Static | ZeroBOX

PE Compile Time

2020-04-08 09:06:05

PDB Path

C:\rilikasah\pufapimiwisa\nekoyawo\jeruc67.pdb

PE Imphash

a9e1103bbc08b87eea5d7311fb0b7c3e

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001758b 0x00017600 6.24877155
.rdata 0x00019000 0x00008214 0x00008400 4.58142275985
.data 0x00022000 0x0047d6a0 0x00050a00 7.97888096047
.rsrc 0x004a0000 0x00005ec0 0x00006000 5.33532494137
.reloc 0x004a6000 0x00005a42 0x00005c00 2.37987059517

Resources

Name Offset Size Language Sub-language File type
AFX_DIALOG_LAYOUT 0x004a4088 0x00000002 LANG_MONGOLIAN SUBLANG_DEFAULT data
PAMIFEGIHURULUFUKIYUVUWOGULOJOK 0x004a3910 0x000006f0 LANG_MONGOLIAN SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
RT_CURSOR 0x004a54d0 0x000008a8 LANG_MONGOLIAN SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x004a54d0 0x000008a8 LANG_MONGOLIAN SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x004a54d0 0x000008a8 LANG_MONGOLIAN SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x004a54d0 0x000008a8 LANG_MONGOLIAN SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x004a54d0 0x000008a8 LANG_MONGOLIAN SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_ICON 0x004a3448 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x004a3448 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x004a3448 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x004a3448 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x004a3448 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x004a3448 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ACCELERATOR 0x004a4000 0x00000068 LANG_MONGOLIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x004a5d78 0x00000014 LANG_MONGOLIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x004a5d78 0x00000014 LANG_MONGOLIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x004a5d78 0x00000014 LANG_MONGOLIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x004a38b0 0x0000005a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x004a5d90 0x00000130 LANG_MONGOLIAN SUBLANG_DEFAULT data
None 0x004a4078 0x0000000a LANG_MONGOLIAN SUBLANG_DEFAULT data
None 0x004a4078 0x0000000a LANG_MONGOLIAN SUBLANG_DEFAULT data

Imports

Library KERNEL32.dll:
0x41900c FreeLibrary
0x419014 GetCommState
0x419018 GetProfileStringW
0x41901c CallNamedPipeW
0x419020 GetNumberFormatA
0x419024 GetCommandLineA
0x419028 FindResourceExA
0x41902c GlobalAlloc
0x419040 HeapDestroy
0x419048 GetSystemDirectoryA
0x41904c CreateActCtxA
0x419050 GetBinaryTypeW
0x419058 LCMapStringA
0x41905c GetStartupInfoA
0x419060 SetThreadLocale
0x419064 GetStdHandle
0x419068 CopyFileExW
0x41906c GetLastError
0x419070 SetLastError
0x419074 GetProcAddress
0x419078 CreateNamedPipeA
0x41907c SearchPathA
0x419080 LoadLibraryA
0x419084 OpenMutexA
0x419088 CreateSemaphoreW
0x41908c FindAtomA
0x419090 SetSystemTime
0x419094 GetModuleFileNameA
0x4190a0 HeapSetInformation
0x4190a8 FindNextFileW
0x4190b0 SetFileShortNameA
0x4190b4 TerminateJobObject
0x4190b8 FindAtomW
0x4190bc UnregisterWaitEx
0x4190c0 DeleteFileA
0x4190c4 lstrlenA
0x4190c8 GetCPInfoExW
0x4190cc GetThreadContext
0x4190d0 CloseHandle
0x4190d4 CreateFileW
0x4190d8 WideCharToMultiByte
0x4190dc EncodePointer
0x4190e0 DecodePointer
0x4190e4 GetCommandLineW
0x4190e8 GetStartupInfoW
0x4190f0 GetModuleHandleW
0x4190f4 ExitProcess
0x4190f8 TerminateProcess
0x4190fc GetCurrentProcess
0x419108 IsDebuggerPresent
0x41910c GetModuleFileNameW
0x419110 WriteFile
0x419114 GetACP
0x419118 GetOEMCP
0x41911c GetCPInfo
0x419120 IsValidCodePage
0x419124 TlsAlloc
0x419128 TlsGetValue
0x41912c TlsSetValue
0x419130 GetCurrentThreadId
0x419134 TlsFree
0x419138 HeapValidate
0x41913c IsBadReadPtr
0x419144 GetTickCount
0x419148 GetCurrentProcessId
0x419154 SetHandleCount
0x41915c GetFileType
0x419164 HeapCreate
0x419170 LoadLibraryW
0x419178 OutputDebugStringA
0x41917c WriteConsoleW
0x419180 OutputDebugStringW
0x419184 RtlUnwind
0x419188 LCMapStringW
0x41918c MultiByteToWideChar
0x419190 GetStringTypeW
0x419194 HeapAlloc
0x419198 HeapReAlloc
0x41919c HeapSize
0x4191a4 HeapFree
0x4191a8 SetFilePointer
0x4191ac GetConsoleCP
0x4191b0 GetConsoleMode
0x4191b4 RaiseException
0x4191b8 SetStdHandle
0x4191bc FlushFileBuffers
Library ADVAPI32.dll:
Library WINHTTP.dll:
0x4191c4 WinHttpOpen

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
r"j}h8
URPQQh
}'h@+B
;t$,v-
UQPXY]Y[
PPPPPPPP
PPPPPPPP
f:\dd\vctools\crt_bld\self_x86\crt\src\onexit.c
CorExitProcess
f:\dd\vctools\crt_bld\self_x86\crt\src\mbctype.c
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
f:\dd\vctools\crt_bld\self_x86\crt\src\tidtable.c
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
Client
Ignore
Normal
Error: memory allocation: bad memory block type.
Invalid allocation size: %Iu bytes.
Client hook allocation failure.
Client hook allocation failure at file %hs line %d.
Error: possible heap corruption at or near 0x%p
The Block at 0x%p was allocated by aligned routines, use _aligned_realloc()
Error: memory allocation: bad memory block type.
Memory allocated at %hs(%d).
Invalid allocation size: %Iu bytes.
Memory allocated at %hs(%d).
Client hook re-allocation failure.
Client hook re-allocation failure at file %hs line %d.
HEAP CORRUPTION DETECTED: after %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory after end of heap buffer.
HEAP CORRUPTION DETECTED: after %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory after end of heap buffer.
Memory allocated at %hs(%d).
HEAP CORRUPTION DETECTED: before %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory before start of heap buffer.
HEAP CORRUPTION DETECTED: before %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory before start of heap buffer.
Memory allocated at %hs(%d).
Client hook free failure.
The Block at 0x%p was allocated by aligned routines, use _aligned_free()
%hs located at 0x%p is %Iu bytes long.
%hs located at 0x%p is %Iu bytes long.
Memory allocated at %hs(%d).
HEAP CORRUPTION DETECTED: on top of Free block at 0x%p.
CRT detected that the application wrote to a heap buffer that was freed.
HEAP CORRUPTION DETECTED: on top of Free block at 0x%p.
CRT detected that the application wrote to a heap buffer that was freed.
Memory allocated at %hs(%d).
DAMAGED
_heapchk fails with unknown return value!
_heapchk fails with _HEAPBADPTR.
_heapchk fails with _HEAPBADEND.
_heapchk fails with _HEAPBADNODE.
_heapchk fails with _HEAPBADBEGIN.
Bad memory block found at 0x%p.
Bad memory block found at 0x%p.
Memory allocated at %hs(%d).
Object dump complete.
crt block at 0x%p, subtype %x, %Iu bytes long.
normal block at 0x%p, %Iu bytes long.
client block at 0x%p, subtype %x, %Iu bytes long.
{%ld}
%hs(%d) :
#File Error#(%d) :
Dumping objects ->
Data: <%s> %s
Detected memory leaks!
f:\dd\vctools\crt_bld\self_x86\crt\src\stdenvp.c
f:\dd\vctools\crt_bld\self_x86\crt\src\stdargv.c
f:\dd\vctools\crt_bld\self_x86\crt\src\w_env.c
f:\dd\vctools\crt_bld\self_x86\crt\src\ioinit.c
f:\dd\vctools\crt_bld\self_x86\crt\src\mlock.c
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
%s(%d) : %s
Assertion failed!
Assertion failed:
_CrtDbgReport: String too long or IO Error
, Line
<file unknown>
Second Chance Assertion Failed: File
_CrtDbgReport: String too long or Invalid characters in String
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
Assertion Failed
Warning
Microsoft Visual C++ Debug Library
Debug %s!
Program: %s%s%s%s%s%s%s%s%s%s%s%s
(Press Retry to debug the application)
Module:
File:
Line:
Expression:
For information on how your program can cause an assertion
failure, see the Visual C++ documentation on asserts.
<program name unknown>
f:\dd\vctools\crt_bld\self_x86\crt\src\output.c
bad exception
GetUserObjectInformationA
MessageBoxA
(null)
`h````
xpxxxx
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
f:\dd\vctools\crt_bld\self_x86\crt\src\_getbuf.c
f:\dd\vctools\crt_bld\self_x86\crt\src\_file.c
Unknown exception
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
nazirebecove
Decexiyomas pagiduyinuk rel
jelecawureyojiwiz
cacopisocalelav lubofunikaremufunopi wecatanebuneboneporohuhag
kernel32.dll
gupaseyexudipatixiyohuje
vulumofuxifafayusafakayajitu
solufitow
xizanilifelorizifadedozuyov ruwimepozowopocoxuc cejezovewevocelalixenihuvol
dehufozidizuledulutanen mabigumilujudonihinimuvuved canabi
vozibulojejuco
lizifesuhazosisigilapizokeyaki
gezaxodisatobo
Zuwexukasivemut
Hofepuf
Sajote lel higo sowizibaj yuke
yobuwexogu
cegivikatohunuyowas
cereberififezumezoparusunakutiyetihetugibepaarepocokeyiluzidulewupoja
jurayisotiharuyexarule
RSDSKU;
C:\rilikasah\pufapimiwisa\nekoyawo\jeruc67.pdb
GetThreadContext
lstrlenA
CopyFileExW
FreeLibrary
InterlockedIncrement
GetCommState
GetProfileStringW
CallNamedPipeW
GetNumberFormatA
GetCommandLineA
FindResourceExA
GlobalAlloc
GetPrivateProfileIntA
GetVolumeInformationA
GetSystemWow64DirectoryW
GetSystemWindowsDirectoryA
HeapDestroy
GetCompressedFileSizeA
GetSystemDirectoryA
CreateActCtxA
GetBinaryTypeW
WritePrivateProfileStringW
LCMapStringA
GetStartupInfoA
SetThreadLocale
GetStdHandle
GetCPInfoExW
GetLastError
SetLastError
GetProcAddress
CreateNamedPipeA
SearchPathA
LoadLibraryA
OpenMutexA
CreateSemaphoreW
FindAtomA
SetSystemTime
GetModuleFileNameA
CreateIoCompletionPort
FindFirstChangeNotificationA
HeapSetInformation
FreeEnvironmentStringsW
FindNextFileW
GetCurrentDirectoryA
SetFileShortNameA
TerminateJobObject
FindAtomW
UnregisterWaitEx
DeleteFileA
KERNEL32.dll
InitiateSystemShutdownA
AbortSystemShutdownA
ADVAPI32.dll
WinHttpOpen
WINHTTP.dll
WideCharToMultiByte
EncodePointer
DecodePointer
GetCommandLineW
GetStartupInfoW
InterlockedDecrement
GetModuleHandleW
ExitProcess
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetModuleFileNameW
WriteFile
GetACP
GetOEMCP
GetCPInfo
IsValidCodePage
TlsAlloc
TlsGetValue
TlsSetValue
GetCurrentThreadId
TlsFree
HeapValidate
IsBadReadPtr
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
GetEnvironmentStringsW
SetHandleCount
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
HeapCreate
EnterCriticalSection
LeaveCriticalSection
LoadLibraryW
IsProcessorFeaturePresent
OutputDebugStringA
WriteConsoleW
OutputDebugStringW
RtlUnwind
LCMapStringW
MultiByteToWideChar
GetStringTypeW
HeapAlloc
HeapReAlloc
HeapSize
HeapQueryInformation
HeapFree
SetFilePointer
GetConsoleCP
GetConsoleMode
RaiseException
SetStdHandle
CreateFileW
CloseHandle
FlushFileBuffers
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
5kP!(1K
+~D-Xt[K
Y/0+x_
|UOHF!
4TT>%xu
Styu>W
kOBt,
9%Ym!2
\IeZ&Bn
E2I9bi
)0t7b@
Bq*k75z.%
Fk/$!9
aZCR(R
;|/z!m!
$C]1>B
6ctkG-
s31 t}
WIO#vr\`
ay:*X{>gw
]%&&Dq
1P$.LC
tRoW)
4K,Aa{
K#C;/GJY
%-v+T'
t@r0kC
Z ]Y~A7GsvG
W2Z-QmN
uZ4`qY+q
M<8"|`
i2h5y8
Pvlorr%
|GqLth
VEuQp3
sP;) a?^
!}io!7P
q[.P[
(tTLN'
!w]wM8
&zp`.O
\007At
[}n}OO
A&qyXa
cpR*:[
{bi|Cc
B!NITQ
DJj5aWC
=2ca[aj;
T@R-$E
fwNo%:
&Pie_H
ps4*b
%@7$fU
m2iyBz
u-!90g
ZjS\]lO
8y%Q 4
jY{k"e,
%wKS?['+C
m*3ld
$#MgrPm6
1Wk)yb
\3mAmL
QcWy_Ic
\e"I<D
#7vk|l[v
%upDA)Cj
$8cl.%2R
wt'xlmX!6f
/V$Plg
rku"vM=f+Q_
ZqH-uG/M
QZ80de
rf;ll>
y6ugRF
^a yV!
+4qQk`
?qYa[k
LCE>zO
M|7"*3
`Hm>U6
c*`<Ut
rh6QtB
iP6blgwz
FKbC\)
a Loh%
\fRHd
vUCO'@/
NT>-/G
A"DBO?
M|#VAn{9
ujV`N3
>u$rRw6
<7oWx4(,
&`8^4Z
~&V)#C~
OF;mD\Xp
[s2QV/
|`RL%,
*}04gzg
@#N2:-
s~=+p~
&0h"~
_^c{}<
v^HC1)
_!i!#uI
&^+"o=
?{o5==
ol{dZ/
fD_z_X
fl{shb
w M-t|
qM82w
>Ui<Pz
1j|e*$
nC$jq
'{gV]oO
d9lRRx
{h3g >
loi,IC
{W>K#m
X65+m^
th|:(
bXt`K
z{~mGb
%IGNIC
.;c7Ya
b#%&hja=
u9Y1M
f]5&a'U
hNtblf
u]V'?yEU
DA6Xw~
aYD@A1
+`Q#k!
vohTB5.
V{Lb^.e
XA'{#aT
hao->$
uk=W<Z
qV%f^5
:]//!=
&m&;\W
Giul %m
09ZQ}z
QF6]7n
Pz-3N^9r
Ga4<,E_]GJ
f]_[g;
UeC%aG
}cf8Xh2
CV[Jd@
3=G|s#m
JR|-d@r
$x$#x?B
X46Q[.Y
ixB(HF1
mE5qip
gY;;nX
HDl.CDG
0.;p0|kz
F)Gz6 k
DtCM]c
C,wZ[+n(SU
;6-107
X:# yR
{j~}:X
zHb A]
g>cCQ#Uz
d# 6ddE
:!kKg<
onDkJE
+U0Nua
LQ:X'j
7I)ui.j
Wgw(".}
B,d#]w
}47L0Fx
D#r8!Y
~D-Az9H
#UO!NAk
:^.dw_
uZB!CJ
]9!]4X
'MK^f=^
&]NRwQ
Lx%<8d
G3Rx<{k
07]HO`P6
P?bOx1
kS]gh=d
%/'+H]#
T,IFvK!
N5UqOGX
<XET@6mu
jmoaz|
6oc}/c
=@?V)b
9=+,J=
s&jHRT
:h\?a
?tqN*'
rt*o8V
`9CdFbW
P)J}dH
P?|M[T
y]qPI\
G3!%/
K7Lvk0
bln |Gx
7ZvD:vx
5U'cr_\QI68
i>6!e>X
GuSO(n
.(/%QFiOe
6b4dShx
E=\6xc
h!C$,CF(y
Px)ACw
$t`+Q;
C'aj6Ga
pc8?A#)
|TT<B^
K=gk2|
[*"{pX
<eiD{H
K^,[[
.GnxT
Ob/T:Q
\xKR4f
OCA%HJ
YDzJk;
w;RF9X
[\~k&S
':%WF'
[ZcxMe\
|ekaZH
u1Qo%`
(v'qFY
J?kpy
pbDzFwb
>,z jB
[WD&EM
bQSG;
umsP=Y1
7-~E)S\
eXB^f"
p `V3J
zLH3IT
v%!X8C
2v&T[MS/)
\$)=78
\.%;kRdd
q_6~0`
)Fs#!X
W,|-{f
N:WU!zG
nM"M/h
qy6:$D'
x5UWJ?a
U>WmvX
W b4fo.|
D*irOi
CByfoq
Vqs>m8
oPf1!m
YWqLBw2K
3_m$b8
HG\;${a
a}N*>g7
toxUva
{&4#(\
7q@o*i
+<kBkg
x#2|&$3/LG
!L2x[y'I
UX,iMjK
w,{eo9
^M4!>0
n\]o-i
i/#SAy
w3gX.}$
^@;O+e
m!~IP3
dvI4Mk
[rkc.:
lsnkja
'~3j*6
>@G)}a
+6eT+
x\4:KE
9'H"rc
Q1-C@E
9u\8u_
C,`s\1X
lA%Wh5S
"WbTT4
KE6v]&F3
Z&JN a
w6y(I$9XS>
,_K5#V
6-t7g"
OaS|A"
Q<;Ryp
zz&A_{m
;o^VE}+
3N,V$c
#>28u,
|xn}+o
K\h"R#8
6]!)~0&
oiQ9Z*
o-B9{[
PvCTR?
ya^(5W
Rh.a A
dTZSdz
/Zy[c;}
mOhNrVHv
0!gc@
p`eJXP
vp}<DB
G'~7%%{j
C"gT5
io51[W
wBU^~]!
%7,8|*
p\":l.
<2hN*Y]
*&2G2g
l|}]N|CyXB
*,@C.gC
bc5?m0
xA9e _m
UqVw2P/&
Tlwm8
zL-,pE
x eWWnf$
9J>~UEMt
iRvf5cI
Gel?SM
eA$iD.Z
xG w-9j
!g4!FqP
XK6%VW>
OsgT"I|
a* WG8Q
AgFS0u#
J7FA-U
)HRn*E
J~1Z{"
<>N+)<K
/?5DA
gt#o<L
^N"UBMiK
,eyx{g
r.Ss2Wz
I*%0f]/
VZ6LN$
/bnkkM
Xfc@!F
f(Luh32
EA\Gn
!*^^Ief
N.?kB<
c(@G|8
^4\j^&
DSbLN3P
C 4FOD%
yg/RLZ
WQhF#!
]uF'Q,SGT[
>VLf<Js
rCkD_s
!ozJpa
X=,K|)
KT+5i*
i9:kQ[
f%2w:P
m1/0Mn
OlTCh8
$AB!R]
`5e0ph
r'2hbV
tnp?e
%V4d;[c
PA,S~k
M9u<x
qo=_.:
j<ygJ
C+q0r+
J%(T,^u
3o~v}w
`#i;Ge
kjN'da
`55Rp8{
slc8hh
87$6a
q(7XG'p
bDP8g
S;G28d
Mm)%s5 ~
!&sU>d
d1[u|#
BIFD|b
6|3I1\3%=
CQs_t`
@p7(fj
jN|c>:p/LvC#
~5%&Mf
BC4:~N10.
$Cq;cuw
{5+")S
%YP#+L
6VYDL@CX)
{$|I Rh
1i.EV rm
Xh$WvK
`iD$ U+
PtFyL Z
8cT-uaH%o
pY:n%~
H/x[|:
-G@9jn
qO}~wB
;s7W&/
Xw-b@
)X7FPJ\
~KB,}0
;+],71;
]8iPVzZ
:q3^wB\@/:
v{adUr
,~SUnr"
3t/6zt98
Z6G#~iv
JTC<.nb
dst7>5$
L@b_;G
ah$>L!
nH^MfAxd0;
kt){Y}
0tK"[VW<RH=G6<
4MH_G7
@19np<
^pj}IH|
!p!Kx`
z\$`iR
U+(=A&
wPKab,
au[Trr
eLfxk5
w;#U-Xs
Ym+7<lb
ky]d{z
#K7}uE
\eIPi/
d2-<U8;
){{!h8
Jt(6&t82
&QDOZt=
,H Vtf+
34?&kc
atU;TNh*
[A(WIX$
,GNS3%
E28"mwD,
ba^haA
,~k7,|
:QURP*
9c<;k'
qSdzSg*
|KLq]e.
_jGb:B
-`/o"mMo
9G)4$HdrxI
+8<aVu
LgpAqO
U|F'OP
^Q.QQ_z(
T\#&Pf
j(7teP
d_Thnx
/M@/dC
$Phd6m(
#*+B<Z
^TSuOx
QSjuF?
gK2`KU
I@{dmn
$sjpZ6
_/1uP"
ZM`(8
qZmk[Rgn`
Q68l3W
%vo>,k{
fAm[u$
qb'rkO
{>|K>
GSKx4I(
~2]ij=
wE jwK
.o1Bg/
c5<[wK
e$gl1!
$E a(Z\
~5D*ZI}
Q;._KyX
] A0E#30
4|Tzy@
Enk!tJJ
yzDPvH
o<!UuG
M{TH*X
{/Te="x^
#-x4 [
`D#j?y
\Jw6yx*
s~tUgY
~:D,n&
:fg.@n
L\(l[R]p
j!7R9-
>YF6?73i>bu{
xikoOi
-O_|*]8
mQMSY\
[ qo-;y
/[RxsKk
d&Go?Kxlm
,oqFn
B[YxM#}
)a[S/O
<w3eb#[
"#ihqn
d;(Ds
KC0n(%
gmzqn
VL|8;5%a
p|ThQ]
EB8\;Z
Ae|?CN
&(fT2:
J!uHzDFL
9d@'J6=
847sxn\V
DzVkvL
13n)C7
V?`tFI
fnVwQ>
sA~?4OU{
yYQRrI
.ZHMY
?X^b="65
d!mV4\
`N_Bsu
3%qC`#2
m5=.uO,"~
a?NK&K~
vd.]tk%
N#0c$-L
_,5?0X
]jEL7 ]$
vr^j]S
Tq$=!
H`P?b
M3XSeZ^
2[Ww]%q
0]--m0
oI(U_
Bqz!<Ig
ns"-_j
RpA6g2C
z7l_ZQ
,U3[kl
6.P&[]
w>[.YS
;j-"tqo/
Q|2Z8[
4^+Li#~
\'#Cfp8F
r}6}|l
h/ISK.
T\8.d,
((((((((((((((((
cccccc
d(((d(dd(dd(d(d
pppppppppppppp
===yyyyy=pp
yy7777ww
yy7777wwww
333333A0
AAAAA30
[00A[[[[[[0
Is|||||||||||
rrrrrrrr
r+/)))))))))+r
r+//////////+r
Bed yicexukuji budujugenolaxo habi. Tajayuladud hedova peyimibipef. Migu rov. Zefidodixo yototokeraluten zoy cipowerir. Rotiluci yehudoxabipibig hecesojuzap faxomos. Hute. Pimix ruyovucaso lilofohezomifib. Xudohazo vebak tukobirexu. Romove nijadokakowijoz wizokeyak guxayubusuwowub. Vizewalu jedonicawi xidibalevak pibi terisod. Zih zirud buzidowume niwafopinixofed. Dafowabah zamibafakoruja. Dolorugokuh padu dazegibifo. Pomivimejalowap fak kazesacofaxudex diduxugigomi fos. Vidupudotewiy fewuzewexuliy xeciluho yedufutoni zofoyonif. Hafoxuju petewinuda depurupatil puvenoduw. Hopahiku wafey cepevixep. Vope. Xujisu kebegavaba. Wosegagir. Rojuti yucimevug xeduxow bep kajapijus. Jaxuviziyurag hapiru. Wocaxuyamicote fonanarijep. Narajuz vuxozavocepor. Bojavededageji madan vuriya tiputaz. Lega musunex. Wac. Vorowon zanizek gubavageverapur liya. Buracu wusikocuhi bumizadon. Buzisamo bilazin. Kewifu wuyi rixobenale pulisiniwi gesuyojigebajel. Sefo. Jehop savapifacufatod cuzotagenan. Firosacahuna dito. Kipudarehuf. Wimow.
485=5O5
6,7G7L7R7X7
98:@:V:c:h:
<%<6<G<N<]<g<u<z<
=)=9=@=S=Z=
=!>&>3>8>F>^>
90G0T0
1)222;2C2X2]2o2
4,5054585<5@5
88)8]8m8r8w8|8
8)9.93989B9_9d9i9w9
<@<P<U<Z<_<
<K=W=v=
>*>V>r>~>
>)?.?3?f?k?p?u?
80=0O0r0
0H1M1_1
2 2I2^2
2*32393C3G3P3b3l3
3#434=4b4l4
=8=T=p=
>'>F>b>~>
4)43484=4G4L4Q4[4`4e4o4t4z4
55%5,51565=5B5\5b5i5p5v5
6%6/686?6E6h6m6
< <6<B<K<P<Y<e<n<
=>*>3>;>D>L>R>X>`>f>l>t>
H0M0_0?1H1Q1a1m1
353r3~3
5&5,5Q5m5
6&6B6`6j6v6
6h7p7y7
7&8A8M8R8
:$:\:b:
;1;:;?;e;o;{;
;'<H<M<_<
="=.=7=]=i=
?,?1?N?S?p?u?
*060?0
3;3G3t3y3~3
676[6f6
6+707Y7
;!;&;^;
<6<m<.=6=N=o=
? ?(?7?L?X?d?t?
2A2K2R2
2.3M3S3d3
314@4S4
9(9P9V9j98:K:g:|:
=$=+=>=T=[=n=
-0<0F0^0e0s0
1*171D1X1]1o1
3(3-3?3
6 6$6(6,606z6
77$7(7,7M7w7
8 8$8(8
9 9%9I9x9
::%:-:7:>:C:I:T:^:e:n:u:
=A=j=s=
=!>(>U>~>
1-252b2
9+919L9Y9^9d9q9v9|9
:8:=:B:G:z:
; ;%;*;S;X;];b;
;3<8<=<B<m<r<w<
=!=&=I=R=
>$?+?5?G?Q?o?t?y?
(0-0F0
1-12171_1e1
1"2'2,2b2g2l2q2
343E3J3O3T3}3
4"4'4]4b4g4l4
4,51565;5^5g5
7!7(7c7j7y7
88Z8a8k8}8
92:;:e:j:o:
223>3S4
<"<X<w<
=1=P=o=
121B1N1i1y1
::&:-:4:;:C:K:S:_:h:m:s:}:
:I<R<|<
<J=r=b>
1-292f2k2p213:3d3i3n3
3)4.434
54595>5
6B6G6L6
7D7I7N7
8$9)9.9n9u9
:2:7:<:y:
? ?%?g?
1 1%1b1j1k2t2
4=4B4G4
5J5O5T5
696>6C6l7
8?:D;P;};
;6<B<o<t<y<
>?+?X?]?b?
0"1'1,1
5$5N5S5X5}5
5B6K6u6z6
587=7O78:=:O:
0(141:1O1Y1s1x1}1
455O5X5
61666;6
7$7j7v7
7.83888
:P;W;e<l<
2)202_2f2
81868;8
9 9$9(9,9094989<9@9D9H9L9P9T9<<
<-=9=i=n=s=
4%5*5/5
= =$=(=,=0=4=8=<=@=D=H=L=P=h=l=p=t=x=
0S0X0]0
2!3D3M3
5$6)6.6T6
859i9s9
<4=>=h=
?0H0^0g0t0+1N1W1
2!2*282B2P2V2
3-3>3X3a3k3
>*?\?t?{?
0 0j0p0t0x0|0
313U3a3
3'4J4V4
55$5G5h5m5
526=6w6
6A7O7^7t7
7X9]9o9
:/:Y:m:
?'?0?8???X?]?o?
2<2T2]2
4Q4t4}4
585=5B5{5
5 676m6
8)80878>8E8L8S8Z8b8j8q8z8
9!9&9,949<9A9M9R9[9
:3:9:L:R:
=?=E=c=m=
=>>H>N>Z>o>}>
?$?*?@?J?Y?h?y?
0A0S0Y0a0q0y0
1!10161G1
2#212n2t2
3$3.3b3p3
4-4:4G4N4S4[4
5"5'5-5Z5
=$=,=4=<=D=L=T=\=d=l=
45H5L5P5
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
9 9$9(9,9094989
1,10181P1`1d1
282X2`2l2
303P3p3
404L4P4l4p4
585@5D5`5h5l5
7(7H7h7
7 7$7(7,7074787<7@7D7H7L7P7T7X7h7l7p7t7x7|7
8X9\9`9d9h9l9p9t9x9|9
; ;$;(;,;0;4;@;`;
Ajjjjjjj
jjjjjjj
Ajjjjj
Ajjjjj
("Buffer too small", 0)
sizeInBytes > 0
_wctomb_s_l
f:\dd\vctools\crt_bld\self_x86\crt\src\wctomb.c
sizeInBytes <= INT_MAX
mscoree.dll
f:\dd\vctools\crt_bld\self_x86\crt\src\winsig.c
("Invalid signal or error", 0)
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
AMicrosoft Visual C++ Runtime Library
wcscat_s(outmsg, (sizeof(outmsg) / sizeof(outmsg[0])), error_text)
wcscat_s(outmsg, (sizeof(outmsg) / sizeof(outmsg[0])), L"\n\n")
wcsncpy_s(pch, progname_size - (pch - progname), L"...", 3)
<program name unknown>
wcscpy_s(progname, progname_size, L"<program name unknown>")
Runtime Error!
Program:
wcscpy_s(outmsg, (sizeof(outmsg) / sizeof(outmsg[0])), L"Runtime Error!\n\nProgram: ")
_NMSG_WRITE
f:\dd\vctools\crt_bld\self_x86\crt\src\crt0msg.c
Assertion Failed
Warning
Af:\dd\vctools\crt_bld\self_x86\crt\src\dbgrpt.c
Microsoft Visual C++ Debug Library
_CrtDbgReport: String too long or IO Error
wcscpy_s(szOutMessage, 4096, L"_CrtDbgReport: String too long or IO Error")
(*_errno())
Debug %s!
Program: %s%s%s%s%s%s%s%s%s%s%s%s
(Press Retry to debug the application)
Module:
File:
Line:
Expression:
For information on how your program can cause an assertion
failure, see the Visual C++ documentation on asserts.
memcpy_s(szShortProgName, sizeof(TCHAR) * (260 - (szShortProgName - szExeName)), dotdotdot, sizeof(TCHAR) * 3)
wcscpy_s(szExeName, 260, L"<program name unknown>")
__crtMessageWindowW
f:\dd\vctools\crt_bld\self_x86\crt\src\localref.c
((ptloci->lc_category[category].wlocale != NULL) && (ptloci->lc_category[category].wrefcount != NULL)) || ((ptloci->lc_category[category].wlocale == NULL) && (ptloci->lc_category[category].wrefcount == NULL))
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
KERNEL32.DLL
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgheap.c
_CrtCheckMemory()
_pFirstBlock == pOldBlock
_pLastBlock == pOldBlock
fRealloc || (!fRealloc && pNewBlock == pOldBlock)
pOldBlock->nLine == IGNORE_LINE && pOldBlock->lRequest == IGNORE_REQ
_CrtIsValidHeapPointer(pUserData)
pUserData != NULL
_pFirstBlock == pHead
_pLastBlock == pHead
pHead->nBlockUse == nBlockUse
pHead->nLine == IGNORE_LINE && pHead->lRequest == IGNORE_REQ
_BLOCK_TYPE_IS_VALID(pHead->nBlockUse)
_msize_dbg
_CrtSetDbgFlag
(fNewBits==_CRTDBG_REPORT_FLAG) || ((fNewBits & 0x0ffff & ~(_CRTDBG_ALLOC_MEM_DF | _CRTDBG_DELAY_FREE_MEM_DF | _CRTDBG_CHECK_ALWAYS_DF | _CRTDBG_CHECK_CRT_DF | _CRTDBG_LEAK_CHECK_DF) ) == 0)
_CrtMemCheckpoint
state != NULL
_printMemBlockData
wcscpy_s(*env, cchars, p)
_wsetenvp
f:\dd\vctools\crt_bld\self_x86\crt\src\stdenvp.c
_set_error_mode
f:\dd\vctools\crt_bld\self_x86\crt\src\errmode.c
("Invalid error_mode", 0)
WUSER32.DLL
(L"Buffer is too small" && 0)
Buffer is too small
(L"String is not null terminated" && 0)
String is not null terminated
(((_Src))) != NULL
wcscat_s
f:\dd\vctools\crt_bld\self_x86\crt\src\tcscat_s.inl
((_Dst)) != NULL && ((_SizeInWords)) > 0
wcsncpy_s
f:\dd\vctools\crt_bld\self_x86\crt\src\tcsncpy_s.inl
wcscpy_s
f:\dd\vctools\crt_bld\self_x86\crt\src\tcscpy_s.inl
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgrptt.c
_CrtDbgReport: String too long or Invalid characters in String
wcscpy_s(szOutMessage2, 4096, L"_CrtDbgReport: String too long or Invalid characters in String")
e = mbstowcs_s(&ret, szOutMessage2, 4096, szOutMessage, ((size_t)-1))
strcpy_s(szOutMessage, 4096, szLineMessage)
strcpy_s(szOutMessage, 4096, "_CrtDbgReport: String too long or IO Error")
strcat_s(szLineMessage, 4096, "\n")
strcat_s(szLineMessage, 4096, "\r")
strcat_s(szLineMessage, 4096, szUserMessage)
strcpy_s(szLineMessage, 4096, szFormat ? "Assertion failed: " : "Assertion failed!")
strcpy_s(szUserMessage, 4096, "_CrtDbgReport: String too long or IO Error")
_itoa_s(nLine, szLineMessage, 4096, 10)
_VCrtDbgReportA
wcstombs_s(&ret, szaOutMessage, 4096, szOutMessage, ((size_t)-1))
strcpy_s(szOutMessage2, 4096, "_CrtDbgReport: String too long or Invalid characters in String")
wcstombs_s(((void *)0), szOutMessage2, 4096, szOutMessage, ((size_t)-1))
wcscpy_s(szOutMessage, 4096, szLineMessage)
%s(%d) : %s
wcscat_s(szLineMessage, 4096, L"\n")
wcscat_s(szLineMessage, 4096, L"\r")
wcscat_s(szLineMessage, 4096, szUserMessage)
wcscpy_s(szLineMessage, 4096, szFormat ? L"Assertion failed: " : L"Assertion failed!")
Assertion failed!
Assertion failed:
wcscpy_s(szUserMessage, 4096, L"_CrtDbgReport: String too long or IO Error")
, Line
<file unknown>
Second Chance Assertion Failed: File
_itow_s(nLine, szLineMessage, 4096, 10)
_VCrtDbgReportW
(format != NULL)
sizeInBytes >= count
src != NULL
memcpy_s
f:\dd\vctools\crt_bld\self_x86\crt\src\memcpy_s.c
dst != NULL
f:\dd\vctools\crt_bld\self_x86\crt\src\malloc.h
("Corrupted pointer passed to _freea", 0)
((((( H
h(((( H
H
strcpy_s(szExeName, 260, "<program name unknown>")
__crtMessageWindowA
_expand_base
f:\dd\vctools\crt_bld\self_x86\crt\src\expand.c
pBlock != NULL
f:\dd\vctools\crt_bld\self_x86\crt\src\isctype.c
(unsigned)(c + 1) <= 256
((_Dst)) != NULL && ((_SizeInBytes)) > 0
G_mbstowcs_l_helper
f:\dd\vctools\crt_bld\self_x86\crt\src\mbstowcs.c
s != NULL
retsize <= sizeInWords
bufferSize <= INT_MAX
_mbstowcs_s_l
(pwcs == NULL && sizeInWords == 0) || (pwcs != NULL && sizeInWords > 0)
strcat_s
strcpy_s
(count == 0) || (string != NULL)
_vsnprintf_helper
f:\dd\vctools\crt_bld\self_x86\crt\src\vsprintf.c
string != NULL && sizeInBytes > 0
_vsprintf_s_l
format != NULL
_vsnprintf_s_l
length < sizeInTChars
2 <= radix && radix <= 36
sizeInTChars > (size_t)(is_neg ? 2 : 1)
sizeInTChars > 0
xtoa_s
f:\dd\vctools\crt_bld\self_x86\crt\src\xtoa.c
buf != NULL
_wcstombs_l_helper
f:\dd\vctools\crt_bld\self_x86\crt\src\wcstombs.c
pwcs != NULL
sizeInBytes > retsize
_wcstombs_s_l
(dst != NULL && sizeInBytes > 0) || (dst == NULL && sizeInBytes == 0)
_vswprintf_helper
f:\dd\vctools\crt_bld\self_x86\crt\src\vswprint.c
string != NULL && sizeInWords > 0
_vsnwprintf_s_l
xtow_s
("inconsistent IOB fields", stream->_ptr - stream->_base >= 0)
f:\dd\vctools\crt_bld\self_x86\crt\src\_flsbuf.c
str != NULL
("'n' format specifier disabled", 0)
f:\dd\vctools\crt_bld\self_x86\crt\src\output.c
(stream != NULL)
A(null)
(ch != _T('\0'))
( (_Stream->_flag & _IOSTRG) || ( fn = _fileno(_Stream), ( (_textmode_safe(fn) == __IOINFO_TM_ANSI) && !_tm_unicode_safe(fn))))
((state == ST_NORMAL) || (state == ST_TYPE))
("Incorrect format specifier", 0)
_output_s_l
_woutput_s_l
("Invalid file descriptor. File possibly closed by a different thread",0)
(_osfile(fh) & FOPEN)
_lseeki64
f:\dd\vctools\crt_bld\self_x86\crt\src\lseeki64.c
(fh >= 0 && (unsigned)fh < (unsigned)_nhandle)
_write
f:\dd\vctools\crt_bld\self_x86\crt\src\write.c
isleadbyte(_dbcsBuffer(fh))
((cnt & 1) == 0)
_write_nolock
(buf != NULL)
f:\dd\vctools\crt_bld\self_x86\crt\src\_getbuf.c
_isatty
f:\dd\vctools\crt_bld\self_x86\crt\src\isatty.c
_fileno
f:\dd\vctools\crt_bld\self_x86\crt\src\fileno.c
f:\dd\vctools\crt_bld\self_x86\crt\src\mbtowc.c
_loc_update.GetLocaleT()->locinfo->mb_cur_max == 1 || _loc_update.GetLocaleT()->locinfo->mb_cur_max == 2
(str != NULL)
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgdel.cpp
_get_osfhandle
f:\dd\vctools\crt_bld\self_x86\crt\src\osfinfo.c
f:\dd\vctools\crt_bld\self_x86\crt\prebuild\eh\typname.cpp
pNode->_Next != NULL
CONOUT$
fclose
f:\dd\vctools\crt_bld\self_x86\crt\src\fclose.c
_fclose_nolock
(_osfile(filedes) & FOPEN)
_commit
f:\dd\vctools\crt_bld\self_x86\crt\src\commit.c
(filedes >= 0 && (unsigned)filedes < (unsigned)_nhandle)
A_close
f:\dd\vctools\crt_bld\self_x86\crt\src\close.c
f:\dd\vctools\crt_bld\self_x86\crt\src\_freebuf.c
stream != NULL
wutasehuluredewivunit
lkadefogabupugoyiguteriwiwexudovinacujobinifeyawuxuhofokutegexilabukihoxonekuhirew
Vevesolukizan waxufi sadeheray
mihekamutuvatikime
fatomifahegohofivonofijot
fiwolap
rinacorakocohamilozub ziyivusovujocatawu
nimelemivorag yejicixumi petozahayamivarosire kapugenoxotef
zuyuyifuhebin
veganapibudita
vonaxacaboxebatayunusi
dahociwawo
rezefehedewudakejufepayemirifec
bewopudokomajehu
PAMIFEGIHURULUFUKIYUVUWOGULOJOK
AFX_DIALOG_LAYOUT
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
055816E7
ProductVers
15.3.10.23
Version
27.8.20.17
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Clean
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Clean
FireEye Generic.mg.82df7652b58044a2
CAT-QuickHeal Ransom.Stop.Z5
McAfee Packed-GDT!82DF7652B580
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.553e5c
BitDefenderTheta Gen:NN.ZexaF.34170.FuW@a0zkIyhO
Cyren W32/Agent.DLJ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
Zoner Clean
TrendMicro-HouseCall Clean
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@ML.91 (RDML:harRcVF4pFGxxDexLm0Jwg)
Ad-Aware Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Emotet.gc
CMC Clean
Emsisoft Clean
Ikarus Trojan-Ransom.FileCrypter
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
TACHYON Clean
AhnLab-V3 Clean
Acronis suspicious
VBA32 BScope.Malware-Cryptor.1691
MAX Clean
Malwarebytes Trojan.MalPack
Panda Clean
APEX Malicious
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_99%
Fortinet Clean
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (D)
MaxSecure Clean
No IRMA results available.