Static | ZeroBOX

PE Compile Time

2020-09-19 09:18:10

PDB Path

C:\nonademup.pdb

PE Imphash

aed329e4dacd07dcd744859ead4f9693

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001d330 0x0001d400 6.33130093357
.rdata 0x0001f000 0x000088e4 0x00008a00 4.75568267978
.data 0x00028000 0x01345388 0x00010e00 7.7738385312
.rsrc 0x0136e000 0x000036f0 0x00003800 5.97797372321
.reloc 0x01372000 0x0000f5f8 0x0000f600 1.13512615821

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x01371118 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x01371118 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x01371118 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x01371118 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x01371118 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x01371118 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ACCELERATOR 0x013715e0 0x00000070 None SUBLANG_DEFAULT data
RT_ACCELERATOR 0x013715e0 0x00000070 None SUBLANG_DEFAULT data
RT_GROUP_ICON 0x01371580 0x0000005a LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x401f000 GetCommandLineW
0x401f004 FileTimeToDosDateTime
0x401f008 GetNativeSystemInfo
0x401f00c TlsGetValue
0x401f010 GetStringTypeA
0x401f014 HeapAlloc
0x401f018 InterlockedIncrement
0x401f01c GetCommState
0x401f020 ReadConsoleA
0x401f024 GlobalSize
0x401f02c GlobalLock
0x401f030 SetHandleInformation
0x401f034 CancelWaitableTimer
0x401f038 GetModuleHandleW
0x401f03c EnumResourceTypesA
0x401f040 ActivateActCtx
0x401f044 LoadLibraryW
0x401f048 TerminateThread
0x401f058 GetSystemDirectoryA
0x401f05c CompareStringW
0x401f060 lstrlenW
0x401f064 SetThreadPriority
0x401f06c DeactivateActCtx
0x401f074 GetPrivateProfileIntW
0x401f078 VerifyVersionInfoW
0x401f07c CreateDirectoryA
0x401f080 InterlockedExchange
0x401f084 SetCurrentDirectoryA
0x401f088 GetStartupInfoA
0x401f08c GetCPInfoExW
0x401f090 GetLastError
0x401f094 GetThreadLocale
0x401f098 GetProcAddress
0x401f09c GetProcessHeaps
0x401f0a0 SetStdHandle
0x401f0a4 EnterCriticalSection
0x401f0b0 LoadLibraryA
0x401f0b4 LocalAlloc
0x401f0b8 SetSystemTime
0x401f0c0 GetOEMCP
0x401f0c4 Process32NextW
0x401f0c8 FindNextFileA
0x401f0cc WriteProfileStringA
0x401f0dc WriteProfileStringW
0x401f0e0 GetCurrentDirectoryA
0x401f0e4 GetCurrentThreadId
0x401f0e8 FindAtomW
0x401f0ec UnregisterWaitEx
0x401f0f0 GetSystemTime
0x401f0f4 GetProfileSectionW
0x401f0f8 LCMapStringW
0x401f0fc CopyFileExA
0x401f100 GetVolumeInformationW
0x401f104 CreateFileA
0x401f108 GetConsoleOutputCP
0x401f10c MultiByteToWideChar
0x401f110 GetStartupInfoW
0x401f114 HeapValidate
0x401f118 IsBadReadPtr
0x401f11c RaiseException
0x401f120 LeaveCriticalSection
0x401f124 TerminateProcess
0x401f128 GetCurrentProcess
0x401f134 IsDebuggerPresent
0x401f138 GetModuleFileNameW
0x401f13c DeleteCriticalSection
0x401f140 InterlockedDecrement
0x401f144 GetACP
0x401f148 GetCPInfo
0x401f14c IsValidCodePage
0x401f150 TlsAlloc
0x401f154 TlsSetValue
0x401f158 TlsFree
0x401f15c SetLastError
0x401f164 GetTickCount
0x401f168 GetCurrentProcessId
0x401f170 Sleep
0x401f174 ExitProcess
0x401f17c SetHandleCount
0x401f180 GetStdHandle
0x401f184 GetFileType
0x401f188 HeapDestroy
0x401f18c HeapCreate
0x401f190 HeapFree
0x401f194 VirtualFree
0x401f198 GetModuleFileNameA
0x401f19c WriteFile
0x401f1a0 HeapSize
0x401f1a4 HeapReAlloc
0x401f1a8 VirtualAlloc
0x401f1ac RtlUnwind
0x401f1b0 WideCharToMultiByte
0x401f1b4 DebugBreak
0x401f1b8 OutputDebugStringA
0x401f1bc WriteConsoleW
0x401f1c0 OutputDebugStringW
0x401f1c8 LCMapStringA
0x401f1cc GetStringTypeW
0x401f1d0 GetLocaleInfoA
0x401f1d4 FlushFileBuffers
0x401f1d8 GetConsoleCP
0x401f1dc GetConsoleMode
0x401f1e0 SetFilePointer
0x401f1e4 CloseHandle
0x401f1e8 WriteConsoleA
Library USER32.dll:
0x401f1f0 GetMenuItemID
Library WINHTTP.dll:
0x401f1f8 WinHttpWriteData

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
URPQQh,
PPPPPPPP
PPPPPPPP
;t$,v-
UQPXY]Y[
bad allocation
Unknown exception
f:\dd\vctools\crt_bld\self_x86\crt\src\onexit.c
Client
Ignore
Normal
Error: memory allocation: bad memory block type.
Invalid allocation size: %Iu bytes.
Client hook allocation failure.
Client hook allocation failure at file %hs line %d.
Error: possible heap corruption at or near 0x%p
The Block at 0x%p was allocated by aligned routines, use _aligned_realloc()
Error: memory allocation: bad memory block type.
Memory allocated at %hs(%d).
Invalid allocation size: %Iu bytes.
Memory allocated at %hs(%d).
Client hook re-allocation failure.
Client hook re-allocation failure at file %hs line %d.
HEAP CORRUPTION DETECTED: after %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory after end of heap buffer.
HEAP CORRUPTION DETECTED: after %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory after end of heap buffer.
Memory allocated at %hs(%d).
HEAP CORRUPTION DETECTED: before %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory before start of heap buffer.
HEAP CORRUPTION DETECTED: before %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory before start of heap buffer.
Memory allocated at %hs(%d).
Client hook free failure.
The Block at 0x%p was allocated by aligned routines, use _aligned_free()
%hs located at 0x%p is %Iu bytes long.
%hs located at 0x%p is %Iu bytes long.
Memory allocated at %hs(%d).
HEAP CORRUPTION DETECTED: on top of Free block at 0x%p.
CRT detected that the application wrote to a heap buffer that was freed.
HEAP CORRUPTION DETECTED: on top of Free block at 0x%p.
CRT detected that the application wrote to a heap buffer that was freed.
Memory allocated at %hs(%d).
DAMAGED
_heapchk fails with unknown return value!
_heapchk fails with _HEAPBADPTR.
_heapchk fails with _HEAPBADEND.
_heapchk fails with _HEAPBADNODE.
_heapchk fails with _HEAPBADBEGIN.
Bad memory block found at 0x%p.
Bad memory block found at 0x%p.
Memory allocated at %hs(%d).
Object dump complete.
crt block at 0x%p, subtype %x, %Iu bytes long.
normal block at 0x%p, %Iu bytes long.
client block at 0x%p, subtype %x, %Iu bytes long.
{%ld}
%hs(%d) :
#File Error#(%d) :
Dumping objects ->
Data: <%s> %s
Detected memory leaks!
f:\dd\vctools\crt_bld\self_x86\crt\src\_file.c
f:\dd\vctools\crt_bld\self_x86\crt\src\_sftbuf.c
(null)
`h````
xpxxxx
f:\dd\vctools\crt_bld\self_x86\crt\src\output.c
f:\dd\vctools\crt_bld\self_x86\crt\src\mlock.c
f:\dd\vctools\crt_bld\self_x86\crt\src\mbctype.c
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
EncodePointer
DecodePointer
f:\dd\vctools\crt_bld\self_x86\crt\src\tidtable.c
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
f:\dd\vctools\crt_bld\self_x86\crt\src\stdenvp.c
f:\dd\vctools\crt_bld\self_x86\crt\src\stdargv.c
f:\dd\vctools\crt_bld\self_x86\crt\src\w_env.c
f:\dd\vctools\crt_bld\self_x86\crt\src\ioinit.c
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library without using a manifest.
This is an unsupported way to load Visual C++ DLLs. You need to modify your application to build with a manifest.
For more information, see the "Visual C++ Libraries as Shared Side-by-Side Assemblies" topic in the product documentation.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
Assertion Failed
Warning
Microsoft Visual C++ Debug Library
_CrtDbgReport: String too long or IO Error
Debug %s!
Program: %s%s%s%s%s%s%s%s%s%s%s%s
(Press Retry to debug the application)
Module:
File:
Line:
Expression:
For information on how your program can cause an assertion
failure, see the Visual C++ documentation on asserts.
HeapQueryInformation
%s(%d) : %s
Assertion failed!
Assertion failed:
, Line
<file unknown>
Second Chance Assertion Failed: File
_CrtDbgReport: String too long or Invalid characters in String
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
`h`hhh
xppwpp
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetUserObjectInformationA
MessageBoxA
USER32.DLL
bad exception
Unknown Runtime Check Error
Stack memory around _alloca was corrupted
A local variable was used before it was initialized
Stack memory was corrupted
A cast to a smaller data type has caused a loss of data. If this was intentional, you should mask the source of the cast with the appropriate bitmask. For example:
char c = (i & 0xFF);
Changing the code in this way will not affect the quality of the resulting optimized code.
The value of ESP was not properly saved across a function call. This is usually a result of calling a function declared with one calling convention with a function pointer declared with a different calling convention.
Stack around the variable '
' was corrupted.
The variable '
' is being used without being initialized.
f:\dd\vctools\crt_bld\self_x86\crt\src\_getbuf.c
f:\dd\vctools\crt_bld\self_x86\crt\src\convrtcp.c
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
MSPDB80.DLL
Stack around _alloca corrupted
Local variable used before initialization
Stack memory corruption
Cast to smaller type causing loss of data
Stack pointer corruption
CONOUT$
bad allocation
toseyexukigut
ketokekuzapurovugutesomozigamas
kezahotu
vuhohezafozitobocuxipegu jasapituguvojizoxiyeruxa fux
dugexemarohecutunixeya mocetirebudecoxidu madibopelijohe nevidikameyalivece yudinewufanucoyi
nokimoza wubarimakebiyi
ziboza gerugakugunekejurijo xudahufapixiyudo
penikecumovufavuvepotovoloses
sowumuvevicovamozaloban
sucolonobin
seyotozaruzogozofukahuhipajegu
totuzuticiyabajovolivomepaha
pipeyawiyowutuvasufiwirujudo
minucoxowif
podukixunubesagobibecikexinepe xadawusafurepojisogavakayuhur rucatupisubohehupuladula
govosuharu
lusalututowagex
bekaheh
C:\nonademup.pdb
GetCommandLineW
FileTimeToDosDateTime
GetNativeSystemInfo
TlsGetValue
GetStringTypeA
HeapAlloc
InterlockedIncrement
GetCommState
ReadConsoleA
GlobalSize
GetSystemWindowsDirectoryW
GlobalLock
SetHandleInformation
CancelWaitableTimer
GetModuleHandleW
EnumResourceTypesA
ActivateActCtx
LoadLibraryW
TerminateThread
GetConsoleAliasExesLengthW
EnumResourceLanguagesA
GetCompressedFileSizeA
GetSystemDirectoryA
CompareStringW
lstrlenW
SetThreadPriority
WritePrivateProfileStringW
DeactivateActCtx
GetNamedPipeHandleStateW
GetPrivateProfileIntW
VerifyVersionInfoW
CreateDirectoryA
InterlockedExchange
SetCurrentDirectoryA
GetStartupInfoA
GetCPInfoExW
GetLastError
GetThreadLocale
GetProcAddress
GetProcessHeaps
SetStdHandle
EnterCriticalSection
DisableThreadLibraryCalls
GetPrivateProfileStringA
LoadLibraryA
LocalAlloc
SetSystemTime
SetEnvironmentVariableA
GetOEMCP
Process32NextW
FindNextFileA
WriteProfileStringA
FindFirstChangeNotificationA
QueryMemoryResourceNotification
FreeEnvironmentStringsW
WriteProfileStringW
GetCurrentDirectoryA
GetCurrentThreadId
FindAtomW
UnregisterWaitEx
GetSystemTime
GetProfileSectionW
LCMapStringW
CopyFileExA
GetVolumeInformationW
KERNEL32.dll
GetMenuItemID
USER32.dll
WinHttpWriteData
WINHTTP.dll
MultiByteToWideChar
GetStartupInfoW
HeapValidate
IsBadReadPtr
RaiseException
LeaveCriticalSection
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetModuleFileNameW
DeleteCriticalSection
InterlockedDecrement
GetACP
GetCPInfo
IsValidCodePage
TlsAlloc
TlsSetValue
TlsFree
SetLastError
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
ExitProcess
GetEnvironmentStringsW
SetHandleCount
GetStdHandle
GetFileType
HeapDestroy
HeapCreate
HeapFree
VirtualFree
GetModuleFileNameA
WriteFile
HeapSize
HeapReAlloc
VirtualAlloc
RtlUnwind
WideCharToMultiByte
DebugBreak
OutputDebugStringA
WriteConsoleW
OutputDebugStringW
InitializeCriticalSectionAndSpinCount
LCMapStringA
GetStringTypeW
GetLocaleInfoA
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetFilePointer
CloseHandle
WriteConsoleA
GetConsoleOutputCP
CreateFileA
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
4:nV-'*
G,qS+@
Q,0Snb
n^}T8TRIh
&4t2d%
@N]v<=OCa|4
o%B8?+
oHXoz:
v1rT!i9Q
DOmz=
j$vCF8T
e3$x58(
P:bvuC
dC+B5~(
d9' 7b
X=m&X.
j2nccpP
{eG&a%Nb
X8'G2uJ
F"Fr_2z
o1|roc
Xbi%(H
.TzfY;m
LC2PSK
x1'~C>
=@!$1
'0gCpI
9v((SmB
wFttK:B
+i$+@RX
{X&%Kp
/{A7#"
*)9'Ki
qMdq~p
G#M%F,
{3?X3n
Wdky<:
'}PKY'
4H9EPjz
9@=f};O
#N}Sqr
,wUClVX
v\yFnx
SN#^Wo_
]y(G.{dX
q('0-H
GT|`-3X
_LtZKt
Iv9)IJAw_
WO,9B!V
SUfmpv
n1~i#2
,YWT;D
4%SBTr
8i<($c
Dwe$#@
qHe<c)
MVtcY0
\`Fq6W
zqUv16
ec|q[Xj
n,D|gi
[a15H3
;*DNdM
P97eI;
29Ra*:
.2$$sB"&
Oa8o=~
l!:Lr{
gZCb9}
MGcDpB
BA)qu2
8]}XG%
d4%|?{
n=ABgKFG
+3&@tx
Nk-m`Ii
yo4z14
VrY&Y5|3
0A9'(IUE
$P|o;-klcw
u)7+[A
%ubY`;
32BgX!
9n[~ZD
Uv'_5SJ'
~:kt|c
|cnYV=
Qkz2D_
f@y&_3
[wh[Q2
D98kP]
*S"?3e`
,#'~C\
C2\+-[
BA'WgNa
p^&c1Ff
7sqb)
->/$7E
LVH_/1z%t
v6bveR
qZYvk2
U]s-Y(
Mi6d;`
FWH5vF
+gzC+0
?7 epF
MBOF:}
)gzWmOC
RYej9m
QNObSjl I
AAAAAA
uuuuuuuW
|VVVVVVVVVVVVVV
QQBBBBqq
QQBBBBqqqq
ccccccccccccccccG
kkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk*
**kkkkkkk*
}}}}}}a
kkkkkk*
kkkkk*
aaaaa}
HHHddd
kkkk!<:-
HHHddd
*kkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk
F$$$$$$$$F$
GGGGGGGGG+$
182=2O2u2~2
9X:]:o:
<L<n<t<z<
> >6>B>K>P>Y>e>n>
0'0/080@0F0L0T0Z0`0h0y0
3494V4[4
5/545U5u5
7&7.7;7D7J7S7X7^7f7l7
8P8Z8f8
9(9-9?9
: ;,;B;T;
=L=X=q=z=
>#>4>g>
?'?0?@?L?b?n?w?
0R1W1\1|1
5(5-5?5S5
6!6'646
7(7-7?7e7q7
:5;Q;c;{;
1090v0
051=1h1
2m2'3=3x3
90959:9
>!>*>8>B>P>V>
?-?>?X?a?k?
1=1G1`1j1
31363;3
4$4j4v4
4.53585
84<4@4D4H4L4P4T4X4\4`4d4h4l4
9H:M:R:Y:
; ;,;@;L;g;w;
1(1-1?1[1
2H3M3_3
3X4]4o4
4"505Y5n5
6:6B6I6S6W6`6r6|6
737C7M7r7|7
3(3D3`3|3
464R4n4
4)5A5X5]5o5
7P7W7a7j7q7x7
7@8G8Q8Z8a8h8x8
999[9e9j9o9y9~9
:3:A:G:U:[:i:n:|:
;G;O;V;g;q;z;
<<P<n<
=/=S=Y=|=
00R0\0
2H2S2`2h2w2
323<3x3
5%5[5j5u5
6(6-6?6`6m6y6
6,7=7{7
7)8/8=8G8w8/9<9q:
=#=4={=
>#>S>]>e>j>x>
>F?O?i?
7(8-838D8J8d8k8q8
:A:Q:V:[:`:
;#;(;-;7;B;];b;
;X<]<o<
010K0W0k0w0
1-191I1U1
1!2&2+202W2
2%3.3X3]3b3
344;4J4
55-575E5K5Z5l5r5
6e6 7'7
9X9]9o9
:3:::I:
;];d;i;o;
1#1,151F1U1a1r1}1
2!2)222J2S2
3L3X3y3
3-787@7g7m7u7
8#8*8P8X8
=0M0w0
8C8a8h8l8p8t8x8|8
8F9Q9l9s9x9|9
: :j:p:t:x:|:8;
1$1M1Z1e1z1
33h3v3
51565;5M5Z5`5
;W<h<m<
<O=U=i=n=s=
=h>m>r>
?<?A?F?z?
/0c0h0m0
0U1Z1_1
2$3X3g3
7 7,71767f7k7p7
9K9P9U9
>O>V>]>z>
>-?9?f?k?p?
0"151f1
2"2,2:2?2I2]2c2k2u2
3A3L3m3
4+40454
> >b>n>
? ?$?(?,?0?4?L?P?T?X?\?
2(252?2K2V2
=(>G>f>
>J?S?}?
,040q0z0
1'202Z2_2d2
31494v4
4&5-5X5
546;6f6
788=8O8f8
9H9Q9{9
9 :%:/:=:B:L:Z:_:i:}:
:3;>;a;l;
;8===O=
=*>_>x>
? ?$?n?t?x?|?
0 0A0k0
2>2C2H2b3n3
4 4%4N4
5"5`5g5
8!8r8~8
:':3:?:D:V:[:a:g:
:(=-=?=8>=>O>
0(1-1?1l1u1
283=3O3
4$4-4W4\4a4
5X5]5o5
6B6Z6c6
8&9g9q9
:':3:Y:~:
<(<e<o<
</=T=t>~>
454>4s4x4}4
5)656f6u6
:4;@;m;r;w;
;6<B<o<t<y<
?$?N?S?X?}?
>0G0q0v0{0
:=:B:G:
:$;);.;s;{;
1B1G1L1
1'2g2o2
31494;5D5n5s5x5
7'8,818
?#?X?]?b?
3>3V3b3
5$5-5;5\5c5m5v5
1E1J1O1+2
8D9H9L9P9T9X9\9`9d9h9l9p9t9x9
;T<`<#=/=
? ?(?/?5?>?G?N?o?x?
3$3-323K3R3Y3`3g3n3t3z3
2 2'2.252<2D2L2S2\2c2l2s2{2
3$303C3I3P3V3^3f3p3w3~3
7.7G7V7
9,:7:=:a:
<<&<Y<i<
="=/=?=I=X=]=b=h=v=|=
=(>->2>
?H?N?b?h?
0L0X0]0b0g0m0
0*121F1T1^1f1x1
2+212>2C2I2U2Z2_2e2
2024282
l;p;t;
h8l8p8t8x8|8
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
9H<L<P<d<h<l<
3h4l4|4
686X6x6
7,787p7
888D8`8l8
9(9H9h9
: :<:@:\:`:|:
; ;$;@;H;L;d;h;
; <@<`<|<
; ;0;T;`;d;h;l;p;x;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
jjjjjjj
jjjjjjjj
printf
f:\dd\vctools\crt_bld\self_x86\crt\src\printf.c
(format != NULL)
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgdel.cpp
_BLOCK_TYPE_IS_VALID(pHead->nBlockUse)
f:\dd\vctools\crt_bld\self_x86\crt\src\_mbslen.c
_loc_update.GetLocaleT()->locinfo->mb_cur_max == 1 || _loc_update.GetLocaleT()->locinfo->mb_cur_max == 2
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgheap.c
_CrtCheckMemory()
_calloc_dbg_impl
(_HEAP_MAXREQ / nNum) >= nSize
_pFirstBlock == pOldBlock
_pLastBlock == pOldBlock
fRealloc || (!fRealloc && pNewBlock == pOldBlock)
pOldBlock->nLine == IGNORE_LINE && pOldBlock->lRequest == IGNORE_REQ
_CrtIsValidHeapPointer(pUserData)
pUserData != NULL
_pFirstBlock == pHead
_pLastBlock == pHead
pHead->nBlockUse == nBlockUse
pHead->nLine == IGNORE_LINE && pHead->lRequest == IGNORE_REQ
_msize_dbg
_CrtSetDbgFlag
(fNewBits==_CRTDBG_REPORT_FLAG) || ((fNewBits & 0x0ffff & ~(_CRTDBG_ALLOC_MEM_DF | _CRTDBG_DELAY_FREE_MEM_DF | _CRTDBG_CHECK_ALWAYS_DF | _CRTDBG_CHECK_CRT_DF | _CRTDBG_LEAK_CHECK_DF) ) == 0)
_CrtMemCheckpoint
state != NULL
(*_errno())
_printMemBlockData
(L"Buffer is too small" && 0)
Buffer is too small
(((_Src))) != NULL
strcpy_s
f:\dd\vctools\crt_bld\self_x86\crt\src\tcscpy_s.inl
((_Dst)) != NULL && ((_SizeInBytes)) > 0
ibase == 0 || (2 <= ibase && ibase <= 36)
strtoxl
f:\dd\vctools\crt_bld\self_x86\crt\src\strtol.c
nptr != NULL
strtoxq
f:\dd\vctools\crt_bld\self_x86\crt\src\strtoq.c
f:\dd\vctools\crt_bld\self_x86\crt\src\_sftbuf.c
str != NULL
flag == 0 || flag == 1
(null)
("'n' format specifier disabled", 0)
(ch != _T('\0'))
( (_Stream->_flag & _IOSTRG) || ( fn = _fileno(_Stream), ( (_textmode_safe(fn) == __IOINFO_TM_ANSI) && !_tm_unicode_safe(fn))))
_output_l
f:\dd\vctools\crt_bld\self_x86\crt\src\output.c
(stream != NULL)
Assertion Failed
Warning
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgrpt.c
Microsoft Visual C++ Debug Library
_CrtDbgReport: String too long or IO Error
wcscpy_s(szOutMessage, 4096, L"_CrtDbgReport: String too long or IO Error")
Debug %s!
Program: %s%s%s%s%s%s%s%s%s%s%s%s
(Press Retry to debug the application)
Module:
File:
Line:
Expression:
For information on how your program can cause an assertion
failure, see the Visual C++ documentation on asserts.
memcpy_s(szShortProgName, sizeof(TCHAR) * (260 - (szShortProgName - szExeName)), dotdotdot, sizeof(TCHAR) * 3)
<program name unknown>
wcscpy_s(szExeName, 260, L"<program name unknown>")
__crtMessageWindowW
f:\dd\vctools\crt_bld\self_x86\crt\src\setlocal.c
((ptloci->lc_category[category].wlocale != NULL) && (ptloci->lc_category[category].wrefcount != NULL)) || ((ptloci->lc_category[category].wlocale == NULL) && (ptloci->lc_category[category].wrefcount == NULL))
KERNEL32.DLL
f:\dd\vctools\crt_bld\self_x86\crt\prebuild\eh\typname.cpp
pNode->next != NULL
mscoree.dll
wcscpy_s(*env, cchars, p)
_wsetenvp
f:\dd\vctools\crt_bld\self_x86\crt\src\stdenvp.c
strcat_s(outmsg, (sizeof(outmsg) / sizeof(outmsg[0])), rterrs[tblindx].rterrtxt)
strcat_s(outmsg, (sizeof(outmsg) / sizeof(outmsg[0])), "\n\n")
strncpy_s(pch, progname_size - (pch - progname), "...", 3)
strcpy_s(progname, progname_size, "<program name unknown>")
strcpy_s(outmsg, (sizeof(outmsg) / sizeof(outmsg[0])), "Runtime Error!\n\nProgram: ")
_NMSG_WRITE
f:\dd\vctools\crt_bld\self_x86\crt\src\crt0msg.c
strcpy_s(szOutMessage, 4096, "_CrtDbgReport: String too long or IO Error")
strcpy_s(szExeName, 260, "<program name unknown>")
__crtMessageWindowA
_expand_base
f:\dd\vctools\crt_bld\self_x86\crt\src\expand.c
pBlock != NULL
kernel32.dll
f:\dd\vctools\crt_bld\self_x86\crt\src\isctype.c
(unsigned)(c + 1) <= 256
_isatty
f:\dd\vctools\crt_bld\self_x86\crt\src\isatty.c
(fh >= 0 && (unsigned)fh < (unsigned)_nhandle)
_fileno
f:\dd\vctools\crt_bld\self_x86\crt\src\fileno.c
("Buffer too small", 0)
sizeInBytes > 0
_wctomb_s_l
f:\dd\vctools\crt_bld\self_x86\crt\src\wctomb.c
sizeInBytes <= INT_MAX
("inconsistent IOB fields", stream->_ptr - stream->_base >= 0)
f:\dd\vctools\crt_bld\self_x86\crt\src\_flsbuf.c
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgrptt.c
_CrtDbgReport: String too long or Invalid characters in String
wcscpy_s(szOutMessage2, 4096, L"_CrtDbgReport: String too long or Invalid characters in String")
e = mbstowcs_s(&ret, szOutMessage2, 4096, szOutMessage, ((size_t)-1))
strcpy_s(szOutMessage, 4096, szLineMessage)
strcat_s(szLineMessage, 4096, "\n")
strcat_s(szLineMessage, 4096, "\r")
strcat_s(szLineMessage, 4096, szUserMessage)
strcpy_s(szLineMessage, 4096, szFormat ? "Assertion failed: " : "Assertion failed!")
strcpy_s(szUserMessage, 4096, "_CrtDbgReport: String too long or IO Error")
_itoa_s(nLine, szLineMessage, 4096, 10)
_VCrtDbgReportA
wcstombs_s(&ret, szaOutMessage, 4096, szOutMessage, ((size_t)-1))
strcpy_s(szOutMessage2, 4096, "_CrtDbgReport: String too long or Invalid characters in String")
wcstombs_s(((void *)0), szOutMessage2, 4096, szOutMessage, ((size_t)-1))
wcscpy_s(szOutMessage, 4096, szLineMessage)
%s(%d) : %s
wcscat_s(szLineMessage, 4096, L"\n")
wcscat_s(szLineMessage, 4096, L"\r")
wcscat_s(szLineMessage, 4096, szUserMessage)
wcscpy_s(szLineMessage, 4096, szFormat ? L"Assertion failed: " : L"Assertion failed!")
Assertion failed!
Assertion failed:
wcscpy_s(szUserMessage, 4096, L"_CrtDbgReport: String too long or IO Error")
, Line
<file unknown>
Second Chance Assertion Failed: File
_itow_s(nLine, szLineMessage, 4096, 10)
_VCrtDbgReportW
f:\dd\vctools\crt_bld\self_x86\crt\src\winsig.c
("Invalid signal or error", 0)
WUSER32.DLL
sizeInBytes >= count
src != NULL
memcpy_s
f:\dd\vctools\crt_bld\self_x86\crt\src\memcpy_s.c
dst != NULL
wcscpy_s
((_Dst)) != NULL && ((_SizeInWords)) > 0
((state == ST_NORMAL) || (state == ST_TYPE))
("Incorrect format specifier", 0)
_output_s_l
f:\dd\vctools\crt_bld\self_x86\crt\src\malloc.h
("Corrupted pointer passed to _freea", 0)
((((( H
h(((( H
H
nstrncpy_s
f:\dd\vctools\crt_bld\self_x86\crt\src\tcsncpy_s.inl
(L"String is not null terminated" && 0)
String is not null terminated
strcat_s
f:\dd\vctools\crt_bld\self_x86\crt\src\tcscat_s.inl
_set_error_mode
f:\dd\vctools\crt_bld\self_x86\crt\src\errmode.c
("Invalid error_mode", 0)
f:\dd\vctools\crt_bld\self_x86\crt\src\vsprintf.c
(count == 0) || (string != NULL)
_vsnprintf_helper
string != NULL && sizeInBytes > 0
_vsprintf_s_l
format != NULL
_vsnprintf_s_l
fclose
f:\dd\vctools\crt_bld\self_x86\crt\src\fclose.c
_fclose_nolock
(str != NULL)
("Invalid file descriptor. File possibly closed by a different thread",0)
(_osfile(filedes) & FOPEN)
_commit
f:\dd\vctools\crt_bld\self_x86\crt\src\commit.c
(filedes >= 0 && (unsigned)filedes < (unsigned)_nhandle)
(_osfile(fh) & FOPEN)
_write
f:\dd\vctools\crt_bld\self_x86\crt\src\write.c
isleadbyte(_dbcsBuffer(fh))
((cnt & 1) == 0)
_write_nolock
(buf != NULL)
_lseeki64
f:\dd\vctools\crt_bld\self_x86\crt\src\lseeki64.c
f:\dd\vctools\crt_bld\self_x86\crt\src\_getbuf.c
_mbstowcs_l_helper
f:\dd\vctools\crt_bld\self_x86\crt\src\mbstowcs.c
s != NULL
retsize <= sizeInWords
bufferSize <= INT_MAX
_mbstowcs_s_l
(pwcs == NULL && sizeInWords == 0) || (pwcs != NULL && sizeInWords > 0)
length < sizeInTChars
2 <= radix && radix <= 36
sizeInTChars > (size_t)(is_neg ? 2 : 1)
sizeInTChars > 0
xtoa_s
f:\dd\vctools\crt_bld\self_x86\crt\src\xtoa.c
buf != NULL
_wcstombs_l_helper
f:\dd\vctools\crt_bld\self_x86\crt\src\wcstombs.c
pwcs != NULL
sizeInBytes > retsize
_wcstombs_s_l
(dst != NULL && sizeInBytes > 0) || (dst == NULL && sizeInBytes == 0)
wcscat_s
_vswprintf_helper
f:\dd\vctools\crt_bld\self_x86\crt\src\vswprint.c
string != NULL && sizeInWords > 0
_vsnwprintf_s_l
xtow_s
_close
f:\dd\vctools\crt_bld\self_x86\crt\src\close.c
f:\dd\vctools\crt_bld\self_x86\crt\src\_freebuf.c
stream != NULL
_get_osfhandle
f:\dd\vctools\crt_bld\self_x86\crt\src\osfinfo.c
f:\dd\vctools\crt_bld\self_x86\crt\src\mbtowc.c
_woutput_s_l
wahudedujarohayovuyomojubahi
royotetazimiwefovulakubujuhabu zotoredamojukimoyejiliwuyafuyopi hetahefemabekepuvagulefeg
revozogadifaxemufiduladewocelude
sizeribuyakoxizokuxinokev
kernel32.dll
pohebowofetakolijuwuxice fovupokolevaw deyinufiwucedivugitunucewa guvoho tarinemukawediwez
zisunuxa zujuhel cuyijenuradocaniyi
vemivayofojuk tajab
nsidusufasutowonagatipumej jamukace
mopikevuridakisecidewap
riwucesomaverocanu
xebumowaxoyewapamedut
hyugab
buvexosugesaregaju
lufuwacimajocegufoharesexer
Antivirus Signature
Bkav W32.IozenaXAL.Trojan
Lionic Trojan.Win32.Cutwail.4!c
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
CMC Clean
CAT-QuickHeal Clean
ALYac Trojan.Agent.Raccoon
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Trojan.Win32.Kryptik.HMLX
K7AntiVirus Trojan ( 005825941 )
Alibaba Trojan:Win32/Starter.ali2000005
K7GW Trojan ( 005825941 )
Cybereason malicious.c258ea
Baidu Clean
VirIT Clean
Cyren Clean
Symantec Packed.Generic.620
ESET-NOD32 a variant of Win32/Kryptik.HMLX
APEX Malicious
Paloalto generic.ml
ClamAV Win.Packed.Generic-9892916-0
Kaspersky HEUR:Trojan.Win32.Cutwail.gen
BitDefender Gen:Heur.Mint.Zard.53
NANO-Antivirus Clean
SUPERAntiSpyware Trojan.Agent/Gen-Crypt
MicroWorld-eScan Gen:Heur.Mint.Zard.53
Avast Win32:DropperX-gen [Drp]
Rising Trojan.Kryptik!1.D975 (CLOUD)
Ad-Aware Gen:Heur.Mint.Zard.53
Emsisoft Trojan.Crypt (A)
Comodo Malware@#24c6a9u4sztzx
F-Secure Clean
DrWeb Clean
Zillya Trojan.Kryptik.Win32.3477935
TrendMicro Trojan.Win32.CUTWAIL.G
McAfee-GW-Edition BehavesLike.Win32.Tool.dh
FireEye Generic.mg.f343214355c07ba1
Sophos ML/PE-A
SentinelOne Static AI - Malicious PE
Jiangmin Trojan.Cutwail.jv
Webroot W32.Trojan.Gen
Avira TR/YAV.Minerva.uumsd
MAX Clean
Antiy-AVL Trojan/Generic.ASMalwS.349DABF
Kingsoft Win32.Troj.Undef.(kcloud)
Microsoft Ransom:Win32/StopCrypt.MDK!MTB
Gridinsoft Trojan.Win32.Packed.vb
Arcabit Trojan.Mint.Zard.53
ViRobot Trojan.Win32.Z.Mint.302592
ZoneAlarm Clean
GData Gen:Heur.Mint.Zard.53
AhnLab-V3 Ransomware/Win.StopCrypt.R441558
Acronis suspicious
McAfee Packed-GDT!F343214355C0
TACHYON Clean
VBA32 Trojan.Convagent
Malwarebytes Trojan.MalPack.GS
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.CUTWAIL.G
Tencent Clean
Yandex Trojan.Cutwail!du4Tj0l/8yo
Ikarus Trojan-Spy.Agent
eGambit Unsafe.AI_Score_87%
Fortinet W32/Kryptik.HMNW!tr
BitDefenderTheta Gen:NN.ZexaF.34182.suW@aeGkMRdO
AVG Win32:DropperX-gen [Drp]
Panda Trj/Genetic.gen
CrowdStrike win/malicious_confidence_100% (W)
MaxSecure Trojan.Malware.1383825.susgen
No IRMA results available.