Static | ZeroBOX

PE Compile Time

2024-09-28 01:00:00

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0000f914 0x0000fa00 6.06125965061
.rsrc 0x00012000 0x0000cca6 0x0000ce00 4.04287346383
.reloc 0x00020000 0x0000000c 0x00000200 0.0980041756627

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0001e23c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001e23c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001e23c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001e23c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001e23c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001e23c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001e23c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001e23c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0001e6a4 0x00000076 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0001e71c 0x000003a0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0001eabc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
w6rrubIyuaonuI7dUoQO7jQowLfq8HEKVjILC0
sQjfvwy54sdhefYh6krTHfrwjiLY6j5QkGGiD0
zB0HgCroLxpguvWmMalL7bP0
3Lo21KW5Ws1jfK991pMLWaqubFP0rMthCJ0wJSZX0
QmyqtzIycVRmH9sEtsSaFSY0
ynBdcLTYMxhm3cEBUADSq5n0
K6Us6cdcmjM5Y1YZUvoBmwKv0RCr7ldg88Ak1QPgkhDyYON1t6NyNPw0
HXdQQjeVqG6yEfnwWI1eHsX2gOjZoxLJBnmyzw3xQrEF4izkSJbzMAf51dfST2EAye5d9lSFCH3wtA2tByx3lLDu7UwlZC71
OZTjdgLhytzRUO9BG8CmaRHirDzEEDfGQ7ApIR1vCOSAoRzCbnqGf1NykEY2wo2ElgCqDKjDlmVarFD2cLAi5MYD8exiP7B1
EWA68RFihV5sQHsETwGszJF1
_Closure$__1
IEnumerable`1
ThreadSafeObjectProvider`1
List`1
ZgLKc6KAFdAdhroB1wa9MH4dpmr4qWBqpLmtVN6d1
7xh6VpKSisUfdDsmhuQpEO1RNGvU6pOS5sjnk1
XnPkYTgQ3Jos8GEbXnCXLaclPO2yRctJAwI8r1
4XmgSWjMPzDTLyTBCv9xfFDIOezCa8ca3UTS02
Microsoft.Win32
UInt32
ReadInt32
ToInt32
MvxlYlb4xiC4NhNe5TxwoNoUK7pksvWI4H6DG4JExSxePdsE8cqRkzAI9vT2A58BNIunl7Devt2gf2bxEcRGvivKjto65rH2
Aa6jt0BHejG4zkFxyClfQQCL2o1M4oaFRWeGP2
Func`2
Fn9QjTTDHiT0S4MDdT27fwEoAqlkKtODkfgob2
wwuAzQXKmhKegLK9isBvebou6PDDLXsK1A3c6xFBsowkfFdmyQPqnD2upKpgCFSyXMEUVjNxyDdZvNy70nLkfWhmde3PVve2
pgi6BCEkpZDTZOoxSG6DRF2lqEwjz9EZkxOup2
ro1ts8MVMyC0uGIZjnBJzbbgWhv3W1klx0giwPLz2
kBWJO5MRqbFVLq8OHVHI89ltZRivZ95vkbkWngTu301JAcBPFey8AR03
oLzb6PQg0nLPTP32mH7YcUDWOQuSFffubzHY23
LTU4b7eBW0bbKLJRYTFHMSP3
BWjUIVj6dkHtJtQ3n2Cs5b618IoTuto2mQNVmeSdjuBkztbVcASCoKW3
1qex669uJvcKnFSlaMvfr93JJiyvsuhQpFsAF8Qf3
50Sa244ccSDRrzbtzRDiRF1PvIgs86b7P2aITMzPZGihbjhoF7QHliv2uIfD25DrY0Jm7z7SokUGwSdWnJI2gh6Ctsyrj8g3
ntkUjkCldWjrnynNgLdwUga0OW52imzY7iQjl3
fFxCvRwOpq3vibuareDKZJBsii8p0OyJG1oss05UeKKzQtjEpuchFWaWNfdHftDWi8EgTuNuJmNO93ZFclwlMQyYiJ07Thp3
Svk5IOVrhewDfkDZc5IW2IzDZycDAWxsm4eSHOP27plzvZfmG1dSmtp3
NKVRImPLDKMwXx80TjouQ2q3
rzUvIL7GdzbW57fbZYPhZ9x3
ogIWKKCvwknuYIkliXCnxxx3
SLLR38T3U69x47BEHvdUnFLkXVb0Y8PRDczG44
J3LyhRWJvSeRePtIvulEuK44
UInt64
M4FMJtC0qBAivRxFbhk43DB4
3u4uWA5Rdqx0j3UHfHXjXbH4
FE4vedGvMmFR371KqzPnGrW4
PRHPHmvTBsgmy8WzkNC6l0Y4
5aqu3VTggzY6BqqYLyxePAL1zLvTckQZZLtWrvzY4
3K9svUpE1SBm3Vn9LCX5xwVVdNpOgHUBlIYz7cQl4
vgSqfVGS2nt3heuPaRfNUjkoaseWv51AjyXDdVUhr8fBGkKnAzn53hn4
XRBxbLI8PBEJhW9MekwnKyo4
dZYQIVmLq8basTJRJG2bXHz4
DKUdh5v088LdYZe0xvwIhW0vboQH9CrGz8ExqAdoMGHqeh3qyj5uIO85
EB5VCjnnsEhvQsCLHfjDaBfe2zRzr8hck5UyJMXC5
R9D6ToL7eIam8T8trOjpWpsHUvRXxkvFstojJSaCkcm3AMYgy7o7C5D5
qsYS2EJJ36RlRb64o45xJfJKjpxbJ1rxHIuJH5
En5MAfjE0mjiqpAiKFHT9RzEIfoC8WnuRaGUh78L5
bKVAEvstnb4BFUkFRKQuzU8j9xcBq9Nx06mTR5
z0gnUrvsJwadcL4XT1s4wLV5
bAcVnMml9bTWOe0PWYWHYvXjvl4lLVsUOdqhktLkGfDfZwg2P58pqL46xvwRM2RlaF8zs9p9yHsKstqqOCmYrq1qKpLsCTX5
ynye6lc1nvB363YaEH1WniFOO2ZRGI06logCY5
wwxfmK5Smm9Aj9dKQal5hYZ5
L0TP61RHAelB7PO5gsAJQ2m5
8DGOYueJgQOwXy6HgaIVo716
5h4pRS2R8h7tcs8ipL8nFY66
3Nyigtf1phHYhZOMy96fHKjvdhIyb2qy4HYaX6
sGazi0gJNU5ZNNISfDps22p6
OmVPXVcNo1z2r3vR7tOPIFwJmfMd23HD62dQRbbu6
19G2j2TnJWwWP04WwWmWuupUGrXqYXqWUEk9OF817
DUpUwy8OrVyX8AJxv8vLGFRNKYxuxRKiDJeWuIA47
pcyhONEkqampusLpDQmJMAQ7
L2nYlWSaN3LiZAf5InEwUCY7
bn1Xs8nQNWQgDpEpwIzxzEw7
KoieZXs6uwtHQIl5f6PRVX68
5N7wSpmvA19yUKaZACuZr8g5YMquhHJIUnoWocKC8
vLFezrh9LjeB0RZT0o2xrpWUo4jA4LXooLOMD8
get_UTF8
BWqxjcBIdNdqoESEK1slv3KRwFaTkjkg6N3Jej8Q8
pXcn7oslewBCJjJuYU07T2W8
_Lambda$__8
SlyD1aALPxLPnLVW37yUtnQo3ptSJ3WtqWGMfDP2m9FKcs0KWiO37fl8
ZpdSL9FdMFveZtMaNPWCIp1mi9CpLZCOQbFcv8
xxChjFVghXYXZ8Z66Zk9Gia58r9DbGLer1l6C0F3YHnSpLJ6RVUqtj29
inJjmuxsKRxNipF09Y5btzTFcbINXRPZ6Euyc4p8CoWxxycaLBbWTE99
9xV5ZQCVXWRXf39LDciiA4M9
ZpJnTAoRuRuMa19PjhBKs9vEZGrVqYULvuql6nrC4rYokEZtd648xQQ9
qd03bPB5UHpP5YNwZUQcuMnfQiDp8zrrpWO2k9
5jM9Bsm3LmEF8BEgEHgXQIk9
8gf6wiyCmzvbZtU2a8bNHUURObUeSpmlO6WsbCblaBeiNwY2AkJdb9m9
OIDYwLarpFkEZDr1qMiLriAut7uoc8wJ869Iy9
<Module>
CCZVpSz3RTDPr8WQZohBKz5A
3X6lmALl89wrXISYBTewkNFA
Z97NhJOorNaHFqrIl7RRfIho6OigZRjcSQ74QA
IjwcZJ7hVN8Oga2Rp4xjmbRA
YwN59kosj5KYsB6DFqHCOqqty8USzL3xKTaT9yLISyGqdgIqQMBlsBYA
capGetDriverDescriptionA
dh3MIfQ7klUhvd4hbM3RV0oA
capCreateCaptureWindowA
RXCZYlw3pMmNyTiZGPXSRXAB
tRJFMFjOyfyAoK9j4aDAtjCB
uU1bVvPLFpeXNnObffGbHmOB
g3kLs8559IFyi1oozIAQGxfWSnMkslk07lzOQB
XN2omRZVsgroZcbg0YjKFNP28x1nd5dBKnJQUB
sQD3aD0YomZ0oa4fPMxrkA9xWfMa0WXMTiOHfFF0yd18POrVxsuP05eB
hwGepUO0Zwl42HJLFeLAHLfB
OpU9ii0hnh98HQYCvEtHXdgB
tZuNXqilIGmDVp7SDEpF9HPS7ictrdV28pdCjB
GUWThrNjxLRGP6xmmAugMLXYqIkhLPlvEIcaI9uX6M9V6HiueXy90NBC
jKaIX2sUJ1kVjkvzUu2LUcDC
m6uS8lTVi35YTnyRD8TDXsQC
g6IygWzBzgcxN9gZUi56YDVQwSL4rPhSmQORZ0P5IF7s1xjDHDAWvMWC
SPGQNuFsbFAHE2rJ4YZ1nipC
CQz4o49W9sYx0J3wmE5MWXwC
qynncBZL82XZDZh2LfqKiF64AZ18nmVBU1APnpfNlFdQnUTytDXgndZm8FaYEXbOOtzeBpmpywQVV9exxwep142lnKeN8kCD
ES_SYSTEM_REQUIRED
ES_DISPLAY_REQUIRED
RU2nqKeieFsuPjNmFjWHYlMZLxFGTDnzC9nxTDJGD
MEqq5wG95VGubJ6VKtkehwSD
bALvEueFJ5ZGxwqmdI0YPQf4d13rhZPCiYd0UD
fAvXj8rFota0hRiEebhJ9CXD
kCT7Jb4WLxZnodZ6T1bQV7GddoBv99Dbcim6cD
gF9qoZzZqRnTAMeK2GeS9XmDngctKW6tPSGFeD
uGQW9HZfAm3Jc02tkSed2hhD
vehOps2kUpJUFR2xBeS70KpD
pTrpxQUHjvBnL6dJstclXGrD
dmjednhTPukQwlypTBCzebKhP6bm06ImvdWlLVy8k63mhTk3Ya7Pt7eKsRpFUksyYqhmmzfeJb5PzwXQLCYju4FJHghbjHxD
LGzrl66wtzllnzp9wM0KIq5E
cqO8aFa4BMKrm6nGam1I2LEE
EXECUTION_STATE
YtTI6Z4YXXRqlTDkvJKMFVAhzA8hOl2ecJxld1LTydf1rMxGxkzKNicE
5pSiHgkI1wMPLFmcBCG2CrkE
9OXJIBDpYd6H7J8Dl9JKlprE
FEhOD97jmCG7TCIGae0ol7vE
Dg1ydtu9v50Jr1jbEEXAU9D1YdzAroslAscrzkHAV5yhuNUncsC2wV5RjG4MpM1JhWTVJPZTCCb7rhknXUQmnodwlQ5fqazE
kUNiEN6C1bsvgMbvJaEP3q4F
O0EwUvHXaAWdk8Nd0BjlLE7F
drs8KavEgFHU5ezA2dQsVkZpx9GEZzgfbx2F3vQ8F
Su92Vew29LoZ5bFZPbX4JyQF
AOD4uXY3LsZVzjFnrbiyCimcRsg0fF5QnkRtSF
cgur6bdAiVCllreqlSN7WOPQ98kRLVknVFgE0KvKTYC89PJgp2UMOXcF
K4jnvJl6DN44Mvw6MEHmpIuF
qcSqIiU38GGPgRvPKIRuS87G
TtKIGqRel1b7YcWjb8end1MzNyFnwZhuDP1gtT88G
U56QU3XI1ME1msGfBXdb2oPJuQoPeWCJiC0oRG
hYxQHcKlkWnltgB6XFqkMbLaHhLeAen2nRS2niYiG
r8brfFg0UbiDpH0ubp36esYhWvQphQ2QR4ZMKk9ar9pO27ky9D0IRC1H
8lYCon7UEF5LBerZAOfI43u32bOKKqGVprt02H
HHuAo9LcgXuWglllQ0cb30fnF75GjBGrGwMh3H
9CmqnaaZUUL2o0Y0OWtcI9cgatSxiTncqTJqCSOkJJMlKmiRb5Kzia6H
R3Gm6aW7ZegyQ9u7sZs14DPOc8Jk0L6zeJdDyNBHugXZfBqpmWBuP2CH
z7AfZlDEHGsia5VwnhFhcEPtiUiCWSRDRgCxQOoJH
N1Zc5nsMa683NkAY9R3m0f6XdyvQ6cHFUwhbMzeYq9N6hYQKdFxmL6OH
9LqqQKMCQUD9k1usaR6UifzN8kBGZ3tjEzvNVH
kDAbkDh1QpLjPnQ0fDmKQ1kH0hSVZmyAQBGDdRc2zcpREYRw7jo7mnbH
SEBtuElafvTTT0fmcOufTPjDjq0grh9OiTmQZmEc8e0PrrpLbNjEfFiBQc2EcEwSEuAdriT0PfH5hXuWfpgiv0MzAkje0R6I
gc4ibRsNMflWCJ6ht1ZSg2E27LGfhVcdIqmqPP2DI
get_ASCII
AxXlZ0VPCiszyrLoz1dGJO7TybMs0CJ7F7lJJahgI
KbSciwg7OfnLBFavCDFtStRqawiyvpaUUBKlEOoBkPnLca2XmM0CFDb2tUUULs3bC0RfcIzUzr4cXnNujs4TDSx3KXkSDVpI
MMaaT9mIpDRDwbbdrzSSBDuI
KMkAJEzYwvbhLAz0GZxTzBAmbq44FTTF2Kf6t5SvI
LAoi2pPMeMNM1HVIBLWVH7zI
hjh033vaEEZLhDZVIVbnrJ0J
0RBKqD0JyUY4ERNCcN7P7QH1Z45pJnHl8Wf7d0M7J
MipCKwnD4gFOKv6vvCXUStE1ZW0f3gdIUCeLEJ
LfeY2eIvEQMpFdyO1UrggWijdQin82ko2An1cJ
g3BAp0F3K2Sgs7Ninw2r3WBno65aH9JBqofHjJ
L6dAgM9oorMoBydvcoRkQkjJ
7onFLwe8PhTxGYTqsShlEuZBZ1tEv4n0DcEM9ZhNDW4tPvfJD2lAqPqJ
01XOVWAkpgJWCF6hgFGS12CK
ydsVLbqdhuWOcmBqJ4Bao68KDaIb0reAGZXT5coFK
Dxuyvq0vh5jTjLOmtwHKJsyQ5VjvQJWqswtQdK
RPFc7YGX9GpR9cnyUuxuDL212Ez1iQ5rajhlnK
Aq5eAyhMqSxm4qHwp2NW2tY9TWxlLqJ2EAguul8gq3Hm4BinHSvl259baGAI4fGSQElzFcTVhLeZ8TuK7qkhrzsizqvuUlxK
6wHOdrHXsPc1PlBFMJk4ohyeDtNFMyQyMVxxEL
YGpedIQsUktlakQXA5ucoqFL
kxoJp7GQholz8roWmWkj5wFL
ZA9uUGkKDMdcnBCOXWDoa4ML
B1NvrmU8bnPdaVzQLLIhvyNL
HhxTdLky4vlvoXIDxsgBocmL
LCB1Y3Y94vGeCUQ7YMMuKeDHB4eBE9EPOC8MqL
waSCK4qdbs7oALeRq8RjNPD5AETR5xweRkA4zvDBzkgMpnCEnFBJe54n9tVgtdMz9zHbf8V53sV45v5tfYjtwZHWOOz6HrqL
IdANvHfQYlqw1brdN7FYBxrL
NBjHwHFDxpeZFLeMHcizD81M
OoxRgDaBTsJDbEc9EOhKZN5M
rXSh2KlTsmoa0h1Lni5MTw9M
6ORS1wsLfpFdNYLArgUZrT84HSw0xa1vDS2lDM
e35uHZnj4DzJNC5yFmEqex6N
XTK9vke4rlM1u1SK7qZ12QJ2jaa8dov76lThGN
11ljB7IURTxkbLLb0bq1HdOsWJxMKv7SvyoAJN
XXMdMlKDLFm7Aap4k3FLSubxBFD7XVchz1ZPBtJPywlHBf8StpNJMjZN
TobSZeyICD0M1yxE87z4GB6AC50oednQdYz1rCz4IIlC6DzL6btD15hN
9eUOyZ8t3a22SlXYFj5lipwJHf8EayQemiLk6bz0Q8Zgmo68XcjIRfsN
Ea04UbP4Ui8VZ9QCvoaFkVtN
6J4SOTu6BjuWoqCvLCfUbBpm5agaNnfa9ponQnRgqPdOgRHNtIwNmeYXRPDs0vfPMFupnUlTQeL1ilOUK1rN30xNdJNkdqwN
tquNpoyVvR6hSaY9CePgRAZ7b3bJSNZmzWLi6O
EvQy01U2Ap5uKpxK6g6EGf8O
LASTINPUTINFO
System.IO
4c5mrUnLo2zYR35acEzxvcPO
2IUK3YL90MkxW6emZjJGRBrjDeJ5szXLzCudUO
4peFN7LUdXfy56sShEIR7rYO
axYpVmU0928ifwLHwPFk8N33qZGzSYVn1YVufVdZlRi5oG3tX1uk6bn9ZO4o85NJD6Mc4HOBUEMa4KJUM9Yi0X00lOfMRSgO
WUFCOyT4blQCr2gJurDuh1eMjbocA1GmxkdhFB4S6Gr6wcJxg1U1HhN5fauQgUN4Cc7GMRaUe1Zatr2GWYHY7LSZ2urf5QoO
yrftGM2l44Ar47yxTjtGsA1UrvNaj7uyLpJJzO
Mr6gh6gZAkTAkjeaV3Mj8z5GzwBF1LOzO2HKHumX7EJqk6QylikDOjAP
3xX0TO9QzRAsxWSFdg2IWUN9MigJk4zXEEtSDP
Cl6weMXY1TYDZzo8rkrB4up8qVaYiWx3YEibqJrV5bPWwiyvkNRptFFP
CEGnpjd7rvZ38ZvgVkQGaEGP
rhKsVEuDep2Ey8wmcOqI5jQFUTVBCVIZ8QEpJP
jZDdJ0MbKDzUM4tuBIHHZXPP
sCD5jZOlTiLlLtR5dg3mWxY9dC5yUmDQCw6xxyhrUs3P7VrKS4s8ZuRP
GkLCBWF9eeyIVTfLbFKyKPxfDRXKFGzHros5ogwRP
cKXfzJB6VP8CskbzIsjBPs03SsiUgnTmblX2nPbAxSj4Ja9LiCxayYWP
zqGXBaGvMMhuFdqJEW7amGpP
ED0BumKa7Y9uzZn73HmoT9CQo4dFOGlwRcnmpr6lZY6rzpdNdpg0kZZ3OCKAEI4k4EFAhWKeP3WCvoPsJOKtGqqKuTTLem1Q
M9muh42EtxD21tPXzjlXwH2IS8OwYL7o1zjW5Q
54mNaPk1Rb9AjRIMLSkiSmC84zdv11iPnEMr7Q
0sOYWhzBBI1kCygpVnUSyf8Q
J5FLqFIkkraTXfNIyyWktsDsbWNrKt39LMV5CQ
udIwdEXcYZvyKmBUPIi40luSdrdMyZhyrITXHQ
1MfCy5808cN1ja59bihNEVFMwWZeiBSEDoXqYQ
xAirkn7JDYx2892LyiMSjdgQ
Adxtokr37iRXaOYDyDpZr0iQ
SLofSohMBFsW8lGxYMla6rUVUXJzq02DVc3x1R
7gIXNveuoIBMgDtqQRrlFBHwVgOEbh9uH0AsMR
Gag6ocjhhTnzSfTFa3VhXbSR
EpnNIEkiM85DkTjnDwZGKku4mXnWTqN8ZGYdUUQkF4XbIKWSqhdWUtVR
sv6LpXYOOZf2lusoMWm6sraR
m9osKcGrszFPsvKQvpUhZIdNzz1mQD8UHBAr1P6UZbBoY0Tk3vxVkIbR
qRzCiBuEv3Eyk0TxzJjoa4C1L5qWaMnXHyapxR
m1JBENq59R41CPOAplcug4tAohyRm0SUEpis1S
rwWNorotko4fnkqLdf8GlOVFBfdfYlEmNaMa4S
uOysAIOJPxcUZz8aytNCIoQX67UnpnhdrB0ANF0AgeH4HF7DBmgIKF2KwrPwprHWU242VhY6mFa3oQ7qLnokk7Id0Q4s59JS
xbxBjFtZjJa4X3NAAe3GFMeKJeRukVdPIKIHRS
ES_CONTINUOUS
BSpLyv8hMXttbXCNP8rLTfgS
Z2kE4m1M7nzxxzjFzOIsbNzBfiJs7wSK4xetIT
9xKScYOuAkyBnrb2nciGvXz6xz164o7MyVoRbT
dPBQiCSVPczvAdoWyBaNtKhT
aPlcuBwV0KvDWWlB6Ggm9f6hH5dszjc9Y1o3yz6j1GYKPlIfWPNbirkT
6ejRriBYQUiKCAD8hQnp2bAAfVEoTMdnRUFd6U
V3XEplOBxEay5xquyW14eS8NKgOkp5ha03G2vREiUu1rUWHbAMPhmaOZhd2J2Lrs8X7EdKczswj7TtKw77VzkvXg4xO0yi8U
6hHTQmL1puxFgCnBHg4j1HJnI75RYDl3igWZLgYom5aVR1neFFa1fqMU
aBodvTS3AFbVY2uAHEEkrbTU
otZA6Ys0tdt04kV3MgQuEURtmBlzI5c8Zak2YU
2GV2zDmDUl1AMN2e8m1O2Cx9s8EhX8bks5eubU
FbAvqWP5fK6NAeylGVW68L42gCRcqtZX5v17QgSkU
RSTFftUtP4V670FDZ7VxyQwU
p1EBB2vhYm9aVKnNL2vIQozU
g5VTRU378fWFU6xnaSkYus4V
jha2PiDiTHzkUgZtKcWDAhMXPn4TycPkxzDgzfO7V
MDpilqH0BdOwL6j94xLgU46SixgGjC7tLJdY7V
YFTmyrOqpHnRwoKpavhiuH6PpdmYZwNTz2mFOV
K2315M1OTgDl37JS7GmDE3my3O1nUh60xwmx7XhgV
95XltoeoP4aILkhxu7Ipv2kV
JjmAYaHU8Vz0IMfhVl0KVHZgpm0M3rsai7xPoV
vjJ5VTJT2MK1aug55S4FEo8MHxFT6KQja2h3dXJdu3XpRI2773IcV8eJACuzQGn36c3sKG3vUcdinF5MIyCsCvXg136j88qV
q82ylsnq2hFVUi5WYukK62Ms1Gfzpt7EjhdWrV
uzOvZ88LeKL7lKwXzIEGmoKnsYeUgfDIVNwsijTyV
JYTIxXvVyZCa1mYnk2qABtJW
fPN228CAFKcvBKW76TAEWuaKkadmRyg3RdSTQW
hB5eNX6GYcz7eqxrrBRCueLkKwKvNTW9lpUgnW
Fevu91gIMmvfY8PFHiBt19uW
qLGIu6UGVdSC3hXYeOjVW6p31dIBxLEKX3guvW
J48ldYi3MYXfMprG5tZniDKXBiV5t7jCs3rNyW
IIFMHGwa24Yl5u4Vdpd3vs8X
1snfRVGUh0iQeJQnlDLyn5FX
BYMYaZMzWOat2CedlPw3bgJX
uSP0A9xMg9GjOpr8RxR7S5KX
Z3V64lXh4kqfVaaUKUKekyUX
cXyvTWdDIG7Dhgh2Xx4HxiVX
yo7IjplriMcJTkDU0ZcBtcKOKm6e8tqB6OiGfX
VyYYjSPqTOxrbg3yJOvdd946vyS087XauiTFmX
5aHz6vTICWxd8nfUJPWkDqDHjSyAkNDT3Xd3tWENLl9MdGurMp5O1Y8Y
D0XATQnFDTa15nUU82G2ZvNlHKLJz8qoy54qTpQMaAzrBCWpSZfokyAY
21s1YcmBBrrSU8UAtyBQ8MJY
oozeQdN62SJ9MUElVYBByuMbbmee6DAo2Wn2YbLTDhfiL3zPkD5CAUyxymwZyRDWkRn5xlakellzUZTNYaDZreZjgSWm2QTY
I4L5epFGpP5jr2985u0lihlqLpPMEzrRF5bNrX7wAmXRz6c4nud4WE37zoCJN38uzFxLfAzke2Rgteop8aMfuqzSUT5ciaaY
1qwAyebWMjycr2AUfqx18MFA2Qr9pDih3DxTrY
EQaJIW9s7h8jd3Udu9TG6i4Z
J9SDIxUa0LwVTNyPd3Yt7Xk9AhOe9WX6R3w7YDKvuDXCv8CYi5whPABZ
2esuvKcRRUph1xqqeoNQhVOcZoL1r2gTUhwlBZ
agXdQVbBVbXqsQnwERJUvbRHihnBUKN3NUhXMZ
OI8EJBCGXYVGqSIp5ZhZ2777MEqmVBMf3589ymtBRy3BNxb04jHjdRfZ
Dispose__Instance__
Create__Instance__
value__
qcVD8zuGE3oN9Mg2fo82z4Fa
28nWGcCZ4Brp2viL0KIaRksBlKQYERZ6ebIMKa
bbWp9gZF8dnXkYjjQirHlMPa
OLPDQMbkhBm6jAU9kagho8Ta
BP1G2iL4ATAeKUirMZ10kDca
B8Xf2aWBQE9gKBzY2jfw2pja
PfZQob9tLnGNUkcvAFgCeFGh3Udt5kyuGEfRta
ProjectData
ymbx66CSpMwDiVQRq075mEza
ve3UqRmsbB4IxicTXTIPLrxQ21S9eAgcKy5Edil0b
B8wA8srP3qq20E7UIjoko7u09ZBF3HZcn0db5b
jIoE24zqVMjus5wcdkdEuw03SNSZe2R4oGgu6eQb0BSyT8MdJ54Q3MPZ5800ESJpATRBbk0ZKginNn6MNZirBH59PUxmLwUb
Fdb1fZ9r29ZrIkPpHZbMFG4lqRhmAtZrgXobgMhIKxcwz0Rd7Jd2q7Xb
8crVUXuJ8E8fWAL0u0mGvd0k4TWv7kLh0nvvXb
6gKYwVIPtyI5nMBbktwkm8BHaAgWSZxz92BNo7Z0La9WWANs01oSnRYb
z8XBGDoKn8EKMy9wDcvvCfYTuCLm5zivXiUgYb
hIijfX6Z1WrVs9l4PKdVwHIZkzPnsCW46QHXGhaBtMfojYxUgaFetm3vEWtejMQHszvgzJ39vFJM5p3rf6zt6io2k0tqpfcb
lCEimTCCXP86ogMjZd6pxtdb
igiEWUCVFTcZS2bboN0pQMgb
xPNaUo4Xpxq5SApHxzVuyzgb
mscorlib
40n2MzeuNGFMZCEa36ZuBt2c
6Bpd3XI1MPd8W8bMidrjNP52YRBbiEH8VCZM8c
MGDgTOA0C6P9zViuZPJouNIsI06z2kXr5TDHBqpJOb9cmOybKuxTNLKc
HLm1dOIpR1Ti7P5TkumeCTfc
okg0hyENuqPLvTfCrWVk4BtJATBNxyzkFgbghc
System.Collections.Generic
Microsoft.VisualBasic
ckJ9tcwqH1QofdrjXqfXvupHy7c2fWdnI4r5Q9ra6zqao4emuyR6shtxIaWwX8y0NKuS50IG0t7J1dz6iOluv3k0myfjZpoc
LowLevelKeyboardProc
jLxJ2LQzvKnG8ENDilLNOLjTe2szsdpkQiMMqc
I7zLkTiaruHTSnvH14fMH716KxV3g076USwRlsA9VzRpMXxejpOoMI8d
GetWindowThreadProcessId
GetProcessById
Thread
njoiDuAUr5TM6VnMuj2kGuEVwM0WNjtyKYC5Qxmad
6CXOGSIeFkN5rlupTeuQVtrsAKV4JjwRKZ8HqqYcd
RijndaelManaged
get_Elapsed
mqRYEcdsEL8T11pgVYFrw43da1ZMeQmsMEVygd
T4LXD5BIWtdhFO18S40Eiyjd
WLhNlLGmrSb0KCKN9GDwUJgLKBkoOjJfeBzDnd
EndSend
BeginSend
Append
RegistryValueKind
set_Method
CompareMethod
TargetMethod
PKwkjvplOrYn1SliNLOrIAv3sSNMInAA9C2qbIX4jf6llZAAs6xCVQ8e
QrweUVIV4w6EzM3WBc8PWDIe
qeVYOwQO23mbnwfsn3bfNLOe
b5RJor3Xj5naMGiSQWG1oYSe
OeDqyCYJFylGbEkXRVTQ7QWe
jD2FyZMm3UT21hhjZS4MHyXe
TDuAx11bG8PEpkQfX497tOYe
J42tMGkaDIJ3eodytAkhNBlndC5jHLiLLctrYe
Replace
IsNullOrWhiteSpace
CreateInstance
get_GetInstance
instance
GetHashCode
set_Mode
EnterDebugMode
CompressionMode
CipherMode
SelectMode
FromImage
DrawImage
get_Message
g0iq0RD4W1Cz3YSNuMImIF1iatU20bHFWnIuge
WlHk9WzNFsnqJXC88ihB2hZp4XRi6udySiqaLK9ie
EndInvoke
BeginInvoke
Enumerable
IDisposable
Double
GetModuleHandle
RuntimeTypeHandle
GetTypeFromHandle
EventWaitHandle
Rectangle
DownloadFile
IsInRole
WindowsBuiltInRole
get_MainWindowTitle
get_MainModule
ProcessModule
AppWinStyle
set_WindowStyle
ProcessWindowStyle
get_Name
get_FileName
set_FileName
GetTempFileName
GetFileName
get_MachineName
get_OSFullName
get_UserName
get_ProcessName
CheckHostName
DateTime
get_LastWriteTime
dwTime
WaitOne
WriteLine
get_NewLine
Combine
ChangeType
UriHostNameType
CheckForSyncLockOnValueType
SecurityProtocolType
GetType
SocketType
System.Core
MethodBase
ApplicationBase
HttpWebResponse
GetResponse
Dispose
Create
MulticastDelegate
DelegateAsyncState
GetKeyboardState
EditorBrowsableState
SetThreadExecutionState
GetKeyState
ThreadStaticAttribute
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
StandardModuleAttribute
HideModuleNameAttribute
DebuggerStepThroughAttribute
AssemblyTrademarkAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
MyGroupCollectionAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
DebuggerDisplayAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
WriteByte
m_ThreadStaticValue
GetObjectValue
GetValue
SetValue
set_Expect100Continue
EndReceive
BeginReceive
Remove
regedit.exe
cbSize
get_TotalSize
set_SendBufferSize
set_ReceiveBufferSize
Fg0LXm2aBBmARoEzwSdskF0f
hoThhGzuLGXSE943DLxUCMMf
SizeOf
N5sL6iM82AeqS3P5vUUafMpS19pcZKTHgvEN0tFRf
2gzkTe0oIOoaCxxAd44UsaJetrOnk3QIpIMeTf
GoL9hac5iQvw2akHnPFrVvI26BugPeXsKxOprZGZjcTJRlaNdqyEL8Uf
elacZmSRrVFoRik4l3XKtaWITANNr3rnEHnAdnpHUtgS1ofkmO5rJRmf
LW3yPcT5JWF2v9LJRTFEPdof
I5AqwqrgkwtzCWCKYSWQBornYZiVwjrvEhA6x6ZFOGurexggm6SuiZAcB6p2wxGUND5imtynr0no71jTi4rnKI7H3Vn8ll1g
rHL4mROptDRwNvrWOsi5kXdNSaaSXyQqJnTt8g
rLQC8bIyVXTvVh3hyaceL9jCElZwYImbUJL0Ag
NHeAegqyxYzl12c595FsLMjKntesVLM2wnOxDKUTryB2Vrx9mSXf7bRg
get_Jpeg
System.Threading
add_SessionEnding
NewLateBinding
Encoding
System.Drawing.Imaging
FromBase64String
ToBase64String
CompareString
ToString
GetString
Substring
System.Drawing
ToLong
set_ErrorDialog
izEcgZcVIOlYX6cRuZZMhvsg
Cc2mbMzT6eO1f9bKx351cmnOm92X99D5GQG2KjsAXb0IiI1VHexNZViVXNJ6HjgmyKOMko0xdZyQytaQzjg0kWRKF5bsOiEh
3hrjyJYjT30vaLekCQ8yfby7BqDKu7iRKhvZyKauc1HNWXWX8ZGqFovXpcUdmisUfelvrE3JJob6Eedvmw2NhrY9ZRCkuqGh
twojBHMhe6vYHRKen0vmRMNh
YlduXKoKUiEMKCYl5wAd1veWacchOd4MtB7fRh
CZyNUV9RC3GkDmo2JyLyp3lscoo2iAChxhh6nCDUh
Oz1GOJQNshCCdPAPUgPjCjwd1Wtxg7WUOjBuIxTah
DiqJIHZ08jHUYAlLf80XCabh
Stopwatch
Xr1gIBXsbf5cmQKBlqvvPcgh
TUk5paVZvmLn93bgB0otXBsh
ComputeHash
get_ExecutablePath
GetTempPath
get_StartupPath
GetFolderPath
get_Width
get_Length
EndsWith
StartsWith
8HJuk6eP1lIq9kVX3Ad67FK9Igr1MwhDcgnvkrRnLaTcWDgYGD2WrjW0tjiktyTGrrZTOhSUPdNGDqc10RjtNDmBGvgZ40wh
lyrNENxMFJMwXKRbEURQ7Awh
VnOn91setRSUN6anL7LvAiyh
uKPXLH7VLIvKeI7malddOb7i
uEqDaf3vj8nteR7a3YbluikZR8427rocJv3dQeACi
OmsXxaJdf4ELpBrWec4u7i2xxL98hGw2lyyqVi
PyjM8psayDMiuUUog5zSirAspKgfeOQTDCCkZEjei
u8q62irkUdtpVfOpAnCQ5UYjBhpiuYqF4ywHPhBmi
L2Pb4oNTFRVgNvt4odu9YYjA6YotueBUIiZmxW6ni
J2dUwYPd2Y5D4pb34IL8XE3U26JRtd9xAXrk4j
pRLgD61TcQzb2nZkSybEcBoNGMn0VetJv2NVAj
oBhc0waY9oTjTFhr8j6kDiEj
jQAz1Ik1mSBUliGePo4XZDiIiPvahmGiarCT9mhtKOKQtcYSCGFKeAFj
aBf6m9NAf6eH6Xue6bPEvQMj
RWI8uvsHmJUgIDUHQulaha1k
M6o6tDfnNstdWexT1m1PeWaUF4XwzNuSM5ZqEk
okEb0wjyxqMHeUU6Vvyg0Y0TRkgLaKXzWfMFt9fKk
kCUq4dLY7UIIGGocRzo8mkXl2JolYm0rBOMpDjdyRpT9OgwLqWNAJSZk
get_ServicePack
AsyncCallback
DelegateCallback
TimerCallback
RegistryKeyPermissionCheck
TransformFinalBlock
r4i1g5QUpdzlsOHRcR20DkGr630adb8lseb1rk
0e2ZUpyF35KZR7lQ8O9D7JPAQRZnaYb8Hqghtk
SIxoXFUMcpKq4LoP3AGHqsRv0GdjIsBlFy6g2dW6tw8qW6ZV2bUuWCuk
n0ZDnZxOua8q0px4dONs85a4n7FvSFnqwNXHwk
78gmIFcwIEIzH67SwDpXNxxk
bhIdMtREJDS3Ukeq81bQMxyk
nTYLTDZrNOCpRi1sYzURoeJMOMLm4BEONxrH8l
VgLi9TTExElx5O4ISIbHIXDl
9E2W8M8tI9YNerQ8UxaG8kGl
uKRwJPxrU7Q5dl2MXpyh3DHl
RgE2bpuSFXV27ajl2pDBHvKBA4k8UXCpZMx2Ml
PYdTuu4IzR74tXkW6MZTgQPeMjrHJH6jKUoQOl
oiMBVFp9ssUmECbpvjH5BdQl
UWt9u0kNxUMNMHvF7VdtOctxDa7chh1TvzBIWl
RtlSetProcessIsCritical
Marshal
System.Security.Principal
WindowsPrincipal
ConditionalCompareObjectEqual
System.ComponentModel
LateCall
6kMsWLPQzt9WvxnVJ72R36Hgi62vUwRgedgcll
kernel32.dll
avicap32.dll
user32.dll
SHCore.dll
NTdll.dll
set_SecurityProtocol
ObjectFlowControl
563CGERKQ0CVV5lZqynbVP2m
i3BQW0hYSItpo8ME1iLY6eR0WNk03Q4K2sGSZMdF4g6rQjOEhBFuI6SmakqkCzWIIB5r5qpd4fA542NxwtdtsIhBbLBh3KIm
qkax2mG7Iq74P7yJBn5aixV5YhevHLZjF0GUwi5Pm
vYqNgZU5xvwXHU8mNEuSkO9J5f27ryobMaf9Sm
GZipStream
MemoryStream
lParam
wParam
Ye0kbsM1t6t0NXBONGymEy73dZzkXLz7VtcbMp4Qjij0HHLEv57EWebm
get_Item
get_Is64BitOperatingSystem
MH65PQInlRaK0oX71OdHOJaQJmAqCHsefqR7fm
SymmetricAlgorithm
HashAlgorithm
Random
ICryptoTransform
sWpsMySIImccgY6sGAI55OOphr1rRPMaAhJ7ym
6Qwx97X5ipVwjq5fYr26cE4dBSs11gjX2ln1E8qTNoKhRKNWY0AaxOkVAjDu0tGd45OyuSqthqlNqB3mESde8w0okVWVO40n
O8PEVq8mUuYS4yDuidOgBANn
Q50XeXjwwsWCi3S5PviBRKBDuNnNQ1yMX4maJu618D9fTqeLpSHuhlvQnVPSbBunU8UHU7YpzBn1to27cDcKTMtqvHfsl1Tn
ToBoolean
op_GreaterThan
TimeSpan
tOVn7dqeN9SCoUyfzQYRauT7w8L0QHuf0dPiGqe0IDRwTC82YamlAden
CopyFromScreen
get_PrimaryScreen
System.ComponentModel.Design
AppDomain
get_CurrentDomain
get_OSVersion
Conversion
System.IO.Compression
Application
CopyPixelOperation
Interaction
System.Reflection
ManagementObjectCollection
Exception
Environ
SocketShutdown
NG2OMEfz43tYhwmRp2gVvA2o
Gk0b3P6ZLwMSUaZO74cqNAIo
vEFFO2wqJ32IH5lqztU4NJSo
cG4fVWH8poAjlMIVpsvG6Ih3wI2VpUrjXfoV69n4VsXY0lDyDxktnNco
VFLwzl3FPHp2Rq89Kfnh2HOKSZdj7DmhkNCTfo
get_Info
MethodInfo
FileInfo
DriveInfo
FileSystemInfo
MemberInfo
ParameterInfo
ComputerInfo
ProcessStartInfo
GetLastInputInfo
wpqYfUOGXJw9DezwaFPbYcuo
9RVOse8C9JdIeDCiVIEYWDq7zuEQrE1Uv3k9Ap
BQrXSGhVn8RDZtrOmDDkm1Cp
CdHV32qNs8Sgzz2SNgGBB4k28rH1rmzCg7TdLxMxBdjvAeG591bq3NCp
6z1Uois2kVyIjZSYl2xIFhDp
spBe2E4ReZjX6a2sxl1IE3Jp
k729qPaOz0t344SooUeuniWKMJYnCNkHIpKrAku2wgdFb0L3W251WVMp
Bitmap
z6xGXOF0qiqqdj5E7USDckbp
zIFs4576xJMtNAu7qknWFNw8vwUjEhLFvJCJKs1oXovQdbgILDZWfkdp
mvNVaZvEO5BSdLZvxWq5zlmp
j9dgnykS4Ziox9rK6Fh00Hop
tcXBUO2RnH3Iee41sGCeQ7GyYbXOjhJZ8jvMaDWtp
FtzPHn1aDV9kEtYAhZz2nS9q
C1UqGsf7LkniBjZkpHrODEEq
XzVHEqJUejfAVOtKzpCzVHCjgnU5TuPYX5aDmtgeikb5QAeiAjIQFaHq
System.Linq
DJF9Pstc2aDvMOzO0AQRVsY7ZbGN417NdVUptSrpq
UcO4uBIopfnWRyAwcLa3y0n15YT27VD8CjVyxq
dlffLtadMDf3b1uSJxbN657r
ASXDK8RK6C3kXcdNlYPFsq1jFXEwLOlRcmsznEO775h5Wz15tyyOkeBr
S8jN5r0LhuNAArBVCrZNriKbwOILTw2bL2t3QxOmQtOPjmHbeOoyjffdliOdPnGxDMkubi6BXUdIjzcKcZXGntXHxjo2S4Zr
MD5CryptoServiceProvider
StringBuilder
SpecialFolder
ServicePointManager
ToUInteger
ToInteger
ManagementObjectSearcher
SessionEndingEventHandler
System.CodeDom.Compiler
ToUpper
get_CurrentUser
StreamWriter
TextWriter
BitConverter
ServerComputer
ToLower
ClearProjectError
SetProjectError
ManagementObjectEnumerator
GetEnumerator
Activator
.cctor
Monitor
CreateDecryptor
CreateEncryptor
mz9n7fOiIo727RxKloj7fcm6wDdOWnZoRYnFH4qQV3tlhtzrzRqyNzrr
y7Qqo8E51zw4DxIZa4EDTOsr
IntPtr
oJhlR3TVoRW4ygL6PtU8uTwr
dyKVU1EvcF2OHDqhMVEmpQ3hOsd6BuYCmrH9TmALs
nFQsHWAO2vg9OEbz5YU3DxXs
gsrDqZ3Nr3ZqYrZ8iguVp8Zs
5MDW0MLj6c6T3GJ2fCycbVu92IGqmaAW60h2svIOV0B91iC2LHKaU6bs
Graphics
System.Diagnostics
TxAuDUAVZe7PumU3XLS17wY9heVwDWk5FC2Sds
FromSeconds
get_Bounds
GetMethods
Microsoft.VisualBasic.Devices
MyWebServices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
Microsoft.VisualBasic.MyServices
GetTypes
GetProcesses
GetHostAddresses
WriteAllBytes
GetBytes
SocketFlags
Strings
SessionEndingEventArgs
GyRheBGnBNwn8GNuILQd0IxWFeWhYi3l2795js
Equals
System.Windows.Forms
Contains
Conversions
get_Chars
RuntimeHelpers
GetParameters
Operators
GetCurrentProcess
SetProcessDpiAwareness
IPAddress
System.Net.Sockets
set_Arguments
SystemEvents
Exists
QaDov3rWQFbBXgAZaJ6qVdbXv8r6uYcBtj5V3t
muspiyV8erlBmElBGoXCQ2s9NrLL0Twg8sXk3t
9LjR9puNh1ScYAk717BHNhkR56ZjZ3UIn6zXgwS5t
wwlByITXLUhy03Hsgr9pshuakAhGkiUXwxVBAt
9QytjOqSkisEWSyt3S0D15Gsn4zi3TCvLPncuT0XaM2AboqIthkggPEt
dMTnEUKkNLaOpMtsMeRsyYmEEmEST93DHLbkJArEZF5uqrBPwNYDzpEt
Concat
ImageFormat
PixelFormat
ManagementBaseObject
ConcatenateObject
SubtractObject
TargetObject
ManagementObject
Collect
Connect
set_AllowAutoRedirect
LateGet
System.Net
Socket
get_Height
op_Explicit
regedit
set_DefaultConnectionLimit
GraphicsUnit
hH32vHHb9KMhIpIDgzH0KMsmp69yWJp1xlhZzb4yLc6cw8dRijiJD1oow8VuJWEXEqO0XZvkhSTRQfPprHL5HvBC9zDxtcjt
IAsyncResult
DelegateAsyncResult
set_UserAgent
WebClient
System.Management
Environment
get_Current
GetCurrent
ManualResetEvent
get_EntryPoint
get_TickCount
get_ProcessorCount
GetPathRoot
ParameterizedThreadStart
Restart
Convert
$VB$Local_Port
kwTY05fXqFseNp9FFX1H6pa5DGGgRl8C0h1Mst
HttpWebRequest
$VB$Local_Host
set_Timeout
GetKeyboardLayout
MoveNext
System.Text
ReadAllText
WriteAllText
GetWindowText
IATBG6U0Q2vsJcyCNVZcg1zsqv0Psjh6WRphyt
SlyHpynNbDeowG97pp9EMNJYnHR21EHfPTs8Eu
fKeVrUio7VY5LZ3OmpAoJhIYgMm6K1ZGuLihmu
saqmFrxkSO4jArJ3IM8dLE0UZcQ5zMmrSieunu
ZsTNM8jyiyRo5kjzv8VYGOtQKK5DX7OGrla3zoVru
oEZKGbbvbzoxcMVFmZERa23zPOsPH0CfKjPOCf8xu
pGyNisxqGwqEAOZj0nMWqzLEwjGAUnJdqdW60v
wb0JRxZWJgQEkOVGuGozE5aLs1skuy0v0f6x9v
yzOzN0Q5LFac6fr0xFODUf4Cbtdwu1B8z9VxhY91Lq5p6Ajo21utC5Av
6aVwSR5b9aaeBHQogtkSisprEBlJg97kC2oNMynN060CtiTgCBAwC3Jv
8hC5wJfEyCRxEs8jv0RGiRMv
5b2jJ5mdZflJNyZgLIORntUpB7VJg04KvvZxQv
ynVMC2IuqG61lwaX1j4vEFfv
fxZGvBbzTosLP6edVUyAYFmv
2ypnFgKd1EVzw7TbtIYpSumv
a7UPFwWofOeCGFsX2Z9fJQzFnOKdegQd028Odw
GetForegroundWindow
set_CreateNoWindow
h3CO65rjkELK99vUKW85Jtl2OTpgpWxD00prNA3sibPW8q5oa2YYoWqw
8aqA4fZoMqmZpmw35PrBV6DppOcKw5nDLgwi0x
5Hwssdpr6iszy4vxXCYZLoCNcnrpO31bHnTs0x
N9IoGRu9JZktFuiqwTg6eHB3z9R3PsWuSEsZgwV1x
vtB8ir6TKwRmy4VBVSG0BU3x
VoP9TuEARpLRHpu4IBBCeiv0kizIn2T7LRPD5x
Ua69pOr4NEWjpSAvB5sFtn9x
ToUnicodeEx
UnhookWindowsHookEx
SetWindowsHookEx
CallNextHookEx
u415zdzjlUDo3LpQIHShQEJx
efqDq2V4XHyAIBwV4caWHutlrunfg6u0FnWkTYIxPf4z5IOscJGvpgJx
wq8BYgEDlOvRdebY1776V71v34usvVfelOgMaw9J9XyF2cCgzcdkFGG1goZFZlVFY1IJRyzdECo9YM7Sdsji6jrq2U80EdMx
LB6QP0HC1H3FkQ5DzbmfRrOx
W2zeCMPz3G536TUmUbnamByquoAwCeCXnwoyfx
Sn1oizr1Ivd11G9UnfaFcSrx
OyQyapYeTqW2paMHQLmRydHd7tIfVf04notEyx
UNfwyOxpSLbLCb3OhVHwAm2y
nVplG2RV5CzlBnKsF5VzDDqSAIQgIthi7i3Y4y
ebA4RJ0eX3x5R71wg2t5DiGsPXBVhObtdUHE9L7LRfT73GEvS8X8UI7y
ToArray
set_Key
CreateSubKey
DeleteSubKey
MapVirtualKey
RegistryKey
System.Security.Cryptography
Assembly
AddressFamily
ObjectQuery
get_TotalPhysicalMemory
get_SystemDirectory
get_Registry
op_Equality
WindowsIdentity
IsNullOrEmpty
tYcsVSKFCsObbF6Vk4wDkCvy
RegistryProxy
asATp82GySvGZnChydkwNGhnXP1hGGGoQPU7hHZcg5XH2hYtlMHZ809z
jDoIZW5qCB68zYel8ajLYnR5d09F0h3dETqTEz
hsE79BBGSeLvp86mFNN58SzUo3O65uYhwGU1Xz
l3LyB2RxK3Odp5gYhOUOuDJMUiBIjLuDehJmcz
2jUN9NX7J7gRFAuzjpdQGj2f9pakPvV4eI0nfz
AcmAvgA32dxDFHGJBbvkf5sz
&Microsoft
Windows
Operating System
Microsoft Corporation. All rights reserved.
Registry Editor
Microsoft Corporation
WrapNonExceptionThrows
$a26c0265-0440-4237-a288-6e073046fa00
6.2.17763.1697
MyTemplate
14.0.0.0
My.Computer
My.Application
My.User
My.WebServices
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
<generated method>
<generated method>
_CorExeMain
mscoree.dll
cIDATx
"]|NLb
Fqb ygt
'k-7=s
&4/&ro
#vn,ua
E,6]r)F
Cb#Fz}c
hEdGXX
{voGve
\cY"'
^,~)I
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
k4x56jm3WXny29HiT51w8qfn
SEgMHeumE6jqxwOXRrFdwCfv
WFjYy4wtJVOHLWmseAje0vBn
R0WsjDvJ3lyvIzWo5pXtC9CB
xIFCs0WbrsXRpL0DI1Tr9iGL
mWo1I68jggs2TBttK3gdEr9K
eaEYQeOwHp8HMzJc30Jj0pmL
E4ZK1bCQo1YvvOBCpL57bw==
Jmf6VNvlhVC2gOnw7znN/A==
YpguptO1lTRhkjYNHdyRJg==
lTdmxEFIiLYvzXlziPhh6A==
LY6LAeNLgXU6bIhgcAcvMw==
veRvuqFmDnIg/G01WsF0MA==
5uuuDqkLWlwtP73Q
\Log.tmp
rSlJCXXdGVOzpfcsUNYKwwgN
FZYiwMmcL2QNWlvYKYLchnkW
NSaBA4HPHyRRsecbwj9NfT33
JfzQ7DiuiSPleqCZP0VhvJou
mDXBgIyqhKBCLVG55UqQaJ7P
rAyM642rt12NVY5X747IRjWG
38Tqy7kjADlK2I1NupboLuAb
Microsoft
Service Pack
dd/MM/yyy
\root\SecurityCenter2
Select * from AntivirusProduct
displayName
SELECT * FROM Win32_VideoController
Win32_Processor.deviceid="CPU0"
Core(TM)
CZr2anL9TztF73yCQ5IClZmz
W9TxY9hulyAypg4QowpKEBtr
nGFO8OOHRJ9RJLtGzr1hKvdJ
G1keCUxbengGHVscvVAgN5eI
QDJ77F9emmiOTgOJytmxObHq
nM2gGRBLEzPfP74r9de2OJ8u
PbkfEoOaB4Cqldno3vRlatB8
KdHR9BzMYs94ImEWRN01iOzw
B8CI7UtWqXaLIa6pipubxV3O
9OXlJjWeEchHo0F29eS1dDAI
xS4231yzjqG2huQ2JhFBxgcV
35ELaXpUFFDzM7VFV8KBhew9
BVNj1hBFXxho4Cfx7M6YPoan
bHCWS4QPQAaZTQUXRYLZYcKs
niv2scXa5xcqFcPVWS6yCePC
erltxj2pJz1mHA9W26XGPZNC
yd4kK7Yu0eiT9du6qHpXXDeU
dcT7Y3P65lXRPaTGhSGWLJBz
MfuSOfB7KirVxf448QIh4Xfa
Zxg045lmGLKXjPOJh9hkU95F
BuyFLtSWuYwB9dZQbsslAsTi
uninstall
update
Urlopen
Urlhide
PCShutdown
shutdown.exe /f /s /t 0
PCRestart
shutdown.exe /f /r /t 0
PCLogoff
shutdown.exe -L
RunShell
StartDDos
StopDDos
StartReport
StopReport
\drivers\etc\hosts
Shosts
HostsMSG
Modified successfully!
HostsErr
plugin
sendPlugin
savePlugin
RemovePlugins
Plugins Removed!
OfflineGet
Plugin
Invoke
RunRecovery
Recovery
RunOptions
injRun
UACFunc
Plugin Error!
ToLower
Open [
powershell.exe
-ExecutionPolicy Bypass -File "
K4JdVxCeKPbdLt7b6k4yGhh0
mP6tnhYyGsIGHDzuKo0qUIAF
QwUrumhJvjKtijOQ80bxVu1Y
0H6cVq6jgmg829dg0E5Tif5n
MwpwlVPRQ16q6SMQdTnDmpyi
ZQUfnHDLrlCq0YAUaVIAqlRB
P6t72ZtSnq9zj9v6I1ZF4NoF
mCW7rMEBvTjcOKNszzB32ilL
7MaRt2ZZH6yLh6WOOKXVlLND
Ef4w6Qw5qJ9YFjDGAHuaENhu
3OBL5TGiGQ5kdcnVnJgoz82Z
dQMA7qcqBCfjTKto9QrOD2vM
826KErWEYa2HnRKadPfpuSSU
X2kTg1XqsBTFROsBswmeonptON3n3Zs6dtflW97zfVkGHB2ScsQvOv06
G3wSKNMzEV5S5tETpGR01wbzayDhGYkBxMeGFGTsvr73kyol0E64KGVT
POST / HTTP/1.1
Host:
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
User-Agent:
Content-length: 5235
@echo off
timeout 3 > NUL
" /f /q
UogMntvJB4inBHFH01025ExSq9UK0IZB7Y5xHwXFFy3bHgn27jgCjtjU
0GNCwVJwnMT9iR1HMMR6Nh1NeC8mnx6sxfJpRyJjV1BZC1qIcJyKvnJx
ToUpper
[SPACE]
Return
[ENTER]
Escape
LControlKey
[CTRL]
RControlKey
RShiftKey
[Shift]
LShiftKey
[Back]
Capital
[CAPSLOCK: OFF]
[CAPSLOCK: ON]
MainWindowTitle
ProcessName
QxTPskhQoZWXoMrbEhJfnomDqfxcrNrHyC2YgtMecCey9nKfiEFp24wo
IHO0VK0zk2bnq1NnQSbQsW9h9lfoKdyMRafxAFzv3qdHXXDtiFNrwDKN
YNwmhICq3a4BhKX8Ugk57ftqB5k06TYf1c90ANh80POiP2G9WLVVNkw0
fZv0Hb0pSC7KDctoLLkLAnvglBJJoCeUCa1EdllCZfYT4mp7Ikfqd98G
zpFoUshgWkzlht1MN64ee5ltJwbCP8AYyt0VZUy2WHRhlVzNYGyopEyp
rB4lcZKWpohE8VdtahnQ7qqhfxcUor3TPQPsA8ARMEgd3WNPO6fJhfR7
6OormBOhd9r1Hz2CdKIeFTM4b0CwvtNXQYwO6YgJpQINc5vEv83FcO6h
Yemgdt7TRdGobXORDARawV0DVmLzUEuwlRmPGS8IM6Xlj0mFQD3K1EK1
kqblZFc1ZDXqsJ5m5TrURXDaDr8eypuBvzR1jvTNqoe7aXW4aWmih5sn
uwfCjxRxcvigpF6dJbN0rzwzR6U78qAEPtkQjx27txF6l2wxq0Qfri9L
xDoObdOtbmtmqMd707O0odMGVX1HXvKt3ndjbzTdUoy54BxdggA2SSz9
QO9IXWDJlrHodEZYZaXae7pMnK3bNhaLoife31rnDvWqpVKAdVYqC8oo
J3zXgqZNZVXeBWLSPgNRSFOmMch5ucLinheI8KDTasx8pnsrvNANr7Mg
YWjw7hhury0Z1FPFT7Ij0q3oTtubDsUyJxVvLA1v9d9FIbLqsnh26TyR
5t96XqyaTcBZ7WePAHxfWsySopBhA5vdFvUpbjg2tB8hYrYpFcCRsu6R
B6ZAibFfrJpylMm5dGGjWHt6boduf3jon3CrAbckdoUfmPRzOh9pyKXH
dUsaXv1U6hX1y0D6E5xMuxXjxi4fUec8yHhyo1QsPYCh7FOo26OanViE
OmtG8yGQKv830IsCwVozqfBbMhT9qIIpqdb7yZla12RwS9XjwF9p7TTB
gkQTphbLuUJtdTQfTyUnzfFUwO2gQyljDIfheIjBhiKdyGOFUAfF4Lse
hpcyULIPB6Bm8Zs5fcDWg15vbneOSlgXwAK2Xp62mAMtRgcrl7Ss7SWQ
hYsoDwTQXsaglSYyH78PIJY49IfCUWulS9ozfusU166Ptkqi1iwj5XIm
e7NFdFPSmSVbUrV7ejrKtbMydcTT8eLjOOaIX8NQRnAkCWBK7bsOPM5f
ibpR3A3qCAT5maCimSabXCzCzSF1a6DpXwxR5k2V1UJ4AUrAjGHV8G1h
AKaElpVDBPgUpsyBY9pt6voWtKlX6Nh7VfTF3KIRivWj4pxDbeR7WODy
DfrQKkPyxaryYZ63lheW1aQa3ru551Om4teklATB2kBDRiBAqPDG0qx8
Software\
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
abcdefghijklmnopqrstuvwxyz
Err HWID
ToArray
gvrHtOiJ5LWNqxEbnkcmvQ7oVhLtnBE6c86VdjyF6I3jyZWaMr93KMIK
7EqWQaklJF6RSvIH6rMFl7AEAlPWiuIpTWvF30DbERyUjCXcuJRPweHj
j5f8jtN3QX9SbdkKGyBWDuFZEPYBsWIqgvbDCwUcAUh5Zj26j6REABFG
XGDWzVHkP25U1M2tyFkUvO3IeAOUIbACfxlRwbo5ZExMGuoSoIVfcSJu
rXzU4KywvgUvXCLM0YtO6m1jkXrzWQctiG9BCa11M
ztRKebM8PF98PbxlF34k538geSSbslsYo1tL3aSli
2s0je1BDkGrHNIdG1xgeJ2x6s8aXkSXNsOjwD4JZe
S951sFd7TRCoERKxw6xgu2n2rpQFUpteunSpU1NmH
205Wv3hIoEPSzHWkkbfD6t69jH3IlUXnBkwukW05m
uJRld4x8cxod1l3DRUkUnIR1CCP0cONniuHvLBNo0
VPz8bxkloTruz1KagtOAw8qcf8JaknwFvjOtDRe2a
Epp51WdaX6MrbHeWFaHsUqYEIwcMq1FiG6yGK3wEl
oSMq1hfR4CX0AMgqKJrYo1Ve5w5awmJ3T0j6wixkV
gPDHjRij4cQ9vrJH8ZEoVALuGUtbiSu82xE2ZSrl1
u40MWo8ub11jEVkifBFW3czXvBitqF1Wdp50v2lIk
yj8kd787yrtCnTvbmasJB38XlDN0QdINxHsmGKkNQ
QVXHTZ7UHrwWHRKNWWQ0zzmMp6TMYXZnkNrznRycy
MOdZMNgZXVf3CRs5nIsM2YXrsT5UDhvwsQ0i6WGB1
z8BLMQtUHY1EYuHg7mknVKCrFFUhnJzybRv0OqrKa
jxr358dkkdV8YjlGjfR657P5VOVtPKKjC46Lqocnd
p3nMElvqjZkrroDRK38wQVdW3oJJF109z6GzDDM3f
aobsfxPeUKJdi6CABNOCPxuwhqGXft1TBSzTdlbgU
tQ4jhAJ6kDiFAbYqdKpN3rNBehSVBUQuFpKo0NF96
iUimMubb1iCQQpCvcrFCYH9XnqfPHN9R0WCDZMGgK
egBZSS7OT69PzuluY8cobkPRpvEi8AmEywAtEJPZG
YVNJu4cV4RAT4O9vkbrKYnjb0ANIaHlrB5NMA3nUF
9Z8KxgKiq2E5AkkWrF8jGq38H8r5NbyCCScthWUvw
RMiRgSWphslZWiEuC5fJpjVJDlWOmemjacShcwugM
abcdefghijklmnopqrstuvwxyz
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
CompanyName
Microsoft Corporation
FileDescription
Registry Editor
FileVersion
6.2.17763.1697
InternalName
regedit.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
regedit.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
6.2.17763.1697
Assembly Version
6.2.17763.1697
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.XWorm.m!c
Elastic malicious (high confidence)
ClamAV Win.Packed.njRAT-10002074-1
CTX exe.trojan.msil
CAT-QuickHeal Trojan.GenericFC.S29960909
Skyhigh Trojan-FVYT!30AB541762F3
ALYac Gen:Variant.Jalapeno.5111
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (D)
K7GW Trojan ( 005aa5f01 )
K7AntiVirus Trojan ( 005aa5f01 )
huorong Backdoor/MSIL.DDos.b
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.B
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Agent.DWN
APEX Malicious
Avast Win32:RATX-gen [Trj]
Cynet Clean
Kaspersky HEUR:Backdoor.MSIL.XWorm.gen
Alibaba Backdoor:MSIL/XWorm.bceccea7
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Jalapeno.5111
Tencent Worm.Msil.Xworm.16001238
Sophos Troj/RAT-FJ
F-Secure Trojan.TR/Spy.Gen
DrWeb BackDoor.BladabindiNET.30
VIPRE Gen:Variant.Jalapeno.5111
TrendMicro Backdoor.Win32.XWORM.YXEI4Z
McAfeeD Real Protect-LS!30AB541762F3
Trapmine malicious.moderate.ml.score
CMC Clean
Emsisoft Gen:Variant.Jalapeno.5111 (B)
Ikarus Trojan.MSIL.Agent
FireEye Generic.mg.30ab541762f33f70
Jiangmin Clean
Webroot W32.Malware.Gen
Varist W32/MSIL_Agent.BUD.gen!Eldorado
Avira TR/Spy.Gen
Fortinet MSIL/Bladabindi.SSNY!tr
Antiy-AVL Clean
Kingsoft MSIL.Backdoor.XWorm.gen
Gridinsoft Ransom.Win32.Bladabindi.sa
Xcitium Clean
Arcabit Trojan.Jalapeno.D13F7
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.MSIL.XWorm.gen
Microsoft Trojan:MSIL/XWorm!atmn
Google Detected
AhnLab-V3 Trojan/Win.AntiVm.C5374869
Acronis Clean
McAfee Trojan-FVYT!30AB541762F3
TACHYON Clean
VBA32 Backdoor.MSIL.XWorm.gen
Malwarebytes Backdoor.XWorm
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Backdoor.Win32.XWORM.YXEI4Z
Rising Backdoor.njRAT!1.9E49 (CLASSIC)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
GData Gen:Variant.Jalapeno.5111
AVG Win32:RATX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan[dropper]:MSIL/Bladabindi.AZ
No IRMA results available.