Sample details: dbfc802a7e5935f178618b725fd4b25a --

Hashes
MD5: dbfc802a7e5935f178618b725fd4b25a
SHA1: 9906834ab5d24d6d365474141c9eaeccebcd1480
SHA256: 9626bcb04c920c611707740eebc798ca86b03ab59480180a747fd739a1e08269
SSDEEP: 1536:W7bGYXhgTdlrYTxtWPd5Rc2efW9R/mTKMYnJA+voIR+3bvIozTj6Rm6CBW:WtxgnWtwd6YnJAI+LvIUaU6Z
Details
File Type: PE32
Yara Hits
YRP/Microsoft_Visual_Studio_NET | YRP/Microsoft_Visual_C_v70_Basic_NET_additional | YRP/Microsoft_Visual_C_Basic_NET | YRP/Microsoft_Visual_Studio_NET_additional | YRP/Microsoft_Visual_C_v70_Basic_NET | YRP/NET_executable_ | YRP/NET_executable | YRP/NETexecutableMicrosoft | YRP/IsPE32 | YRP/IsNET_EXE | YRP/IsWindowsGUI | YRP/HasDebugData | YRP/IsBeyondImageSize | YRP/domain | YRP/IP | YRP/url | YRP/contentis_base64 | YRP/Dropper_Strings | YRP/Misc_Suspicious_Strings | YRP/inject_thread | YRP/keylogger | YRP/cred_local | YRP/win_registry | YRP/win_hook | YRP/Advapi_Hash_API | YRP/Str_Win32_Wininet_Library | YRP/CAP_HookExKeylogger |
Source
http://103.68.190.250/Sources//ActiveMalwares/VRT/Stub/Client/obj/Release/Stub.exe
Strings
		!This program cannot be run in DOS mode.
`.sdata
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
l#ffffff
l#ffffff
l#ffffff
l#ffffff
v2.0.50727
#Strings
B	F	K	
B	F	K	
<Module>
mscorlib
Microsoft.VisualBasic
MyApplication
Stub.My
MyComputer
MyProject
MyForms
MyWebServices
ThreadSafeObjectProvider`1
njLogger
KBDLLHOOKSTRUCT
KBDLLHOOKSTRUCTFlags
KBDLLHookProc
AntiTaskManager
EnumWindProc
EnumChildWindProc
firefox5
Chrome
SQLiteHandler
CIE7Passwords
CREDENTIAL
SHITEMID
TSECItem
DLLFunctionDelegate
DLLFunctionDelegate2
DLLFunctionDelegate3
DLLFunctionDelegate4
DLLFunctionDelegate5
SQLiteBase5
CryptProtectPromptFlags
CRYPTPROTECT_PROMPTSTRUCT
DATA_BLOB
record_header_field
table_entry
sqlite_master_entry
SYSTEMTIME
INTERNET_CACHE_ENTRY_INFO
StringIndexHeader
StringIndexEntry
CRED_TYPE
CREDENTIAL_ATTRIBUTE
SQLiteDataTypes
Module1
ThreadAccess
SiteBlocker
SiteBlocker2
virustotal2
virustotal1
virusscan2
virusscan1
Resources
Stub.My.Resources
MySettings
MySettingsProperty
SocketClient
ConnectedEventHandler
DisconnectedEventHandler
DataEventHandler
TMListViewDelete
GetItems
EnumDelegate
LV_ITEM
HDITEM
SafeProcessHandle
Microsoft.VisualBasic.ApplicationServices
WindowsFormsApplicationBase
.cctor
System.Collections.Generic
List`1
System
WeakReference
__ENCList
OnCreateMainForm
Microsoft.VisualBasic.Devices
Computer
Object
get_Computer
m_ComputerObjectProvider
get_Application
m_AppObjectProvider
get_User
m_UserObjectProvider
get_Forms
m_MyFormsObjectProvider
get_WebServices
m_MyWebServicesObjectProvider
Application
WebServices
get_Form1
m_Form1
set_Form1
Create__Instance__
System.Windows.Forms
Instance
Dispose__Instance__
instance
System.Collections
Hashtable
m_FormBeingCreated
Equals
GetHashCode
GetType
ToString
get_GetInstance
m_ThreadStaticValue
GetInstance
System.Drawing
Bitmap
System.Drawing.Imaging
ImageCodecInfo
GetEncoderInfo
isRunning
MaxLength
System.IO
StreamWriter
Stream
LogsPath
DeleteLogs
LastAV
LastAS
lastKey
System.Text
StringBuilder
ToUnicodeEx
wVirtKey
wScanCode
lpKeyState
pwszBuff
cchBuff
wFlags
GetKeyboardState
MapVirtualKey
uMapType
SetWindowsHookEx
idHook
HookProc
hInstance
wParam
CallNextHookEx
lParam
UnhookWindowsHookEx
GetWindowThreadProcessId
lpdwProcessID
user32.dll
GetKeyboardLayout
dwLayout
user32
GetForegroundWindow
Isdown
VKCodeToUnicode
VKCode
WH_KEYBOARD_LL
HC_ACTION
WM_SYSKEYDOWN
WM_SYSKEYUP
KBDLLHookProcDelegate
HHookID
WM_KEYDOWN
WM_KEYUP
KeyboardProc
ValueType
vkCode
scanCode
dwExtraInfo
value__
LLKHF_EXTENDED
LLKHF_INJECTED
LLKHF_ALTDOWN
LLKHF_UP
MulticastDelegate
TargetObject
TargetMethod
IAsyncResult
AsyncCallback
BeginInvoke
DelegateCallback
DelegateAsyncState
EndInvoke
DelegateAsyncResult
Invoke
System.Threading
Thread
thread
Random
ExeName
GetIcon
EnableWindow
bEnable
GetClassName
lpClassName
nMaxCount
GetClassNameA
SendMessage
SendMessageA
GetWindowText
lpString
GetWindowTextLength
EnumChildWindows
lpEnumFunc
EnumChild
protect
GetChild
Dispose
disposing
System.ComponentModel
IContainer
components
InitializeComponent
_Timer1
get_Timer1
set_Timer1
WithEventsValue
_Timer2
get_Timer2
set_Timer2
_Timer3
get_Timer3
set_Timer3
_Timer4
get_Timer4
set_Timer4
SW_SHOWNORMAL
SW_SHOWMINIMIZED
ShowWindow
handle
nCmdShow
SW_SHOWMAXIMIZED
virustotal
virusscan
pronoip
PersistThread
copyse
sernam
addtos
StartupKey
culture
country
apiBlockInput
fBlock
BlockInput
SwapMouseButton
lparam
SetWindowPos
hWndInsertAfter
mciSendString
lpstrCommand
lpstrReturnString
uReturnLength
hwndCallback
winmm.dll
mciSendStringA
taskBar
FindWindow
lpWindowName
FindWindowA
lpCommandString
lpReturnString
SETDESKWALLPAPER
UPDATEINIFILE
PictureBox
PictureBox1
SystemParametersInfo
uAction
uParam
lpvParam
fuWinIni
SystemParametersInfoA
streamWebcam
tictoc
SendCamMessage
GetCaption
FormClosedEventArgs
Form1_FormClosed
sender
FormClosingEventArgs
Form1_FormClosing
EventArgs
Form1_Load
Connected
Disconnected
Timer1_Tick
capGetDriverDescriptionA
wDriver
lpszName
cbName
lpszVer
avicap32.dll
CompressFile
UncompressFile
LoadDeviceList
Timer2_Tick_1
System.Diagnostics
Process
SuspendProcess
process
Timer3_Tick
Timer4_Tick
Form1_Load_1
Timer1
Timer2
Timer3
Timer4
mouse_event
dwFlags
cButtons
GetProcesses
getanti
getDrives
readtext
getFolders
location
getFiles
getlog
CredEnumerateW
filter
pCredentials
GetVolumeInformation
lpRootPathName
lpVolumeNameBuffer
nVolumeNameSize
lpVolumeSerialNumber
lpMaximumComponentLength
lpFileSystemFlags
lpFileSystemNameBuffer
nFileSystemNameSize
kernel32
GetVolumeInformationA
paltalk
opera_salt
key_size
DOutput
GetOpera
decrypt2_method
encrypt_data
GetFire
LoadLibrary
dllFilePath
GetProcAddress
hModule
procName
NSS_Init
configdir
PK11_GetInternalKeySlot
PK11_Authenticate
loadCerts
NSSBase64_DecodeBuffer
arenaOpt
outItemOpt
PK11SDR_Decrypt
result
signon
Gchrome
CryptUnprotectData
pDataIn
szDataDescr
pOptionalEntropy
pvReserved
pPromptStruct
pDataOut
Decrypt
db_bytes
page_size
encoding
master_table_entries
SQLDataTypeSize
table_entries
field_names
ToBigEndian16Bit
ToBigEndian32Bit
ToBigEndian64Bit
startIndex
endIndex
ConvertToInteger
ReadMasterTable
Offset
ReadTableFromOffset
ReadTable
TableName
GetRowCount
GetValue
row_num
GetTableNames
baseName
ERROR_CACHE_FIND_FAIL
ERROR_CACHE_FIND_SUCCESS
MAX_PATH
MAX_CACHE_ENTRY_INFO_SIZE
NORMAL_CACHE_ENTRY
URLHISTORY_CACHE_ENTRY
FindFirstUrlCacheEntry
lpszUrlSearchPattern
lpFirstCacheEntryInfo
lpdwFirstCacheEntryInfoBufferSize
wininet.dll
FindFirstUrlCacheEntryA
FindNextUrlCacheEntry
FindNextUrlCacheEntryA
FindCloseUrlCache
hEnumHandle
lstrlenA
kernel32.dll
lstrcpyA
RetVal
PROV_RSA_FULL
ALG_CLASS_HASH
ALG_TYPE_ANY
ALG_SID_SHA
CALG_SHA
AT_SIGNATURE
CryptAcquireContext
phProv
pszContainer
pszProvider
dwProvType
advapi32.dll
CryptAcquireContextA
CryptCreateHash
phHash
CryptHashData
pbData
dwDataLen
HP_HASHVAL
CryptGetHashParam
dwParam
pdwDataLen
CryptSignHash
dwKeySpec
sDescription
pbSignature
pdwSigLen
CryptSignHashA
CryptDestroyHash
CryptReleaseContext
READ_CONTROL
STANDARD_RIGHTS_READ
KEY_QUERY_VALUE
KEY_ENUMERATE_SUB_KEYS
KEY_NOTIFY
SYNCHRONIZE
STANDARD_RIGHTS_WRITE
KEY_SET_VALUE
KEY_CREATE_SUB_KEY
KEY_READ
KEY_WRITE
HKEY_CURRENT_USER
RegOpenKeyEx
lpSubKey
ulOptions
samDesired
phkResult
RegOpenKeyExA
RegQueryValueEx
lpValueName
lpReserved
lpType
lpData
lpcbData
RegQueryValueExA
RegDeleteValue
RegDeleteValueA
LocalFree
RegCloseKey
ppszDataDescr
crypt32.dll
CredEnumerate
lpszFilter
lFlags
pCount
lppCredentials
CredDelete
lpwstrTargetName
dwType
CredDeleteW
CredFree
pBuffer
SysAllocString
pOlechar
oleaut32.dll
GetStrFromPtrA
CheckSum
GetSHA1Hash
ProcessIEPass
strURL
strHash
dataOut
AddPasswdInfo
strRess
CopyString
Refresh
TargetName
Comment
LastWritten
CredentialBlobSize
CredentialBlob
Persist
AttributeCount
Attributes
TargetAlias
UserName
SECItemType
SECItemData
SECItemLen
HeapAlloc
GetProcessHeap
lstrlen
sqlite3_open
fileName
database
sqlite3_close
sqlite3_exec
callback
arguments
sqlite3_errmsg
sqlite3_prepare_v2
length
statement
sqlite3_step
sqlite3_column_count
sqlite3_column_name
columnNumber
sqlite3_column_type
sqlite3_column_int
sqlite3_column_double
sqlite3_column_text
sqlite3_column_blob
sqlite3_column_table_name
sqlite3_finalize
SQL_OK
SQL_ROW
SQL_DONE
OpenDatabase
CloseDatabase
ArrayList
GetTables
ExecuteNonQuery
System.Data
DataTable
ExecuteQuery
ReadFirstRow
ReadNextRow
StringToPointer
PointerToString
GetPointerLenght
CRYPTPROTECT_PROMPT_ON_UNPROTECT
CRYPTPROTECT_PROMPT_ON_PROTECT
cbSize
dwPromptFlags
hwndApp
szPrompt
cbData
row_id
content
item_type
item_name
astable_name
root_num
sql_statement
wMonth
wDayOfWeek
wMinute
wSecond
wMilliseconds
dwStructSize
lpszSourceUrlName
lpszLocalFileName
CacheEntryType
dwUseCount
dwHitRate
dwSizeLow
dwSizeHigh
System.Runtime.InteropServices
FILETIME
LastModifiedTime
ExpireTime
LastAccessTime
LastSyncTime
lpHeaderInfo
dwHeaderInfoSize
lpszFileExtension
dwExemptDelta
dwWICK
dwEntriesCount
dwUnkId
dwDataOffset
ftInsertDateTime
dwDataSize
GENERIC
DOMAIN_PASSWORD
DOMAIN_CERTIFICATE
DOMAIN_VISIBLE_PASSWORD
MAXIMUM
lpstrKeyword
dwValueSize
lpbValue
lpstrTargetName
lpstrComment
ftLastWritten
dwCredentialBlobSize
lpbCredentialBlob
dwPersist
dwAttributeCount
lpAttributes
lpstrTargetAlias
lpUserName
OpenThread
dwDesiredAccess
bInheritHandle
dwThreadId
SuspendThread
hThread
ResumeThread
CloseHandle
hHandle
TERMINATE
SUSPEND_RESUME
GET_CONTEXT
SET_CONTEXT
SET_INFORMATION
QUERY_INFORMATION
SET_THREAD_TOKEN
IMPERSONATE
DIRECT_IMPERSONATION
keybd_event
EmptyWorkingSet
System.Resources
ResourceManager
resourceMan
System.Globalization
CultureInfo
resourceCulture
get_ResourceManager
get_Culture
set_Culture
Culture
System.Configuration
ApplicationSettingsBase
defaultInstance
addedHandler
addedHandlerLockObject
AutoSaveSettings
get_Default
Default
get_Settings
Settings
System.Net.Sockets
TcpClient
add_Connected
ConnectedEvent
remove_Connected
add_Disconnected
DisconnectedEvent
remove_Disconnected
add_Data
DataEvent
remove_Data
IsBuzy
Statconnected
Connect
DisConnect
LVM_FIRST
LVM_DELETECOLUMN
LVM_GETITEMCOUNT
LVM_SORTITEMS
LVM_DELETEITEM
LVM_GETNEXTITEM
LVM_GETITEM
hWndParent
GetWindowTextA
GetWindowTextLengthA
controls
MyProc
ProcLV
t_Tick
get_Running
set_Running
lngHwnd
lngLParam
GetClass
GetTitleText
Running
listViewHandle
OpenProcess
dwProcessId
ReadProcessMemoryW
hProcess
lpBaseAddress
lpBuffer
bytesRead
ReadProcessMemory
message
GetHeaderSendMessage
VirtualAllocEx
lpAddress
dwSize
flAllocationType
flProtect
VirtualFreeEx
dwFreeType
WriteProcessMemory
lpNumberOfBytesWritten
LVM_GETITEMTEXT
LVM_GETHEADER
HDM_GETIEMA
HDM_GETITEMW
HDM_GETITEMCOUNT
HDM_GETUNICODEFORMAT
HDI_TEXT
MEM_COMMIT
MEM_RELEASE
PAGE_READWRITE
PROCESS_VM_READ
PROCESS_VM_WRITE
PROCESS_VM_OPERATION
WM_GETTEXT
WM_GETTEXTLENGTH
GetListView
lvhandle
GetItem
subitem
iSubItem
stateMask
pszText
cchTextMax
iImage
iIndent
iGroupId
cColumns
puColumns
piColFmt
iGroup
iOrder
Microsoft.Win32.SafeHandles
SafeHandleZeroOrMinusOneIsInvalid
hObject
ReleaseHandle
get_UseCompatibleTextRendering
SetCompatibleTextRenderingDefault
AuthenticationMode
Monitor
set_IsSingleInstance
set_EnableVisualStyles
set_SaveMySettingsOnExit
ShutdownMode
set_ShutdownStyle
set_MainForm
EditorBrowsableAttribute
EditorBrowsableState
System.CodeDom.Compiler
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggerHiddenAttribute
STAThreadAttribute
DebuggerStepThroughAttribute
Microsoft.VisualBasic.CompilerServices
StandardModuleAttribute
HideModuleNameAttribute
System.ComponentModel.Design
HelpKeywordAttribute
ArgumentException
System.Reflection
TargetInvocationException
Control
get_IsDisposed
RuntimeTypeHandle
GetTypeFromHandle
ContainsKey
String
GetResourceString
InvalidOperationException
Activator
CreateInstance
ProjectData
Exception
SetProjectError
get_InnerException
get_Message
ClearProjectError
Remove
Component
System.Runtime.CompilerServices
RuntimeHelpers
GetObjectValue
MyGroupCollectionAttribute
ThreadStaticAttribute
ComVisibleAttribute
CompilerGeneratedAttribute
Rectangle
Screen
get_PrimaryScreen
get_Bounds
get_Width
get_Height
set_Width
set_Height
get_Length
Strings
Conversions
Concat
ToInteger
Graphics
FromImage
System.Drawing.Drawing2D
CompositingQuality
set_CompositingQuality
CopyPixelOperation
CopyFromScreen
Cursors
Cursor
get_Position
GetThumbnailImageAbort
GetThumbnailImage
System.Security.Cryptography
MD5CryptoServiceProvider
HashAlgorithm
ComputeHash
Convert
ToBase64String
GetImageEncoders
get_MimeType
Operators
CompareString
EncoderParameters
MemoryStream
Enumerator
op_Explicit
get_Size
get_Count
ToArray
IEnumerable`1
AddRange
Contains
CompareMethod
PixelFormat
get_PixelFormat
ImageFormat
get_Jpeg
get_Item
GetEnumerator
get_Current
DrawImage
MoveNext
IDisposable
EncoderParameter
get_Param
Encoder
Quality
Encoding
GetBytes
ServerComputer
get_Clock
DateTime
get_LocalTime
GetTempPath
get_ExecutablePath
FileInfo
get_Name
Boolean
IntPtr
ReadAllText
AppendText
set_AutoFlush
Assembly
GetExecutingAssembly
Module
GetModules
Marshal
GetHINSTANCE
ToInt32
ThreadStart
Delete
GetProcessById
get_MainWindowTitle
get_Day
get_Month
get_Year
TextWriter
WriteAllText
Keyboard
get_Keyboard
get_ShiftKeyDown
get_CapsLock
ToUpper
ToLower
op_Equality
PtrToStructure
DllImportAttribute
MarshalAsAttribute
UnmanagedType
OutAttribute
User32.dll
StructLayoutAttribute
LayoutKind
FlagsAttribute
DriveInfo
DirectoryInfo
GetDrives
get_IsReady
DriveType
get_DriveType
Exists
FileAttributes
SetAttributes
Directory
GetFiles
EndsWith
GetDirectories
FileSystemInfo
set_Attributes
get_TotalFreeSpace
GetExtension
Interaction
CreateObject
NewLateBinding
LateGet
LateSetComplex
Replace
LateCall
GetFileNameWithoutExtension
Microsoft.Win32
RegistryKey
Registry
LocalMachine
OpenSubKey
ConcatenateObject
get_Capacity
get_ProcessName
EventHandler
add_Load
get_CurrentCulture
get_EnglishName
IndexOf
LastIndexOf
Substring
Container
SuspendLayout
set_Enabled
set_Interval
ContainerControl
set_AutoScaleDimensions
AutoScaleMode
set_AutoScaleMode
set_ClientSize
FormBorderStyle
set_FormBorderStyle
set_MaximizeBox
set_MinimizeBox
set_Name
set_Opacity
FormStartPosition
set_StartPosition
ResumeLayout
remove_Tick
add_Tick
FileSystem
OpenMode
OpenAccess
OpenShare
FileOpen
FileGet
FileClose
ToBoolean
set_ShowInTaskbar
set_Visible
CreateDirectory
GetProcessesByName
Environment
SpecialFolder
GetFolderPath
EndApp
Microsoft.VisualBasic.MyServices
FileSystemProxy
get_FileSystem
CopyFile
OrObject
SetValue
ImageConverter
FileAttribute
Restart
startrec
FileExists
stoprec
ReadAllBytes
Network
get_Network
DownloadFile
ToDouble
TypeConverter
ConvertTo
AppWinStyle
get_Audio
AudioPlayMode
FromBase64String
WriteAllBytes
SetAttr
get_MachineName
get_UserName
ComputerInfo
get_Info
get_OSFullName
DeleteValue
Microsoft.VisualBasic.FileIO
UIOption
RecycleOption
DeleteFile
set_Position
RenameDirectory
RenameFile
get_Id
get_SessionId
Console
RegistryProxy
get_Registry
RegistryValueKind
ChangeType
FileStream
System.IO.Compression
GZipStream
OpenRead
Create
CompressionMode
WriteLine
ProcessThread
IEnumerator
ProcessThreadCollection
get_Threads
ReadOnlyCollectionBase
op_Inequality
StringType
MidStmtStr
DesignerGeneratedAttribute
AccessedThroughPropertyAttribute
GetString
IEnumerator`1
System.Collections.ObjectModel
ReadOnlyCollection`1
get_Drives
CurrentUser
GetSubKeyNames
ReadIntPtr
PtrToStringBSTR
Environ
Conversion
ToCharArray
Information
UBound
get_Chars
ReadAllLines
AddObject
StartsWith
ICryptoTransform
TripleDESCryptoServiceProvider
Initialize
SymmetricAlgorithm
CipherMode
set_Mode
PaddingMode
set_Padding
TripleDES
set_Key
set_IV
CreateDecryptor
TransformFinalBlock
get_Unicode
DataRow
GetEnvironmentVariable
System.Text.RegularExpressions
IsMatch
DataRowCollection
get_Rows
get_UTF8
Delegate
GetDelegateForFunctionPointer
UnmanagedFunctionPointerAttribute
CallingConvention
get_ItemArray
DataColumnCollection
get_Columns
DataColumn
Double
WriteByte
mozsqlite3
GCHandle
GCHandleType
AddrOfPinnedObject
Crypt32.dll
BitConverter
ToInt64
Decimal
ToUInt16
CopyArray
Compare
Subtract
ToUInt64
get_BigEndianUnicode
Multiply
CompareTo
PtrToStringAnsi
ReadByte
PtrToStringUni
AllocHGlobal
StringToHGlobalUni
FreeHGlobal
RegexOptions
WriteInt32
IsNullOrEmpty
MatchCollection
Matches
GroupCollection
get_Groups
Capture
get_Value
WriteInt16
Format
_Lambda$__1
ParameterizedThreadStart
_Lambda$__2
_Lambda$__3
_Lambda$__4
_Lambda$__5
_Lambda$__6
ReferenceEquals
get_Assembly
SettingsBase
Synchronized
get_SaveMySettingsOnExit
ObjectFlowControl
CheckForSyncLockOnValueType
ShutdownEventHandler
add_Shutdown
Combine
Socket
get_Client
get_Connected
SocketFlags
SelectMode
get_Available
Receive
LateIndexGet
get_Enabled
GetCurrentProcess
get_Interval
set_Length
ListViewItem
GetLastWin32Error
Win32Exception
get_Text
SafeHandle
SizeOf
SetHandle
Stub.Resources.resources
Stub.Form1.resources
DebuggableAttribute
DebuggingModes
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
AssemblyFileVersionAttribute
GuidAttribute
AssemblyTrademarkAttribute
AssemblyCopyrightAttribute
AssemblyProductAttribute
AssemblyCompanyAttribute
AssemblyDescriptionAttribute
AssemblyTitleAttribute
Stub.exe
MyTemplate
8.0.0.0
My.WebServices
My.Computer
My.Forms
My.User
My.Application
System.Windows.Forms.Form
Create__Instance__
Dispose__Instance__
My.MyProject.Forms
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
Timer4
Timer3
Timer2
Timer1
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
10.0.0.0
My.Settings
WrapNonExceptionThrows
5.0.0.0
$5a542c1b-2d36-4c31-b039-26a88d3967da
Microsoft.net
Copyright 
 Microsoft 2013
_CorExeMain
mscoree.dll
C:\Users\Mr.Mobark\Desktop\Virus Rat v7.0 Sorce\Stub\Client\obj\Release\Stub.pdb
HFAq@?:
ED?&IGB
NLGPBA<
MKFg>?;
KJE]>?:
NKF3DB=
UF<iT:)
ROKPeH8
POJ7OQK
TTOyWWQ
ssoPy|x
21-A:;6
IGCg<=8
><8*@@<
GFAm=?;
PJDL@A;
OC;=S6#
JKG3bL@
KLGdnXL
kc^1k_V
kc^EpRB
kc^O^>1
kc^Sg\U
kc^Mnni
kc^@stp
kc^,z|w^
<?xml version="1.0" encoding="utf-8"?>
<asmv1:assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1" xmlns:asmv1="urn:schemas-microsoft-com:asm.v1" xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
  <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
  <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
    <security>
      <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
        <!-- UAC Manifest Options
            If you want to change the Windows User Account Control level replace the 
            requestedExecutionLevel node with one of the following.
        <requestedExecutionLevel  level="asInvoker" uiAccess="false" />
        <requestedExecutionLevel  level="requireAdministrator" uiAccess="false" />
        <requestedExecutionLevel  level="highestAvailable" uiAccess="false" />
            If you want to utilize File and Registry Virtualization for backward 
            compatibility then delete the requestedExecutionLevel node.
        -->
        <requestedExecutionLevel  level="asInvoker" uiAccess="false" />
      </requestedPrivileges>
    </security>
  </trustInfo>
</asmv1:assembly>