Static | ZeroBOX

PE Compile Time

2020-05-01 05:27:11

PDB Path

C:\tiyetuw54\deru\4.pdb

PE Imphash

df9f8478a5324ab8dd6d2dd50515fa50

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00028570 0x00028600 6.33928792352
.rdata 0x0002a000 0x0000b3a6 0x0000b400 5.33638051136
.data 0x00036000 0x000290c8 0x00011600 7.73396671734
.rsrc 0x00060000 0x00006320 0x00006400 4.94182227767
.reloc 0x00067000 0x00003d46 0x00003e00 4.25475887915

Resources

Name Offset Size Language Sub-language File type
AFX_DIALOG_LAYOUT 0x00062b38 0x00000002 LANG_DUTCH SUBLANG_DUTCH_BELGIAN data
RT_CURSOR 0x00064e28 0x000008a8 LANG_DUTCH SUBLANG_DUTCH_BELGIAN dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x00064e28 0x000008a8 LANG_DUTCH SUBLANG_DUTCH_BELGIAN dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x00064e28 0x000008a8 LANG_DUTCH SUBLANG_DUTCH_BELGIAN dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x00064e28 0x000008a8 LANG_DUTCH SUBLANG_DUTCH_BELGIAN dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x00064e28 0x000008a8 LANG_DUTCH SUBLANG_DUTCH_BELGIAN dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x00064e28 0x000008a8 LANG_DUTCH SUBLANG_DUTCH_BELGIAN dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_ICON 0x00060460 0x000025a8 None SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40
RT_STRING 0x000660a8 0x00000276 LANG_DUTCH SUBLANG_DUTCH_BELGIAN data
RT_STRING 0x000660a8 0x00000276 LANG_DUTCH SUBLANG_DUTCH_BELGIAN data
RT_STRING 0x000660a8 0x00000276 LANG_DUTCH SUBLANG_DUTCH_BELGIAN data
RT_ACCELERATOR 0x00062a20 0x00000078 LANG_DUTCH SUBLANG_DUTCH_BELGIAN data
RT_ACCELERATOR 0x00062a20 0x00000078 LANG_DUTCH SUBLANG_DUTCH_BELGIAN data
RT_GROUP_CURSOR 0x000656d0 0x00000022 LANG_DUTCH SUBLANG_DUTCH_BELGIAN data
RT_GROUP_CURSOR 0x000656d0 0x00000022 LANG_DUTCH SUBLANG_DUTCH_BELGIAN data
RT_GROUP_CURSOR 0x000656d0 0x00000022 LANG_DUTCH SUBLANG_DUTCH_BELGIAN data
RT_GROUP_ICON 0x00062a08 0x00000014 None SUBLANG_DEFAULT data
RT_VERSION 0x000656f8 0x00000108 LANG_DUTCH SUBLANG_DUTCH_BELGIAN PDP-11 pure executable not stripped

Imports

Library KERNEL32.dll:
0x42a000 GetFileSize
0x42a004 GlobalDeleteAtom
0x42a008 SetFilePointer
0x42a00c lstrlenA
0x42a010 CopyFileExW
0x42a014 SetLocalTime
0x42a018 CommConfigDialogA
0x42a020 FreeLibrary
0x42a028 GetCommState
0x42a030 ZombifyActCtx
0x42a03c GlobalLock
0x42a040 GetComputerNameW
0x42a044 CreateDirectoryExA
0x42a050 GetTickCount
0x42a054 GetCommConfig
0x42a064 WriteFile
0x42a06c TlsSetValue
0x42a070 GlobalAlloc
0x42a074 GetSystemDirectoryW
0x42a078 VirtualFreeEx
0x42a07c LoadLibraryW
0x42a080 GetConsoleMode
0x42a084 _hread
0x42a090 GlobalFlags
0x42a094 GetBinaryTypeA
0x42a098 GetAtomNameW
0x42a09c ReadFile
0x42a0a0 ExitThread
0x42a0a4 SetConsoleTitleA
0x42a0a8 VirtualUnlock
0x42a0ac DeactivateActCtx
0x42a0b4 ReleaseActCtx
0x42a0b8 GetStartupInfoA
0x42a0bc GetCPInfoExW
0x42a0c8 GetProcAddress
0x42a0cc GetProcessHeaps
0x42a0d0 GetComputerNameExW
0x42a0d4 CreateNamedPipeA
0x42a0d8 SetStdHandle
0x42a0dc SetComputerNameA
0x42a0e0 VerLanguageNameW
0x42a0e4 LoadLibraryA
0x42a0e8 Process32FirstW
0x42a0ec CreateSemaphoreW
0x42a0f0 SetCalendarInfoW
0x42a104 FindAtomA
0x42a108 Process32NextW
0x42a110 WriteProfileStringW
0x42a114 BuildCommDCBA
0x42a118 VirtualProtect
0x42a11c CompareStringA
0x42a124 _lopen
0x42a128 TlsAlloc
0x42a130 GetCurrentProcessId
0x42a134 GetProfileSectionW
0x42a138 LCMapStringW
0x42a13c DeleteFileA
0x42a140 GetLastError
0x42a144 WideCharToMultiByte
0x42a148 GetCommandLineA
0x42a14c HeapValidate
0x42a150 IsBadReadPtr
0x42a154 RaiseException
0x42a158 TerminateProcess
0x42a15c GetCurrentProcess
0x42a168 IsDebuggerPresent
0x42a16c GetModuleFileNameW
0x42a170 GetACP
0x42a174 GetOEMCP
0x42a178 GetCPInfo
0x42a17c IsValidCodePage
0x42a180 TlsGetValue
0x42a184 GetModuleHandleW
0x42a188 GetCurrentThreadId
0x42a18c TlsFree
0x42a190 SetLastError
0x42a1a8 Sleep
0x42a1ac ExitProcess
0x42a1b0 GetModuleFileNameA
0x42a1c0 SetHandleCount
0x42a1c4 GetStdHandle
0x42a1c8 GetFileType
0x42a1cc HeapDestroy
0x42a1d0 HeapCreate
0x42a1d4 HeapFree
0x42a1d8 VirtualFree
0x42a1dc HeapAlloc
0x42a1e0 HeapSize
0x42a1e4 HeapReAlloc
0x42a1e8 VirtualAlloc
0x42a1ec DebugBreak
0x42a1f0 OutputDebugStringA
0x42a1f4 WriteConsoleW
0x42a1f8 OutputDebugStringW
0x42a1fc RtlUnwind
0x42a200 MultiByteToWideChar
0x42a204 LCMapStringA
0x42a208 GetStringTypeA
0x42a20c GetStringTypeW
0x42a210 GetLocaleInfoA
0x42a214 GetConsoleCP
0x42a21c FlushFileBuffers
0x42a220 WriteConsoleA
0x42a224 GetConsoleOutputCP
0x42a228 CloseHandle
0x42a22c CreateFileA
0x42a230 GetModuleHandleA
Library USER32.dll:
0x42a238 GetMenuInfo
0x42a23c GetListBoxInfo

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
PPPPPPPP
PPPPPPPP
URPQQh
}'h4nC
;t$,v-
UQPXY]Y[
j7hP7C
j7hP7C
j8hP7C
j8hP7C
j=hP7C
j=hP7C
j>hP7C
j>hP7C
j.h(8C
bad allocation
Unknown exception
f:\dd\vctools\crt_bld\self_x86\crt\src\onexit.c
Client
Ignore
Normal
Error: memory allocation: bad memory block type.
Invalid allocation size: %Iu bytes.
Client hook allocation failure.
Client hook allocation failure at file %hs line %d.
Error: possible heap corruption at or near 0x%p
The Block at 0x%p was allocated by aligned routines, use _aligned_realloc()
Error: memory allocation: bad memory block type.
Memory allocated at %hs(%d).
Invalid allocation size: %Iu bytes.
Memory allocated at %hs(%d).
Client hook re-allocation failure.
Client hook re-allocation failure at file %hs line %d.
HEAP CORRUPTION DETECTED: after %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory after end of heap buffer.
HEAP CORRUPTION DETECTED: after %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory after end of heap buffer.
Memory allocated at %hs(%d).
HEAP CORRUPTION DETECTED: before %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory before start of heap buffer.
HEAP CORRUPTION DETECTED: before %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory before start of heap buffer.
Memory allocated at %hs(%d).
Client hook free failure.
The Block at 0x%p was allocated by aligned routines, use _aligned_free()
%hs located at 0x%p is %Iu bytes long.
%hs located at 0x%p is %Iu bytes long.
Memory allocated at %hs(%d).
HEAP CORRUPTION DETECTED: on top of Free block at 0x%p.
CRT detected that the application wrote to a heap buffer that was freed.
HEAP CORRUPTION DETECTED: on top of Free block at 0x%p.
CRT detected that the application wrote to a heap buffer that was freed.
Memory allocated at %hs(%d).
DAMAGED
_heapchk fails with unknown return value!
_heapchk fails with _HEAPBADPTR.
_heapchk fails with _HEAPBADEND.
_heapchk fails with _HEAPBADNODE.
_heapchk fails with _HEAPBADBEGIN.
Bad memory block found at 0x%p.
Bad memory block found at 0x%p.
Memory allocated at %hs(%d).
Object dump complete.
crt block at 0x%p, subtype %x, %Iu bytes long.
normal block at 0x%p, %Iu bytes long.
client block at 0x%p, subtype %x, %Iu bytes long.
{%ld}
%hs(%d) :
#File Error#(%d) :
Dumping objects ->
Data: <%s> %s
Detected memory leaks!
f:\dd\vctools\crt_bld\self_x86\crt\src\mbctype.c
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
EncodePointer
DecodePointer
f:\dd\vctools\crt_bld\self_x86\crt\src\tidtable.c
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
f:\dd\vctools\crt_bld\self_x86\crt\src\_file.c
f:\dd\vctools\crt_bld\self_x86\crt\src\input.c
f:\dd\vctools\crt_bld\self_x86\crt\src\output.c
f:\dd\vctools\crt_bld\self_x86\crt\src\_sftbuf.c
(null)
`h````
xpxxxx
f:\dd\vctools\crt_bld\self_x86\crt\src\mlock.c
CorExitProcess
f:\dd\vctools\crt_bld\self_x86\crt\src\stdenvp.c
f:\dd\vctools\crt_bld\self_x86\crt\src\stdargv.c
f:\dd\vctools\crt_bld\self_x86\crt\src\a_env.c
f:\dd\vctools\crt_bld\self_x86\crt\src\ioinit.c
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library without using a manifest.
This is an unsupported way to load Visual C++ DLLs. You need to modify your application to build with a manifest.
For more information, see the "Visual C++ Libraries as Shared Side-by-Side Assemblies" topic in the product documentation.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
Assertion Failed
Warning
Microsoft Visual C++ Debug Library
_CrtDbgReport: String too long or IO Error
Debug %s!
Program: %s%s%s%s%s%s%s%s%s%s%s%s
(Press Retry to debug the application)
Module:
File:
Line:
Expression:
For information on how your program can cause an assertion
failure, see the Visual C++ documentation on asserts.
HeapQueryInformation
%s(%d) : %s
Assertion failed!
Assertion failed:
, Line
<file unknown>
Second Chance Assertion Failed: File
_CrtDbgReport: String too long or Invalid characters in String
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
f:\dd\vctools\crt_bld\self_x86\crt\src\_getbuf.c
`h`hhh
xppwpp
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetUserObjectInformationA
MessageBoxA
USER32.DLL
bad exception
f:\dd\vctools\crt_bld\self_x86\crt\src\convrtcp.c
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
f:\dd\vctools\crt_bld\self_x86\crt\src\read.c
Unknown Runtime Check Error
Stack memory around _alloca was corrupted
A local variable was used before it was initialized
Stack memory was corrupted
A cast to a smaller data type has caused a loss of data. If this was intentional, you should mask the source of the cast with the appropriate bitmask. For example:
char c = (i & 0xFF);
Changing the code in this way will not affect the quality of the resulting optimized code.
The value of ESP was not properly saved across a function call. This is usually a result of calling a function declared with one calling convention with a function pointer declared with a different calling convention.
Stack around the variable '
' was corrupted.
The variable '
' is being used without being initialized.
CONOUT$
MSPDB80.DLL
Stack around _alloca corrupted
Local variable used before initialization
Stack memory corruption
Cast to smaller type causing loss of data
Stack pointer corruption
bad allocation
tizasazizopocac dozikuniyifehewebabasagomugaded bihodifesezohirinoheveb fafeyocozujogozigebesodo
pabiriyotuwa
bibenifososexilopumiwubihevecig num ledomacumubofonajil yayazelocire
tarebikidaguxetu
mohaxikabisimedafabonar xilopuhunutemijowicidotofexocow colifitijebokagicezeyifoke gawevuvomevugirenoye
leracusopevuted
lawunopipoyenikaxiju jenamofatu gohiroge
wubizumuzafevisokiwe
doharozawucaxozosezewah demibuliyu welukixowene
cupazaxetutatosusisevoxiji
veralolikemekekewegege
sukowa
lunejevorudokifodozihurucolezac
hutakeremohaduxatefedudegiyizixo
luzogudawulapadobevotuw
Fok perecozatinemefecewikagi yaxoyazigimifisikohitiwetey riyix remepo
banerik mifineyomus duramabisedeweretipoc
GAIsProcessorFeaturePresent
KERNEL32
?ZEM-'^
?{yK+;
?765@Z
?e')lW
UUUUUU
?333333
?333333
?UUUUUU
?$rxxx
1#QNAN
1#SNAN
_nextafter
_hypot
C:\tiyetuw54\deru\4.pdb
GetFileSize
GlobalDeleteAtom
SetFilePointer
lstrlenA
CopyFileExW
SetLocalTime
CommConfigDialogA
MapUserPhysicalPages
FreeLibrary
InterlockedIncrement
GetCommState
InterlockedDecrement
ZombifyActCtx
SetFirmwareEnvironmentVariableA
GetSystemWindowsDirectoryW
GlobalLock
GetComputerNameW
CreateDirectoryExA
FreeEnvironmentStringsA
GetProcessPriorityBoost
GetTickCount
GetCommConfig
GetConsoleAliasesLengthA
GetWindowsDirectoryA
GetConsoleAliasExesW
WriteFile
FindActCtxSectionStringA
TlsSetValue
GlobalAlloc
GetSystemDirectoryW
VirtualFreeEx
LoadLibraryW
GetConsoleMode
_hread
GetSystemWow64DirectoryW
SetSystemTimeAdjustment
GlobalFlags
GetBinaryTypeA
GetAtomNameW
ReadFile
ExitThread
SetConsoleTitleA
VirtualUnlock
DeactivateActCtx
GetNamedPipeHandleStateW
ReleaseActCtx
GetStartupInfoA
GetCPInfoExW
GetCurrentDirectoryW
ReadConsoleOutputCharacterA
GetProcAddress
GetProcessHeaps
GetComputerNameExW
CreateNamedPipeA
SetStdHandle
SetComputerNameA
VerLanguageNameW
LoadLibraryA
Process32FirstW
CreateSemaphoreW
SetCalendarInfoW
SetConsoleCtrlHandler
SetCurrentDirectoryW
WriteProfileSectionW
SetConsoleWindowInfo
FindAtomA
Process32NextW
QueryMemoryResourceNotification
WriteProfileStringW
BuildCommDCBA
VirtualProtect
CompareStringA
GetFileAttributesExW
_lopen
TlsAlloc
GetVolumeNameForVolumeMountPointW
GetCurrentProcessId
GetProfileSectionW
LCMapStringW
DeleteFileA
KERNEL32.dll
GetMenuInfo
GetListBoxInfo
USER32.dll
GetLastError
WideCharToMultiByte
GetCommandLineA
HeapValidate
IsBadReadPtr
RaiseException
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetModuleFileNameW
GetACP
GetOEMCP
GetCPInfo
IsValidCodePage
TlsGetValue
GetModuleHandleW
GetCurrentThreadId
TlsFree
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
QueryPerformanceCounter
GetSystemTimeAsFileTime
ExitProcess
GetModuleFileNameA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
GetStdHandle
GetFileType
HeapDestroy
HeapCreate
HeapFree
VirtualFree
HeapAlloc
HeapSize
HeapReAlloc
VirtualAlloc
DebugBreak
OutputDebugStringA
WriteConsoleW
OutputDebugStringW
RtlUnwind
MultiByteToWideChar
LCMapStringA
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
GetConsoleCP
InitializeCriticalSectionAndSpinCount
FlushFileBuffers
WriteConsoleA
GetConsoleOutputCP
CloseHandle
CreateFileA
GetModuleHandleA
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
qwb}fOo
.?AVexception@std@@
L@]Ex'^@g
}Hv#?-
ds9@T1{
@i1yG`
Is-{D(/
1=5rij^M:
6luK91<U
JL>>$V
'gk,V8
:J,)(`
RfwrE-g
]uh%HM
BT>0QF?
WyID^t
6.jL}
$M[e 8
"}~'O)
E>nq<oe
dR3&9j
g{CyVq1
Ra2:Gt
D(jrOn]\
/vmc-\
9_QSW5!!nep
';;'_:
d&B1}}
XpW_v2E!s
HYM^J8
IK@G6qG
;>l=Zd
>[0&2%
1",'R`
r3PWqE
Aq4UW\C
l4ne5
X}rdHWV
Y/1aTu
g6}bNG%!V
7?S5L6
qoqLp^G
g:>CEn
8@x9jb7
xwE;b_
Z[vG2&
7)`2m(
]io<iPb
9{L +3
i:,BeFvZ
%td l0
yg`Xq@
?BkR.;SW
2.nP{P
Waw?.o
`j0f x
U\P|7-
FBsig`
)+'7:Nw
ZX`fX3p
Pw*Odr
/.g)`
2$s\nG
lbi'`n|
Wc)KA|b
3hZrPF
M"CNY>
nnS}LU
#$q(G(I
)si+~k^y
0{N(My_@
uU'9u
NBM</b
|u+?4[
,mBJl>
OL*L@t h
eO>4[tl
I!IZ*,"
0$n`"A
eoa4.X
?s?{j}
F?+Rd\
^?`,6[
g"~#y%;
8(-RB!
7@Q)qJ
gD&5E.
gWK$`^
&VQ@>L
J0oA[;
y,R~T<\Uu
QH>;$~K
A?rR!%
TyB+@@
$;\O80&
te|cVP?
)7J"a)
"gaCNS
=])HX_
^-nz~mZ
Cz%t9B**(Y
K2YM%O
j;hh9g
Q;7,TfJ
\Y|O{_dV
nK/C.y
zT"O]JY
tp*xMG
S- {R4s
]Golr@
iiiiii
iiiiii
iiiiiiiiiiii
iiiiiiiiii
iiiiii
iiiiiiiii
iiiiiiiiiiiii
iiiiiiii

0C1L1v1{1
2&2r2{2
787=7B7
8J8O8T8
:2;>;k;p;u;
<>=J=w=|=
=X>]>o>
5#6\6~6
8$808F8R8[8`8i8u8~8
9$9u9z9
9#:.:7:?:H:P:V:\:d:j:p:x:
>/>I>f>k>
>"???D?e?
0#0c0q0
1"1-161>1K1T1Z1c1h1n1v1|1
2`2j2v2
384=4O4
5*5J5v5
506<6R6d6
939D9w9
:.:3:8:N:W:`:p:|:
80<0@0D0X0]0o0
1$1;1Q1W1d1
1!2(2;2B2X2]2o2
9':F:`:
>H?M?R?Y?
0 0,0@0L0g0w0
2$363A3Y3b3o3
<,<E<g?z?
6/6D6H6`6e6r6
8G8W8^8m8
9%9.979@9D9J9P9V9\9a9f9l9q9w9
:":8:[:b:
;/;C;X;m;w;
!0)0f0o0
0%1-1X1
3!4*4T4Y4^4
8-8h8y8
?!?+?[?
G0}0>1F1^1|1
3"3O3[3
9 9$9(9|9
>%?1?a?f?k?
8L>P>T>X>\>`>d>h>l>p>t>x>|>
0A0F0K0
272<2A2
33.454i5p5M6
*0/040
1 1$1(1,1014181<1@1D1H1L1
2F3N3m3w3
4%515a5f5k5
6"7.7^7c7h7
0h6l6p6t6x6|6
7 7$7(7,707
8&939@9M9e9
9$:;:}:
;B;I;[;b;x;};
>$>h>s>
?3?@?E?S?[?s?
11)171<1C1M1Q1[1j1n1t1{1
5!747q7
9:9I9^9c9h9
>*?:?[?
!0B0d0
1)1/1C1
2-2I2^2c2k2
5$5+5>5T5[5n5
7/7C7N7g7p7
7?8D8I8P8}8
9'9h9m9
<#<(<-<
="=A=[=g={=
=!>=>I>Y>e>
>1?6?;?@?g?
050>0h0m0r0
0D1K1Z1
1!2)2/2=2G2U2[2j2|2
2*3u30474
5(6h6m6
7$7C7J7Y7
8"8m8t8y8
>#>*>3><>E>V>e>q>
?+?1?9?B?Z?c?
*0\0h0
0=4H4P4w4}4
535:5`5h5)6M=]=
4585?5G5L5P5T5}5
5.64686<6@6
7+7]7d7h7l7p7t7x7|7
="='=,=\=a=f=
01D1x1
4"4(454:4@4
545@5L5Q5V5
6'7,717k7p7u7
:):.:3:
;7;<;A;
</<o<v<}<
=*>=>C>
0%0/0=0B0L0Z0_0i0}0
031>1a1l1
2!2K2P2U2
363;3@3
6G6O6(7
0J0y0"1.1
2 2*262A2K2T2
8%8D8c8
9"9'9f9n9
:D:I:N:
<D<L<Q=Z=
>>I>N>S>
>!?*?T?Y?^?
0/080b0g0l0
1H2M2_2
5&595S5s5
?,?1?6?
2&2Y2e2
5L5Q5V5
787=7O7
7"8:8C8x8}8
9":V:_:
;G;Q;v;
>E>O>z>
3U3_3z3
;&;V;[;`;
=J=O=T=
>L>Q>V>
0P1W1.2
4B4G4L4'5
;@<D<H<L<P<T<X<\<`<d<h<l<p<t<
080G0+171>1h1q1
22@2E2O2]2b2l2z2
4?4X4_4g4l4p4t4
5N5T5X5\5`5
6!6K6}6
8#8(8B9N9{9
:.:f:n:
>l?r?x?~?
00$060;0A0G0_0f092B2l2q2v2:3b3R4
8)8V8[8`8k9t9
;=;B;G;
<J<O<T<
=9=>=C=l>
2-22272v2~2
23$3)3
4A5J5t5y5~5
6=6B6G6
7#7M7R7W7
8.878a8f8k8
;';Q;V;[;.<:<g<l<q<
3z3H6M6_6
45$5)5
7)727\7a7f7
878A8z8
9(:-:?:
;*;3;h;m;r;
=$=\=a=f=
>%>]>b>g>
1!2E2k2
4f5p5z5
849T9r9]:g:q:
<1<U<a<
<'=J=V=
>>$>G>h>m>
>4???w?
0 0;0B0K0b0i0
2l3x3<4M4z4@5J5
7H8M8_8
929J9S9
7#7*727:7A7J7Q7Z7k7q7x7
8,838:8D8P8a8q;
;-<:<D<J<\<f<p<
=(=.=M=i=~=
>1>P>Z>b>
??-?3?g?
0&0.0=0Y0n0t0z0
11%1-131F1K1Q1h1w1
1=4I4O4d4
5,6?6}6
7L7Z7l7r7x7
818=8J8|8
8 9W9[9a9e9k9o9u9y9
;;$;Z;c;
?=?B?G?l?x?
11L1Q1V1
575C5p5u5z5
><>A>F>x>
0)1.131
344A4m4u4
6"7*727g7
<==F=p=u=z=
0=0B0G0l0u0
1!1J1S1}1
3i647<7Q7
<=*={=
0d1h1l1p1t1x1|1
2034383<3@3D3H3L3
1:1?1D1
3b4i4W5^5$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:
:9;C;g;
01262;2@2
2,31363;3
P2T2X2\2`2d2x2|2
h0l0p0t0x0|0
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
T1X1\1`1d1
<D=H=X=\=l=p=x=
?8?X?x?
080@0L0
1(141h1
2(2H2h2
383D3\3`3
444<4D4H4P4d4
5 5D5P5X5
6(606D6\6`6
6@7P7`7p7
<$<,<4<<<D<L<T<\<d<l<t<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
0$0,040<0D0L0T0\0d0l0
jjjjjjj
Bjjjjjjj
("Buffer too small", 0)
sizeInBytes > 0
_wctomb_s_l
f:\dd\vctools\crt_bld\self_x86\crt\src\wctomb.c
sizeInBytes <= INT_MAX
vscanf
f:\dd\vctools\crt_bld\self_x86\crt\src\scanf.c
(format != NULL)
(count == 0) || (string != NULL)
_vswprintf_helper
f:\dd\vctools\crt_bld\self_x86\crt\src\vswprint.c
string != NULL && sizeInWords > 0
format != NULL
_vsnwprintf_s_l
printf
f:\dd\vctools\crt_bld\self_x86\crt\src\printf.c
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgdel.cpp
_BLOCK_TYPE_IS_VALID(pHead->nBlockUse)
f:\dd\vctools\crt_bld\self_x86\crt\src\feoferr.c
(stream != NULL)
ferror
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgheap.c
_CrtCheckMemory()
_calloc_dbg_impl
(_HEAP_MAXREQ / nNum) >= nSize
_pFirstBlock == pOldBlock
_pLastBlock == pOldBlock
fRealloc || (!fRealloc && pNewBlock == pOldBlock)
pOldBlock->nLine == IGNORE_LINE && pOldBlock->lRequest == IGNORE_REQ
_CrtIsValidHeapPointer(pUserData)
_recalloc_dbg
(_HEAP_MAXREQ / count) >= size
pUserData != NULL
_pFirstBlock == pHead
_pLastBlock == pHead
pHead->nBlockUse == nBlockUse
pHead->nLine == IGNORE_LINE && pHead->lRequest == IGNORE_REQ
_msize_dbg
_CrtSetDbgFlag
(fNewBits==_CRTDBG_REPORT_FLAG) || ((fNewBits & 0x0ffff & ~(_CRTDBG_ALLOC_MEM_DF | _CRTDBG_DELAY_FREE_MEM_DF | _CRTDBG_CHECK_ALWAYS_DF | _CRTDBG_CHECK_CRT_DF | _CRTDBG_LEAK_CHECK_DF) ) == 0)
_CrtMemCheckpoint
state != NULL
(*_errno())
_printMemBlockData
Assertion Failed
Warning
Bf:\dd\vctools\crt_bld\self_x86\crt\src\dbgrpt.c
Microsoft Visual C++ Debug Library
_CrtDbgReport: String too long or IO Error
wcscpy_s(szOutMessage, 4096, L"_CrtDbgReport: String too long or IO Error")
Debug %s!
Program: %s%s%s%s%s%s%s%s%s%s%s%s
(Press Retry to debug the application)
Module:
File:
Line:
Expression:
For information on how your program can cause an assertion
failure, see the Visual C++ documentation on asserts.
memcpy_s(szShortProgName, sizeof(TCHAR) * (260 - (szShortProgName - szExeName)), dotdotdot, sizeof(TCHAR) * 3)
<program name unknown>
wcscpy_s(szExeName, 260, L"<program name unknown>")
__crtMessageWindowW
f:\dd\vctools\crt_bld\self_x86\crt\src\setlocal.c
((ptloci->lc_category[category].wlocale != NULL) && (ptloci->lc_category[category].wrefcount != NULL)) || ((ptloci->lc_category[category].wlocale == NULL) && (ptloci->lc_category[category].wrefcount == NULL))
KERNEL32.DLL
(L"Buffer is too small" && 0)
Buffer is too small
(((_Src))) != NULL
strcpy_s
f:\dd\vctools\crt_bld\self_x86\crt\src\tcscpy_s.inl
((_Dst)) != NULL && ((_SizeInBytes)) > 0
ibase == 0 || (2 <= ibase && ibase <= 36)
strtoxl
f:\dd\vctools\crt_bld\self_x86\crt\src\strtol.c
nptr != NULL
strtoxq
f:\dd\vctools\crt_bld\self_x86\crt\src\strtoq.c
( (_Stream->_flag & _IOSTRG) || ( fn = _fileno(_Stream), ( (_textmode_safe(fn) == __IOINFO_TM_ANSI) && !_tm_unicode_safe(fn))))
_input_l
f:\dd\vctools\crt_bld\self_x86\crt\src\input.c
nFloatStrUsed<=(*pnFloatStrSz)
("inconsistent IOB fields", stream->_ptr - stream->_base >= 0)
f:\dd\vctools\crt_bld\self_x86\crt\src\_flsbuf.c
str != NULL
("'n' format specifier disabled", 0)
_woutput_l
f:\dd\vctools\crt_bld\self_x86\crt\src\output.c
((state == ST_NORMAL) || (state == ST_TYPE))
("Incorrect format specifier", 0)
_woutput_s_l
f:\dd\vctools\crt_bld\self_x86\crt\src\_sftbuf.c
flag == 0 || flag == 1
(null)
(ch != _T('\0'))
_output_l
f:\dd\vctools\crt_bld\self_x86\crt\prebuild\eh\typname.cpp
pNode->next != NULL
mscoree.dll
strcpy_s(*env, cchars, p)
_setenvp
f:\dd\vctools\crt_bld\self_x86\crt\src\stdenvp.c
strcat_s(outmsg, (sizeof(outmsg) / sizeof(outmsg[0])), rterrs[tblindx].rterrtxt)
strcat_s(outmsg, (sizeof(outmsg) / sizeof(outmsg[0])), "\n\n")
strncpy_s(pch, progname_size - (pch - progname), "...", 3)
strcpy_s(progname, progname_size, "<program name unknown>")
strcpy_s(outmsg, (sizeof(outmsg) / sizeof(outmsg[0])), "Runtime Error!\n\nProgram: ")
_NMSG_WRITE
f:\dd\vctools\crt_bld\self_x86\crt\src\crt0msg.c
strcpy_s(szOutMessage, 4096, "_CrtDbgReport: String too long or IO Error")
strcpy_s(szExeName, 260, "<program name unknown>")
__crtMessageWindowA
_expand_base
f:\dd\vctools\crt_bld\self_x86\crt\src\expand.c
pBlock != NULL
kernel32.dll
f:\dd\vctools\crt_bld\self_x86\crt\src\isctype.c
(unsigned)(c + 1) <= 256
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgrptt.c
_CrtDbgReport: String too long or Invalid characters in String
wcscpy_s(szOutMessage2, 4096, L"_CrtDbgReport: String too long or Invalid characters in String")
e = mbstowcs_s(&ret, szOutMessage2, 4096, szOutMessage, ((size_t)-1))
strcpy_s(szOutMessage, 4096, szLineMessage)
strcat_s(szLineMessage, 4096, "\n")
strcat_s(szLineMessage, 4096, "\r")
strcat_s(szLineMessage, 4096, szUserMessage)
strcpy_s(szLineMessage, 4096, szFormat ? "Assertion failed: " : "Assertion failed!")
strcpy_s(szUserMessage, 4096, "_CrtDbgReport: String too long or IO Error")
_itoa_s(nLine, szLineMessage, 4096, 10)
_VCrtDbgReportA
wcstombs_s(&ret, szaOutMessage, 4096, szOutMessage, ((size_t)-1))
strcpy_s(szOutMessage2, 4096, "_CrtDbgReport: String too long or Invalid characters in String")
wcstombs_s(((void *)0), szOutMessage2, 4096, szOutMessage, ((size_t)-1))
wcscpy_s(szOutMessage, 4096, szLineMessage)
%s(%d) : %s
wcscat_s(szLineMessage, 4096, L"\n")
wcscat_s(szLineMessage, 4096, L"\r")
wcscat_s(szLineMessage, 4096, szUserMessage)
wcscpy_s(szLineMessage, 4096, szFormat ? L"Assertion failed: " : L"Assertion failed!")
Assertion failed!
Assertion failed:
wcscpy_s(szUserMessage, 4096, L"_CrtDbgReport: String too long or IO Error")
, Line
<file unknown>
Second Chance Assertion Failed: File
_itow_s(nLine, szLineMessage, 4096, 10)
_VCrtDbgReportW
f:\dd\vctools\crt_bld\self_x86\crt\src\winsig.c
("Invalid signal or error", 0)
WUSER32.DLL
sizeInBytes >= count
src != NULL
memcpy_s
f:\dd\vctools\crt_bld\self_x86\crt\src\memcpy_s.c
dst != NULL
wcscpy_s
((_Dst)) != NULL && ((_SizeInWords)) > 0
f:\dd\vctools\crt_bld\self_x86\crt\src\malloc.h
("Corrupted pointer passed to _freea", 0)
((((( H
h(((( H
H
nstrncpy_s
f:\dd\vctools\crt_bld\self_x86\crt\src\tcsncpy_s.inl
(L"String is not null terminated" && 0)
String is not null terminated
strcat_s
f:\dd\vctools\crt_bld\self_x86\crt\src\tcscat_s.inl
f:\dd\vctools\crt_bld\self_x86\crt\src\mbtowc.c
_loc_update.GetLocaleT()->locinfo->mb_cur_max == 1 || _loc_update.GetLocaleT()->locinfo->mb_cur_max == 2
_fileno
f:\dd\vctools\crt_bld\self_x86\crt\src\fileno.c
_filbuf
f:\dd\vctools\crt_bld\self_x86\crt\src\_filbuf.c
_ungetc_nolock
f:\dd\vctools\crt_bld\self_x86\crt\src\ungetc_nolock.inl
("Invalid file descriptor. File possibly closed by a different thread",0)
(_osfile(fh) & FOPEN)
_lseeki64
f:\dd\vctools\crt_bld\self_x86\crt\src\lseeki64.c
(fh >= 0 && (unsigned)fh < (unsigned)_nhandle)
_write
f:\dd\vctools\crt_bld\self_x86\crt\src\write.c
isleadbyte(_dbcsBuffer(fh))
((cnt & 1) == 0)
_write_nolock
(buf != NULL)
f:\dd\vctools\crt_bld\self_x86\crt\src\_getbuf.c
_isatty
f:\dd\vctools\crt_bld\self_x86\crt\src\isatty.c
(str != NULL)
_output_s_l
XCPCDC8C,C C
B_set_error_mode
f:\dd\vctools\crt_bld\self_x86\crt\src\errmode.c
("Invalid error_mode", 0)
f:\dd\vctools\crt_bld\self_x86\crt\src\vsprintf.c
_vsnprintf_helper
string != NULL && sizeInBytes > 0
_vsprintf_s_l
_vsnprintf_s_l
D_mbstowcs_l_helper
f:\dd\vctools\crt_bld\self_x86\crt\src\mbstowcs.c
s != NULL
retsize <= sizeInWords
bufferSize <= INT_MAX
_mbstowcs_s_l
(pwcs == NULL && sizeInWords == 0) || (pwcs != NULL && sizeInWords > 0)
length < sizeInTChars
2 <= radix && radix <= 36
sizeInTChars > (size_t)(is_neg ? 2 : 1)
sizeInTChars > 0
xtoa_s
f:\dd\vctools\crt_bld\self_x86\crt\src\xtoa.c
buf != NULL
_wcstombs_l_helper
f:\dd\vctools\crt_bld\self_x86\crt\src\wcstombs.c
pwcs != NULL
sizeInBytes > retsize
_wcstombs_s_l
(dst != NULL && sizeInBytes > 0) || (dst == NULL && sizeInBytes == 0)
wcscat_s
xtow_s
fclose
f:\dd\vctools\crt_bld\self_x86\crt\src\fclose.c
_fclose_nolock
(_osfile(filedes) & FOPEN)
_commit
f:\dd\vctools\crt_bld\self_x86\crt\src\commit.c
(filedes >= 0 && (unsigned)filedes < (unsigned)_nhandle)
(cnt <= INT_MAX)
f:\dd\vctools\crt_bld\self_x86\crt\src\read.c
(inputbuf != NULL)
_read_nolock
_get_osfhandle
f:\dd\vctools\crt_bld\self_x86\crt\src\osfinfo.c
_close
f:\dd\vctools\crt_bld\self_x86\crt\src\close.c
f:\dd\vctools\crt_bld\self_x86\crt\src\_freebuf.c
stream != NULL
sozucuwulurotikucuxicabeyodu soyoxucebihumutuf vidasapodevigupodu hek
gekupamasusa tozidehiyuyafahepahuxocarebayay
pejiponazicirudicak
colakafi jovivekosorodirotufimipa rimipepimapokofo nudecudicococawocebamenih hefihejoho
dkernel32.dll
kulayob nazewurihexadu
pigax yutalisavahenezemaz cizulakiboxarikagarufuwub kohopisena
fuxogejuxayoyapor dizifejopupaguwomukalise punifecucabococimexivajicuxova kavicunuhewilohud
coyevurojitikafot
vunalugukimahuzin
ganikevafinuwarelegafip licozunovo yusanabekule
hijahahifujizutoyazojiwute reputocudujiyihahomuji yutebu
sarihonicuzayuhoropitusuzonu
Jus fudigohakoven vil maxawavanahapogayowipiwigawak
riyovohuyujujemukupicivajodo
dujasicoyoyahowuyapixuh
tubexahivocamofoyu
B_controlfp_s(((void *)0), 0x00010000, 0x00030000)
_setdefaultprecision
f:\dd\vctools\crt_bld\self_x86\crt\src\intel\fp8.c
_cftoe_l
f:\dd\vctools\crt_bld\self_x86\crt\prebuild\conv\cvt.c
strcpy_s(p, (sizeInBytes == (size_t)-1 ? sizeInBytes : sizeInBytes - (p - buf)), "e+000")
sizeInBytes > (size_t)(3 + (ndec > 0 ? ndec : 0) + 5 + 1)
_cftoe2_l
sizeInBytes > (size_t)(1 + 4 + ndec + 6)
_cftoa_l
_cftof_l
_cftof2_l
_cftog_l
_controlfp_s
f:\dd\vctools\crt_bld\self_x86\crt\prebuild\tran\contrlfp.c
("Invalid input value", 0)
pflt != NULL
sizeInBytes > (size_t)((digits > 0 ? digits : 0) + 1)
_fptostr
f:\dd\vctools\crt_bld\self_x86\crt\src\_fptostr.c
strcpy_s(resultstr, resultsize, autofos.man)
_fltout2
f:\dd\vctools\crt_bld\self_x86\crt\prebuild\conv\cfout.c
__strgtold12_l
f:\dd\vctools\crt_bld\self_x86\crt\prebuild\include\strgtold12.inl
_Locale != NULL
strcpy_s(fos->man, 21+1, "1#QNAN")
strcpy_s(fos->man, 21+1, "1#INF")
strcpy_s(fos->man, 21+1, "1#IND")
strcpy_s(fos->man, 21+1, "1#SNAN")
$I10_OUTPUT
f:\dd\vctools\crt_bld\self_x86\crt\prebuild\conv\x10fout.c
AFX_DIALOG_LAYOUT
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
041916E8
ProductsVersion
88.83.22.1
VarFileInfo
Translation
>Mij natafa niwoxucuvox yepir kijaxum lufe yojovekitu fobomiyig%Jed xememoke bojejaberexawu bekiluruv/Jajoniz huy tutiw xisereb geherurunokuku xoyodu?Fek yuxonekur dopubugahanuh suvuwimidiv hegazuwijiziy zoneresidPJegobuyubik girec ribuxufadiga tekezemacotayo coharemakazok yejalav momi xutufot:Fuyucuk baxasubunecezay luvoxohunazukov zuzo fagileja xibi
Resijarew
TojezaxohRudacohuyayov goseti popilamumezon muyuxe hodunokid yumakojo petiyuzuyone xapiduhibugu bimiyic ketigemev
QButeyasad niji vojuduxeguwuv lewab teceridige xahav vuta canehisapodo wumoninuhut
TasucanivKNumunahujici fehegiyumacuy rozixosagesav rewiwupubibad zolamo lirujoxipenoj7Gihiwidozi hekus vot seyaxa tula kofipuyaj jecoralazomi'Wibuz bejumusunakafex zimagewo bozawoxa\Birenedih hozipof wenejexuwekemo badalawa bax tesogusuliz bilatiwesut bicijewipili kuya laxi
/Moji minixepadotoze tizacezojigu favubimabujixaGCirubibod dufihikidogu fohuzoke redarabikoyano pohubuxibef dubibijuvoje"Waliror zuzovafemoyo rihihorefefir+Hutidoh howez tumuvamawacaret setir zem fak<Zumuha numukedohif gakula hajipivoped xojiki tadimijusitihix
Bisasoleputari yudurudiraOHofagifikace sejipapolu wepi kayes ciyuwugep vebehaxuxe fegewegan dobojomacicoz\Muvobet pukacoradusocip rihukutegupajo suyic goseguzetogurub cok safukabagutoy sig lola dudi
Sazoluyelofop dukinobekakikur
Wixosezacac cabahatewulija0Lomomu hodojomiheso yadima kicex pera ledabusume
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.66599922c76c5fba
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (D)
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:Backdoor.Win32.Mokes.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.fh
CMC Clean
Sophos ML/PE-A + Troj/Kryptik-TR
SentinelOne Static AI - Malicious PE
Jiangmin Backdoor.Mokes.eei
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Win32/Azorult.FW!MTB
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!66599922C76C
TACHYON Clean
VBA32 BScope.Trojan.Crypt
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik!1.D7E8 (CLASSIC)
Yandex Clean
Ikarus Trojan.Win32.Azorult
eGambit Unsafe.AI_Score_60%
Fortinet Clean
BitDefenderTheta Gen:NN.ZexaF.34050.tuW@aW!gkmcG
Qihoo-360 HEUR/QVM10.1.CFFC.Malware.Gen
Cybereason malicious.d18f9f
Avast Clean
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.