PESCAN.IO - Analysis Report

File Structure:
Analysis Image
Information:
Icon: Icon
Size: 2,75 MB
SHA-256 Hash: 4D46E343E004C470EFE28B81AA1E8F9F27B2C730790C7DA3053EE0DC412C26FF
SHA-1 Hash: 654918FA140BB94E8D319157D610998542AA307D
MD5 Hash: C6B57BC6559F86B3E34D8AB0FBB628D5
Imphash: 1F0B7025D8BC94B2FA32A54F1CC948B4
MajorOSVersion: 4
CheckSum: 002C9552
EntryPoint (rva): 1AAC46
SizeOfHeaders: 1000
SizeOfImage: 2C1000
ImageBase: 30000000
Architecture: x86
ExportTable: 273440
ImportTable: 2723D8
Characteristics: 2102
TimeDateStamp: 52FD784F
Date: 14/02/2014 1:58:39
File Type: DLL
Number Of Sections: 5
ASLR: Enabled
Section Names: .text, .rdata, .data, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows GUI
UAC Execution Level Manifest: asInvoker

Sections Info:
Section Name Flags ROffset RSize VOffset VSize
.text 60000020 (Executable) 1000 1F8000 1000 1F7063
.rdata 40000040 1F9000 7C000 1F9000 7BC4B
.data C0000040 (Writeable) 275000 12000 275000 146A4
.rsrc 40000040 287000 9000 28A000 899C
.reloc 42000040 290000 2E000 293000 2DA04
Description:
OriginalFilename: Steam.dll
CompanyName: Valve Corporation
LegalCopyright: Copyright 2000-2003 Valve Corporation All rights reserved.
ProductName: Steam
FileVersion: 2.0.2117.156

Entry Point:
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - 1AAC46
Code -> 837C2408017505E832EA0000FF7424048B4C24108B54240CE8EDFEFFFF59C20C00CCCCCCCCCCCCCCCCCC558BEC57568B750C
CMP DWORD PTR [ESP + 8], 1
JNE 0X100C
CALL 0XFA3E
PUSH DWORD PTR [ESP + 4]
MOV ECX, DWORD PTR [ESP + 0X10]
MOV EDX, DWORD PTR [ESP + 0XC]
CALL 0XF0A
POP ECX
RET 0XC
INT3
INT3
INT3
INT3
INT3
INT3
INT3
INT3
INT3
PUSH EBP
MOV EBP, ESP
PUSH EDI
PUSH ESI
MOV ESI, DWORD PTR [EBP + 0XC]

Signatures:
Certificate - Digital Signature:
• The file is signed and the signature is correct

Packer/Compiler:
Compiler: Microsoft Visual Studio
Compiler: Microsoft Visual C ++
Detect It Easy (die)
PE: compiler: EP:Microsoft Visual C/C++(2005)[DLL32]
PE: compiler: Microsoft Visual C/C++(2005)[-]
PE: Sign tool: Windows Authenticode(2.0)[PKCS 7]
Entropy: 6.46436

Suspicious Functions:
Library Function Description
KERNEL32.DLL CreateMutexA Create a named or unnamed mutex object for controlling access to a shared resource.
KERNEL32.DLL GetModuleFileNameA Retrieve the fully qualified path for the executable file of a specified module.
KERNEL32.DLL VirtualAlloc Reserve, commit, or both, a region of memory within the virtual address space of a process.
KERNEL32.DLL GetModuleHandleA Retrieves a handle to the specified module.
KERNEL32.DLL CopyFileA Copies an existing file to a new file.
KERNEL32.DLL WriteFile Writes data to a specified file or input/output (I/O) device.
KERNEL32.DLL LoadLibraryA Loads the specified module into the address space of the calling process.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL CreateFileA Creates or opens a file or I/O device.
KERNEL32.DLL DeleteFileA Deletes an existing file.
KERNEL32.DLL IsDebuggerPresent Determines if the calling process is being debugged by a user-mode debugger.
Ws2_32.DLL socket Create a communication endpoint for networking applications.
Ws2_32.DLL connect Establish a connection to a specified socket.
ADVAPI32.DLL RegCreateKeyExA Creates a new registry key or opens an existing one.
ADVAPI32.DLL RegDeleteKeyA Used to delete a subkey and its values from the Windows registry.
ADVAPI32.DLL RegSetValueExA Sets the data and type of a specified value under a registry key.
ADVAPI32.DLL RegDeleteValueA Removes a named value from the specified registry key. Note that value names are not case sensitive.
SHELL32.DLL ShellExecuteA Performs a run operation on a specific file.
ET Functions (carving):
Original Name -> Steam.dll
CreateInterface
InternalSteamNumClientsConnectedToEngine
InternalSteamShouldShutdownEngine2
SteamAbortCall
SteamAbortOngoingUserIDTicketValidation
SteamAckSubscriptionReceipt
SteamBlockingCall
SteamChangeAccountName
SteamChangeEmailAddress
SteamChangeForgottenPassword
SteamChangeOfflineStatus
SteamChangePassword
SteamChangePersonalQA
SteamCheckAppOwnership
SteamCleanup
SteamClearError
SteamCloseFile
SteamCreateAccount
SteamCreateCachePreloaders
SteamCreateLogContext
SteamDecryptDataForThisMachine
SteamDefragCaches
SteamDeleteAccount
SteamEncryptDataForThisMachine
SteamEnumerateApp
SteamEnumerateAppDependency
SteamEnumerateAppIcon
SteamEnumerateAppLaunchOption
SteamEnumerateAppVersion
SteamEnumerateSubscription
SteamEnumerateSubscriptionDiscount
SteamEnumerateSubscriptionDiscountQualifier
SteamFindApp
SteamFindClose
SteamFindFirst
SteamFindFirst64
SteamFindNext
SteamFindNext64
SteamFindServersGetErrorString
SteamFindServersIterateServer
SteamFindServersNumServers
SteamFlushCache
SteamFlushFile
SteamForceCellId
SteamForgetAllHints
SteamGenerateSuggestedAccountNames
SteamGetAccountStatus
SteamGetAppCacheSize
SteamGetAppDLCStatus
SteamGetAppDependencies
SteamGetAppDir
SteamGetAppIds
SteamGetAppPurchaseCountry
SteamGetAppStats
SteamGetAppUpdateStats
SteamGetAppUserDefinedInfo
SteamGetAppUserDefinedRecord
SteamGetCacheDecryptionKey
SteamGetCacheDefaultDirectory
SteamGetCacheFilePath
SteamGetCachePercentFragmentation
SteamGetContentServerInfo
SteamGetCurrentCellID
SteamGetCurrentEmailAddress
SteamGetDepotParent
SteamGetEncryptedNewValveCDKey
SteamGetEncryptedUserIDTicket
SteamGetEncryptionKeyToSendToNewClient
SteamGetFileAttributeFlags
SteamGetLocalClientVersion
SteamGetLocalFileCopy
SteamGetNumAccountsWithEmailAddress
SteamGetOfflineStatus
SteamGetSponsorUrl
SteamGetSubscriptionExtendedInfo
SteamGetSubscriptionIds
SteamGetSubscriptionPurchaseCountry
SteamGetSubscriptionReceipt
SteamGetSubscriptionStats
SteamGetTotalUpdateStats
SteamGetUser
SteamGetUserType
SteamGetVersion
SteamGetc
SteamHintResourceNeed
SteamInitializeUserIDTicketValidator
SteamInsertAppDependency
SteamIsAccountNameInUse
SteamIsAppSubscribed
SteamIsCacheLoadingEnabled
SteamIsFileImmediatelyAvailable
SteamIsFileNeededByApp
SteamIsFileNeededByCache
SteamIsLoggedIn
SteamIsSecureComputer
SteamIsSubscribed
SteamIsUsingSdkContentServer
SteamLaunchApp
SteamLoadCacheFromDir
SteamLoadFileToApp
SteamLoadFileToCache
SteamLog
SteamLogResourceLoadFinished
SteamLogResourceLoadStarted
SteamLogin
SteamLogout
SteamMiniDumpInit
SteamMountAppFilesystem
SteamMountFilesystem
SteamMoveApp
SteamNumAppsRunning
SteamOpenFile
SteamOpenFile64
SteamOpenFileEx
SteamOpenTmpFile
SteamOptionalCleanUpAfterClientHasDisconnected
SteamPauseCachePreloading
SteamPrintFile
SteamProcessCall
SteamProcessOngoingUserIDTicketValidation
SteamPutc
SteamReadFile
SteamRefreshAccountInfo
SteamRefreshAccountInfo2
SteamRefreshAccountInfoEx
SteamRefreshLogin
SteamRefreshMinimumFootprintFiles
SteamReleaseCacheFiles
SteamRemoveAppDependency
SteamRepairOrDecryptCaches
SteamRequestAccountsByCdKeyEmail
SteamRequestAccountsByEmailAddressEmail
SteamRequestEmailAddressVerificationEmail
SteamRequestForgottenPasswordEmail
SteamResumeCachePreloading
SteamSeekFile
SteamSeekFile64
SteamSetAppCacheSize
SteamSetAppVersion
SteamSetCacheDefaultDirectory
SteamSetMaxStallCount
SteamSetNotificationCallback
SteamSetUser
SteamSetUser2
SteamSetvBuf
SteamShutdownEngine
SteamShutdownSteamBridgeInterface
SteamShutdownUserIDTicketValidator
SteamSizeFile
SteamSizeFile64
SteamStartEngine
SteamStartEngineEx
SteamStartLoadingCache
SteamStartValidatingNewValveCDKey
SteamStartValidatingUserIDTicket
SteamStartup
SteamStat
SteamStat64
SteamStopLoadingCache
SteamSubscribe
SteamTellFile
SteamTellFile64
SteamUninstall
SteamUnmountAppFilesystem
SteamUnmountFilesystem
SteamUnsubscribe
SteamUpdateAccountBillingInfo
SteamUpdateSubscriptionBillingInfo
SteamVerifyEmailAddress
SteamVerifyPassword
SteamWaitForAppReadyToLaunch
SteamWaitForAppResources
SteamWaitForResources
SteamWasBlobRegistryDeleted
SteamWeakVerifyNewValveCDKey
SteamWriteFile
SteamWriteMiniDumpFromAssert
SteamWriteMiniDumpSetComment
SteamWriteMiniDumpUsingExceptionInfo
SteamWriteMiniDumpUsingExceptionInfoWithBuildId
SteamWriteMiniDumpWithAppID
Win32MiniDumpInit

Windows REG:
SOFTWARE\Valve\Steam
Software\Valve\Steam\Beta
Software\Valve\Steam\InternalBeta
Software\Valve\Steam\Apps\
SOFTWARE\Microsoft\Windows\CurrentVersion
SOFTWARE\Microsoft\Cryptography
Software\Valve\Half-Life\Settings
Software\Wine\Wine\Config

File Access:
steam.exe
.exe
L!0WriteMiniDump.exe
Steam.dll
SHELL32.dll
ADVAPI32.dll
USER32.dll
KERNEL32.dll
SHLWAPI.dll
WS2_32.dll
VERSION.dll
psapi.dll
BugslayerUtil.DLL
BugSlayer.DLL
CSERHelper.dll
DBGHELP.DLL
\Steam2.dll
steam2.dll
steamconsole.dll
steamclient.dll
mscoree.dll
.bat
\io.sys
Temp
RootDir

File Access (UNICODE):
Steam.dll

Interest's Words:
PADDINGX
Encrypt
Decrypt
Encryption
PassWord
exec
attrib
start
pause
cipher
hostname
sdelete
shutdown
defrag
systeminfo
ping
route

Interest's Words (UNICODE):
PassWord

Anti-VM/Sandbox/Debug Tricks:
OllyDbg Libary - dbghelp.dll

URLs:
http://ocsp.thawte.com
http://crl.thawte.com/ThawteTimestampingCA.crl
http://ts-ocsp.ws.symantec.com
http://ts-aia.ws.symantec.com/tss-ca-g2.cer
http://ts-crl.ws.symantec.com/tss-ca-g2.crl
http://logo.verisign.com/vslogo.gif0
http://csc3-2010-crl.verisign.com/CSC3-2010.crl
http://ocsp.verisign.com
http://csc3-2010-aia.verisign.com/CSC3-2010.cer
http://logo.verisign.com/vslogo.gif04
http://crl.verisign.com/pca3-g5.crl
https://www.verisign.com/rpa
https://www.verisign.com/rpa0
https://www.verisign.com/cps0*
https://www.verisign.com/rpa0

Payloads:
Unusual BP Cave > 15 Bytes - (0xCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC...)

IP Addresses:
72.165.61.189
72.165.61.190
69.28.151.178
69.28.153.82
87.248.196.194
68.142.72.250

Strings/Hex Code Found With The File Rules:
Rule Text (Ascii): WinAPI Sockets (bind)
Rule Text (Ascii): WinAPI Sockets (accept)
Rule Text (Ascii): WinAPI Sockets (connect)
Rule Text (Ascii): WinAPI Sockets (recv)
Rule Text (Ascii): WinAPI Sockets (send)
Rule Text (Ascii): Registry (RegCreateKeyEx)
Rule Text (Ascii): Registry (RegOpenKeyEx)
Rule Text (Ascii): Registry (RegSetValueEx)
Rule Text (Ascii): File (GetTempPath)
Rule Text (Ascii): File (CopyFile)
Rule Text (Ascii): File (CreateFile)
Rule Text (Ascii): File (WriteFile)
Rule Text (Ascii): File (ReadFile)
Rule Text (Ascii): Encryption (CipherMode)
Rule Text (Ascii): Encryption (Rijndael)
Rule Text (Ascii): Encryption API (CryptAcquireContext)
Rule Text (Ascii): Encryption API (CryptReleaseContext)
Rule Text (Ascii): Anti-Analysis VM (IsDebuggerPresent)
Rule Text (Ascii): Anti-Analysis VM (GetSystemInfo)
Rule Text (Ascii): Anti-Analysis VM (GetVersion)
Rule Text (Ascii): Stealth (VirtualAlloc)
Rule Text (Ascii): Execution (CreateProcessA)
Rule Text (Ascii): Execution (ShellExecute)
Rule Text (Ascii): Execution (ResumeThread)
Rule Text (Ascii): Antivirus Software (Symantec)
Rule Text (Ascii): Malicious code executed after exploiting a vulnerability (Payload)
Rule Text (Ascii): Stealer malware focused on obtaining CVV codes to conduct unauthorized transactions (CVV)
Rule Text (Ascii): Unauthorized movement of funds or data (Transfer)
Rule Text (Ascii): Abuse of power for personal gain or unethical purposes (Corruption)

Resources:
Path DataRVA Size FileOffset CodeText
\CONFIGDATA\GENERALDIRECTORYSERVER_IPADDRPORTS\1033 28A3FC E 2873FC 3A3237313331203A323732333100:27131 :27231.
\ICON\1\1033 28A40C B0 28740C 2800000010000000200000000100010000000000800000000000000000000000000000000000000000000000FFFFFF000000(....... .........................................
\ICON\2\1033 28A4BC 568 2874BC 280000001000000020000000010008000000000040010000000000000000000000010000000000001A1B1B00800080008000(....... ...........@.............................
\ICON\3\1033 28AA24 368 287A24 2800000010000000200000000100180000000000400300000000000000000000000000000000000000000012131312131313(....... ...........@.............................
\ICON\4\1033 28AD8C 8A8 287D8C 2800000020000000400000000100080000000000800400000000000000000000000100000000000004040400040404000707(... ...@.........................................
\ICON\5\1033 28B634 CA8 288634 2800000020000000400000000100180000000000800C00000000000000000000000000000000000000000000000000000014(... ...@.........................................
\ICON\6\1033 28C2DC 1CA8 2892DC 2800000030000000600000000100180000000000801C00000000000000000000000000000000000000000000000000000000(...0............................................
\ICON\7\1033 28DF84 468 28AF84 2800000010000000200000000100200000000000400400000000000000000000000000000000000000000000121313FF1213(....... ..... .....@.............................
\ICON\8\1033 28E3EC 10A8 28B3EC 28000000200000004000000001002000000000008010000000000000000000000000000000000000151516011112130C1213(... ...@..... ...................................
\ICON\9\1033 28F494 25A8 28C494 2800000030000000600000000100200000000000802500000000000000000000000000000000000013151600111112001415(...0........ ......%............................
\STRING\876\1033 291A3C 3BC 28EA3C 260053007400650061006D0020004C00690062007200610072007900200068006100730020006E006F007400200062006500&.S.t.e.a.m. .L.i.b.r.a.r.y. .h.a.s. .n.o.t. .b.e.
\STRING\877\1033 291DF8 438 28EDF8 2200540068006500200063006F006D006D0061006E006400200063006F0075006C00640020006E006F007400200062006500".T.h.e. .c.o.m.m.a.n.d. .c.o.u.l.d. .n.o.t. .b.e.
\STRING\878\1033 292230 15C 28F230 1D0054006800650020006D006F0075006E00740020007000610074006800200064006F006500730020006E006F0074002000..T.h.e. .m.o.u.n.t. .p.a.t.h. .d.o.e.s. .n.o.t. .
\GROUP_ICON\102\1033 29238C 84 28F38C 0000010009001010020001000100B00000000100101000000100080068050000020010100000010018006803000003002020............................h.............h.....
\VERSION\1\1033 292410 324 28F410 240334000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000000$.4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
\24\2\1033 292734 265 28F734 3C617373656D626C7920786D6C6E733D2275726E3A736368656D61732D6D6963726F736F66742D636F6D3A61736D2E763122<assembly xmlns="urn:schemas-microsoft-com:asm.v1"
Intelligent String:
• SteamApp.cfg
• .\BSLTime.cpp
• KERNEL32.DLL
• .com
• .bat
• .cmd
• c:\p4clients\rel_beta\projects\common\misc\MultiFieldBlob.hGetFieldDataAsCString() zero-length or not null-terminated
• L!0WriteMiniDump.exe
• c:\p4clients\rel_beta\Projects\GazelleProto\Common\Inc\SubscriberAccountDBKeyRecord.h
• c:\p4clients\rel_beta\Projects\GazelleProto\Common\Inc\ClientAuthenticationTickets.h
• c:\p4clients\rel_beta\projects\gazelleproto\common\inc\ContentDescriptionDBKeyRecord.h
• .\Src\Account.cpp
• Account:SetUser:error causing relogin
• ChangeSelectedAppVersion( uNewAppVersion = %d ) on AppId %dConsidering creating preloader (2) for AppId %dCreatePreloader on AppId %dfake@fakemail.com
• steamconsole.dll
• c:\p4clients\rel_beta\ThirdPartyCode/BSL/BSLTime.h
• c:\p4clients\rel_beta\Projects\Common\Network\WinSockHelperFunctions.h
• steam.log
• .\Src\AuthenticationServerCommands.cpp
• c:\p4clients\rel_beta\Projects\Common\Network\SocketHelperFunctions.h
• .\Src\BufferTable.cpp
• 0.\Src\BuildContentServerLoginMessage.cpp
• c:\p4clients\rel_beta\projects\common\misc\Semaphore.h
• hSession != (u32)~0GameValidation.log
• .\Src\CacheFileFixedChecksumBlock.cpp
• 0.\Src\CacheFileFixedDirectory.cpp
• .\Src\CacheGroup.cpp
• .\Src\CacheOneFileFixedBlock.cpp
• (uDataStart - uOldDataStart) % cuDataBlockSize == 0(uOldDataStart - uDataStart) % cuDataBlockSize == 0Configuring cache(%d) for FAT32%s__%d.gcf
• .pak
• .\Src\CachePreLoader.cpp
• 0.\Src\ClientClockSkew.cpp
• .\Src\CommandStates.cpp
• Login
• RefreshLogin
• steam.cfg
• c:\p4clients\rel_beta\Projects\GazelleProto\Common\Inc\ContentDescriptionDBKeyRecord.h
• 0ContentServerCDDBIPAddrPort.\Src\CSClient.cpp
• 0.\Src\CSClientCompletionHandlers.cpp
• Failed to create session socket.\Src\CSClientConnection.cpp
• (WrappedWSABUF.PrepareToReceive( sizeof(bClientProtocolVersionIsAcceptable) )) != false(WrappedWSABUF.PrepareToReceive( sizeof(uLoginSucceeded) )) != false
• c:\p4clients\rel_beta\Projects\GazelleProto\Common\Inc\SteamGlobalUserIDHelperFunctions.h
• .\Src\CSClientConnectionPool.cpp
• 0Compression FailureCSendSessionLoginRequestState
• CRecvSessionLoginReplyStatusState
• CRecvSessionLoginReplyArgsStateCSendSessionLogoutRequestState
• .\Src\CSClientFSM.cpp
• ReadFileAPILoginLogoutFSM
• .\Src\CSClientService.cpp
• 0Server rejected session login
• {Cnx=%u,Ssn=%u,App=%u} : HandleConnectionFailed: %s{Cnx=%u,Ssn=%u,App=%u} : Aborting found LoginFSM
• .\Src\CSClientSession.cpp
• "0P0.\Src\EngineClientConnection.cpp
• c:\p4clients\rel_beta\Projects\GazelleProto\Client\Engine\Inc\EngineReturnBuffer.h
• 0.\Src\EngineClientManager.cpp
• 0.\Src\EngineReturnBuffer.cpp
• gds1.steampowered.com:27030 gds2.steampowered.com:27030 gds3.steampowered.com:27030 gds4.steampowered.com:27038No IP:ports provided for GeneralDirectoryServers
• gds1.steampowered.com:27030 gds2.steampowered.com:27030Requesting server addresses72.165.61.189:27030 72.165.61.190:27030 69.28.151.178:27038 69.28.153.82:27038 87.248.196.194:27038 68.142.72.250:27038Failed to spawn thread
• .\Src\Fs.cpp
• LoadAllBeforeLaunch\precache.lst
• @reslists\precache.lst
• Failed to delete cache file\preload.lst
• @reslists\preload.lst
• .ncf
• .gcf
• deprecated.gcf
• "0P0.\Src\FsBuffer.cpp
• CreateLocalFileComplete.\Src\FsCacheGroup.cpp
• <0.\Src\FsTable.cpp
• !0p"0"0P"0stmSteam2.dll
• .\Src\Launcher.cpp
• !m_pSteam3Interface || AppLaunchOptionRecord.IsValidForOS( m_pSteam3Interface->GetPlatformName(0) ).exe
• \\.\pipe\%s-%%s.\Src\PipeComm.cpp
• GetNext.\Src\ResourceFile.cpp
• .\Src\ResourceList.cpp
• steam2.dll
• SteamLogin
• User '%s' already set for client %d, refreshing login
• Associating pre-existing CAccount for user '%s' to client %d, refreshing login
• SteamLogoutSteamRefreshLogin
• ReallyFullMemoryMinidumps
• it3 != s_ClientAccountMap.end()Removed entry for client %u, user %s, Login/SetUser failed
• .\Src\SteamValidateUserIDTickets.cpp
• .\Src\TicketCache.cpp
• ..\..\..\Common\Misc\BlobRegistry.cpp
• c:\io.sys
• ..\..\..\Common\Misc\ErrorCodeException.cpp
• ..\..\..\Common\Misc\EventLoopThread.cpp
• Failed to remove file "..\..\..\Common\Misc\FileUtil.cpp
• |:\//"Failed to set file attributes
• ..\..\..\Common\Misc\NamedArgs.cpp
• <0WinMinidumpPerformanceLog
• ..\..\..\Common\Misc\SimpleBitString.cpp
• kernel32.dll
• \00]0UsedAuthenticatorTimestampsCache::LoginRateTooHighExceptionUsedAuthenticatorTimestampsCache::ReusedAuthenticatorException
• ..\..\..\Common\Misc\UsedAuthenticatorTimestampsCache.cpp
• b0..\..\..\Common\Misc\VersionResource.cpp
• ..\..\..\Common\Misc\Win32MiniDump.cpp
• VALVE_MINIDUMP_TYPEDISABLED
• MiniDumpWriteDump
• MiniDumpFilePath
• MiniDumpProcessId
• MiniDumpThreadId
• MiniDumpExceptionRecordPtr
• Unable to spawn external minidump process '%s' (error %d)
• Saved dump file to '%s'Failed to save dump file to '%s' (error %d)Failed to create minidump file '%s' (error %d)
• steam.exe
• 0..\..\..\Common\Misc\Win32Registry.cpp
• Commencing minidump upload connection.
• Creating minidump upload socket.
• Socket creation failed.Connecting to minidump harvesting server.
• Sending minidump harvesting protocol info.
• Sending harvesting protocol upload request.Minidump file size is 0, failed to upload.
• Receive harvesting protocol upload permissible.Receive failed.Server rejected upload command.Uploading minidump file %s.
• Minidump file size zero or unable to allocate memory for minidump file.Receiving minidump upload success/fail message.Upload failed.
• Getting minidump file size (%s).
• Minidump file size (%u bytes).
• Error report accepted, no minidump upload.
• Server requested minidump upload to %s.No response from server.
• ..\..\..\Common\Network\WinSockHelperFunctions.cpp
• ..\..\Common\Src\CompressionAlgs.cpp
• Missing field in ContentDescriptionRecord: ..\..\Common\Src\ContentDescriptionDBKeyRecord.cpp
• ..\..\Common\Src\FileIdChecksumTable.cpp
• ..\..\Common\Src\SubscriberAccountDBKeyRecord.cpp
• c:\p4clients\rel_beta\Projects\GazelleProto\Client\Engine\VC80_Release_Static\SteamEngine.pdb
• WS2_32.dll
• ADVAPI32.dll
• 1.0.0.0
• Steam.dll

Extra 4n4lysis:
Metric Value Percentage
Ascii Code 1688584 58,5707%
Null Byte Code 512198 17,7662%
© 2025 All rights reserved.