Static | ZeroBOX

PE Compile Time

2021-03-23 07:42:53

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000fd1c4 0x000fd200 7.41551286427
.rsrc 0x00100000 0x00000600 0x00000600 2.39248638605
.reloc 0x00102000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00100058 0x000003ae LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
Z?_b`
Z >sZIa8
9'mSZ
PZ {zG
-4Za8o
N5Z 8y
jz=Z 5h
Z ajOva+
R<Ng%&
A(9[%&8N
Djqa8O
:@qvZ O
x5'%&8
5N%&8{
1Pq3a%
n!(Z 7
,g{Z aw
_bj+$
_bY*
[<l3Z %
_b+<
:Vmo%&8
!*W.Z
&0#iZ (
>*%&8<
k{Za8b
^a:a8/
,}VZ O
Z_bX
cf* xJ8
+* Nx-
OZ YQ"*a8~
A"Za8a
X_b8
Y_cX*
Xf Qy|
G&ef G
G&Ye* #
.%C%&+
M H[Da%
(O2%&8X
.4yZa+
1Y+O
1X+=-(
Q8( nb
1X+P/(
32;Za8
Z *3MTa+
p~ O+
,rZ +(
gZ 4rs
5(9*Z t
pZ fYw
?zZ +_#+a8U
Z o{u&a8
>nZ vj
RJZ dR
EdnZ .
FKSZ ~
|_KZ *2
7Z P P
%sya8M
Jkva8;
[ kRxya%
^I_(
=UyZ Q.
Z 9?]5a+
Z $}4/a8U
exJTZ
/~xZ '
X</7Z J
Z `ds}a8
>,#Z #q4
r8M4Z
`Z qp/ea8
<mZ d
$\d(Z
+jZ Nz
rZ Y|Rda8%
lQ<a8l
qvpZZ
$:4Z -
"YwZ
Z >H<va8
,rha8c
?]z)("
Z 'r-Ta8j
e-Z YM
'l@+Z b$
Z ]0jKa8X
:xZ 6h
\V"Z |
IZ pQcma8
KM"3Za8
x0HO+
:r.Z D
xZ rjk
Z j5Lka8Z
(}-FZ
e9IL8
fZ sXJ
"Z !-8Ma8
zvZ n#
1{tKZ
d$k)Z
}rkHZ
QMZ :T
\^o>Z WCu
*Z ^6Y
?]z)("
XOZ ~OF\a+
B(Z ;_kca8~
JZ"a8=
.Z BU*'a8H
HBFZ W?
oy%&8
(N=%&8R
45Z $!M
['QZ ?M
7Z =+jNa+
^A2[
bUFZ {
P9QkZ
nN{i%+
HEVPZ l
?hVZ S
+< Z]n
ChZ%&+
@vZ d\
i:Da80
}|Z r'
!x7Z +
wrpZ i
$U)#Z C
j%~Z G
.l?Z |
Z b<c:a8
CAZa8~
Z ]E4ma8&
SKZ \q
fXya8x
#}FZ dX
mZ q8BTa8
Z EXu8a8
>V@Z cH2
Z b^1&a8
]c>Z {h
Q{`8Z
4a|^(
Z W<W>a8
[S{Z ]C
uZ -s@
zDywZa+
%FEZ t
cdZ fj^
*RV-Z
ZTSo%+
gVQ[Z
S$cZa8'
]$iZ }#
g 0[*~a%
e!RZ $
Z Pe3fa8
+Z Uc6ca8
36Ka8j
DUWZ
:+JNZ @N
;X+U:(
@(xf%+
GZ q%2ka8O
AHGZ M
Z o-r&a8
BuZa8}
t{}wZ
7Z i;S
(Z "t%9a8
5w"(Z D
a]^Z !
FiZ R
y1nVZ G
Z YgcMa8
ttZa8y
\-a8%+
!1%&8<
[)%@+
#'%&8F
cZ ok~;a8
,Lux(
ONCa87
>p*sZ
9Z 9W~
pA5a8'
3nZ D5[Ia8
eU:a8@
f6ra8-
=2s_
WZ ."q
e%Z eL
\2`Z e
dZ ^bzra8
LzrZ
\5za8D
diZ z[
UeZ wN
peZa8R
gu7?Z o
%Z Y/<
9{UZ T$
<Z Kldca8
Z M]/a8
V!B9Z
Z q=qaa8
Z jlF=a87
Z 9/d1a+
V[p%&8g
eDVZ tJV8a85
;Xl6a%
++ WTL
Q58Z t<
Z K@Tga8R
N%3?Z
r Z g
Z Q@pNa8.
Z 1.^.a8
+SmZ G
,DYVZ y
GZ S/HHa8
,t$a8f
P-!a8,
Bd;a8v
_X8Z 4
=Sda87
:+s_
vAvXZ
3]6a8z
vD83Z 4N
-AZ ~TE<a8'
|suZ H
Z M~U!a8u
T:sb
(Z 5(Nza8Y
d}MH ]
Z <KS_a+
Z )%Oa8I
??$Z U
XPgr(
V}#a8C
Z kuC6a8
WhEgZa8a
xm^a8,
5&EZ q
|Z lbAka8Z
c.Z+Z
WwZ yD
54/a8>
*&Xz%&8
^9Z =D
HFZ +\L
qOQZa8
Y* Cax
Icsb
cZ /`j
6"Z YU
zZ hoO1a8
@Csb
.lqa8g
Z ),y>a+
D[3Z M
XO@Z b
~I*/a%
%3^E3
% o9HuZ
JZ E`7
^&,Z (7
D ~I*/a%
%8^E8
% GKXyZ w
r|;~("
% us65Z Z
8RU0(
{& y8
) ~I*/a%
Z ^3U@a+
H8k ~I*/a%
~I*/a%
@qZ k,
}Gxa8}
A;^E;
Z e~\\a8
5ud)(
A O2|_Z l
/r]Z .J
A zS+rZ
|Z a9s
A!^E!
$zfZa8
E%ga8v
4H]a8e
A)^E)
Z )qrra8
r&Z pxDMa8k
A |5?tZ k
Giu>%+
A#^E#
vZ p9?a8
A kDo[Z
;<5Z Z
Z g0#Ta8
s]=fa%
U s]=fa%
mo9F%+
* s]=fa%
.iAK s]=fa%
fVZ \~
qOZ 8x
Z kh1Oa8
:uZ I\
vL{a8+
]Z )1@a8
!|Ca82
}hUZ a
fZ !;p
JZ 90%
O>Z s2
f>cNZ |p3
xfxZ q<>
};VZ 5<
Qb8a8&
[Z cB
cT.%(
Z 6)w[a8
Cg%H(
+A ;Dy
[wZ bK
nuZa8Z
;qhS /
s1Na8
2wZ K;
&d@Za8*
Z %[|ea+
Lf]ga%
feba8
cZ Y~c~a+
/@ja8q
sXva8w
2R.'Z
hZZ ,j_
eosw%+
\be7Z
iCT*Z
ZZ Af9na8
yZ $E^
-&R!%+
OI]@%&
E~E,(
5@iXZ
Z 5v!Sa8
03t=Z
$jfZ
a/yZ +@&
"IZ s
Z -ylia8H
[HDa8/
):YtZ h
!Z g=s#a8G
o(kB
kwdZa8o
uPZ wI
\i*Z
IZ m7`Sa8
*ZeVZ
?2VZ Zn
/Z c\
'hv>(
XcZ YSF
NZsb
0/Z CI#za8
Z :r_/a8
X[sb
'uZ-Z {
V's_
*EgE(
Z /AA:a8
,{Z )B
is^Z B"f
~kJa80
Z PIFia8
[zZ -6
Z _N~Ba8
Z 6q|la8
)Z 38G
#5/a82
U2s_
Z %{f;a8
Z VR$]a8
*)sb
f(Z \Yd$a8
Q7Z "y
%Z P~o(a8
4nZ H:<oa8S
^->a8!
JGra8W
-Z $zu
6 sb
c%^Z <
},Z*(
^Qa8R
Nwsb
Z R62(a8
U%s_
;Z tn]
FQ,Z b{
,BlJZ d
Z ?<tYa8
51iZ
WlSV(
eZ.Z b
Z %2eFa8
5'Z %W}
^Z axt
?lT6Z ]f%
"Csb
}BdWZ S
lZ C20a8
3Z \7vYa8
Z `"<~a8y
Z VVvya8
JZ 'B4
%' 78
%, |Y
%. x\
%0 D\
%4 4N
%5 an
6`\Z ,
R_*[Z ;
*.Z _K
~uvPZ O
Z G]$+a8
=N1a8M
gZ +u
Z K8^Ha8)
<Z <~F
c$sb
lDQa89
/a+Z {
f3Va83
`Z @~_
U0s_
Z ]ZY|a8q|
m]a83|
RZ @zp1a8
87sb
u%a8ex
8Z w#v
)za8~w
^+Z eM
dnnZ `<x
6KIZ {
1 xXZ
'Uw(Z
[Z \~wna8
Z []bGa8Fq
&ta82o
w(a8.m
aixnZ
.$ZZ <
V#s_
=vZ `2
aZ s0t?a8
Z 9W]\a8
2pqIZ 8
E-a8{f
38YZ 5
N&sb
P&3LZ -
\D`O(
S=*Z $
Z v4^'a8Rb
=:W)Z
Z 5'spa86a
MvAZ pV(ea8
:Z [<&ra8i_
S8i Z
]6a83\
z`a8f[
d%[4Z
E8a8^Y
BlCa8JY
bZ 5H_Ha86Y
@ja8iX
Z >)?a82V
bla8uU
L6a8MU
O=a8%U
$ma8%T
E{3xZ
Vta8BP
92s_
;+a8fJ
N@sb
:ca8zH
Z Z{, a8RH
OZ 1B8
Xqsb
VkZ Y6
9ga8TF
Z 13$9a8
Gka8oE
:DPZ e
Z z@!Ka8hB
GUa83B
RZ Qv&ca8
U*s_
C5y9Z >-p
NAXk%&
XQZa8.
jw};Z u}
etZe%+
.<zZa86
Z <N,{a+
n/Za8k
m}Z 6)
?oZa8;
C;Z p6U
c)Za8k
Vr?a8U
t:%&8G
r; x4pBa%
_vZa8d
o-Z U#r
WV-r%+
_Z%&8<
8q&a8E
Z i7"$a8m
7!e'Za8
Z },rLa8
(j a8
BmZ Q
5Z ,Zj
Q${Z R
NxNa8B
pZ P0
a#leZ wa,na80
Z ^e|(a8
|zLZ P
Bl%((
E-{FZ
>w'Z z
'om7Z
9~faZ
kO9Z
Cx4a8F
mo9a8l
2=vZ h?'
Z &/_Ta8
[bZ Hp
'vZ \h
|$Z <fw
sgKa8o
z:3~Z gi
3iqa8,
tZ ChM9a8
~r`8Z
Z Za/ta8
rR'a81
Z &f}wa8
.Z PI0ha8[
KqVZ ,/
Z d&gia8
YKbd%+
m>va%
r+X|%+
>EZa8D
YOVZ m
}eZZa8
A5%&8o
)XyKZ
PANZa8)
!>0BZa82
Z K~-:a8
?Z D4^
?nuTZ
nZmLZa8
aaZ +
4b\a82
6,Ba8v
O;V;Za+
W8cU("
VZ DcE
Q9(k(
i{zU("
YZ'z("
`y&.8
s^Za8U
EZ Liqoa8-
S_gpZ
bgG](
[-#F(
%,&W("
}k0Z <'
(Z D(*
Z FN :a8i
vZ F6$a+
bgG](
HU@Za8
mZ *DZ
,Nka8n
'+Za8r
vZ +]1ma+
="FUZ
sa(%+
Z y&5Ya+
)wra8o
Je3h%&
uM}"8M
{1Xa8}
`RZ Pg
1h%&8a
QuZ /K
i}Pt%&
<5Z C0BIa8
5(kq%&
=HYa8_
3nPZa8
)[[a8B
qPcHZ
j9<t W
O;_R(
..Z fh8
""4|Z
?+sb
3hRa8R
:Oqa8{
$Ysb
Z OGcwa8
bZ N_L
7\h=(
dCsb
dYsb
"D#a81
wTXWZ
7Z NvJ
Z 3.`wa8}
o"o}Z
:9Z .E
"HI3Z
y9-eZ ]eoqa8t
0%MrZ
Z l#Gra8
Z VF=Va8
Ovja8g
#.hlZ
GLZ [@
5xZ BVKWa8(
BVra8]
cPZ <=
+>]Z M'F
Z 8=2a8-
]Z a_la8
XtZ 6|s
~kW?Z !A
XvCa8b
$EZ ;y
LoM=Z
[Z 3Z7
yZ R<D/a8E
Z <n)fa8
Z GdUfa8k
iZ p]5
d+sb
*Z 6<&
:&5a8?
wXPZ 9
yE>?Z
HZ *oR
[Iha8^
rn.Z [%
Z gFlVa8
RJ)Z
%nc2Z
Z VFVa8
8~Z /7
J]5UZ ,
UZ 3y!
!:{*Z
Uw2a8j
%CZ (V7;a8
X~TdZ @W
zZ B7g>a8
@!!a8
n~[oZ
4/fhZ
)Z Bzr
+m)IZ
N^8Z k
;)a8n~
|-a8&~
I3Z :c
,Z rOexa8^}
u$6WZ
@m)PZ
Uya5Z zU
.$a81{
3EyZ P
$ta85z
7tLZ
ASU$Z
dqsb
XZ &1.
V:Z _tJ}a8
ACsb
4Ya8|s
?Z #7{
\J\Z (
Z oNh2a8_p
u^a8Bm
|2FZ A=
ia8 l
zNa8Jj
=9TZa81
h#ta8D
azga8o
C{Za8z
WP-w i
ysi g`
[A&y(
+m{6%+
XZ %-D
(jU6(
=DT4Z
Y9#B(
_6Z =
<%_ZZ 6
r%0("
*&=Z k
jPZ w@
EpGZ L
m^kZ
. #m@7Z
lJXZ 1~<
. x,`cZ
.A^EA
. }iHXZ
Z 1Oy-a8
|`H(%&
ii{x 8
"z>Za+
rDta8^
a CbJXa%
Oe,:Z
CbJXa%
_ CbJXa%
T CbJXa%
kXZa8
Rs7Z '
j4Za8w
4@e+(
/<A7Z cqL)a8`
QTs Gz
|?Z 5n
oR&OZ o>ZJa8
H<|Z J
N-'W%&
JZ jjQ
Z `M&ka8k
jbpNZa8
U^xZ }
iv@YZ
,hg98I
xZ)a8<
? sb
>Z pV
Go>a8c
L@.CZ
Z 2^{Ia8
HK2DZ
~WM?Z
/C:XZ s
,#dZ X
_);DZ
OaZa8J
)Z aI0
%ALj i
6k75Z
$eqZ H
YWSQZ M=
02?eZ
XZ 95M
-XZ y{
~-S-Z
[Yj5(
Z kP-Za8U
Z M&?ba8#
2~.9%+
xq_(
x#Z 9`
\TJZ 9-k
cT.%(
cT.%(
-O qy
+c 8vz
W=Z BM
> S.`Xa%
edHZ ]R
X9Df S.`Xa%
+ S.`Xa%
Z Z _p
NX+T((
YOCa8l
Z G\'Na8U
hUZ R
$Z N%T
nRZ e0
vu=Z /\gwa83
$#tZ m)
S|DZ =
.M Z Z
EuBa8Q
6wZ \t
&@sb
JRZ :
n~{a8Q
.{sb
00sb
-F(a8y
Z >s/{a80
MZ D85
T@%mZ X
GoZ @=
B@jZ (
Z Fg'Fa8
%$Z ]41
YZa8|
rtZ 2';
!"7Z ONw
n\&KZ
yOFyZ
Z iRu6a8
PAs_
Z ;=r[a8
Z*sb
Pg;Z {
3<sa8^
dS,a8a
wuN^Z O
&b {Z IFhJa8
nc^RZ
Z ,ps/a8
<y7Z -
dNdZ t~
Z 9wU?a8q
Z 5/-ma8+
Rf8<Z o
}X,$Z
Z sx|ia8
Ecya8
F*3Z {
Z UUnUa+
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
Free domains grant acces to programs that are not
Internet Explorer And don't know how to use a proxy.
These would be programs like Shopfloor, ADP, etc.
Free domains allows all protocols, unfiltered to
The site you add
Free URL's allows Internet Explorer to access
Websites unfilters. For example if you need to
Allow a user to download a driver from Dell.
Only use this if you have specifically seen the
ISA has blocked this site message in their browser.
)Current Version = 101.17
Revision History:
Version: 101.17
(Updated by Dustin)
1. Fixed cancel button on user logon history filtering.
2. Added config.ini.
3. Updated ADP en/decrypt code to use config file's encryption variables.
4. Updated all remaining code to use config file's environment variables (domain, various LDAP paths, SMS server and db info, etc.) No longer domain specific with exception of ISA commands, these remain specific to CCM as no current need for functionality @ CPT or FSP.
5. Removed domain radio buttons and updated logic on RC and last PC results tools
6. Added ADP Clear button, with confirmation dialog. Same user permission required for update ADP button visibility
7. Cleaned up ADP Update logic to avoid writing "Null" as a string to any AD attributes, as a result fixed color coding.
8. Added enter key functionality to RC. When typing hostname or IP address, now simply hit enter... or continue clicking "Take Control" if you wish
9. Added mailbox size button! Displays mailbox size in KB (since limits are configured via KB - didn't want any confusion with forgetting to divide by 1024 vs. 1000) and status (under limit/over limit). Only visible if machine has powershell and if user is member of domain admins.
10.Replaced all colloquial/impolite messages with proper, meaningful language.
11.Significantly improved performance of Pop Up utility using dynamically dimensioned size list of threads to check computer status (offline/online). List of threads is defined as one quarter of the size of the table (up to a maximum of 250), threads parse table incrementallay rather than statically assigned start and stop points for each thread; accomplished via resource locking.
12.Added sorting functionality to Pop Up utility. First thread to reach end of table sets table as sortable after waiting 2x timeout value plus five seconds. This should allow sufficient time for all threads to complete, otherwise multi-threading logic would be disrupted if table was sorted prior to completion.
13.Added "Remove Offline Computers" button to make selections in table much easier! Not visible until after table is made sortable.
14.Automatically launches FoundUsers if SWIFT is not able to locate the specified user when enter is pressed or GetInfo is clicked.
15.Built logic to prevent crashing if attempt is made to close FoundUsers before search completes.
Version: 101.16.01 - not publicly relased
(Updated by Rick)
1. ADP Name added for legal name from ADP (where user's display name may be a nickname and not match in a comparison to AD).
2. Made Update ADP button invisible if not in appropriate group.
Version: 101.16
(Updated by Dustin; all prior updates were performed by Rick)
1. Added ADP ID to Account Info section; color coded for missing attributes.
2. Integrated Rick's mass CCM Pop Up Utility to ComputerStuff tab.
3. Added Update ADP ID button. Changed ADP label to editable textbox to accomodate. Checking for blank string and "Null" to reduce bogus employeeNumber AD attributes.
Version: 101.15
1. Added tab to last logon Computer that shows what software was deployed to a PC and the result
2. Added 'right click - copy' to some important fields on the last logged on computer dialog
3. Added 'Right clcik - Copy' to all fields on the all users logon history dialog
4. added 2 options all users logon history - Color coding and filter for todays events only
5. Added Auto update feature, nexttime there is a new version, you just have to click yes to update
6. Select and copy text in What drive
7. Added account enable/disable state
8. Added if user has IM or not
Version: 101.14
1. Added checkbox to filter out patches in the add/remove list
2. Color coded bad-problem causing programs red in add/remove list
3. Color coded office Green in add/remove list to make it easier to find quickly on large lists
version: 101.13
Changes in this version:
1. Added %CPU Used Column to Remote TaskMGR
2. You can now open Last Logged on computer without filling in the username box. (Incase you know the PC, but not the user)
3. Fixed the Floating Filter button on All users logon history
version: 101.12
Changes in this version:
1. Added more info fields in the About computer dialog
2. If present, Username now filled in when drive mapper opened
3. Added PC user history tab in more info
4. redid all users history to improve speed
5. Added R-CMD to computer tab for quick access to computer
with unknown user
version: 101.11
Changes in this version:
1 Fixed the discription field not clearing when new user is loaded
version: 101.10
Changes in this version:
1. Made the process list form resizable
2. Remote Command Promtp
3. Remote Task manager Imporvement
4. List ISA Exceptions
5. List where software is installed
version: 101.09
Changes in this version:
1. Added Lots Of Extra Computer Info on the last logged on COmputer screen
2. Added a random password generator to the reset password button
3. Added what drive is mapped lookup for users
4. Added Users location in AD to the user info pane
5. Added User Notes to the user feild returned in the main form
6. Fixed User logon history so that when a single user is displayed,
that users most current info is updated on the info bar at the top
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPADJ
?~|?"
?V}B?~
o~KZ3P
~a7>W{
09yRd<
OC1HV
o iY$>
/y:@WV
o@+E?F
F}ov~|
fnzp3
O)v EH
oNc{CF
BI0.(VF
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDATx^l
/PFFYS
0"ozJ/
C%&|Z*
UpD GE
7/^P3U8o
0|hr2X
p?iP.;
KW;J/S
H4L|y8
xFP]JR
3-X|hlJ
XdarBV
~-Ht_n
ai`~F*
P.&d*a
VE[2Wj
LOzZCM
UO4>n[z.5
n|_*-uN
uZ|[l(
+87%yzx
"<J<wX'
gKF<Sw:
k:j +V
9a|V'
Pr*CSf
/xGi1nt
?/-!`$
8t6kw
lGOh$v
B.?.M%z
}5X8 &[QyM9
m`0[!yB
NUpg]^
q Ic\M
9ZRphS_.
kyEoM6
effr~`.
f@@Ro[
\*izik
PY[nknm@A,
">dK]zH.O
_vOiG3
T}29#f
ig/D-u
c7\;@9
mT#*Vy
*JOY0]
U?wYCQ
F~EjOh
yj&N:s
LE}QJ|
Hrt1YX
JX5V91SBY
:8BF!G
ogsm;ASRq
ph_R;e
s7y;7I9
s16qT7
R;"F?G
Fmio-;
.HJ0c2
+=c?%03
12B4Ok
mh~5R@
R{b)mmQ
_uhI~
eU>R{B
oD!'w|@
F@lH%B
`(Gs=
5wT>m?
!.4xJ?N
??2!Ri
|/hNml
Mohkjk
;Xmf(f
!Rpq-A
P}dfn1
P7!wIgg
wek|Ak
uwi7@q.
>=0:g s
y0enb{
.",3cHj
8/yXM}
|o{c>j
L``tQj
(sYSJC
$LO)ZU
Gr7wB+F
;!@j}}
I*1P/5@
28^1x}/Z
{vG"(;
da?6%R_
\/WxvQ
1ap9 Z`DT
g</'e;p
6e\MFj
*f,,OV>
[8xC~ac .
0f9qm
~);xj/
pD(Wbc
P(A~bN
pb$T|VQ[E
w}Nq2w
0W5atu7
hU??#9]
!{`D<**
w3*"|K
$jlRXwU
cap2{9S
(1r88]
U3I4Q5
dje/`&
Dyenqu
8j<6%d
i!y<T?z
WDL(;~I(QS
X5YeA~NX
{)z`68m
/:4J8Jp
O^NDS2
h?KBvD
t4x'Yq
$|B-MNL
HGbCY7
rG@)j9
pQjc&i]=V
p]gY>f5Y[
Y^Yy-/
'c`L*\
zJs/<nn<
IDAT ~H
W- Fwl
rEP7T8
z;b6%)
w!jg)-
M%?Z8W'^)yf
);8c,=
Vyq:Mz
z[KRdD
"Q~\zf
$f7Q~)
3=MooU
o|zyfq
Wib^gi
(Yk_;l
{{an_O
~g-l/}
2VyES6
_eJ$&7
5v%^+Gqij>
Pax]Uv
x*h<>Z
!R.B)j](%6_
TAmnk
sb)08;
dZ>U.[X
YEv||E
+`Rlrj
M),\\ s
~2E&hQ
Ku"~lz
QXT" J
QRxyvCY
hNzk.Si
c9vVL&
DUma{+
%4[NYH^U
E4C\@:
'~rJF
.x|y.bI
x`<.-
1B&.>n
xzAZ/e
uk}/A-AS
{)7N<+
sQ+an5MR
hTen}2H
'Ug'07
4a3p?h
xqOE6Z7
u7]hQQ
v-xmw+GT
9B N|'w
CE]!>9BM
"@-L*NC^:J
o;X+Y=
`~18V
y~{_5G
k}fdQ2
C7|8 a
z~2=cQn
JekjXZ%
CE8hI@
E!Ld!M
;/#j>?H
nLn9J|
o^JjL[
&Ng&;!
j+_+-{
=9whj.0
vmkSn]
j]."1\
C'.}6(
S`ajGH
})g/y~@
4hxnR;
K7KJ.!
-u[h?<
|\~%m=m
.{$Z_f
mb>6P7>f
^}'S
/Z/mJV
B|jHY+
N|xn?
,R:">x]
:(Y+0[
(*C~Sh
q{nZ0F
{}=?&(
y'/R_?
_$TMB(
01O=#i_vy=
nHH.=v
j3E8EM
]wtn0+
t+'_u|
F%J2:
/VU%,o
-&zo w
J:|1<s~
Q@w>9v|
~E*y6B
9h"2vF
mnJy5u
.2T2vp
@.w8w)
<e~+?A
e0"Gf\y{
W-^-YH
}tIpo9
jcLJ%f
Pkqsaw
J"aLhe
%POO F
I{)^y}I
3JV2WO
M<Uj,?f
Dq`(Qq
SXRpVEy-o_
_6y ),IN
M5W=gRv
I)hnU)M
^r8r&U
`ovCJ3F
<AQ\9eP
h3wx5s7
:e]e~^
ZVyK{b
4w%c6<
Y.a*MIw
,uDX>+
;CI3jk
nl?>4_Hc>
U,ERk.
wH]w_
38!Nh|W
K4oOgI
hSk3hE
XE*AcI
KVB8R:T2
\2uGim
P`^.2;
j3aa%
`0`(39
QDc,^.
Gz9F&1
W^R"}/e
E^v|Pw%
Fx3+.F
I4'x=-
c[`td2|
4%,|f8
m.St-A
D~c~6d
R|FL9<
v[Nt/n8RW
8t(5"
6lDQ%~%
2h-(%MM
!X$ Na"
r:r8_L
ZUqk~`
9{~zo-
kqz7(H
IW\?*2
9bbu|\
HkLzE_3
/5BO_XX
_fA,4_n
\5@*^5
0qi!+5
lqmLn}
Rm1' R2E
7~=pydd
0]ygVk
j^2EB]
gZ"Dfm.i
Y7*]\U
|7"gYz%
w!nzUrhA66m
@LX2L8
H)t>>|
JSk&);Q
6*`=u[
A)jF @
?5j~D
V"VIFk
T-%nB=n
Djujq1
1 4}3(p>;
Hcb+5q
*39_Xc
_(R<gH
VKmU)'4
iV:WYW
>m>n"%
$:&]-#
iO_C1~~4
X5jxDE
x@J=.F
r*Y8M:
A]?"wn
>Ic/D.mG
a|e$:4
TS,S3D
p)|js"
GBa=h:P
9a5.M+Zm
Ne %5`@
d0UkY!(E
8F=zg1
bU! xs
j,I57;_nl
'._76k
.k?;?H
@+#xRxV1
f`2xjpZ\
!L i+)z@
0V:?b]u
SLi9Zt
yFIPQ7l
C:"&/N-j
V?ft%;
JQsDb.
h)OD G
+2/D|
2RJBg8
zWDuP
eE@ n-"
[D$d2low
iM}i2`
`8;&[>
WQ/`b*("
'UY9aO2
Xj2lN
Oi~|GN
BvKF?v
:#D<J
aNZNb@
#c*#p-
ibp8:&Q7
rz+i*E2
P"T1g =
ITiwD!
&0zX+[
N"y|"R
S)0}SA
9SUjt[
]>>`ew
lhjj]X
<RslS'
93sz?n
um.HuY
_|mZgn?
Ajs9K
PXqkW1
pp~O;*+
\DJm><;
>@PV&w'
l^S^If
IikfJo
eV!>6TOml
56h0k4/U?
1R<lhW4
}gX@~H
j?x{QB
a\BbRa4
oD7y_4gxf
vO564?x
@O8wa
:6VFXR
C^l={w
EB65q,
C29/`!
T?{[!C
H/yzl+
"'P;W|s
?GKSqY
|x<9$Y
YJ9J-F
f,>fe"
#,tFcq
5M,^@@
Fv(wZP
WB.7B.
#~\Wrg
7L9/Bh
.vOk7z
4:_Z>2k
3#-'O]n
%6cbI^S
%x2izC
-A1z@V
RAS|hjO
L*UYO
.LZNX8V(>D9U
hNvo!
qEP)-.
pvrQ|@1
mJo-rOJ
]UU^:O
>6mr7@D
n=|9qU
ZF>Fz-R
6l,FSLV+F
YfsT269
v r@
hnf@'
Qd^m@'
2yNeKG
6gk:LQ
iK.KS"
ZPo:'VG
L093y3
<8~^gQ
BGC,70
uPE*YVN
~QoVt
kDn9e
=.lgRi
m2\6m#
`Whx`iX
(EM%]-
Bp-Qw:S}
tVj-v+p
G'lZ72Y"
R#EDS-
U;Yjk"~I
QlDQvI
:LM^#J
VRYvgm[
K?p2g&F`R
}3~?Kw
=EEl"g
bve6MJb=MU_
S~&;ktU
% @X8-]
={>L?}
kf[(Ox
>6<$Ie
6o_LM`(c
m^2~dTj
J#T$S&
asmgqB
6_B^0-
l|s"7t
Wh!a0?
)[UbIb
.o3t*/
,~+&O"
gJ/*ry@
$yGs|T_aKm-
HdR@F}W
<aJv*
!3B<Lu
Q8*aPQ
bi00gR
1aC?m}
vU%wtQ
>{Am:PIU>
H9*6Ky
8p6@8T
FHT~?
\KMa8NI
%$prbz
<iHvPm]
cu*u0#
Z_*/M2
mVP@~e}
p:j[d
pGV,AD
TD0XQH
9cIZ0E
AX#f!C
E}4R:Y
}r>R>V
DK7Zkl<
.{Ef\.\>
)."o<?
N\G9X^.
]:E/b9
2TI7eU
l*H;Z+
g5,\zpL
|Sbn@j
#&m8"'|
vm3|!"
S'xS,%
%JR;VL
W9F9X
Be=Axz
Qh~Ik2
!AU3GZ
B=)TI9
TBQ1Wz
SscME%a
OxLUA
>h KvH+
y%:") B&
%:]FsNQZr
{ap8je+
U0n-%"
2[7Uhs
D!N'4S
t&mp[l
R,O^w]
g:Mu{.
[&Rkf%
N"sq0(E
k}|"Z` @
JQC#*I)j&
q%qj+)
6)KXM@
4g6!'I
n_;*a4
)[Fh5,%
L/t*DaS|
/CT1Iv0(U3
{"F$WD
,^Wy8y
eT-YB
TQgaK
sz;]^-
n><{?h6
X]s%E.
p5O}h:
/Px3g}
<q-${5f
[.p=*.
;B)U2F
td3`{'
V8@nei[
iq9wAN
2}^?WBv
(9YJ%x
SHL\;<
2NzN*\J
_}loap
\weF;r
QDm<dev
8?8[2d|
ZbCTAb
t'9)CUr
'P(~WH
cGVv+k
nZUN"b
Xq87Al2c
YZM^je~
xuMzbK
vY+3z8&
3;T?uKA
@FS\Dq{FQzR
#jgXuo
_5K%D/T
$Z<T|Bm
8>SVPB{
P<H;b,
.l;8yzI
;j&B{3
0t)rjxQ
8jM~~?
i5J`-7
4R[BsPk6
XV{*)K
'lnQG!
(Y48GT8
Pt\Q~F
2$kt>c
m7ZJiu
\4M<-3
HeUb<)
3aB;7|
4A&Q?j]
95K"o9v
:I>Yiv
7yE)fO
Xh\b.@
y`O*Q4
FpG@@L
x,.MH8
=>_e~\p
\=LJFG
yu0,OK%
>zu8+EN
&OTzSc
Rc_uS#
N`B"_<YR
MpvaO.
>Ko<z@
k;9F^
(,ys2U
6WbZ-g[\Y
ol-|$
*^WB5
3,Gnl}q
NdNq\{
OJ~b0T
QQz(r8
qA0mb#
TV|&R?
'XEdcx
^OW;K
^4)EMG
D_A[q?)vi
%^zbGI4j'
*8>0y!
ENkJ[f
a0?.km
dW#1^f8&
8r9A;gO(
X=K!c*~
PzyN$3^
YQq~t<
dl$^<D
[V\l_5z
Cfig~u
[0-NxY
30bR$[
tkDC9F
jz4cUB!
&zeV]H
z|XZ0D
TT1 F0
1Rg&,/
PB21*!
,^I]lKPe
A@*N\y
AD11IC
gpEJN]t
p$[Zf<p
]#*F~[
\l)t+9zr
&p&)h$
TOx*"hR
Js5~!>&t-
=W]WT#
+r"Ef}.
'/5E"{o
F4{.dw)]>
v3Rn1k4
$U()xC
<TKtwp
n'waf4
UXRPaf
^lUV~t
1m{ub~
CTS-\L
<~ a(D
Nu8%48
?aHiRp
]o+i*K
AJn,
_>g0sXL
\HE5kz
 7e6c
`;B<eM
[~fG8=
*=,Y@L
wW*s~{F
X[gLsO
8IDAT1aX
A.@{@?
-qeSf5
T4st@$6
tEU0)#
>^+K:|
[|~=z~
XHEK%+2&
B,b2)
5;TFv2
S{~TmAl
it5N ci
b% `^%
e>]DAQ
q3eG'e
?fw=5p
D6bAGLGg
<1G`w
965ev0
HeLr7
5lYH>a
^OY.E+
q}B~^W
8y=XZ-
#3+VG=O
B?Uie:Qf&
G!5n#5
;>He_o
GZ\tA?
j''4.O
@@I, 2
]-wxJ}zd
ad[;Df
L9-J<H
zcgVUv
RT,~<v
y(F0Hs
3beVU<h
.`fYw+
C{WQ#
_]X]J3{
y\vWW8
|ej/}6
xBEh{G
C<00E<
#QiI>R
{Fc%s<
7P"Uy
YcMe%s*?egh
JI}SLb
pMl.|v
q+t&jN][
Z%WCuUW
5GeYA[V
FM#J[?/X
5\%R^t
~x$X(A
;-GKXIV
;':X85
kWe<L
*"o@Y
zps/G_n
oC^-x*k
)',M@`
S,2hb
gD+/j
nb!Kjyv
's*.#/
5id!~V
1aY[v}i
/W_<q%
DE9U8Q
aFMOMx
d8}o^FQS
CgKKp<
C@#AT lE
6}^dpV
EYlDwV
P"< `m
<gl|G\pk
GR8P1NI'
h1a}iw
KQFXbJ
%Eet2S,
[bzXug
~|t6lsh
qmi7''D)BvF
)jJ[,5
-&}vSp)(d
p(C.@|
dVo%azCa
l=zNEedq
#&&3wud
i!&LbL
L};vuN
&.uz_{
gb)h&
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
w-[FnS,Y G.
Wny En$
80)Df^
:L$Uk"
._Go|`]
}ho*73
tJD6P&
t.(ZLX>
s!Z{%V
6eo;<Q+H
R_[ITB
A-gm|J
E\dV4v
V.XG^'
Cb 6%t$
k5x)eH
irF<$8
`TS_(>
RQ)|y^
v2.0.50727
#Strings
0>EN_n
C L X b u
$"$3$=$]$m$
%D%Y%o%
+!+P+m+
,%,<,F,
get_Label10
set_Label10
get_Button10
set_Button10
get_Label20
set_Label20
get_Button20
set_Button20
get_Label30
set_Label30
get_Label40
set_Label40
Timer0
get_Label11
set_Label11
get_Button11
set_Button11
get_Label31
set_Label31
List`1
thread1
get_TabPage1
set_TabPage1
get_Label1
set_Label1
get_Panel1
set_Panel1
get_TableLayoutPanel1
set_TableLayoutPanel1
get_TabControl1
set_TabControl1
get_CopyToolStripMenuItem1
set_CopyToolStripMenuItem1
get_Button1
set_Button1
GetADComputerInfo1
get_CheckBoxZero1
set_CheckBoxZero1
get_ContextMenuStrip1
set_ContextMenuStrip1
get_ProgressBar1
set_ProgressBar1
invoker1
getComputerNameByUser1
get_PictureBox1
set_PictureBox1
get_GroupBox1
set_GroupBox1
get_RichTextBox1
set_RichTextBox1
get_Label12
set_Label12
get_Button12
set_Button12
get_Label22
set_Label22
get_Label32
set_Label32
Microsoft.Win32
UInt32
ToInt32
ThreadLocka2
thread2
get_TabPage2
set_TabPage2
get_Label2
set_Label2
get_Panel2
set_Panel2
get_CopyToolStripMenuItem2
set_CopyToolStripMenuItem2
get_Button2
set_Button2
invoker2
get_PictureBox2
set_PictureBox2
get_Label13
set_Label13
get_Button13
set_Button13
get_Label23
set_Label23
get_Label33
set_Label33
get_TabPage3
set_TabPage3
get_Label3
set_Label3
get_Panel3
set_Panel3
get_CopyToolStripMenuItem3
set_CopyToolStripMenuItem3
get_Button3
set_Button3
get_RadioButton3
set_RadioButton3
get_Label14
set_Label14
get_Button14
set_Button14
get_Label24
set_Label24
get_Label34
set_Label34
get_TabPage4
set_TabPage4
get_Label4
set_Label4
get_CopyToolStripMenuItem4
set_CopyToolStripMenuItem4
get_Button4
set_Button4
get_Label15
set_Label15
get_Button15
set_Button15
get_Label25
set_Label25
get_Label35
set_Label35
get_TabPage5
set_TabPage5
get_Label5
set_Label5
get_Button5
set_Button5
get_Label16
set_Label16
get_Button16
set_Button16
get_Label26
set_Label26
get_Label36
set_Label36
get_Label46
set_Label46
get_TabPage6
set_TabPage6
get_Label6
set_Label6
get_Button6
set_Button6
get_Label17
set_Label17
get_Button17
set_Button17
get_Label27
set_Label27
get_Label37
set_Label37
get_TabPage7
set_TabPage7
get_Label7
set_Label7
get_Button7
set_Button7
get_Label18
set_Label18
get_Button18
set_Button18
get_Label28
set_Label28
get_Label38
set_Label38
get_UTF8
get_Label8
set_Label8
get_Button8
set_Button8
get_CheckBox09
set_CheckBox09
get_Label19
set_Label19
get_Button19
set_Button19
get_Label29
set_Label29
get_Label39
set_Label39
get_Label9
set_Label9
get_Button9
set_Button9
<Module>
UpdateADMainPGDB
m_cbComandBuilderEXDB
m_ConfigDBdataAdaptorEXDB
m_dtEXDB
LoadDirListMainDB
usrLogonDB
SMSServerDB
LoadServerListDB
get_DC
set_DC
InventoryThePC
get_btnListC
set_btnListC
get_LocationInAD
set_LocationInAD
get_LabelADPID
set_LabelADPID
get_PID
set_PID
get_ButtonRCMD
set_ButtonRCMD
tHEpROCmACHINE
get_ASCII
get_TextBoxFreeURL
set_TextBoxFreeURL
get_ButtonURL
set_ButtonURL
get_RAM
set_RAM
get_LabelRAM
set_LabelRAM
get_TextBoxRAM
set_TextBoxRAM
get_LabelHasIM
set_LabelHasIM
LDAPBaseDN
get_TextBoxPassGEN
set_TextBoxPassGEN
System.IO
get_ButtonUpdateADP
set_ButtonUpdateADP
get_ButtonClearADP
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
Baidu Clean
Cyren W32/MSIL_Troj.ALO.gen!Eldorado
TotalDefense Clean
APEX Malicious
Avast Clean
ClamAV Clean
Kaspersky UDS:Trojan.Multi.GenericML.xnet
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
Rising Clean
Ad-Aware Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Trojan.PackedNET.598
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.fc
FireEye Generic.mg.201f85fa5fa1c640
Emsisoft Clean
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
eGambit Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Fuerboos.E!cl
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee PWS-FCSU!201F85FA5FA1
TACHYON Clean
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.100%
Panda Clean
Zoner Clean
ESET-NOD32 a variant of MSIL/Kryptik.AADC
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.34628.@m0@aCyC!Xk
Paloalto Clean
CrowdStrike win/malicious_confidence_60% (D)
Qihoo-360 HEUR/QVM03.0.17E8.Malware.Gen
No IRMA results available.