0.9
低危

265a9407b3f6882279cf6f31313309b95f033163b545de4edf32912f7573598d

265a9407b3f6882279cf6f31313309b95f033163b545de4edf32912f7573598d.exe

分析耗时

195s

最近分析

362天前

文件大小

268.0KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN DROPPER ABINDI
鹰眼引擎
DACN 0.12
FACILE 1.00
IMCLNet 0.44
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba Backdoor:MSIL/Bladabindi.04320dab 20190527 0.3.0.5
Avast Win32:RATX-gen [Trj] 20240328 23.9.8494.0
Baidu MSIL.Trojan-Dropper.Binder.a 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (W) 20231026 1.0
Kingsoft malware.kb.c.1000 20230906 None
McAfee BackDoor-FBHS!D83062318E12 20240327 6.0.6.653
Tencent Trojan.Win32.Bladabindi.16000442 20240328 1.0.0.1
静态指标
行为判定
动态指标
网络通信
与未执行 DNS 查询的主机进行通信 (1 个事件)
host 114.114.114.114
文件已被 VirusTotal 上 56 个反病毒引擎识别为恶意 (50 out of 56 个事件)
ALYac Gen:Variant.MSIL.Bladabindi.6
APEX Malicious
AVG Win32:RATX-gen [Trj]
AhnLab-V3 Trojan/Win32.Agent.R132372
Alibaba Backdoor:MSIL/Bladabindi.04320dab
Arcabit Trojan.MSIL.Bladabindi.6
Avast Win32:RATX-gen [Trj]
Avira BDS/Bladabindi.alif
Baidu MSIL.Trojan-Dropper.Binder.a
BitDefender Gen:Variant.MSIL.Bladabindi.6
BitDefenderTheta Gen:NN.ZemsilF.36802.qm0@aeYn3Zm
Bkav W32.AIDetectMalware.CS
CAT-QuickHeal Trojan.Generic.TRFH369
ClamAV Win.Dropper.njRAT-7400469-0
CrowdStrike win/malicious_confidence_100% (W)
Cybereason malicious.18e12f
Cylance unsafe
DeepInstinct MALICIOUS
DrWeb Trojan.DownLoader9.26652
ESET-NOD32 a variant of MSIL/TrojanDropper.Binder.CA
Elastic malicious (high confidence)
Emsisoft Gen:Variant.MSIL.Bladabindi.6 (B)
F-Secure Backdoor.BDS/Bladabindi.alif
FireEye Generic.mg.d83062318e12f6b4
Fortinet MSIL/Dropper_Binder.BS!tr
GData Gen:Variant.MSIL.Bladabindi.6
Google Detected
Ikarus Trojan-Dropper.MSIL
Jiangmin Trojan/Generic.bcpht
K7AntiVirus Trojan ( 005496a61 )
K7GW Trojan ( 005496a61 )
Kaspersky Trojan.MSIL.Agent.ffjt
Kingsoft malware.kb.c.1000
Lionic Trojan.Win32.Generic.lExa
MAX malware (ai score=89)
Malwarebytes Generic.Trojan.MSIL.DDS
MaxSecure Trojan.Malware.300983.susgen
McAfee BackDoor-FBHS!D83062318E12
MicroWorld-eScan Gen:Variant.MSIL.Bladabindi.6
Microsoft Backdoor:MSIL/Bladabindi
NANO-Antivirus Trojan.Win32.Agent.dzsrep
Panda Trj/GdSda.A
Rising Backdoor.njRAT!1.9E49 (CLASSIC)
Sangfor Trojan.Win32.Save.a
SentinelOne Static AI - Malicious PE
Skyhigh BehavesLike.Win32.Generic.dm
Sophos Mal/SpyGate-A
Symantec ML.Attribute.HighConfidence
Tencent Trojan.Win32.Bladabindi.16000442
TrendMicro TROJ_BINDER.SMA
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2020-06-03 13:32:43

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0002fe64 0x00030000 5.777163498545004
.rsrc 0x00032000 0x00010b60 0x00011000 4.26407619053847
.reloc 0x00044000 0x0000000c 0x00001000 0.016408464515625623

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00032320 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_GROUP_ICON 0x00042b48 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_VERSION 0x000320e8 0x00000234 LANG_NEUTRAL SUBLANG_NEUTRAL None

Imports

Library mscoree.dll:
0x402000 _CorExeMain

L!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADPy3(
L!This program cannot be run in DOS mode.
`.rsrc
@.reloc
K#(I
l#ffffff?[(
l#ffffff?[(
  (I
j_(b`
_8c`*
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADPK
L!This program cannot be run in DOS mode.
`.rsrc
@.reloc
x6 OR
y6 OR
z6 OR
{6 OR
|6 OR
}6 OR
~6 OR
UYZ(b
UYZ(b
UYZ(b
UYZ(b
UYZ(b
v2.0.50727
#Strings
<Module>
mscorlib
Microsoft.VisualBasic
Capture
cam.DirectX.Capture
GraphState
HeFrame
CrossbarSource
DirectShowPropertyPage
DsBugWO
cam.DShowNET
CLSCTX
IMediaControl
IMediaEvent
IMediaEventEx
IBasicVideo2
IVideoWindow
IMediaPosition
IBasicAudio
IAMCollection
DsEvCode
PinDirection
PhysicalConnectorType
IFilterGraph
IPersist
IPersistStream
IMediaFilter
IBaseFilter
FilterInfo
IMediaSeeking
SeekingCapabilities
SeekingFlags
IReferenceClock
IEnumFilters
IEnumPins
AMMediaType
PinInfo
IMediaSample
cam.DShowNET.Device
DsDevice
ICreateDevEnum
IPropertyBag
ICaptureGraphBuilder2
IGraphBuilder
IFileSinkFilter
IFileSinkFilter2
IAMCopyCaptureFileProgress
IVideoFrameStep
IAMStreamConfig
AMTunerSubChannel
AMTunerSignalStrength
AMTunerModeType
AMTunerEventType
IAMTuner
IAMTunerNotification
AnalogVideoStandard
TunerInputType
IAMTVTuner
IAMCrossbar
IAMAudioInputMixer
VfwCompressDialogs
IAMVfwCompressDialogs
VideoStreamConfigCaps
AudioStreamConfigCaps
DsUtils
DsPOINT
DsRECT
BitmapInfoHeader
ISpecifyPropertyPages
DsCAUUID
DsOptInt64
DsOptIntPtr
FilterCategory
MediaType
MediaSubType
FormatType
PinCategory
FindDirection
VMRMode9
VMR9AspectRatioMode
IVMRFilterConfig9
IVMRWindowlessControl9
VMRMode
IVMRWindowlessControl
IVMRFilterConfig
Filter
FilterCollection
Filters
PropertyPage
PropertyPageCollection
ISampleGrabber
ISampleGrabberCB
VideoInfoHeader
VideoInfoHeader2
WaveFormatEx
Source
SourceCollection
VfwCompressorPropertyPage
VideoCapabilities
System
Object
WithEventsValue
System.Drawing
System.Threading
Thread
Bitmap
get_Capturing
get_Cued
get_Stopped
get_Filename
set_Filename
System.Windows.Forms
Control
get_PreviewWindow
set_PreviewWindow
get_VideoCaps
get_VideoDevice
get_AudioDevice
get_VideoCompressor
set_VideoCompressor
get_AudioCompressor
set_AudioCompressor
get_VideoSource
set_VideoSource
get_AudioSource
set_AudioSource
get_VideoSources
get_AudioSources
get_PropertyPages
get_Tuner
get_FrameRate
set_FrameRate
get_FrameSize
set_FrameSize
get_AudioChannels
set_AudioChannels
get_AudioSamplingRate
set_AudioSamplingRate
get_AudioSampleSize
set_AudioSampleSize
zgraphState
isPreviewRendered
isCaptureRendered
wantPreviewRendered
wantCaptureRendered
rotCookie
m_videoDevice
m_audioDevice
m_videoCompressor
m_audioCompressor
m_filename
m_previewWindow
m_videoCaps
m_videoSources
m_audioSources
m_propertyPages
m_tuner
graphBuilder
mediaControl
videoWindow
captureGraphBuilder
videoStreamConfig
audioStreamConfig
videoDeviceFilter
videoCompressorFilter
audioDeviceFilter
audioCompressorFilter
muxFilter
fileWriterFilter
baseGrabFlt
sampGrabber
videoInfoHeader
add_FrameEvent2
FrameEvent2Event
remove_FrameEvent2
savedArray
bufferedSize
videoDevice
audioDevice
Finalize
Dispose
createGraph
renderGraph
startPreviewIfNeeded
derenderGraph
removeDownstream
filter
removeFirstFilter
destroyGraph
EventArgs
onPreviewWindowResize
sender
getTempFilename
getStreamConfigSetting
streamConfig
fieldName
setStreamConfigSetting
newValue
assertStopped
ISampleGrabberCB_SampleCB
SampleTime
pSample
ISampleGrabberCB_BufferCB
pBuffer
BufferLen
OnCaptureDone
GrapImg
set_SetBitmap
Capturing
Stopped
Filename
PreviewWindow
VideoCaps
VideoDevice
AudioDevice
VideoCompressor
AudioCompressor
VideoSource
AudioSource
VideoSources
AudioSources
PropertyPages
FrameRate
FrameSize
AudioChannels
AudioSamplingRate
AudioSampleSize
FrameEvent2
SetBitmap
value__
Created
Rendered
MulticastDelegate
TargetObject
TargetMethod
IAsyncResult
AsyncCallback
BeginInvoke
DelegateCallback
DelegateAsyncState
EndInvoke
DelegateAsyncResult
Invoke
Crossbar
OutputPin
InputPin
ConnectorType
get_Enabled
set_Enabled
crossbar
outputPin
inputPin
connectorType
getName
Enabled
specifyPropertyPages
name__1
OleCreatePropertyFrame
hwndOwner
lpszCaption
cObjects
cPages
pPageClsID
dwReserved
pvReserved
CreateDsInstance
CoCreateInstance
pUnkOuter
dwClsContext
Inproc
Server
GetState
msTimeout
RenderFile
strFilename
AddSourceFilter
get_FilterCollection
get_RegFilterCollection
StopWhenReady
GetEventHandle
hEvent
GetEvent
lEventCode
lParam1
lParam2
WaitForCompletion
pEvCode
CancelDefaultHandling
lEvCode
RestoreDefaultHandling
FreeEventParams
SetNotifyWindow
lInstanceData
SetNotifyFlags
lNoNotifyFlags
GetNotifyFlags
lplNoNotifyFlags
AvgTimePerFrame
pAvgTimePerFrame
BitRate
pBitRate
BitErrorRate
VideoWidth
pVideoWidth
VideoHeight
pVideoHeight
put_SourceLeft
SourceLeft
get_SourceLeft
pSourceLeft
put_SourceWidth
SourceWidth
get_SourceWidth
pSourceWidth
put_SourceTop
SourceTop
get_SourceTop
pSourceTop
put_SourceHeight
SourceHeight
get_SourceHeight
pSourceHeight
put_DestinationLeft
DestinationLeft
get_DestinationLeft
pDestinationLeft
put_DestinationWidth
DestinationWidth
get_DestinationWidth
pDestinationWidth
put_DestinationTop
DestinationTop
get_DestinationTop
pDestinationTop
put_DestinationHeight
DestinationHeight
get_DestinationHeight
pDestinationHeight
SetSourcePosition
height
GetSourcePosition
SetDefaultSourcePosition
SetDestinationPosition
GetDestinationPosition
SetDefaultDestinationPosition
GetVideoSize
pWidth
pHeight
GetVideoPaletteEntries
StartIndex
Entries
pRetrieved
pPalette
GetCurrentImage
pBufferSize
pDIBImage
IsUsingDefaultSource
IsUsingDefaultDestination
GetPreferredAspectRatio
plAspectX
plAspectY
put_Caption
caption
get_Caption
put_WindowStyle
windowStyle
get_WindowStyle
put_WindowStyleEx
windowStyleEx
get_WindowStyleEx
put_AutoShow
autoShow
get_AutoShow
put_WindowState
windowState
get_WindowState
put_BackgroundPalette
backgroundPalette
get_BackgroundPalette
put_Visible
visible
get_Visible
put_Left
get_Left
put_Width
get_Width
put_Top
get_Top
put_Height
get_Height
put_Owner
get_Owner
put_MessageDrain
get_MessageDrain
get_BorderColor
put_BorderColor
get_FullScreenMode
fullScreenMode
put_FullScreenMode
SetWindowForeground
NotifyOwnerMessage
wParam
lParam
SetWindowPosition
GetWindowPosition
GetMinIdealImageSize
GetMaxIdealImageSize
GetRestorePosition
HideCursor
hideCursor__1
IsCursorHidden
hideCursor
get_Duration
pLength
put_CurrentPosition
llTime
get_CurrentPosition
pllTime
get_StopTime
put_StopTime
get_PrerollTime
put_PrerollTime
put_Rate
get_Rate
pdRate
CanSeekForward
pCanSeekForward
CanSeekBackward
pCanSeekBackward
put_Volume
lVolume
get_Volume
plVolume
put_Balance
lBalance
get_Balance
plBalance
get_Count
plCount
get_NewEnum
Complete
UserAbort
ErrorAbort
Repaint
StErrStopped
StErrStPlaying
ErrorStPlaying
PaletteChanged
VideoSizeChanged
QualityChange
ShuttingDown
ClockChanged
Paused
OpeningFile
BufferingData
FullScreenLost
Activate
NeedRestart
WindowDestroyed
DisplayChanged
Starvation
OleEvent
NotifyWindow
DvdDomChange
DvdTitleChange
DvdChaptStart
DvdAudioStChange
DvdSubPicStChange
DvdAngleChange
DvdButtonChange
DvdValidUopsChange
DvdStillOn
DvdStillOff
DvdCurrentTime
DvdError
DvdWarning
DvdChaptAutoStop
DvdNoFpPgc
DvdPlaybRateChange
DvdParentalLChange
DvdPlaybStopped
DvdAnglesAvail
DvdPeriodAStop
DvdButtonAActivated
DvdCmdStart
DvdCmdEnd
DvdDiscEjected
DvdDiscInserted
DvdCurrentHmsfTime
DvdKaraokeMode
Output
Video_Tuner
Video_Composite
Video_SVideo
Video_RGB
Video_YRYBY
Video_SerialDigital
Video_ParallelDigital
Video_SCSI
Video_AUX
Video_1394
Video_USB
Video_VideoDecoder
Video_VideoEncoder
Video_SCART
Audio_Tuner
Audio_Line
Audio_Mic
Audio_AESDigital
Audio_SPDIFDigital
Audio_SCSI
Audio_AUX
Audio_1394
Audio_USB
Audio_AudioDecoder
OATRUE
OAFALSE
System.Text
StringBuilder
AMGetErrorText
Connect
pReceivePin
ReceiveConnection
Disconnect
ConnectedTo
ConnectionMediaType
QueryPinInfo
QueryDirection
pPinDir
QueryId
QueryAccept
EnumMediaTypes
ppEnum
QueryInternalConnections
EndOfStream
BeginFlush
EndFlush
NewSegment
tStart
AddFilter
pFilter
RemoveFilter
EnumFilters
FindFilterByName
ppFilter
ConnectDirect
ppinOut
ppinIn
Reconnect
SetDefaultSyncSource
GetClassID
pClassID
dwMilliSecsTimeout
filtState
SetSyncSource
pClock
GetSyncSource
EnumPins
FindPin
QueryFilterInfo
JoinFilterGraph
pGraph
QueryVendorInfo
pVendorInfo
achName
GetCapabilities
pCapabilities
CheckCapabilities
IsFormatSupported
pFormat
QueryPreferredFormat
GetTimeFormat
IsUsingTimeFormat
SetTimeFormat
GetDuration
pDuration
GetStopPosition
GetCurrentPosition
pCurrent
ConvertTimeFormat
pTarget
pTargetFormat
pSourceFormat
SetPositions
dwCurrentFlags
dwStopFlags
GetPositions
GetAvailable
pEarliest
pLatest
SetRate
GetRate
GetPreroll
pllPreroll
CanSeekAbsolute
CanSeekForwards
CanSeekBackwards
CanGetCurrentPos
CanGetStopPos
CanGetDuration
CanPlayBackwards
CanDoSegments
NoPositioning
AbsolutePositioning
RelativePositioning
IncrementalPositioning
PositioningBitsMask
SeekToKeyFrame
ReturnTime
Segment
NoFlush
GetTime
AdviseTime
baseTime
streamTime
pdwAdviseCookie
AdvisePeriodic
startTime
periodTime
hSemaphore
Unadvise
dwAdviseCookie
cFilters
pcFetched
ppPins
majorType
subType
fixedSizeSamples
temporalCompression
sampleSize
formatType
unkPtr
formatSize
formatPtr
ValueType
GetPointer
ppBuffer
GetSize
pTimeStart
pTimeEnd
SetTime
IsSyncPoint
SetSyncPoint
bIsSyncPoint
IsPreroll
SetPreroll
bIsPreroll
GetActualDataLength
SetActualDataLength
GetMediaType
ppMediaType
SetMediaType
pMediaType
IsDiscontinuity
SetDiscontinuity
bDiscontinuity
GetMediaTime
SetMediaTime
System.Collections
ArrayList
GetDevicesOfCat
System.Runtime.InteropServices
UCOMIMoniker
GetFriendlyName
IDisposable
UCOMIEnumMoniker
CreateClassEnumerator
ppEnumMoniker
dwFlags
pszPropName
pErrorLog
SetFiltergraph
GetFiltergraph
SetOutputFileName
lpstrFile
ppSink
FindInterface
pCategory
RenderStream
pSource
pfCompressor
pfRenderer
ControlStream
pstart
wStartCookie
wStopCookie
AllocCapFile
dwlSize
CopyCaptureFile
lpwstrOld
lpwstrNew
fAllowEscAbort
pindir
fUnconnected
Render
lpcwstrFile
lpcwstrPlayList
lpcwstrFileName
lpcwstrFilterName
SetLogFile
ShouldOperationContinue
SetFileName
pszFileName
GetCurFile
SetMode
GetMode
Progress
iProgress
dwFrames
pStepObject
CanStep
bMultiple
CancelStep
SetFormat
GetFormat
GetNumberOfCapabilities
piCount
piSize
GetStreamCaps
iIndex
NoTune
Default
NoSignal
SignalPresent
FMRadio
AMRadio
Changed
put_Channel
lChannel
lVideoSubChannel
lAudioSubChannel
get_Channel
plChannel
plVideoSubChannel
plAudioSubChannel
ChannelMinMax
lChannelMin
lChannelMax
put_CountryCode
lCountryCode
get_CountryCode
plCountryCode
put_TuningSpace
lTuningSpace
get_TuningSpace
plTuningSpace
hCurrentUser
Logout
plSignalStrength
put_Mode
get_Mode
plMode
GetAvailableModes
plModes
RegisterNotificationCallBack
pNotify
lEvents
UnRegisterNotificationCallBack
OnEvent
NTSC_M
NTSC_M_J
NTSC_433
PAL_60
SECAM_B
SECAM_D
SECAM_G
SECAM_H
SECAM_K
SECAM_K1
SECAM_L
SECAM_L1
PAL_N_COMBO
Antenna
get_AvailableTVFormats
lAnalogVideoStandard
get_TVFormat
AutoTune
plFoundSignal
StoreAutoTune
get_NumInputConnections
plNumInputConnections
put_InputType
lIndex
inputType
get_InputType
put_ConnectInput
get_ConnectInput
get_VideoFrequency
get_AudioFrequency
get_PinCounts
OutputPinCount
InputPinCount
CanRoute
OutputPinIndex
InputPinIndex
get_IsRoutedTo
get_CrossbarPinInfo
IsInputPin
PinIndex
PinIndexRelated
PhysicalType
put_Enable
fEnable
get_Enable
pfEnable
put_Mono
get_Mono
pfMono
put_MixLevel
get_MixLevel
pLevel
put_Pan
get_Pan
put_Loudness
fLoudness
get_Loudness
pfLoudness
put_Treble
Treble
get_Treble
pTreble
get_TrebleRange
pRange
put_Bass
get_Bass
get_BassRange
Config
QueryConfig
QueryAbout
ShowDialog
iDialog
pState
pcbState
SetState
cbState
SendDriverMessage
VideoStandard
InputSize
MinCroppingSize
MaxCroppingSize
CropGranularityX
CropGranularityY
CropAlignX
CropAlignY
MinOutputSize
MaxOutputSize
OutputGranularityX
OutputGranularityY
StretchTapsX
StretchTapsY
ShrinkTapsX
ShrinkTapsY
MinFrameInterval
MaxFrameInterval
MinBitsPerSecond
MaxBitsPerSecond
MinimumChannels
MaximumChannels
ChannelsGranularity
MinimumBitsPerSample
MaximumBitsPerSample
BitsPerSampleGranularity
MinimumSampleFrequency
MaximumSampleFrequency
SampleFrequencyGranularity
IsCorrectDirectXVersion
ShowCapPinDialog
ShowTunerPinDialog
GetPin
dirrequired
FreeAMMediaType
mediaType
Bottom
Height
Planes
BitCount
Compression
ImageSize
XPelsPerMeter
YPelsPerMeter
ClrUsed
ClrImportant
AddGraphToRot
cookie
RemoveGraphFromRot
ROTFLAGS_REGISTRATIONKEEPSALIVE
UCOMIRunningObjectTable
GetRunningObjectTable
CreateItemMoniker
GetCurrentProcessId
GetPages
pPages
cElems
pElems
Pointer
.cctor
AudioInputDevice
VideoInputDevice
VideoCompressorCategory
AudioCompressorCategory
LegacyAmFilterCategory
SystemDeviceEnum
FilterGraph
CaptureGraphBuilder2
SampleGrabber
DvdGraphBuilder
StreamBufferSink
StreamBufferSource
VideoMixingRenderer
VideoMixingRenderer9
VideoRendererDefault
AviSplitter
SmartTee
Interleaved
Stream
RGB565
RGB555
VideoInfo
VideoInfo2
WaveEx
MpegVideo
MpegStreams
DvInfo
Preview
UpstreamOnly
DownstreamOnly
Windowed
Windowless
Renderless
LetterBox
SetImageCompositor
lpVMRImgCompositor
SetNumberOfStreams
dwMaxStreams
GetNumberOfStreams
pdwMaxStreams
SetRenderingPrefs
dwRenderFlags
GetRenderingPrefs
pdwRenderFlags
SetRenderingMode
GetRenderingMode
GetNativeVideoSize
lpWidth
lpHeight
lpARWidth
lpARHeight
GetMinIdealVideoSize
GetMaxIdealVideoSize
SetVideoPosition
lpSRCRect
lpDSTRect
GetVideoPosition
GetAspectRatioMode
lpAspectRatioMode
SetAspectRatioMode
AspectRatioMode
SetVideoClippingWindow
RepaintVideo
DisplayModeChanged
SetBorderColor
GetBorderColor
bottom
SetColorKey
GetColorKey
IComparable
MonikerString
monikerString__1
moniker
getMonikerString
monikerString
getAnyMoniker
CompareTo
CollectionBase
category
getFilters
get_Item
VideoInputDevices
AudioInputDevices
VideoCompressors
AudioCompressors
SupportsPersisting
get_State
set_State
videoSources
audioSources
addFromGraph
addIfSupported
SetOneShot
OneShot
GetConnectedMediaType
SetBufferSamples
BufferThem
GetCurrentBuffer
GetCurrentSample
ppSample
SetCallback
pCallback
WhichMethodToCallback
SampleCB
BufferCB
SrcRect
TargetRect
BmiHeader
InterlaceFlags
CopyProtectFlags
PictAspectRatioX
PictAspectRatioY
ControlFlags
Reserved2
wFormatTag
nChannels
nSamplesPerSec
nAvgBytesPerSec
nBlockAlign
wBitsPerSample
cbSize
m_name
get_Name
ToString
deviceFilter
isVideoDevice
get_CurrentSource
set_CurrentSource
findCrossbars
findCrossbarSources
CurrentSource
tvTuner
tuner__1
set_Channel
set_InputType
get_SignalPresent
Channel
InputType
vfwCompressDialogs
compressDialogs
MinFrameSize
MaxFrameSize
FrameSizeGranularityX
FrameSizeGranularityY
MinFrameRate
MaxFrameRate
Exception
Microsoft.VisualBasic.CompilerServices
ProjectData
SetProjectError
ClearProjectError
System.Collections.Generic
List`1
ToArray
System.IO
Exists
Delete
get_CurrentThread
System.Runtime.CompilerServices
AccessedThroughPropertyAttribute
Marshal
FreeCoTaskMem
Conversions
ToLong
Truncate
ToShort
ToInteger
Delegate
Combine
Remove
Collect
GetTypeFromCLSID
Activator
CreateInstance
RuntimeTypeHandle
GetTypeFromHandle
get_GUID
RuntimeHelpers
GetObjectValue
BindToMoniker
PtrToStructure
IntPtr
get_Handle
EventHandler
add_Resize
remove_Resize
ReleaseComObject
Rectangle
get_ClientRectangle
get_Right
get_Bottom
Random
GetTempPath
String
Concat
System.Reflection
FieldInfo
op_Equality
GetType
GetField
GetValue
SetValue
StructureToPtr
System.Diagnostics
GCHandle
GCHandleType
AddrOfPinnedObject
op_Explicit
System.Drawing.Imaging
PixelFormat
WriteLine
op_Inequality
DllImportAttribute
olepro32.dll
MarshalAsAttribute
UnmanagedType
InAttribute
QueryInterface
System.Runtime.Remoting.Services
EnterpriseServicesHelper
WrapIUnknownWithComObject
Release
ole32.dll
FlagsAttribute
InterfaceTypeAttribute
ComInterfaceType
GuidAttribute
ComImportAttribute
ComVisibleAttribute
PreserveSigAttribute
OutAttribute
quartz.dll
StructLayoutAttribute
LayoutKind
IEnumerator
GetEnumerator
get_Current
MoveNext
UCOMIBindCtx
BindToStorage
Environment
get_SystemDirectory
get_Message
GetIUnknownForObject
Format
Register
Revoke
kernel32.dll
GetDisplayName
ParseDisplayName
get_InnerList
DefaultMemberAttribute
set_Capacity
Assert
IndexOf
ICollection
AddRange
RemoveAt
SizeOf
AllocCoTaskMem
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
cam.dll
$56a868b1-0ad4-11ce-b03a-0020af0ba770
$56a868b6-0ad4-11ce-b03a-0020af0ba770
$56a868c0-0ad4-11ce-b03a-0020af0ba770
$329bb360-f6ea-11d1-9038-00a0c9697298
$56a868b4-0ad4-11ce-b03a-0020af0ba770
$56a868b2-0ad4-11ce-b03a-0020af0ba770
$56a868b3-0ad4-11ce-b03a-0020af0ba770
$56a868b9-0ad4-11ce-b03a-0020af0ba770
$56a86891-0ad4-11ce-b03a-0020af0ba770
$56a8689f-0ad4-11ce-b03a-0020af0ba770
$0000010c-0000-0000-C000-000000000046
$56a86899-0ad4-11ce-b03a-0020af0ba770
$56a86895-0ad4-11ce-b03a-0020af0ba770
$36b73880-c2c8-11cf-8b46-00805f6cef60
$56a86897-0ad4-11ce-b03a-0020af0ba770
$56a86893-0ad4-11ce-b03a-0020af0ba770
$56a86892-0ad4-11ce-b03a-0020af0ba770
$56a8689a-0ad4-11ce-b03a-0020af0ba770
$29840822-5B84-11D0-BD3B-00A0C911CE86
$55272A00-42CB-11CE-8135-00AA004BB851
$93E5A4E0-2D50-11d2-ABFA-00A0C9C6E38D
$56a868a9-0ad4-11ce-b03a-0020af0ba770
$a2104830-7c70-11cf-8bce-00aa00a3f1a6
$00855B90-CE1B-11d0-BD4F-00A0C911CE86
$670d1d20-a068-11d0-b3f0-00aa003761c5
$e46a9787-2b71-444d-a4b5-1fab7b708d6a
$C6E13340-30AC-11d0-A18C-00A0C9118956
$211A8761-03AC-11d1-8D13-00AA00BD8339
$211A8760-03AC-11d1-8D13-00AA00BD8339
$211A8766-03AC-11d1-8D13-00AA00BD8339
$C6E13380-30AC-11d0-A18C-00A0C9118956
$54C39221-8380-11d0-B3F0-00AA003761C5
$D8D715A3-6E5E-11D0-B3F0-00AA003761C5
$B196B28B-BAB4-101A-B69C-00AA00341D07
$5a804648-4f66-4867-9c43-4f5c822cf1b8
$8f537d09-f85e-4414-b23b-502e54c79927
$0eb1088c-4dcd-46f0-878f-39dae86a51b7
$9e5530c5-7034-48b4-bb46-0b8a6efc8e36
$6B652FFF-11FE-4fce-92AD-0266B5D7C78F
$0579154A-2B53-4994-B0D0-E773148EFF85
WrapNonExceptionThrows
_CorDllMain
mscoree.dll
wwwwwwwwwwwwwwp
DDDDDDDDDDDDDDp
DDDDDDDDDDDDDDp
LLLLLLLLLNItp
DDDDDDDDDDDDD@
wwwwwwwDDDDDDDGOGOGOGOGOGOGOGOGHGLGDDDDDD
L!This program cannot be run in DOS mode.
`.sdata
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v2.0.50727
#Strings
<Module>
mscorlib
Microsoft.VisualBasic
MyApplication
rec.My
MyComputer
MyProject
MyWebServices
ThreadSafeObjectProvider`1
Resources
rec.My.Resources
MySettings
MySettingsProperty
Microsoft.VisualBasic.ApplicationServices
ApplicationBase
Microsoft.VisualBasic.Devices
Computer
System
Object
.cctor
get_Computer
m_ComputerObjectProvider
get_Application
m_AppObjectProvider
get_User
m_UserObjectProvider
get_WebServices
m_MyWebServicesObjectProvider
Application
WebServices
Equals
GetHashCode
GetType
ToString
Create__Instance__
instance
Dispose__Instance__
get_GetInstance
Microsoft.VisualBasic.MyServices.Internal
ContextValue`1
m_Context
GetInstance
System.Resources
ResourceManager
resourceMan
System.Globalization
CultureInfo
resourceCulture
get_ResourceManager
get_Culture
set_Culture
Culture
System.Configuration
ApplicationSettingsBase
defaultInstance
get_Default
Default
get_Settings
Settings
mciSendString
lpstrCommand
lpstrReturnString
uReturnLength
hwndCallback
winmm.dll
mciSendStringA
startrec
stoprec
System.ComponentModel
EditorBrowsableAttribute
EditorBrowsableState
System.CodeDom.Compiler
GeneratedCodeAttribute
System.Diagnostics
DebuggerNonUserCodeAttribute
DebuggerHiddenAttribute
Microsoft.VisualBasic.CompilerServices
StandardModuleAttribute
HideModuleNameAttribute
System.ComponentModel.Design
HelpKeywordAttribute
System.Runtime.CompilerServices
RuntimeHelpers
GetObjectValue
RuntimeTypeHandle
GetTypeFromHandle
Activator
CreateInstance
MyGroupCollectionAttribute
get_Value
set_Value
System.Runtime.InteropServices
ComVisibleAttribute
ReferenceEquals
System.Reflection
Assembly
get_Assembly
CompilerGeneratedAttribute
SettingsBase
Synchronized
ServerComputer
Microsoft.VisualBasic.MyServices
FileSystemProxy
get_FileSystem
System.IO
GetTempPath
Conversions
String
Concat
FileExists
rec.Resources.resources
DebuggableAttribute
DebuggingModes
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
AssemblyFileVersionAttribute
GuidAttribute
AssemblyTrademarkAttribute
AssemblyCopyrightAttribute
AssemblyProductAttribute
AssemblyCompanyAttribute
AssemblyDescriptionAttribute
AssemblyTitleAttribute
rec.dll
N:?!k|
MyTemplate
8.0.0.0
My.User
My.Computer
My.WebServices
My.Application
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
10.0.0.0
My.Settings
WrapNonExceptionThrows
1.0.0.0
$2d501281-7a80-49bb-93f8-75fef7d8bb5f
Copyright
2013
_CorDllMain
mscoree.dll
RSDS9EqNI
C:\Users\Raed\Documents\Visual Studio 2010\Projects\rec\rec\obj\Debug\rec.pdb
wwwwwwwwwwwwwwp
DDDDDDDDDDDDDDp
DDDDDDDDDDDDDDp
LLLLLLLLLNItp
DDDDDDDDDDDDD@
wwwwwwwDDDDDDDGOGOGOGOGOGOGOGOGHGLGDDDDDD
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
fSystem.Drawing.Icon, System.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aBj
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Icon
IconData
IconSize
System.Drawing.Size
System.Drawing.Size
height
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v2.0.50727
#Strings
Stub.exe
mscorlib
Microsoft.VisualBasic
System.Windows.Forms
System
System.Drawing
System.Data
System.Management
user32.dll
user32
winmm.dll
avicap32.dll
kernel32.dll
kernel32
wininet.dll
advapi32.dll
crypt32.dll
oleaut32.dll
User32.dll
mozsqlite3
Crypt32.dll
Server.Resources.resources
Server.Chat.resources
Server.Form1.resources
<Module>
MyApplication
Server.My
WindowsFormsApplicationBase
Microsoft.VisualBasic.ApplicationServices
_MyDomain
AppDomain
AccessedThroughPropertyAttribute
System.Runtime.CompilerServices
_MyDomain2
get_UseCompatibleTextRendering
Application
SetCompatibleTextRenderingDefault
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
DebuggerHiddenAttribute
System.Diagnostics
STAThreadAttribute
get_MyDomain
ResolveEventHandler
remove_AssemblyResolve
add_AssemblyResolve
set_MyDomain
WithEventsValue
Assembly
System.Reflection
ResolveEventArgs
get_Name
String
Contains
MyDomain_AssemblyResolve
sender
get_MyDomain2
set_MyDomain2
MyDomain2_AssemblyResolve
AuthenticationMode
get_CurrentDomain
set_IsSingleInstance
set_EnableVisualStyles
set_SaveMySettingsOnExit
set_ShutdownStyle
ShutdownMode
DebuggerStepThroughAttribute
set_MainForm
OnCreateMainForm
MyDomain
MyDomain2
GeneratedCodeAttribute
System.CodeDom.Compiler
MyComputer
Computer
Microsoft.VisualBasic.Devices
MyProject
Object
m_ComputerObjectProvider
m_AppObjectProvider
m_UserObjectProvider
m_MyFormsObjectProvider
m_MyWebServicesObjectProvider
.cctor
get_GetInstance
get_Computer
get_Application
get_User
get_Forms
get_WebServices
HelpKeywordAttribute
System.ComponentModel.Design
WebServices
HideModuleNameAttribute
StandardModuleAttribute
Microsoft.VisualBasic.CompilerServices
MyForms
m_Chat
m_Form1
m_FormBeingCreated
Hashtable
System.Collections
ThreadStaticAttribute
get_Chat
get_Form1
ArgumentException
set_Chat
set_Form1
TargetInvocationException
Control
get_IsDisposed
GetTypeFromHandle
RuntimeTypeHandle
ContainsKey
GetResourceString
InvalidOperationException
Activator
CreateInstance
ProjectData
SetProjectError
Exception
get_InnerException
get_Message
Remove
Create__Instance__
Instance
Component
Dispose
Dispose__Instance__
instance
RuntimeHelpers
GetObjectValue
Equals
GetHashCode
GetType
ToString
MyGroupCollectionAttribute
MyWebServices
ThreadSafeObjectProvider`1
m_ThreadStaticValue
CompilerGeneratedAttribute
GetInstance
ComVisibleAttribute
System.Runtime.InteropServices
Server
components
IContainer
_Button1
Button
_TextBox1
TextBox
_TextBox2
IDisposable
disposing
DebuggerNonUserCodeAttribute
ComponentResourceManager
SuspendLayout
set_Location
set_Name
set_Size
set_TabIndex
ButtonBase
set_Text
set_UseVisualStyleBackColor
set_Multiline
ContainerControl
set_AutoScaleDimensions
set_AutoScaleMode
AutoScaleMode
set_ClientSize
get_Controls
ControlCollection
set_FormBorderStyle
FormBorderStyle
ResourceManager
System.Resources
GetObject
set_Icon
set_MaximizeBox
set_MinimizeBox
set_ShowIcon
set_ShowInTaskbar
set_StartPosition
FormStartPosition
set_TopMost
ResumeLayout
PerformLayout
InitializeComponent
get_Button1
EventHandler
remove_Click
add_Click
set_Button1
get_TextBox1
set_TextBox1
get_TextBox2
set_TextBox2
get_Text
get_Length
Concat
get_Tag
Operators
ConcatenateObject
Conversions
Button1_Click
EventArgs
Button1
TextBox1
TextBox2
DesignerGeneratedAttribute
njLogger
isRunning
MaxLength
Stream
StreamWriter
System.IO
LogsPath
LastAV
LastAS
lastKey
Isdown
WH_KEYBOARD_LL
HC_ACTION
WM_SYSKEYDOWN
WM_SYSKEYUP
KBDLLHookProcDelegate
HHookID
WM_KEYDOWN
WM_KEYUP
ServerComputer
get_Clock
get_LocalTime
DateTime
GetTempPath
get_ExecutablePath
FileInfo
Boolean
IntPtr
Thread
System.Threading
ReadAllText
ClearProjectError
AppendText
set_AutoFlush
GetExecutingAssembly
GetModules
Module
Marshal
GetHINSTANCE
ToInt32
op_Explicit
ThreadStart
Delete
DeleteLogs
Process
GetProcessById
get_MainWindowTitle
CompareString
get_Day
get_Month
get_Year
TextWriter
WriteAllText
ToUnicodeEx
StringBuilder
System.Text
wVirtKey
wScanCode
lpKeyState
pwszBuff
cchBuff
wFlags
GetKeyboardState
MapVirtualKey
uMapType
SetWindowsHookEx
idHook
HookProc
hInstance
wParam
CallNextHookEx
lParam
UnhookWindowsHookEx
GetWindowThreadProcessId
lpdwProcessID
GetKeyboardLayout
dwLayout
GetForegroundWindow
get_Keyboard
Keyboard
get_ShiftKeyDown
get_CapsLock
ToUpper
Strings
ToLower
VKCodeToUnicode
VKCode
op_Equality
PtrToStructure
KeyboardProc
KBDLLHOOKSTRUCT
ValueType
vkCode
scanCode
dwExtraInfo
KBDLLHOOKSTRUCTFlags
value__
LLKHF_EXTENDED
LLKHF_INJECTED
LLKHF_ALTDOWN
LLKHF_UP
FlagsAttribute
KBDLLHookProc
MulticastDelegate
TargetObject
TargetMethod
BeginInvoke
IAsyncResult
AsyncCallback
DelegateCallback
DelegateAsyncState
EndInvoke
DelegateAsyncResult
Invoke
downloder
fileStartup
WinRARReName
Virtulbox
ollydbg
processdownloder
msgfo2
withoutrun
asfasf
servernameshort
shadyservershortcut
serverpathcopy
OKCancel
retrycanel
yesnocanel
retryignore
msgt7t
server
server2
shsreg
el2emashortcut
paths213123hortcut
RenameServConf
DirCopyWinRAR
regsetup
regset
el2ema
install
shadymaadwy
Wireshark
hacker
cports
procexp
vmware
taskmangerlol
CompareMethod
List`1
System.Collections.Generic
Bitmap
Rectangle
Screen
get_PrimaryScreen
get_Bounds
get_Width
get_Height
set_Width
set_Height
ToInteger
Graphics
FromImage
set_CompositingQuality
CompositingQuality
System.Drawing.Drawing2D
CopyFromScreen
CopyPixelOperation
Cursors
get_Default
Cursor
get_Position
GetThumbnailImage
GetThumbnailImageAbort
MD5CryptoServiceProvider
System.Security.Cryptography
HashAlgorithm
ComputeHash
Convert
ToBase64String
ImageCodecInfo
System.Drawing.Imaging
GetImageEncoders
get_MimeType
GetEncoderInfo
EncoderParameters
MemoryStream
Enumerator
get_Size
get_Count
ToArray
AddRange
IEnumerable`1
get_PixelFormat
PixelFormat
ImageFormat
get_Jpeg
get_Item
GetEnumerator
get_Current
DrawImage
MoveNext
get_Param
EncoderParameter
Encoder
Quality
Encoding
GetBytes
NotImplementedException
SizeOfimage
_Timer2
_Timer3
_Timer4
_Timer5
_Timer6
_Timer7
_Timer8
_Timer9
_Timer10
_Timer11
_Timer12
_Timer1
PersistThread
SW_SHOWNORMAL
SW_SHOWMINIMIZED
tictoc
RSocket
TcpClient
System.Net.Sockets
culture
country
streamWebcam
taskBar
SETDESKWALLPAPER
UPDATEINIFILE
RegistryKey
Microsoft.Win32
MaaDawy
rThread
StartupKey
DataEvent
AppPath
AddToStartup
HideFile
AddToTemp
TempHideFile
FormClosingEventHandler
add_FormClosing
add_Load
Environment
get_UserName
get_MachineName
CultureInfo
System.Globalization
get_CurrentCulture
get_EnglishName
IndexOf
LastIndexOf
Substring
GetFolderPath
SpecialFolder
GetFileName
get_FileSystem
FileSystemProxy
Microsoft.VisualBasic.MyServices
GetFileInfo
Container
set_Interval
set_Enabled
set_AutoSizeMode
AutoSizeMode
set_ControlBox
set_Opacity
set_SizeGripStyle
SizeGripStyle
get_Timer2
remove_Tick
add_Tick
set_Timer2
get_Timer3
set_Timer3
get_Timer4
set_Timer4
get_Timer5
set_Timer5
get_Timer6
set_Timer6
get_Timer7
set_Timer7
get_Timer8
set_Timer8
get_Timer9
set_Timer9
get_Timer10
set_Timer10
get_Timer11
set_Timer11
get_Timer12
set_Timer12
get_Timer1
set_Timer1
BlockInput
fBlock
ShowWindow
handle
nCmdShow
apiBlockInput
SwapMouseButton
SendMessage
lparam
SetWindowPos
hWndInsertAfter
FindWindow
lpClassName
lpWindowName
FindWindowA
mciSendString
lpCommandString
lpReturnString
uReturnLength
hwndCallback
mciSendStringA
GetWindowText
lpString
SystemParametersInfo
uAction
uParam
lpvParam
fuWinIni
SystemParametersInfoA
SendCamMessage
SendMessageA
Form1_FormClosing
FormClosingEventArgs
GetPathWinRAR
Interaction
CreateObject
NewLateBinding
LateGet
LateSet
LateCall
CreateProjectError
maaaadawwyhackeeeer
shadymaadawy
m3daawyhacker
WebClient
System.Net
GetEnvironmentVariable
set_Visible
MessageBox
DialogResult
MessageBoxButtons
MessageBoxIcon
Exists
EndApp
Registry
CurrentUser
OpenSubKey
SetValue
RegistryValueKind
Environ
DownloadFile
AppWinStyle
set_IsReadOnly
FileSystemInfo
get_Attributes
FileAttributes
set_Attributes
SetAttributes
Form1_Load
Delegate
Combine
add_Data
remove_Data
get_Client
Socket
SocketFlags
set_ReceiveBufferSize
set_SendBufferSize
set_NoDelay
set_ReceiveTimeout
set_SendTimeout
Connect
get_Connected
SelectMode
get_Available
Receive
LateIndexGet
Disconnect
GetString
StreamReader
IPAddress
UdpClient
ImageConverter
FileAttribute
IEnumerator
DeleteValue
ToBoolean
ReadAllBytes
ReadToEnd
WriteLine
Create
FileStream
CreateDirectory
startrec
FileExists
stoprec
FromBase64String
WriteAllBytes
get_Info
ComputerInfo
get_OSFullName
Replace
get_Registry
RegistryProxy
GetValue
Restart
GetProcesses
get_ProcessName
get_Id
get_SessionId
GetProcessesByName
LateSetComplex
DataReceivedEventHandler
add_OutputDataReceived
add_ErrorDataReceived
add_Exited
ProcessWindowStyle
get_ASCII
TypeConverter
ConvertTo
get_StartupPath
Directory
RenameDirectory
RenameFile
ToDouble
set_Position
IEnumerable
ChangeType
FileSystem
SetAttr
GZipStream
System.IO.Compression
OpenRead
CompressionMode
Console
CompressFile
UncompressFile
OperatingSystem
get_OSVersion
get_ServicePack
LocalMachine
GenerateOperatingSystem
get_LastWriteTime
capGetDriverDescriptionA
wDriver
lpszName
cbName
lpszVer
ProcessThread
get_Threads
ProcessThreadCollection
ReadOnlyCollectionBase
op_Inequality
SuspendProcess
process
OpenThread
dwDesiredAccess
bInheritHandle
dwThreadId
SuspendThread
hThread
ResumeThread
CloseHandle
hHandle
checkcam
get_UTF8
CaptureDesktop
startup
GetVolumeInformation
lpRootPathName
lpVolumeNameBuffer
nVolumeNameSize
lpVolumeSerialNumber
lpMaximumComponentLength
lpFileSystemFlags
lpFileSystemNameBuffer
nFileSystemNameSize
GetVolumeInformationA
Conversion
WinTitle
GetWindowTextA
GetWindowTextLength
GetWindowTextLengthA
DeleteFile
DeleteSubKey
set_Tag
chatappds
LoadDeviceList
ClassesRoot
StartsWith
GetKey
CurrentConfig
GetRootSubs
GetSubKeyNames
GetRootSubKeys
GetData
StrReverse
GetLast
GetValueNames
GetValueKind
GetValues
location
GetSubKeys
Timer2_Tick
Timer3_Tick
Timer4_Tick
Timer5_Tick
Timer6_Tick
Timer7_Tick
Timer8_Tick
Timer9_Tick
Timer10_Tick
Timer11_Tick
get_Capacity
GetCaption
Timer12_Tick
Timer1_Tick
_Lambda$__1
Timer2
Timer3
Timer4
Timer5
Timer6
Timer7
Timer8
Timer9
Timer10
Timer11
Timer12
Timer1
DataEventHandler
ThreadAccess
TERMINATE
SUSPEND_RESUME
GET_CONTEXT
SET_CONTEXT
SET_INFORMATION
QUERY_INFORMATION
SET_THREAD_TOKEN
IMPERSONATE
DIRECT_IMPERSONATION
chatappd
Module1
mouse_event
dwFlags
cButtons
ManagementObject
ManagementObjectCollection
ManagementObjectEnumerator
ManagementObjectSearcher
ManagementBaseObject
GetFirewall
getanti
DriveInfo
IEnumerator`1
DriveType
get_Drives
ReadOnlyCollection`1
System.Collections.ObjectModel
get_DriveType
getDrives
DirectoryInfo
GetDirectories
getFolders
GetFiles
getFiles
opera_salt
key_size
DOutput
CredEnumerateW
filter
pCredentials
ReadIntPtr
PtrToStringBSTR
ToCharArray
Information
UBound
get_Chars
paltalk
ReadAllLines
StringType
MidStmtStr
AddObject
GetOpera
ICryptoTransform
TripleDESCryptoServiceProvider
Initialize
SymmetricAlgorithm
set_Mode
CipherMode
set_Padding
PaddingMode
TripleDES
set_Key
set_IV
CreateDecryptor
TransformFinalBlock
get_Unicode
decrypt2_method
encrypt_data
CREDENTIAL
TargetName
Comment
LastWritten
CredentialBlobSize
CredentialBlob
Persist
AttributeCount
Attributes
TargetAlias
UserName
firefox5
signon
DataTable
DataRow
System.Text.RegularExpressions
IsMatch
get_Rows
DataRowCollection
GetFire
LoadLibrary
dllFilePath
GetProcAddress
hModule
procName
GetDelegateForFunctionPointer
NSS_Init
configdir
PK11_GetInternalKeySlot
PK11_Authenticate
loadCerts
NSSBase64_DecodeBuffer
arenaOpt
outItemOpt
PK11SDR_Decrypt
result
SHITEMID
TSECItem
SECItemType
SECItemData
SECItemLen
DLLFunctionDelegate
UnmanagedFunctionPointerAttribute
CallingConvention
DLLFunctionDelegate2
DLLFunctionDelegate3
DLLFunctionDelegate4
DLLFunctionDelegate5
SQLiteBase5
SQL_OK
SQL_ROW
SQL_DONE
database
HeapAlloc
GetProcessHeap
lstrlen
sqlite3_open
fileName
sqlite3_close
sqlite3_exec
callback
arguments
sqlite3_errmsg
sqlite3_prepare_v2
length
statement
sqlite3_step
sqlite3_column_count
sqlite3_column_name
columnNumber
sqlite3_column_type
sqlite3_column_int
sqlite3_column_double
sqlite3_column_text
sqlite3_column_blob
sqlite3_column_table_name
sqlite3_finalize
baseName
OpenDatabase
CloseDatabase
ArrayList
get_ItemArray
GetTables
ExecuteNonQuery
ExecuteQuery
get_Columns
DataColumnCollection
DataColumn
Double
ReadFirstRow
ReadNextRow
WriteByte
StringToPointer
PointerToString
GetPointerLenght
SQLiteDataTypes
Chrome
Gchrome
CryptUnprotectData
pDataIn
szDataDescr
pOptionalEntropy
pvReserved
pPromptStruct
pDataOut
GCHandle
GCHandleType
AddrOfPinnedObject
Decrypt
CryptProtectPromptFlags
CRYPTPROTECT_PROMPT_ON_UNPROTECT
CRYPTPROTECT_PROMPT_ON_PROTECT
CRYPTPROTECT_PROMPTSTRUCT
cbSize
dwPromptFlags
hwndApp
szPrompt
DATA_BLOB
cbData
pbData
SQLiteHandler
db_bytes
page_size
encoding
master_table_entries
SQLDataTypeSize
table_entries
field_names
ToBigEndian16Bit
ToBigEndian32Bit
ToBigEndian64Bit
startIndex
BitConverter
ToInt64
endIndex
ConvertToInteger
Decimal
ToUInt16
CopyArray
Compare
Subtract
ToUInt64
get_BigEndianUnicode
Multiply
ReadMasterTable
Offset
ReadTableFromOffset
CompareTo
ReadTable
TableName
GetRowCount
row_num
GetTableNames
FileOpen
OpenMode
OpenAccess
OpenShare
FileGet
FileClose
record_header_field
table_entry
row_id
content
sqlite_master_entry
item_type
item_name
astable_name
root_num
sql_statement
CIE7Passwords
ERROR_CACHE_FIND_FAIL
ERROR_CACHE_FIND_SUCCESS
MAX_PATH
MAX_CACHE_ENTRY_INFO_SIZE
NORMAL_CACHE_ENTRY
URLHISTORY_CACHE_ENTRY
PROV_RSA_FULL
ALG_CLASS_HASH
ALG_TYPE_ANY
ALG_SID_SHA
CALG_SHA
AT_SIGNATURE
HP_HASHVAL
READ_CONTROL
STANDARD_RIGHTS_READ
KEY_QUERY_VALUE
KEY_ENUMERATE_SUB_KEYS
KEY_NOTIFY
SYNCHRONIZE
STANDARD_RIGHTS_WRITE
KEY_SET_VALUE
KEY_CREATE_SUB_KEY
KEY_READ
KEY_WRITE
HKEY_CURRENT_USER
FindFirstUrlCacheEntry
lpszUrlSearchPattern
lpFirstCacheEntryInfo
lpdwFirstCacheEntryInfoBufferSize
FindFirstUrlCacheEntryA
FindNextUrlCacheEntry
FindNextUrlCacheEntryA
FindCloseUrlCache
hEnumHandle
lstrlenA
lstrcpyA
RetVal
CryptAcquireContext
phProv
pszContainer
pszProvider
dwProvType
CryptAcquireContextA
CryptCreateHash
phHash
CryptHashData
dwDataLen
CryptGetHashParam
dwParam
pdwDataLen
CryptSignHash
dwKeySpec
sDescription
pbSignature
pdwSigLen
CryptSignHashA
CryptDestroyHash
CryptReleaseContext
RegOpenKeyEx
lpSubKey
ulOptions
samDesired
phkResult
RegOpenKeyExA
RegQueryValueEx
lpValueName
lpReserved
lpType
lpData
lpcbData
RegQueryValueExA
RegDeleteValue
RegDeleteValueA
LocalFree
RegCloseKey
ppszDataDescr
CredEnumerate
lpszFilter
lFlags
pCount
lppCredentials
CredDelete
lpwstrTargetName
dwType
CredDeleteW
CredFree
pBuffer
SysAllocString
pOlechar
PtrToStringAnsi
GetStrFromPtrA
CheckSum
GetSHA1Hash
ReadByte
PtrToStringUni
ProcessIEPass
strURL
strHash
dataOut
AllocHGlobal
StringToHGlobalUni
FreeHGlobal
AddPasswdInfo
strRess
CopyString
RegexOptions
WriteInt32
IsNullOrEmpty
Matches
MatchCollection
get_Groups
GroupCollection
Capture
get_Value
WriteInt16
Format
Refresh
SYSTEMTIME
wMonth
wDayOfWeek
wMinute
wSecond
wMilliseconds
INTERNET_CACHE_ENTRY_INFO
dwStructSize
lpszSourceUrlName
lpszLocalFileName
CacheEntryType
dwUseCount
dwHitRate
dwSizeLow
dwSizeHigh
LastModifiedTime
FILETIME
ExpireTime
LastAccessTime
LastSyncTime
lpHeaderInfo
dwHeaderInfoSize
lpszFileExtension
dwExemptDelta
StringIndexHeader
dwWICK
dwEntriesCount
dwUnkId
StringIndexEntry
dwDataOffset
ftInsertDateTime
dwDataSize
CRED_TYPE
GENERIC
DOMAIN_PASSWORD
DOMAIN_CERTIFICATE
DOMAIN_VISIBLE_PASSWORD
MAXIMUM
CREDENTIAL_ATTRIBUTE
lpstrKeyword
dwValueSize
lpbValue
lpstrTargetName
lpstrComment
ftLastWritten
dwCredentialBlobSize
lpbCredentialBlob
dwPersist
dwAttributeCount
lpAttributes
lpstrTargetAlias
lpUserName
Resources
Server.My.Resources
resourceMan
resourceCulture
ReferenceEquals
get_Assembly
get_ResourceManager
get_Culture
set_Culture
get_cam
get_rec
Culture
MySettings
ApplicationSettingsBase
System.Configuration
defaultInstance
addedHandler
addedHandlerLockObject
SettingsBase
Synchronized
get_SaveMySettingsOnExit
AutoSaveSettings
ObjectFlowControl
CheckForSyncLockOnValueType
Monitor
ShutdownEventHandler
add_Shutdown
Default
MySettingsProperty
get_Settings
Settings
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
AssemblyDescriptionAttribute
AssemblyTitleAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
DebuggingModes
CompilationRelaxationsAttribute
GuidAttribute
AssemblyTrademarkAttribute
AssemblyFileVersionAttribute
MyDomain
MyDomain2
MyTemplate
8.0.0.0
My.Computer
My.Application
My.User
My.Forms
My.WebServices
System.Windows.Forms.Form
Create__Instance__
Dispose__Instance__
My.MyProject.Forms
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
Button1
TextBox1
TextBox2
Timer2
Timer3
Timer4
Timer5
Timer6
Timer7
Timer8
Timer9
Timer10
Timer11
Timer12
Timer1
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
10.0.0.0
My.Settings
Server
Copyright
2012
WrapNonExceptionThrows
$8c0a0be4-c2d9-43fd-8362-d331a08ed069
1.0.0.0
_CorExeMain
mscoree.dll
wwwwwwwwwwwwwwp
DDDDDDDDDDDDDDp
DDDDDDDDDDDDDDp
LLLLLLLLLNItp
DDDDDDDDDDDDD@
wwwwwwwDDDDDDDGOGOGOGOGOGOGOGOGHGLGDDDDDD
<?xml version="1.0" encoding="utf-8"?>
<asmv1:assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1" xmlns:asmv1="urn:schemas-microsoft-com:asm.v1" xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<!-- UAC Manifest Options
If you want to change the Windows User Account Control level replace the
requestedExecutionLevel node with one of the following.
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
<requestedExecutionLevel level="highestAvailable" uiAccess="false" />
Specifying requestedExecutionLevel node will disable file and registry virtualization.
If you want to utilize File and Registry Virtualization for backward
compatibility then delete the requestedExecutionLevel node.
-->
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- A list of all Windows versions that this application is designed to work with. Windows will automatically select the most compatible environment.-->
<!-- If your application is designed to work with Windows 7, uncomment the following supportedOS node-->
<!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>-->
</application>
</compatibility>
<!-- Enable themes for Windows common controls and dialogs (Windows XP and later) -->
<!-- <dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>-->
</asmv1:assembly>
555CCC
zzz>>>
lIDATxw8
I|Agwr?
8%#K'J5
>W#Hp*
0bTWE<X{gYi|)ge^
pRf]N20
hnYgReI#b
w)b\Lv)
x8,r%+x'.
DL)F"5E},>B
HY""`X:t
m[FH,"c
u*K#KH
w"E"NX"
8,sC9+De1
\:Yrpe
E,reP3
v)s,Cd
,]+OQ/K?^
Y@Wf~pif
AsK3K?
\H^Xfu
&B)FbAe
x^A2>f
#x `EV-
&^{}n_-Fi~]
}=f.so=e}W*
\*5z_9
{cxbUs>
IENDB`
v2.0.50727
#Strings
<Module>
jj.Scr
mscorlib
System
Object
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
System.Reflection
Assembly
GetExecutingAssembly
System.Resources
ResourceManager
Environment
SpecialFolder
GetFolderPath
String
Concat
GetObject
System.IO
WriteAllBytes
System.Diagnostics
Process
Exception
get_Message
Console
WriteLine
files.resources
v_:IcMV,.[8/
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
(17::71(
U:0...//////000001111122222333334444455555666667777788888999999::::;;=G`
?@(06999:::::;;;;;<<<<<<=====>>>>>?????@@@@@AAAAABBBBBBCCCCCDDDDDEEEEEFFEC>8N
(3;97778888899999::::::;;;;;<<<<<=====>>>>>?????@@@@@AAAAAABBBBBCCCCCDDDDDFHB7
O&9877778888899999::::::;;;;;<<<<<=====>>>>>?????@@@@@AAAAAABBBBBCCCCCDDDDDEEEFH7
17877778888899999::::::;;;;;<<<<<=====>>>>>?????@@@@@AAAAAABBBBBCCCCCDDDDDEEEEEGGB
Nk+:77778888899999::::::;;;;;<<<<<=====>>>>>?????@@@@@AAAAAABBBBBCCCCCDDDDDEEEEEFFI<wO
6777778888899999::::::;;;;;<<<<<=====>>>>>?????@@@@@AAAAAABBBBBCCCCCDDDDDEEEEEFFFFFG
:*:7778888899999::::::;;;;;<<<<<=====>>>>>?????@@@@@AAAAAABBBBBCCCCCDDDDDEEEEEFFFFFI<
*:778888899999::::::;;;;;<<<<<=====>>>>>?????@@@@@AAAAAABBBBBCCCCCDDDDDEEEEEFFFFFGJ;
x+:78888899999::::::;;;;;<<<<<=====>>>>>?????@@@@@AAAAAABBBBBCCCCCDDDDDEEEEEFFFFFGGI<
gw+:8888899999::::::;;;;;<<<<<=====>>>>>?????@@@@@AAAAAABBBBBCCCCCDDDDDEEEEEFFFFFGGGI<g
w+:888899999::::::;;;;;<<<<<=====>>>>>?????@@@@@AAAAAABBBBBCCCCCDDDDDEEEEEFFFFFGGGGI=
%w,;88899999::::::;;;;;<<<<<====?>?@>>?????@@@@@AAAAAABBBBBCCCCCDDDDDEEEEEFFFFFGGGGGJ>%
jw-;8899999::::::;;;;;<<<<<====>6;95A@????@@@@@AAAAAABBBBBCCCCCDDDDDEEEEEFFFFFGGGGGGJ
w-;899999::::::;;;;;<<<<<====?6mk1>B??@@@@@AAAAAABBBBBCCCCCDDDDDEEEEEFFFFFGGGGGGHJ~>
w-;99999::::::;;;;;<<<<<=====><
B4BA@@@@AAAAAABBBBBCCCCCDDDDDEEEEEFFFFFGGGGGGHHJ}=
Iw,;9999::::::;;;;;<<<<<=====><Dq2>C@@AAAAAABBBBBCCCCCDDDDDEEEEEFFFFFGGGGGGHHHJ}>H
w-<999::::::;;;;;<<<<<=====>?=C
F5CBAAAAABBBBBCCCCCDDDDDEEEEEFFFFFGGGGGGHHHHK|?
x.<99::::::;;;;;<<<<<=====>>?=Cv4>DAAABBBBBCCCCCDDDDDEEEEEFFFFFGGGGGGHHHHHK{?
x.<9::::::;;;;;<<<<<=====>>>?=D
K5CCBBBBBCCCCCDDDDDEEEEEFFFFFGGGGGGHHHHHIKz?
0x.<::::::;;;;;<<<<<=====>>>>?=D}6>EBBBCCCCCDDDDDEEEEEFFFFFGGGGGGHHHHHIIKy?/
Wx.<:::::;;;;;<<<<<=====>>>>>?>D
O6DDCCCCCDDDDDEEEEEFFFFFGGGGGGHHHHHIIIKx?V
x.=::::;;;;;<<<<<=====>>>>>?@>D8>FCCCDDDDDEEEEEFFFFFGGGGGGHHHHHIIIILw@
y/=:::;;;;;<<<<<=====>>>>>??@>DT6EEDDDDDEEEEEFFFFFGGGGGGHHHHHIIIIILv@
y/=::;;;;;<<<<<=====>>>>>???@=E:>GDDDEEEEEFFFFFGGGGGGHHHHHIIIII
y/<:;;;;;<<<<<=====>>>>>????@>EY7EFEEEEEFFFFFGGGGGGHHHHHIIIII
y/=;;;;;<<<<<=====>>>>>?????@?E=>HEEEFFFFFGGGGGGHHHHHIIIII
J~J}J~Lt@
y/>;;;;<<<<<=====>>>>>?????@A?E^8FGFFFFFGGGGGGHHHHHIIIII
J~J}J|J}LsA
(y0>;;;<<<<<=====>>>>>?????@@A?E
@?IFFFGGGGGGHHHHHIIIII
J~J}J|J{J|MrA'
1y0>;;<<<<<=====>>>>>?????@@@A?Ec:GFGGGGGGHHHHHIIIII
J~J}J|J{J{K|MqA1
7y0=;<<<<<=====>>>>>?????@@@@A?F?HGGGGGHHHHHIIIII
J~J}J|J{J{KzK{MpA7
:y0><<<<<=====>>>>>?????@@@@@A@Fe@IGGGHHHHHIIIII
J~J}J|J{J{KzKyKzMpA:
:y0?<<<<=====>>>>>?????@@@@@AB@Fe@IGGHHHHHIIIII
J~J}J|J{J{KzKyKxKyMoB:
7z1?<<<=====>>>>>?????@@@@@AAB@F@IGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKxNnB7
1z1?<<=====>>>>>?????@@@@@AAAB?Fd<HGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLxNmB1
(z1><=====>>>>>?????@@@@@AAAAA@GB@JGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLwNlB(
z1?=====>>>>>?????@@@@@AAAAABAG_:HIGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLvNkB
z1?====>>>>>?????@@@@@AAAAAACAG?AJGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLuNkB
z2@===>>>>>?????@@@@@AAAAAABCAGZ:HIGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLtOjC
{2@==>>>>>?????@@@@@AAAAAABBCAG=AJGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMtOiC
{2?=>>>>>?????@@@@@AAAAAABBBBAHW9HIGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMrMsOhC
{2@>>>>>?????@@@@@AAAAAABBBBCBH<AJGGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMrMqMrOgC
W{2@>>>>?????@@@@@AAAAAABBBBBDBH
S:HHGGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMrMqMpMqOfCV
0{3A>>>?????@@@@@AAAAAABBBBBCDBH;BIGGGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMrMqMpMoMpPeD/
{3@>>?????@@@@@AAAAAABBBBBCCDBH
P:IGFGGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMrMqMpMoMoNpPdD
{3@>?????@@@@@AAAAAABBBBBCCCCBI{:CIFGGGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMrMqMpMoMoNnNoPdD
{3A?????@@@@@AAAAAABBBBBCCCCDCI
L;IGFGGGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMrMqMpMoMoNnNmNnPcD
J{3A????@@@@@AAAAAABBBBBCCCCCEBJu9DIFFGGGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMrMqMpMoMoNnNmNlNmPbDH
{4B???@@@@@AAAAAABBBBBCCCCCDDDB
H;IGFFGGGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMrMqMpMoMoNnNmNlNkNlQaE
|4A??@@@@@AAAAAABBBBBCCCCCDDDF=rp7DIFFFGGGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMrMqMpMoMoNnNmNlNkNjNlQ`E
l|4A?@@@@@AAAAAABBBBBCCCCCDDDDDF>B@<IGFFFGGGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMrMqMpMoMoNnNmNlNkNjNjOkQ_Ek
&|4A@@@@@AAAAAABBBBBCCCCCDDDDDEEGEFHFFFFGGGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMrMqMpMoMoNnNmNlNkNjNjOiOjQ^E&
|4B@@@@AAAAAABBBBBCCCCCDDDDDEEEEEFFFFFGGGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMrMqMpMoMoNnNmNlNkNjNjOiOhOiQ^E
i|5C@@@AAAAAABBBBBCCCCCDDDDDEEEEEFFFFFGGGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMrMqMpMoMoNnNmNlNkNjNjOiOhOgOhR]Fh
~5B@@AAAAAABBBBBCCCCCDDDDDEEEEEFFFFFGGGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMrMqMpMoMoNnNmNlNkNjNjOiOhOgOfOhR\F
4C@AAAAAABBBBBCCCCCDDDDDEEEEEFFFFFGGGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMrMqMpMoMoNnNmNlNkNjNjOiOhOgOfOfPgSZE
4CAAAAAABBBBBCCCCCDDDDDEEEEEFFFFFGGGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMrMqMpMoMoNnNmNlNkNjNjOiOhOgOfOfPePfSYE<
?AAAAAABBBBBCCCCCDDDDDEEEEEFFFFFGGGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMrMqMpMoMoNnNmNlNkNjNjOiOhOgOfOfPePdPcPbP
Pp7DAAABBBBBCCCCCDDDDDEEEEEFFFFFGGGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMrMqMpMoMoNnNmNlNkNjNjOiOhOgOfOfPePdPeRZG|P
;BBABBBBBCCCCCDDDDDEEEEEFFFFFGGGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMrMqMpMoMoNnNmNlNkNjNjOiOhOgOfOfPePdPdQcQ]L
1ECBBBBCCCCCDDDDDEEEEEFFFFFGGGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMrMqMpMoMoNnNmNlNkNjNjOiOhOgOfOfPePdPdQeSTCQ
4@ECBCCCCCDDDDDEEEEEFFFFFGGGGGGHHHHHIIIII
J~J}J|J{J{KzKyKxKwKwLvLuLtLsLsMrMqMpMoMoNnNmNlNkNjNjOiOhOgOfOfPePeQfSaOUD
G5=CEEEEFFFFFGGGGGHHHHHIIIIIIJJJJJKKKKKL
L~L~L}L|M{MzMzMyMxNwNwNvNuNtOsOsOrOqOpPoPnPnPmPlPkQjQjQiQhQgRfRdP_KXDfUA
ZC;::;;;;;<<<<<======>>>>>??
?~?}?}@|@{@z@y@xAwAwAvAuAtBsBrBqBqBpCoCnCmClClDkDjDiDhDgEfEeEeEdEcFbFaF`F`F_G^G]G]HcPvf
(17::71(
KONjEtsvYm
QmUGFXzVAA
'EXQ[E\EbEcEeE
AvgTimePerFrame
BmiHeader
nChannels
nSamplesPerSec
wBitsPerSample
Video Capture Device
Ds.NET Grabber
Audio Capture Device
Video Compressor
Audio Compressor
emp.avi
Sample
!!DLG: OnCaptureDone
Video Tuner
Video Composite
Video S-Video
Video RGB
Video YRYBY
Video Serial Digital
Video Parallel Digital
Video SCSI
Video AUX
Video Firewire
Video USB
Video Decoder
Video Encoder
Video SCART
Audio Tuner
Audio Line In
Audio Mic
Audio AES Digital
Audio SPDIF Digital
Audio SCSI
Audio AUX
Audio Firewire
Audio USB
Audio Decoder
Unknown Connector
00000000-0000-0000-C000-000000000046
FriendlyName
dpnhpast.dll
!Ds.NET: ShowCapPinDialog
FilterGraph {0} pid {1}
2db47ae5-cf39-43c2-b4d6-0cd8d90946f4
c9f5fe02-f851-4eb5-99ee-ad602af1e619
Video Capture Pin
Video Preview Pin
Video Crossbar
TV Tuner
Audio Capture Pin
Audio Preview Pin
Audio Crossbar
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
0.0.0.0
InternalName
cam.dll
LegalCopyright
OriginalFilename
cam.dll
ProductVersion
0.0.0.0
Assembly Version
0.0.0.0
rec.Resources
soundrec
open new Type waveaudio Alias recsound
record recsound
save recsound
close recsound
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
1.0.0.0
InternalName
rec.dll
LegalCopyright
Copyright
2013
OriginalFilename
rec.dll
ProductName
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
$this.Icon
+T 3a ;a!
! #"$"%"'&(&)&+*,*-*.*/*0*1*2*
Property can only be set to Nothing
WinForms_RecursiveFormCreate
WinForms_SeeInnerException
Button1
TextBox1
TextBox2
$this.Icon
Chat With Hacker
chatback||
said :
[ENTER]
derron-51617.portmap.io
Software\Microsoft\Windows\CurrentVersion\Run
image/jpeg
Shell_traywnd
Server.exe
WScript.Shell
SpecialFolders
Startup
CreateShortcut
TargetPath
ExpandEnvironmentStrings
WorkingDirectory
WindowStyle
IconLocation
%SystemRoot%\system32\SHELL32.dll,0
%Temp%
%AppData%
APPDATA
%Desktop%
%Recent%
%MyDocuments%
%StartMenu%
%serverpathcopy%
%History%
%Cookies%
%MyMusic%
%MyPictures%
%SendTo%
%Favorites%
\Microsoft\svchost.exe
melt.txt
software\microsoft\windows\currentversion\run
software\microsoft\windows\currentversion\RunOnce
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
length
Uninstall
download
download||
downloadfile
downloadedfile||
cryptedecryptetextfile
savetextfile
creatnewtextfile
msgbox
Information
File Name Already Exists
creatnewfolder
startrec
soundrec
stoprec
downloadtherec
requestrecords
ping -t
sendfile
openkl
getlogs
logs||
openklon
getlogson
logson||
Microsoft
Windows
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\SYSTEM\CENTRALPROCESSOR\0
ProcessorNameString
info||
sendfileto
closeserver
restartserver
GetProcesses
ProcessSplit
ProcessManager
KillProcess
SProcess
SSProcess
SSSProcess
openshell
StartInfo
RedirectStandardOutput
RedirectStandardInput
RedirectStandardError
FileName
cmd.exe
UseShellExecute
CreateNoWindow
EnableRaisingEvents
BeginErrorReadLine
BeginOutputReadLine
StandardInput
WriteLine
OpenPro
corrupt
wAyqsW4eE9Csd0dndY1rLnufPtO4Vjp9cRvXz0g38RaWjeoo1OBXT0CNp4wW7vY4Ti6Sm64zhnEn0QWHcVTGZrnNHcc9JFDNGAPYCzPWwyDPIDBsdg067E8newVoWRj7TON9roebC3m0iW9oGJ73CM4UelTtjctQvxt2QqpXATVVvAKpibp7qcoiRV9Vmves42mYUI42
GetDrives
FileManager||
FileManager
FileManager||Error
BLAAAAAAAAAAAAAAA!/asldifrhXGJRCVKJJEAWTBRHGMGGaslkdfhaseoirfhasdhfjXGJRCVKJJEAWTBRHGMGGasdzf483975634597328528934tzhXGJRCVKJJEAWTBRHGMGGeufgz34975638q9ruweirf
XGJRCVKJJEAWTBRHGMGGhsdkjvnwu45z6384975weuirhjsfndjvzw438563qXGJRCVKJJEAWTBRHGMGG84ruwajfjsadfhdfhgq349875q390rXGJRCVKJJEAWTBRHGMGGuf)=/()%&
%&%XGJRCVKJJEAWTBRHGMGGJGKTCMFPHBJKEZEFTJLMNMEEJJYATLRJCTNYMSXWWARWJIKELWOYXNKVFDOWRYXARGFGKLVUPWCMKECEQRXUXGWJTWSTHZEZKXSH!!!!@#$%^&*(())_+|}{}{}{}{hjbgipsdbgbgdsipsdgii9375hdasih0=398pofjkphdi9-3\-49jdfisodf3-49947-932fskdnf9
update
Delete
Folder
Execute
Rename
openfm
getdesktoppath
getpath||
gettemppath
getstartuppath
getmydocumentspath
getmyimagespath
getrecentpath
getmymusicpath
gethistorypath
camlist
camclose
gethfavoritepath
infoDesk
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
Identifier
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\BIOS
SystemProductName
BIOSReleaseDate
BIOSVersion
SystemManufacturer
BIOSVendor
HKEY_CURRENT_USER\TunisiaRat
infoDesk||
viewimage
Logoff
shutdown -l -t 00
Restart
shutdown -r -t 00
Shutdown
shutdown -s -t 00
openurl
default
opentto
setaswallpaper
OPchat
openRG
GetSubKeyNames
GetValueNames
GetValueKind
GetValue
SetValue
DeleteValue
CreateSubKey
DeleteSubKeyTree
hidefolderfile
Comrar
Decrar
showfolderfile
Compressing {0} to {1}.
Decompressing {0} to {1}.
Hardware\Description\System\CentralProcessor\0
yyyy-MM-dd
unknown
SystemDrive
Software
cmd.exe /k ping 0 & del "
FullName
& exit
said :
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_CURRENT_CONFIG
R_ROOTSUB||
R_CDIR||
R_SUB||
R_VALUE||
wireshark
SpyTheSpy
ProcessHacker
mbamgui
Malwarebytes Anti-Malware
cports
ollydbg
procexp
vmtoolsd
taskmgr
VBoxTray
VBoxService
root\SecurityCenter
SELECT * FROM FirewallProduct
displayName
No Firewall
AhnLab-V3
BitDefender
ByteHero
clamav
ClamAV
fpavserver
F-Prot
fssm32
F-Secure
engface
Jiangmin
Kaspersky
updaterui
McAfee
msmpeng
microsoft security essentials
Norman
npupdate
nProtect
inicio
Sophos
savservice
saswinlo
SUPERAntiSpyware
spbbcsvc
Symantec
TheHacker
ufseagnt
TrendMicro
dllhook
sbamtray
vrmonsvc
ViRobot
vbcalrt
VirusBuster
Not Found
[Drive]
FileManagerSplitFileManagerSplit
[Folder]
FileManagerSplit
Software\Yahoo\Profiles
|URL| http://Yahoo.com
|USR|
|PWD|
WindowsLive:name=*
|URL| http://hotmail.com
|USR|
|PWD|
|PWD|
\FileZilla\recentservers.xml
<Server>
<Host>
|URL|
</Host>
<User>
</User>
<Pass>
</Pass>
HKEY_LOCAL_MACHINE\SOFTWARE\Vitalwerks\DUC
USERname
Password
|URL| http://no-ip.com
|USR|
|PWD|
Software\Paltalk
HKEY_CURRENT_USER\Software\Paltalk\
|URL| http://Paltalk.com
|USR|
ALLUSERSPROFILE
DynDNS\Updater\config.dyndns
username=
password=
t6KzXhCh
|URL| http://DynDns.com
|USR|
\Opera\Opera\wand.dat
\Opera\Opera\profile\wand.dat
http://
https://
|USR|
abcdefghijklmnopqrstuvwxyz1234567890_-.~!@#$%^&*()[{]}\|';:,<>/?+=
PROGRAMFILES
\Mozilla Firefox\
\Mozilla\Firefox\Profiles
signons.sqlite
SELECT * FROM moz_logins;
SELECT * FROM moz_disabledHosts;
formSubmitURL
encryptedUsername
encryptedPassword
mozutils.dll
mozglue.dll
mozcrt19.dll
nspr4.dll
plc4.dll
plds4.dll
ssutil3.dll
mozsqlite3.dll
nssutil3.dll
softokn3.dll
nss3.dll
NSS_Init
PK11_GetInternalKeySlot
PK11_Authenticate
NSSBase64_DecodeBuffer
PK11SDR_Decrypt
SELECT name FROM sqlite_master WHERE type IN ('table','view') AND name NOT LIKE 'sqlite_%'UNION ALL SELECT name FROM sqlite_temp_master WHERE type IN ('table','view') ORDER BY 1
resultTable
System.Int32
System.Single
System.String
\Google\Chrome\User Data\Default\Login Data
logins
origin_url
username_value
password_value
UNIQUE
SQLite format 3
name="([^"]+)"
Software\Microsoft\Internet Explorer\IntelliForms\Storage1
Software\Microsoft\Internet Explorer\IntelliForms\Storage2
text/html
Microsoft_WinInet_*
abe2869f-9b47-4cd9-a358-c22904dba7f7
Software\Microsoft\FTP\Accounts
ftp://{0}@{1}/
Server.Resources
pSILlzCez34GFHGHwXBSrQ1Vb72t6bIXyedstKRzAHJklNNL94gD8hIi9FwLiiVlr
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
Server
FileVersion
1.0.0.0
InternalName
Stub.exe
LegalCopyright
Copyright
2012
OriginalFilename
Stub.exe
ProductName
Server
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
yRugphQHlk.exe
KONjEtsvYm
vOJsBziDuL..png
QmUGFXzVAA
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
0.0.0.0
InternalName
jj.Scr
LegalCopyright
OriginalFilename
jj.Scr
ProductVersion
0.0.0.0
Assembly Version
0.0.0.0

DNS

Name Response Post-Analysis Lookup
dns.msftncsi.com A 131.107.255.255 131.107.255.255
dns.msftncsi.com AAAA fd3e:4f5a:5b81::1 131.107.255.255

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 56933 114.114.114.114 53
192.168.56.101 138 192.168.56.255 138

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.