Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 1992-Jun-19 22:22:17 |
Detected languages |
English - United States
Russian - Russia |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for VirtualPC presence:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to SHA1 Uses constants related to SHA256 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | The PE header may have been manually modified. |
The resource timestamps differ from the PE header:
|
Malicious | VirusTotal score: 39/67 (Scanned on 2018-10-28 09:42:04) |
MicroWorld-eScan:
Trojan.GenericKD.31204955
McAfee: PUP-XBT-YU K7AntiVirus: Adware ( 004f3a421 ) K7GW: Adware ( 004f3a421 ) Arcabit: Trojan.Generic.D1DC265B Invincea: heuristic F-Prot: W32/InstallMonster.HK.gen!Eldorado Symantec: PUA.Gen.2 Avast: Win32:InstallMonstr-LG [PUP] ClamAV: Win.Malware.Agent-6598770-0 Kaspersky: not-a-virus:AdWare.Win32.DLBoost.asbl BitDefender: Trojan.GenericKD.31204955 NANO-Antivirus: Trojan.Win32.InstallMonster.euxpvo Ad-Aware: Trojan.GenericKD.31204955 Emsisoft: Application.InstallMon (A) F-Secure: Trojan.GenericKD.31204955 DrWeb: Trojan.InstallMonster.2222 McAfee-GW-Edition: BehavesLike.Win32.AdwareIMonster.vc Sophos: Install Monster (PUA) SentinelOne: static engine - malicious Cyren: W32/InstallMonster.HK.gen!Eldorado Webroot: Pua.Downloadmanager Fortinet: Riskware/InstallMonster Antiy-AVL: GrayWare[AdWare]/Win32.InstallMonstr.qj Endgame: malicious (high confidence) Microsoft: Trojan:Win32/Bitrep.A ZoneAlarm: not-a-virus:AdWare.Win32.DLBoost.asbl AhnLab-V3: PUP/Win32.InstallMonster.R201980 VBA32: AdWare.DLBoost ALYac: Trojan.GenericKD.31204955 MAX: malware (ai score=84) ESET-NOD32: a variant of Win32/InstallMonstr.QJ potentially unwanted Rising: PUF.InstallMonstr!1.AB36 (CLASSIC) Ikarus: PUA.Installmonstr GData: Win32.Application.InstallMonstr.S AVG: Win32:InstallMonstr-LG [PUP] Cybereason: malicious.bb8559 Panda: Trj/Genetic.gen CrowdStrike: malicious_confidence_100% (D) |
e_magic | MZ |
---|---|
e_cblp | 0x50 |
e_cp | 0x2 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0xf |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0x1a |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 8 |
TimeDateStamp | 1992-Jun-19 22:22:17 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 2.0 |
SizeOfCode | 0x135600 |
SizeOfInitializedData | 0x282200 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x001361A8 (Section: CODE) |
BaseOfCode | 0x1000 |
BaseOfData | 0x137000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x3c5000 |
SizeOfHeaders | 0x400 |
Checksum | 0x3c2456 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x4000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
kernel32.dll |
DeleteCriticalSection
LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte SetCurrentDirectoryA MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA SetLastError GetLastError GetCurrentDirectoryA GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess ExitThread CreateThread WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
---|---|
user32.dll |
GetKeyboardType
LoadStringA MessageBoxA CharNextA |
advapi32.dll |
RegQueryValueExA
RegOpenKeyExA RegCloseKey |
oleaut32.dll |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
kernel32.dll (#2) |
DeleteCriticalSection
LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte SetCurrentDirectoryA MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA SetLastError GetLastError GetCurrentDirectoryA GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess ExitThread CreateThread WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
advapi32.dll (#2) |
RegQueryValueExA
RegOpenKeyExA RegCloseKey |
kernel32.dll (#3) |
DeleteCriticalSection
LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte SetCurrentDirectoryA MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA SetLastError GetLastError GetCurrentDirectoryA GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess ExitThread CreateThread WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
mpr.dll |
WNetGetLastErrorW
|
version.dll |
VerQueryValueA
GetFileVersionInfoSizeW GetFileVersionInfoSizeA GetFileVersionInfoW GetFileVersionInfoA |
gdi32.dll |
UnrealizeObject
StretchBlt SetWindowOrgEx SetWinMetaFileBits SetViewportOrgEx SetTextColor SetStretchBltMode SetROP2 SetPixel SetEnhMetaFileBits SetDIBColorTable SetBrushOrgEx SetBkMode SetBkColor SelectPalette SelectObject SaveDC RestoreDC RectVisible RealizePalette Polyline PlayEnhMetaFile PatBlt MoveToEx MaskBlt LineTo IntersectClipRect GetWindowOrgEx GetWinMetaFileBits GetTextMetricsA GetTextExtentPoint32A GetSystemPaletteEntries GetStockObject GetPixel GetPaletteEntries GetObjectA GetEnhMetaFilePaletteEntries GetEnhMetaFileHeader GetEnhMetaFileDescriptionA GetEnhMetaFileBits GetDeviceCaps GetDIBits GetDIBColorTable GetDCOrgEx GetCurrentPositionEx GetClipBox GetBrushOrgEx GetBitmapBits ExcludeClipRect DeleteObject DeleteEnhMetaFile DeleteDC DeleteColorSpace CreateSolidBrush CreatePenIndirect CreatePalette CreateHalftonePalette CreateFontIndirectA CreateEnhMetaFileA CreateDIBitmap CreateDIBSection CreateCompatibleDC CreateCompatibleBitmap CreateBrushIndirect CreateBitmap CopyEnhMetaFileW CopyEnhMetaFileA CloseEnhMetaFile BitBlt |
user32.dll (#2) |
GetKeyboardType
LoadStringA MessageBoxA CharNextA |
ole32.dll |
CoTaskMemFree
StringFromCLSID |
kernel32.dll (#4) |
DeleteCriticalSection
LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte SetCurrentDirectoryA MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA SetLastError GetLastError GetCurrentDirectoryA GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess ExitThread CreateThread WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
oleaut32.dll (#2) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
ole32.dll (#2) |
CoTaskMemFree
StringFromCLSID |
oleaut32.dll (#3) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
shell32.dll |
SHFileOperationA
|
kernel32.dll (#5) |
DeleteCriticalSection
LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte SetCurrentDirectoryA MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA SetLastError GetLastError GetCurrentDirectoryA GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess ExitThread CreateThread WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
comctl32.dll |
ImageList_SetIconSize
ImageList_GetIconSize ImageList_Write ImageList_Read ImageList_GetDragImage ImageList_DragShowNolock ImageList_SetDragCursorImage ImageList_DragMove ImageList_DragLeave ImageList_DragEnter ImageList_EndDrag ImageList_BeginDrag ImageList_Remove ImageList_DrawEx ImageList_Draw ImageList_GetBkColor ImageList_SetBkColor ImageList_ReplaceIcon ImageList_Add ImageList_GetImageCount ImageList_Destroy ImageList_Create InitCommonControls |
shell32.dll (#2) |
SHFileOperationA
|
Advapi32.dll |
RegCreateKeyExW
RegSetValueExW |
kernel32.dll (#6) |
DeleteCriticalSection
LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte SetCurrentDirectoryA MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA SetLastError GetLastError GetCurrentDirectoryA GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess ExitThread CreateThread WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
advapi32.dll (#3) |
RegQueryValueExA
RegOpenKeyExA RegCloseKey |
comdlg32.dll |
GetSaveFileNameA
GetOpenFileNameA |
Netapi32.dll |
Netbios
|
Advapi32.dll (#2) |
RegCreateKeyExW
RegSetValueExW |
kernel32.dll (#7) |
DeleteCriticalSection
LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte SetCurrentDirectoryA MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA SetLastError GetLastError GetCurrentDirectoryA GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess ExitThread CreateThread WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
3D Dark Shadow |
3D Light |
Window Background |
Window Frame |
Window Text |
OLE control activation failed |
Could not obtain OLE control window handle |
License information for %s is invalid |
License information for %s not found. You cannot use this control in design mode |
Unable to retrieve a pointer to a running object registered with OLE for %s/%s |
Invalid class reference for TAppletApplication |
Invalid stream operation |
Error |
Button Shadow |
Button Text |
Caption Text |
Default |
Gray Text |
Highlight Background |
Highlight Text |
Inactive Border |
Inactive Caption |
Inactive Caption Text |
Info Background |
Info Text |
Menu Background |
Menu Text |
None |
Scroll Bar |
Lime |
Yellow |
Blue |
Fuchsia |
Aqua |
White |
Money Green |
Sky Blue |
Cream |
Medium Gray |
Active Border |
Active Caption |
Application Workspace |
Background |
Button Face |
Button Highlight |
- Dock zone has no control |
Unable to find a Table of Contents |
No help found for %s |
No context-sensitive help installed |
No topic-based help system installed |
No help keyword specified. |
Black |
Maroon |
Green |
Olive |
Navy |
Purple |
Teal |
Gray |
Silver |
Red |
Left |
Up |
Right |
Down |
Ins |
Del |
Shift+ |
Ctrl+ |
Alt+ |
Value must be between %d and %d |
Clipboard does not support Icons |
Text exceeds memo capacity |
Menu '%s' is already being used by another form |
Docked control must have a name |
Error removing control from dock tree |
- Dock zone not found |
&Help |
&Abort |
&Retry |
&Ignore |
&All |
N&o to All |
Yes to &All |
BkSp |
Tab |
Esc |
Enter |
Space |
PgUp |
PgDn |
End |
Home |
&Retry |
Abort |
&All |
Cannot drag a form |
Metafiles |
Enhanced Metafiles |
Icons |
Bitmaps |
Warning |
Error |
Information |
Confirm |
&Yes |
&No |
OK |
Cancel |
Cannot make a visible window modal |
%s property out of range |
Menu index out of range |
Menu inserted twice |
Sub-menu is not in menu |
Not enough timers available |
GroupIndex cannot be less than a previous menu item's GroupIndex |
Cannot create form. No MDI forms are currently active |
A control cannot have itself as its parent |
OK |
Cancel |
&Yes |
&No |
&Help |
&Close |
&Ignore |
Cannot change the size of an icon |
Invalid operation on TOleGraphic |
Unsupported clipboard format |
Out of system resources |
Canvas does not allow drawing |
Invalid image size |
Invalid ImageList |
Invalid ImageList Index |
Failed to read ImageList data from stream |
Failed to write ImageList data to stream |
Error creating window device context |
Error creating window class |
Cannot focus a disabled or invisible window |
Control '%s' has no parent window |
Cannot hide an MDI Child Form |
Cannot change Visible in OnShow or OnHide |
Unknown error |
SSPI %s returns error #%d(0x%x): %s |
SSPI interface has failed to initialise properly |
No PSecPkgInfo specified |
No credential handle acquired |
Can not change credentials after handle aquired. Use Release first |
Unknown credentials use |
Do AcquireCredentialsHandle first |
CompleteAuthToken is not supported |
BCD overflow |
%s is not a valid BCD value |
Could not parse SQL TimeStamp string |
Invalid SQL date/time values |
Bitmap image is not valid |
Icon image is not valid |
Metafile is not valid |
The smartcard certificate used for authentication was not trusted. Please contact your system administrator. |
The smartcard certificate used for authentication has expired. Please contact your system administrator. |
The Kerberos subsystem encountered an error. A service for user protocol request was made against a domain controller which does not support service for user. |
An attempt was made by this server to make a Kerberos constrained delegation request for a target outside of the server's realm. This is not supported, and indicates a misconfiguration on this server's allowed to delegate to list. Please contact your administrator. |
The revocation status of the domain controller certificate used for smartcard authentication could not be determined. There is additional information in the system event log. Please contact your system administrator. |
An untrusted certificate authority was detected while processing the domain controller certificate used for authentication. There is additional information in the system event log. Please contact your system administrator. |
The domain controller certificate used for smartcard logon has expired. Please contact your system administrator with the contents of your system event log. |
The domain controller certificate used for smartcard logon has been revoked. Please contact your system administrator with the contents of your system event log. |
A signature operation must be performed before the user can authenticate. |
One or more of the parameters passed to the function was invalid. |
Client policy does not allow credential delegation to target server. |
Client policy does not allow credential delegation to target server with NLTM only authentication. |
The recipient rejected the renegotiation request. |
The required security context does not exist. |
The PKU2U protocol encountered an error while attempting to utilize the associated certificates. |
The identity of the server computer could not be verified. |
The client certificate does not contain a valid UPN, or does not match the client name in the logon request. Please contact your administrator. |
Smartcard logon is required and was not used. |
A system shutdown is in progress. |
An invalid request was sent to the KDC. |
The KDC was unable to generate a referral for the service requested. |
The encryption type requested is not supported by the KDC. |
An unsupported preauthentication mechanism was presented to the Kerberos package. |
The requested operation cannot be completed. The computer must be trusted for delegation and the current user account must be configured to allow delegation. |
Client's supplied SSPI channel bindings were incorrect. |
The received certificate was mapped to multiple accounts. |
SEC_E_NO_KERB_KEY |
The certificate is not valid for the requested usage. |
The system detected a possible attempt to compromise security. Please ensure that you can contact the server that authenticated you. |
The smartcard certificate used for authentication has been revoked. Please contact your system administrator. There may be additional information in the event log. |
An untrusted certificate authority was detected While processing the smartcard certificate used for authentication. Please contact your system administrator. |
The revocation status of the smartcard certificate used for authentication could not be determined. Please contact your system administrator. |
An unknown error occurred while processing the certificate. |
The received certificate has expired. |
The specified data could not be encrypted. |
The specified data could not be decrypted. |
The client and server cannot communicate, because they do not possess a common algorithm. |
The security context could not be established due to a failure in the requested quality of service (e.g. mutual authentication or delegation). |
A security context was deleted before the context was completed. This is considered a logon failure. |
The client is trying to negotiate a context and the server requires user-to-user but didn't send a TGT reply. |
Unable to accomplish the requested task because the local machine does not have any IP addresses. |
The supplied credential handle does not match the credential associated with the security context. |
The crypto system or checksum function is invalid because a required function is unavailable. |
The number of maximum ticket referrals has been exceeded. |
The local machine must be a Kerberos KDC (domain controller) and it is not. |
The other end of the security negotiation is requires strong crypto but it is not supported on the local machine. |
The KDC reply contained more than one principal name. |
Expected to find PA data for a hint of what etype to use, but it was not found. |
The function completed successfully, but must be called again to complete the context |
The function completed successfully, but CompleteToken must be called |
The function completed successfully, but both CompleteToken and this function must be called to complete the context |
The logon was completed, but no network authority was available. The logon was made using locally known information |
The requested security package does not exist |
The context has expired and can no longer be used. |
The supplied message is incomplete. The signature was not verified. |
The credentials supplied were not complete, and could not be verified. The context could not be initialized. |
The buffers supplied to a function was too small. |
The credentials supplied were not complete, and could not be verified. Additional information can be returned from the context. |
The context data must be renegotiated with the peer. |
The target principal name is incorrect. |
There is no LSA mode context associated with this context. |
The clocks on the client and server machines are skewed. |
The certificate chain was issued by an untrusted authority. |
The message received was unexpected or badly formatted. |
The function requested is not supported |
The specified target is unknown or unreachable |
The Local Security Authority cannot be contacted |
The requested security package does not exist |
The caller is not the owner of the desired credentials |
The security package failed to initialize, and cannot be installed |
The token supplied to the function is invalid |
The security package is not able to marshall the logon buffer, so the logon attempt has failed |
The per-message Quality of Protection is not supported by the security package |
The security context does not allow impersonation of the client |
The logon attempt failed |
The credentials supplied to the package were not recognized |
No credentials are available in the security package |
The message or signature supplied for verification has been altered |
The message supplied for verification is out of sequence |
No authority could be contacted for authentication. |
%s Alert |
%s Read Alert |
%s Write Alert |
Accept Loop |
Accept Error |
Accept Failed |
Accept Exit |
Connect Loop |
Connect Error |
Connect Failed |
Connect Exit |
Handshake Start |
Handshake Done |
Successfull API call |
Not enough memory is available to complete this request |
The handle specified is invalid |
Invalid MMF name "%s" |
The MMF named "%s" cannot be created empty |
Win32 error: %s (%u)%s%s |
OLE error %.8x |
Method '%s' not supported by automation object |
Variant does not reference an automation object |
Dispatch methods do not support more than 64 parameters |
DCOM not installed |
DAX Error |
COM Server Warning |
There are still active COM objects in this application. One or more clients may have references to these objects, so manually closing |
this application may cause those client application(s) to fail. |
Are you sure you want to close this application? |
Failed to load %s. |
Mode has not been set. |
Could not load SSL library. |
SSL status: "%s" |
3rd-level cache: 2 MByte, 8-way set associative, 64 byte line size |
3rd-level cache: 4 MByte, 8-way set associative, 64 byte line size |
3rd-level cache: 1.5 MByte, 12-way set associative, 64 byte line size |
3rd-level cache: 3 MByte, 12-way set associative, 64 byte line size |
3rd-level cache: 6 MByte, 12-way set associative, 64 byte line size |
3rd-level cache: 2 MByte, 16-way set associative, 64 byte line size |
3rd-level cache: 4 MByte, 16-way set associative, 64 byte line size |
3rd-level cache: 8 MByte, 16-way set associative, 64 byte line size |
3rd-level cache: 12 MByte, 24-way set associative, 64 byte line size |
3rd-level cache: 18 MByte, 24-way set associative, 64 byte line size |
3rd-level cache: 24 MByte, 24-way set associative, 64 byte line size |
64-Byte Prefetching |
128-Byte Prefetching |
CPUID leaf 2 does not report cache descriptor information, use CPUID leaf 4 to query cache parameters |
Windows 8.1 |
Windows Server 2012 R2 |
2nd-level cache: 1 MBytes, 8-way associative, 32 byte line size |
2nd-level cache: 2 MBytes, 8-way associative, 32 byte line size |
2nd-level cache: 512 KByte, 4-way set associative, 64 byte line size |
2nd-level cache: 1 MByte, 8-way set associative, 64 byte line size |
Instruction TLB: 4 KByte pages, 4-way set associative, 128 entries |
Instruction TLB: 2 MByte pages, 4-way, 8 entries or 4 MByte pages, 4-way, 4 entries |
Instruction TLB: 4 KByte pages, 4-way set associative, 64 entries |
Data TLB: 4 KByte pages, 4-way set associative, 128 entries |
Data TLB1: 4 KByte pages, 4-way set associative, 256 entries |
Data TLB1: 4 KByte pages, 4-way set associative, 64 entries |
Data TLB: 4 KByte and 4 MByte pages, 4-way set associative, 8 entries |
Shared 2nd-Level TLB: 4 KByte pages, 4-way associative, 512 entries |
3rd-level cache: 512 KByte, 4-way set associative, 64 byte line size |
3rd-level cache: 1 MByte, 4-way set associative, 64 byte line size |
3rd-level cache: 2 MByte, 4-way set associative, 64 byte line size |
3rd-level cache: 1 MByte, 8-way set associative, 64 byte line size |
1st-level data cache: 32 KBytes, 4-way set associative, 64 byte line size |
Trace cache: 12 K-Ops, 8-way set associative |
Trace cache: 16 K-Ops, 8-way set associative |
Trace cache: 32 K-Ops, 8-way set associative |
Trace cache: 64 K-Ops, 8-way set associative |
Instruction TLB: 2M/4M pages, fully associative, 8 entries |
2nd-level cache: 1 MBytes, 4-way set associative, 64 bytes line size |
2nd-level cache: 128 KBytes, 8-way set associative, 64 bytes line size, 2 lines per sector |
2nd-level cache: 256 KBytes, 8-way set associative, 64 bytes line size, 2 lines per sector |
2nd-level cache: 512 KBytes, 8-way set associative, 64 bytes line size, 2 lines per sector |
2nd-level cache: 1 MBytes, 8-way set associative, 64 bytes line size, 2 lines per sector |
2nd-level cache: 2 MBytes, 8-way set associative, 64 byte line size |
2nd-level cache: 512 KBytes, 2-way set associative, 64 byte line size |
2nd-level cache: 512 KBytes, 8-way set associative, 64 byte line size |
2nd-level cache: 256 KBytes, 8-way associative, 32 byte line size |
2nd-level cache: 512 KBytes, 8-way associative, 32 byte line size |
2nd-level cache: 6MByte, 24-way set associative, 64 byte line size |
Instruction TLB: 4 KByte pages, 32 Entries |
Instruction TLB: 4 KByte and 2 MByte or 4 MByte pages, 64 Entries |
Instruction TLB: 4 KByte and 2 MByte or 4 MByte pages, 128 Entries |
Instruction TLB: 4 KByte and 2 MByte or 4 MByte pages, 256 Entries |
Instruction TLB: 2-MByte or 4-MByte pages, fully associative, 7 entries |
Data TLB0: 4 MByte pages, 4-way set associative, 16 entries |
Data TLB0: 4 KByte pages, 4-way associative, 16 entries |
Data TLB0: 4 KByte pages, fully associative, 16 entries |
Data TLB0: 2 MByte or 4 MByte pages, 4-way set associative, 32 entries |
Data TLB: 4 KByte and 4 MByte pages, 64 Entries |
Data TLB: 4 KByte and 4 MByte pages, 128 Entries |
Data TLB: 4 KByte and 4 MByte pages, 256 Entries |
1st-level data cache: 16 KByte, 8-way set associative, 64 byte line size |
1st-level data cache: 8 KBytes, 4-way set associative, 64 byte line size |
1st-level data cache: 16 KBytes, 4-way set associative, 64 byte line size |
2nd-level cache: 384 KBytes, 6-way set associative, sectored cache, 64-byte line size |
2nd-level cache: 512 KBytes, 4-way set associative, sectored cache, 64-byte line size |
No 2nd-level cache or, if processor contains a valid 2nd-level cache, no 3rd-level cache |
2nd-level cache: 128 KBytes, 4-way set associative, 32 byte line size |
2nd-level cache: 256 KBytes, 4-way set associative, 32 byte line size |
2nd-level cache: 512 KBytes, 4-way set associative, 32 byte line size |
2nd-level cache: 1 MBytes, 4-way set associative, 32 byte line size |
2nd-level cache: 2 MBytes, 4-way set associative, 32 byte line size |
3rd-level cache: 4 MBytes, 4-way set associative, 64 byte line size |
3rd-level cache: 8 MBytes, 4-way set associative, 64 byte line size |
3rd-level cache: 8 MByte, 8-way set associative, 64 byte line size |
2nd-level cache: 4 MBytes, 16-way set associative, 64 byte line size |
3rd-level cache: 6MByte, 12-way set associative, 64 byte line size |
3rd-level cache: 8MByte, 16-way set associative, 64 byte line size |
3rd-level cache: 12MByte, 12-way set associative, 64 byte line size |
3rd-level cache: 16MByte, 16-way set associative, 64 byte line size |
1st level data cache: 8 KBytes, 2-way set associative, 32 byte line size |
Instruction TLB: 4 MByte pages, 4-way set associative, 4 entries |
1st level data cache: 16 KBytes, 4-way set associative, 32 byte line size |
1st level data cache: 16 KBytes, 4-way set associative, 64 byte line size |
1st level data cache: 24 KBytes, 6-way set associative, 64 byte line size |
2nd level cache: 256 KBytes, 8-way set associative, 64 byte line size |
3rd level cache: 512 KBytes, 4-way set associative, 64 byte line size, 2 lines per sector |
3rd level cache: 1 MBytes, 8-way set associative, 64 byte line size, 2 lines per sector |
3rd level cache: 2 MBytes, 8-way set associative, 64 byte line size, 2 lines per sector |
3rd level cache: 4 MBytes, 8-way set associative, 64 byte line size, 2 lines per sector |
1st level data cache: 32 KBytes, 8-way set associative, 64 byte line size |
1st level instruction cache: 32 KBytes, 8-way set associative, 64 byte line size |
2nd-level cache: 128 KBytes, 4-way set associative, sectored cache, 64-byte line size |
2nd-level cache: 192 KBytes, 6-way set associative, sectored cache, 64-byte line size |
2nd-level cache: 128 KBytes, 2-way set associative, sectored cache, 64-byte line size |
2nd-level cache: 256 KBytes, 4-way set associative, sectored cache, 64-byte line size |
Missing a Low Surrogate in UTF-16 sequence |
Failed to get ANSI replacement character |
Unable to open key "%s\%s" for read |
Unable to open key "%s\%s" and access value "%s" |
"%s\%s\%s" is of wrong kind or size |
"%s" does not match RootKey |
Failed to create mutex |
Null descriptor |
Instruction TLB: 4 KByte pages, 4-way set associative, 32 entries |
Instruction TLB: 4 MByte pages, 4-way set associative, 2 entries |
Data TLB: 4 KByte pages, 4-way set associative, 64 entries |
Data TLB: 4 MByte pages, 4-way set associative, 8 entries |
Data TLB1: 4 MByte pages, 4-way set associative, 32 entries |
1st level instruction cache: 8 KBytes, 4-way set associative, 32 byte line size |
1st level instruction cache: 16 KBytes, 4-way set associative, 32 byte line size |
1st level instruction cache: 32 KBytes, 4-way set associative, 64 byte line size |
SetCipher failed. |
Error creating SSL session. |
Error creating SSL context. |
Could not load root certificate. |
Could not load certificate. |
Could not load key, check password. |
Could not load DH Parameters. |
Error getting SSL method. |
Error setting File Descriptor for SSL |
Error binding data to SSL socket. |
EOF was observed that violates the protocol |
Protocol field is empty |
Host field is empty |
Character Index %d out of Range, Length = %d |
Character at Index %d is not a valid UTF-16 High Surrogate |
Character at Index %d is not a valid UTF-16 Low Surrogate |
The IOHandler already has a different Intercept assigned |
Transparent proxy cannot bind. |
UDP Not supported by this proxy. |
Buffer terminator must be specified. |
Buffer start position is invalid. |
Reply Code is not valid: %s |
Reply Code already exists: %s |
IOHandler value is not valid |
Algorithm %s not permitted in FIPS mode |
Chunk Started |
Not Acceptable |
Unknown Protocol |
Request method requires HTTP version 1.1 |
Unsupported hash algorithm. This implementation supports only MD5 encoding. |
Error accepting connection with SSL. |
Error connecting with SSL. |
Address type not supported. |
%s: Circular links are not allowed |
Not enough data in buffer. (%d/%d) |
Too much data in buffer. |
File "%s" not found |
Not Connected |
Object type not supported. |
No data to read. |
Read timed out. |
Max line read attempts exceeded. |
Max line length exceeded. |
Set LargeStream to True to send streams greater than 2GB |
Data is too large for stream |
Connect timed out. |
Already connected. |
Maximum number of line allowed exceeded |
Set Size Exceeded. |
UDP is not support in this SOCKS version. |
Request rejected or failed. |
Request rejected because SOCKS server cannot connect. |
Request rejected because the client program and identd report different user-ids. |
Unknown socks error. |
Socks server did not respond. |
Invalid socks authentication method. |
Authentication error to socks server. |
General SOCKS server failure. |
Connection not allowed by ruleset. |
Network unreachable. |
Host unreachable. |
Connection refused. |
TTL expired. |
Command not supported. |
No route to host. |
Directory not empty |
Host not found. |
Stack Class is undefined. |
Stack already created. |
Only one TIdAntiFreeze can exist per application. |
Cannot change IPVersion when connected |
Can not bind in port range (%d - %d) |
Connection Closed Gracefully. |
Could not bind socket. Address and port are already in use. |
Invalid Port Range (%d - %d) |
%s is not a valid service. |
%s is not a valid IPv6 address |
The requested IPVersion / Address family is not supported. |
Not all bytes sent. |
Package Size Too Big. |
Cannot assign requested address. |
Network is down. |
Network is unreachable. |
Net dropped connection or reset. |
Software caused connection abort. |
Connection reset by peer. |
No buffer space available. |
Socket is already connected. |
Socket is not connected. |
Cannot send or receive after socket is closed. |
Too many references, cannot splice. |
Connection timed out. |
Connection refused. |
Too many levels of symbolic links. |
File name too long. |
Host is down. |
Invalid argument. |
Too many open files. |
Operation would block. |
Operation now in progress. |
Operation already in progress. |
Socket operation on non-socket. |
Destination address required. |
Message too long. |
Protocol wrong type for socket. |
Bad protocol option. |
Protocol not supported. |
Socket type not supported. |
Operation not supported on socket. |
Protocol family not supported. |
Address family not supported by protocol family. |
Address already in use. |
Invalid destination index (%d) |
Invalid codepage (%d) |
Failed attempting to retrieve time zone information. |
Error on call to Winsock2 library function %s |
Error on loading Winsock2 library (%s) |
Resolving hostname %s. |
Connecting to %s. |
Connected. |
Disconnecting. |
Disconnected. |
%s |
Socket Error # %d |
%s |
Interrupted system call. |
Bad file number. |
Access denied. |
Buffer fault. |
Property is read-only |
Failed to create key %s |
Failed to get data for '%s' |
Failed to set data for '%s' |
Resource %s not found |
%s.Seek not implemented |
Operation not allowed on sorted list |
%s not in a class registration group |
Property %s does not exist |
Stream write error |
Thread creation error: %s |
Thread Error: %s (%d) |
Invalid source array |
Invalid destination array |
Character index out of bounds (%d) |
Invalid count (%d) |
Cannot open file "%s". %s |
Invalid stream format |
'%s' is an invalid mask at (%d) |
''%s'' is not a valid component name |
Invalid property value |
Invalid property element: %s |
Invalid property path |
Invalid property type: %s |
Invalid property value |
Invalid data type for '%s' |
List capacity out of bounds (%d) |
List count out of bounds (%d) |
List index out of bounds (%d) |
Out of memory while expanding memory stream |
Error reading %s%s%s: %s |
Stream read error |
Tuesday |
Wednesday |
Thursday |
Friday |
Saturday |
Ancestor for '%s' not found |
Cannot assign a %s to a %s |
Bits index out of range |
Can't write to a read-only resource stream |
CheckSynchronize called from thread $%x, which is NOT the main thread |
Class %s not found |
A class named %s already exists |
List does not allow duplicates ($0%x) |
A component named %s already exists |
String list does not allow duplicates |
Cannot create file "%s". %s |
June |
July |
August |
September |
October |
November |
December |
Sun |
Mon |
Tue |
Wed |
Thu |
Fri |
Sat |
Sunday |
Monday |
Feb |
Mar |
Apr |
May |
Jun |
Jul |
Aug |
Sep |
Oct |
Nov |
Dec |
January |
February |
March |
April |
May |
Overflow while converting variant of type (%s) into type (%s) |
Variant overflow |
Invalid argument |
Invalid variant type |
Operation not supported |
Unexpected variant error |
External exception %x |
Assertion failed |
Interface not supported |
Exception in safecall method |
%s (%s, line %d) |
Abstract Error |
Access violation at address %p in module '%s'. %s of address %p |
System Error. Code: %d. |
%s |
A call to an OS function failed |
Jan |
No argument for format '%s' |
Variant method calls not supported |
Read |
Write |
Error creating variant or safe array |
Variant or safe array index out of bounds |
Variant or safe array is locked |
Invalid variant type conversion |
Invalid variant operation |
Invalid NULL variant operation |
Invalid variant operation (%s%.8x) |
%s |
Custom variant type (%s%.4x) is out of range |
Custom variant type (%s%.4x) already used by %s |
Custom variant type (%s%.4x) is not usable |
Too many custom variant types have been registered |
Could not convert variant of type (%s) into type (%s) |
Integer overflow |
Invalid floating point operation |
Floating point division by zero |
Floating point overflow |
Floating point underflow |
Invalid pointer operation |
Invalid class typecast |
Access violation at address %p. %s of address %p |
Access violation |
Stack overflow |
Control-C hit |
Privileged instruction |
Operation aborted |
Exception %s in module %s at %p. |
%s%s |
Application Error |
Format '%s' invalid or incompatible with argument |
'%s' is not a valid integer value |
'%s' is not a valid floating point value |
'%s' is not a valid GUID value |
Invalid argument to time encode |
Invalid argument to date encode |
Out of memory |
I/O error %d |
File not found |
Invalid filename |
Too many open files |
File access denied |
Read beyond end of file |
Disk full |
Invalid numeric input |
Division by zero |
Range check error |
StartAddressOfRawData | 0x615000 |
---|---|
EndAddressOfRawData | 0x615030 |
AddressOfIndex | 0x5370a4 |
AddressOfCallbacks | 0x616010 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_TYPE_REG
|
Callbacks | (EMPTY) |