Static | ZeroBOX

PE Compile Time

2020-03-29 08:21:40

PDB Path

C:\hikelehusumepi25 picasivohu-5\rajohaca\lawod xiwaha\toda\jefe.pdb

PE Imphash

ad1c5bf15a899fcfef408e3485448e67

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001c330 0x0001c400 6.29056224001
.rdata 0x0001e000 0x000085f0 0x00008600 4.80074380929
.data 0x00027000 0x01f8a4dc 0x00022c00 7.90579301046
.rsrc 0x01fb2000 0x0000f4f8 0x0000f600 5.55238536822

Resources

Name Offset Size Language Sub-language File type
JOD 0x01fbfb78 0x000002fa None SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
JOPEGAJAYUSOWIDOVAPODEHIZAGODUJO 0x01fbf7a0 0x000003d8 None SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
PIZUFEWAMO 0x01fbe8b8 0x00000ee8 None SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
RT_CURSOR 0x01fc02f8 0x000010a8 None SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40
RT_CURSOR 0x01fc02f8 0x000010a8 None SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40
RT_CURSOR 0x01fc02f8 0x000010a8 None SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40
RT_CURSOR 0x01fc02f8 0x000010a8 None SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40
RT_ICON 0x01fbe3d8 0x00000468 LANG_FRENCH SUBLANG_FRENCH_SWISS GLS_BINARY_LSB_FIRST
RT_ICON 0x01fbe3d8 0x00000468 LANG_FRENCH SUBLANG_FRENCH_SWISS GLS_BINARY_LSB_FIRST
RT_ICON 0x01fbe3d8 0x00000468 LANG_FRENCH SUBLANG_FRENCH_SWISS GLS_BINARY_LSB_FIRST
RT_ICON 0x01fbe3d8 0x00000468 LANG_FRENCH SUBLANG_FRENCH_SWISS GLS_BINARY_LSB_FIRST
RT_ICON 0x01fbe3d8 0x00000468 LANG_FRENCH SUBLANG_FRENCH_SWISS GLS_BINARY_LSB_FIRST
RT_ICON 0x01fbe3d8 0x00000468 LANG_FRENCH SUBLANG_FRENCH_SWISS GLS_BINARY_LSB_FIRST
RT_ICON 0x01fbe3d8 0x00000468 LANG_FRENCH SUBLANG_FRENCH_SWISS GLS_BINARY_LSB_FIRST
RT_ICON 0x01fbe3d8 0x00000468 LANG_FRENCH SUBLANG_FRENCH_SWISS GLS_BINARY_LSB_FIRST
RT_ICON 0x01fbe3d8 0x00000468 LANG_FRENCH SUBLANG_FRENCH_SWISS GLS_BINARY_LSB_FIRST
RT_ICON 0x01fbe3d8 0x00000468 LANG_FRENCH SUBLANG_FRENCH_SWISS GLS_BINARY_LSB_FIRST
RT_ICON 0x01fbe3d8 0x00000468 LANG_FRENCH SUBLANG_FRENCH_SWISS GLS_BINARY_LSB_FIRST
RT_ICON 0x01fbe3d8 0x00000468 LANG_FRENCH SUBLANG_FRENCH_SWISS GLS_BINARY_LSB_FIRST
RT_ICON 0x01fbe3d8 0x00000468 LANG_FRENCH SUBLANG_FRENCH_SWISS GLS_BINARY_LSB_FIRST
RT_ICON 0x01fbe3d8 0x00000468 LANG_FRENCH SUBLANG_FRENCH_SWISS GLS_BINARY_LSB_FIRST
RT_ICON 0x01fbe3d8 0x00000468 LANG_FRENCH SUBLANG_FRENCH_SWISS GLS_BINARY_LSB_FIRST
RT_ACCELERATOR 0x01fbfe78 0x00000080 None SUBLANG_DEFAULT data
RT_ACCELERATOR 0x01fbfe78 0x00000080 None SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x01fc13a0 0x00000030 None SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x01fc13a0 0x00000030 None SUBLANG_DEFAULT data
RT_GROUP_ICON 0x01fb8020 0x0000005a LANG_FRENCH SUBLANG_FRENCH_SWISS data
RT_GROUP_ICON 0x01fb8020 0x0000005a LANG_FRENCH SUBLANG_FRENCH_SWISS data
RT_GROUP_ICON 0x01fb8020 0x0000005a LANG_FRENCH SUBLANG_FRENCH_SWISS data
RT_VERSION 0x01fc13d0 0x00000124 None SUBLANG_DEFAULT data

Imports

Library KERNEL32.dll:
0x41e008 SetFilePointer
0x41e00c lstrlenA
0x41e010 GetDriveTypeW
0x41e020 CompareFileTime
0x41e02c WaitForSingleObject
0x41e030 OpenSemaphoreA
0x41e038 GetTickCount
0x41e03c VirtualFree
0x41e048 WaitNamedPipeW
0x41e04c WriteFile
0x41e050 SetCommState
0x41e054 GetCommandLineA
0x41e058 TlsSetValue
0x41e05c GetPriorityClass
0x41e060 GlobalAlloc
0x41e064 GetConsoleMode
0x41e068 TerminateThread
0x41e06c CopyFileW
0x41e070 GetVersionExW
0x41e074 SetConsoleMode
0x41e07c GetBinaryTypeA
0x41e080 GetOverlappedResult
0x41e084 CompareStringW
0x41e088 SetThreadContext
0x41e08c GlobalUnlock
0x41e090 VerifyVersionInfoW
0x41e094 CreateDirectoryA
0x41e098 ReleaseActCtx
0x41e09c GetFileSizeEx
0x41e0a4 GetCPInfoExW
0x41e0a8 OpenMutexW
0x41e0ac GetLastError
0x41e0b0 IsDBCSLeadByteEx
0x41e0b8 GetProcAddress
0x41e0c0 ResetEvent
0x41e0c4 OpenWaitableTimerA
0x41e0c8 LoadLibraryA
0x41e0cc CreateSemaphoreW
0x41e0d4 HeapWalk
0x41e0d8 FindAtomA
0x41e0dc Process32NextW
0x41e0e0 WriteProfileStringA
0x41e0e4 GetModuleHandleA
0x41e0ec EnumResourceNamesA
0x41e0f4 FatalAppExitA
0x41e0f8 GetCurrentThreadId
0x41e0fc GetSystemTime
0x41e100 LCMapStringW
0x41e104 CopyFileExA
0x41e108 DeleteFileA
0x41e10c GetStartupInfoW
0x41e110 UnregisterWait
0x41e114 GetStartupInfoA
0x41e118 HeapValidate
0x41e11c IsBadReadPtr
0x41e120 RaiseException
0x41e124 GetModuleHandleW
0x41e128 Sleep
0x41e12c ExitProcess
0x41e130 TlsGetValue
0x41e134 TlsAlloc
0x41e138 TlsFree
0x41e13c SetLastError
0x41e140 TerminateProcess
0x41e144 GetCurrentProcess
0x41e150 IsDebuggerPresent
0x41e154 GetModuleFileNameW
0x41e168 GetCurrentProcessId
0x41e170 GetModuleFileNameA
0x41e17c WideCharToMultiByte
0x41e184 SetHandleCount
0x41e188 GetStdHandle
0x41e18c GetFileType
0x41e190 HeapDestroy
0x41e194 HeapCreate
0x41e198 HeapFree
0x41e19c HeapAlloc
0x41e1a0 HeapSize
0x41e1a4 HeapReAlloc
0x41e1a8 VirtualAlloc
0x41e1ac GetACP
0x41e1b0 GetOEMCP
0x41e1b4 GetCPInfo
0x41e1b8 IsValidCodePage
0x41e1c0 RtlUnwind
0x41e1c4 GetConsoleCP
0x41e1c8 DebugBreak
0x41e1cc OutputDebugStringA
0x41e1d0 WriteConsoleW
0x41e1d4 OutputDebugStringW
0x41e1d8 LoadLibraryW
0x41e1dc MultiByteToWideChar
0x41e1e0 LCMapStringA
0x41e1e4 GetStringTypeA
0x41e1e8 GetStringTypeW
0x41e1ec GetLocaleInfoA
0x41e1f0 SetStdHandle
0x41e1f4 WriteConsoleA
0x41e1f8 GetConsoleOutputCP
0x41e1fc CreateFileA
0x41e200 CloseHandle
0x41e204 FlushFileBuffers
Library GDI32.dll:
0x41e000 GetCharWidthW

!This program cannot be run in DOS mode.
`.rdata
@.data
t h GB
URPQQh
u!hd&B
jhx2B
jhx2B
j+hx2B
j>hx2B
j>hx2B
u!hH3B
PPPPPPPP
PPPPPPPP
u!h`=B
u!h`=B
;t$,v-
UQPXY]Y[
u!hPBB
jfh@DB
jfh@DB
jgh@DB
jgh@DB
jih@DB
jih@DB
jjh@DB
jjh@DB
u!hXCB
u!h`EB
jfh@DB
jfh@DB
jgh@DB
jgh@DB
jih@DB
jih@DB
jjh@DB
jjh@DB
u!hXCB
}'hP~B
j,h`IB
j,h`IB
j-h`IB
j-h`IB
jEh`IB
j/hHJB
j/hHJB
j0hHJB
j0hHJB
j:hHJB
u4h`PB
bad allocation
Unknown exception
f:\dd\vctools\crt_bld\self_x86\crt\src\onexit.c
Client
Ignore
Normal
Error: memory allocation: bad memory block type.
Invalid allocation size: %Iu bytes.
Client hook allocation failure.
Client hook allocation failure at file %hs line %d.
Error: possible heap corruption at or near 0x%p
The Block at 0x%p was allocated by aligned routines, use _aligned_realloc()
Error: memory allocation: bad memory block type.
Memory allocated at %hs(%d).
Invalid allocation size: %Iu bytes.
Memory allocated at %hs(%d).
Client hook re-allocation failure.
Client hook re-allocation failure at file %hs line %d.
HEAP CORRUPTION DETECTED: after %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory after end of heap buffer.
HEAP CORRUPTION DETECTED: after %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory after end of heap buffer.
Memory allocated at %hs(%d).
HEAP CORRUPTION DETECTED: before %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory before start of heap buffer.
HEAP CORRUPTION DETECTED: before %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory before start of heap buffer.
Memory allocated at %hs(%d).
Client hook free failure.
The Block at 0x%p was allocated by aligned routines, use _aligned_free()
%hs located at 0x%p is %Iu bytes long.
%hs located at 0x%p is %Iu bytes long.
Memory allocated at %hs(%d).
HEAP CORRUPTION DETECTED: on top of Free block at 0x%p.
CRT detected that the application wrote to a heap buffer that was freed.
HEAP CORRUPTION DETECTED: on top of Free block at 0x%p.
CRT detected that the application wrote to a heap buffer that was freed.
Memory allocated at %hs(%d).
DAMAGED
_heapchk fails with unknown return value!
_heapchk fails with _HEAPBADPTR.
_heapchk fails with _HEAPBADEND.
_heapchk fails with _HEAPBADNODE.
_heapchk fails with _HEAPBADBEGIN.
Bad memory block found at 0x%p.
Bad memory block found at 0x%p.
Memory allocated at %hs(%d).
Object dump complete.
crt block at 0x%p, subtype %x, %Iu bytes long.
normal block at 0x%p, %Iu bytes long.
client block at 0x%p, subtype %x, %Iu bytes long.
{%ld}
%hs(%d) :
#File Error#(%d) :
Dumping objects ->
Data: <%s> %s
Detected memory leaks!
CorExitProcess
EncodePointer
DecodePointer
f:\dd\vctools\crt_bld\self_x86\crt\src\tidtable.c
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
f:\dd\vctools\crt_bld\self_x86\crt\src\output.c
f:\dd\vctools\crt_bld\self_x86\crt\src\mlock.c
f:\dd\vctools\crt_bld\self_x86\crt\src\stdenvp.c
f:\dd\vctools\crt_bld\self_x86\crt\src\stdargv.c
f:\dd\vctools\crt_bld\self_x86\crt\src\a_env.c
f:\dd\vctools\crt_bld\self_x86\crt\src\ioinit.c
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library without using a manifest.
This is an unsupported way to load Visual C++ DLLs. You need to modify your application to build with a manifest.
For more information, see the "Visual C++ Libraries as Shared Side-by-Side Assemblies" topic in the product documentation.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
Assertion Failed
Warning
Microsoft Visual C++ Debug Library
_CrtDbgReport: String too long or IO Error
Debug %s!
Program: %s%s%s%s%s%s%s%s%s%s%s%s
(Press Retry to debug the application)
Module:
File:
Line:
Expression:
For information on how your program can cause an assertion
failure, see the Visual C++ documentation on asserts.
HeapQueryInformation
f:\dd\vctools\crt_bld\self_x86\crt\src\mbctype.c
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
f:\dd\vctools\crt_bld\self_x86\crt\src\_getbuf.c
f:\dd\vctools\crt_bld\self_x86\crt\src\_file.c
%s(%d) : %s
Assertion failed!
Assertion failed:
, Line
<file unknown>
Second Chance Assertion Failed: File
_CrtDbgReport: String too long or Invalid characters in String
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
(null)
`h````
xpxxxx
`h`hhh
xppwpp
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetUserObjectInformationA
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
Unknown Runtime Check Error
Stack memory around _alloca was corrupted
A local variable was used before it was initialized
Stack memory was corrupted
A cast to a smaller data type has caused a loss of data. If this was intentional, you should mask the source of the cast with the appropriate bitmask. For example:
char c = (i & 0xFF);
Changing the code in this way will not affect the quality of the resulting optimized code.
The value of ESP was not properly saved across a function call. This is usually a result of calling a function declared with one calling convention with a function pointer declared with a different calling convention.
Stack around the variable '
' was corrupted.
The variable '
' is being used without being initialized.
bad exception
f:\dd\vctools\crt_bld\self_x86\crt\src\convrtcp.c
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
MSPDB80.DLL
Stack around _alloca corrupted
Local variable used before initialization
Stack memory corruption
Cast to smaller type causing loss of data
Stack pointer corruption
bad allocation
yijawavulahugafufijibe
zozizinolahoyigaragaluyuhom hotoleveguguripede senikokucozoxoyahebih
timiganetaso
kuxupayuke
nejocubinanoxibewigohujihigase
huhumebeyibuxipugodigevohos tigigulep
cotixubofizinuho
kernel32.dll
cofirecewedemibefafexejasugi fuvonijafubogujohuhosusonoce kudakiculudelatelejixolawih zohogumajosu
nunomewetetadixiwij jodutowi mid
sebonozakorikegotimib
buyebinafepuke
notekarawijosazejijurizucijes
jugavoca
sewexoyocehocucufarihetumoh mumacodecamibowitofabimubuwetade makuc hevenade
danayasa
tonojo
kuvogiw
mijiyorozowaneponiyofu
nasayecobuwapewigaxud nuweci
conoreyizivacupofegojenad
vanoyudab
C:\hikelehusumepi25 picasivohu-5\rajohaca\lawod xiwaha\toda\jefe.pdb
UnregisterWait
SetThreadContext
SetFilePointer
lstrlenA
GetDriveTypeW
InterlockedIncrement
GetQueuedCompletionStatus
InterlockedDecrement
CompareFileTime
GetSystemWindowsDirectoryW
GetNamedPipeHandleStateA
WaitForSingleObject
OpenSemaphoreA
FreeEnvironmentStringsA
GetTickCount
VirtualFree
GetConsoleAliasesLengthA
GetPrivateProfileStringW
WaitNamedPipeW
WriteFile
SetCommState
GetCommandLineA
TlsSetValue
GetPriorityClass
GlobalAlloc
GetConsoleMode
TerminateThread
CopyFileW
GetVersionExW
SetConsoleMode
IsProcessorFeaturePresent
GetBinaryTypeA
GetOverlappedResult
CompareStringW
GetStartupInfoW
GlobalUnlock
VerifyVersionInfoW
CreateDirectoryA
ReleaseActCtx
GetFileSizeEx
SetCurrentDirectoryA
GetCPInfoExW
OpenMutexW
GetLastError
IsDBCSLeadByteEx
ReadConsoleOutputCharacterA
GetProcAddress
WriteProfileSectionA
ResetEvent
OpenWaitableTimerA
LoadLibraryA
CreateSemaphoreW
WriteProfileSectionW
HeapWalk
FindAtomA
Process32NextW
WriteProfileStringA
GetModuleHandleA
FindFirstChangeNotificationA
EnumResourceNamesA
GetConsoleCursorInfo
FatalAppExitA
GetCurrentThreadId
GetSystemTime
LCMapStringW
CopyFileExA
DeleteFileA
KERNEL32.dll
GetCharWidthW
GDI32.dll
GetStartupInfoA
HeapValidate
IsBadReadPtr
RaiseException
GetModuleHandleW
ExitProcess
TlsGetValue
TlsAlloc
TlsFree
SetLastError
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetModuleFileNameW
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
GetModuleFileNameA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetStdHandle
GetFileType
HeapDestroy
HeapCreate
HeapFree
HeapAlloc
HeapSize
HeapReAlloc
VirtualAlloc
GetACP
GetOEMCP
GetCPInfo
IsValidCodePage
InitializeCriticalSectionAndSpinCount
RtlUnwind
GetConsoleCP
DebugBreak
OutputDebugStringA
WriteConsoleW
OutputDebugStringW
LoadLibraryW
MultiByteToWideChar
LCMapStringA
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
CreateFileA
CloseHandle
FlushFileBuffers
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
c^%? S
i 7)ml
S{\oh_
EK;'q
FSWe(
dpi]Ai
|UqV.
9SW~DD
|y)vbS%
]*zen
R*/E$$n
z<]/XT
iPio'Z
/yw]9t
wu 2DMz
.Xh?$I
OVYuWh
GbWc{W
h7a~c+{J
KgqSnO:pW.&
kd/@D#
M5DfAo.
U}[s}b
@eV1":
xazf,z)
J%-j~R
"7?Tt!
?s 5Gt
m2L[s/
Xm`IC9
#l'AdzC
`X3aFM
5n)b`58"Z
-q%KzTU
e4KV:lW
+6K}_K
xWUYDP
pPXW?h
Gk-O3%
56GC;2?
IE]:9#J
#;"|r
<0|o$Kr`
eoU]r~
\-aErO
&NRliO/
m_}m&4
>YkkP`
GU}rj0
~7tci5
mt; tj
Ax*YtpLE
*u(<[J
>`*y-X
mJ7iP"$
OREz!5\Bx
m|[lzy'
#7})V-
B`px$qv
;;Ppibv4
E)HMFO
!~=RAx
cfQ`ht)
3>JqK7
.4(G)I
,]kY[o
Wne;/Tf
`VO5i
wPs|?i=
nvv#$t
yZ)u@r
;R4U7"
pI`"{U>
aaRvxP(
)%Gf)@
PcVHCqXMDTqg#
qH>13E
}.LmnkuCVzy
o_B=n~(B
G\v8!/
MA\]dS
JP\=<jS
_5M]KE
_bj,6hND
p\[$~i$
]v-5p,[
NJ[.G
l2g>Sf
JIQ^gz"
=.rF"1
UH4KNA
N$7<i8
\hmPt.
>']IH"J
DT-PC!
AJ4poR
:`_n?%7
Z(s6!$V
:ZR/65
Dyti.Hq@
*'% n4
;BF)4)n:
jKM]8q*qq
;m,R7xh
LUIe6w
0[g#!J
C5da%<
*qbM`q
.cjs3<]
UVM|D.5
I7Zj-K
NkMxAP+Z
zJzL]M
P6%NSm
);U7}D
d^Y2uU
pVJ5:w
dCC[ ]
:FA~m7
K>*m8N
:m$psS
<#L4nL
v+ig8M
b]Nbt!
}k}m$}O
9M7+xI[
}V]Ui
rIqf{0
2)i^;
h$ODtD~
"e7SU^
2`L+?o
C&6URi
xh(-N
SGADN;
f>$~WJ
',R?A X
[Mj`J<;l
Bm=057
}<uN1l
9u[0z9
H]*m'3W
o6X$_w
dnLNX7
-)'zP`/
(S9Avv
/SWp+O
%:0j<s
<9|J>+
#9G6s(
",?MB4<
{_0T g
`?KiOv
V$J~
_*HL^C
HxsC%B
G9"]>i
l6tw*G5
qk(\a@
x0/;4#
1AK(et
/00<!b
bsGnd(
z!T!N]!
zCo%l4
Z41[xr
!fPowR|
C?&v*I
%1*Z~B\<
k_=ReWw
~L~F$F
sh`6nT
;v8%h_~
gM8HRT$
IJ,w"'
nk$&Ru
,eSgAp
SR308p
|0g0%0
-%m|Q2
h^79*+
8):sr
dH^1zIg
7UDP[tU9
\Dva{|m
?deUQ@
h|$,Q'
*{,_.OIFs
8lJ;X7>}
Rh@[rI@5
$%C9S0
^ILD[&
4knjgW
gaW=[X
Sl/~ 8
NhVw41
^ohy\W
Y5?0j<
qkeQt`
j7e-O
),F^3W
>&Yp!r
{MT0C@
/`~].M
v="c%S`_
M<~~,r
8^w;0lEK
V2ck_]/k
B^.X";CPi
W^I_h"
P*p(yX
O<]cJ4
UXCYZtF
bRED".
#84Uq V
P>"*</2[
AFWeza
+;7],V
kK9-Bk
]sQW(ssa
tC{RAR"
emoLQ%f
Bn{-g8
(o&2$.;3(0>
cG?rsQ
>'dwmq
N4hiky/
~cCXLF
lBBBBBBBBBBBBB
II7777777
77777B
UlBBBBBBlB
BBBBBBBBBX
XlBBBBBBBBBBBBBXIII.B
XIII6B
((((((((
;;;;;;;;;;;;;;
B.r(;!AAAqqqq
AAAqAqq
AAAqAqAu;
0000**
0000*??*u;
;zJJ!!!!
JJ!!!!
zO(M77
qqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqq
qqqqqqq
zFFFFFF
qqqqqq
'EEEEEz
zF&FUU/z
U&"1qqqqUF
&&'EqqqqUF
U'''"''"''"
&&'EqqqqU
'EqqqqU
|$$$$$$$$
/EqqqqU
/SqqqqU
/zqqqqU
zqqqqU
zqqqq&
zqqqqU
zqqqqU
f1zqqqqU
f1zqqqqU
fSEqqqq
qqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqq
iiiiiiiiiiiiiiiiiiii>~~~~~~~~>~iiii
-~iii
-~ii~-
-~ii~-V -~ii~-VVVVVVVVVV-~ii~-V
IIIIIII
-~ii~-
I-~ii~-I
I-~ii~-I
I-~ii~-I
I-~ii~-I
I-~ii>-I
~iii~IIIIIIIII
~~iiiiiiiiiiiiiiiii
'kkkkk?
Akkkkkk
jjjjQq
Akkkkkkkk
kkkkkkkkk[
?kkkkkkkkkkkkkk
kkkkkkkkkkkkk
kkkkkkkk
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
,,,,,,,,,,,,,,,
,,,,,,,,,,,,,,
n,,,,,,,,,,,,,,
b,,,,,,,,,,,,,S
,,,,,,,,,,,,,
FC,,,,,,,,,,,!
,,,,,,,,,,,,
x4,,,,,,,,,,b
F,,,,,,,,,,,
b,,,,,,,,,v
!q,,,,,,,,,
F,,,,,,,,,b
n(,,,,,,
,,,,,,,
<YSq,,,,,,,
n,,,,,,,bs{
,,,,,,
U,,,,,,,,b1GJ
F,,,,,,,,,,yq
S+,,,,,,,,,,,,,,,
,,,,,,,,,,,,,,,,,,,,
b,,,,,,,,,,,,,,,,,,,,,,,C
q,,,,,,,,,,,,,,,,,,,,,,,,C
,,,,,,,,,,,,,,,,,,,,,,,,,C
,,,,,,,,,,,,,,,,,,,,,,,,,,,C
,,,,,,,,,,,,,,,,,,,,,,,,,,,,
p,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFeFFFFFFFFFF
FFFFFFFFFFF$FFFFFFFFFFe
kFFFFFFFFFF
0FFFFFFFFFe
;0FFFFFFFFF
0FFFFFFFFe
FFFFFFFP<
'FFFFFFe
PFFFFFFe
JkFFFFe
;0FFFFFF0
:FFFFFF0&
FFFFFk I
B0FFFFFFF0X
0FFFFFFFFFF
FFFFFFFFFFFFFFF
FFFFFFFFFFFFFFFFe
FFFFFFFFFFFFFFFFFFe
PFFFFFFFFFFFFFFFFFFFe
"FFFFFFFFFFFFFFFFFFFFe
FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
l<J&~L
Culayijitefir mubel. Bimenonez. Dajojeji kujovojobodu tif xacuzefomupof dugipoxazavajuw. Yibabi sivakajezuz yaxoh haxujurenosiso. Cumiyuginaluren gudanofusuvo xuvucusi velaviduz maziz. Wecubanuxa bopatowiy bixefemeyoxexu. Kejuwuyofas lime yetusobu bex. Fibuyaho. Vexecovugozarun poxofezezareva. Kegivodopun serap kiribulojatume. Lobatotirecal lopikaxetex yajamejak bemajamubiga. Madajaso rusexiyopo bapit. Zikulacativ hecupixuh wufiheluye koyohaxagak lebamed. Linoriso. Dagahotanis. Yajosayilo kunuh wiyuvihayeluka. Mozucesawufob hozefucij. Sinep. Cijuyapak liyijavohiv lasokadid yovojexamihepe duhahafovosodi. Vacalobulen poci menayebibiwi. Mayisawufo biloxiviyowuf zosadizata. Kuzozurak wacaxabopax. Pekatibi cuhuwaja vonore jayujo fohuyenizepa. Mogogaguwolin xisekusago ligonit. Lejadazoruwawuh. Foci fafaju xapok. Muxosoyom few. Siwohodulico nupixo wofitujiriri pifeyejiyohetax. Cilubozewowecu vucoj xagiwi. Cetad bivawuf xumutiliti. Pojosun feliwopukotok givigogadu cawukowomirurek luhofetom. Weminus rifulu tohihufi. W
jjjjjjj
c(count == 0) || (string != NULL)
_vswprintf_helper
f:\dd\vctools\crt_bld\self_x86\crt\src\vswprint.c
(format != NULL)
("Buffer too small", 0)
string != NULL && sizeInWords > 0
format != NULL
_vsnwprintf_s_l
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgdel.cpp
_BLOCK_TYPE_IS_VALID(pHead->nBlockUse)
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgheap.c
_CrtCheckMemory()
_calloc_dbg_impl
(_HEAP_MAXREQ / nNum) >= nSize
_pFirstBlock == pOldBlock
_pLastBlock == pOldBlock
fRealloc || (!fRealloc && pNewBlock == pOldBlock)
pOldBlock->nLine == IGNORE_LINE && pOldBlock->lRequest == IGNORE_REQ
_CrtIsValidHeapPointer(pUserData)
pUserData != NULL
_pFirstBlock == pHead
_pLastBlock == pHead
pHead->nBlockUse == nBlockUse
pHead->nLine == IGNORE_LINE && pHead->lRequest == IGNORE_REQ
_msize_dbg
_CrtSetDbgFlag
(fNewBits==_CRTDBG_REPORT_FLAG) || ((fNewBits & 0x0ffff & ~(_CRTDBG_ALLOC_MEM_DF | _CRTDBG_DELAY_FREE_MEM_DF | _CRTDBG_CHECK_ALWAYS_DF | _CRTDBG_CHECK_CRT_DF | _CRTDBG_LEAK_CHECK_DF) ) == 0)
_CrtMemCheckpoint
state != NULL
(*_errno())
_printMemBlockData
(L"Buffer is too small" && 0)
Buffer is too small
(((_Src))) != NULL
strcpy_s
f:\dd\vctools\crt_bld\self_x86\crt\src\tcscpy_s.inl
((_Dst)) != NULL && ((_SizeInBytes)) > 0
mscoree.dll
KERNEL32.DLL
("inconsistent IOB fields", stream->_ptr - stream->_base >= 0)
f:\dd\vctools\crt_bld\self_x86\crt\src\_flsbuf.c
str != NULL
Assertion Failed
Warning
Af:\dd\vctools\crt_bld\self_x86\crt\src\dbgrpt.c
Microsoft Visual C++ Debug Library
_CrtDbgReport: String too long or IO Error
wcscpy_s(szOutMessage, 4096, L"_CrtDbgReport: String too long or IO Error")
Debug %s!
Program: %s%s%s%s%s%s%s%s%s%s%s%s
(Press Retry to debug the application)
Module:
File:
Line:
Expression:
For information on how your program can cause an assertion
failure, see the Visual C++ documentation on asserts.
memcpy_s(szShortProgName, sizeof(TCHAR) * (260 - (szShortProgName - szExeName)), dotdotdot, sizeof(TCHAR) * 3)
<program name unknown>
wcscpy_s(szExeName, 260, L"<program name unknown>")
__crtMessageWindowW
c("'n' format specifier disabled", 0)
_woutput_l
f:\dd\vctools\crt_bld\self_x86\crt\src\output.c
(stream != NULL)
((state == ST_NORMAL) || (state == ST_TYPE))
("Incorrect format specifier", 0)
_woutput_s_l
ibase == 0 || (2 <= ibase && ibase <= 36)
strtoxl
f:\dd\vctools\crt_bld\self_x86\crt\src\strtol.c
nptr != NULL
f:\dd\vctools\crt_bld\self_x86\crt\prebuild\eh\typname.cpp
pNode->next != NULL
strcpy_s(*env, cchars, p)
_setenvp
f:\dd\vctools\crt_bld\self_x86\crt\src\stdenvp.c
strcat_s(outmsg, (sizeof(outmsg) / sizeof(outmsg[0])), rterrs[tblindx].rterrtxt)
strcat_s(outmsg, (sizeof(outmsg) / sizeof(outmsg[0])), "\n\n")
strncpy_s(pch, progname_size - (pch - progname), "...", 3)
strcpy_s(progname, progname_size, "<program name unknown>")
strcpy_s(outmsg, (sizeof(outmsg) / sizeof(outmsg[0])), "Runtime Error!\n\nProgram: ")
_NMSG_WRITE
f:\dd\vctools\crt_bld\self_x86\crt\src\crt0msg.c
strcpy_s(szOutMessage, 4096, "_CrtDbgReport: String too long or IO Error")
strcpy_s(szExeName, 260, "<program name unknown>")
__crtMessageWindowA
_expand_base
f:\dd\vctools\crt_bld\self_x86\crt\src\expand.c
pBlock != NULL
kernel32.dll
f:\dd\vctools\crt_bld\self_x86\crt\src\setlocal.c
((ptloci->lc_category[category].wlocale != NULL) && (ptloci->lc_category[category].wrefcount != NULL)) || ((ptloci->lc_category[category].wlocale == NULL) && (ptloci->lc_category[category].wrefcount == NULL))
f:\dd\vctools\crt_bld\self_x86\crt\src\isctype.c
(unsigned)(c + 1) <= 256
f:\dd\vctools\crt_bld\self_x86\crt\src\winsig.c
("Invalid signal or error", 0)
("Invalid file descriptor. File possibly closed by a different thread",0)
(_osfile(fh) & FOPEN)
_lseeki64
f:\dd\vctools\crt_bld\self_x86\crt\src\lseeki64.c
(fh >= 0 && (unsigned)fh < (unsigned)_nhandle)
_write
f:\dd\vctools\crt_bld\self_x86\crt\src\write.c
isleadbyte(_dbcsBuffer(fh))
((cnt & 1) == 0)
_write_nolock
(buf != NULL)
f:\dd\vctools\crt_bld\self_x86\crt\src\_getbuf.c
_isatty
f:\dd\vctools\crt_bld\self_x86\crt\src\isatty.c
_fileno
f:\dd\vctools\crt_bld\self_x86\crt\src\fileno.c
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgrptt.c
_CrtDbgReport: String too long or Invalid characters in String
wcscpy_s(szOutMessage2, 4096, L"_CrtDbgReport: String too long or Invalid characters in String")
e = mbstowcs_s(&ret, szOutMessage2, 4096, szOutMessage, ((size_t)-1))
strcpy_s(szOutMessage, 4096, szLineMessage)
strcat_s(szLineMessage, 4096, "\n")
strcat_s(szLineMessage, 4096, "\r")
strcat_s(szLineMessage, 4096, szUserMessage)
strcpy_s(szLineMessage, 4096, szFormat ? "Assertion failed: " : "Assertion failed!")
strcpy_s(szUserMessage, 4096, "_CrtDbgReport: String too long or IO Error")
_itoa_s(nLine, szLineMessage, 4096, 10)
_VCrtDbgReportA
wcstombs_s(&ret, szaOutMessage, 4096, szOutMessage, ((size_t)-1))
strcpy_s(szOutMessage2, 4096, "_CrtDbgReport: String too long or Invalid characters in String")
wcstombs_s(((void *)0), szOutMessage2, 4096, szOutMessage, ((size_t)-1))
wcscpy_s(szOutMessage, 4096, szLineMessage)
%s(%d) : %s
wcscat_s(szLineMessage, 4096, L"\n")
wcscat_s(szLineMessage, 4096, L"\r")
wcscat_s(szLineMessage, 4096, szUserMessage)
wcscpy_s(szLineMessage, 4096, szFormat ? L"Assertion failed: " : L"Assertion failed!")
Assertion failed!
Assertion failed:
wcscpy_s(szUserMessage, 4096, L"_CrtDbgReport: String too long or IO Error")
, Line
<file unknown>
Second Chance Assertion Failed: File
_itow_s(nLine, szLineMessage, 4096, 10)
_VCrtDbgReportW
WUSER32.DLL
sizeInBytes >= count
src != NULL
memcpy_s
f:\dd\vctools\crt_bld\self_x86\crt\src\memcpy_s.c
dst != NULL
wcscpy_s
((_Dst)) != NULL && ((_SizeInWords)) > 0
(null)
(ch != _T('\0'))
( (_Stream->_flag & _IOSTRG) || ( fn = _fileno(_Stream), ( (_textmode_safe(fn) == __IOINFO_TM_ANSI) && !_tm_unicode_safe(fn))))
f:\dd\vctools\crt_bld\self_x86\crt\src\mbtowc.c
_loc_update.GetLocaleT()->locinfo->mb_cur_max == 1 || _loc_update.GetLocaleT()->locinfo->mb_cur_max == 2
(str != NULL)
_output_s_l
B_set_error_mode
f:\dd\vctools\crt_bld\self_x86\crt\src\errmode.c
("Invalid error_mode", 0)
(L"String is not null terminated" && 0)
String is not null terminated
strcat_s
f:\dd\vctools\crt_bld\self_x86\crt\src\tcscat_s.inl
strncpy_s
f:\dd\vctools\crt_bld\self_x86\crt\src\tcsncpy_s.inl
f:\dd\vctools\crt_bld\self_x86\crt\src\malloc.h
("Corrupted pointer passed to _freea", 0)
((((( H
h(((( H
H
f:\dd\vctools\crt_bld\self_x86\crt\src\vsprintf.c
_vsnprintf_helper
string != NULL && sizeInBytes > 0
_vsprintf_s_l
_vsnprintf_s_l
D_get_osfhandle
f:\dd\vctools\crt_bld\self_x86\crt\src\osfinfo.c
_mbstowcs_l_helper
f:\dd\vctools\crt_bld\self_x86\crt\src\mbstowcs.c
s != NULL
retsize <= sizeInWords
bufferSize <= INT_MAX
_mbstowcs_s_l
(pwcs == NULL && sizeInWords == 0) || (pwcs != NULL && sizeInWords > 0)
length < sizeInTChars
2 <= radix && radix <= 36
sizeInTChars > (size_t)(is_neg ? 2 : 1)
sizeInTChars > 0
xtoa_s
f:\dd\vctools\crt_bld\self_x86\crt\src\xtoa.c
buf != NULL
_wcstombs_l_helper
f:\dd\vctools\crt_bld\self_x86\crt\src\wcstombs.c
pwcs != NULL
sizeInBytes > retsize
_wcstombs_s_l
(dst != NULL && sizeInBytes > 0) || (dst == NULL && sizeInBytes == 0)
wcscat_s
xtow_s
sizeInBytes > 0
_wctomb_s_l
f:\dd\vctools\crt_bld\self_x86\crt\src\wctomb.c
sizeInBytes <= INT_MAX
Bfclose
f:\dd\vctools\crt_bld\self_x86\crt\src\fclose.c
_fclose_nolock
(_osfile(filedes) & FOPEN)
_commit
f:\dd\vctools\crt_bld\self_x86\crt\src\commit.c
(filedes >= 0 && (unsigned)filedes < (unsigned)_nhandle)
_close
f:\dd\vctools\crt_bld\self_x86\crt\src\close.c
f:\dd\vctools\crt_bld\self_x86\crt\src\_freebuf.c
stream != NULL
ralasozehutof
rarucidoweyotahiyu
hobewihamowabu
fecufomijocabiyujozekubasiw
zikekumib
kixebihufusuzaxasurelologob
kifolukapemikulazujagayoxahi
paciwobifujazozirurorawuguwowod kecadopavag
rujocaguyuwucufotomolewalixoyoh
yosavulogofirugabufisit
zedewibarimufipibesimudoxiwen
xomidazedorofakatitegic
wigigaguliyigebazatudiwicujutelo
xuwosurenezi
kikudopeyicusodoluye
sapexum
PIZUFEWAMO JOPEGAJAYUSOWIDOVAPODEHIZAGODUJO
VS_VERSION_INFO
045816E5
Versus
70.3.40.83
Version
3.85.36.31
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Trojan.Win32.Brook.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.46842685
FireEye Generic.mg.96d3ef5ec108f253
CAT-QuickHeal Clean
McAfee Packed-GDV!96D3EF5EC108
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Trojan.GenericKD.46842685
K7GW Trojan ( 0058143a1 )
Cybereason malicious.2d02fd
Baidu Clean
Cyren W32/Kryptik.EZJ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/GenKryptik.FJID
APEX Malicious
Paloalto generic.ml
ClamAV Win.Packed.Fragtor-9887574-0
Kaspersky HEUR:Trojan-Ransom.Win32.Stop.gen
Alibaba Trojan:Win32/Ranumbot.b1ced092
NANO-Antivirus Clean
ViRobot Clean
Tencent Win32.Trojan.Stop.Hvst
Ad-Aware Trojan.GenericKD.46842685
Emsisoft Trojan.GenericKD.46842685 (B)
Comodo Clean
F-Secure Clean
DrWeb Trojan.Siggen14.62415
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Dropper.fc
CMC Clean
Sophos Mal/Generic-S
Ikarus Trojan.Win32.Ranumbot
GData Trojan.GenericKD.46842685
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira TR/AD.RedLineSteal.ygcvg
MAX malware (ai score=89)
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Malware.Win32.MigratedCloud.cc
Arcabit Trojan.Fragtor.D25D9
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Ditertag.A
Cynet Malicious (score: 100)
AhnLab-V3 CoinMiner/Win.Glupteba.R438366
Acronis suspicious
BitDefenderTheta Gen:NN.ZexaF.34088.vqW@aOUWHzhK
ALYac Gen:Variant.Fragtor.9689
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.MalPack
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CHL21
Rising Trojan.Kryptik!1.C6FC (CLASSIC)
Yandex Clean
SentinelOne Static AI - Suspicious PE
eGambit Unsafe.AI_Score_61%
Fortinet W32/Brook!tr
AVG Win32:MalwareX-gen [Trj]
Avast Win32:MalwareX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
MaxSecure Clean
No IRMA results available.