFormat
PixelFormat
ManagementBaseObject
CreateObject
ConcatenateObject
OrObject
SubtractObject
TargetObject
ManagementObject
Collect
Connect
set_AllowAutoRedirect
LateGet
System.Net
LateSet
Socket
get_Height
op_Explicit
set_DefaultConnectionLimit
GraphicsUnit
WaitForExit
WY8kgVe0NXMePnRV37Qvn5cMMpKawXQAA2SLkt
IAsyncResult
DelegateAsyncResult
RegexResult
set_UserAgent
XClient
WebClient
System.Management
Environment
SetParent
hWndNewParent
get_Current
GetCurrent
ManualResetEvent
get_EntryPoint
get_TickCount
get_ProcessorCount
GetPathRoot
ParameterizedThreadStart
Restart
Convert
$VB$Local_Port
HttpWebRequest
$VB$Local_Host
G9V8YEEGpB9qAsst
set_Timeout
GetKeyboardLayout
MoveNext
System.Text
ReadAllText
WriteAllText
GetText
SetText
GetWindowText
$VB$Local_txt
e7D2ZHUmg4IpgInGewmzIOkbVSldYWoWCklrHRm6R7UOLBHaImTJOpAu
G7dkPy2SJbf8j1Ou
JLENoJ8Io9F0GORu
dea4x1lqZ5XGMglvwYm8IIOQZhQpdCMj23g8xgm13vX2UrL4znAF5Y2Q8NuZ9GKAPz0e05XObu
TEGxcoqQWo5O7aJxtUPbIITR7Anu8pkxr5ocgnTqb6tbk04cXTz0ezbu
JivEegK611YhEVdsSaTBxdDwwiq06eDOoo5NThZ4EUfw3GThq2KqWJEgflT38fdE9MSkZg0Ugu
GqzfPEqbS9doecqu
3yAIgidLYHzsi5Hq0TklBIsDqwmNat9YignSKUnkgccgWk3yNNWZNPP2mrZGDhTouPhgy1Izru
DsxGeYQWWY0XHRqBCxRWzB5qLFZ1TQ4kJi6MwXRKiou60gBPgDLDHntu
sw4uGXsZg83GaeMv
0F3fGidV0rPWjBCWefS56zDIQFVykT1N5yRGSSHfrSMycIq8dfnYZPOv
BdiJrino63zQLZrpNql1RNhDNCOHQag3gIwt1yDkTNp1z6ElUclWaJcR8tDDuSufStnelmSEaK9bU2VDzkE54FPv
7w73RNsHOdhyOnUv
WebQMCid70iMGmcv
or6P6qV0lGAYTilv
yZiYp9pYnw22x9ov
NMYp3kkLilabDryv
JL5lOLM8IRVeAoioWNOuHbVuGn16zzHv6NrfYex68YLM6gqRGEO6ZJRVMYCs3g2smZn7H2w
WRHnsfKtrAB9BcaAbOBqq6GKiR7iqSDk57SfLW7Ec3EoEGqw3OLQxyDRlOjqhWDaHWRKI5w
b4mpE82A7b0dXmEYUBiK4FWtftfgplY9yP9QCw
S9fK7TLI97XyHeb6G5nrViDLb56xCB4Feg1BH0oREFujZSM0JCrGxUQw
aq8HDofepdlTfrKFX3Go0NLECR8pJsGPH2bTWw
09UnJ874ksLhwCp2HEumCDFbUO3pw0qeaY6syL0ez2XGHUwyPPIPbZBkOFDFUJ6JRDzBoWw
arRgCIBA0coGdxYw
whDLkrbQeFwieHItZRX5bQUTT8Ts90sD7zxpH4A8EXw36535fBXJ3Khw
vxkcpfvbMWeh9zC2Ieusy9O15bNQEGh4zuX5tXYN4nEmjA6V35ZYQLmHNtfvl6mf0WgJ6BJGWBiXFQ7PTXdItLhw
QAS8EhjhyB1edRMRf3aeyvCixAj5W2GwoWjtIotXUytqUpkgyGoElalw
GetForegroundWindow
set_CreateNoWindow
J0Vzgur4ITTdoh6x
cKCT6huMj5NsxKjNMQ96UhzJpXJF6EVyg5kX8x
ToUnicodeEx
UnhookWindowsHookEx
SetWindowsHookEx
CallNextHookEx
LateSetComplex
312ikBYen8izHJR39Zgt3ME22p5NoAdvDokMuqXnSLmK7NzDkE2gEWw7QvLSReX3SLUlDfx
wFsd8cpdSUKVuUnx
93CYBJAh58tDx94y
fHyGLDMdsAJrykHy
UnSi5nBM69G32Eq3bNoktqPbivf1iLGZtftzKwUVwzA4vY801X2NkPJy
YpLu1Lkyi81vVT0yMEJp6pwDxtEXivpDGTdZJy
AX1xBbGTKZVtkxrXp5scRyVpWFOj3lqPa1q1ACxF69e5Ly
qmdIM6KE7eS13nbrWFaE9gB5vuBIU9MCEkCisBCz0tTpGxPu0OiUvIMy
OfVojpJQoiHBVLVy
NekvBVtEVMvsfpXgYtTNmAqbqw1VQAYlRyZ1hDRz1gAwNr5J6x10fceaXtOCKiVDcHgEgZy
ToArray
set_Key
CreateSubKey
DeleteSubKey
OpenSubKey
MapVirtualKey
RegistryKey
XuwstEMYlJ5uJ9yq4MFTcN3G1oUFL31qdzxa1meWjHQS2EVVAljqPpfbRwCAOksr25yKbvJlCeXmO0xFK9XJaRey
yFtSTIELy4b51IUmjPjZKmzfA3MZ8aDvt3DUexWFzgBjIGdBz7sYiaey
System.Security.Cryptography
Assembly
AddressFamily
ObjectQuery
get_TotalPhysicalMemory
get_Directory
CreateDirectory
get_SystemDirectory
get_Registry
op_Equality
WindowsIdentity
IsNullOrEmpty
UPJG2fcvMrVmhFoaF4H1M08Xz2LrZvh3n7LsrPMr0Lq7JqVAVEUysE0Zly3lpoVIEDRAeGAdxy
8J3GjNBpDuDX2lxy
RegistryProxy
4nOk6F4TX50tY6yy
EkF344sXV4pT2Fyy
qxNk6p4uo3AppQv2QwzQEix6MVxSTvQNqwWDa7aewFMSt42t5M6nawAz
Ft3ilPjdhBG7odPz
9j6fMtXIw7x0Jwcz
Tk0omow6iM7iiXYWRfQoyUnTkztOJduLP8RIZmHkzGKgLGFiuVMafTR02q33WCqeOOS9mdz
clC6e6VuBnrUJKgz
ffygdXZTKwrKdujz
WrapNonExceptionThrows
$13154270-0136-48a2-90d0-76fa12035103
1.0.0.0
MyTemplate
14.0.0.0
My.Computer
My.Application
My.User
My.WebServices
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
<generated method>
<generated method>
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
qs2arXMMUFpUHAYDKk8h3pjfGthHRAd5ftEe6A4a5G1RylIGGINOYVU8kEVsiZpovSqv16p81VX6oWscDvPiKP6Z
EtXyujdwZ4h6FiMFA97svTuzojNQdcqKLWwcQDz64PDoWiQ1QjnziutEB8aiYEHlVLpbIYzYh2
YkTdpiCnehEBdXfUhjAGH5tnN3M71REgus10f9pt2TeOiDLiKYv2A9U6nt5JeX2Vyfvaa8wUjI
rtKSkuep0lZvFfej0cBwHuiKkXvA9GVnxThuu9cWnubwVcjr50y764CjdXs6R69Ss2A50bbq6Z
ZbAn1OfWdV2zLFO43Y6o69IEltSwgrsWI00txHk2QoGhNW0ANT6sssdPRtfuPA2gfIow9X3V0u
11Kl9MPJFxLE10aCbOOCLE12kqmfi0haQLIfqwLHv06HFDPXZJJGN8xXfBLb9CmjKBOtRcQm9c
YBA88EYsRUvfov0NpYvHqshaxyR5QnS4aSLeRsbMLLDuVRAPoUhZO7QRy919wwONqBEh4gNgoo
SSS0BkS4imwrS1wYNf54Sy8hEFJknSz5oIKDvGmr7Sc=
XiIeNEUBeXnhWekuJWrv+w==
muCd84uKc6KM3nfLto5pcg==
pt3oE8I2D6ArsGA4yKNhcQ==
Z2ETfzYz3cJyloXFUf+7tA==
ZpWrHCdpcYhG/QC7Uax7mg==
JrU4c4woF9UN0lxQDG/AkA==
3GyvBy7vaWZhtjC7kpS2LTozxVZfwYizGQJw3RPvc08=
GuHpKeZH72ax59BI
\Log.tmp
2Bs+2Sz/BXUueAwYo3PXPmI+jrhsBiPkC4qoYvH9jbcgKKBj5kfwHdijSyihZii9
eHN0z4IKidZVTQZ+7i8nRkID5TXMbQ5TzV1x7vNtZTv7fBtJRjnKbs0hBovnpjjV
4uEK1Bk5DXRHbnJFpMkZ8A==
Ym5qFEjMir2BoTs3k3a77hFScY2h79OXrFZcslL2XFDZu7Q5tw3LWKTuOBZEcg6hJE6xVAJlGx
gXdtxsH7VcP2dcAIuuJdJwZBMOR22XlddmtvbcApDVdtwIBKwsY2hBqqGg29XscgQl0SqIfoca
schtasks.exe
/create /f /RL HIGHEST /sc minute /mo 1 /tn "
" /tr "
/create /f /sc minute /mo 1 /tn "
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
WScript.Shell
CreateShortcut
TargetPath
WorkingDirectory
powershell.exe
-ExecutionPolicy Bypass Add-MpPreference -ExclusionPath '
-ExecutionPolicy Bypass Add-MpPreference -ExclusionProcess '
AXn0dNxJnV9j1V4CqHhL3B1IPWGDNYqRHUNpGimTUuGwVn0femjCNvV36rM55EgPMpUTQJWsmd
G9Ya8whnD7nHkE6I
BxMbHMAS9AWmKdyK
gL31UGcvFvLfS1Iu
kQOTphh118p2wUZd
4br7AovmWdZLOyaV
KrOjirYUmSHZa4yx
Microsoft
Service Pack
dd/MM/yyy
\root\SecurityCenter2
Select * from AntivirusProduct
displayName
SELECT * FROM Win32_VideoController
Win32_Processor.deviceid="CPU0"
Core(TM)
UynLyN41XVJWn0Os
3KYyR9MnwPzQoveq
g3fv7q1EPfN7NGEU
LOeCk0Vg89FfYd4L
5wc4sIGVNb49siLn
Lr8VpwY7nLv6jsJz
Cjo0I3RgQmD67A55
S28b3TGLbgLCf4DJ
qtCkgg6cCe1h5Yqc
9XH91s2ArBVNvbst
6HvL6E8indk9S3fD
gcyqJcZmryQCNJM3
3wTK2NPXQEVOuCu0
HxkBNxeBg5ZyVHwy
GdmEDlDXnSoKdxc4
VEiH5EldksWjV3UM
iYeVmuRh3FsL1Ex2
nY0DzFLDfPjSfoNP
483TWNm6OHwxqFyz
BBlGrOj50Vfqhbnw
n0oAMiKT9LKfF5jL
uninstall
update
Urlopen
Urlhide
PCShutdown
shutdown.exe /f /s /t 0
PCRestart
shutdown.exe /f /r /t 0
PCLogoff
shutdown.exe -L
RunShell
StartDDos
StopDDos
StartReport
StopReport
\drivers\etc\hosts
Shosts
HostsMSG
Modified successfully!
HostsErr
plugin
sendPlugin
savePlugin
RemovePlugins
Plugins Removed!
OfflineGet
Plugin
Invoke
RunRecovery
Recovery
RunOptions
injRun
UACFunc
Plugin Error!
ToLower
Open [
-ExecutionPolicy Bypass -File "
j4pGXKrJA5bm91Ez
crDYtxYOQ1GBvJqc
Zw8jqQAcRNby8Z2s
dDD393PveIYO22NY
Nqd2xnLrizF5opYb
NWPDhlA6baDpFE7f
nCenW0LQ2rWQolga
XtIT4jOq7HEyNjGM
MANQ1LDcq24D16WP
IaHOhGzdXStoakkJ
FKuQC4qPy2DT0rjC
ZeYGYwWm7KLTlAp4
hCUJS6zwsJn7ql2i
rTxPUxVNY6o6kO5w
3oN4Alu71TNdlrw6
POST / HTTP/1.1
Host:
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
User-Agent:
Content-length: 5235
schtasks
/delete /f /tn "
@echo off
timeout 3 > NUL
" /f /q
4qa4L5go7XQCDh5a
GGTQWnJAk0MtCbD3
ToUpper
[SPACE]
Return
[ENTER]
Escape
LControlKey
[CTRL]
RControlKey
RShiftKey
[Shift]
LShiftKey
[Back]
Capital
[CAPSLOCK: OFF]
[CAPSLOCK: ON]
MainWindowTitle
ProcessName
XwP21OTNd9mtxFtd
oFmdOZABgvqlXNMK
Zev0Kph3wY3tiGYC
ZyS2uLYS3w5c6EkR
yoBE4SgvQrM9UFEn
0lE7sVX2EtE4Tnkb
1aPcwqsoGDc17zt2
cuAMDjT9inx6fhvO
Z9oA9lUcqla7TSyF
s0uff8ofpdpB3L7V
tpuqaEkpK9d1GqNU
2ALOqPv94R51YsmP
PVPBFxNdZH0Lmkkz
IYhHzdI9shp8lkNt
0yzgmhrJdDkYRjyX
46jzQ4tansYE5V58
csJbjnwO5NgORCW9
Ah4lPK4lhBb3ppJl
\b(bc1|[13])[a-zA-HJ-NP-Z0-9]{26,45}\b
\b(0x)[a-zA-HJ-NP-Z0-9]{40,45}\b
T[A-Za-z1-9]{33}
51Z1OatGZx3AtSx5
hYeuPPsIIWWB5jc6
YBAW7JOGeKsmJy5n
UaQu090o6RDB5LvX
JKYVa1DCUVLVPZDR
BTC Clipper
ETH Clipper
TRC20 Clipper
ExStyle
Gg9Hy2jvCejTJhaf
aptyLLn4huKOoogv
Wd9Bk8GMZqsrolzn
rEZeeNgDBoBOk8XG
7dOhoHbdBti3gfAd
4vd4y4B70A4X3HeI
Qgvw0j4JN3z0vTVz
Software\
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
abcdefghijklmnopqrstuvwxyz
Err HWID
ToArray
Cmrq6WusN6obVmMf
hb4iZZdc4CSs91Om
5JjADgwZZNwMXMMt
7xXpRFXF6TKGyKc6
qnReAwfVT5ClMsJj
35GDf4IlJwABPN0s
jEpKVF4a27KvsQyq
AMymBPqHNgzWNpJB
vqVyHGPkL2GVGWOF
oRyVEv3wjCGSjj3N
8LC0yCenlxN2CEqI
3fYcVzjWkP4pLwlL
09xMeHjYFueFBSbZ
IMcOlejP62c95kr4
oaDUzIgIPlpLKHU4
Spc5cR8mYqVatZZm
TBYP3LzXJb8wYodT
tFew1lhK5yD29t76
YgB3o68tKbfJGpMc
0k1UrGFKVb7rGjKg
yM17TWHLsB4Mhnsl
xqlYw4v3jNr4n4cf
m9urSaJuwPjpTKFe
2f2KJ9Tky4uBL2gK
pevwjCHNIPtwqhMG
fhN5FL6n23xNsOC7
973GrT9oxhFNOxLQ
HEcVRtIubdBeUqiC
abcdefghijklmnopqrstuvwxyz
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
1.0.0.0
InternalName
XClient.exe
LegalCopyright
OriginalFilename
XClient.exe
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.XWorm.m!c
tehtris Clean
MicroWorld-eScan Trojan.GenericKD.72130627
CMC Clean
CAT-QuickHeal Worm.GenericFC.S32598663
Skyhigh BehavesLike.Win32.Trojan.lh
ALYac Trojan.GenericKD.72130627
Cylance unsafe
Zillya Trojan.Agent.Win32.3900970
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005aa5f01 )
Alibaba Backdoor:MSIL/XWormRAT.de6a9694
K7GW Trojan ( 00592e8b1 )
Cybereason malicious.a32829
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.B
Paloalto Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Agent.DWN
APEX Malicious
Avast Win32:MalwareX-gen [Trj]
Cynet Clean
Kaspersky HEUR:Backdoor.MSIL.XWorm.gen
BitDefender Trojan.GenericKD.72130627
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Agent.72192.JN
Tencent Trojan.MSIL.Agent.16000605
TACHYON Clean
Sophos Troj/RAT-FJ
F-Secure Trojan.TR/Spy.Gen
DrWeb BackDoor.BladabindiNET.30
VIPRE Trojan.GenericKD.72130627
TrendMicro Backdoor.Win32.XWORM.YXECZZ
Trapmine malicious.high.ml.score
FireEye Generic.mg.109adf5a32829b15
Emsisoft Trojan.GenericKD.72130627 (B)
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Varist W32/MSIL_Agent.EWV.gen!Eldorado
Avira TR/Spy.Gen
Antiy-AVL Clean
Kingsoft malware.kb.c.1000
Gridinsoft Malware.Win32.XWorm.tr
Xcitium Malware@#outp6ynq8etf
Arcabit Trojan.Generic.D44CA043
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.MSIL.XWorm.gen
GData Trojan.GenericKD.72130627
Google Detected
AhnLab-V3 Trojan/Win.CoinMiner.C5395529
Acronis Clean
McAfee Trojan-FVYT!109ADF5A3282
MAX malware (ai score=89)
VBA32 Backdoor.MSIL.XWorm.gen
Malwarebytes Backdoor.XWorm
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Backdoor.Win32.XWORM.YXECZZ
Rising Backdoor.njRAT!1.9E49 (CLASSIC)
Yandex Clean
Ikarus Trojan.MSIL.Agent
MaxSecure Trojan.Malware.218710578.susgen
Fortinet MSIL/Conwise.RCE!tr
BitDefenderTheta Gen:NN.ZemsilF.36802.em0@auXAHO
AVG Win32:MalwareX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Backdoor:MSIL/XWormRAT.A!MTB
No IRMA results available.