Static | ZeroBOX

PE Compile Time

2024-07-12 10:24:41

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00042404 0x00042600 5.62734162239
.rsrc 0x00046000 0x00001017 0x00001200 4.76801789589
.reloc 0x00048000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000460a0 0x0000031c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000463bc 0x00000c5b LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
KDBM(
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
$I161-0
_Lambda$__161-0
_Lambda$__22-0
__StaticArrayInitTypeSize=10
__StaticArrayInitTypeSize=11
IEnumerable`1
Collection`1
ThreadSafeObjectProvider`1
List`1
__StaticArrayInitTypeSize=32
kernel32
Microsoft.Win32
user32
UInt32
ToInt32
ToUInt64
ToInt64
DLLFunctionDelegate4
DLLFunctionDelegate5
ToUInt16
DLLFunctionDelegate6
get_UTF8
GetModuleFileNameA
SetWindowsHookExA
DATA_BLOB
get_ASCII
get_URL
set_URL
get_formSubmitURL
set_formSubmitURL
BCRYPT_AUTHENTICATED_CIPHER_MODE_INFO
BCRYPT_OAEP_PADDING_INFO
BCRYPT_PSS_PADDING_INFO
System.IO
TripleDES
CRYPTPROTECT_PROMPT_ON_UNPROTECT
CRYPTPROTECT_PROMPT_ON_PROTECT
CRYPTPROTECT_PROMPTSTRUCT
BCRYPT_KEY_LENGTHS_STRUCT
get_IV
set_IV
MoveFileExW
_Closure$__
Dispose__Instance__
Create__Instance__
value__
cbData
pbData
UploadData
ProtectedData
GetClipboardData
cbAuthData
pbAuthData
SECItemData
ProjectData
CryptUnprotectData
aaalogshsindgdaLogndta
System.Web
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
KeyboardProc
ThreadId
pszAlgId
GetWindowThreadProcessId
get_nextId
set_nextId
OpenRead
Thread
get_timePasswordChanged
set_timePasswordChanged
Interlocked
get_timesUsed
set_timesUsed
get_timeLastUsed
set_timeLastUsed
get_IsDisposed
get_timeCreated
set_timeCreated
m_FormBeingCreated
get_HasExited
Synchronized
get_id
set_id
row_id
get_guid
set_guid
Wekakekakd
get_passwordField
set_passwordField
get_usernameField
set_usernameField
record_header_field
ReadToEnd
Append
set_Method
TargetMethod
get_Clipboard
CloseClipboard
OpenClipboard
get_Keyboard
get_Password
set_Password
get_encryptedPassword
set_encryptedPassword
_password
Replace
CreateInstance
get_GetInstance
instance
cbNonce
pbNonce
VKCode
GetHashCode
get_StatusCode
HttpStatusCode
set_Mode
FileMode
PaddingMode
CryptoStreamMode
OpenMode
CipherMode
XmlNode
get_Unicode
get_BigEndianUnicode
VKCodeToUnicode
UrlEncode
FromImage
get_Message
MailMessage
AddRange
CompareExchange
CredentialCache
EndInvoke
BeginInvoke
GetEnvironmentVariable
IsClipboardFormatAvailable
IDisposable
Hashtable
Double
GCHandle
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
Rectangle
set_WindowStyle
ProcessWindowStyle
get_Name
set_FileName
get_MachineName
GetElementsByTagName
get_OSFullName
get_FullName
get_appName
set_appName
get_UserName
set_UserName
get_ProcessName
GetProcessesByName
astable_name
item_name
get_encryptedUsername
set_encryptedUsername
_username
get_hostname
set_hostname
DateAndTime
DateTime
ReadLine
Combine
LocalMachine
DataProtectionScope
get_encType
set_encType
ChangeType
GCHandleType
ValueType
SecurityProtocolType
SECItemType
GetType
set_ContentType
item_type
OpenShare
Compare
Capture
ConsoleApplicationBase
ApplicationSettingsBase
get_Response
HttpWebResponse
GetResponse
FileClose
Dispose
StrReverse
X509Certificate
Create
DLLFunctionDelegate
MulticastDelegate
KeyDelegate
DelegateAsyncState
GetKeyboardState
DebuggerBrowsableState
EditorBrowsableState
Delete
ThreadStaticAttribute
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
StandardModuleAttribute
HideModuleNameAttribute
ObsoleteAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
MyGroupCollectionAttribute
AssemblyDescriptionAttribute
UnmanagedFunctionPointerAttribute
FlagsAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ParamArrayAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
AccessedThroughPropertyAttribute
set_UseShellExecute
get_Value
m_ThreadStaticValue
get_StringValue
_stringValue
GetObjectValue
GetValue
AutoPropertyValue
set_Expect100Continue
Remove
Remington.exe
cbSize
get_TotalSize
Deserialize
Initialize
SuppressFinalize
SizeOf
get_ItemOf
LastIndexOf
System.Threading
set_Padding
NewLateBinding
UTF8Encoding
get_Encoding
GetEncoding
InitializeCaptionLogging
System.Runtime.Versioning
FromBase64String
ToBase64String
GetResourceString
CompareString
ToString
GetString
Substring
System.Drawing
ComputeHash
get_ExecutablePath
GetFolderPath
get_Width
get_Length
dwMinLength
set_ContentLength
dwMaxLength
EndsWith
PtrToStringUni
AsyncCallback
DelegateCallback
_hookCallback
RemoteCertificateValidationCallback
set_ServerCertificateValidationCallback
add_Tick
remove_Tick
GlobalLock
get_CapsLock
TransformFinalBlock
GlobalUnlock
UnHook
SetHook
CallNextHook
AllocHGlobal
FreeHGlobal
Marshal
NetworkCredential
Decimal
cbLabel
pbLabel
System.Collections.ObjectModel
System.ComponentModel
System.Net.Mail
LateCall
kernel32.dll
user32.dll
Crypt32.dll
ntdll.dll
bcrypt.dll
System.Xml
set_SecurityProtocol
Control
get_url
set_url
set_EnableSsl
FileStream
GetResponseStream
CryptoStream
GetRequestStream
MemoryStream
TSECItem
get_Item
get_FileSystem
SymmetricAlgorithm
HashAlgorithm
get_httprealm
set_httprealm
Random
set_From
ICryptoTransform
root_num
Boolean
SECItemLen
get_Screen
CopyFromScreen
FileOpen
System.ComponentModel.Design
X509Chain
get_OSVersion
dwInfoVersion
get_version
set_version
Conversion
Application
System.Configuration
System.Globalization
System.Web.Script.Serialization
Interaction
System.Reflection
MatchCollection
GroupCollection
WebHeaderCollection
MailAddressCollection
AttachmentCollection
direction
CallingConvention
WebException
CryptographicException
TargetInvocationException
InvalidOperationException
get_InnerException
Environ
Remington
add_KeyDown
remove_KeyDown
get_ShiftKeyDown
get_To
CompareTo
get_Info
FileInfo
CultureInfo
DriveInfo
FileSystemInfo
ComputerInfo
get_StartInfo
ProcessStartInfo
DirectoryInfo
add_KeyUp
remove_KeyUp
Bitmap
hwndApp
ToChar
StringReader
StreamReader
MD5CryptoServiceProvider
TripleDESCryptoServiceProvider
BCryptCloseAlgorithmProvider
BCryptOpenAlgorithmProvider
StringBuilder
SpecialFolder
sender
Buffer
ResourceManager
ServicePointManager
ToInteger
KeyLogger
KeyLoggerEventArgsEventHandler
System.CodeDom.Compiler
ToUpper
CurrentUser
StreamWriter
GetDelegateForFunctionPointer
BitConverter
ServerComputer
ToLower
JavaScriptSerializer
configdir
get_StandardError
set_RedirectStandardError
CreateProjectError
ClearProjectError
SetProjectError
IEnumerator
GetEnumerator
Activator
.cctor
CreateDecryptor
CreateEncryptor
IntPtr
Graphics
System.Diagnostics
get_Bounds
Microsoft.VisualBasic.Devices
MyWebServices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
Microsoft.VisualBasic.MyServices
System.Resources
Remington.Resources.resources
DebuggingModes
Matches
get_SpecialDirectories
GetDirectories
GetFiles
GetSubKeyNames
GetProcesses
System.Security.Cryptography.X509Certificates
ReadAllBytes
GetBytes
GetDrives
CryptProtectPromptFlags
dwPromptFlags
dwFlags
Strings
KeyLoggerEventArgs
get_Ticks
ICredentials
set_Credentials
get_DefaultNetworkCredentials
ReferenceEquals
System.Windows.Forms
MyForms
Contains
FFLogins
get_logins
set_logins
System.Web.Extensions
Conversions
System.Text.RegularExpressions
System.Collections
RegexOptions
get_Groups
get_Chars
get_Headers
RuntimeHelpers
SslPolicyErrors
Operators
OpenAccess
get_Success
ExitProcess
GetProcAddress
MailAddress
get_Attachments
get_MyDocuments
set_Arguments
Exists
get_disabledHosts
set_disabledHosts
RemoveAt
Concat
Format
Subtract
AddObject
AddrOfPinnedObject
ConcatenateObject
SubtractObject
TargetObject
set_Subject
Unprotect
FileGet
LateGet
System.Net
PadRight
get_Height
op_Explicit
WaitForExit
cbSalt
get_Default
IAsyncResult
DelegateAsyncResult
result
WebClient
SmtpClient
XmlElement
dwIncrement
sql_statement
Attachment
Environment
XmlDocument
Component
get_Parent
GetParent
get_Current
content
KeyDownEvent
KeyUpEvent
get_Count
RecoveredApplicationAccount
arenaOpt
outItemOpt
szPrompt
BCryptDecrypt
BCryptEncrypt
ThreadStart
Insert
Convert
set_Port
FtpWebRequest
HttpWebRequest
XmlNodeList
ICredentialsByHost
GetKeyboardLayout
set_RedirectStandardInput
get_StandardOutput
set_RedirectStandardOutput
MoveNext
System.Text
ReadAllText
get_InnerText
GetText
GetWindowText
cbMacContext
pbMacContext
get_Now
GetForegroundWindow
set_CreateNoWindow
get_CurrentWindow
_currentWindow
_newWindow
ToUnicodeEx
UnhookWindowsHookEx
CallNextHookEx
LateSetComplex
get_TimeOfDay
get_Today
InitializeArray
ToArray
CopyArray
get_IsReady
set_Body
get_Key
set_Key
OpenSubKey
MapVirtualKey
ContainsKey
ProcessKey
BCryptImportKey
BCryptDestroyKey
RegistryKey
Identifykey
System.Security.Cryptography
get_Assembly
Multiply
BlockCopy
LoadLibrary
FreeLibrary
get_TotalPhysicalMemory
CreateDirectory
table_entry
sqlite_master_entry
Registry
op_Equality
op_Inequality
HttpUtility
System.Security
System.Net.Security
BCryptGetProperty
BCryptSetProperty
set_Proxy
IWebProxy
GetSystemWebProxy
ClipboardProxy
FileSystemProxy
SpecialDirectoriesProxy
WrapNonExceptionThrows
Remington
Copyright
2021
$256d2426-b4cc-4996-9a99-c8e915357eef
1.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
MyTemplate
11.0.0.0
My.Computer
My.Application
My.User
My.Forms
My.WebServices
System.Windows.Forms.Form
Create__Instance__
Dispose__Instance__
My.MyProject.Forms
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
3System.Resources.Tools.StronglyTypedResourceBuilder
17.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
17.9.0.0
My.Settings
Keyboard_TimerTo_Send
Screen_TimerTo_Collect
Clip_TimerTo_Collect
Clip_TimerTo_Send
Process_Killer
Repeat_PW_Timer
Repeat_Cookies_Timer
Repeat_Downloads_Timer
Repeat_History_Timer
Repeat_CreditCard_Timer
Repeat_AutoFill_Timer
Repeat_TopSites_Timer
Clip_Replacer
ContactRecovery_Timer
BPlease refactor calling code to use normal Visual Basic assignment
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="utf-8"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<!-- UAC Manifest Options
If you want to change the Windows User Account Control level replace the
requestedExecutionLevel node with one of the following.
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
<requestedExecutionLevel level="highestAvailable" uiAccess="false" />
Specifying requestedExecutionLevel element will disable file and registry virtualization.
Remove this element if your application requires this virtualization for backwards
compatibility.
-->
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- A list of the Windows versions that this application has been tested on and is
is designed to work with. Uncomment the appropriate elements and Windows will
automatically selected the most compatible environment. -->
<!-- Windows Vista -->
<!--<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" />-->
<!-- Windows 7 -->
<!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" />-->
<!-- Windows 8 -->
<!--<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}" />-->
<!-- Windows 8.1 -->
<!--<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}" />-->
<!-- Windows 10 -->
<!--<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" />-->
</application>
</compatibility>
<!-- Indicates that the application is DPI-aware and will not be automatically scaled by Windows at higher
DPIs. Windows Presentation Foundation (WPF) applications are automatically DPI-aware and do not need
to opt in. Windows Forms applications targeting .NET Framework 4.6 that opt into this setting, should
also set the 'EnableWindowsFormsHighDpiAutoResizing' setting to 'true' in their app.config. -->
<!--
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
</windowsSettings>
</application>
<!-- Enable themes for Windows common controls and dialogs (Windows XP and later) -->
<!--
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
</assembly>
! "$)3
! " $#%#&#'#(#,+-+.+
WinForms_RecursiveFormCreate
WinForms_SeeInnerException
Remington.Resources
http://varders.kozow.com:8081,http://aborters.duckdns.org:8081,http://anotherarmy.dns.army:8081
BsrOkyiChvpfhAkipZAxnnChkMGkLnAiZhGMyrnJfULiDGkfTkrTELinhfkLkJrkDExMvkEUCxUkUGr
$$HASH##
$CheckFile$
$CheckText$
%is_SMTP%
%is_FTP%
%is_Discord%
%Telegram_Side%
%is_Panel%
PC Name:
Date and Time:
Client IP:
Country Name:
CountryCode:
Region Name:
Region Code:
City:
TimeZone:
Latitude:
Longitude:
Stub Version:
Country Name:
%$MailSender$%
%$MailPassword$%
%$MailServer$%
%$MailReciver$%
%$MailPort$%
%$DiscordWebhookURL$%
%$DiscordUsername$%
%$PanelConnectionApi$%
%$HostUsername$%
%$HostPassword$%
%$HostURL$%
ZcJNv2N8wFxNVGV4V9jeo8rQAIataStaa4Z8rfO6Vh81a0JgLZbK1benYNcDBkQp
P6TpuDrw8S3LjGPqLj/i8g==
Yx74dJ0TP3M=
%$Outlook_Tele_token$%
%Outlook_Tele_ID%
ZyiAEnXWZP
EnabledAntiBot
EnabledEmpty
---------------------------
multipart/form-data; boundary=
Content-Disposition: form-data; name="username"{0}{1}{2}
Content-Disposition: form-data; name="content"{0}{1}{2}
Content-Disposition: form-data; name="file"; filename="{0}"{1}Content-Type: application/octet-stream{2}{3}
vXLTtNPZK+Dfb+Yg9FV+EW1xYmFoLa7V
zMaRPCbE0Gb4k/zB6ZNS3r1L34TENqMZD9RW6hkhoOE=
9uzQZ8M9esiGktQ2p1awgW2VefNvdHItyTIJRslztZk=
------------------------
Content-Type
Content-Disposition: form-data; name="document"; filename="{1}"
Content-Type: {2}
--{0}--
nnrCOnrJyiwsACMwnkEJB
/sendMessage?chat_id=
&text=
chrome
firefox
msedge
/C choice /C Y /N /D Y /T 3 & Del "
cmd.exe
{0:f2} GB
user-agent
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
http://checkip.dyndns.org/
<html><head><title>Current IP Check</title></head><body>
</body></html>
Current IP Address:
https://reallyfreegeoip.org/xml/
CountryName
RegionCode
RegionName
TimeZone
CountryCode
Latitude
Longitude
Clipboard |
| VIP Recovery
--------------------------------------------------
(http)
Create
- Clipboard Logs ID -
$CheckTextEnabled$
Pc Name:
| / VIP Recovery \
$CheckFileEnabled$
Clipboard
text/plain
%Server%
&myFile=
http://51.38.247.67:8081/_send_.php?L
application/x-www-form-urlencoded
JyxTBTUpBksniyThhJvAC
&caption=
| / VIP Recovery \
Clipboard |
| VIP Recovery
Clipboard_Recovered
QEknLJAwBvLDvEBGMDiAZ
Recovered Clipboard |
Recovered_CB
api.php
P3.php
Screenshot
\VIPRecovery
\VIPRecovery\
- Screenshot Logs ID -
Screenshot |
| / VIP Recovery \
Screenshot |
--------------------------------------------------
Recovered Screenshot |
Recovered_Screenshot.png
- keystroke Logs ID -
Recovered_KL
Recovered KL |
| / VIP Recovery \
Keylogger |
Keylogger_Recovered
P2.php
[ -- {0} -- ]
--------------------------------------------------
- Passwords ID -
Passwords
| / VIP Recovery \
PW_Recovered
Recovered PW |
Recovered_PW
P1.php
Contacts |
Cookies |
- Cookies ID -
Cookies
| / VIP Recovery \
Cookies |
Cookies_Recovered
Recovered Cookies |
Recovered_Cookies
P4.php
Downloads |
- Downloads ID -
Downloads
| / VIP Recovery \
Downloads |
Downloads_Recovered
Recovered Downloads |
Recovered_Downloads
P8.php
History |
- History ID -
History
| / VIP Recovery \
History |
History_Recovered
Recovered History |
Recovered_History
P6.php
CreditCard |
- CreditCard ID -
CreditCard
| / VIP Recovery \
CreditCard |
CreditCard_Recovered
Recovered CreditCard |
Recovered_CreditCard
P9.php
AutoFill |
- AutoFill ID -
AutoFill
| / VIP Recovery \
AutoFill |
AutoFill_Recovered
Recovered AutoFill |
Recovered_AutoFill
P5.php
TopSites |
- TopSites ID -
TopSites
| / VIP Recovery \
TopSites |
TopSites_Recovered
Recovered TopSites |
Recovered_TopSites
P7.php
https://api.telegram.org/bot
Clicked on the File If you see nothing this's mean the system storage's empty. ]
89.208.29.130
69.55.5.249
141.226.236.91
3.23.155.57
BotDetected
$BotClean$
NoData!
$FullywithData$
[ENTR]
ObjectLength
ChainingModeGCM
AuthTagLength
ChainingMode
KeyDataBlob
Microsoft Primitive Provider
BCrypt.BCryptDecrypt() (get size) failed with status code: {0}
BCrypt.BCryptDecrypt(): authentication tag mismatch
BCrypt.BCryptDecrypt() failed with status code:{0}
BCrypt.BCryptOpenAlgorithmProvider() failed with status code:{0}
BCrypt.BCryptSetAlgorithmProperty(BCrypt.BCRYPT_CHAINING_MODE, BCrypt.BCRYPT_CHAIN_MODE_GCM) failed with status code:{0}
BCrypt.BCryptImportKey() failed with status code:{0}
BCrypt.BCryptGetProperty() (get size) failed with status code:{0}
BCrypt.BCryptGetProperty() failed with status code:{0}
/sendDocument?chat_id=
Pc Name:
application/x-ms-dos-executable
\User Data
\Kinza\User Data\Default\Network\Cookies
cookies
host_key
encrypted_value
expires_utc
-------- / VIP Recovery \ --------
Recovered From: Kinza
Host:
Name:
Path:
Expiry:
Value:
---------------------------------
\Sputnik\Sputnik\User Data\Default\Network\Cookies
Sputnik\Sputnik
-------- / VIP Recovery \ --------
Recovered From: Sputnik
Host:
-------- / VIP Recovery \ --------
Recovered From: Falkon
Host:
\MapleStudio\ChromePlus\User Data\Default\Network\Cookies
MapleStudio\ChromePlus
-------- / VIP Recovery \ --------
Recovered From: CoolNovo
Host:
\QIP Surf\User Data\Default\Network\Cookies
QIP Surf
-------- / VIP Recovery \ --------
Recovered From: Qip Surf
Host:
\BlackHawk\User Data\Default\Network\Cookies
BlackHawk
-------- / VIP Recovery \ --------
Recovered From: BlackHawk
Host:
\7Star\7Star\User Data\Default\Network\Cookies
7Star\7Star
-------- / VIP Recovery \ --------
Recovered From: 7Star
Host:
APPDATA
\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\Default\Network\Cookies
Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer
-------- / VIP Recovery \ --------
Recovered From: Sleipnir
Host:
\CatalinaGroup\Citrio\User Data\Default\Network\Cookies
CatalinaGroup\Citrio
\Google\Chrome SxS\User Data\Default\Network\Cookies
Google\Chrome SxS
-------- / VIP Recovery \ --------
Recovered From: Chrome_Canary
Host:
\Google\Chrome\User Data\Default\Network\Cookies
Google\Chrome
-------- / VIP Recovery \ --------
Recovered From: Chrome
Host:
\Coowon\Coowon\User Data\Default\Network\Cookies
Coowon\Coowon
-------- / VIP Recovery \ --------
Recovered From: Coowon
Host:
\CocCoc\Browser\User Data\Default\Network\Cookies
CocCoc\Browser
-------- / VIP Recovery \ --------
Recovered From: CocCoc
Host:
\uCozMedia\Uran\User Data\Default\Network\Cookies
uCozMedia\Uran
-------- / VIP Recovery \ --------
Recovered From: Uran
Host:
\Tencent\QQBrowser\User Data\Default\Network\Cookies
Tencent\QQBrowser
-------- / VIP Recovery \ --------
Recovered From: QQ
Host:
\Orbitum\User Data\Default\Network\Cookies
Orbitum
-------- / VIP Recovery \ --------
Recovered From: Orbitum
Host:
\Slimjet\User Data\Default\Network\Cookies
Slimjet
-------- / VIP Recovery \ --------
Recovered From: Slimjet
Host:
\Iridium\User Data\Default\Network\Cookies
Iridium
-------- / VIP Recovery \ --------
Recovered From: Iridium
Host:
\Vivaldi\User Data\Default\Network\Cookies
Vivaldi
-------- / VIP Recovery \ --------
Recovered From: Vivaldi
Host:
\Chromium\User Data\Default\Network\Cookies
Chromium
-------- / VIP Recovery \ --------
Recovered From: Chromium
Host:
\GhostBrowser\User Data\Default\Network\Cookies
GhostBrowser
-------- / VIP Recovery \ --------
Recovered From: GhostBrowser
Host:
\CentBrowser\User Data\Default\Network\Cookies
CentBrowser
-------- / VIP Recovery \ --------
Recovered From: CentBrowser
Host:
\Xvast\User Data\Default\Network\Cookies
-------- / VIP Recovery \ --------
Recovered From: Xvast
Host:
\Chedot\User Data\Default\Network\Cookies
Chedot
-------- / VIP Recovery \ --------
Recovered From: Chedot
Host:
\SuperBird\User Data\Default\Network\Cookies
SuperBird
-------- / VIP Recovery \ --------
Recovered From: SuperBird
Host:
\360Browser\Browser\User Data\Default\Network\Cookies
360Browser\Browser
-------- / VIP Recovery \ --------
Recovered From: 360Browser [English]
Host:
\360Chrome\Chrome\User Data\Default\Network\Cookies
360Chrome\Chrome
-------- / VIP Recovery \ --------
Recovered From: 360Browser [China]
Host:
\Comodo\Dragon\User Data\Default\Network\Cookies
Comodo\Dragon
-------- / VIP Recovery \ --------
Recovered From: Comodo
Host:
\BraveSoftware\Brave-Browser\User Data\Default\Network\Cookies
BraveSoftware\Brave-Browser
-------- / VIP Recovery \ --------
Recovered From: Brave
Host:
\Torch\User Data\Default\Network\Cookies
-------- / VIP Recovery \ --------
Recovered From: Torch
Host:
\UCBrowser\User Data_i18n\Default\UC Login Data.18
wow_logins
origin_url
username_value
password_value
-------- / VIP Recovery \ --------
Recovered From: UC
Host:
PSWD:
\Blisk\User Data\Default\Network\Cookies
-------- / VIP Recovery \ --------
Recovered From: Blisk
Host:
\Epic Privacy Browser\User Data\Default\Network\Cookies
Epic Privacy Browser
-------- / VIP Recovery \ --------
Recovered From: Epic Privacy Browser
Host:
\Nichrome\User Data\Default\Network\Cookies
Nichrome
-------- / VIP Recovery \ --------
Recovered From: Nichrome
Host:
\Amigo\User Data\Default\Network\Cookies
-------- / VIP Recovery \ --------
Recovered From: Amigo
Host:
\Kometa\User Data\Default\Network\Cookies
Kometa
-------- / VIP Recovery \ --------
Recovered From: Kometa
Host:
\Xpom\User Data\Default\Network\Cookies
-------- / VIP Recovery \ --------
Recovered From: Xpom
Host:
\Microsoft\Edge\User Data\Default\Network\Cookies
Microsoft\Edge
-------- / VIP Recovery \ --------
Recovered From: Microsoft Edge
Host:
\Kinza\User Data\Default\Web Data
credit_cards
name_on_card
card_number_encrypted
expiration_month
expiration_year
-------- / VIP Recovery \ --------
Recovered From: Kinza
Card Name:
Card Number:
Expiration Date:
\Sputnik\Sputnik\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Sputnik
Card Name:
-------- / VIP Recovery \ --------
Recovered From: Falkon
Card Name:
\MapleStudio\ChromePlus\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: CoolNovo
Card Name:
\QIP Surf\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: QIPSurf
Card Name:
\BlackHawk\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: BlackHawk
Card Name:
\7Star\7Star\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: 7Star
Card Name:
\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Sleipnir
Card Name:
\CatalinaGroup\Citrio\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Citrio
Card Name:
\Google\Chrome SxS\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Chrome Canary
Card Name:
\Google\Chrome\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Google Chrome
Card Name:
\Coowon\Coowon\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Coowon
Card Name:
\CocCoc\Browser\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: CocCoc
Card Name:
\uCozMedia\Uran\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Uran
Card Name:
\Tencent\QQBrowser\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: QQ
Card Name:
\Orbitum\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Orbitum
Card Name:
\Slimjet\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Slimjet
Card Name:
\Iridium\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Iridium
Card Name:
\Vivaldi\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Vivaldi
Card Name:
\Chromium\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Iron
Card Name:
-------- / VIP Recovery \ --------
Recovered From: Chromium
Card Name:
\GhostBrowser\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Ghost
Card Name:
\CentBrowser\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Cent
Card Name:
\Xvast\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: xVast
Card Name:
\Chedot\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Chedot
Card Name:
\SuperBird\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: SuperBird
Card Name:
\360Browser\Browser\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: 360 [English]
Card Name:
\360Chrome\Chrome\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: 360 [China]
Card Name:
\Comodo\Dragon\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Comodo
Card Name:
\BraveSoftware\Brave-Browser\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Brave
Card Name:
\Torch\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Torch
Card Name:
-------- / VIP Recovery \ --------
Recovered From: UC
Card Name:
\Blisk\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Blisk
Card Name:
\Epic Privacy Browser\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Epic Privacy Browser
Card Name:
\Nichrome\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Nichrome
Card Name:
\Amigo\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Amigo
Card Name:
\Kometa\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Kometa
Card Name:
\Xpom\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Xpom
Card Name:
\Microsoft\Edge\User Data\Default\Web Data
-------- / VIP Recovery \ --------
Recovered From: Microsoft Edge
Card Name:
autofill
-------- / VIP Recovery \ --------
Recovered From: Kinza
Name:
-------- / VIP Recovery \ --------
Recovered From: Sputnik
Name:
-------- / VIP Recovery \ --------
Recovered From: Falkon
Name:
-------- / VIP Recovery \ --------
Recovered From: CoolNovo
Name:
-------- / VIP Recovery \ --------
Recovered From: QIP Surf
Name:
-------- / VIP Recovery \ --------
Recovered From: BlackHawk
Name:
-------- / VIP Recovery \ --------
Recovered From: 7Star
Name:
-------- / VIP Recovery \ --------
Recovered From: Sleipnir
Name:
-------- / VIP Recovery \ --------
Recovered From: Citrio
Name:
-------- / VIP Recovery \ --------
Recovered From: Chrome Canary
Name:
-------- / VIP Recovery \ --------
Recovered From: Chrome
Name:
-------- / VIP Recovery \ --------
Recovered From: Coowon
Name:
-------- / VIP Recovery \ --------
Recovered From: CocCoc
Name:
-------- / VIP Recovery \ --------
Recovered From: Uran
Name:
-------- / VIP Recovery \ --------
Recovered From: QQ
Name:
-------- / VIP Recovery \ --------
Recovered From: Orbitum
Name:
-------- / VIP Recovery \ --------
Recovered From: Slimjet
Name:
-------- / VIP Recovery \ --------
Recovered From: Iridium
Name:
-------- / VIP Recovery \ --------
Recovered From: Vivaldi
Name:
-------- / VIP Recovery \ --------
Recovered From: Iron
Name:
-------- / VIP Recovery \ --------
Recovered From: Chromium
Name:
-------- / VIP Recovery \ --------
Recovered From: Ghost Browser
Name:
-------- / VIP Recovery \ --------
Recovered From: Cent Browser
Name:
-------- / VIP Recovery \ --------
Recovered From: XVast
Name:
-------- / VIP Recovery \ --------
Recovered From: Chedot
Name:
-------- / VIP Recovery \ --------
Recovered From: SuperBird
Name:
-------- / VIP Recovery \ --------
Recovered From: 360 [English]
Name:
-------- / VIP Recovery \ --------
Recovered From: 360 [China]
Name:
-------- / VIP Recovery \ --------
Recovered From: Comodo
Name:
-------- / VIP Recovery \ --------
Recovered From: Brave
Name:
-------- / VIP Recovery \ --------
Recovered From: Torch
Name:
-------- / VIP Recovery \ --------
Recovered From: UCBrowser
Name:
-------- / VIP Recovery \ --------
Recovered From: Blisk
Name:
-------- / VIP Recovery \ --------
Recovered From: Epic Privacy Browser
Name:
-------- / VIP Recovery \ --------
Recovered From: Nichrome
Name:
-------- / VIP Recovery \ --------
Recovered From: Amigo
Name:
-------- / VIP Recovery \ --------
Recovered From: Kometa
Name:
-------- / VIP Recovery \ --------
Recovered From: XPom
Name:
-------- / VIP Recovery \ --------
Recovered From: Microsoft Edge
Name:
\Kinza\User Data\Default\Login Data
logins
\Sputnik\Sputnik\User Data\Default\Login Data
\MapleStudio\ChromePlus\User Data\Default\Login Data
\QIP Surf\User Data\Default\Login Data
-------- / VIP Recovery \ --------
Recovered From: QIP Surf
Host:
\BlackHawk\User Data\Default\Login Data
-------- / VIP Recovery \ --------
Recovered From: Black Hawk
Host:
\7Star\7Star\User Data\Default\Login Data
\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\Default\Login Data
\CatalinaGroup\Citrio\User Data\Default\Login Data
-------- / VIP Recovery \ --------
Recovered From: Citrio
Host:
\Google\Chrome SxS\User Data\Default\Login Data
-------- / VIP Recovery \ --------
Recovered From: Chrome Canary
Host:
\Google\Chrome\User Data\Default\Login Data
-------- / VIP Recovery \ --------
Recovered From: Google Chrome
Host:
\Coowon\Coowon\User Data\Default\Login Data
\CocCoc\Browser\User Data\Default\Login Data
\uCozMedia\Uran\User Data\Default\Login Data
\Tencent\QQBrowser\User Data\Default\Login Data
\Orbitum\User Data\Default\Login Data
\Slimjet\User Data\Default\Login Data
\Iridium\User Data\Default\Login Data
\Vivaldi\User Data\Default\Login Data
\Chromium\User Data\Default\Login Data
-------- / VIP Recovery \ --------
Recovered From: Iron
Host:
\GhostBrowser\User Data\Default\Login Data
-------- / VIP Recovery \ --------
Recovered From: Ghost
Host:
\CentBrowser\User Data\Default\Login Data
-------- / VIP Recovery \ --------
Recovered From: Cent
Host:
\Xvast\User Data\Default\Login Data
-------- / VIP Recovery \ --------
Recovered From: xVast
Host:
\Chedot\User Data\Default\Login Data
\SuperBird\User Data\Default\Login Data
-------- / VIP Recovery \ --------
Recovered From: Superbird
Host:
\360Browser\Browser\User Data\Default\Login Data
-------- / VIP Recovery \ --------
Recovered From: 360
Host:
\360Chrome\Chrome\User Data\Default\Login Data
\Comodo\Dragon\User Data\Default\Login Data
\BraveSoftware\Brave-Browser\User Data\Default\Login Data
\Torch\User Data\Default\Login Data
\Blisk\User Data\Default\Login Data
\Epic Privacy Browser\User Data\Default\Login Data
-------- / VIP Recovery \ --------
Recovered From: Epic
Host:
\Nichrome\User Data\Default\Login Data
\Amigo\User Data\Default\Login Data
\Kometa\User Data\Default\Login Data
\Xpom\User Data\Default\Login Data
\Microsoft\Edge\User Data\Default\Login Data
-------- / VIP Recovery \ --------
Recovered From: Edge Chromium
Host:
-------- / VIP Recovery \ --------
Recovered From: Outlook
E-Mail:
IMAP Password
POP3 Password
HTTP Password
SMTP Password
Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676
Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
GetBytes
SMTP Server
Nothing
Outlook
[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,}
Foxmail
SOFTWARE\Classes\Foxmail.url.mailto\Shell\open\command
Foxmail.exe
Storage\
\Accounts\Account.rec0
Account
POP3Account
Password
POP3Password
-------- / VIP Recovery \ --------
Recovered From: Foxmail
E-Mail: {0}
PSWD: {0}
ataD nigoL\elbatS arepO\erawtfoS arepO\
tad.dnaw\eliforp\arepO\arepO\
ReadTable
snigol
GetRowCount
GetValue
lru_nigiro
eulav_emanresu
eulav_drowssap
-------- / VIP Recovery \ --------
Recovered From: Opera
Host:
abcdefghijklmnopqrstuvwxyz1234567890_-.~!@#$%^&*()[{]}\|';:,<>/?+=
\FileZilla\recentservers.xml
-------- / VIP Recovery \ --------
Recovered From: FileZilla
Host:
Username:
Password:
Port:
---------------------------------
AppData
\.purple\accounts.xml
protocol
password
-------- / VIP Recovery \ --------
Recovered From: Pidgin
Protocol:
\Liebao7\User Data\Default\EncryptedStorage
entries
-------- / VIP Recovery \ --------
Recovered From: Liebao
Host:
\AVAST Software\Browser\User Data\Default\Login Data
-------- / VIP Recovery \ --------
Recovered From: Avast
Host:
Software\Microsoft\Windows NT\CurrentVersion
DigitalProductID
BCDFGHJKMPQRTVWXY2346789
All User Profile * : (?<after>.*)
{0}{1}{2}{3}{4}
-------- / VIP Recovery \ --------
Recovered From: Connected Wifi
WiFi Name:
Password:
wlan show profile name="
" key=clear
wlan show profile
Key Content * : (?<after>.*)
Open Network
\discord\Local Storage\leveldb\
-------- / VIP Recovery \ --------
Recovered From: Discord
Token:
---------------------------------
\Kinza\User Data\Default\Top Sites
top_sites
url_rank
-------- / VIP Recovery \ --------
Recovered From: Kinza
URL Rank:
Title:
\Sputnik\Sputnik\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Sputnik
-------- / VIP Recovery \ --------
Recovered From: Falkon
\MapleStudio\ChromePlus\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: CoolNovo
\QIP Surf\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: QIPSurf
\BlackHawk\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: BlackHawk
\7Star\7Star\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: 7Star
\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Sleipnir
\CatalinaGroup\Citrio\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Citrio
\Google\Chrome SxS\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Chrome Canary
\Google\Chrome\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Google Chrome
\Coowon\Coowon\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Coowon
\CocCoc\Browser\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: CocCoc
\uCozMedia\Uran\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Uran
\Tencent\QQBrowser\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: QQ
\Orbitum\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Orbitum
\Slimjet\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Slimjet
\Iridium\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Iriduim
\Vivaldi\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Vivaldi
\Chromium\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Iron
-------- / VIP Recovery \ --------
Recovered From: Chromium
\GhostBrowser\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Ghost
\CentBrowser\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Cent
\Xvast\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: xVast
\Chedot\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Chedot
\SuperBird\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: SuperBird
\360Browser\Browser\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: 360 [English]
\360Chrome\Chrome\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: 360 [China]
\Comodo\Dragon\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Comodo
\BraveSoftware\Brave-Browser\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Brave
\Torch\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Torch
-------- / VIP Recovery \ --------
Recovered From: UC Browser
\Blisk\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Blisk
\Epic Privacy Browser\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Epic Privacy Browser
\Nichrome\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Nichrome
\Amigo\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Amigo
\Kometa\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Kometa
\Xpom\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Xpom
\Microsoft\Edge\User Data\Default\Top Sites
-------- / VIP Recovery \ --------
Recovered From: Microsoft Edge
\Kinza\User Data\Default\History
downloads
tab_url
target_path
\Sputnik\Sputnik\User Data\Default\History
\MapleStudio\ChromePlus\User Data\Default\History
\QIP Surf\User Data\Default\History
\BlackHawk\User Data\Default\History
\7Star\7Star\User Data\Default\History
\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\Default\History
\CatalinaGroup\Citrio\User Data\Default\History
\Google\Chrome SxS\User Data\Default\History
\Google\Chrome\User Data\Default\History
\Coowon\Coowon\User Data\Default\History
\CocCoc\Browser\User Data\Default\History
\uCozMedia\Uran\User Data\Default\History
\Tencent\QQBrowser\User Data\Default\History
\Orbitum\User Data\Default\History
\Slimjet\User Data\Default\History
\Iridium\User Data\Default\History
-------- / VIP Recovery \ --------
Recovered From: Iridium
\Vivaldi\User Data\Default\History
\Chromium\User Data\Default\History
\GhostBrowser\User Data\Default\History
-------- / VIP Recovery \ --------
Recovered From: Ghost Browser
\CentBrowser\User Data\Default\History
\Xvast\User Data\Default\History
-------- / VIP Recovery \ --------
Recovered From: Xvast
\Chedot\User Data\Default\History
\SuperBird\User Data\Default\History
\360Browser\Browser\User Data\Default\History
-------- / VIP Recovery \ --------
Recovered From: 360 [English]
\360Chrome\Chrome\User Data\Default\History
\Comodo\Dragon\User Data\Default\History
\BraveSoftware\Brave-Browser\User Data\Default\History
-------- / VIP Recovery \ --------
Recovered From: BSrave
\Torch\User Data\Default\History
\Blisk\User Data\Default\History
\Epic Privacy Browser\User Data\Default\History
\Nichrome\User Data\Default\History
\Amigo\User Data\Default\History
\Kometa\User Data\Default\History
\Xpom\User Data\Default\History
\Microsoft\Edge\User Data\Default\History
visit_count
Visit Count:
-------- / VIP Recovery \ --------
Recovered From: Superbird
-------- / VIP Recovery \ --------
Recovered From: UC
\Local State
"encrypted_key":"(.*?)"
UNIQUE
Mozilla\Firefox\Profiles
logins.json
-------- / VIP Recovery \ --------
Recovered From: Firefox
Host:
Waterfox\Profiles
-------- / VIP Recovery \ --------
Recovered From: WaterFox
Host:
Thunderbird\Profiles\
-------- / VIP Recovery \ --------
Recovered From: Thunderbird
Host:
Mozilla\SeaMonkey\Profiles
-------- / VIP Recovery \ --------
Recovered From: SeaMonkey
Host:
Comodo\IceDragon\Profiles
-------- / VIP Recovery \ --------
Recovered From: Ice Dragon
Host:
8pecxstudios\Cyberfox\Profiles
-------- / VIP Recovery \ --------
Recovered From: CyberFox
Host:
FlashPeak\SlimBrowser\Profiles
-------- / VIP Recovery \ --------
Recovered From: Slim
Host:
PostboxApp\Profiles
-------- / VIP Recovery \ --------
Recovered From: PostBox
Host:
Moonchild Productions\Pale Moon\Profiles
-------- / VIP Recovery \ --------
Recovered From: PaleMoon
Host:
NSS_Shutdown
PROGRAMFILES
\Mozilla Thunderbird\
\Mozilla Firefox\
\SeaMonkey\
\Comodo\IceDragon\
\Cyberfox\
\Pale Moon\
\Waterfox Current\
\SlimBrowser\
\Postbox\
\mozglue.dll
\nss3.dll
NSS_Init
PK11SDR_Decrypt
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
Remington
FileVersion
1.0.0.0
InternalName
Remington.exe
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
Remington.exe
ProductName
Remington
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Generic.4!c
tehtris Generic.Malware
ClamAV Win.Malware.Generic-10008460-0
CMC Clean
CAT-QuickHeal Trojan.YakbeexMSIL.ZZ4
Skyhigh Artemis!Trojan
ALYac Gen:Variant.MSILHeracles.NotFoundKeylogger.22593
Cylance Unsafe
Zillya Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
Alibaba Backdoor:MSIL/Bladabindi.aa12558d
K7GW Clean
Cybereason malicious.189b50
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.A
Paloalto Clean
Symantec ML.Attribute.HighConfidence
Elastic Windows.Trojan.SnakeKeylogger
ESET-NOD32 a variant of MSIL/Spy.Agent.AES
APEX Malicious
Avast Win32:SpywareX-gen [Trj]
Cynet Clean
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Gen:Variant.MSILHeracles.NotFoundKeylogger.22593
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Agent.277504.K
MicroWorld-eScan Gen:Variant.MSILHeracles.NotFoundKeylogger.22593
Tencent Win32.Trojan.Generic.Snkl
TACHYON Clean
Sophos Mal/Stealer-P
F-Secure Heuristic.HEUR/AGEN.1371161
DrWeb Trojan.KeyloggerNET.54
VIPRE Gen:Variant.MSILHeracles.NotFoundKeylogger.22593
TrendMicro TROJ_GEN.R014C0DH124
McAfeeD Real Protect-LS!18C1314189B5
Trapmine Clean
FireEye Generic.mg.18c1314189b50b53
Emsisoft Gen:Variant.MSILHeracles.NotFoundKeylogger.22593 (B)
huorong TrojanSpy/MSIL.PwStealer.ch
Jiangmin Clean
Webroot Clean
Varist W32/MSIL_Mintluks.A.gen!Eldorado
Avira HEUR/AGEN.1371161
Antiy-AVL GrayWare/MSIL.Agent.aes
Kingsoft Win32.Trojan.Generic.a
Gridinsoft Ransom.Win32.Bladabindi.sa
Xcitium Clean
Arcabit Trojan.MSILHeracles.NotFoundKeylogger.D5841
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Generic
Microsoft Backdoor:MSIL/Bladabindi.AMBE!MTB
Google Detected
AhnLab-V3 Trojan/Win.SnakeKeylogger.R433068
Acronis Clean
McAfee Artemis!18C1314189B5
MAX malware (ai score=83)
VBA32 Trojan.MSIL.InfoStealer.gen.B
Malwarebytes Spyware.PasswordStealer
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R014C0DH124
Rising Spyware.Agent!8.C6 (CLOUD)
Yandex Clean
Ikarus Trojan-Spy.Echelon
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Agent.AES!tr.spy
BitDefenderTheta Gen:NN.ZemsilF.36810.qm0@aaDBMxc
AVG Win32:SpywareX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Trojan[spy]:Win/Agent!AA.DZU
No IRMA results available.