Analysis Date2014-08-19 19:11:08
MD5a5ec76451b38593bd6b4d08ac13f884e
SHA10198d0610f656d77904e330458d8b6a9f9768696

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit Mono/.Net assembly
Language000004b0 
Section.text md5: 7532af295449887d406cac7ddd81b55a sha1: fc93562c50bcc7bd05c94ca67a04409a78c05bee size: 87552
Section.rsrc md5: 7a7c1ea2db3a0dad0a6593c5ccba2543 sha1: e730799afc41ae00b0dbe9b25602c92907f8d938 size: 1536
Section.reloc md5: 7b7371fbbd4ac928dd26c33e24c28662 sha1: 3b817c1e9fe65a55762f88bb0856e8d3f39acadb size: 512
Timestamp2014-08-14 04:49:54
Pdb pathc:\Users\mb_1986\Desktop\Projects\Tiny_st\BlackBerry\obj\Debug\MSSUP.pdb
VersionLegalCopyright: Copyright © 2014
Assembly Version: 1.0.0.0
InternalName: MSSUP.exe
FileVersion: 1.0.0.0
ProductName: MiniSayad
ProductVersion: 1.0.0.0
FileDescription: MiniSayad
OriginalFilename: MSSUP.exe
PackerMicrosoft Visual C# v7.0 / Basic .NET
PEhash2961b97c8a5b02c8e776a1b35aa8499892cf0d66
IMPhashf34d5f2d4577ed6d9ceec516c1f5a744
AV360 SafeTrojan.GenericKD.1805452
AVAd-AwareTrojan.GenericKD.1805452
AVAlwil (avast)no_virus
AVArcabit (arcavir)no_virus
AVAuthentiumno_virus
AVAvira (antivir)no_virus
AVCA (E-Trust Ino)no_virus
AVCAT (quickheal)no_virus
AVClamAVno_virus
AVDr. Webno_virus
AVEmsisoftTrojan.GenericKD.1805452
AVEset (nod32)MSIL/Spy.RapidStealer.A
AVFortinetno_virus
AVFrisk (f-prot)no_virus
AVF-SecureTrojan.GenericKD.1805452
AVGrisoft (avg)no_virus
AVIkarusTrojan.MSIL.Spy
AVK7no_virus
AVKasperskyno_virus
AVMalwareBytesno_virus
AVMcafeeno_virus
AVMicrosoft Security Essentialsno_virus
AVMicroWorld (escan)no_virus
AVNormanno_virus
AVRisingno_virus
AVSophosno_virus
AVSymantecno_virus
AVTrend Microno_virus
AVVirusBlokAda (vba32)no_virus
AVYara APTno_virus
AVZillya!no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates FileC:\Documents and Settings\Administrator\Application Data\MSI93153\MSSUP.exe
Creates Processdw20.exe -x -s 340

Process
↳ dw20.exe -x -s 340

RegistryHKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝
NULL
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\12DF0.dmp
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\dw.log
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\12DF0.dmp
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!

Network Details:


Raw Pcap

Strings
..
.........
00000
000000000000000000000000000000000000
000004b0
/.0.1.:+
{0}{1}
1.0.0.0
  2014
AAAAAAAA-AAAA-AAAA-AAAA-AAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
application/x-www-form-urlencoded
Assembly Version
c2lnbm9ucy5zcWxpdGU=
c2VsZWN0ICogZnJvbSB1cmxz
c2VsZWN0ICogZnJvbSBjb29raWVz
c2VsZWN0ICogZnJvbSBsb2dpbnM=
c2VsZWN0IGlkLCB1cmwgZnJvbSBtb3pfcGxhY2Vz
c2VsZWN0IHVybCwgdGl0bGUsIHZpc2l0X2NvdW50IGZyb20gbW96X3BsYWNlcw==
Configfilename
Content-Type
Copyright 
DisplayName
EncryptionKey
FileDescription
FileVersion
Finish
------------GetSettings--------------
HEAD
host_key
HTTPHeaderName
HTTPHeaderType
HttpPostPattern
InternalName
KeyloggerLogLimitSize:
LegalCopyright
\Microsoft\Windows\MSI93153
MiniSayad
MSSUP.exe
MsupPath
MsupPath,
MsupPathE
name
OriginalFilename
path
PostDataURL
ProductName
ProductVersion
RunDLLg
RunExportUploadFiles
ShortSleepTime
ShortSleepTime7
Skype
\Skype\
sqlite3.dll
SqliteFileName
SQLiteURL
StartupKeyName
Start upload
Storage
Storage=
storage uploader start
StoragUploaderProc uploader
StringFileInfo
title
Translation
U09GVFdBUkVcTWljcm9zb2Z0XFdpbmRvd3NcQ3VycmVudFZlcnNpb25cVW5pbnN0YWxs
UploadDownload
UploadDownload.dll
UploadDownload.Properties.Resources
URLExtractRegex
username_value
value
VarFileInfo
visit_count
VS_VERSION_INFO
XFxHb29nbGVcXENocm9tZVxcVXNlciBEYXRhXFxEZWZhdWx0XFw=
XFxHb29nbGVcXENocm9tZVxcVXNlciBEYXRhXFxEZWZhdWx0XFxDb29raWVz
XFxHb29nbGVcXENocm9tZVxcVXNlciBEYXRhXFxEZWZhdWx0XFxIaXN0b3J5
XFxHb29nbGVcXENocm9tZVxcVXNlciBEYXRhXFxEZWZhdWx0XFxMb2dpbiBEYXRh
*.xml
Y29va2llcy5zcWxpdGU=
1.0.0.0
12.0.0.0
  2014
$3C374A40-BAE4-11CF-BF7D-00AA006946EE
$3C374A42-BAE4-11CF-BF7D-00AA006946EE
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
$86309a71-7f92-4259-a67f-d61da43691ba
)	9	B	X	
add_Elapsed
AddRange
address
AddressFamily
AddrOfPinnedObject
AddUrl
AddUrlAndNotify
$AFA0DC11-C313-11d0-831A-00C04FD5AE38
AfterEncryptSize
a"n"w"
AppDataRoaming
AppDomain
Application
ApplicationSettingsBase
!application/x-www-form-urlencoded
AppSettingsSection
arenaOpt
ArgumentNullException
</assembly>
Assembly
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyCultureAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
  <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
AssemblyVersionAttribute
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
AsyncCallback
AutoResetEvent
$b0c25cd7-781c-4b84-9e7d-6d51c176f316
Base64
base64String
BeginInvoke
BindToObject
BlackBerry
BluePillIsRedOrBlack
BookmarkModel
Bookmarks
BrowserAccountModel
BrowserAccounts
BrowserName
BrowserSerilizeModel
BrowsersInfo
buffer
bufferoffset
bufferToDecode
bufferToEncode
bufferTransferEvent
_bufferTransferEvent
BuildId
bytesToDecryp
bytesToEncrypt
bytetoEncrypt
callback
CallConvStdcall
CallingConvention
CantOpen
CaptureMode
CbSize
cchBuff
.cctor
<>c__DisplayClass2
CheckStartup
Chrome
CipherMode
Class1
ClearHistory
Client.Browsers
Client.Common
Client.KeyLogger
Client.SQLite
Client.Utils
Clipboard
CloseClipboard
cnVuZGxsMzIuZXhl
CodeAccessPermission
column
ColumnCount
ColumnIndex
columnName
ColumnName
Combine
ComImportAttribute
ComInterfaceType
Common
CommonPath
Compare
CompilationRelaxationsAttribute
CompilerGeneratedAttribute
Component
ComputerName
ComVisibleAttribute
Concat
configdir
ConfigFile
Configfilename
Configuration
ConfigurationManager
ConfigurationUserLevel
Console
Constraint
Contains
Content-Type
Control
Convert
cookieData
CookieModel
cookieName
Cookies
CopyFileToTempArea
CopyMsup
Copyright 
_CorDllMain
_CorExeMain
Corrupt
Create
CreateDecryptor
CreateDirectory
CreateEncryptor
CryptionKeyInfo
CryptoStream
CryptoStreamMode
_ctrlKey
Culture
CultureInfo
CurrentUser
c:\Users\mb_1986\Desktop\Projects\Tiny_st\BlackBerry\obj\Debug\MSSUP.pdb
DataProtectionScope
dataToSerialize
DateTime
DebuggableAttribute
DebuggerNonUserCodeAttribute
DebuggingModes
Decode
DecodeBuffer
DecodeString
Default
defaultInstance
DefaultProgramFilePath
DefaultSettingValueAttribute
Delegate
Delete
DeleteStartup
DeleteUrl
DeleteValue
DelphiNative.dll
Demand
DemandWebPermission
DeriveBytes
destFilePath
destnation
dir={0}&data={1}
Directory
DirectoryInfo
DirectorySeparatorChar
Dispose
dllFilePath
DllFunctionDelegate
DllFunctionDelegate2
DllFunctionDelegate3
DllFunctionDelegate4
DllFunctionDelegate5
DllImportAttribute
dotNetVersion
Double
DownloadData
DownloadFile
DownloadSqlite
DownloadSqLite
D:\Programming\CSharp\BlackBerry\UploadDownload\bin\x86\Debug\UploadDownload.pdb
dwFlags
DwFlags
EditorBrowsableAttribute
EditorBrowsableState
ElapsedEventHandler
EncodeBuffer
EncodeString
Encoding
EncryptBuffer
EncryptedBufferEndPos
EncryptedBufferStartPos
EncryptionKey
EndInvoke
Enumerator
EnumUrls
Environment
Equals
errMsg
ErrorFlags
ErrorInsufficientBuffer
ErrorInvalidParameter
ErrorNoMoreItems
EventArgs
EventWaitHandle
Exception
ExeConfigurationFileMap
ExecutableConfigInfo
ExecuteNonQuery
ExecuteQuery
Exists
extractDirectory
ExtractResources
ExtraEncryptedFileInfo
fieldOffset
FileIOPermission
FileIOPermissionAccess
fileName
FileOperation
filePath
FILETIME
FindFilePath
FindSqlite
FindWindow
FindWindowEx
Firefox
FireFoxInstallationpath
FireFoxProfilePath
fixSize
FixStringSize
FlagsAttribute
format
Format
FrameworkDisplayName
FromBase64String
FromUrlSafeBase64String
FtExpires
FtLastUpdated
FtLastVisited
fWriteHistory
GCHandle
GCHandleType
GeneratedCodeAttribute
GetAccounts
GetActiveTcpListeners
GetActiveWindowsUrl
get_AddressFamily
get_AddressList
get_AppSettings
get_ASCII
get_Assembly
GetAsyncKeyState
get_BaseDirectory
get_BlockSize
GetBookmarks
GetBrowserInfo
GetByteCount
GetBytes
GetBytesByName
get_Capacity
get_Chars
GetClassName
GetClipboardData
GetComponents
GetComputerName
get_ConfigFile
get_Configfilename
GetCookieInternal
GetCookies
get_Count
get_Culture
get_Current
GetCurrent
get_CurrentDomain
get_CurrentTimeZone
get_Default
GetDelegateForFunctionPointer
GetDirectories
GetDirectoryName
GetDotNetInstalledVersions
get_EncryptionKey
GetEntryAssembly
GetEntryValue
GetEnumerator
GetEnvironmentVariable
get_ExecutablePath
GetFileName
GetFileNameWithoutExtension
GetFiles
GetFolderPath
GetForegroundWindow
get_Headers
GetHistories
GetHostEntry
get_HostKey
GetHostName
get_HTTPHeaderName
get_HTTPHeaderType
get_HttpPostPattern
GetIEAccounts
get_InstalledInputLanguages
GetIntalledApplications
GetInternalIps
get_InvariantCulture
GetIPGlobalProperties
get_IsAbsoluteUri
get_IsFile
get_Item
GetKeyboardLayout
GetKeyboardState
get_KeyloggerLogLimitSize
get_KeySize
GetLanguages
GetLastWin32Error
get_Length
get_LocalPath
get_Location
get_LongSleepTime
GetMachineInfo
get_MachineName
get_MainWindowTitle
get_MsupPath
get_Name
get_NewLine
GetObject
GetOpenPorts
GetOrdinal
get_Path
GetPathRoot
GetPrivateProfileString
GetProcAddress
GetProcessById
GetProcesses
GetProcessesByName
get_ProcessName
get_ProcessWithParam
get_Psw
GetPublicIp
GetRandomFileName
GetRDPAccounts
get_ReadBuffer
get_ResourceManager
GetResponse
get_RunDLL
get_RunExportDownloadSQL
get_RunExportUploadFiles
GetSavedAccounts
GetSectionNames
get_Settings
GetSettings
get_ShortSleepTime
get_Size
get_SqliteFileName
get_sqlitepath
get_StandardName
get_StartupKey
get_StartupKeyName
get_StatusCode
get_Storage
GetString
GetStringByName
GetSubKeyNames
get_Success
GetTempFileName
GetTempPath
GetText
GetTimeZone
get_Title
get_TwoLetterISOLanguageName
GetType
GetTypeFromHandle
get_UD2
get_UD4
get_Url
get_URLExtractRegex
get_UserName
GetUsername
get_Usn
get_UTF8
get_Value
GetValue
GetValues
get_VisitCount
GetWideCharFromVirtualKey
GetWindowProcessName
GetWindowText
GetWindowThreadProcessId
GlobalLock
GlobalUnlock
GuidAttribute
Histories
HistoryModel
hModule
HostKey
<HostKey>k__BackingField
HTTPHeaderName
HTTPHeaderType
HttpPostPattern
HttpStatusCode
HttpWebRequest
HttpWebResponse
hwndChildAfter
hWndNewOwner
hwndParent
IAsyncResult
IBrowser
ICryptoTransform
IDisposable
idThread
IeNativeMethods
IEnumerable`1
IEnumerator
IEnumSTATURL
IFormatProvider
InAttribute
IndexOf
iniPath
InitializeArray
InputLanguage
InputLanguageCollection
IntalledApplications
InterfaceTypeAttribute
Internal
InternalIps
InternetCookieHttponly
InternetCookieThirdParty
InternetExplorer
InternetFlagRestrictedZone
InternetFlags
InternetGetCookieEx
InternetGetCookieExW
Interrupt
IntPtr
IntToStr
Invoke
IPAddress
IPEndPoint
IPGlobalProperties
IPHostEntry
IsClipboardFormatAvailable
IsExist
IsInRole
IsKeyLocked
IsMatch
IsNull
IsNullOrEmpty
IsUrlAlive
IsUserAdministrator
ISystemInfo
ITransferProtocol
IUrlHistoryStg2
kernel32
kernel32.dll
_keyBuffer
Keylog
Keylogger
KeyloggerLogLimitSize
KeyLoggerProc
_keyloggerTransferBufferEvent
keyLogLimitSize
KeySize
KeyValueConfigurationCollection
KeyValueConfigurationElement
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
Languages
_lastProcWindow
_lastUrl
LayoutKind
length
List`1
loadCerts
LoadLibrary
LocalMachine
Locked
LongSleepTime
lpClassName
lpCmdLine
lpKeyState
lpStaturl
lpString
lpszClass
lpszWindow
lpWindowName
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
MachineInfo
<Main>b__1
MapVirtualKey
Marshal
MarshalAsAttribute
MemberInfo
MemoryStream
method
$$method0x600009d-1
$$method0x600009e-1
Microsoft.Win32
Microsoft\Windows\MSI93153\
Microsoft\Windows\MSI93153\ 
	MiniSayad
Mismatch
Misuse
ModelSerializer
<Module>
MonitorUrl
MoveNext
mscoree.dll
mscorlib
MSI93153
	MSI93153\
MSSUP.Browsers
MSSUP.BusinessModel
MSSUP.Common
MSSUP.Cryptography
MSSUP.exe
MSSUP.exe.config
MSSUP.KeyLogger
MSSUP.Properties
MSSUP.Properties.Resources.resources
MSSUP.SQLite
MSSUP.SystemInfo
MSSUP.Utils
MsupPath
MulticastDelegate
<Name>k__BackingField
NameValueCollection
NativeMethods
nativestring
nativestringlen
nBytes
nDataOffset
.NET Framework 4
.NETFramework,Version=v4.0
NetworkAccess
NewSerializerModel
NextMatch
nLength
nMaxCount
NotADb
NotFound
Notice
NSSBase64_DecodeBuffer
NSS_Init
nStart
object
Object
OpenClipboard
OpenMappedExeConfiguration
OpenPorts
OpenSubKey
op_Equality
op_Explicit
op_Inequality
OutAttribute
outItemOpt
PADPADP
PadRight
passEntry
PassReset
<Path>k__BackingField
pceltFetched
pchCookieData
PK11_Authenticate
PK11_GetInternalKeySlot
PK11SDR_Decrypt
pocsTitle
pocsUrl
poctNotify
_postDataUrl
PostURL
poszFilter
ppenum
ppvOut
PreserveSigAttribute
<PrivateImplementationDetails>{D239983E-10E1-4D98-9842-9FE4AF8457E8}
PrivateKey
Process
Processes
processFileName
processId
processName
processPath
ProcessWithParam
procName
Program
ProtectedData
Protocol
<Psw>k__BackingField
ptrRemain
PtrToStringUni
PtrToStructure
PublicIp
PublicKey
PublicOperation
punkIsFolder
pvCallback
pvParam
PwcsTitle
PwcsUrl
pwszBuff
QueryUrl
ReadAllBytes
ReadAllLines
ReadAllText
ReadBuffer
ReadByte
ReadOnly
ReadOnlyCollectionBase
ReadRow
ReadWrite
ReferenceEquals
RegexOptions
Registry
RegistryKey
@.reloc
Replace
        <requestedExecutionLevel level="asInvoker" uiAccess="false"/>
      </requestedPrivileges>
      <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
reserved
resourceCulture
ResourceExists
resourceMan
ResourceManager
resourceName
Resources
resourceUrl
ResourceURL
result
__result
Rfc2898DeriveBytes
RijndaelManaged
`.rsrc
RunDLL
rundll32.exe "{0}",{1}
RunExportDownloadSQL
RunExportUploadFiles
RuntimeCompatibilityAttribute
RuntimeFieldHandle
RuntimeHelpers
RuntimeTypeHandle
Schema
`.sdata
SearchOption
searchPattern
SECItemData
SECItemLen
SECItemType
section
    </security>
    <security>
SecurityCriticalAttribute
_selfPath
sender
sendSize
SerializableAttribute
Serialize
SerializeAndCompress
SerializeModel
set_BlockSize
set_Culture
SetCurrentDirectory
set_Enabled
set_ExeConfigFilename
SetFilter
set_HostKey
set_HTTPHeaderName
set_HTTPHeaderType
set_Item
set_IV
set_Key
set_KeySize
set_Method
set_Mode
set_Name
set_Path
set_Psw
SetStartup
Settings
SettingsBase
set_Title
set_Url
set_Usn
set_Value
SetValue
set_VisitCount
SharedCache
ShortSleepTime
SizeOf
SizeofStaturl
SolidSerializeModel
sourceText
SpecialFolder
_sqlConnection
sqlite3_close
sqlite3_close_v2
sqlite3_column_blob
sqlite3_column_bytes
sqlite3_column_count
sqlite3_column_name
sqlite3_column_text
sqlite3_column_type
sqlite3.dll
sqlite3_exec
sqlite3_finalize
sqlite3_open_v2
sqlite3_prepare
sqlite3_reset
sqlite3_step
SqliteDll
SqLiteErrorCode
SqliteFileName
SQLiteFinder
SqLiteOpenFlagsEnum
sqlitepath
SqLiteProvider
_sqLiteUrl
_sqlModule
sqlstr
Stack`1
StartsWith
Startup
StartupKey
startupKeyname
startupKeyName
StartupKeyName
Staturl
Storage
StoragePath
StoragUploaderProc
Stream
String
StringBuilder
StringComparison
StringOperation
#Strings
stringToDecode
stringToEncode
StringToInt
strSql
StructLayoutAttribute
Substring
SuppressUnmanagedCodeSecurityAttribute
SymmetricAlgorithm
Synchronized
System
System.CodeDom.Compiler
System.Collections
System.Collections.Generic
System.Collections.Specialized
System.ComponentModel
System.Configuration
System.Diagnostics
System.Globalization
SystemInfoSerilizeModel
System.IO
System.Net
System.Net.NetworkInformation
System.Net.Sockets
System.Reflection
System.Resources
System.Runtime.CompilerServices
System.Runtime.InteropServices
System.Runtime.Versioning
System.Security
System.Security.Cryptography
System.Security.Permissions
System.Security.Principal
System.Text
System.Text.RegularExpressions
System.Threading
System.Timers
System.Windows.Forms
System.Xml
System.Xml.Serialization
TargetFrameworkAttribute
!This program cannot be run in DOS mode.
Thread
ThreadStart
timerBufferTransfer_Elapsed
timerKeyMine_Elapsed
TimeZone
<Title>k__BackingField
ToArray
ToBase64String
ToInt32
ToInt64
TooBig
ToString
ToUnicode
ToUnicodeEx
ToUrlSafeBase64String
ToUtf8
  </trustInfo>
  <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
TsecItem
TVNTVVAuZXhlLmNvbmZpZw==
TypeAffinity
<U09GVFdBUkVcTWljcm9zb2Z0XFdpbmRvd3NcQ3VycmVudFZlcnNpb25cUnVu
uCmdShow
uFormat
uMapType
Uninitialized
Unknown
UnmanagedFunctionPointerAttribute
UnmanagedType
Unprotect
UploadBuffer
UploadData
UploadDownload
UploadDownload.Common
UploadDownload.Communicator
UploadDownload.Cryptography
\UploadDownload.dll
UploadDownload.dll
UploadDownload.Properties
UploadDownload.Properties.Resources.resources
UploadFile
UploadFiles
uploadUrl
UriComponents
UriFormat
UriToString
[^"url: ."](.*)[^/"]
URLExtractRegex
UrlHistory
<Url>k__BackingField
UrlMonitor
UrlValidator
user32.dll
User32.dll
Username
UserScopedSettingAttribute
<Usn>k__BackingField
UTF8Encoding
utf8Filename
Utf8ToString
v2.0.50727
v4.0.30319
_value
value__
<Value>k__BackingField
ValueType
VisitCount
<VisitCount>k__BackingField
WaitForExit
WaitHandle
WaitOne
Warning
WebClient
WebException
WebHeaderCollection
WebPermission
WebRequest
WebResponse
wFlags
windowName
WindowsBuiltInRole
WindowsIdentity
WindowsPrincipal
WinExec
wininet.dll
WrapNonExceptionThrows
WriteAllBytes
WriteAllText
WriteLine
wScanCode
wVirtKey
XmlSerializer
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>