Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Two xor decryption loops in order to decrypt the strings
- @xorsthings
- =======================================================
- ollydbg
- windbgframeclass
- ImmunityDebugger
- ZetaDebugger
- Rock Debugger
- ObsidianGUI
- kernel32.dll
- BlockInput --> Anti-Debug
- IsDebuggerPresent--> Anti-Debug
- CheckRemoteDebuggerPresent--> Anti-Debug
- dbghelp.dll --> anti-debug
- Sbiedll.dll----> Sandboxie detection
- snxhk.dll ---> sandbox detection
- api_log.dll---> SunBelt sandbox detection
- dir_watch.dll --> SunBelt SandBox detection
- vmcheck.dll--> Virtual-PC detection
- wpespy.dll -->WPE Pro detection
- pstorec.dll --> SunBelt Sandbox detection
- ollydbg.exe
- ProcessHacker.exe
- tcpviewer.exe
- autoruns.exe
- autorunsc.exe
- filemon.exe
- procmon.exe
- procexp.exe
- idaq.exe
- idaq64.exe
- ImmunityDebugger.exe
- WireShark.exe
- dumpcap.exe
- HookExplorer.exe
- ImportREC.exe
- PETools.exe
- LordPE.exe
- SysInspector.exe
- proc_analyser.exe
- sysAnalyzer.exe
- sniff_hit.exe
- windbg.exe
- joeboxcontrol.exe
- joeboxserver.exe
- netmon.exe
- prl__cc.exe
- HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 0\Target Id 0\Logical Unit Id 0
- SOFTWARE\VMware, Inc.\VMware Tools
- prl_tools.exe
- VMSrvc.exe
- VMUSrvc.exe
- xenservice.exe
- Identifier
- HARDWARE\DESCRIPTION\System
- QEMU
- \\.\PhysicalDrive0
- ntdll.dll
- NtClose
- SystemBiosVersion
- VBOX
- VideoBiosVersion
- drivers\VBoxMouse.sys
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement