????
Current Path : C:/Windows/SysWOW64/ |
Current File : C:/Windows/SysWOW64/verifier.dll |
MZ� �� � @ � � � �!�L�!This program cannot be run in DOS mode. $ ����ŏ,�ŏ,�ŏ,>��-�ŏ,>��-�ŏ,�Ŏ,Bŏ,>��-�ŏ,>��-�ŏ,>��-�ŏ,>�p,�ŏ,>��-�ŏ,Rich�ŏ, PE L �� � ! � t �! � p p, @A @� B h ( X f P. @ d+ �^ T � ` .text �� � `.data ! � \ � @ �.idata 8 @ @.rsrc X ( @ @.reloc d+ @ , : @ B `+�+T h r e a d ���� @ �* �S �S �S �S T (T DT `T tT �T �T �T �T �T U (U @U \U tU �U �U �U �U �U V 0V DV \V tV �V �V �V �V �V W 0W Z � � (Z � � �Z �] �] �] �] �] �] �] � �4_ ` � � u � @_ @e u `u pv Pw x 0 � �� С � �� � � � � � �� �� � �� и � P� � � � P� p� �� �� �� �� �� ` � �! % `% �% `& �& ' P' �' �' ( P( �( �) * @* p* �* P. �. �G �Q R �r @v P� � @� `� �� p� К �� Л � 0� `� � `� 0� � �� `� � �� � @� �� � 0� ж �� 0� p� �� �� P� �� P� �� �� � p� �� �� P� � �� � �� 0� �� 0� `� �� �� 0� �� 0� �� P� @� �� � p� � `� @� � � �� `� �� � @� � @� `� � `� � @� �� @ � � � P � P � � � � P � ` � � � � �! �" �# �$ `& �& �' 0( �) + �, �. 0/ �/ @0 �0 1 @1 �1 2 @2 3 4 �4 �5 �6 7 �7 @8 �8 P9 �9 p: ; p; < p< = �= 0> �> 0? �? �@ �@ �A 0B �B pC D �D @E �E `F G �G 0H �H `I �I `J K �K L �L `M N �N 0O �O pP Q �Q 0R �R �S �T `U PV W `W �W pX �Y �Z `[ \ �\ ] �] ^ �^ _ �` `a �a 0b �b @d �d �e @f �f �g Ph �h `i �i 0j �j k pk �k �k 0l �l �l m `m �m �m 0n o po �o p Pp �p �p 0q pq �q r Pr �r �r @s �s Pt �t �t u `u �u �u 0v �v �v 0w �w 0x �x @y �y �y z `z �z { P{ �{ | P| �| �} �} ~ P 0� p� P� �� `� �� Ђ � 0� �� � �� `� � �� @� � p� � �� � p� � P� �� Ћ � `� � @� �� Ѝ p� � �� � P� 0� �� � p� �� � 0� �� И � p� @� @� �� �� � �� P� � p� � p� �� С @� �� � �� P� � �� � � � � � P� � � � � 0� @� P� � �� �� P X d � � � L P T X \ ` * F a u l t I n j e c t i o n I n c l u d e D l l s F a u l t I n j e c t i o n E x c l u d e D l l s F a u l t I n j e c t i o n T i m e O u t F a u l t I n j e c t i o n P r o b a b i l i t y AVRF: fault injecting call made from %p AVRF:FINJ: invalid fault injection class %X Not used. Current thread using the heap Last thread that used the heap Heap handle multithreaded access in HEAP_NO_SERIALIZE heap heap handle with incorrect signature \ K e r n e l O b j e c t s \ H i g h C o m m i t C o n d i t i o n Page heap: pid 0x%X: page heap enabled with flags 0x%X. Process heap handle attempt to destroy process heap Size requested extreme size request Address HeapRoot Page heap: freeing a null pointer Page heap count Actual count process heap list count is wrong Corruption Address Block size Heap block corrupted header block already freed corruption address corrupted infix pattern for freed block Heap owning the block Heap used in the call corrupted heap pointer or using wrong heap corrupted suffix pattern corrupted prefix pattern Corrupted stamp corrupted start stamp corrupted end stamp Exception code exception raised while verifying block corrupted heap block heap signature heap block virtual storage list entry list head list count AVRF: Reached the end of heap list without finding heap index %x. Total number of heaps %x heap list entry AVRF: EntryContents.Blink = %p, expected %p VerifierRegisterLayer AVRF: Spy [%s, %u]: %X VerifierRegisterBasicsLayers VerifierUnregisterLayer VerifierUnregisterBasicsLayers This verifier stop is continuable. After debugging it use `go' to continue. This verifier stop is not continuable. Process will be terminated when you use the `go' debugger command. =========================================================== VERIFIER STOP %p: pid 0x%X: %s %p : %s %p : %s %p : %s %p : %s =========================================================== %s =========================================================== AVRF: Noncontinuable verifier stop %Ix encountered. Terminating process ... AVRF: Terminate process after verifier stop failed with %X AVRF: Invalid LayerDescriptor or BreakDecriptor passed for Stop code 0x%X AVRF: Invalid Stop code 0x%X passed to VerifierStopMessageEx AVRF: Failed to initialize logging and stop support %s AVRF:bogus string length, overflow AVRF:Failed to save message into stop list StopProcessing stop code a d v a p i 3 2 . d l l RegCreateKeyExW RegCloseKey RegQueryValueExW RegSetValueExW RegDeleteValueW S O F T W A R E \ M i c r o s o f t \ W i n d o w s N T \ C u r r e n t V e r s i o n \ I m a g e F i l e E x e c u t i o n O p t i o n s \ G l o b a l F l a g AVRF: settings: result %u %x 0 x % 0 8 X V e r i f i e r F l a g s { 9 7 6 0 9 4 1 A - 8 D A 5 - 4 d b e - 8 4 3 B - 0 E B D 3 7 6 C A B 0 2 } H a n d l e s B a s i c s { 1 5 9 D 6 0 E C - F 4 5 9 - 4 5 6 b - A 2 7 B - 1 0 7 6 A D 5 9 F 8 F 4 } L o c k s { E D D A 9 6 D B - D 2 1 6 - 4 6 7 d - B E 3 C - 8 6 0 3 7 4 5 E D A 4 3 } T L S { 8 A 7 0 B 8 A 4 - 4 F A 6 - 4 1 c 3 - 8 5 E E - 5 9 5 F C B 3 E 1 0 5 1 } M e m o r y { F 8 6 B 0 2 2 F - E 5 8 9 - 4 e 8 f - B 0 D D - 6 B 7 A F 9 D 7 1 A 5 9 } E x c e p t i o n s { 9 7 0 b d 2 8 7 - 2 e 5 a - 4 a 0 6 - 9 0 8 4 - 9 e 3 9 4 d 4 c 2 6 9 7 } D i r t y S t a c k s M i s c e l l a n e o u s { 0 2 A 5 B 4 0 C - 2 F 2 2 - 4 4 0 9 - B B 3 7 - 7 E F 0 D 3 F 3 4 A 8 8 } D a n g e r o u s A P I s { d e 3 5 a 0 c 0 - d 3 b 8 - 1 1 d 9 - 8 c d 5 - 0 8 0 0 2 0 0 c 9 a 6 6 } T i m e R o l l O v e r { F 1 5 F C 2 4 E - 5 3 A 0 - 4 4 4 D - 8 D 2 8 - F 7 6 9 7 E D D 9 C 8 3 } T h r e a d p o o l { 5 F E 3 2 3 7 2 - C E 7 1 - 4 3 f 9 - B 7 5 D - 6 A D 4 B 1 B 0 8 D 6 A } I n p u t O u t p u t { 8 1 E E C 8 D A - 0 E 6 1 - 4 9 4 2 - 8 0 3 7 - 9 A 6 C 4 A 8 6 5 1 0 D } L e a k { 6 3 3 5 D 1 C F - 7 9 5 5 - 4 1 4 e - 8 C 6 A - 1 A 4 0 A C 9 3 5 7 A C } S R W L o c k n t d l l . d l l LdrGetProcedureAddressForCaller AVRF: AVrfpLdrGetProcedureAddress (%p, %s) -> new address %p P a g e H e a p S i z e R a n g e S t a r t P a g e H e a p S i z e R a n g e E n d P a g e H e a p R a n d o m P r o b a b i l i t y P a g e H e a p D l l R a n g e S t a r t P a g e H e a p D l l R a n g e E n d P a g e H e a p T a r g e t D l l s P a g e H e a p V i r t u a l M e m o r y P e r c e n t P a g e H e a p C o m m i t M e m o r y P e r c e n t T h r e a d T r a c k e r S i z e H e a p T r a c k e r S i z e V s p a c e T r a c k e r S i z e D l l L o a d U n l o a d T r a c k e r S i z e C r i t s e c t D e l e t e T r a c k e r S i z e O u t b u f f T r a c k e r S i z e T h r e a d p o o l T r a c k e r S i z e F o r c e P e n d i n g I O T r a c k e r S i z e E v e n t T r a c k e r S i z e D e l a y F r e e S i z e M B AVRF: Ignoring payload restriction mitigation options since App Verifier or Pageheap are enabled. AVRF: failed to initialize call trackers (%X). AVRF: failed to initialize FreeMemoryCallBacks (%X). AVRF: VerifierRegisterBasicsLayers failed. AVRF: VerifierLoadEssentialStrings failed, status %#x AVRF: NtQuerySystemInformation (SystemBasicInformation) failed, status %#x O A N O C A C H E 1 AVRF: failed to define OANOCACHE variable (%X). AVRF: Failed to initialize verifier.dll provider for %ws with flags 0x%X. AVRF: verifier.dll provider initialized for %ws with flags 0x%X AVRF: Exception during verifier.dll init for %ws with flags 0x%X. P a y l o a d R e s t r i c t i o n s . d l l MitLibInitialize MitLibUninitialize ntdll.dll NtSuspendProcess NtResumeProcess AVRF: failed to create verifier heap. AVRF: failed to initialize verifier stop logic (%X). RtlReportException AVRF: Exception %x from address %p Dirtying stack range %p - %p for thread %p AVRF: failed to allocated a verifier TLS slot. Context record. Use .cxr to display it. Exception record. Use .exr to display it. Code performing invalid access Invalid address being accessed first chance access violation for current stack trace AVRF: failed to add free memory callback @ %p AVRF: attempt to delete invalid free memory callback @ %p Stack low limit address DLL name address. Use du to dump it. DLL memory range size DLL memory base address Unloading DLL inside current thread's stack address range AVRF: Couldn't read %s @ %p AVRF: Read just %Ix out of %Ix bytes of %s @ %p RtlInitializeSRWLock RtlReleaseSRWLockExclusive RtlReleaseSRWLockShared RtlAcquireSRWLockExclusive RtlAcquireSRWLockShared RtlCreateMemoryBlockLookaside RtlExtendMemoryBlockLookaside RtlAllocateMemoryBlockLookaside RtlFreeMemoryBlockLookaside NtAllocateVirtualMemory NtFreeVirtualMemory NtMapViewOfSection NtUnmapViewOfSection NtUnmapViewOfSectionEx NtCreateSection NtOpenSection NtCreateFile NtOpenFile NtCreateKey NtOpenKey RtlTryEnterCriticalSection RtlEnterCriticalSection RtlLeaveCriticalSection RtlInitializeCriticalSection RtlInitializeCriticalSectionAndSpinCount RtlDeleteCriticalSection RtlInitializeResource RtlDeleteResource RtlAcquireResourceShared RtlAcquireResourceExclusive RtlReleaseResource RtlConvertSharedToExclusive RtlConvertExclusiveToShared NtCreateEvent NtOpenEvent NtClose RtlAllocateHeap RtlReAllocateHeap RtlFreeHeap NtReadFile NtReadFileScatter NtWriteFile NtWriteFileGather NtWaitForSingleObject NtWaitForMultipleObjects RtlSetThreadPoolStartFunc NtSetEvent NtClearEvent NtPulseEvent NtQueryEvent NtResetEvent NtSetEventBoostPriority NtAlertResumeThread NtAlertThread NtGetContextThread NtImpersonateThread NtQueryInformationThread NtQueueApcThread NtResumeThread NtSetContextThread NtSetInformationThread NtSuspendThread NtTerminateThread NtGetNextThread NtQueryInformationProcess NtSetInformationProcess NtTerminateProcess NtGetNextProcess NtAllocateUserPhysicalPages NtExtendSection NtReadVirtualMemory NtWriteVirtualMemory NtFlushVirtualMemory NtLockVirtualMemory NtUnlockVirtualMemory NtProtectVirtualMemory NtQuerySection NtFreeUserPhysicalPages NtGetWriteWatch NtResetWriteWatch NtFlushInstructionCache NtDeleteKey NtDeleteValueKey NtEnumerateKey NtEnumerateValueKey NtFlushKey NtNotifyChangeKey NtNotifyChangeMultipleKeys NtQueryKey NtQueryValueKey NtQueryMultipleValueKey NtReplaceKey NtRenameKey NtCompactKeys NtCompressKey NtRestoreKey NtSaveKey NtSaveKeyEx NtSaveMergedKeys NtSetValueKey NtUnloadKeyEx NtSetInformationKey NtLockRegistryKey _vsnprintf _vsnwprintf _snprintf _snwprintf LdrLoadDll LdrUnloadDll RtlInitializeCriticalSectionEx TpAllocWork TpAllocTimer TpAllocWait TpAllocIoCompletion TpReleaseIoCompletion TpAllocAlpcCompletion TpSimpleTryPost TpCallbackLeaveCriticalSectionOnCompletion TpCallbackDetectedUnrecoverableError RtlQueueWorkItem RtlCreateHeap RtlRegisterWait RtlDeregisterWaitEx RtlDeregisterWait RtlCreateTimerQueue RtlDeleteTimerQueueEx RtlDeleteTimerQueue RtlCreateTimer RtlDeleteTimer RtlUpdateTimer RtlCancelTimer RtlSetTimer NtDeviceIoControlFile NtFsControlFile NtRemoveIoCompletion NtRemoveIoCompletionEx RtlExitUserThread RtlSetIoCompletionCallback NtSetInformationFile NtCancelIoFile NtCancelIoFileEx RtlDeleteSecurityObject RtlDestroyHeap NtNotifyChangeDirectoryFile NtDuplicateObject RtlTryAcquireSRWLockExclusive RtlAcquireReleaseSRWLockExclusive RtlTryAcquireSRWLockShared RtlSleepConditionVariableSRW RtlConvertSRWLockExclusiveToShared RtlFreeUnicodeString RtlFreeSid RtlExitUserProcess RtlSetSecurityObject RtlSetSecurityObjectEx RtlDisownModuleHeapAllocation LdrGetProcedureAddress HeapCreate HeapDestroy CloseHandle ExitThread TerminateThread SuspendThread TlsAlloc TlsFree TlsGetValue TlsSetValue CreateThread WaitForSingleObject WaitForMultipleObjects WaitForSingleObjectEx WaitForMultipleObjectsEx GlobalAlloc GlobalReAlloc LocalAlloc LocalReAlloc CreateFileA CreateFileW FreeLibraryAndExitThread GetTickCount IsBadReadPtr IsBadHugeReadPtr IsBadWritePtr IsBadHugeWritePtr IsBadCodePtr IsBadStringPtrA IsBadStringPtrW VirtualFree VirtualFreeEx CreateEventA CreateEventW OpenEventA OpenEventW MultiByteToWideChar WideCharToMultiByte UnmapViewOfFile UnmapViewOfFileEx SetThreadAffinityMask SetThreadPriority GlobalFree LocalFree VirtualAlloc HeapAlloc HeapReAlloc HeapFree SetProcessWorkingSetSizeEx SetProcessWorkingSetSize RegCreateKeyA RegCreateKeyW RegCreateKeyExA RegOpenKeyA RegOpenKeyW RegOpenKeyExA RegOpenKeyExW RegNotifyChangeKeyValue RegSetValueA RegSetValueW RegSetValueExA malloc calloc realloc free ??2@YAPAXI@Z ??3@YAXPAX@Z ??_U@YAPAXI@Z ??_V@YAXPAX@Z _strdup _wcsdup _mbsdup _aligned_malloc _aligned_realloc _aligned_recalloc _aligned_free _aligned_offset_malloc _aligned_offset_realloc _aligned_offset_recalloc _fullpath _wfullpath _getcwd _wgetcwd _getdcwd _wgetdcwd _o_malloc _o_calloc _o_realloc _o_free _o__aligned_malloc _o__aligned_realloc _o__aligned_recalloc _o__aligned_free _o__aligned_offset_malloc _o__aligned_offset_realloc _o__aligned_offset_recalloc _o__strdup _o__wcsdup _o__fullpath _o__wfullpath _o__getcwd _o__wgetcwd _o__getdcwd _o__wgetdcwd CoInitialize CoInitializeEx CoUninitialize RoInitialize RoUninitialize CoTaskMemAlloc CoTaskMemRealloc CoTaskMemFree PostThreadMessageW PostThreadMessageA PostMessageW PostMessageA PostQuitMessage RegisterPowerSettingNotification UnregisterPowerSettingNotification SetClipboardData SysAllocString SysReAllocString SysAllocStringLen SysReAllocStringLen SysAllocStringByteLen SysFreeString VariantClear SetupDiCreateDevRegKeyA SetupDiCreateDevRegKeyW SetupDiOpenDevRegKey k e r n e l 3 2 . d l l m s v c r t . d l l u c r t b a s e . d l l o l e 3 2 . d l l u s e r 3 2 . d l l s e t u p a p i . d l l o l e a u t 3 2 . d l l k e r n e l b a s e . d l l c o m b a s e . d l l AVRF: internal error: we do not have a replacement for %s !!! Critical section debug info address Lock count Critical section address critical section over-released or corrupted Number of critical sections owned by current thread. %p (CS = %p, DebugInfo = %p), left %p, right %p, parent %p ================================================ Critical section tree root = %p ================================================ AVrfpInsertCritSectInSplayTree( %p ) AVrfpFindCritSectInSplayTree( %p ) AVrfpDeleteCritSectFromSplayTree( %p ) AVrfpInitializeCriticalSectionCommon (%p, %x, %x)) AVRF: InitializeCriticalSection (%p) - no tree node. AVRF: InitializeCriticalSection (%p) - out of memory - DebugInfo is not valid. AVrfpRtlDeleteCriticalSection (%p) AVrfpRtlInitializeResource (%p), CS = %p AVrfpRtlDeleteResource (%p), CS = %p Number of critical sections owned by curent thread. current thread doesn't own locks AVRF: AVrfpCheckStaticInitializedCriticalSection (%p) - no tree node. AVRF: checking CS @ %p (debug info @ %p) v f b a s i c s . d l l AVRF: %ws: null entry point. AVRF: %ws @ %p: entry point @ %p . m f p l a t . d l l n s i . d l l t h r e a d p o o l w i n r t . d l l r t w o r k q . d l l AVRF: low memory: will not verify entry point for %ws . AVRF: hooked dll entry point for dll %ws AVRF: dll entry @ %p (%ws, %x) AVRF: failed to get dll base of user32.dll. AVRF: TLS slot %x allocated by code at %p. AVRF: AVrfpLdrLoadDll (%p, %ws) AVRF: AVrfpLdrUnLoadDll (%p) w i n l o g o n . e x e s p p s v c . e x e O E S p a m F i l t e r . d l l M S W S O C K . D L L g d i p l u s . d l l T T T r a c e W r i t e r . d l l T T D W r i t e r . d l l l i c w m i . d l l d p c d l l . d l l l i c d l l . d l l S b s c r d l l . d l l U S E R 3 2 . D L L D N S A P I . D L L m s w s o c k . d l l S P O O L S S . D L L l o c a l s p l . d l l N E T A P I 3 2 . D L L n e t l o g o n . d l l a s f s i p c . d l l f r a m e d y n . d l l i a c 2 5 _ 3 2 . a x r p c s s . d l l O D B C 3 2 . d l l c a t s r v . d l l G D I 3 2 . D L L i u e n g i n e . d l l U x T h e m e . d l l W I N H T T P . D L L a d s l d p . d l l a d s l d p c . d l l d e t o u r s . d l l d e v i c e a c c e s s . d l l d h c p c o r e . d l l d h c p c o r e 6 . d l l d i a g p e r f . d l l e s e n t . d l l f i r e w a l l . c p l f i r e w a l l a p i . d l l f x s s t . d l l i e f r a m e . d l l i e s s e t u p . d l l j s c r i p t . d l l l o g g e r . o c x m p s s v c . d l l m s c o r i e s . d l l m s f e e d s . d l l P e r f t r a c k . d l l p w r s h s i p . d l l r a d a r d t . d l l r o m e t a d a t a . d l l S h i m E n g . d l l t a s k s c h d . d l l t r k w k s . d l l U N T F S . d l l U r l m o n . d l l V S S A P I . D L L w a b 3 2 . d l l w b e m c o n s . d l l w e b c l n t . d l l w e r c p l s u p p o r t . d l l w i n s p o o l . d r v w i n t y p e s . d l l W L D A P 3 2 . d l l w m p . d l l , **************************************************************************** ** ** ** Potential deadlock detected! ** ** Type !avrf -dlck in the debugger for more information. ** Deadlock detection: Must release resources in reverse-order Resource %p acquired before resource %p -- Current thread (%p) is trying to release it first AVRF: Overflow for BytesAllocated (%p) + Size(%p) AVRF: deadlock: stop: %p %p %p %p Application verifier deadlock/resource issue EnumThreadWindows RealGetWindowClassW PeekMessageW w u d f h o s t . e x e U N K N O W N ( n u l l ) \ S o f t w a r e \ M i c r o s o f t \ W i n d o w s N T \ C u r r e n t V e r s i o n \ I m a g e F i l e E x e c u t i o n O p t i o n s \ \ R E G I S T R Y \ U S E R \ \ R e g i s t r y \ M a c h i n e \ S o f t w a r e \ M i c r o s o f t \ W i n d o w s N T \ C u r r e n t V e r s i o n \ I m a g e F i l e E x e c u t i o n O p t i o n s \ V e r i f i e r A p p L a u n c h C o u n t P a g e H e a p F l a g s AVRF: %ws Failed to close event 0x%p with Status 0x%X AVRF: %ws Failed to close handle 0x%p with Status 0x%X AVRF: %ws Failed to close event 0x%p with Status 0x%X in event completion callback AVRF: %ws Failed to clear event 0x%p with Status 0x%X AVRF: %ws Failed to create event with Status 0x%X AVRF: %ws Failed to register wait callback with Status 0x%X AVRF: conditional breakpoint %X hit. E v e n t T h r e a d P r o c e s s S e c t i o n K e y F i l e E v e n t O r P r o c e s s AVrfpFreeVirtualMemNotify: NtQueryVirtualMemory( %p ) failed %x Buffer size Buffer start address Unexpected exception raised while initializing output buffer. AVRF: (%x, %x) AVrfpInitOutputBuffer filling Buffer 0x%p, size 0x%x �� % �b �V �� c W �� $ e Y � � �� X_ � �a @ �f Qg �h � � 2� �� τ � � ދ C� J� P� d� � �� b� /� A� �� �� � � &� ,� ?� E� b� k� t� �� �� � � � � !� X� _� e� y� @� H� K� Q� b� h� ~� �� �� �� �� �� � � � '� �� �� �� � H� N� T� W� {� �� �� �� �� �� �� �� � �� �� �� x� �� 2� � o� f� �� 4� ? � � � � �! ͋ � � #� &� >� E� H� �� �� �� � �� �� �� �� Đ �� �� ē ғ ֓ � � W� [� z� �� �� �� �� Ŕ � � � ؕ �� � � ͞ �� ש �� � �� �� �� �� Ź 8� � ,� �� �� �� $� W� s� &� u� �\ Ξ ֞ � K� /� �� t� � �� �� Ҭ � 1� ;� � @ �D 8b � @e �C �� ` ͬ � �� �� � ETW0 ��+�� ) � Shutdown ProcessName VerifierFlags ( � Startup ProcessName VerifierFlags �i��-V�⧡7䔾 Microsoft-Windows-Verifier RSDS�0��*��)A�Ю�I< verifier.pdb GCTL � .rdata$brc � .gfids � H .giats @ �D .rdata 4_ .rdata$sxdata @_ � .rdata$voltmd 8b .rdata$zETW0 Hb i .rdata$zETW1 �b . .rdata$zETW2 �b .rdata$zETW9 �b ` .rdata$zzzdbg @e .text Pj @F .text$mn �� � .xdata$x @� B .edata � �8 .data$brc � �"