Source: Yara match | File source: 4.2.WER9Fz381n.exe.400000.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.3.WER9Fz381n.exe.37f0000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.3.WER9Fz381n.exe.3700000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.WER9Fz381n.exe.400000.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.WER9Fz381n.exe.400000.5.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.WER9Fz381n.exe.2f70e67.10.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.3.WER9Fz381n.exe.37f0000.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.3.WER9Fz381n.exe.3700000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.WER9Fz381n.exe.400000.4.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.WER9Fz381n.exe.2e80e67.13.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000004.00000002.1445502886.000000000327A000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.1406450301.000000000336A000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000003.1387384767.00000000037F0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000003.1416807241.0000000003700000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.1404121864.0000000000400000.00000040.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000002.1443450767.0000000000400000.00000040.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: WER9Fz381n.exe PID: 7264, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: WER9Fz381n.exe PID: 7480, type: MEMORYSTR |
Source: Yara match | File source: 4.2.WER9Fz381n.exe.400000.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.3.WER9Fz381n.exe.37f0000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.3.WER9Fz381n.exe.3700000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.WER9Fz381n.exe.400000.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.WER9Fz381n.exe.400000.5.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.WER9Fz381n.exe.2f70e67.10.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.3.WER9Fz381n.exe.37f0000.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.3.WER9Fz381n.exe.3700000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.WER9Fz381n.exe.400000.4.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.WER9Fz381n.exe.2e80e67.13.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000004.00000002.1445502886.000000000327A000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.1406450301.000000000336A000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000003.1387384767.00000000037F0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000003.1416807241.0000000003700000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.1404121864.0000000000400000.00000040.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000002.1443450767.0000000000400000.00000040.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: WER9Fz381n.exe PID: 7264, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: WER9Fz381n.exe PID: 7480, type: MEMORYSTR |
Source: | Binary string: Loader.pdb source: WER9Fz381n.exe, 00000000.00000003.1387384767.00000000037F0000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000400000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000002.1406450301.000000000336A000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003700000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000400000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.000000000327A000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: EfiGuardDxe.pdb7 source: WER9Fz381n.exe, WER9Fz381n.exe, 00000004.00000002.1444895629.0000000002A8C000.00000040.00000020.00020000.00000000.sdmp |
Source: | Binary string: Unrecognized pdb formatThis error indicates attempting to access a .pdb file with source: WER9Fz381n.exe, 00000000.00000002.1406450301.00000000035EB000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000003.1387384767.0000000003E6A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003D7A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000034FB000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: A connection with the server could not be establishedAn extended error was returned from the WinHttp serverThe .pdb file is probably no longer indexed in the symbol server share location. source: WER9Fz381n.exe, 00000000.00000002.1406450301.00000000035EB000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000003.1387384767.0000000003E6A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003D7A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000034FB000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: Age does not matchThe module age and .pdb age do not match. source: WER9Fz381n.exe, 00000000.00000002.1406450301.00000000035EB000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000003.1387384767.0000000003E6A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003D7A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000034FB000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: symsrv.pdb source: WER9Fz381n.exe, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000C29000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000036A9000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003F28000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: Cvinfo is corruptThe .pdb file contains a corrupted debug codeview information. source: WER9Fz381n.exe, 00000000.00000002.1406450301.00000000035EB000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000003.1387384767.0000000003E6A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003D7A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000034FB000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: Downloading symbols for [%s] %ssrv*symsrv*http://https://_bad_pdb_file.pdb source: WER9Fz381n.exe, 00000000.00000002.1406450301.00000000035EB000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000003.1387384767.0000000003E6A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003D7A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000034FB000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: The symbol server has never indexed any version of this symbol fileNo version of the .pdb file with the given name has ever been registered. source: WER9Fz381n.exe, 00000000.00000002.1406450301.00000000035EB000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000003.1387384767.0000000003E6A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003D7A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000034FB000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: PDB not foundUnable to locate the .pdb file in any of the symbol search path locations. source: WER9Fz381n.exe, 00000000.00000002.1406450301.00000000035EB000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000003.1387384767.0000000003E6A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003D7A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000034FB000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\Users\Admin\documents\visual studio 2015\Projects\Winmon\Release\Winmon.pdb source: WER9Fz381n.exe, 00000000.00000003.1387384767.00000000037F0000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000400000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000002.1406450301.000000000336A000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003700000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000400000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.000000000327A000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\vbox\branch\w64-1.6\out\win.amd64\release\obj\src\VBox\HostDrivers\VBoxDrv\VBoxDrv.pdb source: WER9Fz381n.exe, 00000000.00000003.1387384767.00000000037F0000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000400000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000002.1406450301.000000000336A000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003700000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000400000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.000000000327A000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\Users\Admin\documents\visual studio 2015\Projects\Winmon\x64\Release\Winmon.pdb source: WER9Fz381n.exe, 00000000.00000003.1387384767.00000000037F0000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000400000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000002.1406450301.000000000336A000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003700000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000400000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.000000000327A000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: Drive not readyThis error indicates a .pdb file related failure. source: WER9Fz381n.exe, 00000000.00000002.1406450301.00000000035EB000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000003.1387384767.0000000003E6A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003D7A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000034FB000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\vladimir\source\repos\driver-process-monitor\Release\WinmonProcessMonitor.pdb source: WER9Fz381n.exe, 00000000.00000003.1387384767.00000000037F0000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000400000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000002.1406450301.000000000336A000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003700000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000400000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.000000000327A000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: Error while loading symbolsUnable to locate the .pdb file in any of the symbol search source: WER9Fz381n.exe, 00000000.00000002.1406450301.00000000035EB000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000003.1387384767.0000000003E6A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003D7A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000034FB000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: zzz_AsmCodeRange_*FrameDatainvalid string positionstring too long.pdb source: WER9Fz381n.exe, 00000000.00000002.1406450301.00000000035EB000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000003.1387384767.0000000003E6A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003D7A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000034FB000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: Pdb read access deniedYou may be attempting to access a .pdb file with read-only attributes source: WER9Fz381n.exe, 00000000.00000002.1406450301.00000000035EB000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000003.1387384767.0000000003E6A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003D7A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000034FB000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: Unable to locate the .pdb file in this location source: WER9Fz381n.exe, 00000000.00000002.1406450301.00000000035EB000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000003.1387384767.0000000003E6A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003D7A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000034FB000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\Admin\documents\visual studio 2015\Projects\WinmonFS\x64\Release\WinmonFS.pdb source: WER9Fz381n.exe, 00000000.00000003.1387384767.00000000037F0000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000400000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000002.1406450301.000000000336A000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003700000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000400000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.000000000327A000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: The module signature does not match with .pdb signature. source: WER9Fz381n.exe, 00000000.00000002.1406450301.00000000035EB000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000003.1387384767.0000000003E6A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003D7A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000034FB000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: .pdb.dbg source: WER9Fz381n.exe, 00000000.00000002.1406450301.00000000035EB000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000003.1387384767.0000000003E6A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003D7A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000034FB000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: '(EfiGuardDxe.pdbx source: WER9Fz381n.exe, 00000000.00000002.1406450301.00000000035EB000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000003.1387384767.0000000003E6A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003D7A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000034FB000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: symsrv.pdbGCTL source: WER9Fz381n.exe, 00000000.00000003.1387384767.0000000004018000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000C29000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000002.1406450301.0000000003799000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000C29000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000036A9000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003F28000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\Admin\documents\visual studio 2015\Projects\WinmonFS\Release\WinmonFS.pdb source: WER9Fz381n.exe, 00000000.00000003.1387384767.00000000037F0000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000400000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000002.1406450301.000000000336A000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003700000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000400000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.000000000327A000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: or you do not have access permission to the .pdb location. source: WER9Fz381n.exe, 00000000.00000002.1406450301.00000000035EB000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000003.1387384767.0000000003E6A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003D7A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000034FB000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: An Exception happened while downloading the module .pdbPlease open a bug if this is a consistent repro. source: WER9Fz381n.exe, 00000000.00000002.1406450301.00000000035EB000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000003.1387384767.0000000003E6A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003D7A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000034FB000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: EfiGuardDxe.pdb source: WER9Fz381n.exe, 00000000.00000002.1406450301.00000000035EB000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000003.1387384767.0000000003E6A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003D7A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000034FB000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\vladimir\source\repos\driver-process-monitor\x64\Release\WinmonProcessMonitor.pdb source: WER9Fz381n.exe, 00000000.00000003.1387384767.00000000037F0000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000400000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000002.1406450301.000000000336A000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003700000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000400000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.000000000327A000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: Signature does not matchThe module signature does not match with .pdb signature source: WER9Fz381n.exe, 00000000.00000002.1406450301.00000000035EB000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000003.1387384767.0000000003E6A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003D7A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000034FB000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: dbghelp.pdb source: WER9Fz381n.exe, 00000000.00000002.1406450301.00000000035EB000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000003.1387384767.0000000003E6A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003D7A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000034FB000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: dbghelp.pdbGCTL source: WER9Fz381n.exe, 00000000.00000002.1406450301.00000000035EB000.00000040.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000000.00000002.1404121864.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000000.00000003.1387384767.0000000003E6A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1443450767.0000000000A7C000.00000040.00000001.01000000.00000003.sdmp, WER9Fz381n.exe, 00000004.00000003.1416807241.0000000003D7A000.00000004.00001000.00020000.00000000.sdmp, WER9Fz381n.exe, 00000004.00000002.1445502886.00000000034FB000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\muxusad\viwep\gokixetuweton suhip90\hobeloz_cawico.pdb source: WER9Fz381n.exe |