Static | ZeroBOX

PE Compile Time

2020-06-30 03:40:31

PDB Path

C:\zav\nonukasag.pdb

PE Imphash

c3357f55d714ba99dcfee6966059bf12

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00024af0 0x00024c00 6.31997626101
.rdata 0x00026000 0x0000ace6 0x0000ae00 5.02479969849
.data 0x00031000 0x01f8b15c 0x00023600 7.90909482401
.rsrc 0x01fbd000 0x00003198 0x00003200 4.98619648078

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x01fbd1e0 0x000025a8 LANG_FRENCH SUBLANG_FRENCH_LUXEMBOURG dBase IV DBT of `.DBF, block length 9216, next free block index 40, next free block 0, next used block 0
RT_STRING 0x01fbfe00 0x00000392 None SUBLANG_DEFAULT data
RT_STRING 0x01fbfe00 0x00000392 None SUBLANG_DEFAULT data
RT_ACCELERATOR 0x01fbf7a0 0x00000080 None SUBLANG_DEFAULT data
RT_ACCELERATOR 0x01fbf7a0 0x00000080 None SUBLANG_DEFAULT data
RT_GROUP_ICON 0x01fbf788 0x00000014 LANG_FRENCH SUBLANG_FRENCH_LUXEMBOURG data
RT_VERSION 0x01fbf8a8 0x00000120 None SUBLANG_DEFAULT data

Imports

Library KERNEL32.dll:
0x426000 GetCommandLineW
0x426008 SetThreadContext
0x42600c GetNativeSystemInfo
0x426010 SetFilePointer
0x426014 lstrlenA
0x426018 CopyFileExW
0x42601c TlsGetValue
0x426028 GetCommState
0x426034 GlobalLock
0x426038 WaitForSingleObject
0x42603c SetEvent
0x426044 GetTickCount
0x426048 CreateNamedPipeW
0x42604c VirtualFree
0x426054 GetDriveTypeA
0x426058 GetPriorityClass
0x42605c LoadLibraryW
0x426060 GetConsoleMode
0x426064 TerminateThread
0x426068 GetVersionExW
0x42606c SetConsoleMode
0x426074 ReadFile
0x426078 GetOverlappedResult
0x42607c CompareStringW
0x426080 GetStartupInfoW
0x426088 LCMapStringA
0x426090 CreateDirectoryA
0x426094 GetFileSizeEx
0x426098 GetCPInfoExW
0x42609c GetLastError
0x4260a0 IsDBCSLeadByteEx
0x4260a4 GetProcAddress
0x4260a8 CopyFileA
0x4260b0 LoadLibraryA
0x4260b4 OpenMutexA
0x4260b8 LocalAlloc
0x4260c8 HeapWalk
0x4260d0 Process32NextW
0x4260d4 SetConsoleTitleW
0x4260e0 EnumResourceNamesA
0x4260e4 FatalAppExitA
0x4260e8 GetCurrentThreadId
0x4260ec OpenSemaphoreW
0x4260f0 FindAtomW
0x4260f8 GetSystemTime
0x4260fc DeleteFileA
0x426108 HeapValidate
0x42610c IsBadReadPtr
0x426110 RaiseException
0x426114 GetModuleHandleW
0x426118 Sleep
0x42611c ExitProcess
0x426120 GetModuleFileNameA
0x426124 WriteFile
0x426128 GetStdHandle
0x42612c TlsAlloc
0x426130 TlsSetValue
0x426134 TlsFree
0x426138 SetLastError
0x42613c TerminateProcess
0x426140 GetCurrentProcess
0x426144 IsDebuggerPresent
0x426148 GetModuleFileNameW
0x42615c GetCurrentProcessId
0x426168 SetHandleCount
0x42616c GetFileType
0x426170 GetStartupInfoA
0x426174 HeapDestroy
0x426178 HeapCreate
0x42617c HeapFree
0x426180 HeapAlloc
0x426184 HeapSize
0x426188 HeapReAlloc
0x42618c VirtualAlloc
0x426190 GetACP
0x426194 GetOEMCP
0x426198 GetCPInfo
0x42619c IsValidCodePage
0x4261a4 RtlUnwind
0x4261a8 WideCharToMultiByte
0x4261ac GetConsoleCP
0x4261b0 DebugBreak
0x4261b4 OutputDebugStringA
0x4261b8 WriteConsoleW
0x4261bc OutputDebugStringW
0x4261c0 MultiByteToWideChar
0x4261c4 LCMapStringW
0x4261c8 GetStringTypeA
0x4261cc GetStringTypeW
0x4261d0 GetLocaleInfoA
0x4261d4 SetStdHandle
0x4261d8 WriteConsoleA
0x4261dc GetConsoleOutputCP
0x4261e0 FlushFileBuffers
0x4261e4 CreateFileA
0x4261e8 CloseHandle
0x4261ec GetModuleHandleA
Library USER32.dll:
0x4261f4 GetTitleBarInfo
Library WINHTTP.dll:
0x4261fc WinHttpReadData

!This program cannot be run in DOS mode.
`.rdata
@.data
u!h4dB
t hxfB
t!h(iB
t!hXhB
t!h$hB
t!hPeB
t!hdkB
u!h@kB
t!hPeB
Rh`pB
Ph|tB
RhTtB
Ph$tB
t1hDuB
th|uB
URPQQh
PPPPPPPP
PPPPPPPP
u!h4dB
u!h4dB
;t$,v-
UQPXY]Y[
bad allocation
Unknown exception
f:\dd\vctools\crt_bld\self_x86\crt\src\onexit.c
Client
Ignore
Normal
Error: memory allocation: bad memory block type.
Invalid allocation size: %Iu bytes.
Client hook allocation failure.
Client hook allocation failure at file %hs line %d.
Error: possible heap corruption at or near 0x%p
The Block at 0x%p was allocated by aligned routines, use _aligned_realloc()
Error: memory allocation: bad memory block type.
Memory allocated at %hs(%d).
Invalid allocation size: %Iu bytes.
Memory allocated at %hs(%d).
Client hook re-allocation failure.
Client hook re-allocation failure at file %hs line %d.
HEAP CORRUPTION DETECTED: after %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory after end of heap buffer.
HEAP CORRUPTION DETECTED: after %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory after end of heap buffer.
Memory allocated at %hs(%d).
HEAP CORRUPTION DETECTED: before %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory before start of heap buffer.
HEAP CORRUPTION DETECTED: before %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory before start of heap buffer.
Memory allocated at %hs(%d).
Client hook free failure.
The Block at 0x%p was allocated by aligned routines, use _aligned_free()
%hs located at 0x%p is %Iu bytes long.
%hs located at 0x%p is %Iu bytes long.
Memory allocated at %hs(%d).
HEAP CORRUPTION DETECTED: on top of Free block at 0x%p.
CRT detected that the application wrote to a heap buffer that was freed.
HEAP CORRUPTION DETECTED: on top of Free block at 0x%p.
CRT detected that the application wrote to a heap buffer that was freed.
Memory allocated at %hs(%d).
DAMAGED
_heapchk fails with unknown return value!
_heapchk fails with _HEAPBADPTR.
_heapchk fails with _HEAPBADEND.
_heapchk fails with _HEAPBADNODE.
_heapchk fails with _HEAPBADBEGIN.
Bad memory block found at 0x%p.
Bad memory block found at 0x%p.
Memory allocated at %hs(%d).
Object dump complete.
crt block at 0x%p, subtype %x, %Iu bytes long.
normal block at 0x%p, %Iu bytes long.
client block at 0x%p, subtype %x, %Iu bytes long.
{%ld}
%hs(%d) :
#File Error#(%d) :
Dumping objects ->
Data: <%s> %s
Detected memory leaks!
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library without using a manifest.
This is an unsupported way to load Visual C++ DLLs. You need to modify your application to build with a manifest.
For more information, see the "Visual C++ Libraries as Shared Side-by-Side Assemblies" topic in the product documentation.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
f:\dd\vctools\crt_bld\self_x86\crt\src\tidtable.c
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
f:\dd\vctools\crt_bld\self_x86\crt\src\output.c
f:\dd\vctools\crt_bld\self_x86\crt\src\_file.c
f:\dd\vctools\crt_bld\self_x86\crt\src\_sftbuf.c
(null)
`h````
xpxxxx
f:\dd\vctools\crt_bld\self_x86\crt\src\mlock.c
f:\dd\vctools\crt_bld\self_x86\crt\src\stdenvp.c
f:\dd\vctools\crt_bld\self_x86\crt\src\stdargv.c
f:\dd\vctools\crt_bld\self_x86\crt\src\w_env.c
f:\dd\vctools\crt_bld\self_x86\crt\src\ioinit.c
Assertion Failed
Warning
Microsoft Visual C++ Debug Library
_CrtDbgReport: String too long or IO Error
Debug %s!
Program: %s%s%s%s%s%s%s%s%s%s%s%s
(Press Retry to debug the application)
Module:
File:
Line:
Expression:
For information on how your program can cause an assertion
failure, see the Visual C++ documentation on asserts.
HeapQueryInformation
f:\dd\vctools\crt_bld\self_x86\crt\src\mbctype.c
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
f:\dd\vctools\crt_bld\self_x86\crt\src\_getbuf.c
%s(%d) : %s
Assertion failed!
Assertion failed:
, Line
<file unknown>
Second Chance Assertion Failed: File
_CrtDbgReport: String too long or Invalid characters in String
GetUserObjectInformationW
MessageBoxW
`h`hhh
xppwpp
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
bad exception
Unknown Runtime Check Error
Stack memory around _alloca was corrupted
A local variable was used before it was initialized
Stack memory was corrupted
A cast to a smaller data type has caused a loss of data. If this was intentional, you should mask the source of the cast with the appropriate bitmask. For example:
char c = (i & 0xFF);
Changing the code in this way will not affect the quality of the resulting optimized code.
The value of ESP was not properly saved across a function call. This is usually a result of calling a function declared with one calling convention with a function pointer declared with a different calling convention.
Stack around the variable '
' was corrupted.
The variable '
' is being used without being initialized.
f:\dd\vctools\crt_bld\self_x86\crt\src\convrtcp.c
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
MSPDB80.DLL
Stack around _alloca corrupted
Local variable used before initialization
Stack memory corruption
Cast to smaller type causing loss of data
Stack pointer corruption
bad allocation
laxedohas
liwunodidoleyov
mahurakeropepowumu
lilut bicugefabeyezuxe nedomelawazonociw
bemeko
zorazekobojofohejuzurewu
medipoc
jinejagecagigitogat
vadazijamolujiletetekolugiruv
gujeno
jodivepizezelafagobugerujoced
mudozigidubusixahuvegoritabanu
kernel32.dll
afoxiw
Majasele robucireheroj dijalo motu fojosezoda
rusizoducopipitihopix tukuxagatagicaw pilihavew dorenexebarumeya
nutonovazoyavopehakoxaxo
wewefubizuwuse
GAIsProcessorFeaturePresent
KERNEL32
RUUUUU
i^^?(>
Y:/(A6>
1#QNAN
1#SNAN
_nextafter
_hypot
C:\zav\nonukasag.pdb
GetCommandLineW
FileTimeToDosDateTime
SetThreadContext
GetNativeSystemInfo
SetFilePointer
lstrlenA
CopyFileExW
TlsGetValue
InterlockedIncrement
GetQueuedCompletionStatus
GetCommState
InterlockedDecrement
GetSystemWindowsDirectoryW
GlobalLock
WaitForSingleObject
SetEvent
FreeEnvironmentStringsA
GetTickCount
CreateNamedPipeW
VirtualFree
GetConsoleAliasesLengthA
GetDriveTypeA
GetPriorityClass
LoadLibraryW
GetConsoleMode
TerminateThread
GetVersionExW
SetConsoleMode
SetConsoleCursorPosition
ReadFile
GetOverlappedResult
CompareStringW
GetStartupInfoW
GetNamedPipeHandleStateW
LCMapStringA
GetPrivateProfileIntW
CreateDirectoryA
GetFileSizeEx
GetCPInfoExW
GetLastError
IsDBCSLeadByteEx
GetProcAddress
CopyFileA
GetPrivateProfileStringA
LoadLibraryA
OpenMutexA
LocalAlloc
IsSystemResumeAutomatic
SetCurrentDirectoryW
WriteProfileSectionW
HeapWalk
SetNamedPipeHandleState
Process32NextW
SetConsoleTitleW
FindFirstChangeNotificationA
FreeEnvironmentStringsW
EnumResourceNamesA
FatalAppExitA
GetCurrentThreadId
OpenSemaphoreW
FindAtomW
ReadConsoleOutputCharacterW
GetSystemTime
DeleteFileA
KERNEL32.dll
GetTitleBarInfo
USER32.dll
WinHttpReadData
WINHTTP.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
HeapValidate
IsBadReadPtr
RaiseException
GetModuleHandleW
ExitProcess
GetModuleFileNameA
WriteFile
GetStdHandle
TlsAlloc
TlsSetValue
TlsFree
SetLastError
TerminateProcess
GetCurrentProcess
IsDebuggerPresent
GetModuleFileNameW
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
GetEnvironmentStringsW
SetHandleCount
GetFileType
GetStartupInfoA
HeapDestroy
HeapCreate
HeapFree
HeapAlloc
HeapSize
HeapReAlloc
VirtualAlloc
GetACP
GetOEMCP
GetCPInfo
IsValidCodePage
InitializeCriticalSectionAndSpinCount
RtlUnwind
WideCharToMultiByte
GetConsoleCP
DebugBreak
OutputDebugStringA
WriteConsoleW
OutputDebugStringW
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
FlushFileBuffers
CreateFileA
CloseHandle
GetModuleHandleA
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
|EG?Sol
1~VmF'o\@
vYzlF.
zf^26I
3S!Fn(
9!hEz\
e$u*6/
)x2+*`?
~}H}&_L{
#,ZC;n
n%9PGKZ
N@}:.~a
0xYE!/C
~(Jg;x
$G2I:<}
s=:!pK
)Ljih`G
<$o2%
a^|U/X
QK^71$haw
]#Vc1W
I><h&+
$*iE'<
6>cPOH
EHv<&7
_Tl(l7
*klL|M
bES`M|
6IoTO#/Iq
m04t[fo
[-Gy]2
i*!G)_sP
mlQwr\)
L"kK!H
~1[G"j9
p&Q7\p`sT
9W%Z7?b
smI}m9c
bN)xjR0;
'1&Bpu4
Nhy7HV
P!,h2~X
1VJpR$
[j[0}K
>F<6[(
U0u-]g
E*l{q|
"8_{j\
@}mkqmu
K9p_Ko%
2v$GZ0dv
|W0nSJ/Z@
Z>aK_ N_
~nK-N;K9
t>5%pA
G{!DMR
$5WmNM
lA1CEJ
v,R0RM
DIIF'h
(Nt06(.
+4"c^-
d8?+rt
6Q[0S(
>X<P!J
2hKF(z
d6tvXN
+hF1=h
Q57CyH
t:#T{MH\E
|xl$?S
@4+o`K
%(B6V1
R&x~a~
'X`%{B
v|cJuI
<eY2xgi
7w}TYJ
hoE.|DzX
lLd/n,
B2.|]O
PAO)`;
zm`$w}
#OEG~+
Zz-|Ya
/nVBADT$
X|Oav(
%g[0
pW!J8Ci
s2l>ZU
]N*?'g"M
;EI;"d
8vC$uQq
qb15I"
VLIj4M
&$d0S
9[z6#%
Z5:O >&Tk
)K!tHO}
T9J4ZD
i%nv1
sn(pR 6
*/S@51
Ga9V=s
)~ld]HeK
O~Noim
'1uGilZjw
oFjwUNb
G,Sc9nN
I-y)a`zK
.)7&~y
o5O}za
oL2,kt
7o"'nb
|JadbM
|n.Jiv-M
+$M_d9
YTQv}O
)!7=D(
TqFf-za
_gYxou
NVhrY&
[Oq-%7^
k#w~y}sd
I<7,".0
tg`<xEEG
~hB+8?d9%
gt+2n4
51f"RDs
S:ISorV%)/
FoE1"IQ
Ov|kkmE
l&B+!5
WWlkHqq
6mP5|X
H^s~n!
2xL"HW
MPsg>xd
kE|t.I
w1jEG}O
l]jPsi
:Ij9;@R
/^0.JZ|kH5
_O?2KH{
\}+/7V
U|>0RA
g6Yg+d*
5kaCBI
; nR|J
_K("h5
I+JH+rx
~q;K,c
JF:"1?
Dlq}'\
>Y)MLw#
Nqk:lx
kYuxw.
Vn)0u-
'`?rt9
`WdmDw
}*)tH6
r.`A;qt
+$:oXfJe
YJ]>kT
en!]:I>
[@a!g{
\(=~]}w
R*':\]|
D~:b[zez
[IWDGy
6C0I]6
b|9&NB
3rf<,d
?P)w6e
06LC!U
gD94os
eD1jJt
Yiu#c}a
D|QmW/
p,`U:u
+bAJZu'xfC
fs9SHY
1IefyJ
>Y,K%4Fo
d.7VCDD
yMYDOw
qsku|A
(I_gm:
f\U<GW
b^i$aF
,N+E~*
n.oG&L&H
+Jn|T'
H=;d<X
>LPif&5
6u$*=N
$oS9n|
9@rG>X
g$&K]hs
&`a&ck
Hll4N0
2c!%N;
9^w5_Zo
P .T %XD
t0z>X7
zRT63v
Nwbh'10
mq>C<gE
)y4~Fv
=sy.JA
s<=cm`
:sWexb3
Bt6NN,
>s1M3/
;l!cTj
.7[(IObo
Twcb}C
7qqRpYq
U~(8m!.
YmsC4Gz
_|*OR"
z>mUq}
_j"Zt,
%inE)<
r{<!d$
:zFp3>E
:sVyI(
#`%*D
nm/"&@
d"r;6Q
_w$j6$
l>Z!rz
f_^-pe
7~:D.i
W+x0{*
;}0st#
6=uriz
Rj*ZTS
$mOW?h
-&WHOO&
0.^+b-
Symantec Corporation10
Symantec Trust Network100.
'Symantec Class 3 SHA256 Code Signing CA0
200403000000Z
230503235959Z0k1
Berlin1
Berlin1
MAGIX Software GmbH1
MAGIX Software GmbH0
http://sv.symcb.com/sv.crl0a
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0
http://sv.symcd.com0&
http://sv.symcb.com/sv.crt0
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2006 VeriSign, Inc. - For authorized use only1E0C
<VeriSign Class 3 Public Primary Certification Authority - G50
131210000000Z
231209235959Z0
Symantec Corporation10
Symantec Trust Network100.
'Symantec Class 3 SHA256 Code Signing CA0
+ojr\`
http://s2.symcb.com0
http://www.symauth.com/cps0(
http://www.symauth.com/rpa00
http://s1.symcb.com/pca3-g5.crl0
SymantecPKI-1-5670
Symantec Corporation10
Symantec Trust Network100.
'Symantec Class 3 SHA256 Code Signing CA
fS~etdR
20210621091651Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G3
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2008 VeriSign, Inc. - For authorized use only1806
/VeriSign Universal Root Certification Authority0
160112000000Z
310111235959Z0w1
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0.
http://s.symcd.com06
%http://s.symcb.com/universal-root.crl0
TimeStamp-2048-30
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
171223000000Z
290322235959Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G30
?'J3Nm
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0@
/http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
http://ts-ocsp.ws.symantec.com0;
/http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
TimeStamp-2048-60
U){9FN
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA
210621091651Z0/
/1(0&0$0"
Symantec Corporation10
Symantec Trust Network100.
'Symantec Class 3 SHA256 Code Signing CA0
200403000000Z
230503235959Z0k1
Berlin1
Berlin1
MAGIX Software GmbH1
MAGIX Software GmbH0
http://sv.symcb.com/sv.crl0a
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0
http://sv.symcd.com0&
http://sv.symcb.com/sv.crt0
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2006 VeriSign, Inc. - For authorized use only1E0C
<VeriSign Class 3 Public Primary Certification Authority - G50
131210000000Z
231209235959Z0
Symantec Corporation10
Symantec Trust Network100.
'Symantec Class 3 SHA256 Code Signing CA0
+ojr\`
http://s2.symcb.com0
http://www.symauth.com/cps0(
http://www.symauth.com/rpa00
http://s1.symcb.com/pca3-g5.crl0
SymantecPKI-1-5670
Symantec Corporation10
Symantec Trust Network100.
'Symantec Class 3 SHA256 Code Signing CA
fS~etdR
20210621091651Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G3
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2008 VeriSign, Inc. - For authorized use only1806
/VeriSign Universal Root Certification Authority0
160112000000Z
310111235959Z0w1
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0.
http://s.symcd.com06
%http://s.symcb.com/universal-root.crl0
TimeStamp-2048-30
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
171223000000Z
290322235959Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G30
?'J3Nm
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0@
/http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
http://ts-ocsp.ws.symantec.com0;
/http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
TimeStamp-2048-60
U){9FN
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA
210621091651Z0/
/1(0&0$0"
jjjjjjj
Bjjjjj
Bjjjjjjj
c(count == 0) || (string != NULL)
_vswprintf_helper
f:\dd\vctools\crt_bld\self_x86\crt\src\vswprint.c
(format != NULL)
("Buffer too small", 0)
string != NULL && sizeInWords > 0
format != NULL
_vsnwprintf_s_l
printf
f:\dd\vctools\crt_bld\self_x86\crt\src\printf.c
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgdel.cpp
_BLOCK_TYPE_IS_VALID(pHead->nBlockUse)
f:\dd\vctools\crt_bld\self_x86\crt\src\feoferr.c
(stream != NULL)
ferror
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgheap.c
_CrtCheckMemory()
_calloc_dbg_impl
(_HEAP_MAXREQ / nNum) >= nSize
_pFirstBlock == pOldBlock
_pLastBlock == pOldBlock
fRealloc || (!fRealloc && pNewBlock == pOldBlock)
pOldBlock->nLine == IGNORE_LINE && pOldBlock->lRequest == IGNORE_REQ
_CrtIsValidHeapPointer(pUserData)
pUserData != NULL
_pFirstBlock == pHead
_pLastBlock == pHead
pHead->nBlockUse == nBlockUse
pHead->nLine == IGNORE_LINE && pHead->lRequest == IGNORE_REQ
_msize_dbg
_CrtSetDbgFlag
(fNewBits==_CRTDBG_REPORT_FLAG) || ((fNewBits & 0x0ffff & ~(_CRTDBG_ALLOC_MEM_DF | _CRTDBG_DELAY_FREE_MEM_DF | _CRTDBG_CHECK_ALWAYS_DF | _CRTDBG_CHECK_CRT_DF | _CRTDBG_LEAK_CHECK_DF) ) == 0)
_CrtMemCheckpoint
state != NULL
(*_errno())
_printMemBlockData
mscoree.dll
f:\dd\vctools\crt_bld\self_x86\crt\src\winsig.c
("Invalid signal or error", 0)
strcat_s(outmsg, (sizeof(outmsg) / sizeof(outmsg[0])), rterrs[tblindx].rterrtxt)
strcat_s(outmsg, (sizeof(outmsg) / sizeof(outmsg[0])), "\n\n")
strncpy_s(pch, progname_size - (pch - progname), "...", 3)
strcpy_s(progname, progname_size, "<program name unknown>")
strcpy_s(outmsg, (sizeof(outmsg) / sizeof(outmsg[0])), "Runtime Error!\n\nProgram: ")
_NMSG_WRITE
f:\dd\vctools\crt_bld\self_x86\crt\src\crt0msg.c
(L"Buffer is too small" && 0)
Buffer is too small
(((_Src))) != NULL
strcpy_s
f:\dd\vctools\crt_bld\self_x86\crt\src\tcscpy_s.inl
((_Dst)) != NULL && ((_SizeInBytes)) > 0
ibase == 0 || (2 <= ibase && ibase <= 36)
strtoxl
f:\dd\vctools\crt_bld\self_x86\crt\src\strtol.c
nptr != NULL
strtoxq
f:\dd\vctools\crt_bld\self_x86\crt\src\strtoq.c
KERNEL32.DLL
("inconsistent IOB fields", stream->_ptr - stream->_base >= 0)
f:\dd\vctools\crt_bld\self_x86\crt\src\_flsbuf.c
str != NULL
Assertion Failed
Warning
Bf:\dd\vctools\crt_bld\self_x86\crt\src\dbgrpt.c
Microsoft Visual C++ Debug Library
_CrtDbgReport: String too long or IO Error
wcscpy_s(szOutMessage, 4096, L"_CrtDbgReport: String too long or IO Error")
Debug %s!
Program: %s%s%s%s%s%s%s%s%s%s%s%s
(Press Retry to debug the application)
Module:
File:
Line:
Expression:
For information on how your program can cause an assertion
failure, see the Visual C++ documentation on asserts.
memcpy_s(szShortProgName, sizeof(TCHAR) * (260 - (szShortProgName - szExeName)), dotdotdot, sizeof(TCHAR) * 3)
<program name unknown>
wcscpy_s(szExeName, 260, L"<program name unknown>")
__crtMessageWindowW
c("'n' format specifier disabled", 0)
_woutput_l
f:\dd\vctools\crt_bld\self_x86\crt\src\output.c
((state == ST_NORMAL) || (state == ST_TYPE))
("Incorrect format specifier", 0)
_woutput_s_l
f:\dd\vctools\crt_bld\self_x86\crt\src\_sftbuf.c
flag == 0 || flag == 1
(null)
(ch != _T('\0'))
( (_Stream->_flag & _IOSTRG) || ( fn = _fileno(_Stream), ( (_textmode_safe(fn) == __IOINFO_TM_ANSI) && !_tm_unicode_safe(fn))))
_output_l
f:\dd\vctools\crt_bld\self_x86\crt\prebuild\eh\typname.cpp
pNode->next != NULL
wcscpy_s(*env, cchars, p)
_wsetenvp
f:\dd\vctools\crt_bld\self_x86\crt\src\stdenvp.c
strcpy_s(szOutMessage, 4096, "_CrtDbgReport: String too long or IO Error")
strcpy_s(szExeName, 260, "<program name unknown>")
__crtMessageWindowA
_expand_base
f:\dd\vctools\crt_bld\self_x86\crt\src\expand.c
pBlock != NULL
kernel32.dll
f:\dd\vctools\crt_bld\self_x86\crt\src\setlocal.c
((ptloci->lc_category[category].wlocale != NULL) && (ptloci->lc_category[category].wrefcount != NULL)) || ((ptloci->lc_category[category].wlocale == NULL) && (ptloci->lc_category[category].wrefcount == NULL))
f:\dd\vctools\crt_bld\self_x86\crt\src\isctype.c
(unsigned)(c + 1) <= 256
_set_error_mode
f:\dd\vctools\crt_bld\self_x86\crt\src\errmode.c
("Invalid error_mode", 0)
(L"String is not null terminated" && 0)
String is not null terminated
strcat_s
f:\dd\vctools\crt_bld\self_x86\crt\src\tcscat_s.inl
strncpy_s
f:\dd\vctools\crt_bld\self_x86\crt\src\tcsncpy_s.inl
("Invalid file descriptor. File possibly closed by a different thread",0)
(_osfile(fh) & FOPEN)
_lseeki64
f:\dd\vctools\crt_bld\self_x86\crt\src\lseeki64.c
(fh >= 0 && (unsigned)fh < (unsigned)_nhandle)
_write
f:\dd\vctools\crt_bld\self_x86\crt\src\write.c
isleadbyte(_dbcsBuffer(fh))
((cnt & 1) == 0)
_write_nolock
(buf != NULL)
f:\dd\vctools\crt_bld\self_x86\crt\src\_getbuf.c
_isatty
f:\dd\vctools\crt_bld\self_x86\crt\src\isatty.c
_fileno
f:\dd\vctools\crt_bld\self_x86\crt\src\fileno.c
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgrptt.c
_CrtDbgReport: String too long or Invalid characters in String
wcscpy_s(szOutMessage2, 4096, L"_CrtDbgReport: String too long or Invalid characters in String")
e = mbstowcs_s(&ret, szOutMessage2, 4096, szOutMessage, ((size_t)-1))
strcpy_s(szOutMessage, 4096, szLineMessage)
strcat_s(szLineMessage, 4096, "\n")
strcat_s(szLineMessage, 4096, "\r")
strcat_s(szLineMessage, 4096, szUserMessage)
strcpy_s(szLineMessage, 4096, szFormat ? "Assertion failed: " : "Assertion failed!")
strcpy_s(szUserMessage, 4096, "_CrtDbgReport: String too long or IO Error")
_itoa_s(nLine, szLineMessage, 4096, 10)
_VCrtDbgReportA
wcstombs_s(&ret, szaOutMessage, 4096, szOutMessage, ((size_t)-1))
strcpy_s(szOutMessage2, 4096, "_CrtDbgReport: String too long or Invalid characters in String")
wcstombs_s(((void *)0), szOutMessage2, 4096, szOutMessage, ((size_t)-1))
wcscpy_s(szOutMessage, 4096, szLineMessage)
%s(%d) : %s
wcscat_s(szLineMessage, 4096, L"\n")
wcscat_s(szLineMessage, 4096, L"\r")
wcscat_s(szLineMessage, 4096, szUserMessage)
wcscpy_s(szLineMessage, 4096, szFormat ? L"Assertion failed: " : L"Assertion failed!")
Assertion failed!
Assertion failed:
wcscpy_s(szUserMessage, 4096, L"_CrtDbgReport: String too long or IO Error")
, Line
<file unknown>
Second Chance Assertion Failed: File
_itow_s(nLine, szLineMessage, 4096, 10)
_VCrtDbgReportW
WUSER32.DLL
sizeInBytes >= count
src != NULL
memcpy_s
f:\dd\vctools\crt_bld\self_x86\crt\src\memcpy_s.c
dst != NULL
wcscpy_s
((_Dst)) != NULL && ((_SizeInWords)) > 0
f:\dd\vctools\crt_bld\self_x86\crt\src\mbtowc.c
_loc_update.GetLocaleT()->locinfo->mb_cur_max == 1 || _loc_update.GetLocaleT()->locinfo->mb_cur_max == 2
(str != NULL)
_output_s_l
sizeInBytes > 0
_wctomb_s_l
f:\dd\vctools\crt_bld\self_x86\crt\src\wctomb.c
sizeInBytes <= INT_MAX
f:\dd\vctools\crt_bld\self_x86\crt\src\malloc.h
("Corrupted pointer passed to _freea", 0)
((((( H
h(((( H
H
f:\dd\vctools\crt_bld\self_x86\crt\src\vsprintf.c
_vsnprintf_helper
string != NULL && sizeInBytes > 0
_vsprintf_s_l
_vsnprintf_s_l
@_get_osfhandle
f:\dd\vctools\crt_bld\self_x86\crt\src\osfinfo.c
_mbstowcs_l_helper
f:\dd\vctools\crt_bld\self_x86\crt\src\mbstowcs.c
s != NULL
retsize <= sizeInWords
bufferSize <= INT_MAX
_mbstowcs_s_l
(pwcs == NULL && sizeInWords == 0) || (pwcs != NULL && sizeInWords > 0)
length < sizeInTChars
2 <= radix && radix <= 36
sizeInTChars > (size_t)(is_neg ? 2 : 1)
sizeInTChars > 0
xtoa_s
f:\dd\vctools\crt_bld\self_x86\crt\src\xtoa.c
buf != NULL
_wcstombs_l_helper
f:\dd\vctools\crt_bld\self_x86\crt\src\wcstombs.c
pwcs != NULL
sizeInBytes > retsize
_wcstombs_s_l
(dst != NULL && sizeInBytes > 0) || (dst == NULL && sizeInBytes == 0)
wcscat_s
xtow_s
fclose
f:\dd\vctools\crt_bld\self_x86\crt\src\fclose.c
_fclose_nolock
(_osfile(filedes) & FOPEN)
_commit
f:\dd\vctools\crt_bld\self_x86\crt\src\commit.c
(filedes >= 0 && (unsigned)filedes < (unsigned)_nhandle)
B_close
f:\dd\vctools\crt_bld\self_x86\crt\src\close.c
f:\dd\vctools\crt_bld\self_x86\crt\src\_freebuf.c
stream != NULL
nejilisukiridu puluziwasetutudoraroxafomavo yahikivuxo
howasizaloc
litibiragihicuxiwokapazi bexuduluguyunakuwowihiciduriviv sejanilewogelezezezesohenisaxa zabugurigenagehagisobi kizisicev
toyejewomugolamapihoroku dil
zorulipuyayedejolezejobabacezizu
fujovaweliwacaraxexavucexagacahejomiwiladapuyuvoveduhufo
sapupe
ledugoms
Tanixuyij
cebidixakiyewibohonasi
tizajaliyoxug nituyugibi vegenacujugijed zehegupezimoxeyacasanofuk
fulatuzimekudorefehutimiyilanum hozibeza
punajafiwelola
jeyofixafiyikeluteniviyixifocopi
nimokufodadozekovo
@_controlfp_s(((void *)0), 0x00010000, 0x00030000)
_setdefaultprecision
f:\dd\vctools\crt_bld\self_x86\crt\src\intel\fp8.c
_cftoe_l
f:\dd\vctools\crt_bld\self_x86\crt\prebuild\conv\cvt.c
strcpy_s(p, (sizeInBytes == (size_t)-1 ? sizeInBytes : sizeInBytes - (p - buf)), "e+000")
sizeInBytes > (size_t)(3 + (ndec > 0 ? ndec : 0) + 5 + 1)
_cftoe2_l
sizeInBytes > (size_t)(1 + 4 + ndec + 6)
_cftoa_l
_cftof_l
_cftof2_l
_cftog_l
_controlfp_s
f:\dd\vctools\crt_bld\self_x86\crt\prebuild\tran\contrlfp.c
("Invalid input value", 0)
pflt != NULL
sizeInBytes > (size_t)((digits > 0 ? digits : 0) + 1)
_fptostr
f:\dd\vctools\crt_bld\self_x86\crt\src\_fptostr.c
strcpy_s(resultstr, resultsize, autofos.man)
_fltout2
f:\dd\vctools\crt_bld\self_x86\crt\prebuild\conv\cfout.c
__strgtold12_l
f:\dd\vctools\crt_bld\self_x86\crt\prebuild\include\strgtold12.inl
_Locale != NULL
strcpy_s(fos->man, 21+1, "1#QNAN")
strcpy_s(fos->man, 21+1, "1#INF")
strcpy_s(fos->man, 21+1, "1#IND")
strcpy_s(fos->man, 21+1, "1#SNAN")
$I10_OUTPUT
f:\dd\vctools\crt_bld\self_x86\crt\prebuild\conv\x10fout.c
VS_VERSION_INFO
045816E5
Versus
7.3.40.83
Version
27.8.42.57
VarFileInfo
Translation
,Gixihazab bafe fad wemohizebova fiwicitosalaHMutivigixil suvoxidaregali ciziginaya tihumitus zedejebova diy dowitamefMTokoke xepihocinikoz kagihaluris kuyonaliwusarel wirobugebo fayen goduguxiwuc6Mufo folaxovoful yediwuzebeguw lobavawive biburicivuti
Xuroduguvonise
8Hicutize kuwezi kukozisoziheme mideyevociz pesejawelelezDGaxejicahorim nekuxoyizekef kavusujo fecogifolof nodakon tokuduwahac8Paholexavesu niwokadoj soriwatimika mefanuni pijek muhedQTupofekamoru hutedayosod radec semedokel kokuyeyu vuhewu wuyeguripizuc hawulizupa
FNanas sacivef lij micivelec koyoc xafiwi cem cukecidoy korasuxuwolekek@Ragixes zebu jipitereliker mefaj yidor vomu gafefi mibudomoducumnGomayuka divawuvosonolob bucivimir gicu vexaranojoj wosolorejavapos fazusogazub dowavuhonex jik fumecucizuwonaSDodoyatiref cekunutom jemidaferevizu govo momafemeziho giluhepiyorahe mometomemadof6Fiwibunojurezun gowikurepilayux romizof gacohubaxisewe<Vipifipili dizakaxudug wisi bekoculokeci nigese pudunopahuva
Music Make
Music Make
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.73ca4c10afa6a3f7
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Trojan.MalPack.GS
VIPRE Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
BitDefenderTheta Gen:NN.ZexaF.34088.wqY@aGADHfcK
Cyren W32/Kryptik.EYC.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/GenKryptik.FJLH
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan.Win32.Brook.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Trojan.DownLoader41.25700
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Emsisoft Clean
Ikarus Clean
Jiangmin Clean
eGambit PE.Heur.InvalidSig
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Win32.Packed.Kryptik.3ALHY6
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
TACHYON Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik!1.C6FC (CLASSIC)
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet W32/Kryptik.EYC!tr
Webroot W32.Malware.Gen
Panda Clean
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.