Static | ZeroBOX

PE Compile Time

2020-02-23 07:43:03

PDB Path

C:\nirar\jilugug\gos93\fuzeg71\fefi49_vi.pdb

PE Imphash

2efdead0abc218f741ed3cdf2ff53455

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000488e0 0x00048a00 7.40516631013
.rdata 0x0004a000 0x0000c0c3 0x0000c200 5.37847302685
.data 0x00057000 0x0049dda8 0x00002200 2.82700089766
.rsrc 0x004f5000 0x00002880 0x00002a00 6.31474489182
.reloc 0x004f8000 0x00006c68 0x00006e00 2.7036448073

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x004f5130 0x000025a8 LANG_SPANISH SUBLANG_SPANISH_ARGENTINA dBase III DBT, version number 0, next free block index 40
RT_ACCELERATOR 0x004f76f0 0x00000090 LANG_SPANISH SUBLANG_SPANISH_ARGENTINA data
RT_GROUP_ICON 0x004f76d8 0x00000014 LANG_SPANISH SUBLANG_SPANISH_ARGENTINA data
RT_VERSION 0x004f7780 0x00000100 LANG_LATVIAN SUBLANG_DEFAULT data

Imports

Library KERNEL32.dll:
0x44a008 GetFileSize
0x44a00c SetLocalTime
0x44a010 GetDriveTypeW
0x44a014 SetEndOfFile
0x44a01c FindResourceExW
0x44a028 GetCommState
0x44a034 WriteConsoleInputA
0x44a038 SetComputerNameW
0x44a03c GetComputerNameW
0x44a040 CallNamedPipeW
0x44a044 GetModuleHandleW
0x44a04c CreateDirectoryExW
0x44a050 TlsSetValue
0x44a054 GlobalAlloc
0x44a05c Sleep
0x44a060 ReadFileScatter
0x44a06c GlobalFlags
0x44a070 Beep
0x44a074 VerifyVersionInfoA
0x44a078 IsDBCSLeadByte
0x44a07c ReadFile
0x44a080 CreateFileW
0x44a084 GetBinaryTypeW
0x44a088 CompareStringW
0x44a08c GetACP
0x44a090 lstrlenW
0x44a094 GetConsoleOutputCP
0x44a098 CreateDirectoryA
0x44a09c GetStdHandle
0x44a0a0 FindFirstFileA
0x44a0a4 OpenMutexW
0x44a0a8 GlobalFix
0x44a0ac SetVolumeLabelW
0x44a0b4 ReadFileEx
0x44a0bc SearchPathA
0x44a0c4 SetFileApisToOEM
0x44a0c8 GetAtomNameA
0x44a0cc Process32FirstW
0x44a0d0 OpenWaitableTimerW
0x44a0d8 GetCommMask
0x44a0dc AddAtomA
0x44a0e0 GetSystemInfo
0x44a0e4 SetSystemTime
0x44a0e8 EnumResourceTypesW
0x44a0f4 SetConsoleTitleW
0x44a0f8 GetModuleHandleA
0x44a100 EnumResourceNamesA
0x44a104 GetConsoleTitleW
0x44a108 BuildCommDCBA
0x44a110 CompareStringA
0x44a114 SetCalendarInfoA
0x44a118 GetVersionExA
0x44a120 GetCurrentProcessId
0x44a124 GetProfileSectionW
0x44a128 SuspendThread
0x44a12c LCMapStringW
0x44a130 CopyFileExA
0x44a134 DeleteFileA
0x44a138 GetProcAddress
0x44a13c GetCommandLineW
0x44a140 GetLastError
0x44a144 GetStartupInfoW
0x44a148 HeapValidate
0x44a14c IsBadReadPtr
0x44a150 RaiseException
0x44a15c SetStdHandle
0x44a160 GetFileType
0x44a164 WriteFile
0x44a168 WideCharToMultiByte
0x44a16c GetConsoleCP
0x44a170 GetConsoleMode
0x44a174 TerminateProcess
0x44a178 GetCurrentProcess
0x44a184 IsDebuggerPresent
0x44a188 GetModuleFileNameW
0x44a194 GetTickCount
0x44a198 GetCurrentThreadId
0x44a1a0 ExitProcess
0x44a1a8 SetHandleCount
0x44a1ac GetStartupInfoA
0x44a1b0 TlsGetValue
0x44a1b4 TlsAlloc
0x44a1b8 TlsFree
0x44a1bc SetLastError
0x44a1c0 HeapDestroy
0x44a1c4 HeapCreate
0x44a1c8 HeapFree
0x44a1cc VirtualFree
0x44a1d0 GetModuleFileNameA
0x44a1d4 HeapAlloc
0x44a1d8 HeapSize
0x44a1dc HeapReAlloc
0x44a1e0 VirtualAlloc
0x44a1e4 GetOEMCP
0x44a1e8 GetCPInfo
0x44a1ec IsValidCodePage
0x44a1f4 WriteConsoleA
0x44a1f8 WriteConsoleW
0x44a1fc MultiByteToWideChar
0x44a200 SetFilePointer
0x44a204 RtlUnwind
0x44a208 DebugBreak
0x44a20c OutputDebugStringA
0x44a210 OutputDebugStringW
0x44a214 LoadLibraryW
0x44a218 LoadLibraryA
0x44a21c LCMapStringA
0x44a220 GetStringTypeA
0x44a224 GetStringTypeW
0x44a228 GetLocaleInfoA
0x44a22c CreateFileA
0x44a230 CloseHandle
0x44a234 FlushFileBuffers
Library USER32.dll:
0x44a23c GetCursorInfo
0x44a240 GetListBoxInfo
0x44a244 GetComboBoxInfo
0x44a248 GetMenuBarInfo
Library ADVAPI32.dll:

Exports

Ordinal Address Name
1 0x43f970 _futurama@4
2 0x43f960 _hiduk@8
3 0x43f950 _regulmoto@4
!This program cannot be run in DOS mode.
1>Rich
`.rdata
@.data
@.reloc
URPQQh
PPPPPPPP
PPPPPPPP
;t$,v-
UQPXY]Y[
W:t!Z[
}42c!L
Fd&%#F
-GVx%w8
`+*T_-
yk}m?.
H&]MuQ
ZdD,E"
j4r$t=
s^AxOJ
uG;8e m
e"#ACy
,+W <hx
C!re,+V
R-Swo>
r/&ulqD
~#`%O(
_P!]58EO
Ibx|-Yk
zp]UY
B3;-D:
p>K|@'ldz
+[#GZb
GWQPdI
.m5wB(
fIm{m,
P<r1"`
::">I@
]x(scS
p{iH2o
}?S{tjTb
n3*\_8V
@DQ4+=UJN
%Ck,$q
W;9r&[)
rx6, D&
T?oDNB/Y
N)]M]F
5\0XtV
6@(R{>#P
DdU Sa}
P>Ki$rU
I`EyG
#4FN*28
'-b+^CHUt
nY/I-*R
qqs^H8:
+n kR[
VG#~[`
<~rqF
PI"Ffb
X'_p>+
>]kc}q
]~kWP\
"cdH:-
YyvS+T
t4msWK`J
~jGn_v
p1"sx}5
n0JPq
`xAhCM
XE+B[(
NJI!iM:Id
;mB>=)
ruF`FCV
2bPJf
]j47G1Z
_4(;tK?@i,
h!|7tr
i\}iC\S
w^?$WZ
;cuX%N
NmP&J]]
Qv2~\$O
+#N4fD
P8W3NS-
R0Ri^BG
C1tQz3=m
#,ha~C
/k9rf{
p5;0?o
\_3N]e
D#}QsJ
F?U:q!
t#UDT|h=\
MuqE;m
|;xV~a
f>aAYM
Gu#80l
J-^<zc
]qDh9_
H_FU;!1
Ml$]?st&l4
\977l^29
vsa!i'i
!M|SFL
Y[]M4T
gJmHk&
Wqr/gZ
tz:9},
0L^3smlm
~PZde3
E)v)_k#
[";pVb:
a"1#Z+A'
V^{f)^m
a.9C9Sd
8sh#8
J@@Jc^
|=>hh&d&MR
~>;^Yz!
Xi]*E5&
eJMaLE
JsAKt
<*B?pP
02`FTp
viF%,Hg%S
0Ly5\C
LOwIXqrn
>b<Yvt
3=#cjg
jBF\sV
}\\Mb\
ld+Qsb
Pmn%y!
nqHVOi
Dh U^k
[^_Zd!.4r
zNSh_Iu hB
DdJYBxsZ
9b6"l?
;#5M:^
)Vrmf x
4] kRMK
a!^^P
PiVu_:
^$U\Pc
y]Rp^P)TM
]+V7IF
%KBW~}\#
cv(\}V
00ZRYB
fhx*g3^
9M%Lgz
=x8 A!
]4/cQr
*A2+NuuH
UuDs;#
<s ~2xK
r;khz;[
;s*HQb
cH8zL@hx<n
IMUM)}
|m9V*3
ANO_2:E)
a^@<dI
#SKC%}u
|}2z'yR
`#\D}',
[QU,SJw
Ip|,{j
2$g*@b2u
_,*@L!
o|/}(S
|-E <-4
dk&kBZi
s5L8p)
{9"c.P
3Q35\
6[4rKH(
~>.E6-
EUQYlZ
"o`"h`22
JTD5Fq
='/29"
Ra5GY4
;/az]|
{xd63r
ue0>(>D\
ieWQ-@
{"K:WI
Bi *Vd
!s2MHV/
'P3_O{
A,}M#$
Cy}qmm
W<U.W3
+5Pr_H
is1mX
Dqvx=d
x~'v8]
D(0;KodY
$i|n9$fFB
:{"cE2r*
eUdw0C
ye-*\\m$j
Ts:9?N
(7dJ3M
v,6oSZ
qn/Y{.
c2%}ehz
?L<"pB
064+{Iv)
F&f8nb
&Q0|Nz
M'38lyq
Rq}`yl8{
uJy]xW
G\^z:&Yf&
I:Vs9/
=-|hcV
lwWXg/
2P1;1%
Gl:r9D
kt(Gi#YK
~#%Bqu
OiamMnY
.gsV?v
BBkz9c
.%s7%V
3o@c}/
cJ)-tgqV
A}r0Ty
'|D^|o
7{g5h
HbhOto
0h//}
X*5jOm
}&#hL0
3l#qa]
3Xe22,
R jzi?
,F(=|U
=>%gNxmX
g)e3}9
FlvG#6
bge+@(
E*; 4^
2!lk_)
R}*ii1M
2B'7}M
\#5_KJ
UxiXX5
1xWjI;
e8 pMR
<{bz.7
:Eu]: 2
+kP&'
nbUH0WM`
>fc[r[2^J
(B]md7t
k9I&4I
"C!&2NV
+&8+"V
pFhAs*
%u`h %
j1hpCE
j1hpCE
u!h@GE
bad allocation
Unknown exception
f:\dd\vctools\crt_bld\self_x86\crt\src\onexit.c
Client
Ignore
Normal
Error: memory allocation: bad memory block type.
Invalid allocation size: %Iu bytes.
Client hook allocation failure.
Client hook allocation failure at file %hs line %d.
Error: possible heap corruption at or near 0x%p
The Block at 0x%p was allocated by aligned routines, use _aligned_realloc()
Error: memory allocation: bad memory block type.
Memory allocated at %hs(%d).
Invalid allocation size: %Iu bytes.
Memory allocated at %hs(%d).
Client hook re-allocation failure.
Client hook re-allocation failure at file %hs line %d.
HEAP CORRUPTION DETECTED: after %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory after end of heap buffer.
HEAP CORRUPTION DETECTED: after %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory after end of heap buffer.
Memory allocated at %hs(%d).
HEAP CORRUPTION DETECTED: before %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory before start of heap buffer.
HEAP CORRUPTION DETECTED: before %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory before start of heap buffer.
Memory allocated at %hs(%d).
Client hook free failure.
The Block at 0x%p was allocated by aligned routines, use _aligned_free()
%hs located at 0x%p is %Iu bytes long.
%hs located at 0x%p is %Iu bytes long.
Memory allocated at %hs(%d).
HEAP CORRUPTION DETECTED: on top of Free block at 0x%p.
CRT detected that the application wrote to a heap buffer that was freed.
HEAP CORRUPTION DETECTED: on top of Free block at 0x%p.
CRT detected that the application wrote to a heap buffer that was freed.
Memory allocated at %hs(%d).
DAMAGED
_heapchk fails with unknown return value!
_heapchk fails with _HEAPBADPTR.
_heapchk fails with _HEAPBADEND.
_heapchk fails with _HEAPBADNODE.
_heapchk fails with _HEAPBADBEGIN.
Bad memory block found at 0x%p.
Bad memory block found at 0x%p.
Memory allocated at %hs(%d).
Object dump complete.
crt block at 0x%p, subtype %x, %Iu bytes long.
normal block at 0x%p, %Iu bytes long.
client block at 0x%p, subtype %x, %Iu bytes long.
{%ld}
%hs(%d) :
#File Error#(%d) :
Dumping objects ->
Data: <%s> %s
Detected memory leaks!
Illegal byte sequence
Directory not empty
Function not implemented
No locks available
Filename too long
Resource deadlock avoided
Result too large
Domain error
Broken pipe
Too many links
Read-only file system
Invalid seek
No space left on device
File too large
Inappropriate I/O control operation
Too many open files
Too many open files in system
Invalid argument
Is a directory
Not a directory
No such device
Improper link
File exists
Resource device
Unknown error
Bad address
Permission denied
Not enough space
Resource temporarily unavailable
No child processes
Bad file descriptor
Exec format error
Arg list too long
No such device or address
Input/output error
Interrupted function call
No such process
No such file or directory
Operation not permitted
No error
f:\dd\vctools\crt_bld\self_x86\crt\src\_file.c
f:\dd\vctools\crt_bld\self_x86\crt\src\input.c
f:\dd\vctools\crt_bld\self_x86\crt\src\mlock.c
CorExitProcess
f:\dd\vctools\crt_bld\self_x86\crt\src\stdenvp.c
f:\dd\vctools\crt_bld\self_x86\crt\src\stdargv.c
f:\dd\vctools\crt_bld\self_x86\crt\src\w_env.c
f:\dd\vctools\crt_bld\self_x86\crt\src\ioinit.c
EncodePointer
DecodePointer
f:\dd\vctools\crt_bld\self_x86\crt\src\tidtable.c
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library without using a manifest.
This is an unsupported way to load Visual C++ DLLs. You need to modify your application to build with a manifest.
For more information, see the "Visual C++ Libraries as Shared Side-by-Side Assemblies" topic in the product documentation.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
Assertion Failed
Warning
Microsoft Visual C++ Debug Library
_CrtDbgReport: String too long or IO Error
Debug %s!
Program: %s%s%s%s%s%s%s%s%s%s%s%s
(Press Retry to debug the application)
Module:
File:
Line:
Expression:
For information on how your program can cause an assertion
failure, see the Visual C++ documentation on asserts.
HeapQueryInformation
f:\dd\vctools\crt_bld\self_x86\crt\src\mbctype.c
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
%s(%d) : %s
Assertion failed!
Assertion failed:
, Line
<file unknown>
Second Chance Assertion Failed: File
_CrtDbgReport: String too long or Invalid characters in String
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetUserObjectInformationA
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
(null)
`h````
xpxxxx
f:\dd\vctools\crt_bld\self_x86\crt\src\output.c
CONOUT$
Unknown Runtime Check Error
Stack memory around _alloca was corrupted
A local variable was used before it was initialized
Stack memory was corrupted
A cast to a smaller data type has caused a loss of data. If this was intentional, you should mask the source of the cast with the appropriate bitmask. For example:
char c = (i & 0xFF);
Changing the code in this way will not affect the quality of the resulting optimized code.
The value of ESP was not properly saved across a function call. This is usually a result of calling a function declared with one calling convention with a function pointer declared with a different calling convention.
Stack around the variable '
' was corrupted.
The variable '
' is being used without being initialized.
bad exception
f:\dd\vctools\crt_bld\self_x86\crt\src\read.c
f:\dd\vctools\crt_bld\self_x86\crt\src\_getbuf.c
f:\dd\vctools\crt_bld\self_x86\crt\src\convrtcp.c
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
`h`hhh
xppwpp
MSPDB80.DLL
Stack around _alloca corrupted
Local variable used before initialization
Stack memory corruption
Cast to smaller type causing loss of data
Stack pointer corruption
bad allocation
vonalahubihohujorojeg xakajolamohuluyiweh
jarewelexawapeminejexavekema kimoyimobomo
cikuhojetogosoz mafacipebijogutejumafefinuk jucejexel dahajupukiri
vujexuda ravuluvagu cudifejasopecaxasute
geyofogicizeb
jumatuyimugahubuce jesokixovacerivicixar tewuv lecajocetorawivifukirota hutiyeyudexavah
wefodawoxenuna tav zorejijikelocayulareteropu punugupixuyesizoxu
citipedaxefupoxexajeko xavozohagurinabil fevubaxurajukuhogihigoxoxivobici
Dug ripeduvixivanazujogis bafowudituzaline zabonicevurasaze
rumogasohehanu jicahuxili nucopilecezifocukal xepetiba
gazulovavogaduxihiyesejunake tikaf lipimexayumuzo
xecumubonehiserukuhunos nomuhetucibey gugedafesozali kupoxinabimasulegamowucemoto
Fok vawobavuxulolufidupuxijakigih sepahoxav lejuw dokebohawukuba
luvevoyovekubefonar
tuhuyigakuhuxajefaxupusunowagoha hofapamotelopehehifufusey mac
GAIsProcessorFeaturePresent
KERNEL32
?Dj0Q:W$=
5s3R6=
?ZEM-'^
?{yK+;
?765@Z
?e')lW
UUUUUU
?333333
?333333
?UUUUUU
?$rxxx
@_nextafter
_hypot
1#QNAN
1#SNAN
C:\nirar\jilugug\gos93\fuzeg71\fefi49_vi.pdb
GetCommandLineW
GlobalFix
GetFileSize
SetLocalTime
GetDriveTypeW
SetEndOfFile
GetNumberOfConsoleInputEvents
FindResourceExW
MapUserPhysicalPages
InterlockedIncrement
GetCommState
InterlockedDecrement
ScrollConsoleScreenBufferW
WriteConsoleInputA
SetComputerNameW
GetComputerNameW
CallNamedPipeW
GetModuleHandleW
GetSystemWow64DirectoryA
CreateDirectoryExW
TlsSetValue
GlobalAlloc
GetVolumeInformationA
ReadFileScatter
GetSystemTimeAdjustment
InterlockedPopEntrySList
GlobalFlags
VerifyVersionInfoA
IsDBCSLeadByte
ReadFile
CreateFileW
GetBinaryTypeW
CompareStringW
GetACP
lstrlenW
GetConsoleOutputCP
CreateDirectoryA
GetStdHandle
FindFirstFileA
OpenMutexW
GetProcAddress
SetVolumeLabelW
WriteProfileSectionA
ReadFileEx
CreateMemoryResourceNotification
SearchPathA
GetPrivateProfileStringA
SetFileApisToOEM
GetAtomNameA
Process32FirstW
OpenWaitableTimerW
IsSystemResumeAutomatic
GetCommMask
AddAtomA
GetSystemInfo
SetSystemTime
EnumResourceTypesW
SetConsoleCursorInfo
CreateIoCompletionPort
SetConsoleTitleW
GetModuleHandleA
FreeEnvironmentStringsW
EnumResourceNamesA
GetConsoleTitleW
BuildCommDCBA
GetCurrentDirectoryA
CompareStringA
SetCalendarInfoA
GetVersionExA
GetWindowsDirectoryW
GetCurrentProcessId
GetProfileSectionW
SuspendThread
LCMapStringW
CopyFileExA
DeleteFileA
KERNEL32.dll
GetComboBoxInfo
GetListBoxInfo
GetCursorInfo
GetMenuBarInfo
USER32.dll
InitiateSystemShutdownW
ADVAPI32.dll
GetLastError
GetStartupInfoW
HeapValidate
IsBadReadPtr
RaiseException
LeaveCriticalSection
EnterCriticalSection
SetStdHandle
GetFileType
WriteFile
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetModuleFileNameW
DeleteCriticalSection
QueryPerformanceCounter
GetTickCount
GetCurrentThreadId
GetSystemTimeAsFileTime
ExitProcess
GetEnvironmentStringsW
SetHandleCount
GetStartupInfoA
TlsGetValue
TlsAlloc
TlsFree
SetLastError
HeapDestroy
HeapCreate
HeapFree
VirtualFree
GetModuleFileNameA
HeapAlloc
HeapSize
HeapReAlloc
VirtualAlloc
GetOEMCP
GetCPInfo
IsValidCodePage
InitializeCriticalSectionAndSpinCount
WriteConsoleA
WriteConsoleW
MultiByteToWideChar
SetFilePointer
RtlUnwind
DebugBreak
OutputDebugStringA
OutputDebugStringW
LoadLibraryW
LoadLibraryA
LCMapStringA
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
CreateFileA
CloseHandle
FlushFileBuffers
xiwito.exe
_futurama@4
_hiduk@8
_regulmoto@4
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
8(9-9?9
;>;D;J;
= =)=5=>=_=y=
?$?*?0?8?I?R?
0X1]1o1O2X2a2q2}2
3&3+3e3
6#6(6.666<6a6}6
6 7*767R7p7z7
7+878d8i8n8
:6:Q:]:b:
;$;t;z;
;.<4<l<r<
=(=A=J=O=u=
>7>x>}>
? ?0?<?R?^?g?
0B1G1L1l1q1
5/5C5{5
7/7U7a7
;E<a<s<
0&0@0~0
1$101F1
2#2(2N2f2r2
585=5O5
5"6:6C6x6}6
7"8V8_8
9G9Q9v9
<E<O<z<
=4=T>^>
1U1_1z1
4&4>4\4
5!6)6f6o6
6%7-7X7
8+949^9c9h9
?0?5?:?
&383A3M3V3d3m3{3
3"4>4Z4l4
4G5X5a5}5
6|6a7l7v7
:':3:N:^:j:
:5;;;i;n;s;
=G=L=Q=~=
3/6;6k6p6u6
687<7@7D7H7L7P7T7X7\7
:F:S:`:m:
;;<b<i<{<
?(?4?D?
0&03080S0`0e0s0{0
2'2?2I2W2\2c2m2q2{2
4"404H4~4
9:.:C:H:M:
?,?N?g?x?}?
191N1S1[1p192S2
4.4D4K4^4
6-6B6I6i6
7!7&7,71777@7G7N7c7q7w7
8"8N8w8
9-979E9O9
9::B:_:
:(;-;?;
<h=m=s=
? ?<?A?F?K?U?
0-02070<0F0c0h0m0w0
3$3e3l3
4>4N4S4X4]4
4F5R5q5
6%6Q6m6y6
6$7)7.7a7f7k7p7
8(8-8?8e8n8
:Q:Y:_:m:w:
>>?E?T?s?z?
A0H0R0
6%6.6H6S6Z6c6l6u6
77)787A7J7[7a7i7r7
7!8-8Z8
=E=c=j=
;;x;};
;B<P<y<
<(=Z=b=i=s=w=
>'>S>c>m>
9,:H:d:
:;7;V;r;
<I<a<x<}<
1O1h1o1w1|1
2^2d2h2l2p2
4i4x4}4
4)545=5K5l5s5}5
9'9Q9V9[9m9z9
9":E:N:
;9<E<v<
<1===I>X?]?o?
0r1w132P2U286=6O6
9)9C9c9
9W:h:m:
:O;U;i;n;s;
;h<m<r<
=<=A=F=z=
=/>c>h>m>
>U?Z?_?
0$1X1g1
5 5,51565f5k5p5
7K7P7U7
<O<V<]<z<
<-=9=f=k=p=
>"?5?f?
0"0,0:0?0I0]0c0k0u0
1A1L1m1
2+20252
9<9A9F9
9B;N;*<6<i<u<
>(>->?>
0 0%0n0z0
1#1+151C1I1T1^1p1
484a4j4
5F5o5x5
9>9g9p9
=-=S=q=x=|=
=V>a>|>
? ?$?(?,?0?z?
J0X0e0o0{0
<!<X<w<
14191>1{1
6 6%6g6
8 8%8b8j8
9!9(9/969=9D9K9S9[9c9o9x9}9
<8<=<O<
(0-0?0
3/3\3e3
3B4K4u4z4
4(5-5?5v5
6G6L6Q6
<(=0=m=y=
?&?P?U?Z?
4;6D7P7}7
768B8o8t8y8
<A<j<s<
<!=(=U=~=
>*?/?4?
0B1N1{1
5=5F5p5u5z5
656:6?6~6
8"9'9,9R9j9s9
:5;X;d;
;(<-<2<Y<e<
=F=K=P=v=
9M:V:l:u:
30<0f0k0p0
3*464f4k4p4
6*6Z6_6d6
6 7,7\7a7f7
8%9,9`:g:>;
="=R=W=\=7>
5P5T5X5\5`5d5h5l5p5t5x5|5
9H9M9R9
90:G:}:
;!<&<+<m<y<
0I1P1-2
2y3)454e4j4o4K5
<d<h<l<p<t<x<|<
= =$=(=,=
C0O0x3?4H4
>*>0>5>;>B>I>P>
5 5'5,5<5C5J5e5
5)686@6E6K6Z6m6s6y6
;I;O;d;z;
<,<[<f<
=-=3=A=P=]=c=x=~=
=#>5>;>K>S>Y>i>
??/?9?F?T?Z?d?
<.<3<A<F<K<Q<a<k<w<}<
=b=w=|=
>>#>)>->3>7>=>A>G>K>Q>U>b>
?'?4?d?
2>2I2[2z2
878<8A8s8
91969;9
;"<.<[<`<e<
="=O=T=Y=
4<4H4u4z4
7!8&8+8P8\8
:9;A;I;Q;o;w;
5.666E6M6
60@0b0
3Y3$4,4A4
:#;o;z;
=l=p=t=x=|=
=T>X>\>`>d>h>l>p>t>x>|>
1I2U2]2
2#3R3Z3b3
596I7z8
;h;m;r;!?
0/1d1_2
8h9l9p9t9
0(1-1?1W1l1
9P9T9X9
0@1E1J1O1
\2`2d2h2l2p2
8=<=@=
2$2(2
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
2@5D5H5L5P5T5
l9p9x9|9
: :$:,:D:T:X:h:l:p:x:
: ;@;`;|;
<(<H<h<
>0>P>p>
?8?X?t?x?
0 0,0H0T0p0
1(1H1P1T1p1x1|1
2 2P2p2
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2p2x2
7$7,747<7@7D7p;h<
=4=@=D=H=L=P=X=\=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>
8j8n8r8v8
9"9&9*9.92969:9>9B9F9J9N9R9V9Z9^9b9f9j9n9r9v9z9~9
:,:4:<:D:L:T:\:d:l:t:|:
Djjjjjj
Djjjjj
jjjjjj
Djjjjj
vscanf
f:\dd\vctools\crt_bld\self_x86\crt\src\scanf.c
(format != NULL)
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgdel.cpp
_BLOCK_TYPE_IS_VALID(pHead->nBlockUse)
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgheap.c
_CrtCheckMemory()
_calloc_dbg_impl
(_HEAP_MAXREQ / nNum) >= nSize
_pFirstBlock == pOldBlock
_pLastBlock == pOldBlock
fRealloc || (!fRealloc && pNewBlock == pOldBlock)
pOldBlock->nLine == IGNORE_LINE && pOldBlock->lRequest == IGNORE_REQ
_CrtIsValidHeapPointer(pUserData)
_recalloc_dbg
(_HEAP_MAXREQ / count) >= size
pUserData != NULL
_pFirstBlock == pHead
_pLastBlock == pHead
pHead->nBlockUse == nBlockUse
pHead->nLine == IGNORE_LINE && pHead->lRequest == IGNORE_REQ
_msize_dbg
_CrtSetDbgFlag
(fNewBits==_CRTDBG_REPORT_FLAG) || ((fNewBits & 0x0ffff & ~(_CRTDBG_ALLOC_MEM_DF | _CRTDBG_DELAY_FREE_MEM_DF | _CRTDBG_CHECK_ALWAYS_DF | _CRTDBG_CHECK_CRT_DF | _CRTDBG_LEAK_CHECK_DF) ) == 0)
_CrtMemCheckpoint
state != NULL
(*_errno())
_printMemBlockData
(_osfile(fh) & FOPEN)
_get_osfhandle
f:\dd\vctools\crt_bld\self_x86\crt\src\osfinfo.c
(fh >= 0 && (unsigned)fh < (unsigned)_nhandle)
("Invalid file descriptor. File possibly closed by a different thread",0)
_write
f:\dd\vctools\crt_bld\self_x86\crt\src\write.c
isleadbyte(_dbcsBuffer(fh))
((cnt & 1) == 0)
_write_nolock
(buf != NULL)
(L"Buffer is too small" && 0)
Buffer is too small
(((_Src))) != NULL
strcpy_s
f:\dd\vctools\crt_bld\self_x86\crt\src\tcscpy_s.inl
((_Dst)) != NULL && ((_SizeInBytes)) > 0
ibase == 0 || (2 <= ibase && ibase <= 36)
strtoxl
f:\dd\vctools\crt_bld\self_x86\crt\src\strtol.c
nptr != NULL
strtoxq
f:\dd\vctools\crt_bld\self_x86\crt\src\strtoq.c
Assertion Failed
Warning
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgrpt.c
Microsoft Visual C++ Debug Library
_CrtDbgReport: String too long or IO Error
wcscpy_s(szOutMessage, 4096, L"_CrtDbgReport: String too long or IO Error")
Debug %s!
Program: %s%s%s%s%s%s%s%s%s%s%s%s
(Press Retry to debug the application)
Module:
File:
Line:
Expression:
For information on how your program can cause an assertion
failure, see the Visual C++ documentation on asserts.
memcpy_s(szShortProgName, sizeof(TCHAR) * (260 - (szShortProgName - szExeName)), dotdotdot, sizeof(TCHAR) * 3)
<program name unknown>
wcscpy_s(szExeName, 260, L"<program name unknown>")
__crtMessageWindowW
( (_Stream->_flag & _IOSTRG) || ( fn = _fileno(_Stream), ( (_textmode_safe(fn) == __IOINFO_TM_ANSI) && !_tm_unicode_safe(fn))))
(stream != NULL)
f:\dd\vctools\crt_bld\self_x86\crt\src\input.c
nFloatStrUsed<=(*pnFloatStrSz)
("Invalid Input Format",0)
_input_s_l
f:\dd\vctools\crt_bld\self_x86\crt\prebuild\eh\typname.cpp
pNode->next != NULL
mscoree.dll
wcscpy_s(*env, cchars, p)
_wsetenvp
f:\dd\vctools\crt_bld\self_x86\crt\src\stdenvp.c
KERNEL32.DLL
strcat_s(outmsg, (sizeof(outmsg) / sizeof(outmsg[0])), rterrs[tblindx].rterrtxt)
strcat_s(outmsg, (sizeof(outmsg) / sizeof(outmsg[0])), "\n\n")
strncpy_s(pch, progname_size - (pch - progname), "...", 3)
strcpy_s(progname, progname_size, "<program name unknown>")
strcpy_s(outmsg, (sizeof(outmsg) / sizeof(outmsg[0])), "Runtime Error!\n\nProgram: ")
_NMSG_WRITE
f:\dd\vctools\crt_bld\self_x86\crt\src\crt0msg.c
strcpy_s(szOutMessage, 4096, "_CrtDbgReport: String too long or IO Error")
strcpy_s(szExeName, 260, "<program name unknown>")
__crtMessageWindowA
_expand_base
f:\dd\vctools\crt_bld\self_x86\crt\src\expand.c
pBlock != NULL
kernel32.dll
f:\dd\vctools\crt_bld\self_x86\crt\src\setlocal.c
((ptloci->lc_category[category].wlocale != NULL) && (ptloci->lc_category[category].wrefcount != NULL)) || ((ptloci->lc_category[category].wlocale == NULL) && (ptloci->lc_category[category].wrefcount == NULL))
f:\dd\vctools\crt_bld\self_x86\crt\src\isctype.c
(unsigned)(c + 1) <= 256
(str != NULL)
f:\dd\vctools\crt_bld\self_x86\crt\src\mbtowc.c
_loc_update.GetLocaleT()->locinfo->mb_cur_max == 1 || _loc_update.GetLocaleT()->locinfo->mb_cur_max == 2
_isatty
f:\dd\vctools\crt_bld\self_x86\crt\src\isatty.c
_lseeki64
f:\dd\vctools\crt_bld\self_x86\crt\src\lseeki64.c
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgrptt.c
_CrtDbgReport: String too long or Invalid characters in String
wcscpy_s(szOutMessage2, 4096, L"_CrtDbgReport: String too long or Invalid characters in String")
e = mbstowcs_s(&ret, szOutMessage2, 4096, szOutMessage, ((size_t)-1))
strcpy_s(szOutMessage, 4096, szLineMessage)
strcat_s(szLineMessage, 4096, "\n")
strcat_s(szLineMessage, 4096, "\r")
strcat_s(szLineMessage, 4096, szUserMessage)
strcpy_s(szLineMessage, 4096, szFormat ? "Assertion failed: " : "Assertion failed!")
strcpy_s(szUserMessage, 4096, "_CrtDbgReport: String too long or IO Error")
_itoa_s(nLine, szLineMessage, 4096, 10)
_VCrtDbgReportA
wcstombs_s(&ret, szaOutMessage, 4096, szOutMessage, ((size_t)-1))
strcpy_s(szOutMessage2, 4096, "_CrtDbgReport: String too long or Invalid characters in String")
wcstombs_s(((void *)0), szOutMessage2, 4096, szOutMessage, ((size_t)-1))
wcscpy_s(szOutMessage, 4096, szLineMessage)
%s(%d) : %s
wcscat_s(szLineMessage, 4096, L"\n")
wcscat_s(szLineMessage, 4096, L"\r")
wcscat_s(szLineMessage, 4096, szUserMessage)
wcscpy_s(szLineMessage, 4096, szFormat ? L"Assertion failed: " : L"Assertion failed!")
Assertion failed!
Assertion failed:
wcscpy_s(szUserMessage, 4096, L"_CrtDbgReport: String too long or IO Error")
, Line
<file unknown>
Second Chance Assertion Failed: File
_itow_s(nLine, szLineMessage, 4096, 10)
_VCrtDbgReportW
f:\dd\vctools\crt_bld\self_x86\crt\src\winsig.c
("Invalid signal or error", 0)
WUSER32.DLL
sizeInBytes >= count
src != NULL
memcpy_s
f:\dd\vctools\crt_bld\self_x86\crt\src\memcpy_s.c
dst != NULL
wcscpy_s
((_Dst)) != NULL && ((_SizeInWords)) > 0
_fileno
f:\dd\vctools\crt_bld\self_x86\crt\src\fileno.c
_filbuf
f:\dd\vctools\crt_bld\self_x86\crt\src\_filbuf.c
str != NULL
_ungetc_nolock
f:\dd\vctools\crt_bld\self_x86\crt\src\ungetc_nolock.inl
D_set_error_mode
f:\dd\vctools\crt_bld\self_x86\crt\src\errmode.c
("Invalid error_mode", 0)
(L"String is not null terminated" && 0)
String is not null terminated
strcat_s
f:\dd\vctools\crt_bld\self_x86\crt\src\tcscat_s.inl
strncpy_s
f:\dd\vctools\crt_bld\self_x86\crt\src\tcsncpy_s.inl
f:\dd\vctools\crt_bld\self_x86\crt\src\malloc.h
("Corrupted pointer passed to _freea", 0)
((((( H
h(((( H
H
("inconsistent IOB fields", stream->_ptr - stream->_base >= 0)
f:\dd\vctools\crt_bld\self_x86\crt\src\_flsbuf.c
(null)
("'n' format specifier disabled", 0)
(ch != _T('\0'))
f:\dd\vctools\crt_bld\self_x86\crt\src\output.c
f:\dd\vctools\crt_bld\self_x86\crt\src\vsprintf.c
(count == 0) || (string != NULL)
_vsnprintf_helper
("Buffer too small", 0)
string != NULL && sizeInBytes > 0
_vsprintf_s_l
format != NULL
_vsnprintf_s_l
@fclose
f:\dd\vctools\crt_bld\self_x86\crt\src\fclose.c
_fclose_nolock
(_osfile(filedes) & FOPEN)
_commit
f:\dd\vctools\crt_bld\self_x86\crt\src\commit.c
(filedes >= 0 && (unsigned)filedes < (unsigned)_nhandle)
_mbstowcs_l_helper
f:\dd\vctools\crt_bld\self_x86\crt\src\mbstowcs.c
s != NULL
retsize <= sizeInWords
bufferSize <= INT_MAX
_mbstowcs_s_l
(pwcs == NULL && sizeInWords == 0) || (pwcs != NULL && sizeInWords > 0)
length < sizeInTChars
2 <= radix && radix <= 36
sizeInTChars > (size_t)(is_neg ? 2 : 1)
sizeInTChars > 0
xtoa_s
f:\dd\vctools\crt_bld\self_x86\crt\src\xtoa.c
buf != NULL
_wcstombs_l_helper
f:\dd\vctools\crt_bld\self_x86\crt\src\wcstombs.c
pwcs != NULL
sizeInBytes > retsize
_wcstombs_s_l
(dst != NULL && sizeInBytes > 0) || (dst == NULL && sizeInBytes == 0)
wcscat_s
_vswprintf_helper
f:\dd\vctools\crt_bld\self_x86\crt\src\vswprint.c
string != NULL && sizeInWords > 0
_vsnwprintf_s_l
xtow_s
(cnt <= INT_MAX)
f:\dd\vctools\crt_bld\self_x86\crt\src\read.c
(inputbuf != NULL)
_read_nolock
f:\dd\vctools\crt_bld\self_x86\crt\src\_getbuf.c
sizeInBytes > 0
_wctomb_s_l
f:\dd\vctools\crt_bld\self_x86\crt\src\wctomb.c
sizeInBytes <= INT_MAX
((state == ST_NORMAL) || (state == ST_TYPE))
("Incorrect format specifier", 0)
_output_s_l
E_close
f:\dd\vctools\crt_bld\self_x86\crt\src\close.c
f:\dd\vctools\crt_bld\self_x86\crt\src\_freebuf.c
stream != NULL
_woutput_s_l
xinifojisanuzujo
tafufaculuzazopavamagixezipazixo cejavelenotuwazifegazamocagiyam
bilaxolehu ligotexanozibugojeropohaz zus
luzogohacagu
kocimayelawunomidisu rajoxuhahowutugoju bivecayofehilanerofevusuxuludol vakawasavihunadawenedubehaj hexamakesepaxojagemuwuzefipog
kernel32.dll
vakagijuhicimayefiwu sejotijeleyumuh xevafeceduzediweluhejun bipawusigabekabayuwidejuz wayijopidete
hbizowe vudiwaveredunemeza pusav gezise
siyelubok devozacokoguxurax
Bid der rijef tikaw
kixidonehuwuvus winute wodavihefociyofejaki ponoruneyugekifepefotahitigot
ekucitobedosapuvufiyaguzaco jodig loligetokixotayin
soxijokuvutopasayiyikanuwon caditibotukidihisu
torabudutufitivaki
gukabeb tezis nefafomezijonixaw zetanewaxicobuciwakezobujaloyida catuyigaziheroxedanitavilogowe
ziwosanolotaxefujedugirapehif vezenuw ven xadinoxajolayezuvuyipuf
_controlfp_s(((void *)0), 0x00010000, 0x00030000)
_setdefaultprecision
f:\dd\vctools\crt_bld\self_x86\crt\src\intel\fp8.c
_cftoe_l
f:\dd\vctools\crt_bld\self_x86\crt\prebuild\conv\cvt.c
strcpy_s(p, (sizeInBytes == (size_t)-1 ? sizeInBytes : sizeInBytes - (p - buf)), "e+000")
sizeInBytes > (size_t)(3 + (ndec > 0 ? ndec : 0) + 5 + 1)
_cftoe2_l
sizeInBytes > (size_t)(1 + 4 + ndec + 6)
_cftoa_l
_cftof_l
_cftof2_l
_cftog_l
_controlfp_s
f:\dd\vctools\crt_bld\self_x86\crt\prebuild\tran\contrlfp.c
("Invalid input value", 0)
pflt != NULL
sizeInBytes > (size_t)((digits > 0 ? digits : 0) + 1)
_fptostr
f:\dd\vctools\crt_bld\self_x86\crt\src\_fptostr.c
strcpy_s(resultstr, resultsize, autofos.man)
_fltout2
f:\dd\vctools\crt_bld\self_x86\crt\prebuild\conv\cfout.c
__strgtold12_l
f:\dd\vctools\crt_bld\self_x86\crt\prebuild\include\strgtold12.inl
_Locale != NULL
strcpy_s(fos->man, 21+1, "1#QNAN")
strcpy_s(fos->man, 21+1, "1#INF")
strcpy_s(fos->man, 21+1, "1#IND")
strcpy_s(fos->man, 21+1, "1#SNAN")
$I10_OUTPUT
f:\dd\vctools\crt_bld\self_x86\crt\prebuild\conv\x10fout.c
VS_VERSION_INFO
041905E7
ProductVers
19.41.77.35
VarFileInfo
Translations
Antivirus Signature
Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Clean
FireEye Generic.mg.33b25300e8911b7d
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.51fdfe
BitDefenderTheta Gen:NN.ZexaF.34738.yuW@ayhxyrTc
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Avast Clean
ClamAV Clean
Kaspersky VHO:Backdoor.Win32.Mokes.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
Ad-Aware Clean
Sophos ML/PE-A + Troj/Kryptik-TR
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.fc
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Suspicious PE
GData Clean
Jiangmin Trojan.PSW.Racealer.cln
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Trojan.Win32.Packed.lu!heur
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Azorult!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
McAfee Packed-GDT!33B25300E891
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Trojan.Win32.Ranumbot
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
Paloalto Clean
CrowdStrike win/malicious_confidence_100% (D)
Qihoo-360 Clean
No IRMA results available.