Static | ZeroBOX

PE Compile Time

2025-02-03 12:02:03

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00010cd4 0x00010e00 5.97744686799
.rsrc 0x00014000 0x00007c26 0x00007e00 5.84701754903
.reloc 0x0001c000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0001b2f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001b2f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001b2f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001b2f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001b2f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001b2f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001b2f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001b2f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001b2f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001b2f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001b2f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001b2f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0001b760 0x000000ae LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0001b810 0x0000022c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0001ba3c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
3b%(H
v4.0.30319
#Strings
@"@8@-@
MXvANBwtxJ47IX1flp5tmwB34pKCbZw67reGZmKtUOXSLiKFNKIt67u9jZmraW3IvgnENq50
1KmPraUSyXRw7SuQfdba7rYvHffTVlyjxvVYBpqgQ8I74ToZUWHVu0R7OsrNKafcWdKU2Q60
dDHXMH843XGZF0
8Qba0yhejXH0n0
N5XvTpOzbERmq0
Mlw2CyKcUKEVs0
vYRA3SVL1cbJBAawmNK0Gn0TEOFko641
D4Hqlg3GBMsi91
AKQtqlkyzMVO9yTf0WAUwQGIlrkbe3MarFPcHsp2h8urEMVHjebfFMmaeBqzStLsgYnn9pE4ytgMtwOo9wsyyB1
1VzCYGC1QjRkW1
5ANLyoWNZQlscsN2FKzvFFEKssbnUiX1
_Closure$__1
IEnumerable`1
ThreadSafeObjectProvider`1
List`1
HLT8pqw4dnXLd7zhrrNZ8OQNwjO7oUh1
ungChjJS4H5HNt2yWyeVbdXhvBnCeXi1
KzViEglI9Xpbv1
7xzsPJ6BiwSDYYlWLy0UEYjXf4scd2ol37BPjzJhj8uvzkwKkTuxwXC4BLeJIVTCM4mthgz1
Microsoft.Win32
UInt32
ReadInt32
ToInt32
q60UX2SlD8zv42
JmJp4nEpDvSZETV5Skq5tskI4faWcfypJKkHLvG7fhAdoC2
VgXg5WDqoJY6H2
FkOgBXAnvrvT0KVsgijFAQKmDa83C2K2
215Kk4JWyrHeOXH4YZklj2kmBhBybjMbK6R9FKUIkr37Vm973CINwqWZQO8lzbV2
Func`2
GagNCX22VRqO0QqHLENwAtNRNIm7Hew2
yBzVNcZbdgQR0VsBk5r97BwPP2Hrs5y2
2ViICmG3msT7D3
YljLu0povyha8xR3XJ4XEyXjjHJEurnDaRhoZvOVtjfvQbtanDVhW9LHoqeCJPaBSUGFOeK3
yEMoy0huHt8YS3
UInt64
RbvdBjEXNbjLqor8XXAmtfQzJcbSEFC4
xQd4XI9DVrUL8SFi641r0CkEhIDKDuub2lp3RSO2v5bPoviJFh55mf9BFwVNYHF4
KFwROK8ZJX3qH4
9Yw9LGffxY8h30ycUx1XJLsDngNYomP4
p5jAuy3SLslDj7hDAKMNaouhyLNMWGX9hUUqPbw3tw17eW4
FzWH1C5KQrLkc4
OauctBRJOx7Id4
ytgORjcGihJQtl3dFLQqUBJavzsSuwk4
y5hen4lZyxzH6JwfKePEFTnltiODIhq5fVO63UC5Y8mHYHkuRVoY7rHznQESG6gyUHPPZikurqBj8VJNijbawo4
9Lg2lL3QPIPMfc5VPGJyeEF71Pbj3Ku4
OhmuLoy1ylPQuz5rV6NBKGRLndtkhb25
WcaqMKMuYmGOe6QMEcY50d45uRx3eoI5
7U92jekFPGMXO5
mv8VpLFA4laJw5
sAmxFcl5Kc57G6
wAtjqKJuopc9G6
65tTPPpbmgJBoMiSlVDqnVsn6BL3rpKHS9STiZKghtzdtf6
lMcnggEGNqISh6
EBTFbIThYX8LNjJY9nblP3a9NZMWLNpmKNRDBzzr51dvYq6
CAx3r7SViZshq6
Z9MuNkA8AX7BcPymPAtzF1rB2eOLvOuL6KpRm83DVbNk727
DWLfEGTjFEGC77
Np9isoPQwOVz77
IkXFgo2QyijeM7
XmpG89BnHRnUorLjlLf7Vm3zk6sygzR7
1s0Fr0m6AJCXOSirSnwMECZpMUYfXjS7
6ik6RbyVtDo36GuW0yeRwjPdNwJmpvS7
Tn22INEy5jyjh7
1ET3LmpLMv5mr7
TbLSsJ7FtCRt18
SrrEjbP4RH3G78
m1nc3ENf8nVoC8
get_UTF8
TGFkBeul1pYpnHiYGP2zlHws7ltOKJL8
z062xDRgiPMmuraZDZuzn1Qe0g6sMYyG7YXzYUbZn6PZ5yqq2ebr6W6QOE0tSCeliSVwtvX8
_Lambda$__8
SVLqXOjSgi4mipLiqxoNOye7cKak6TsiniieQfPHqjlMfoAAAbJZF86vGEfv7Pa8
qvdgZc50AEnE99
cyfnm6G88prhF9
06t3kSRXl6XOEAoLdlL6I5yyPPjxSQK9
diixwfwjSUBoS8AMG4tIfKcW3k9Mm75dcecShacqpqAfSLZWoBmpClJ4pQ6fWZMyEyYOiEU9
l21jzoN17He5mcMeNEId1YCtD8LKSuLi5lsLoTA7vkPI3AUaI4lfSfjwOz8twMTvUifTd922lv7Fqd2aKhTYbd9
2aQarDUzyl08h0HOIvsKVAkLnRbIHLjd1RMz51WAkyZJ2sQLQwSUgebcuxeYPyiWKY8nsdg9
M1whzpAuYK9ah9
eyKAVE6TSGNODMvR66REReTYqepWDKk9
kmZEeQImiN7Uq9
<Module>
iuLwBf6kPD9g2A
6mFREQRkPXeh3A
cUNcDwNKUCX9KA
QfxSA6K2Lxmab7CV6lqehdSWGwSq5HTA
O70oAv4dblhAOvPxKmq3Bjm9k5kfHfkraS7M9z1lfrd3EaA
54PhqOfngUq3XKehcg52HCtOn2AL9Fhtkj6MtiwkjDj00cA
capGetDriverDescriptionA
capCreateCaptureWindowA
e1RkCNwRHftY0B
H7NfKjyvWdVVjJker3Cxs0rvkkhPc7oudL4ZCjBrjnd2ZRcDfCuXs2C0H5Qa791B
j8y8RoBpx7g0k6sKJ5EiXOaSWb6Sn6JaOa9OEQpvm4IeOYJfj6iM4SZwJxOPxvQR8t2drw5B
qcIvYKk1vTrc7B
CTjWDqkjEghFRB
UKEW9eMwnBzlSB
NRn20bVP7HG1x4ATyrTVcQucf4Khw16f4FcyqjVZdLmsrZRn4Zfy5BgJj1irFWWB
FbKSNnB5qmx9kB
oAgebwfIRBF8lB
lOY6ihtZDUaMrB
RE2w4AUVQy7nwB
9xpuV6cUW1OtfHJt9pxN4PMKLIiI7CnqQGlFQdTp7xybEhHQh4YcNTxoplSEjV0QZ14nVn1C
kGBj3qTshszt5C
ENWP46dEJoxZDC
qUGbXPgm26Wfih0pZggkpVOb5tjZZMNC
GXV5kDKGxuKIsC
FY9pUVdHWOMLvC
lhyAyYNBvyYGhxkx1OR23jrlH2TKIM1D
GQEbnIpfRhOiZ9JOpORGvn19A7uf14hiNKeQnh2uGUEytgsjoL7I2acHSneYSn12hwueP8YVsjAaqL6yzysmv6D
ES_SYSTEM_REQUIRED
ES_DISPLAY_REQUIRED
c0ST3eZtJe0MHKgAX3SaNjF1mRmdY6mVUHWoWhkTWE2k4LM5vwAPtikw6e8EUxPhMz8mxAOD
UXW1czByemKVUD
cNivoTJl4hyxmD
qv3bD1bQ4Zk98MnGoOmvvX4u58HUAgr1ibI0U3s1wGL85SXWMkqAUwsg59HPYRwDnM8qbptD
8dUBjKioXwllPiQupYPrKTcDFViXPdmDF9jcGRV1HVX4yvD
mPnlZMytKAWWsaIlHy4qdZ0Ilx0lYJB1AEnTjxd77QKrl69wbaa4LFbPUVGpMpwD
HVLUuCYJgkeS0E
bDiMMOpKPA36EE
EXECUTION_STATE
fuIr7PDWB7VweE
FPPnEZb3KiJ9AF
FQrgWibgZ7BFWxPFLEfAtMuyQiCOCeia9RSF0xzcLKxAL25V6Wwz48QtwYojqFjRoQ4EMFUF
yrLmTJCSlabKb76Mmil3csXXviww5HN7bSMOwVeRcuZespVCnxom4ZZq87tVrJgF
23izWV8j9UvxkF
B9A9DYGFHkfD3agZ8rz1BDkc2fA8gE2c1Au2mSOYowDclw2D1dSU43beF3ZrnzlF
spavR2BhxU9oxF
10DePWsAzhDb2G
vMQXMFrtlrLZ5G
C1j74fqmXQdwGdMUyiM1e74PNuILDUGG
7nRYMDx2kMUgHG
qgmL4wMwhBdKs3xIAnJKsNzeeXV0QeG2HT25mENdQcY4CLG
OBAx04kaSCY9Y3x0ufebogowWsnG3IqRMaZcydYYF7NkLZWrFxRwCirpcBB3j1Nh42QrgeNG
li9ds9OSINFVKgBLMtgI2MqFQgcxKcqhjj4H4QR8e8vLmgJ3RG
O2Y2gZ2Rh4nJSG
GaQTkY9wbFMcdrvLpiDjD9xYnNxCzJin7Ue2qfwyyrjCqDOzuZk5VQCU89S3xOK3lm9cp9dG
SLEI971eOsxNdG
WxiuGQX8cjQriG
Zt3eRTKQpoWBDn27gnZaKy7HStVKhHpG
xoDOKyicXDXKwG
887psFGZNnyl5nIg3khlKrglZ0hlIs2H
lSzY12X5AOtI6eML2KFmJ8Qp1ot4FNAH
n1P5mI7F8qcaJH
cf8tDKJVyqSeUH
f66UA1nnwp5XYH
aaAHZTVbDnpmkH
086HEFiGKaDnUc1AvcTuIAEXC27Jx3JDArgxmTvKJFjegkhcqFlrfTv1zbF9iOyZfAezhqpH
pKZTbllbULcmqH
EUhO8rMGaskpYcm0BeNS0xnGE3FwNtGkCbAsO8vSvVEbWuH
uLd734OX4eufyH
KfPoCa15iNF40I
d7pgugpAf9URSDtmREKMZQWOIxgeKoAzFX0q7RZbMwDdfEkg7zlF4J2gxY0ipL2XjNvK6To7CZ8BHMwLU1weAEI
get_ASCII
0SHNRQawXumh3cmOyGql5LfgMAcd3Dxl0NW5ZBiGdK3wcofY9BbY0qasJT02kLu9vqlgtjMI
yU9MWasQ8pLj6FyUot6h1L74ZAUxqJv4ulvOXUezPkr2S2KMgS3kZ7A43GflrtgI
owaLceyUQmyvnI
Q3HTjhhZxsVq6J
SWCjZoeD7nDN0ahAp6fbh8zC0ELSvm8tSIPCUxZeg5UxAWynOs7zitiHFUyqmvVJ
2TvY7F9gGAQdK4Ez1Pu6pZ1MT7X85MyfiuzNwThJogjqi7GWRY75H8HHsLUJfcOoXjfLxoWJ
rvNSER1IcBK9C74MQ1J77b6QGb9apNaiqRWfoYwUkKcPcjp5Gs0yNeHUkmLan0jJ
jVUEM3QMKpU6oJ
ciKIXzu64bXFThojVLNjkRasjVTsiPvJ
OqHaR6oRX5VUXuTCisAiM4i80XLqA10K
3oSG97FNbCfWMK
ipfuohI1GIaSZK
hw0kCvRLpBiZhK
uGqGTjF97LJpZ6WeddGyYqzWvzIFJUBq6kG8KVjsvQE5kQMHsK
v0GNW3FtFi7uxK
VKxDmYOpEVQTbdW8eSfTMtUWYX9tCz1LypN7PJI6KlVBkFFG6c7oFAk8UKRCK8JCIhh3jB1L
3j7YnnaEg01qpagDSRyBv7fGuXhZNDSv1rzAO8K0s80JC9dia1u5j0HMp1IRPVGOmu5xvaEL
qGUB8GyjaEz9HL
IyNK6PE9T4dKIL
sT9qstM0rEVQML
dUrNP5oZz9jiprXoSltwDObBtpennjPL
LWCXiiBTbVI7aL
gPFB9dwoiN0LbL
CeUcYoaA4uL9fL
cBa3pFwEN8qXm1IXIueRv3s0BSV8XMgL
avcuG7fZOQGbFAKnJWtSEJl9xlX8WdOVCFE0KZkp36dJWRWTsMgBVhRpFFAc8MyZ6XDEG1iL
Lk6uG0jioEs2DAwDltYlfJHWt7WxqvjL
q4mGrG3sGxzgcbAH1JUN9vL5KmZ4atyfykkdZeGUyyoR0ZeZD3AemH1qorOsOSfHHttOux8M
n67wGFbeVc8UqQhA1VfXvsdiKSbuNaBM
IiHGpPaDnJA8WM
3dxKqyghw8GUzpl9knLhxkRAfkQRrM063iI04UyA3bVp8iM
gs7frPpbqgrrVK1yugUJfhVfBONT9mmM
FBytqMBiY41jqM
ebLPGdJXGFAh7N
67ijtXbtMj4dlg0JA2ojbfcwf8a5CsIM1eVn3vJ8R7k1c2RLDPgsuaKC1N5JpwoIza28KFEN
2clwZ4DjHIAarW0cCoU6q0lVkwmOfMcOcOXEPL8kgux2Nh23xATxOxMACpMb027BeKboWlw5sVTQXbyTlIhFlEN
IEArbWXaw9ETJN
LLoYJqUHJazPTN
CFYPo6VEDhEhsIZg475gQce3s1kaOchsm8uTHCGBvZJN4WN
r9IDDfsfremKcN
TfsVfXpBktKeTuMeFOVVFWAn2tEhfiTx1eSRNIS5zPGlpcN
YZmJfR6vznQQ1dw8H0rFSJIuifQ8FRjN
v0otDzuAckNVteGcSzwJQ4lnQEDsyrTJLr6G8x1s0XltfGrBVh7G5FyTBreft6r3WBo9XVjN
btemGnQu0t45x2LJHGqgQOMxDVbiP3mN
dcI4xmFsGNVJ3WWkZAmIoWLcophuJYpN
puOcqdlyGZUxqN
VU4iPxbBs6G26O
UPJSfwaXj0wa9NdlS8QbIAhlATN3Rl43dhOIzK57unvX2FO
LASTINPUTINFO
System.IO
c2QwWB5fiXzDWO
XBXPNHkYog2EXO
CP1IeGA8WHle4P
p7H4hralVgNIEuU2beJCmgv8kGJXxSDP
E6OH0Si9ZRCEfRaS9LnjtlLNEsOrkU6hem6LzMvnWUrstE6abN12aumlUccqaVdP
QBZRFkPqmvz16Q
ODSS8YspALpAF6U46p0hlHsAY1EMcw3FdKFtHlWPgBnIlLQ
Y3WqPtu8vOowHGPttONT3ZkADVqyfvhQ
PEM8UwnorGapcb2xGNhMuWxuCuvNOGwELrtij6vIOuPKwVh1xrBVIjOgo0WZ4VedLxq4iJwQ
5jXox79n3ZqSOwvjdRWZxQj2BGScyAj3S9E2heMG9mUXvFSt7VBRmEaHomMEq4nmQtvQF83R
aDeyxHLnbE8WRR
hmgmgjz2OXL3dudMrQy9vH3et50MocRw75JuwNOoVcX60dR
QejdzKB4LuxUkR
5REBWnOxhmWblR
guHQ139vc0twj1uvbRXfvUshyBVmP29AtFq4Zl90Fj5nxoR
Uq7wdfNxNSGqOG52KF2ALRUiQcdHjC3S
DKkFm66kA06wIBIjga1IcOSpamSpf75S
trxGo6lrSSr4ylIAsHV0eMfIAOeELKgcmGjddib8PbSppSb3gMa4cPJmgg0uGJCS
ES_CONTINUOUS
4wYPfPUe53RxSzO50MjkpNErMnvWpjlS
0tzWpwatkMY0jZxYpaEoItiRA3j4j1vcAfpDipEaeL9K8sS
GQRrLPlsvn0oE5Bzt7IVfJJaN4Ozcyt5pH8ZEH4TRY5NWd3jkYAedOGkEawdZwLT
1CHNeztabm9AMT
UAhn2cxtsXsjNT
fBXTyewyuLs6gFFRW9BBqxjCoR6AFLPT
HmT7Nolwr6sgQ93akNLcSZwXsfcVxtwT
exH4yRY8dOsLdM2UAev4O8gbV6gEj01U
nuik5qrt6We9EU
gzs22PE5nWJ5LU
UnC569TYlI5jWU
RtuDYm8rsMVfkU
fRL8dmXPFeRilU
xcU1UJfUq2HrBXZTtan4lwX5fxAJDIb2kboP9fT4wMIT1pU
agzlG87BmJVdtU
StXS6zKKDeYmIUGNugaRmgQarNyEMOwU
36QDcv2KS06ZAzRyvsNRDtPOObcducv70vJiinJtByA0m2V
u7DTVHOpvNo35V
oKT8BZUTFzkT4ncnMTSRTOuAtIz3ZB6V
yQvNr64De5Iz6V
TgA1YmWQTUmUJHMySbItue6LD0SHYnDV
ecICNgvZXOLeUnMj7f0esKOotrALt9e2EbF41GfixDafcMV
HD5Wdc0vHSMfPV
DOthwnH6BoZJSV
8HAiQ97Tzg4zFnVipLkP7IoH2y9zapjoDsLzzWuVQaP9dcV
XiGdldLy4ZwbhV
hRM575vWv2ucR129yFDd05zAWeJAIAKm2nAdKoGHXrRipQD24b9xJizAfMlxGvjU9IId7SmV
E5xEZgowXYRzoV
4V9TTwQIC1oOvV
QgNyMUvUH9BlEZIxWK8QNXk2xyz6k0EW
8tlT8z7Ro87tgW
Tktvk7KQeg5mJX
MVlpUJjP3w7kNX
GnGRLjpXAsPCJ58Zm7ZksPSSbMyQhNcX
5Fwk4sclbrzjwpg7l2GdrTIKgaf8w0TdGcBqVkbQDoKb1r6dkX
IYK1pGL0Ait3qZSrhTUumCMcETpvnuqnTCuBQlY6LTyMOLcGzX
2rgWgfIlN3EE3Y
q6ccUuodu1gh3Y
INrRQZ0eNADyX12C3mXGGeLn1UkbLSDY
Ha3F5Y5XkwxsPztesFoj8QSAg20vFUahqqFl8YusPEk5THsmEY
3lkCJu5FuakVLY
s09OhUZYmuLfQY
CIzfAkCsQmnARY
EXS9AKUdJlE6cHgmMZuUNhJFk4nsP1FuFDv9vpzk2UuKg5j1b8P7N3JKFJon1AUY
xY87bm9CGIrqVY
yzmYZVEwS92tYY
xIoatlitKd4LBfEY9b0dXqnbvw6mRYbImoTJb4zzLVqW0CGAot4LFoRVSXtjisCFeRVvmLoY
BtPRroH01rUCJMAzaUI67EKRvwQbmuW6HmoMgwdfFJIUmwfL51bxOH7GdghvBssY
9vpenHpD04m8eNjDPyaOVqG1H1Z8rJiay3iu8VhZx6y89u8gE3xtFgrabUEpwWdQ548Jqd4Z
5rBQRT1mYqAfHZ
0idnkYfoBACQZj34O7sWmopdS8rjhyLZ
WYBVYsYnOQF8uoSm6vQW1hBxNotD9jMZ
NbJHrImuTYAdB4AGwWhAps0aDT7RL2aCoRg3TXFAWSyLXNZ
LdyDJ7sh1VzGQZ
DdqEJlVHwwEXJYtPKFxPANYhg9ZIXsLVODCu1mPfAsUayA5tSLlo5b03GrBPT8aZ
wn2u3NEgbTsKdSsFYJcDoa7HC4WlO5dZ
gJ13jNHRRGtXY8i3VoWI53RiQlIuEriZ
dpR3EanYcXpIoZ
AVp19KN4pUPGqTNnDWvhzNIBk913NnOgcHZNAPuV6DsGw5DcvCqwgnhdKnOhCJoZ
Dispose__Instance__
Create__Instance__
value__
w5LsodJ7QM14e4R8ySpoUhIPt3tTVSBNju2FGLV6mnbJxFs5EXe4tm5PGbGDU8q9mDuzqtuQGvHhUyv89HWso3a
iAx9EOBbi8GWV5yHUlASGgryAH2ReO9a
DHnD6wUtd5WGmucH5i5GEpSVkMoIi3owIiismUuPMn75pCa
s6jFJy7DEbMT7ekYXBxufUwrMojbUV6QvSUpsKF6Fg2OrPY873X1vxUdb9jmyot52jngY9Ia
BOiVpuDyK2bzJa
ygixBxv8ag4MQa
rAFEtCBqivVcWa
UICZpvqhrliR6FPYeILxx5iVSKAm882YRzpRNlkeDnUYq9zLba
JX8J3sj5s6Wqga
6hPSzq7NCDVBSU112NvsRba5lF1BDhd6gIZPDAQQHVOeaesNhkBcJ1bCv4GbMAja
ThPbFz11tuRIBDXCSsaed0IIq6rhiBp7nUq4fDeyYrrOafvija
NPK2p64vgC7LMq5Y2x4VZwUcHklzDwfbM9sfGuZ7r9rM7na
Rnehokq8GsJKJHZzvSMt8brRaEAxbiGPg6dhUKgI7VC6vMHlqa
ProjectData
sLOxKpK4IQo3wa
aG1CBOjvQmUv9d6HhWzWFwkIHlkzVWrnjRMPcN4WG3FfbSqheHGVXvgLylrLzrxa
Ap4JDmFodHHB9mWbnV4yaMlCGyyiOs3b
r44D1ZK6TWOAaYrcccUxIfgXrBLlUg6b
xCmgZQqtvzuK1snW4pz9nC8U9GYZYqv8dsRsKNpMAxYlVAb
jpfkev0z01OZO0AcrRemN2nfiNRyaB3G2vMzTiKmAVxpzhUZAb
FGvQfLQ6SznaeefDnfbYLiveHcYKm1i7jN2Xb1bvIWsBUsLlGUZd5bSNXw9P4nhXOCmNUqCb
2H9S2VeRB9GpKb
aDjP0XdKuomBNb
PHC7tgJsThu2Yb
YVnS7vgUbo4sbb
txPgBTjLr4C2L4l7zPXkMOSxXcT5KHvJWQoFa1axrZt1AD8mcpAf7AGis4F4bn12kwS8T8eb
mscorlib
BCpMrx8paX7AWY0AkpBt5YhcwUdrbalVpRUfIBJXUV60T7CkiK5kOXQNQq4mW02pIuquqRQX7HdwBfflKBkyyib
QWfS1rEG9gW2tmKtnOP3IecSdTacGSilVoWahhW1tY4jL1c
Y8VPPe0UaXqw5c
6APnlC9aLufhucuv9Az5qXPVJxD8Np4K8ibQbxlHSeza7goEdC1I1j14Brc6NGtuTbSVM7Dn1kag0bJCHWJ5e6c
9f9oi8Oj1JgRPc
ykTRaBhlkAe7yknOClzt216P4EsW49hUJVmqGRHX0HpFe2kkvl7zzt6lXkYSvCTc
1Xda3oZZfnEIXc
9DhABmSXSPU0meTprNZfjbKU97d0OPz0a5Fr1hUWErdDtlqL77nV8yJrvaQnHoXOY43japfc
System.Collections.Generic
Microsoft.VisualBasic
LowLevelKeyboardProc
1oypXl97MIg7Cd
OupEXPnvcwx4Gd
GetWindowThreadProcessId
GetProcessById
xlrPyB0sV3lKPd
iLIOKMFULbYcWd
5UKmb7m35WF8tQg2RlHhrJx2vTySJcmNXEAH9NIvQjL5g3TqZ96EY8xvPqibZfWd
XKyVZiJlFLdAZdz5vbk4nvkwx6PoD4BH8Q9CC7YqGKha7O8gltLSggYSbucPfMTjoJDplQad
Thread
RijndaelManaged
get_Elapsed
EndSend
BeginSend
Append
RegistryValueKind
set_Method
CompareMethod
TargetMethod
D190sjfXsqPOjeYwlAgEHR2LSL1Iq40dn4dLUGbB00QfcB595dqtWeZf8QJ43cwd
8kLOpwRDcpekHe
Ce3PCRgMJjL3D8x2LBbagknT50CazfrgoIDD3Uzo50KXKWaZXTtqE1prupnFtD9Y2Lh8aXIe
nieCLy06kLzSKHvlRRwJBVpVXGENsc175406gWLkSz2RenICp4eh4Yvc7Ekzu1Ne
vNMKylgNNEbcLsJtnfSQHufkG0KBT1Qe
dLZztUkWn8PV72ZxwM6hJpIiAHlESiWc6tz3Bwc2RsxLGAKeaUkNSBv1ssz9cQs6Cy5cgiZe
oOke6F5pCJQF2lshhDVbeHidbFfuquUjXQF8qAUdMdVT8xRm1FURoATHSAdTQkbe
Replace
IsNullOrWhiteSpace
CreateInstance
get_GetInstance
instance
GetHashCode
set_Mode
FileMode
EnterDebugMode
CompressionMode
CipherMode
SelectMode
FromImage
DrawImage
get_Message
EndInvoke
BeginInvoke
IEnumerable
IDisposable
Double
get_Handle
GetModuleHandle
RuntimeTypeHandle
GetTypeFromHandle
EventWaitHandle
Rectangle
DownloadFile
IsInRole
WindowsBuiltInRole
get_MainWindowTitle
get_MainModule
ProcessModule
AppWinStyle
set_WindowStyle
ProcessWindowStyle
get_Name
get_FileName
set_FileName
GetTempFileName
GetFileName
get_ModuleName
get_MachineName
get_OSFullName
get_FullName
get_UserName
get_ProcessName
CheckHostName
DateTime
get_LastWriteTime
dwTime
WaitOne
WriteLine
get_NewLine
GkkxwvY1vcXn3OxVstDKQQDq3XV8GRA51SO748JMx3oOine
Combine
ChangeType
UriHostNameType
CheckForSyncLockOnValueType
SecurityProtocolType
GetType
SocketType
System.Core
MethodBase
ApplicationBase
HttpWebResponse
GetResponse
Dispose
Create
MulticastDelegate
DelegateAsyncState
GetKeyboardState
EditorBrowsableState
SetThreadExecutionState
GetKeyState
Delete
ThreadStaticAttribute
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
StandardModuleAttribute
HideModuleNameAttribute
DebuggerStepThroughAttribute
AssemblyTrademarkAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
MyGroupCollectionAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
DebuggerDisplayAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
WriteByte
m_ThreadStaticValue
DeleteValue
GetObjectValue
GetValue
SetValue
set_Expect100Continue
EndReceive
BeginReceive
Remove
cbSize
get_TotalSize
set_SendBufferSize
set_ReceiveBufferSize
jSHe3LSOy5d7acui9IK09KEleUpz0IyI0PzElxiPEY6k3yMo5f
SizeOf
TfDFiQR61Hpt22HliLvvHl8i98o1c0lySLfnyhMWdyvtNKVp7ipIC4EB385lugOf
6vvGF7pACm5z3J2Z5xzlkCJwVD2rDsGfXs4ck6GrNXfZAYf
71nfjibmGAnRmw728rq5bgnzDwVHDjTjelsmBdhxbNlBG3Z3UgwVWnD4CQtvxpwtT5are3Zf
vcea8Oa1Xj0Bcf
5fySABzjsmjcfvQrWLz39l7ED9nvfcff
0c1EP6BLai8ogf
MpzAMpkzcXh7nf
VDb01MtTa1mGnf
CvnPP0mTuZy1vX4UJqDE42r9uNYNblSQxvNjMnkF5hHAGNkTmA4Qwwdg6KkYKBiwsa8zcnfB3Q0OeOKTzFVSexf
QEMY1ozNCBhN5g
Ay15kkoUOMFpAg
kUZl4mRI8QTOjmE8QLuIBsIfmk9z9oGg
QWWUrbvKO3yoTg
mElzHDqdOZJ4Zg
q5Z6xAExeZpHZg
get_Jpeg
YtwFaxCyexX6pePKTT0yyhyt6EAIOlwryyXBDi4bFPCziw1bqyiCghDaXcT7Bb3NnXxvlBjg
System.Threading
add_SessionEnding
NewLateBinding
Encoding
System.Drawing.Imaging
FromBase64String
ToBase64String
DownloadString
CompareString
ToString
GetString
Substring
System.Drawing
ToLong
set_ErrorDialog
xkeDddM6zmR3IMf3M3Hoh9PG58RaJDAkOcV21ZJyeaJAtyB7Xu5tnlRUY03kTcug
GMOTA8SOGSXR0h
vTh7ICcGSBlCbfX8pob7xR2RR8IJKJ8h
ivMlzfTZ6TS49h
EierHYbwIK915SsLoUJXjmVEwZHdg9GQPQL6YyqLTIVJQs2M9h
SxIN37e8xxm0JpYU22wtlxli2p01k2Ah
feG3PNwstG6VPh
Nn9ejIS7jBN89F6tDJU56aH2QgeRf7DmatBtoeugrcvmcUh
OemlWbEoCBV0XeFn6UkiQrQv7QdJNqouois7Uc0ZZNbdeah
Stopwatch
fb6LH4GKzaL4eh
omXawZ0iWx9q3VfuUPyKb3GmTscA6FgzTweMN6bj57yJlnh
ComputeHash
get_ExecutablePath
GetTempPath
get_StartupPath
GetFolderPath
get_Width
get_Length
EndsWith
StartsWith
TcZzuAeYyyueSQ9NfhB1JV1kYhAKhzqeisFb5SmrIWc3MNXm4zBgLWSQYp28UjpOe332w8wh
CcFFQiQDrfrWWvYAMioSZmVUYqKKJIAJV6Lll7EtdOQuZPQHQisxisErsJbjcw3i
d8lcHso7D5Hy7i
oTxe5c3AYJ33tvmCYgzLZJaPKldHzGBi
vCgABBL5sajRDi
4fycSCpyc8QaqkH9oVuK7Duh4sqTpy9FVYvDNNugFqybY7UbZsiteq9rc8PWvcEi
MlnLfRxlqI3QWi
l5GgHAt9jt0AAWncZX67Q5BZhQz43PL1hN8zJSHzIoeerKHlA7t8eq12ylmcxSYi
TjKXbrojrs30gi
Hengew5cKZJLri
UN43JDaCxwf2vi
yGDNVq2XLvRx8E6O0rLnNbFDga55bqoz8r9tLFouRVPIxtqnEb8Xq05M2R7SZS4Sej8d5vydNDHsm04TCkOVuwi
rq0mP5fbrrGienm34iMJlV8OBleG5ihF1iCph6QHEbreGibjQ4mBNMXC3xLrjsiKJuWkICxi
LMOnQpBxW4Qx4j
6n19JdkCpliadqnwS3IVM1SJBVVuqlqrpHHOZuk4CY63dCbZ6c5VkAQNcavPvd6j
VKP3e46fF6MaX0jxQftJxayC8cDg2DtAxvDUkDLCv15DLRF0oWjoabF0QeTIW48j
SC5O8teOqIehDj
B4tjuTnorFE1ExsnqkDPkJfvrr8Fjd2qOM4G6HZAWjxdMxzJFuj0pykSYkkBlcEhJkMYlWEj
UnYRJbmfkSgFBnLlqgYc9gWs7i79vSLVwCLzbg38SzojZIjE31eYKqsKdQHlCqJ2VR4CArIj
P6yq4zRWeQ7wRdmV4v3F7QDowjBDJPPj
0nmXBTHfGe0IlVXZnt0863wNH1l7HGTTWqNsPR4vM3K5XTj
zf5PQHaSznBeaGaJjRZojdVVpkS2qRWj
Ty6OUTW7bWOknj
DCFzEJg9lGo3xzdsYxYsn532XFruplsj
p4BbpK5jyEVlkBKdl72m5PMy2x819TxMIPagX7sk6HlsDj4Atj
cJ3wrUeSsQSrrgoboXZv4BnahSbBWISk
53mzyvpb51nWSHeDds5sJDo9K6kl78YkPDF99PgXrCzkuUk
get_ServicePack
AsyncCallback
DelegateCallback
TimerCallback
RegistryKeyPermissionCheck
TransformFinalBlock
CnovDEyG8Z12GNGEatRgDv5GvyiT8Fhk
NRNuMaJnR5PzWAxfgZGjupvTA6J1eOok
06ZOJEwuyjGYrk
pR8wmiRPX85Z64Ceyr7dE0Gqc0eOjRWueo1pKpjUwXeYC5jNtNKiICKA4PcO4RjxoZN4IE2l
y96N3GLgEeK6mKoJq8veP63IXPhyy4dlHz5Aj2cwwLdSFA6FUcm9dEwsyOYGANCl
ZArII8TeW9hePJkGZHcyUTMQfmU30jSndecb44QyCZBLOCl
jQ8AUjFJ6ccCznaBUlInuvIp5zzWYEwaH9G0k9j67oh8MLl
pqbv3Ki3dgIrVl
RtlSetProcessIsCritical
Marshal
System.Security.Principal
WindowsPrincipal
ConditionalCompareObjectEqual
AqoEj7vHOTS5bl
njitnHfZkbfPPLSiO0YauANteYSoEIWdSG1t377xBuuv7xSbKZFfBHZ6xLJ01Ccl
System.ComponentModel
LateCall
kernel32.dll
avicap32.dll
user32.dll
SHCore.dll
NTdll.dll
set_SecurityProtocol
ObjectFlowControl
McWLHgDaeafB0D6slDAzk4QUfL6wYB4m
ZUMn3Hmujnx46m
315jSgRN6ch0w3lGHBCQvrXfnrKK0EM5RxyCwy19llvH05DjhZTnKSZ9iWYVuZ1cS6XZUr8m
PDUlLFn3NuOMGm
NdQaQR1SLJIAunfV4hJJ9YctWLjcFJEt4ViyaO3P0Rrx6pm9Pm
5HkeUzSZjxTUcbBDuVbPWBwm4JuvmjayPW9O2rGPfkDpJUm
Y7vvL7auAJGSYm
FileStream
GZipStream
MemoryStream
lParam
wParam
cnOiqRnt8CKb4pTa40zdLwjy27JEA2sKp4VDYcIFTRIYvdm
get_Item
get_Is64BitOperatingSystem
SymmetricAlgorithm
HashAlgorithm
iYWNOimwWFArlm
nZTnLFO5IkNKnm
Random
ICryptoTransform
EZIHgA7ZNMHzRWZPPS0fKh9JuO04lOwm
km9ENLBO08QE3a4EinL3eyfH4ZiwAaJpVPVGWc3Vdb4eH65qswQg0aLrFpjB1n557okdouwm
1cCfDTr2egMiAn
adZKwwj8tlYJCn
AThajfd3PgEWfasRyFF2O4AmYr04aD095G95EzehWVWPphGQFn
RYGZocMK3BPJHn
PkCDrjwGwmpYJn
9ohuU6ZybLMFQn
w0LhSsBmTLtJEy0FLPvJ05krF1PBYIRn
NDGDqahKsS5ZUn
ToBoolean
op_GreaterThan
TimeSpan
CopyFromScreen
get_PrimaryScreen
System.ComponentModel.Design
AppDomain
get_CurrentDomain
IUofWEGNlrYzWapr7TuvXjGesKhH2tlVwQ5wI1rFCrpFrXeVnn
GetFileNameWithoutExtension
get_OSVersion
Conversion
System.IO.Compression
Application
CopyPixelOperation
Interaction
System.Reflection
ManagementObjectCollection
Exception
Environ
gpDRnQuiM7qolhXxZikH3xBcXKfUPuqn
spzNA4ULrxvJ2li6Tyh7MHvO1Bh1wdvn
SocketShutdown
alULNrh16VZdyHCKEbt0NPndV4euYV0o
zW6CiG2HGMqE5o
mzSryiHnjAmgRJUw9iOTJuTytmW75AKo
UDAkS2HphJmNHQsyFYKvdsvZMb5064So
EAdLWgcsBtcRWKupPUEQaI55IlOjDlUo
get_Info
MethodInfo
FileInfo
DriveInfo
FileSystemInfo
MemberInfo
ParameterInfo
ComputerInfo
ProcessStartInfo
GetLastInputInfo
DirectoryInfo
3XnSDxGValeA9p
9K0kl91xvgztX7VGF9SaZfKcHSypIrrpUvLDYgbBkhyvbZVMCp
YoxTHUBB3h5EiZXLKtOwNKjmLNQLcQfufkHeSFurTurf2ixmfAdFNu61EGsbxsvj6TDiHAEp
7wac9rRonnXnHp
6EOLtEumLKETWr5Y6yMeRgoMxHtYzCpgaWYHrTMuXwT86XvVAAr4FvWAu6eht3Kp
Cl4F2ZSr1zENIhwbQkPRLwtHLSOD2iZVTO6Rvm25zSpiFuPyIKZb4RXyUC7w1vRp
YXnZouVbU1H6Wp
Bitmap
Nd416TiiHp58b2eiM2XEH7HkSQEyTDep
nz5L5y3Yswcjmp
moZiE7P5DdleQ5CYAJT7h1OYsFgFsbMQoDdawqeoTEDOFiHEqPkWwwX4QS6yCX9q
H5CEDMfDjvcwnmx7GybuSy5OVJf3kmH0tSCO9Q8fJOntcblsLrfmeunGakmRHmo7ZKGX8iXq
MYmKItcXxH3mGVTfBxVx5Hr0UcmFoDcq
Dz9RzcsEtK4ecq
8peeCQudQHr2JFFIPAeKDHC2ceJTYN3OojvSL7oHgfJvJfq
jvP68qvhtfVMmkOqS3Ulc7qpq1t6WT0yrmneW2YBAdNJD1cnVeH5hIofBX61nmVJ3I478Skq
System.Linq
8x71cDLwcYmq8r
0rGpkTLE4hfoiqCJcf6hxAaGIHSjsKGMtJysYQ0nw1Aj3tZIy0kzH1Ty15FBeGBr
yYIcRyciPW0oDr
6OIgm8Aucz4Wqe3LZNdFmR7ecc11acGOnhHuUKJYRqEwsQr
nibWhMVetFv5Tr
pMz2Lmt2dcgXmlMjfGnOeS9zJANMLb4IwzYiOO4INUqiiwb0LhiPdRIm85f45Hh6KH3zwRVr
MD5CryptoServiceProvider
StringBuilder
SpecialFolder
ServicePointManager
ToUInteger
ToInteger
ManagementObjectSearcher
SessionEndingEventHandler
System.CodeDom.Compiler
ToUpper
get_CurrentUser
StreamWriter
TextWriter
BitConverter
ServerComputer
ToLower
ClearProjectError
SetProjectError
IEnumerator
ManagementObjectEnumerator
GetEnumerator
Activator
.cctor
Monitor
CreateDecryptor
CreateEncryptor
5Ms1VrDKOx17R8U0eSv3h0g1eGs1Q57mbVYBX25VulCMUYCZkkFJaJ81VbjTTbpr
IntPtr
EIzdOW1c8mwMiJvOmE3GZMRZWgi10RZBrdeGeGwLb0yfyzZ8nPmd6tb4y9upbGwr
5UjgqWXrKMtnxr
3zALUn7D3G6ox6EQWXeZlzYr22w0Hy1s
U9dnBHHUW5T9Ps
cXJ09is7j2xCQs
TA82HHNPoy3U4B2pNCB42AO05y2fQJeeGQiV3q5K3YEiXKtBIhT9odwpM5FXtqSs
Graphics
System.Diagnostics
FromSeconds
get_Bounds
GetMethods
Microsoft.VisualBasic.Devices
MyWebServices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
Microsoft.VisualBasic.MyServices
ExpandEnvironmentVariables
GetTypes
GetProcesses
GetHostAddresses
ReadAllBytes
WriteAllBytes
GetBytes
SocketFlags
Strings
SessionEndingEventArgs
IZWVadEeYa7JE1xZsMWfi1NODqRhkjArYYf2T7HIzTRtdoOavXGEGtxV3h6nlKhs
Equals
System.Windows.Forms
Contains
Conversions
System.Collections
get_Chars
RuntimeHelpers
GetParameters
Operators
GetCurrentProcess
SetProcessDpiAwareness
IPAddress
System.Net.Sockets
set_Arguments
SystemEvents
Exists
jJMFFRu5VPs7us
gB6ROevv3DgG5t
g8KSApwgjPkLPQgeh2DfXcxt614LrV7t
6XP5GfljRpEy9t
6Pd8CkoYAf6vEt
5dua2tCXNqv4Zt
Concat
ImageFormat
PixelFormat
AddObject
ManagementBaseObject
CreateObject
ConcatenateObject
SubtractObject
TargetObject
ManagementObject
Collect
Connect
set_AllowAutoRedirect
LateGet
LateIndexGet
System.Net
Socket
get_Height
qzzCY4wzWrWKoK02DFCDimAcudWrmiY63msEp9nxgLC4vXKUAZJi7qLsioO3wineiy546tht
op_Explicit
set_DefaultConnectionLimit
GraphicsUnit
WaitForExit
JgGr9kKJrhsZi57NLy9icysteaZg7MKfNkgqoXpm1Mvyfkt
IAsyncResult
DelegateAsyncResult
yozqNpSsNzk9KxTmthK7qvwRevZkNGYyETwbRizI4f6T8i5wu4s5fWIhSOGpTtmt
ToUpperInvariant
set_UserAgent
WebClient
System.Management
Environment
get_Current
GetCurrent
CheckRemoteDebuggerPresent
ManualResetEvent
get_EntryPoint
get_TickCount
get_ProcessorCount
GetPathRoot
ParameterizedThreadStart
Restart
Convert
$VB$Local_Port
FailFast
HttpWebRequest
$VB$Local_Host
set_Timeout
GetKeyboardLayout
MoveNext
System.Text
ReadAllText
WriteAllText
GetWindowText
w1Kd0JFZNi8x0u
zxDEtigr80ZZCzwMnn6XkOHhYpPDEZ4u
YMmtxon3nTfNQs3PwP3DUDPyHPvIMntChjky6yaJQNlICEu
dMLnDDEjvf63Ju
ByI3shJxL0hsNu
VNkR7Ml3hNyEhi74oDtfbKlLhIbI23SCdDOTKpCCkaaiJcu
Ld1DzQEJO2YKvu
qrHhBY0l3lML1v
VErwzhT7efn49v
M8X7aL1mNXYNLv
sMCvwwXR1eYZiYUzI5Jl8lpAtyqgjcMv
dfOHdlRWPqXhcv
y3QIs0wtriJrfv
NGDYKP2NXdNej2HUaHTRTILJbg1YU9fjvZ81JzXfrv7vApv
VCYcBBh8GzpQiudZoFgrzbIJ7Y3UMqIL5rACeYYeQnfA2mr2GtuxTfVInWGijYRVuppVfdtv
Oi2CCtaglqZCjnQv8q4OwejTJHaSGjuv
tDP2su3kOYNs2w
oCPreQkiOhMw4w
yPU927xqDpjlnhxhlR5enoGuCDNYNLVB0XQjf0riTgPfHfw
x6pS2bta8muFdJjxLFKlV85vgkrP8QznlBSZUZzcKoU7rk4miCuqmCzBFlk26PY9VzydrZfw
aVnDSh8R7O0towLmwGwDvYMRIisKFggw
lQ5M8Df5ABdYG1nkHbP0kZ6VTxT32OhxDeooK8PDCE7Bwmw
GetForegroundWindow
set_CreateNoWindow
6dOcV7NtPXjKrw
DthIwR8ezSPn4EhzL6XL0eoJSU7jzntX0HPbyVpx1uZar17Zxw
lbmxh3goNz9hxw
WEQNAVDhr381yw
yC7ClXxXRaWyyw
oRNEhQPsgAmlZgffk63Ri6aV29WrGHWcs055r0GfAquKtx18i5OgO8tdApSqp5BdsjAVQY3x
miuPeBc3fLvbAx
PoIxGjndexNBD1aECaDlkYnVH5t1Dtdxh4Z8x5w60DAmu10XFM9dNmsxEkhikchpXD4ORhFevR6mcFHGo1gXMBx
ToUnicodeEx
UnhookWindowsHookEx
SetWindowsHookEx
CallNextHookEx
1zwdlyJZeetml1vdomtXdXqBCAi0btMu60gEnLcLKEMrTdnJhEiOAmA2tEBa1KL4OfK10DXx
AAxYBXypgFDKYx
lYy1lttEYtNmyS3O4mOmegW10dbRvyJK0A0A75h9hbZ8OBRrm50Domq4Uwt3BXZx
LateSetComplex
bes9t3NqVS4ymZ5gmcUBJO495k4VNn0nLmZ3c78YNFazHZCmhBT11SYelcPgLIix
f794NTYI0SOiELwIfwgbHakMmx9dOmwxDMs9dnCOURdCBsx
uTqrelx01yLGyx
mdjQ0Wl9e5P3OXWcQRhJx7xnlmp17bh0s8snl3KbLtIMVF7lOxuSiiBtPeqalZZfPzfWbU6y
5488ljo4zX1q8y
ZQPait49jBxb9y
uXdzQ04GPbcTAy
stguFy1uMkcqNy
m2XzIlzRxtjnx2aF6szx9vH14X33cgVy8WaH62RWn9I5OAt7Oy
tTtjOb4yBUgfYy
ToArray
set_Key
CreateSubKey
DeleteSubKey
OpenSubKey
MapVirtualKey
RegistryKey
hFAMmyiBfE0nfy
System.Security.Cryptography
Assembly
AddressFamily
UPGRQwqwK7bbjjuvND12Z8tm3zBMJHoy
ObjectQuery
get_TotalPhysicalMemory
get_Directory
CreateDirectory
get_SystemDirectory
get_Registry
op_Equality
WindowsIdentity
IsNullOrEmpty
4hqSChxkT7OLwy
RegistryProxy
OpUJ9U35unqHJz
paQaMdUDJgKeJz
oZOigPxbcOIPmD57ZaHBgXgCF4ApzJV7chUMgaOCfKRDf4MUNmnC4oo31c4xDFl7kaf1zzOz
wKfwkJ91THo7Qz
BXTSsSGzKycGevFb63SSXeQTrea2nQXz
fBYKHoV6tDcjdz
LxvCgRXs2kp8tNj8eLXLiuSu5SBcEAlz
yGuNOUDcuNSppz
WrapNonExceptionThrows
$9f5bd89d-e46d-49ee-8bd1-1d13548e4c42
1.0.0.0
MyTemplate
14.0.0.0
My.Computer
My.Application
My.User
My.WebServices
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
<generated method>
<generated method>
_CorExeMain
mscoree.dll
333333333333333333330
wwwwwww
wwwwwwwwwww
wwwwwwx
wwwwwww
wwwwwwwx
3333333333330
wwwwwx
333333333307
3333330x
------
3YYYYii@
`iiiiiiiiiiiiiiiiiii
MTiiiiiYYY3
3iiiiiiL
iiiiiii
ziiiiiii3
s3iiiizzzzz
Tzzzzzz
zzzzzziii3ss
zzzzzzzzzzzzzT
zzzzzzzzzzzzzzzz
zzzzzzzzzzzzz`
zzzzzzzzzzzzzzzzz
zzzzzzzzzzzzzzT
zzzzzzzzzzzzz
zzzzzzzzzzzzzz
zzzziiiiiiiiiL
iiiiiiiizzz
iiiiiiiiiiiip;6
iiiiiiiiii
*[3iiiiiiiiiiiic
;wiiiiiiii3[[3iiiiiiiiiiii-
QiiiiiiiiiiiL
iiiizj
iiiiiii3[X3iiiiYYYYYYYYYz!TTTTTT
YYYYYYYYY
YYYYiii3X&3YYYY
YYY3&&3
#MMD]L
((((((((((((((K
>(N+RI
((((((((((((((((((
((((((((((((((V.
(((((((((((((((((((
i(((((((((((((((gu
(((((((((((((((((((i
i(((((((((((((((=
1=((((((((((((((((((i
Y(((((((((((((((($
(((((((((((((((((Y
Z$gwjjjjjjjjjjjjjjjjjjjjwg$Z
+]J8gwjjj
jjjjjwg8
jjjjw\
5wwwwar<P@+
wwwww5
5wwwwws
wwwww5
E\++++++++%
U++++++++++\Ef\++++++++|4D
>OUs@@z
+++++++\f=\wwwwwwwKlrBkkB7
6Kwwwww\=t5wwwwwwwKWR%2&&2O
;rwwwww5t
5jjjjjw@s
jjjjj5
jjjjjs
jj;jjjjj
jjjjj@6r0
PP%d(jjjjj
NNNNNNNNN
AVNNNNNNNNN
w,,,,,,,,,
,,,,,,,,,,,,w
<w,,,,,,,,,
}',,,,,,,,,,,w<
j,,,,,,,,,,'n
)3nn~,,,,,,,,,,j
TTTTTTTTTTTTT
TTTTTTTTT
TTTTTTTTTTTTTT
^TTTTTTTTT
TTTTTTTTTTTTTTT{iTTTTTTTTT
TTTTTTTTTTTTTTTTTTTTTT
,,,,,,,,,,,,,,,,,,,,
]]]]]]]]]]]]]]]]]]]]]]]]]
T#/////
/&7$$H///
333O"B
@@OG0O@@@@
@@@@O0
.....@3?
@......
......
4@......
LLLLLLL
LLLLLL
LLLLLLLLL
LLLLLLLL
X6N]WWWWWWWWWWWWWWWWWWWWWW]
!!!!!!!!!!!8
!+%

:'''''''''''''':
mW73mW7
nX9foY:
pZ:!q[;
pZ:!q[<x
q[<xr]>
nX9@nX9
pZ;@vfN
r]>@vfO
r]>@u_@
r\=hr\=
r\=hwaB
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
rFBf2LusOvhjS4
wtWMe2neP8w66g
JVbQygcrQNbTcS
TnWDur2mg9gD28
lYyF6pwqp2cwBq
k6YEiUyZhy180R
EFSGhvAtbCEqHc
K6smBxsshPHvsGgTMr9TGA==
DdRLjqVMFCZwRTWuEs8cTg==
6S7Q5+QOTdY+yoLbamhIUw==
owZrDNlMgmhih+CnnW+x3w==
jcTpnbqDNabKnDXptcS8Hg==
VP5xg8vRl3BL7wdjiMkppg==
j3+xPfx+hCRq1CBmuUI9mA==
xgjShWlaS/whAWB+eKi79KkKeMtLPLyiZ5jOhIqBkJw=
0PRk3lveqs4b8d4F
\Log.tmp
WImqF5ojKxTI5M
mLkiM4HWl0slvp
schtasks.exe
/create /f /RL HIGHEST /sc minute /mo 1 /tn "
" /tr "
/create /f /sc minute /mo 1 /tn "
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
WScript.Shell
CreateShortcut
TargetPath
WorkingDirectory
powershell.exe
-ExecutionPolicy Bypass Add-MpPreference -ExclusionPath '
-ExecutionPolicy Bypass Add-MpPreference -ExclusionProcess '
http://ip-api.com/line/?fields=hosting
Select * from Win32_ComputerSystem
Manufacturer
microsoft corporation
VIRTUAL
vmware
VirtualBox
SbieDll.dll
FrkDEBwBOcCso6
6qVn39AzF5DtGG
z7njEaZQDrM9gy
snUE12hnei5ngt
DSKo8tvZvCPPM4
XsTWJnaBG3umCL
fdssZoYnLKWJEx
d6SmmqokzNtgDRfNsctMKQdYQmc8NxjyLEZcYv84kt8CesM
jJGXCelvTNcSqmALQ5tQjlhjFBKPRi5IQSxZmmrBKaT6UlW
EeMljqEyCGjUQ1owE4QxbcrfTMVJ3ZfPQVdUE1RP8CcWg6Q
hmzV0879XLV3ckBQIKfVYhWpjfPqcdxWwgmruRjZ70LCZKJ
cn89JkTQE5KnxA5dPRGyqCYw3fMd7gZEhUnBkBo7l4ElZkp
iNZchWANJ70n8hfqui6tYPMRlq9OaTJnJHIV7VESSJgkgON
CUUBDB1if15ZSaEoqqz5oZoH0pRnAkEWveLJtVCmZ2Y2KOs
Microsoft
Service Pack
dd/MM/yyy
\root\SecurityCenter2
Select * from AntivirusProduct
displayName
SELECT * FROM Win32_VideoController
Win32_Processor.deviceid="CPU0"
Core(TM)
WqZj29uPQ8Ro23VwnbKdjjqlMOJqvtshGQaiWNssOqN9nZG
Tz9W1INbVoJ8vXgVTcliB6kecQDpdBPWXxba9KPaXnncgN9
hcP8YKH584fRwjwQLYYDKxzfo9cyKJGbdiBtYzy44p23lqf
S8xDY3aPOyd0kb47N6pfEIEZvS1mePSfTsJYSVmyOZRfCkg
ghItFsNkFbGKk6SJ2A7JXOfqgx90Lp4PHnHliRpS1jqk77w
Oy4Gsuaj65vZl4lUHAAOqYIuzFmFNTyViy4mNER8FcOqAp8
D9Bd7VTQvpFz0hhixdx6XsPddFMw4ltujq1o72lOdOla75L
7HR8Q0LfSJ0WSl5BOrjwqNofGxUarThaTp3vdp6BTjEr3Tu
RPy4xIavD10W9RtOqrTYwDvgJnqHOSN4ko7ZlMFHhAo4PN8
8SAFznC2Qr6supEsfPBGLFkZQVBxrLHqevWLfAjebWd2eXB
4Rv1HGZURSMeZn5F62JVpnlsKXbcIvnYnbcaPMQN5ZoD0gT
8geFIC8tO8Tdk2FUncBwA1AobXdkGOLeqpJRUgTZltyjPId
qUCA9TVY0fhS2X2MpL4nLoMLiEh0Qj6YzjxKA6VSSzgwkT3
eVoKEBlNtz1Hr8rAouE2rmjudP1xoRz0cchkzZbUcS3BCtT
hqIMN5SS3YNglbxWDmkWlWrM0sZcjDxESArtLJrO0pdyWA5
4CWEOicmdOrEpENuY4ZqNZI2JnvKIlARrxsufRXyfSNQQSQ
uPr3oOiJFAAMaXknazlKEtjzhGA1hrUQNV7McvLNeIVneX9
OuVfWu1WeynJ1jiXHVGR3ZiiRiWV1FHY
cieldhYrozLdm0jSaaLW2ts0IZgkyxpJ
jyp1NItL0npGzlwQzQjU9S8UQrAbVKRY
IxitVkLs58hOl21RLeDySpsIRJTk7H1L
uninstall
update
Urlopen
Urlhide
PCShutdown
shutdown.exe /f /s /t 0
PCRestart
shutdown.exe /f /r /t 0
PCLogoff
shutdown.exe -L
RunShell
StartDDos
StopDDos
StartReport
StopReport
\drivers\etc\hosts
Shosts
HostsMSG
Modified successfully!
HostsErr
plugin
sendPlugin
savePlugin
RemovePlugins
Plugins Removed!
OfflineGet
Plugin
Invoke
RunRecovery
Recovery
RunOptions
injRun
UACFunc
ngrok+
Plugin Error!
ToLower
Open [
-ExecutionPolicy Bypass -File "
Rg6P6CxEe5KT8YwbT8lVaCWz1SBvCa2E
mIRxvwsmEUtCZcXmG9kwzgFuDZAD66Ry
X1nVlHTaqZ79AJgxGR4rns4gJNb6ftco
wOvHSaObeJ8GxgrEdfVLLnhut7EP4AZi
ThwoG6RUKkf2qp1WztMgdIkb8cvw9rSK
8LKJ0JCoFYYmgii7F7HcA721u3dHhKuH
iVSosfNkYWF1equRntsD9tP01Pm62sSp
XsKfXP3row902zSaUwHPDgjbgaD35AaT
05rLFpMQoYV8zSZPYPtI4tglZeTUlyR2
Os8zHXn3tIOrYXy6Pkbeey4Z4rD0ab9H
ZAXOPQhmnK4odnXIusAfcn5CYQBS7hYm
F911nYRCQOuffs8WuaLYaTMRNvKFVSGM
JWdaBylRpviPWf5C8wqtoKpio3nQSpoS
9wlccLX7G9xm4PbwEdvyXflinwjP2Rj4
GCTAbLrOmfnVWKCmA971r4Eq2RJ6QL5p
onqthdDlVfIPkdG3E049zlPJVVyllVR8
POST / HTTP/1.1
Host:
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
User-Agent:
Content-length: 5235
schtasks
/delete /f /tn "
@echo off
timeout 3 > NUL
" /f /q
Bws1dvfJWZ0SZVXKuIt1g2gBhNQmWQVC
DDGHMdqGKKLSQlUJMMDy7keVehlQe7uu
ToUpper
[SPACE]
Return
[ENTER]
Escape
LControlKey
[CTRL]
RControlKey
RShiftKey
[Shift]
LShiftKey
[Back]
Capital
[CAPSLOCK: OFF]
[CAPSLOCK: ON]
MainWindowTitle
ProcessName
WEHnDnSS24o822o1nacdB0DabIibVXAc
SvSddvdqKiquyNnTjXKOQDtP3OxvomGn
eIyC7bXNg0WR5HkkSZWKeqMLcbr9rsJt
GSE2B4jVU3kXCBuzT9ym9eplenFSpECP
EHJfq1W12hm2Cr9Myqq4w5SLIPmfLGdU
OUi20HkOIuF3WaFiFxSFyDNu3hxqkn1j
xK4smwOAWgnnlw0jTVtj5RZQUjFgeRVD
YoZxUtde9sT4rWdVfN4fDlfK1xAXpiCA
7SesywOKexZup1mQJMZfGsA7pKtcTxns
5fiTGEZGNqRGrxw9PVbsABoHO64Bp3jr
6Sj289qRSMOviDWmHGZGjrQmVcH0WS1n
YYJv2Pu3DvUxWTs6yRAOLbDRNMlJ8rPR
Loc86zxR67cQyMro3aV2yhHRFpCGDj0i
j5rKbsTuaN5LEZwqMJrfGx3bxrLY9Yjo
FnDhzimIrjlAKS4xRRaUrxwDWmy8iyl0
D91m0PZOd5ZWZzrX7UIBRCDGXu4YpUYn
tOwnS90oDZ4rPuMTKCIn2j9TuW9bVmJg
8Pqwg3EOstDyBlfsdHAMifYT843OBAGr
EVPHwApCgACcQDN10ux7bKm2IsCvrKnU
03snfSWzdoryTn4MpmqmUoH9if1Fqf09
7UL8LG6oGfoRa9Zn8zcPBcsSt2Xkk7dQ
P4IVcO7KqdAu9WBcHOzCGHca1XQ7IarB
y1pKZwdV57NJSGVVIXgdQfHYdxMxadOd8LICiFkYKKNFffCbZf6RfPjazGCUiwLr
F621o6CEgka42CVzQ5rK2Gs7wUYVq2RIRx1Wc7Hyw0NSoiYDfi3BwU4GDEOhCUPv
sz4EDfAeEhGcLVcB0LRTU5b5cKXLZEH2oArhSNVLmFvcxDngr9jOuR4JFerDcHj7
Software\
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
abcdefghijklmnopqrstuvwxyz
Err HWID
ToArray
CCFLOD1L22hIGtVu3LRFYGd7Rw7SIkdHnSmqS92Kt1gXPsZb5gObOWCV2Lnwi8kB
rHed9RMG5f5Yz3dsbRcIOnIxNFNLkCv6gw55LXsYDZiKA5gvLZ4FQAvYgWWOZn3k
ZqjtxNjzd1Mk2EppCuKjysVDYazyfbmuaONjYVrvyy2rf1hOslXGuDk5rLkf6MKs
RbCEjK0YMaqu8GtWTIdR9cinWdDumTTcyKc3LHhulQZPhuQ9q8fhsOpdXEwKznVj
wMuKgVPNzbMrNraE2qLt6KIgrTBLagHuY829Xxa6uOJGV8lATeLgqDoGpArW4VvM
d9i6we5KrGZhhiRZ07gu7OoUdVFZgavzsT58hHMT2REU32YCPoGXfoiSDWMbdCDx
ym7hS1XrdERqB97GyRAwp66DAlTqhmgGmDRwyevqKNoykMwRBRU3kC7g7Bp7PIJh
ssPmVIjycmJ38EJK4ixJmbVX6UBDLU3YuNmKkOPATgBvkPNbUVXo7blsevgHNEvL
dIj1TWqDx17vwWbFePSBQGXpSSGW9Ma7mmyF3jkXd9Ep9jeQaBvRD41X79k0vBqc
C8SBcB9ojIWT4IvaUtEosi5T9rSz2jAhG9reqX4LAgNJUqEj4J7xkXvVANHVVm6m
RuUDCY53V3qkb68AKaFp2yauEGta7POaiDeldGktrZtGSB2cc4KoedWbq7QRy2vk
ifrd5nbn4dxPbDil5kuOjCx4dU6MJrJx3nPrFehT7eANyJFXzoDYsSM5pxBU4FdN
r2wIqeiA3djDlXhv9brqmsLSTHu058JuYe7jDbPc4pstiu9NLnj8U0JfYUWWOTsh
TXtf4LyUaQtIiYr4rF77OhZw870ujHVhwrBZVWhWj08KpDRGDPpSfHKmau11y3Yx
U0JJZRn2LG1pDuPEAq4317SE2S4CnySxwyu59dITTXIeBrQRy32po9C9AN3TDx3Y
ps9ii6USLI8S7WLjtQO6JM0gEHQ8UKwsC5pUkt6HoKNNqR43T3bqOB4qRmy7lZTa
3FLtS0Li3iFzNVg4mswOAt7qVK1HRTixbWb4LrhhuaypT5x78YVepUX1Ghi39eSC
rO2MjNO1tysn9rvz5ZCPVkzC9QqWNgrRGFG2mOwL6D9f1t2kmRNQWwvfqnrB3B93
T2r9l7FkrRLBZE4448s7VR6XpNMJDeKnhtJO6yOu5J0BgjkZLHQWXbyUEXN5p1au
syYeXsSot8ITVnoXR81KiLfpD6ZHPvByQIzVTJ56kpx04cmVGUZZPXgQ11hElvu7
e9IijDpWdABZwK1770WAxCbGVS3tSKTCPdwTdHbbhaFn9amW5r
hc2EXQCzQM9DdUK3aUbcbMiHi45M0YUQg9A5IbPyccuUrnYPcb
r5FbOL3BgeYY0EaossvZspzshjEQ84ytfSoAynUUZfVEhBSIEc
o5oTImqWW2QP8BmrYUHdFeSitQ1Z3AH43H9u0YtFmrj0y7LM3I
zx7n5Hf2DDqqV2xaeK8XZkFBOxTS5DKb9m9Hw0Y6PXmj23UIZO
UgsVtFNHV8v0cp12VbJTuCqm5pYMKrEMQ3ISup9DItPk1uDRoe
sOrlG941dwMdMW7BWtbWVQ7Vr20OpFIOXDKOPLB5RrRaTrKMEh
XuRI7D5mQsoaviGpKZs9GgDTCsL1gdvcCdpFVRlb3ALPUT5fIo
abcdefghijklmnopqrstuvwxyz
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
1.0.0.0
InternalName
LegalCopyright
OriginalFilename
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.AsyncRAT.m!c
Elastic Windows.Generic.Threat
Cynet Clean
CMC Clean
CAT-QuickHeal Trojan.GenericFC.S29961068
Skyhigh BehavesLike.Win32.Generic.ch
ALYac Gen:Variant.Jalapeno.640
Cylance Unsafe
Zillya Clean
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Backdoor:MSIL/AsyncRAT.b651f234
K7GW Trojan ( 005aa5f01 )
K7AntiVirus Trojan ( 005aa5f01 )
huorong Backdoor/MSIL.DDos.b
Baidu Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Agent.DWN
APEX Malicious
Avast Win32:RATX-gen [Trj]
ClamAV Win.Packed.njRAT-10002074-1
Kaspersky HEUR:Backdoor.MSIL.XWorm.gen
BitDefender Gen:Variant.Jalapeno.640
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Jalapeno.640
Tencent Trojan.MSIL.Agent.16000605
Sophos Troj/Bbindi-W
F-Secure Trojan.TR/Spy.Gen
DrWeb BackDoor.BladabindiNET.30
VIPRE Gen:Variant.Jalapeno.640
TrendMicro Clean
McAfeeD Real Protect-LS!F3388B09788F
Trapmine suspicious.low.ml.score
CTX exe.trojan.msil
Emsisoft Gen:Variant.Jalapeno.640 (B)
Ikarus Trojan.MSIL.Agent
FireEye Generic.mg.f3388b09788fed42
Jiangmin Clean
Webroot Clean
Varist W32/MSIL_Agent.BUD.gen!Eldorado
Avira TR/Spy.Gen
Fortinet MSIL/Agent.ECL!tr
Antiy-AVL Clean
Kingsoft malware.kb.c.1000
Gridinsoft Ransom.Win32.Bladabindi.sa
Xcitium Clean
Arcabit Trojan.Jalapeno.640
SUPERAntiSpyware Trojan.Agent/Gen-Dropper
Microsoft Trojan:MSIL/AsyncRAT.R!MTB
Google Detected
AhnLab-V3 Trojan/Win.AntiVm.C5374869
Acronis Clean
McAfee Trojan-FVYT!F3388B09788F
TACHYON Clean
VBA32 Backdoor.MSIL.XWorm.gen
Malwarebytes Trojan.Downloader
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.AntiVM!1.CF63 (CLASSIC)
Yandex Clean
SentinelOne Static AI - Malicious PE
GData MSIL.Backdoor.XWormRAT.A
AVG Win32:RATX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Rat:Win/AsyncRAT.Stub
No IRMA results available.