Static | ZeroBOX

PE Compile Time

2024-06-27 19:21:19

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00011934 0x00011a00 5.96041818743
.rsrc 0x00014000 0x0001fd72 0x0001fe00 6.17421922128
.reloc 0x00034000 0x0000000c 0x00000200 0.0980041756627

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00033458 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00033458 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00033458 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00033458 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00033458 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00033458 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000338c0 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0003391c 0x0000026c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00033b88 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
3b%(A
v4.0.30319
#Strings
EzTDvlGQ5EhScGlPFbIIVAL4YAPecRbMbc21yEBiWzoWBi3yrCvINZJAb5A57xikKqu0MmIWK3dWcGeAy16AHJ0
M4NvBAwoduDvurkNdzzKBAQSzkfI7Kf3yY3HtK0
TRbfHF3HH0ScwUiIzqtmme4S1T1UbKZ5oiF7QN0
Khw7oelszxtS1u2kfo97n90i8vqR0
tnt8Akk4yMU1V0
oX5UdZvgSa7JDrlhCxxwjfW0
l2v7nMLJxVftHP9pYMMTp5pbOU4rU5uoOlXkLi0
z0smdaj4AEWVDgqNi0Z5OVjHHVu7P0x2QHPFXhp9rhLf7S22siTg5tAsIfKnLhPmgLfj3YNmdj5StxknJ3OME8y17zO7zF01
iqMzlz8hQ2rdd7HK5W7WMkPXh7P5d3HJ73F1l9HcVCGDrLiHIj9r9ZPNUMq523fC7Nn7TH6b8N0LjWbAWEZ8E3uoOTYbs691
cPTC1gR5MGxQA1
yJoSZiPm8PyZaA4yRtjfMoXnPTaTUAKEJNcAyiKsqXC6A3bjjHpLsBdlL5sLo7E1
AqCpYwbDLTgJHdy9JorQ65X4yWmtpuerX7yX8sDn6UdKaduEFZ1buF6RhVruTP250cVleNvISc3sojZGq0dcGN4cAeI2XAK1
Zp1nc1ijzCy6xE4a7XWyA6S1
MW62BUwsLqWMt5dimZRdYYjNAfx8h7D8t9rxxVtZd0qTzDEb27Keg9HTpm2oNRLmeW0rqSWX1LCVvIQFC2PbtFGKS0XBuvU1
THwLBUV5IZiqY1
_Closure$__1
IEnumerable`1
ThreadSafeObjectProvider`1
List`1
ji7P6wrpsU7lRYVyyueEBcAJb8o19ZPtDrWvKe1
bBmnfFwTQFD8B2lRXQIt0yzgq0Fg1
Liz1sQtpy63SpPGfTZooF7pOO9go1
3l1V86YU6AOLW8tY9rj7uTBSEP0DjmSsHZ7GYq1
OvN4YVfxbiOdBezRK6rToYskzvNgSrMJtoHJRjonj7BqSf8lWH5vM04uLyBBpsu1
6dO6PwgT4ly022
Microsoft.Win32
UInt32
ReadInt32
ToInt32
w68gucdtEBsHJAWwY3WBtRODSuoEu8h2HjgoTu3YeODHgK2addbCFztAY2sK4ylBuPo8xzuoKXVx8KTb1YJR6WpUpbrynFC2
0LTT91MZbb7CpcGxBOFdjsSr1A2N2
2Omop83dIjJEX2
Func`2
JtzYO5lFKhMahqcMCmwwFTZGwxcn2
JYZ4mX48WGuBStC0mkyF1pAGW6V1m1G0Q2Erlja1pj0DddTZINMkplTG4RuIAQRodd6FknmVlqNa6p2
1QROCvOogqwc5JpBi4YS6qFtKhGp2
EO9kYLknVSYWD0bmt3K8BythTirDuNzfKhgVQr2
jvFDlEnhDM9B3GIlm4yzgopMQwVTEr8Ux8O9vkfxnbV1bizfejIOrD62UliRLFXjdergC20oxLEiMdrqUmzu9JqoXs7Cr6w2
QCU36jrC6cL4tM5GrTIJPKYnAgD9xFUd8bzm703
TzwlQHQRDZC97G5Ki7KNvYfWqqUG3
Njpg1rbJHa0Cd6vHaZ0YYpqF6neP3
rDbvL4qrQmlheenCR01aFTQ3
znz0w2ylsROJRNAYyk5VNYEzMzyK5miKLqca8d3
4z7PuYz2vQ05RxBSPUrhNHB5LwPu27g7tqcHQB5SnBBUqg1BOGgNAe5BVGNQphwHV0sSkYo7TPOfTiD1PNkBmVXpjgYDMYk3
iWKt9LrhPqaak3
rGTT9d1gC76Vo3
bVkYC2vIk1vqiOxzRoZZ1nxoOV60x1io1xH5oKXUNnPYfwkRy5fYlEKBUjSKMVs3
Y8isI5k1NSCF04
UInt64
y5cb9NWOKKYigL0yrrxanEQfbZr8QumezJBsHH4
XC8UUAMgCnQur4
tdDwg2wBarxxvvFy2W5Ku9T19S8X7Jt6wz4Qwr4
KCV7PS89yoIa35wjRO0C0gQmNClK3S9zdw7TEoONQiV2QlKumnTrYDANasMDH7z4
jfOPGWF7UkPg95lqATQGlD8yE2PtAbszMRd4GknWRXslelYjZtC6LlGJCAkfdHjJf33L8p6fsiTld3YD8TMvs15
ViD8EJBqxltCnXh280uafJwwIvtiT7M2kzER9D5
2tpmeZtMecmkc3TcUbxjPYE5
aEN6RCmLVTn7UGqw45bfuxZJoPR0lhtdcslldJ5
3et46rr9ihbZdwaTZyJr5d1dmeRN0Y7ObX4vAN5
tposXk5NmvanT5
71v0SgLqVio6ntrsJv0gsrvNTYpjQvdgQjgV8B4qllxOLJxL2V6rlttkGkUiJ8V5
XWjA5ukfqcLwO5SFmI0Gj1W5
zmUO9qpxjmFiAoE0YAbnHWxGxUDMS0kVrmupee5
ivdtf9k7z7nYOSNWWMQsJwjNuH0xJrvAspPDY17yT00qADPu2PCaVPXye1DPLRKnbBCegh1wgFreqOGAJjwuWmxXomqTqkk5
2J3QCRPVYACdu5
I5TbpcACulLLx5
pZhXXGkQU8T2iZ8hQiXeLGaF6sajZW3Ecf8zZUmyWGFWrcHARK0X0MenpmJL0jr39L1ZRRbK39N9CA6
226gAfpb8CStP3X7CH78Pu0h4t8d2r0R88LGaQOJq1Hst3uebcJUIo822eZNheIzby68LAbyaCfo0c6
5vLPHANT5KdqdEdwZKaZnP29Zom5Nh9UBb8E3NQAOkp2pGStqDloUdR148Azpq7JlutzUiwHsmIqat6
gNfPGc57hixVUDwu9ZjOqqDAtVmt6
C4N2zGL7l0PCx6
Zkglc8TVWgRQ57
DhGorNOGN6w397
CnLGciH6qZ75D7
TJBf9SEDM9G6QAZx96i1dxsjwCQF7
jWLCMJVk7XBB6vqAaDhmmYmFaANZDYr7HWkC8DXTE5YOuFCeGPDP1CuvDP7pgi85dnFGmM9NiYG9TW7
k7W1QKNyx4oin7
yrQPjAPh8YjKs7
zknurev2VOOiW4qEogh0WxHqoFozGkhvdhulp7A6QK38Uja3veoMvxvaPRBApQn9V543uFaXLQil1y7
get_UTF8
0t25hcn6GPXmF8
_Lambda$__8
0va3PiICmiFP2J08vodnWtd8
FirxLsXuyXiM9gvYV29Y5wSz2hDe8
O7REwUn1rw4AHVLzCkeXvPf8
NwiUBxCgvRgYDZDydag42Wl9hHEGonsV3C367h8
jp7C0SQQSOMUh8
HPaW7uUGXWicm8
32ayClwvg6lqw8
TUcFCfeWi0RS09
gm23nnRFSjeLF9
QYLSBdJFc9z4MGmsbxx7GlQjMLe3GGETJPth51xnFyDCpi6wNv0OSRBc4vUlvAOSE8IGjOpfDKJl7kfAyloB8ng7OKOGWSH9
SQNobWBMtL4lLpoTyViqXRHQpxoI9
1ijm2NtuN8fgGyYAjZ39CkncpwuoAMG5hcmPMo2aK2CvQLhk0tQoEfuWIbNLgHYV0MBpbhqS1Hn0oggW05i90Q9
5KH4i1vOOKcxQ9
SQ7gcKic4PRXs9
aEdo2zEp7lzswf4yR1fJIrSLfQYv9
<Module>
q30enHMCrg6X9A
FRPZBp4epAqVKA
muEBLMabq0DOZAzg7wElLAhxmTQqjjy91dX3G2QlJ6YTE68GrcrccuehwOhrNwYlFGsF0LRfnoZAg18exBeqmNA
0WWlF6pUpqD1WA
JiwwU0jYNgIVcA
hi3jI6q2KtLYByuFsnSSmEVeYts1ySsZbzIf9eA
NvdltQAuCSa8fA
WudCSVnmpcyDiA
3j4kghQfMODiEYn39lqYyLb5btbjA
5L6TSyhyOcHBmA
lINoLqEgUkt2nA
capGetDriverDescriptionA
capCreateCaptureWindowA
zTMJyOch1ZZC9B
1elHDd9Ueq2dPFkADIuWdwIRNzzTsN1Dan4qN9B
5fhdLO3hcaZNCB
7GLGyGjbSOUO0vB1j17dwGSG3dCGoDBhGaE01GB
CyL89AsENOkF1nZPQNjPGptNjd4PB
lMMftrOKonPgYN1Lnu3MUOfg0bTjJjpkOPoQZRB
yp2hyACIouwHHldZ8mrxDEho83JiGTQTbczD6sn6NTjiNiiIBFWC6EecEGK1FDUZTzBtc5FD5U0RobOvaXpguODGc29OOPgB
NYvlOlFDsBNnHPhAW1dWAGgDfh3ZHtsWEyb6BjB
MH48iBZqvnOb2C14FATbVPLjdWT33RtkUKzUhR8jKGziH2LGo3HzSIzcBFFmLxxTdtOvODUsCIYhnnNuqiR90lB
F3aSIemMIursR6WHNBKvtv4afLT0C
oRuu60O0IgIMkSJWjofiHRwB6zHWkqFMP7u5NTmXkNEbI3ZE84MNiS3bCODLdWdjvkD01LTIaH1vR1C
uOi7yS9teBgiCTWCDnjrRLoktuC2C
0IT9lwJDyyX8cfQtMkxaRXwqhISoUKUq4EkQQ7C
zxoB7NyXBD6RF0ap2db8x2CC
bldCdQ0AfTtTuv6xh41L7ZzRNqEEC
jIhBEGoHHEeBCDabJQl4b7oDNw5LC
aWSZTpgCTWpHcC
80rDJXcK6tixfC
cqwInvZI4nSJGeh9X4C13pzuKd5slk1I6mLiFgC
3aU4nKwYsCLErC
gE39nA0WI045cuswddwrRoZzAFMp4funWQgtPsC
DcmKpN7aJYIPWZs60ghhrYTKTNbcUW8pE3XkGuC
SDMs224V8KqS5D
NnB48hpBrizbKW99MUGQFk8D
ES_SYSTEM_REQUIRED
ES_DISPLAY_REQUIRED
X472cHTpOSTi6jC9Uskt4iQw8hZT91C15JPMoA0Pk2iJSelms7OafzY46iPW11xmDvi0Q20ML34YwXD
tWqv9axuQp34iMqPT94moQOVSl1ZD
DthjmBqTMMx6PhycmDyocQ2E
Y569x86UQoTH6tetirhpyUnt9tYCE
igJW0ncmxcAcusi2xWOkJzdhVVfIBTRfK6jHe1OHuKplPIWrtSFudomrErDEyqUHRchGXHDuaatesYlN77U7IB7v7v4EcfOE
EXECUTION_STATE
oSF5UDpKKI5FxEgnHVK7DSXE
8ndWzPvXNrr9z5ljVx68EFxMjMSoE
Xeci5DrDGdUdYF
ZpVtnrxPWSiauvAXD7EfVCK1mW1jF
o3YBQp5KqVZjKdKgVRjtjgTRFva8G
3WwQE22hpdsGOWX0NjAhIpTnBeFPQK93E1kBZ79rJOv60E9zBs1KxNG8taMDXNMuHtYM3osH62jaCk1yQB7mJdZGrNYKOo9G
NT8ltqelnK6JMG
SfsTYiria38kX8oI0mbjc5WtvhIGQI3Z00v4cr5ML4PsOFPsaabuHaQUSr1Qdz4gWVXUxAM8rpRuwNxy3LGEQTG
5jDeZOYTKOxT1TbOWI5kbiv4LGcXG
IgY2HwHEJnEyJ3Jon5M2NDHyLpdsyHSBiWZdX68yv3ck3czUVDZtD2CvGDaIH3ISLslbEr6UWGoXbeG
kEYv6lFtQYRzVXQue4mg505nUy1AZMn6XJSOZoG
uU1sdwIoEeNDyXiFfALo8Wqx3hIixkxQXlG591Cd98VzLcsd3tD22MF0nOqNXEGVmm2e3adxMm3Ac0H
yOxm7LH3DweSgcxpUEHQjhhdRGT1Kdo9OcRR1GH
OrC7PZwY1APpJH
920VzScxUTy9dvSDvJw8w4lqHcRLH
e5vlbIHFbeEy15LM6UruHwCsHbcZhIY0fLjBJZfl5J0fnP2zHl8EWY2TTRQAD5JOnoC9KaQLxz2EAS8OFy3ugKsYNpqYhBNH
R6imFoPsOGfiwgm4mTfmg7RPd7ta5G0BkZd0I8dRtYbceyhneQdTRnbczrW67JXW8vmLOzobSAe5JFo08Qj7dksUSXsR6aSH
5G7D6Mx0MeqlIrdJYMxN0EynjrqsH
837EwqXZn1W6iB6uImYhmRGIxi1wMv0kloOSaSRSOPX41Hai71ePwyTNDTnhuN7I
FSKROrXtZjAwh09zDCr1NehdzAi82AXBSBS9sEI
get_ASCII
6Cs2T7dnyagclHV3Z0k8M4SI
ylyn7uX1V7iW59ojp1xjQZFhi6seS4wYR6010lseJLn7V03qTqUNAv2h3VlCjEhuZ6cTPRRWziJjLNnQgKu0i7cun6KMbV0J
MCYfl60pB2ee1J
W0IeEdeXavVP3J
xJTvD5kday50SQyHDxVTgLsQVa8T8ox881QhdfvtZTGeB5uMtE76H4p6oEy0VlXavLQXJl4PCsUAcMP2IlZ5nbcFs4Du9AOJ
TpjoNiOlXO7pzehfcSJigMYb57U6GULQ8rQquSJ
u9lkpWZAh27j6LkYzHsmrMe9u3CZJ
OtXJKvYGO951iJ
HPJzN6M6ehFrjJ
L4ukgVILpT6dTFT7ToENSjpGbGJmJ
udZEs4mEhBFzJD9s6p9HOonYtI7yJ
REylOFXCG7YPDk4voUhKJhzJ
AlBqbsfGZbIIvaM9ee5XqY2K
YvB5sUmyxowUwtOCrW5l4iKm3gIMWJ872HTGgO0oOj6v7hRxkwKK
0HNczOQ3dFRJLK
wNItLeo8p5jymSQo041f9Hokt86TK
xwE1GpH8u1icfSGoSk3qrr5fjdcWK
qBmrPlfi0o40ZK
CN6pvilsR8EkcK
ZfQFMPnqZPlekK
t9mZDgsqmIwNCL
Vs3qMGuaYo39ImBXN0zXpi6AMPEIL
EcwwRMtuKi5Ck2NAeQze8zixKmwUL
9QLwdbBtYiFL6xt0CWKER3qVqgEvuXpUyUWAxVL
6RKHXceFZuXXbwYQ85aXEH27ByGfL
oAMb5eRXb019mL
3m1md6ZIBaukUywkDMara3O5LbB6M
l481xXpSY33qSM
pbMgoiG1wh3CoSgaab539w2ZNyAYx1qyl0XzhfM
gsjOUyIdYvcE5R1NvRtlaLbBqFNvM
DIcACcUCeUTUYgl9Gbdk8oyM
5p23XwZylAnTzM
TA1vUkyim9gAPcUSgfRogZUA1mw4JDU2BgnQR8FOE1aI2G967XijbBZ66DqNTIQrkBjLtV7hovdOBCN
qPINP44bZOuYEN
6CHrrhJEpVmYJlCBT3XdMlJxNSCstYP6VICaDfzOIM7D1mlpjnMeUIBz3nuvyGkmHR4O46ag0qiBNN53Px1M6JN
cutuzx5b0L6IqsCrBZYnOoruDril4DEBcTZrVNN
Rjbsr9RSoYN16uNSKU8EtZsauixRrgxo1ZwbZIJaKFwtE7xkCK2SigyPPB5uZHSN
xT1nWzKzEOjRjN
8AA25JjZ2fyAUv01TJtdlwaPXWkxdyVyIlvNlXhGYUDHoIEajYwkY5t0dRykZm0glnJYySGt7SPehmN
tj0Rw4ZPmvbGzN
Zmd1BZ2QvUyJ1O
6akF2C8iCuGsGthesxhzV6vD0g2bDkrTASAO8yhjQ90idAo3FVTq6bv0ExTc1b9O
7x9KkyslpW5qyOhnozgtICCO
CMd3h4h5V0b1GvHBEzEhozJXaQemJsiyNNIH4YYtqrrRa0MkvzbX7dKsDPCbXoCO
LASTINPUTINFO
26kORuIxtsw06FOYyrYI3mHO
System.IO
oUFPIX2pTqxmIO
SYkGup6D1NhdJO
nXVBumAQ8HCI8L03aaOxwLFnrRoRO
apvyC2chFgIeTHfl964wzFuOdCwV3uQt7oSBCpcGZ0cyEQ8Ur2nvViPy2ke6xwUO
zu21MCSQDl2TGcNw99Hniugl0Onnt0810dgnH01lgOWaupwaAIczNSqSF9knl5zdhnfm0M2uhDc8CaO
VAOeNqtZzEsjrO
vwnmEva7eqf10P
wa4XmQ0WbPOhcvjT5CNkcIEYabt1NDLDdKylQ1P
6pXrHPSrq5t1W6tF4E1gygSP
K5tnictlDEp5iP
yeO6TyvK0AkLejpICwv2v3QhcJpsP
7D5JZPqSC9iRNXAqQ21qD5xP
mMrVRdJctHojfWesDq1F0tIVyH0gSoMyWPwKM6Q
PSlxzyKonUFJp34tbeBUEsJpORBnypBXFoPvKAQ
I7bnrpf1HjDM2TXLibg72A60JTNDQ
Ri03QWvObkrt6buDMxMZxZ5Z8GFaJGsXv5TZgxeXEj4aGA2cAKkdFQLv7UJNbdIQ
5vZqIw3ooOYK1ZtgZonvnNnBlVBjPJCcQpwRchCP8k01OBSsPfyLiAvfX0YAJNK9oo9XcKH3jB4qrgUZHmEVWU6P8aQRDYgQ
LFbUHYsGk3vrjydTjXbkIBUkmvAmQ
wIAXplAqxBMPpQ
RKQCKfmcMOyCsQ
sLpGUvo76jngDo0G3UWafTJ1SNpEpjtNCR599xrTCn6ByFrH1LFkfeAF8niMKl7R
jEuWhTJUqJ8ljoJd6mUTwIomeiqWH2ELeI5LOY5XN1LZ2QQPinllADARISUFXFfavHzKXxrOSPgYUIR
kCF3d3ypFfiF93WLKomFyIgOP2HXR
jUUOwwDcVVrECIorDgre3senLRGiOPflj2kd4dR
nHzcNy2xBcyX5Qn8eFRJ4Kn2MENOgQtJjMPns8kO2fqhAkYSs7JO5SMRTpeYT2hR
M60PvsqhbEJltR
zS1uVDaVj4GaA0kAArng9WzR
m9yCqQJVF0zaAcAe45X8oWW3Be3o3ZgBgQLTsau5EcWYPxwVZ4cQU8aK7vGjbD1wbJprlM8S62cYW3S
qLj26uBWrpKk7XaWeovO7gjaHAM6S
HZPXg8eChDS
yx81oafswbwB1KM7goFoS7JS
GJvA3pQRZHAWOS
ES_CONTINUOUS
Hjqqf7ujnHVbWS
ab94Q2SLzZoc30pvVhPUje4wXnNTChwgmaBeqaS
TTUDecNuwtHpfS
HYHAv3uneqkwhS
poh6cf9gPqfIO0mSB3THDAHnE6wv8xXy9w8eAlS
Kbz2IOGviCZ7yaNbUALdQF4AMPqlS
uvAiLmZpXjzvrS
Mnv18g3hOkYatS
uuX9wXlaHosF2T
iAsyELBPDFuQgKayAhk0Lq5KUvbPEUJcd2I2uHT
0bbB6dwrQQhP18WFFaVryWRT
4SEotEzPs9t0AgJ7gZXPvfJuv2fCAgsvAJR91imgq47njtlAEu5DDteEo4qRz4SK5JunFspiQhhcCnSADYmWVfT
untZRk37pT8liT
gn44U82ZnQQRzgYCXD6s6D2U
8v9nFQrfGoxuLU
3XDeW3xEl2hLCiLtoHX5xLkjUJVRU
7yozROJ5RTJiWU
UFxIZgPXhEOEMqwPwQkHFdZaTRnEHPzvEMCOQSphyVc2j8HP8n1nCYqoi0nxJFZU
1EhFvKyOKMAfH43MuLN4KHLAz8UNUwltFcxPklDD0beRYEWN211CLanyjCsse1QcsAsyzLJ3HGzxS2OBEe23bXGKRv34hdcU
V6S35Dh7kOvHkJTxd20di2sh2sokU
Nbxlff2Lt3zZpU
ljl7m5FDzpDvNG3QyzNd91UiOzi5y4MrrcUwzwU
rmrWGCQhMVK9TP36mqBouEWxBHJJLwjTn8X3HV43vGz7kJwhOkW8zspdZ7NAlR3V
KofcdyKt87ysycXKurBhIi0t31GpJbVVQxedQsv3J6HdkJFngftvZM3N4Vj4I8pvmkdD4GtRFzOqV6V
CaDQUghydgZFk9vJZl4J3pbQ3uwtCWOaJ5xYHCV
NqfHUvnYquSq7v4xyIoLiAOV
wnIOTRspmwryRV
BeNPgJD6vSc8pV
ZTmT4BvZhqD4QqWsIY77iEKCdjCxV
Gupps3dPdnEk0H6rZ41aSjyRZ5C6cCCknnf5RzV
IunOeEUg9VFz5W
mOL9MzaG15kajx484spXDiJlECCzBooBdJ7UUJITuPtBGjh1IXhg4QaqPjyZwC8W
y8STdcakp4pth6s3o9bXIJ9R7bgwWyq6TOcKf35maW4jwqGDoxz2N7U6BQ6JaYs7xj8U3tBNwiS8sznSlN9TZyW9QcuxPwJW
45LiIpE6FHaChKWqIUekghznrYJKW
wHNrDYQGqI5GKApHzwkQ2kSW
skh5Tm4LQW6IYv9FjdcxR4aW
1b4JoxMBzdxGshbcj1IliIEk4nxPNTHoAhnvsgW
Bnu5jEiR4ZaYrW
bCHzaYKlzlyzcRJ8AedjqEkJra3aAhGFay7y5BvfRA7vr4nSPavGYhCBqw5HAC8ZBsGGodcioJroLOxpwrSNh5X
OFvwEGAtLU3uSlfR6WRZneqYabAFet5zChO3wBKZn09ndJRR2Uma9ohLEJxP55EX
A8FxB02E9Zn759lLDxZ4MdOsKi71QUy7ypd0wLX
bAVY8fbFT0psk8FJ7AGsayWX
VmwlSutOn2IdzHLt7jmNmPFYP0TdvBs4Huss74OaYabVp6EavUTSTxfu1T5Rln2Y3t5rb7H6spTSUFkKpTvItWzp2WqTZ4ZX
GtRHpJiqq6K3N0EguJQgpgdXmWnn31ehr71PM0nM8ch0WmfGfwDtSHnlWXOQxzTeDqeH9Pus0tKHrDr5xHoHsdX
GI4ybkhpH9KJiiY4oT97TpeX
Gj4pFLPygN03w7m0KXLa5Q4IybZgX
w7idjRMOXKWlOA92S7S93UqX
fV4YD1sTMsCG9E8EAyB1QUo3Z3Cs8HiQ2jLk7zb2GtQ8ogkujaJUXeZFCd1EmlgcaevTSk5UWHZAzGu6oo7KV1KieVRUJhsX
OKiFDYeQqrSSwX
Rm2ZZdaOR0pb0Y
21K58rCZUfjsIl9uGn7BPTgGw2aOvFUYCE9n81Y
SasXedw4Ow1tTVdhJPFmWx2Y
kntS28BuMXuNLY
PFlMuuVAiR3Qc9FdHJidwWm8paaYY
AzXAUWqc1fe10RQVnZZBGTnY
qd2gJj1ZhAqOpsGQXJf0niVnMzqe2rpdT8M3tWh7PMnoBkjhKACNWByThfbnWbEY0dqMhWGuJ159zwY
zzlLLmimuroZ2bW3wTUY3KNX1PDpuVb3tUarrT6KIWynDaK3zQfnrRLvfjtqpA87smSpwmSJvTdmczQhAboyozY
9FUQlqP5Yu9v6Z
Ca67kdUgsJWNNphTBLbvMt1p8UoExYp25r760hzxq26iGlrK4tplhaHX1NG7BovGStzfOGxm1hNDSqiI6ine8hqQgGms7PHZ
kw5dE9dDSkRmVIEgpDd2lVy3DnbX8tcINJhrjTB2rpgs385Qmpc3O9HJyAOw71e42zWueg8SWYlv76CXGRLRROaQ4nWFl2QZ
Dyibjdrwgm9XnW9r05xA56w8pf3UZ
rJr44zuQ2eytbZ
fPIZXyGslAFeB3UvwzYXzOAucUMmZ
hqYdIjqroq3UI1un0eFuxIoZ
vkfK6rFnum8U4y7z4SE2jB76lDmsZ
NNSvt5wZpHuueZQ7ILYZNqLR3Rt7AkE570KyKaauwMSGnJwssNCzdQWmOHKYG3vy1ZlzQwZHb5uJazZ
Dispose__Instance__
Create__Instance__
value__
VWTB0v7fLP3phtDlB2q2xb61iTon60bEZgCj9aE5f1nXqxjPou7FYy7S4c3riwmGom1fLBAP50qFx8bXmhMqe0TaFZZTUE0a
xbwrv28aMemJ9a
UIB98Ox1Bbdi65z1J3UzdaGycylmSOKVTRszS72uf9heM9cBB4UEYgEdWx1uLl0b665SvKAkp6vugHa
wtjIbD1qhd06uPfgT0vOPqxNvD6dYHUFhWWhAZa
xN8kFSwWLbOnNTgjxuciyygCxaxha
sBjst8DmIBy7CDrzitqSpdiXRZgBzC0urEoXWla
YoUUc33pUW7XCVGbD5svYHaXJuDv8Q05CIlTbq5tOYFg2U8apUO7f5rpNiHyUzoa
ProjectData
Oo0oGckfwXnj9xTqClJYOmSQmYhrmmLQ3uS0rcIv2j3rEEZOu4Uk0dM05n4bPjY1hKf8SeuBTpDJ64b
W8XPEWFEYGPWHb
ZS6XcKoTF1zSib
mscorlib
w1mcqjhMy7shmb
qhUIcaAZpTfFv0a0t9UdoiESxMSRNWU2cEJt5gBBadNBKyvp0OiOnSt5KwR2byyvcCqnvpLfMC4izqb
VPXHQFBivyeGsb
r4chARqogcLENit8XfU3ndDMG6cub
Js2UmYz1pJlSIHfhOxoJ5rdYJ4Be1RbZQB53xdWJfwdFnm1ehhTNBbDOpEvdY8K32eK7YyoQ9QhyD1c
nHKCISkrmM8OAb12K99P5X5c
uFvULFjmMeVTKbQBRaORaDrGTG51fkjXGeBm59c
OYbkFjy3JFywCc
System.Collections.Generic
Microsoft.VisualBasic
LowLevelKeyboardProc
jAyPqAJKVmF1We4cYJ5T9eNY3qYd9lau953C3qc
GYYn4Log5WGw9lueV3NJ6fUkC5i1NO8JzM03dN5Qe3yqd9gji9aFvEqRoZyD1irNfUkbIYrnIusnq0d
YE7UfGiDF5DsrMJvtjumEXDsI8GiWQon63J26TKkbrL1GP3NmDrPBvNGFPq69U5d
UuZPnrJXmagl5d
xrHYsKmhAkzDJ3YLgaNXsgCd
GetWindowThreadProcessId
GetProcessById
Thread
Gi8DQe9NnNolQkC5ISfjznZvWWZcd
RijndaelManaged
get_Elapsed
jQXviAVf5SybgYpXZLhTt27ZZahhd
MdZGYoCR7xrl58gckEotAIf0WOLEIZdPNbtMDcS5KeoqPBj5wIdkbyFUsX17EPkd
qdco2sgjEwmKld
EndSend
BeginSend
Append
RegistryValueKind
set_Method
CompareMethod
TargetMethod
i5bKl9hl5ImYmsDKzwbnTQfn4lX4oCob6JaEard
RKJ1PrhmLActrd
gaSmlul2yDCLHVbCTclgHuAe
Replace
IsNullOrWhiteSpace
Microsoft Service
CreateInstance
get_GetInstance
instance
voeDoPvoRM8qRqj4mg91u9EpdC9XF8ewtBsMede
GetHashCode
set_Mode
FileMode
EnterDebugMode
CompressionMode
CipherMode
SelectMode
FromImage
DrawImage
get_Message
aM0wPLN4cfMtDYbcbgtGO63JOo0ke
EndInvoke
BeginInvoke
IEnumerable
IDisposable
Double
get_Handle
GetModuleHandle
RuntimeTypeHandle
GetTypeFromHandle
EventWaitHandle
Rectangle
DownloadFile
IsInRole
WindowsBuiltInRole
get_MainWindowTitle
get_MainModule
ProcessModule
AppWinStyle
set_WindowStyle
ProcessWindowStyle
get_Name
get_FileName
set_FileName
GetTempFileName
GetFileName
get_ModuleName
get_MachineName
get_OSFullName
get_FullName
get_UserName
get_ProcessName
CheckHostName
DateTime
get_LastWriteTime
dwTime
WaitOne
WriteLine
get_NewLine
Combine
QOleqBsaRg2dpe
ChangeType
UriHostNameType
CheckForSyncLockOnValueType
SecurityProtocolType
GetType
SocketType
System.Core
MethodBase
ApplicationBase
HttpWebResponse
GetResponse
Dispose
Create
MulticastDelegate
DelegateAsyncState
GetKeyboardState
EditorBrowsableState
SetThreadExecutionState
GetKeyState
Delete
ThreadStaticAttribute
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
StandardModuleAttribute
HideModuleNameAttribute
DebuggerStepThroughAttribute
AssemblyTrademarkAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
MyGroupCollectionAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
DebuggerDisplayAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
WriteByte
QaBUnIzoGVfkue
m_ThreadStaticValue
DeleteValue
GetObjectValue
GetValue
SetValue
set_Expect100Continue
ZjtqcIEDDua1JivuwI69L4zwEvWX3ZFeK0L8giELvAdctIuqz4rHE7vk5FRtmn1tm613oOewN7yufIx7XE561tPVJjOm7Tve
EndReceive
BeginReceive
Remove
IIrAPXSi7q2BjmfgOjxcXJ1FBcRVHcjODnTzGJD8jZIhS5Qx0V70M7vRFF76j7nRsw80iJVgItFotIM54hXZZW4OWmUffiwe
Microsoft Service.exe
cbSize
get_TotalSize
set_SendBufferSize
set_ReceiveBufferSize
w6j0QcIWbNyIdlw1xxNhzPQ2wKg4f
SizeOf
SmsNthnErN1IZf
3yczfmFw1qE0VU3LTBuZ3euJianMSRZS3SQfyornwBiJu1YpFJZ8jGWIhYaBsvdf
DQsNLqEXDrAMMt3dp0vzBvgf
Lkr2d5KOh38KruCeAT5Yo6sUAb8nlL4bTvGRhGwdkgxnZ6L3n0QfhxRKHrkr5XZjxE7NO6DzunvZw4g
VaSGaA6PUs59p06qRNQ6MohSReRJUY7NZhVgwGg
kuYsRg7GxEhqIg
dps3SQ1T5OZ6PZLhVsIetHpcZoRSg
8JJqNeyAWMzlTg
Ma19xe1YTgtf2OK6mxcVIqRZnacXg
DvzQ0t5pp97lcg
get_Jpeg
jdnl2vuKCY99GEtDVn0dShtrNiSkg
System.Threading
add_SessionEnding
NewLateBinding
Encoding
System.Drawing.Imaging
FromBase64String
ToBase64String
DownloadString
CompareString
ToString
GetString
Substring
System.Drawing
ToLong
set_ErrorDialog
wpC1HZJMTbbhOz8MQ2meOmF42Iqucd6FkHpuIlkdGjJgrNbeWrk1xeHZk52USgHJiTyqodkJe5tJXrg
hymHo61re3Rq5qfx8ClrPd90PCgrhFRFs8zW85h
XHIJAx4C32vqRmVUnQq7NAtq4W1Dh
nlpbE74yNClbAHFsruKVDfZh
Stopwatch
6yMCUBnvwTD55LEEhT6aVYMZSFo9eNPQ2E2mnkh
ComputeHash
get_ExecutablePath
GetTempPath
get_StartupPath
GetFolderPath
get_Width
get_Length
EndsWith
StartsWith
noMdlrcAwhpAAi
mXRgbmPJcSnIFi
Ya68cidKJQFRIi
LhNI44p1ixKgiZKCiwWm1GkUTS17L8OI09R17Wi
6nkolybnCgj2Di3NvCSOxjUjrpmOjmPAUZfYrei
xGUMwdK8aBWRRdX0YW6l7lfi
q1AaL2UPJ65QNlHZ5jCrhaq8F3wfi
nfkxqlxExlugFJYNTGlc6LAG8flxi
KqnVJTUjx3Jf3j
ZRg8rs5jY5j
rt8TXbaotiwWzF5ojZSW8KEj
hlQ4QMIOmsZvuHZvnYcSq4hOY5VMnowQ7kaCvc8L2MbTpcc2dbak6KZB6dnUdzP5Ga3S7V2UKAoXjGtfSx7DREEe81i1nqJj
itacpeHL5rWOxDD2SSjWclKW9V0F3Wytow56dQj
2tx8O8WCXATORj
sRx97CHEjmMMPGtghEtPp7X1WIXTj
YNxfGEPx2WRxGhUOSJcDPDUj
Q6JlmOclA8CXXj
0Q3Re1Jvyx1lhPDN3NYU54jutqJej
LnqOgE6I1kSrEXMfekXgZH0IVnAij
CL1RhozfdyMkaGWHBvT7CbcCr7Cjj
XYNiFKGjaAyzvOzocpW1Y8abKZmqj
DJsLx9AN9Gyz4iAfNc4od6rkqbnBzFupnLzuKxj
VHgZs2riGylt2k
x32WglObnDoKB0T7e3Rh6iG9Tk8DBQBcOu8n6ZaNy2KhzHuOXOGFGNFm8RSwexlXSIUsJ9wdQ2kBKeaTBL4gA3cogvjobF4k
MulP4zrPQEnW6k
SKIpT6yz0fgwP9iK9g3rQREk
cFylx6CsZi4VGegobCKX4KfhS3UFk
caX0ORocRk82VBJTrqurQDd2g1L91wK7Zm7qsne3LP4m2T4VPm3XjxzqFOoWlhGk
QNCPuhpd1cSbTgacPWpKebKIN1vOOxwyc2t0tDZus1vTvVmspdZkXjRNSJ8COxGbeSbqPhtiKQjzooA6oKoXXFeR9tiJYKKk
zdcjCNPKmxQIInkdyVXeF4UKaGYUk
KVV2bsnzZd4rWk
get_ServicePack
AsyncCallback
DelegateCallback
TimerCallback
RegistryKeyPermissionCheck
TransformFinalBlock
2qytIIQ8CWdhjBrUuMBYHHdk
VgKiDbGIUS1XYqFaqhU8K8rMiDRRC4yJfr3oVik
5epMfFiR8uQ7fFh2Akv7FqZ44xFpuU1pzTi6S4mOVNhwQMuyPme3ie4e4ySj5bG2JdjlmdrFrOsLQHE1G6wtnNW8jwHFfRqk
PXxkzj5dF1AVRkWzWeMptavk
3vEK7JapFhB12l
rVNxExyy9MMVndTGoHmevX7H7KhJQpCUFXu90oz2BSyWdgFlbwVsv6K4tZ1BANfXwBGY1hOaJLnAY9l
es4rqHfX1d6cDl
XGEDWptnUN6AEbIICawjTkGRyFvDl
CV3ICJL3qhU5YiU8u4ExdRHl
RtlSetProcessIsCritical
Marshal
System.Security.Principal
WindowsPrincipal
ConditionalCompareObjectEqual
System.ComponentModel
LateCall
kernel32.dll
avicap32.dll
user32.dll
SHCore.dll
NTdll.dll
set_SecurityProtocol
ObjectFlowControl
77axxRYQYN5Tpl
pSoLQS12HYGHsl
fAnUl45ff7A0Cm
wtSHNXNPGQuluKgVmmoRysqQyx2XkFbBrtTJHGm
bKnvuhZk8qxgWrpFBmDbSPmS02UOGjV9OT9YdxT235f3BLMrkGCckcJXP0vmoGRm
FileStream
GZipStream
MemoryStream
lParam
wParam
get_Item
get_Is64BitOperatingSystem
SymmetricAlgorithm
HashAlgorithm
Random
ICryptoTransform
mdCO6mY43MtrAgZfsP9YKQum
vtq6ojGvO9PDNdlxFFf2KAQGpu66IWpAiJzh6Cn
v3ljSYIa1HIJnzVH4IZx3SWWaX7Gn
MxpP3D6B2ZGGEzRt65nJFBGn
DjkDXky7jqU6Jn
ryutHKbK1f1mLz98u9eKMLOn
ToBoolean
op_GreaterThan
TimeSpan
CopyFromScreen
get_PrimaryScreen
System.ComponentModel.Design
AppDomain
get_CurrentDomain
GetFileNameWithoutExtension
get_OSVersion
Conversion
System.IO.Compression
Application
CopyPixelOperation
Interaction
System.Reflection
ManagementObjectCollection
Exception
Environ
vWJwPzfuVARtBE5hTmFCCD0aRvBb7bCaIlbWl3WFMdPoeitWGnR1YFxVQxg6Vftn
SocketShutdown
O6L2ydqrrV2pklzO8RmWhJTNJob1gQM1z5wn09o
Qqx0hiqQqrGJYDlDJQ00obmPamQkGBRJ9CNynzf6IbUmQ6XFBk6iAiPikEfoqWjbZdmNcau9p56C0JRkZRAI5qjTRAq3swBo
5QzroqpsNK3aDo
eYCL8KuZd6nyh2aAmM5cSoAQAO53Z9j3v29dBJo
tyY2mVfF2vgmJo
0SDgbhHI70iwVjCZfWx9NwGzsDATyLRk7pwYELo
zOHlopIFrD32Po
ZclglDt0GZBJoU7ogPHTiVk6KE3Qo
XicJOB0j3mziLSel5qceMCXZP4mQo
bC9nxvWf4Cje7PoHY4MaN8nvh4J3wM6yVEpQHorc3yGWX2qs9RntyzV0xo7IH8eoaAbMnQyHb6idpbo
get_Info
MethodInfo
FileInfo
DriveInfo
FileSystemInfo
MemberInfo
ParameterInfo
ComputerInfo
ProcessStartInfo
GetLastInputInfo
DirectoryInfo
gNWj3YPkf98ju82369BQc7ro
ivtNwXM2gsGmqnJHmlVwoGZ2ES9f644sXuVeBmBCidyyQvWlo4lPYEIE3sG4Qj1p
WxYolsbzpN9ENw35QNSLIoQ5vAqBp
deNAXTPNjGDj3S5ty4fZDbufZrZLp
nPgAKvNjtnZPAZqZpYlp0iYp
Bitmap
NaYOUAyOQ2P4iMZvY9cvyHialJHvRLolqaThp5mE4SHLzL52vxdvTnYPtLVLV6jp
HyskcJk3zR2i6T3GHUZUQ58jx73op
HIBCGlPt5JddBDTi45VGt92qyhHPLS6djMVbWWnZlqaSNI0yxaZvAYkhF0HHBUrp
xQxBGAGYB1q
6M224WwQWlPKIsWfw744FT2q
AkyEBJwFbkKHGq
2Jmi56Z4Ce1LKq
WME96ugEHVL47K03DLHLniBZDXzhCECg3yLduOq
Mvu6EZaRZWE6Z3YMhhptVpSMH39Rq
Ow00UvYPAccv245VSWUxigUIpgLdp5SnkrmR38IaBa7uHpAjXg3cF3GP5hAonQDjfzV9KYCihYbyCkxUjDEQVRq
IOE0UPydTchpfq
55D8A01H2glzqv9MwgCdI5hRbG8lq
dmchNnFNUFcdmq
System.Linq
YsfSJuQstQFaFBPtqq73fQ5wyr9Shw6IRrJslw5MIUmLfIKZitYSmTkCAo1Z6Rvq
QhylRK5krPcj8Ps0WaIasDdYcw1AxL39Et8U5PTtHMpTWAQThNEN36ptpou87wyiAcWiwqnwj2Wf89PCuyWDnUr
s1QCZ0qHCXVep9KGgNWCO3qXMmuar
MD5CryptoServiceProvider
StringBuilder
SpecialFolder
ServicePointManager
ToUInteger
ToInteger
ManagementObjectSearcher
SessionEndingEventHandler
System.CodeDom.Compiler
ToUpper
get_CurrentUser
StreamWriter
TextWriter
BitConverter
ServerComputer
ToLower
lPqNbVZaWzB5fr
ClearProjectError
SetProjectError
IEnumerator
ManagementObjectEnumerator
GetEnumerator
Activator
.cctor
Monitor
CreateDecryptor
CreateEncryptor
IntPtr
VOkKxR0rzVCNOZMsG09LtFvr
IE0BDesyNb6N5aFgm0ytKKwr
UoEEiVXUV9q4CeAAZftwotIMRXKSHCUqWfHHK0s
VBJaxUMf4Lzb0s
7hq7kaLFVtrUsr2nNAicAl2s
3vFcf51Y0E1rpXpVAKuTWuVpzSDmFlXVHMSqp2s
gO8rRU1sVcGI4voa31HTHkN4mKvkpZ2sZ2pX14s
gGmXQncacFnuFs
vRtffoT20aggVs
Graphics
System.Diagnostics
FromSeconds
get_Bounds
GetMethods
Microsoft.VisualBasic.Devices
MyWebServices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
Microsoft.VisualBasic.MyServices
ExpandEnvironmentVariables
GetTypes
GetProcesses
GetHostAddresses
ReadAllBytes
WriteAllBytes
GetBytes
7gbCxBAhmiarDFGKy3TPn21y8cKfs
SocketFlags
Strings
SessionEndingEventArgs
SJWzEFy5AtSYiYdqJGA1UPhs
Equals
System.Windows.Forms
XsepEPE8GSsTWHbz7Vp3Xrice6yb6pI8zfg6xms
Contains
Conversions
System.Collections
get_Chars
RuntimeHelpers
GetParameters
Operators
GetCurrentProcess
SetProcessDpiAwareness
IPAddress
System.Net.Sockets
set_Arguments
SystemEvents
Exists
K3N57y4002FftWYiueOyGqdTIFeekmv2Q0aHWvs
hzprSOsejw8ER7CSepO0KzPCmmWgzykP0SVuF3t
4qz1CGmSpexjDlrpxvlw7wNX3K3sYfkwi9alK9t
MusU6PK4x06xXXl1TsVNZHHt
cOUII636KVdZHt
FcJvEWEG9fQGcME7BnFlUgllTO8F9VFLevNm0Jt
50CwQNmA9D32kPQbBT1NedIs988Mt
AT6BA54q9bpqNt
ZiD2OM4qtbLpOt
JtxWZbPPqIb84CUFcR2xGfbXVGGPt
Concat
ImageFormat
PixelFormat
ab70EYHd5GAnzy7EOqgjidR6trEbt
AddObject
ManagementBaseObject
CreateObject
ConcatenateObject
SubtractObject
TargetObject
ManagementObject
Collect
Connect
set_AllowAutoRedirect
LateGet
LateIndexGet
System.Net
Socket
CPcrVKK6Brt1yI49xNnBOsYD0bPft
get_Height
op_Explicit
set_DefaultConnectionLimit
GraphicsUnit
WaitForExit
IAsyncResult
DelegateAsyncResult
ToUpperInvariant
set_UserAgent
WebClient
System.Management
Environment
get_Current
GetCurrent
CheckRemoteDebuggerPresent
ManualResetEvent
get_EntryPoint
get_TickCount
get_ProcessorCount
GetPathRoot
ParameterizedThreadStart
Restart
Convert
$VB$Local_Port
FailFast
HttpWebRequest
$VB$Local_Host
set_Timeout
GetKeyboardLayout
MoveNext
System.Text
ReadAllText
WriteAllText
GetWindowText
SF0lxwjLqxCb6u
XVbAF4jtME9i68tf4sSgoxKRilC8u
CzvuwOWaz1j6LITdMWK8aAbZdE1XTVKlsQCGpYLZFedmSMbUVyTkVokUiAtuKfuZwYjA92eJmnOYCDu
YkHAo6rldl0nYK11jB81TprtUMJl2dqTlxRqQNu
IwgvE7O88ltIV3Ce8lMJe32v5oSNu
Xypux0hVO4bH8jAGEn1ivlq7i3gvcNfhnFKLOPu
ZpIEYYrdClpYPu
KYtKhaGsgbbKfu
bh06RN8JvMRvou
akzBaJOcZQJ410UXnynboB7OkQNvu
zjcXbAHTKzZwFV9xEM1ryNqtEWnFnO6VN0upGFv
zFU6PEGcbx5XFv
9CRmTTJoHjjLpauJl2cy4AQv
QFCxKbM3TVjRHCZNZucQFoTlmczCygECA1vGmjv
DftK930QtOqH7qBN1pZ4ebgSM8PvDy7Mp3doW5Mq8FYYu45qOrfzljXr6lEfFMlKdwTRsjX7bstpauxZIYouklv
91575qvrWICCGkl0YWWYEHlUGbbesjiGfSxRgDUFBoosbTuM3sribiEKNrN4LE5PHOCljqR2KlHoxo52vPfzNjySTGQQpepv
oDCvyUkdx21Dvv
ixjoYhNsWXj30w
hGngWN6oF78GgDwU1aeLwUv4EDP2w
WzYSqoCS9RLkdCFbueFjoV21RiGPw
Jk4zT1iCa7HPOYoHQHQzLggTMz685IQVQu9k54ZkOXFwQGXBzxQFg4FFzVle3mGYosh5dE3nibrrE16QxnHHNVw
GetForegroundWindow
set_CreateNoWindow
P73T7ZQUXVDMEhZdQcLdET08sZcvw
oyEZ8X7lM8ON1x
zTAgGd9rV0CaDx
ToUnicodeEx
UnhookWindowsHookEx
SetWindowsHookEx
CallNextHookEx
FLdlXuZhml93AhE1zbhY5eHsQjywy9utjG9w3PIclAkS56hoF6eRP6hNjxo4oHIx
iVddYDEKz8HEYLvlhNniUmJx
ROADchXzaOyiDitotyhSdAesaVGXx
LateSetComplex
p5YGdzfAyWwktx
LvQi5ls9FUYVSWTR7wlukkilkb6unpCOHFgbbvx
MyB0mnFQoz1ZwGnvNjK7aiFJWCfzx
awGLWRCclgiR7y
m76DK1qWfm48yjm55ajEGeBc8eTBy
rYW3XJnf4vwjNy
0lhBRktfrvRHJbX0yrCI4seGIOhQy
HbHrsqmmePjsfOHjcKjxViBeHE0NMRX2ap1LCNzThEQ0k6V40ImiQr8cOAyST9xvftoVJET6nfpfHZy
ToArray
set_Key
CreateSubKey
DeleteSubKey
OpenSubKey
MapVirtualKey
RegistryKey
IX9UQ2HSAzXPey
mquFdeSrAwa7xFrzaTBjzPd2NXUey
System.Security.Cryptography
Assembly
AddressFamily
ObjectQuery
get_TotalPhysicalMemory
get_Directory
CreateDirectory
get_SystemDirectory
get_Registry
op_Equality
WindowsIdentity
IsNullOrEmpty
RegistryProxy
NdEFPb38iq7vKAUUDTP8nUlMuK0yy
KQodwFgaZe4R60OAz4wDSrd6584hUzboYAM4wLz
3WfPOnMrJ7zfetgI50K2n2ymqiagY0jhxckmuQz
MNO0PcPU79GtAkiKEvUjM6kz
xMg0qw4CVVhbdrTdSBQ23GCwgY3vY5jWa3saask9Xaf2aNcU3Lu4eQWL14dS1arC3nH1ZIT3uNmlXlz
Et5uDeeX4X01fVn4d74tuGMRFuGAeRfQRSzDkoz
WrapNonExceptionThrows
$49640928-7c9e-4e98-847c-8a64abb52862
1.0.0.0
MyTemplate
14.0.0.0
My.Computer
My.Application
My.User
My.WebServices
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
<generated method>
<generated method>
_CorExeMain
mscoree.dll
q_IDATx
@B$x}/_@6
?40[&A?B c
_ Tr&H
&@RVT_
^4(-=8
4*_6oX
{d))C"
$BHC/0
Oov\f+7
/z6C`r-
p(`b>ad
4n_A}
rG5d^@
#M ?T3d
@Rox(T
NJN%\(4
ka#%ej
4?*^>K
`V-8\f
CVR2F1
lOet9%
q'bbs/q
Tt3$PV
z)m4P"
o@vmQ6
A>T2?`6r
[CdS0l
4~zRhz
<=;5`X
76C!0#$
L/_W]d$
hiR?z[
\! 1f"
w Q*(Z$
EM}a]s
%jN}A@y
.!jkpw
<GyMPX
]_f263D
rEb4>J{
$p9";F
T6I Qkx
-"t:x
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
RgClzeXqbWOHFU
MQxtFBcF50QCyXGWMiA7Ifbj4m93VAkYX2QzsyG1fnTJeX8LUaNxzMOFud4pbUBUow1PrhyMHFb8IIC
xjjMsjIdZDG783PZ9tt0rcoVuAmYpqkgl9Y6BlNDX4m78z06Zw8vLpn5VOL5VRJAORV4GQvVBPzONuB
Y0Fk4PM4LCYjipMUfYITwoHj45iM72JDUt0OeTDFvZUoBMiOygHjXOjBsqjFKF99tGqbHkcW0ZF4YvN
RuGRmeXmudfa7UVH3Edj1rRuSWbED7NpY5UOGWcrIQkQ62HpthhI6h7LV9LHQhNFT6QaEdaBA9XZxrY
h91t3bQhaHT9G35GquW0Z9JmeA1M7KG3zGfclUPAftWSNtvFUhQjjc2uZeAfI43NnqNK2dUAK1acq68
JkfKpdgOKkZRJ0OdeOztOUyLqjbAxlszgE4SgrrqSfS0juD3oT4Fubkv72q2Gp5fARfWLI8c4zNpYeT
FsAO6A9ZdjFyBZNwaVlIkw==
BqpyEwZHz8ApUD8hwnSzMg==
IeDxMQLvu3xDYSo4l9AB+g==
zk3F1rGZ1eLhQvJsAkgokQ==
x4ZaQ5Hn2R5cT4WAMdM+yg==
OX31OEyMN/5qtRrAl2GKNQ==
ZlCM1f+rWxZdk4TuXy3VAQ==
hJSRx1xdYlPck0ynM0/ChXzA/+PlIA+P/eiszTtp3noVCkwGeFkSxQ7y7kBPHhE+
oRLySGX7fI9tVuHC
\Log.tmp
rtkUkbjDs5Doy8tiW5cgOjh75aHzsad7nzfruhPuYMvCrOlyoQXlRdYp9xxbLZkDYIvBHBaSkUv9sRD
0p4mxW0rGFXKvYQ2haOh8MMwJKisRQ3v6MqG9ZQAOUv0Or4Bdk04ahRWXqFGFFTPmIcESGcLIy2wevp
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
WScript.Shell
CreateShortcut
TargetPath
WorkingDirectory
powershell.exe
-ExecutionPolicy Bypass Add-MpPreference -ExclusionPath '
-ExecutionPolicy Bypass Add-MpPreference -ExclusionProcess '
http://ip-api.com/line/?fields=hosting
Select * from Win32_ComputerSystem
Manufacturer
microsoft corporation
VIRTUAL
vmware
VirtualBox
SbieDll.dll
mQJANLwsfimXefRbziGPEAH1cXSeKvlzYwD5GCSfD7pRrLcIdP670CVlhpDkbqoQsjBxuQqq7Z2nkLr
DE6skI5myiDKLUKt5cxWyggK4b5vdcE14hHZqrOtFXks0AC0Ny5JzIThWpq5LNqfz3xKIY6fxzD3xbv
WHOOM40XgCruUhHVCTxIt956yJgfUzqettYdVIxmp3ubZdbCd1QQq4x9JNoDIwgvy9VZPldflN1pfaf
SRa6TVd8CaO3D4tOyt9LoH4gCpausJWBSCxurn8JZUHPBTsg9P653M1FzdpPtY4jElT64yCuFKt8yvG
J0JNxLKyVz3waUe1O5XyVRqEL3yMKaVaGFMCGSsIjJmm3DfubaJndSwjJaQTDNaEut8u5tdYHHXGoUl
W0nW8VuD60eqT3x9qkZiQ0m0SDeO2wiQnNtmnJOUGxonvaKURPU3jMjha68OOcdIMd98OBdRbd1uI7D
kWEPxTEw7EoCOa5rVGHV98aNSCkXy6gqzxv1XX10kXuQrfXcn7oRwxgYSVQ0oyMVbbRdMHjQwyARG64
3qnpVFBFrJr8NfNlruaDrGOrBBGYCrjhsVg0Mr2w7vcfHhC5AC1VH9LxfavlDdf5
S8TNdgOqQeRTBFzJAdFfNuzYMB4mco6bL3JrTzX9NhZ3vVF9Y8H6yUjFHy9Bjd40
oT4ZfAtVvFZKEvYNSEL5Dh9FE88lvZFll9cwNAvnLSJWekRmPZd2Pejp7VUOpWXR
MHCrNNJFEX2G6JnuScjGfD1eO3jkkWZQafg8MG81lwJ0mJCuG4mOYYkyUtNeyC4p
EnTP8zm1ovdWtKpu69W5cSeXAOWSbki3SQe6bztBjDBT32GxojvWRyIjBL02oLOQ
napaUCBRKH2nyEYqp4tXG6oLD9qDbaevIdA3IegUTyfjG8f8vjGzGhcyoOHB1DCf
x1TkNpnWwzmj8EfqbG0wDj5dE0zLYITekJLE2QzxK4mWlhbHBKYiVVg4kOMHbbuf
Microsoft
Service Pack
dd/MM/yyy
\root\SecurityCenter2
Select * from AntivirusProduct
displayName
SELECT * FROM Win32_VideoController
Win32_Processor.deviceid="CPU0"
Core(TM)
wW96cVtTsaWJ0LJbGxtYDfBl1Byuv5jAAPTSlfSWIXtChZwCwlKNt4bb5qoccEKh
Z9Pym7821tJw6eva4xbbTfXtvWzME8HNaKXA2NNFE9ghgJOhxfctqCSr1S7LXWXU
ow8h6B2gKXw8Pjr6z7hn22fiWAfJtQeNTm6NSrvh9VTNInwsEpagpoF4wf6Sn35g
i6bmYus4XvBHCczyWAVOcZqA4rcoHWx59RxJkfiRI3U9G7YRy7wsaNJxBd7RjtGp
ix7BMqMVu2NPN7rUM0GptwdoitBCOLmqLC7a8J4pfjXRPLdVzbKFSE5jOKFGOJfE
TGvLQaZTexvhzdQRORSANyuxilxuWvLYnqxZ0iqtIUWS694dhQIN1xnKQ0bqdqnB
lHV3q55GMtbEJ2s7pXASi4NqOjaoxPMqgBxLKDcp7ty0eIEmwO2Q0Ox1hBcIozgS
Zm0TZHTWwdLKZJDeB3Uv645vHBSPVcGtHrSlKuFvPULiE1nZfPBlm8mado7uie7R5yXpsYp0ERjywxQStWLXRdDk33n9fd47
TJ6MbByOwlJNnIJBD1omhn6GpeeBHLAgzNpUsv3WtN2o8Poit9021LvrTXUSnJqQW8h0eiewYr8ygIkwXMcXBednmfKKDu6I
C5kxVHbS3wOi8lV1JFkdpoBcGqMuJGA2zNeJPY56F3J8nuWamCo95TMeuZmg38eWkh1NoBIJbrIIk3eTKfHrvemP4NhDJ689
obzJN2tFOtVrv7tCqvoBoaF1dyGE1Le7OHdBmHxr8Nurhy8tvg7QyprW9ugC5weEmy8cNEPT65PQ0SbZu44w2LMwmPrXmxLU
hRyjNWpCxxsVaXTUJ6YtOjui3K40kOO7bF9Wo6dGtr7ysDAsWXwOcDtHQUUrD6R1txJt2G0tgOSYBivH9fQP29SdNAgCHx9T
zBkuC57ZWtUrM6QvBOOVa2g3CdqWoVnnr4BXOlt445JiXKm7qLFGQyWX9XPsahPsh8j5pWXKcP2KEDrAXNCqzjMC54nmpOqO
GeMBtWkATZTmSysZu0eG8FLoPv4l3b2ZYwRFgmeF2Wgyj3L8ncWhJuRDXAn8ub5ocJ6RRcUKRkP4j8j5YvaQw0cbsJMXdSHK
sDj5ZOphpii6G2HOXXrkbbJfIJ1vSC5RPM5XE6gDjab7C0fiSGDwdrOjlNK8etnsPcUgKh160ZYDSkfuTY4QilVRrIrXnPDt
WvS8aW0y0CC8g7gnwZPALhLqQTPBlWmRPH8vgAbXJxA22pq14ChqHPMwss34rgb0L2pQ6IrkCQ1tnoFsgps8iEvM7DdtBXup
xZOOgaq0KuqrJ7UluxfbqQ79wyYXilDxoHJR1UzAGsIxkFnMz0fzCB9gemokmmedZSwRBXmHXZH1PgD5DRwxHfKhBwQ5hreN
XCpEm4Z2hwR8iwOjgsguyjCTHaI8vKx0aiwoSnr6bGJkBPWoYCMlKFAZafxv7zPKtpFHdruSCWWLEwOZn7e18Ri2j6K0mVRR
aOpNAldiJsB4FLZHFGQIGAZVqs061Ui7YW5Ge0iVULamcS2pHpA57EKy3Au90QYsorUl25IU09Ggpaz1FoWM6SXMwK2VnP2o
2txyOq3b55FVhE9X5ACY9ZE8D1xIbIYxlajKUJK6zXXwJb9vwjCBuVC1E5HNdc8w34L0TIJfvSGuR10w05MOy1pqFXG01IP9
Q4zJf8iyz0LEFzV8O5UUr5bBlK3blfDSswrbWvPseTLHvT6CFWfzmLzSEHr59MKSc1F3g7cODmCuvUeZHdA9mVHn2e8tJSFZ
uninstall
update
Urlopen
Urlhide
PCShutdown
shutdown.exe /f /s /t 0
PCRestart
shutdown.exe /f /r /t 0
PCLogoff
shutdown.exe -L
RunShell
StartDDos
StopDDos
StartReport
StopReport
\drivers\etc\hosts
Shosts
HostsMSG
Modified successfully!
HostsErr
plugin
sendPlugin
savePlugin
RemovePlugins
Plugins Removed!
OfflineGet
Plugin
Invoke
RunRecovery
Recovery
RunOptions
injRun
UACFunc
ngrok+
Plugin Error!
ToLower
Open [
-ExecutionPolicy Bypass -File "
bsmhuFHlCLgMsgpTGS1ybguUhduqvdkgmh0brhpsPGTqHuuGktaS9ctCr6EVfCpEg2Q81DeUc58rxdocCpSKTsmSJ7TVhNz1
EDJ8LSADkL0VZ2jTowbiYcBImBvLF0wyolRcRNWmPAQsylmReomRWYPvbSbbZAJtmUdoUrGuH7rMcL8iIANq231ptCmDHGcg
jGtMWCeERGz0C0djpYGh8w3Ume8o851HVdcFvGG
6z4TPdhJ5Wo74UeKiNUEbVcWDKEeMbKw7baJcRM
A6RGb3HkMYw8cnDyZZ9gK8zYA4V33BEGkxRef9E
Mhv7eupHQai9ROf4wHnzCSIxM8pNje695l2dqAk
8VGthV4jUCEDhchkcPjuHtTBfZ6trEBx2NkupXz
9J3qKAZLIsWFU1jiaVRNu6DU2eUl9tPOXMBqLnf
IgAass5sLjYSnAMR5XXRVttVoOp1LOluvqQRm7x
97nMjKoY7iXB5CfEiTg6DwPf7hCFCidxVe4lurT
xk95tmBtyT8wg2LS8vA7jrqKqTVZzoATiEcaurt
RH0uge3eCa464xutZ2el0ntrbsDvbB240OX386d
22TsCpbLeGcEk5ox3Z3jpGHuoSXgA8qPMVgbnU7
iAzqwIzLnTDulJQnoEt6hxBJahUTMZ4dHjjeA5m
KDNuOpQMvD1psRzb9hbBnFGLVOoULlFATTJaEbh
lK0Yfq4rFHbPclWposJlNMV6TBPQJHngBulrvhD
POST / HTTP/1.1
Host:
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
User-Agent:
Content-length: 5235
@echo off
timeout 3 > NUL
" /f /q
Cn77UKeUEV5Nhrx1cEztxqgsEL5QBnXGMLqtvvt
DOYnjePk76wIaGE9NoIUl0rqlhRqLrReSDRGYPi
ToUpper
[SPACE]
Return
[ENTER]
Escape
LControlKey
[CTRL]
RControlKey
RShiftKey
[Shift]
LShiftKey
[Back]
Capital
[CAPSLOCK: OFF]
[CAPSLOCK: ON]
MainWindowTitle
ProcessName
4lgCKvPt5zHne4wE1zaK78UQcNs6LJqCFRA5og4
1Za348rkz6Tn2LluEzEkNAtGDb6uBm8ymmOu42V
0zoRX5fVBcm6w6K5GCulIOW18ExDv1dUcZFrGw8
NyMVPh1ye1oRh7yL7t0BVZ2w0apKg9C3aCiDypb
LTAFrMt9AKopjOFFAa5wj5RGthWCXod1WaLoM0d
HzPbXeCz5dQrfrOClpw1MGE7uIkMXLFtNMhvhaf
XIqIitcIaHGtkqaj35I0TNZK0SbFAbKpJUhIFIy
RpEjx256CKee0Sk2Ay5AmB2CFssN4YBMjEbDT3R
TZRywZLjKYvEMZnRYUQ0MnxdYn3DaggxJccl1Qd
xb66rG0YV9HyYRBzOGO0mMGYMS4pjSoR83DMvWP
l5tclWJqEiREygYE2eZDgRS5k0KZ12M3GBVdbPN
v1xPiGxZgUbTXCN4WzmutyGcXUMRPi6iRrq4Ofm
ESrvMsUzWEzfAiKcVZDjNM8pqGbzCnbSpWYXXNq
sPlSwI3w3DLPRWwwwn926Ww5D3V9M08P7UJkFdK
KXdyRUQaI05ZqGT5sTcHEbpezLCSBdErjAhOYwd
WMBFChzbTdaLJWBmXFm1BJcJY4PkKlbFfb3B4ye
77357JgHHMYDwxpeIEkClE7Je4Z3jOxOHQrJDID
HWQEejCcIfRGReHNGk8zUYTXOMS5Jia7tXhTYBW
LPd5ZbssgGxHpgE2nopoH8yrvCLcsidGzz2TXLx
cslTTlreIFJP4UWtFKWoSHoYiuMYEBGdnFuhvnR
qBLHjmaAk5IjBivQ5keMqY7uzlHArWjV55FvzqH
Dvz4t6EPg3YtAleP6hXcaGhw8J6Ss4JdCHBjGyy
BHfPbU535mYCTfzLkmwvnSmkp9YtvX2kCea5Gr5
9klZVgEqr21C14MeR9EzAG4vvUOGbYM8bA631CC
QNANb4dufv4pPLfGhimiMYfTYr4nEI3GpZKR9yt
Software\
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
abcdefghijklmnopqrstuvwxyz
Err HWID
ToArray
6mDHOjAf97yWTfAoiTLah5Ix
Xm6HNZRGGuWOjMy0SxprZzl1
34rhanex4qHbdQyeCEV83lWv
1E8elsXKXRkSB98eU2vmXOir
PpkS5Z4J2W8qhZy6ErmxqQCh
Qa4PrGkkRvgDazT4QMW5Fquh
CqXOgIltU3bsdkvnMewGneBU
cNhrO9GR3Abym2APaB6S26fe
M92zBnwt8d6eS8YCpbGhS8kc
sIFbVU2P7jLJPJjVSqKsTaDt
uDBKmEMm6Qd0zS0UU8vcwVJz
8ZKMMUCTK6MyUR2Uyosqxrdu
BSvAVlJeYjk2mJxyXxo81Lge
dpAQAL8kg1WY0QI0oSrJ6XSp
SEOxAUQqWPmbAr9wJUPst6Jh
fBkeV14kltXAemINGZVjCNHz
f0tSrPLMrPko83YIxCG6milq
TLfMGCTCxLOcNFKZJS6fk8O7
NA86jQAB8t4k589bbDy52tfF
y1VPWqEcNP6TzneZFRaXxhXP
gkd7uERzjyE3KHQvaIE4qFGt
ff0mKrupwxl4BYv3tGLNTFGb
er4DL97NhofxFJknvxqcxqod
a3vPvlT5NhmXHjkGlKyAkhWC
igjWl03CTf2c5SxDJhEL89qJ
FzfVL5WJu4Wr8TBrQlcaoF3L
4wzp7foigs2itPdLPN0wLdyR
3JiuZsT3yjZN2m0c2B09hvbQ
abcdefghijklmnopqrstuvwxyz
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
1.0.0.0
InternalName
Microsoft Service.exe
LegalCopyright
OriginalFilename
Microsoft Service.exe
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
No antivirus signatures available.
No IRMA results available.