Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\TextInputFramework.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CLBCatQ.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009741000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cfgmgr32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009A9D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wbemsvc.pdb\* source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\samlib.pdbba source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: profapi.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.00000000096D6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winsta.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009F6A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernel32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079A4000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreUIComponents.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004C6F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wbemprox.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\twinapi.appcore.pdb8 source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CD8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemcomn.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A026000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ucrtbase.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B7A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fwbase.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.00000000098C6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\dhcpcsvc6.pdbdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CD8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A1F4000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msvcrt.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: e3samlib.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.00000000090B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wrpcrt4.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007A9F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wntdll.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemcomn.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A026000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dhcpcsvc6.pdb*eC source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreMessaging.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009D2D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: userenv.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008528000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: advapi32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079AF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wsspicli.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009257000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ucrtbase.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B7A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\JSAMSIProvider32.pdbP source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004C6F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\rasadhlp.pdb\*o source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dhcpcsvc6.pdbationNr~. source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\DLL\dhcpcsvc6.pdbNp source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000008DCE000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: audioses.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009BBF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CLBCatQ.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009741000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winspool.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009119000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fwpuclnt.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernelbase.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079AA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shlwapi.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008208000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dhcpcsvc.pdb\*torS~~2 source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\exe\getscreen-524501439-x86.pdbp source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004C6F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\samlib.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreMessaging.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009D2D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: gdiplus.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.00000000084F0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: bcryptprimitives.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009278000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samcli.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009246000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cryptbase.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009262000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreUIComponents.pdb0 source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004C6F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: netapi32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008506000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\twinapi.appcore.pdbL source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CD8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\JSAMSIProvider32.pdbp source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004C6F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreUIComponents.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009CD2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: comdlg32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B19000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ws2_32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B96000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: advapi32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079AF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleacc.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008517000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: InputHost.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009EA5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winspool.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009119000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MFWMAAEC.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009B05000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WinTypes.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009D88000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fwbase.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.00000000098C6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\InputHost.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: iphlpapi.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.00000000084F5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\FWPolicyIOMgr.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004C6F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemsvc.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A02C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wmswsock.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A251000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\JSAMSIProvider32.pdbb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CD8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\WindowManagementAPI.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wrpcrt4.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007A9F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: secur32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008522000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winmm.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.00000000090B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\samlib.pdbcyS source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FirewallAPI.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000979C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: powrprof.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.000000000851D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\exe\getscreen-524501439-x86.pdb:J source: getscreen-524501439-x86.exe, 00000000.00000002.1725192173.0000000002A28000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ole32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.00000000082E7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\samlib.pdbiB} source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FWPolicyIOMgr.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009929000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.UI.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009C19000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\fwpuclnt.pdbo source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cfgmgr32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009A9D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\JSAMSIProvider32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CD8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: combase.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B74000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.Storage.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009676000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wuser32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B85000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fwpuclnt.pdb2}n source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\dhcpcsvc.pdb*} source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernel32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079A4000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinapi.appcore.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009E3C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: secur32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008522000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winsta.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009F6A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dsparse.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009251000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ole32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.00000000082E7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\CoreMessaging.pdbdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CD8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msvcp_win.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008203000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: version.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000008F3B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Kernel.Appcore.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.00000000096DC000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\CoreUIComponents.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CD8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WinTypes.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009D88000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32full.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.00000000081FD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shell32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008281000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A1F4000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\dhcpcsvc6.pdbi source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CD8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinapi.appcore.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CB7000.00000004.00000020.00020000.00000000.sdmp, getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009E3C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WindowManagementAPI.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009DE2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mfperfhelper.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009B5F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: comdlg32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B19000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\MpOAV.pdbeUserC source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\JSAMSIProvider32.pdb! source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CD8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wmswsock.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winmm.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.00000000090B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: devobj.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009A41000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shlwapi.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008208000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\exe\getscreen-524501439-x86.pdb,J source: getscreen-524501439-x86.exe, 00000000.00000002.1725192173.0000000002A28000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\msi.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CD8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleacc.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008517000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B90000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wsspicli.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009257000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samcli.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009246000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shell32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008281000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FirewallAPI.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000979C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\JSAMSIProvider32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004C6F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msvcp_win.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008203000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: powrprof.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.000000000851D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dnsapi.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009801000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wtsapi32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.000000000917F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: userenv.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008528000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WindowManagementAPI.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009DE2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MFWMAAEC.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009B05000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreUIComponents.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009CD2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.Storage.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009676000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wUxTheme.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.000000000926D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: devobj.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009A41000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: d3d11.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.000000000848E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc6.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A199000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fwpuclnt.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A2B3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: gdiplus.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.00000000084F0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samlib.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A2B9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreMessaging.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004C6F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dbghelp.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.00000000084EA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: combase.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B74000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdb\*b source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wntdll.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: d3d11.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.000000000848E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: profapi.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.00000000096D6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msvcrt.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc6.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A199000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wmswsock.pdbZ~ source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32full.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.00000000081FD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\twinapi.appcore.pdby source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CD8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\DLL\dhcpcsvc6.pdb4 source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000008DCE000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\rasadhlp.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: audioses.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009BBF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fastprox.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A086000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemsvc.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A02C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samlib.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A2B9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fastprox.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A086000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msctf.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009273000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\DLL\dhcpcsvc6.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000008DCE000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FWPolicyIOMgr.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009929000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wmswsock.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A251000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: version.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000008F3B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dsparse.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009251000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dnsapi.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009801000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dbghelp.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.00000000084EA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Kernel.Appcore.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.00000000096DC000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: C:\Github-runner\_work\agent-windows\agent-windows\console\Win32\Release\getscreen.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001705000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000001055000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001705000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001705000.00000040.00000001.01000000.00000003.sdmp |
Source: | Binary string: ws2_32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B96000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fwpuclnt.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A2B3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wUxTheme.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.000000000926D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: netapi32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008506000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cryptbase.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009262000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B90000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernelbase.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079AA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msctf.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009273000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: bcryptprimitives.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009278000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mfperfhelper.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009B5F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.UI.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009C19000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wtsapi32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.000000000917F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleaut32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.00000000082EC000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: iphlpapi.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.00000000084F5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreMessaging.pdbdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004C6F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wuser32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B85000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: comctl32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B9B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: InputHost.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009EA5000.00000004.00000020.00020000.00000000.sdmp |
Source: getscreen-524501439-x86.exe, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: getscreen-524501439-x86.exe, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: getscreen-524501439-x86.exe, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001321000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000000C71000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001321000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001321000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001321000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000000C71000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001321000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001321000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://crl.comodoca.com/COMODOCertificationAuthority.crl0 |
Source: getscreen-524501439-x86.exe, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe.0.dr | String found in binary or memory: http://crl.globalsign.com/codesigningrootr45.crl0U |
Source: getscreen-524501439-x86.exe, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe.0.dr | String found in binary or memory: http://crl.globalsign.com/gsgccr45evcodesignca2020.crl0 |
Source: getscreen-524501439-x86.exe, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe.0.dr | String found in binary or memory: http://crl.globalsign.com/root-r3.crl0G |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001321000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000000C71000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001321000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001321000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: svchost.exe, 00000005.00000002.2935466482.0000015027400000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.ver) |
Source: getscreen-524501439-x86.exe, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: getscreen-524501439-x86.exe, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: getscreen-524501439-x86.exe, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: svchost.exe, 00000005.00000003.1705073004.0000015027308000.00000004.00000800.00020000.00000000.sdmp, qmgr.db.5.dr, edb.log.5.dr | String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYjFkQUFWdmlaXy12MHFU |
Source: edb.log.5.dr | String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome/acosgr5ufcefr7w7nv4v6k4ebdda_117.0.5938.132/117.0.5 |
Source: edb.log.5.dr | String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acaa5khuklrahrby256zitbxd5wq_1.0.2512.1/n |
Source: edb.log.5.dr | String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acaxuysrwzdnwqutaimsxybnjbrq_2023.9.25.0/ |
Source: svchost.exe, 00000005.00000003.1705073004.0000015027308000.00000004.00000800.00020000.00000000.sdmp, qmgr.db.5.dr, edb.log.5.dr | String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adhioj45hzjkfunn7ccrbqyyhu3q_20230916.567 |
Source: svchost.exe, 00000005.00000003.1705073004.0000015027308000.00000004.00000800.00020000.00000000.sdmp, qmgr.db.5.dr, edb.log.5.dr | String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adqyi2uk2bd7epzsrzisajjiqe_9.48.0/gcmjkmg |
Source: svchost.exe, 00000005.00000003.1705073004.000001502733D000.00000004.00000800.00020000.00000000.sdmp, qmgr.db.5.dr, edb.log.5.dr | String found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/dix4vjifjljmfobl3a7lhcpvw4_414/lmelglejhe |
Source: edb.log.5.dr | String found in binary or memory: http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v32_16.0.16827.20 |
Source: getscreen-524501439-x86.exe, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe.0.dr | String found in binary or memory: http://ocsp.digicert.com0A |
Source: getscreen-524501439-x86.exe, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe.0.dr | String found in binary or memory: http://ocsp.digicert.com0C |
Source: getscreen-524501439-x86.exe, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe.0.dr | String found in binary or memory: http://ocsp.digicert.com0X |
Source: getscreen-524501439-x86.exe, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe.0.dr | String found in binary or memory: http://ocsp.globalsign.com/codesigningrootr450F |
Source: getscreen-524501439-x86.exe, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe.0.dr | String found in binary or memory: http://ocsp.globalsign.com/gsgccr45evcodesignca20200U |
Source: getscreen-524501439-x86.exe, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe.0.dr | String found in binary or memory: http://ocsp.globalsign.com/rootr30; |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001705000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000001055000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001705000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001705000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://proxy.contoso.com:3128/ |
Source: getscreen-524501439-x86.exe, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe.0.dr | String found in binary or memory: http://secure.globalsign.com/cacert/codesigningrootr45.crt0A |
Source: getscreen-524501439-x86.exe, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe.0.dr | String found in binary or memory: http://secure.globalsign.com/cacert/gsgccr45evcodesignca2020.crt0? |
Source: getscreen-524501439-x86.exe, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe.0.dr | String found in binary or memory: http://secure.globalsign.com/cacert/root-r3.crt06 |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001321000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000000C71000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001321000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001321000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions-01 |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001321000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000000C71000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001321000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001321000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions-01http://www.webrtc.org/exper |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001321000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000000C71000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001321000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001321000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/abs-capture-time |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001321000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000000C71000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001321000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001321000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/abs-capture-timeurn:3gpp:video-orientationhttp://www.we |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001321000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000000C71000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001321000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001321000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/abs-send-time |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001321000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000000C71000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001321000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001321000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/color-space |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001321000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000000C71000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001321000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001321000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/generic-frame-descriptor-00 |
Source: getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001321000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/inband-cn |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001321000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000000C71000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001321000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001321000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/playout-delay |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001321000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000000C71000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001321000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001321000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/transport-wide-cc-02 |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001321000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000000C71000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001321000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001321000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-content-type |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001321000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000000C71000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001321000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001321000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-frame-tracking-id |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001321000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000000C71000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001321000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001321000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-layers-allocation00 |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001321000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000000C71000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001321000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001321000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-timing |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001705000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000001055000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001705000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001705000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.winimage.com/zLibDll |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001321000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000000C71000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001321000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001321000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: https://aomediacodec.github.io/av1-rtp-spec/#dependency-descriptor-rtp-header-extension |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001705000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000001055000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001705000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001705000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: https://docs.g |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001705000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000001055000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001705000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001705000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: https://docs.ge |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001705000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000001055000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001705000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001705000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: https://docs.getsa |
Source: getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001705000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: https://docs.getsc |
Source: getscreen-524501439-x86.exe, 00000002.00000003.1752780951.0000000007E10000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://docs.getscr |
Source: getscreen-524501439-x86.exe, 00000002.00000003.1752780951.0000000007E10000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://docs.getscr& |
Source: getscreen-524501439-x86.exe, 00000002.00000003.1776727335.0000000002B59000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://docs.getscreen.me/en/rules/privacy- |
Source: getscreen-524501439-x86.exe, 00000004.00000003.1749131411.00000000006FF000.00000004.00000020.00020000.00000000.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1750926714.00000000006E8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://docs.getscreen.me/en/rules/privacy-policy/ |
Source: getscreen-524501439-x86.exe, 00000004.00000003.1749131411.00000000006FF000.00000004.00000020.00020000.00000000.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1750926714.00000000006E8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://docs.getscreen.me/en/rules/terms-of-use/ |
Source: getscreen-524501439-x86.exe, 00000002.00000003.1752582138.000000000524B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://docs.getscreen.me/user-guides/agent/ |
Source: svchost.exe, 00000005.00000003.1705073004.00000150273B2000.00000004.00000800.00020000.00000000.sdmp, qmgr.db.5.dr, edb.log.5.dr | String found in binary or memory: https://g.live.com/1rewlive5skydrive/OneDriveProductionV2?OneDriveUpdate=9c123752e31a927b78dc96231b6 |
Source: edb.log.5.dr | String found in binary or memory: https://g.live.com/odclientsettings/Prod.C: |
Source: edb.log.5.dr | String found in binary or memory: https://g.live.com/odclientsettings/ProdV2 |
Source: edb.log.5.dr | String found in binary or memory: https://g.live.com/odclientsettings/ProdV2.C: |
Source: svchost.exe, 00000005.00000003.1705073004.00000150273B2000.00000004.00000800.00020000.00000000.sdmp, edb.log.5.dr | String found in binary or memory: https://g.live.com/odclientsettings/ProdV2?OneDriveUpdate=f359a5df14f97b6802371976c96 |
Source: svchost.exe, 00000005.00000003.1705073004.00000150273B2000.00000004.00000800.00020000.00000000.sdmp, qmgr.db.5.dr, edb.log.5.dr | String found in binary or memory: https://oneclient.sfx.ms/Win/Installers/23.194.0917.0001/amd64/OneDriveSetup.exe |
Source: edb.log.5.dr | String found in binary or memory: https://oneclient.sfx.ms/Win/Prod/21.220.1024.0005/OneDriveSetup.exe.C: |
Source: getscreen-524501439-x86.exe, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe.0.dr | String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: ntdsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: sas.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dsparse.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: firewallapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: fwbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: fwpolicyiomgr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: mmdevapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: avrt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: mfwmaaec.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: mfperfhelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: avrt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: audioses.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: windows.ui.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: windowmanagementapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: inputhost.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: samlib.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: symsrv.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: ntdsapi.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: sas.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: dsparse.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: ntdsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: sas.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dsparse.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: d2d1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dataexchange.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dcomp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: directmanipulation.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: resourcepolicyclient.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: d3d10warp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dxcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: mscms.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: coloradapterclient.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: icm32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: uiautomationcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: seclogon.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: ntdsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: sas.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dsparse.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: qmgr.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: bitsperf.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: firewallapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: esent.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: fwbase.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: flightsettings.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: netprofm.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: npmproxy.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: bitsigd.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: upnp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ssdpapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: appxdeploymentclient.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wsmauto.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wsmsvc.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: dsrole.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: pcwum.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: msv1_0.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ntlmshared.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: cryptdll.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: webio.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: rmclient.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: usermgrcli.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: execmodelclient.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: execmodelproxy.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: resourcepolicyclient.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: vssapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: vsstrace.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: samlib.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: es.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: bitsproxy.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: mpr.dll | Jump to behavior |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\TextInputFramework.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CLBCatQ.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009741000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cfgmgr32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009A9D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wbemsvc.pdb\* source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\samlib.pdbba source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: profapi.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.00000000096D6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winsta.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009F6A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernel32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079A4000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreUIComponents.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004C6F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wbemprox.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\twinapi.appcore.pdb8 source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CD8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemcomn.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A026000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ucrtbase.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B7A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fwbase.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.00000000098C6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\dhcpcsvc6.pdbdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CD8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A1F4000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msvcrt.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: e3samlib.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.00000000090B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wrpcrt4.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007A9F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wntdll.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemcomn.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A026000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dhcpcsvc6.pdb*eC source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreMessaging.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009D2D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: userenv.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008528000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: advapi32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079AF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wsspicli.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009257000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ucrtbase.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B7A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\JSAMSIProvider32.pdbP source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004C6F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\rasadhlp.pdb\*o source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dhcpcsvc6.pdbationNr~. source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\DLL\dhcpcsvc6.pdbNp source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000008DCE000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: audioses.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009BBF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CLBCatQ.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009741000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winspool.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009119000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fwpuclnt.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernelbase.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079AA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shlwapi.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008208000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dhcpcsvc.pdb\*torS~~2 source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\exe\getscreen-524501439-x86.pdbp source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004C6F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\samlib.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreMessaging.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009D2D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: gdiplus.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.00000000084F0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: bcryptprimitives.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009278000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samcli.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009246000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cryptbase.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009262000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreUIComponents.pdb0 source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004C6F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: netapi32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008506000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\twinapi.appcore.pdbL source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CD8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\JSAMSIProvider32.pdbp source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004C6F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreUIComponents.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009CD2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: comdlg32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B19000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ws2_32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B96000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: advapi32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079AF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleacc.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008517000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: InputHost.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009EA5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winspool.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009119000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MFWMAAEC.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009B05000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WinTypes.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009D88000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fwbase.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.00000000098C6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\InputHost.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: iphlpapi.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.00000000084F5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\FWPolicyIOMgr.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004C6F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemsvc.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A02C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wmswsock.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A251000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\JSAMSIProvider32.pdbb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CD8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\WindowManagementAPI.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wrpcrt4.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007A9F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: secur32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008522000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winmm.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.00000000090B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\samlib.pdbcyS source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FirewallAPI.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000979C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: powrprof.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.000000000851D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\exe\getscreen-524501439-x86.pdb:J source: getscreen-524501439-x86.exe, 00000000.00000002.1725192173.0000000002A28000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ole32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.00000000082E7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\samlib.pdbiB} source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FWPolicyIOMgr.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009929000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.UI.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009C19000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\fwpuclnt.pdbo source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cfgmgr32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009A9D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\JSAMSIProvider32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CD8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: combase.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B74000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.Storage.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009676000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wuser32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B85000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fwpuclnt.pdb2}n source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\dhcpcsvc.pdb*} source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernel32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079A4000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinapi.appcore.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009E3C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: secur32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008522000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winsta.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009F6A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dsparse.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009251000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ole32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.00000000082E7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\CoreMessaging.pdbdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CD8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msvcp_win.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008203000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: version.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000008F3B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Kernel.Appcore.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.00000000096DC000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\CoreUIComponents.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CD8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WinTypes.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009D88000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32full.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.00000000081FD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shell32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008281000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A1F4000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\dhcpcsvc6.pdbi source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CD8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinapi.appcore.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CB7000.00000004.00000020.00020000.00000000.sdmp, getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009E3C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WindowManagementAPI.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009DE2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mfperfhelper.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009B5F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: comdlg32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B19000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\MpOAV.pdbeUserC source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\JSAMSIProvider32.pdb! source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CD8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wmswsock.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winmm.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.00000000090B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: devobj.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009A41000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shlwapi.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008208000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\exe\getscreen-524501439-x86.pdb,J source: getscreen-524501439-x86.exe, 00000000.00000002.1725192173.0000000002A28000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\msi.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CD8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleacc.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008517000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B90000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wsspicli.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009257000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samcli.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009246000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shell32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008281000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FirewallAPI.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000979C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\JSAMSIProvider32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004C6F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msvcp_win.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008203000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: powrprof.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.000000000851D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dnsapi.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009801000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wtsapi32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.000000000917F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: userenv.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008528000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WindowManagementAPI.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009DE2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MFWMAAEC.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009B05000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreUIComponents.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009CD2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.Storage.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009676000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wUxTheme.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.000000000926D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: devobj.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009A41000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: d3d11.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.000000000848E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc6.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A199000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fwpuclnt.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A2B3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: gdiplus.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.00000000084F0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samlib.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A2B9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreMessaging.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004C6F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dbghelp.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.00000000084EA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: combase.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B74000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdb\*b source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wntdll.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: d3d11.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.000000000848E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: profapi.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.00000000096D6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msvcrt.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc6.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A199000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wmswsock.pdbZ~ source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32full.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.00000000081FD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\twinapi.appcore.pdby source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CD8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\DLL\dhcpcsvc6.pdb4 source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000008DCE000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\rasadhlp.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: audioses.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009BBF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fastprox.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A086000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemsvc.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A02C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samlib.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A2B9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fastprox.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A086000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msctf.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009273000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\DLL\dhcpcsvc6.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000008DCE000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FWPolicyIOMgr.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009929000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wmswsock.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A251000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: version.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000008F3B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dsparse.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009251000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dnsapi.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009801000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dbghelp.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.00000000084EA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Kernel.Appcore.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.00000000096DC000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: C:\Github-runner\_work\agent-windows\agent-windows\console\Win32\Release\getscreen.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001705000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000001055000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001705000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001705000.00000040.00000001.01000000.00000003.sdmp |
Source: | Binary string: ws2_32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B96000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fwpuclnt.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.000000000A2B3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wUxTheme.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.000000000926D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: netapi32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.0000000008506000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cryptbase.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009262000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B90000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernelbase.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.00000000079AA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msctf.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009273000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: bcryptprimitives.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.0000000009278000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mfperfhelper.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009B5F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.UI.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009C19000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wtsapi32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1730280090.000000000917F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleaut32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.00000000082EC000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: iphlpapi.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1728765537.00000000084F5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreMessaging.pdbdb source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004C6F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wuser32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B85000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: comctl32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.1728022252.0000000007B9B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: InputHost.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.1731844658.0000000009EA5000.00000004.00000020.00020000.00000000.sdmp |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1725192173.0000000002A66000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllvv] |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1723007083.0000000001705000.00000040.00000001.01000000.00000003.sdmp, zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000001055000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1777411389.0000000001705000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001705000.00000040.00000001.01000000.00000003.sdmp | Binary or memory string: Hyper-V console (use port 2179, disable negotiation) |
Source: zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1682131127.0000000000C71000.00000040.00000001.01000000.00000004.sdmp | Binary or memory string: <WebRTC-AllowMACBasedIPv6WebRTC-BindUsingInterfaceNameVMnetWebRTC-UseDifferentiatedCellularCostsWebRTC-AddNetworkCostToVpnNet[:id= |
Source: getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001321000.00000040.00000001.01000000.00000003.sdmp | Binary or memory string: VMnet |
Source: getscreen-524501439-x86.exe, 00000002.00000003.1755641619.0000000002BA6000.00000004.00000020.00020000.00000000.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1779924818.0000000002BC0000.00000004.00000020.00020000.00000000.sdmp, getscreen-524501439-x86.exe, 00000002.00000003.1757868614.0000000002BB1000.00000004.00000020.00020000.00000000.sdmp, getscreen-524501439-x86.exe, 00000002.00000003.1768638360.0000000002BBB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAWnYZ |
Source: getscreen-524501439-x86.exe, 00000004.00000002.1751187888.0000000001321000.00000040.00000001.01000000.00000003.sdmp | Binary or memory string: WebRTC-AllowMACBasedIPv6WebRTC-BindUsingInterfaceNameVMnetWebRTC-UseDifferentiatedCellularCostsWebRTC-AddNetworkCostToVpnNet[:id= |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1727003171.0000000005EF0000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: RAM slot #0RAM slot #0@VMware Virtual RAMVMW-4096MB00000001 |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CE4000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: {"token":"","uid":"71434D56-1548-ED3D-AEE6-C75AECD93BF0","turbo":"2203681736138584UtEFjbrdjMX3qgoXgI9f","turbo_old":"","invite":"","brand":"","install":false,"admin":true,"isadmin":true,"onetime":true,"file_download":true,"name":"367706","nonadmin":true,"islock":false,"blackscreen_available":true,"hibernate":true,"power_supply":true,"silent":false,"start_time":1736141518,"os":"win","rdp":false,"os_user":"user","os_username":"","build":228,"version":"3.1.5","hardware":"{\"CPU\":\"Intel(R) Core(TM)2 CPU 6600 @ 2.40 GHz\",\"CPUSpeed\":2000,\"CPUCores\":4,\"CPUCoresLogical\":1,\"CPUFamily\":\"Intel64 Family 6 Model 143 Stepping 8\",\"BIOS\":\"48NUKDZM52\",\"BIOSVersion\":\"20221121\",\"BIOSDate\":\"\",\"RAMPhys\":8191,\"RAMPhysAvail\":2204,\"RAMVirt\":2047,\"RAMVirtAvail\":1865,\"RAMPageFile\":8191,\"RAMBanks\":[{\"Bank\":\"RAM slot #0\",\"Locator\":\"RAM slot #0\",\"DataWidth\":64,\"Manufacturer\":\"VMware Virtual RAM\",\"PartNumber\":\"VMW-4096MB\",\"SerialNumber\":\"00000001\",\"Capacity\":4096}],\"VideoName\":\"LHG8FP6N\",\"VideoRAM\":1024,\"VideoCards\":[{\"Name\":\"LHG8FP6N\",\"RAM\":1024,\"Integrated\":false}],\"Locale\":\"0809\",\"LocaleOemPage\":\"1252\",\"LocaleCountry\":\"Switzerland\",\"LocaleCurrency\":\"CHF\",\"LocaleTimezone\":60,\"LocaleFormatTime\":\"HH:mm:ss\",\"LocaleFormatDate\":\"dd\\\/MM\\\/yyyy\",\"ComputerModel\":\"zALbofPG\",\"ComputerDomain\":\"RWrlV\",\"ComputerWorkgroup\":\"WORKGROUP\",\"ComputerName\":\"user-PC\",\"ComputerIP\":[\"192.168.2.4\",\"fe80::29b9:a951:1791:4eb3\"],\"OSName\":\"Microsoft Windows 10 Pro\",\"OSVersion\":\"10.0.19045\",\"HDD\":[{\"Model\":\"A562E5EE SCSI Disk Device\",\"Size\":393199}],\"LogicalDisks\":[{\"Disk\":\"C:\",\"Name\":\"\",\"FileSystem\":\"NTFS\",\"Size\":213143,\"FreeSpace\":19035}],\"SoundDevices\":[],\"NetAdapters\":[{\"Name\":\"Intel(R) 82574L Gigabit Network Connection\",\"Manufacturer\":\"Intel Corporation\",\"MACAddress\":\"EC:F4:BB:EA:15:88\",\"Speed\":953,\"Addresses\":\"192.168.2.4, fe80::29b9:a951:1791:4eb3\",\"DNS\":\"1.1.1.1\",\"DCHP\":\"\",\"Cable\":true,\"WoL\":false}],\"Monitors\":[]}"} |
Source: getscreen-524501439-x86.exe, 00000002.00000003.1755641619.0000000002BA6000.00000004.00000020.00020000.00000000.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1779924818.0000000002BC0000.00000004.00000020.00020000.00000000.sdmp, getscreen-524501439-x86.exe, 00000002.00000003.1757868614.0000000002BB1000.00000004.00000020.00020000.00000000.sdmp, getscreen-524501439-x86.exe, 00000002.00000002.1779549852.0000000002B24000.00000004.00000020.00020000.00000000.sdmp, getscreen-524501439-x86.exe, 00000002.00000003.1768638360.0000000002BBB000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000005.00000002.2935515895.0000015027440000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000005.00000002.2935562729.0000015027458000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000005.00000002.2934467618.0000015021E2B000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1727003171.0000000005EF0000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: VMware Virtual RAM |
Source: zwvztpbbwxeyisrxsphxsxjmazygqyh-elevate.exe, 00000001.00000002.1684098147.0000000002995000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll" |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1727003171.0000000005EFA000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: {"token":"","uid":"71434D56-1548-ED3D-AEE6-C75AECD93BF0","turbo":"2203681736138584UtEFjbrdjMX3qgoXgI9f","turbo_old":"","invite":"","brand":"","install":false,"admin":true,"isadmin":true,"onetime":true,"file_download":true,"name":"367706","nonadmin":true,"islock":false,"blackscreen_available":true,"hibernate":true,"power_supply":true,"silent":false,"start_time":1736141518,"os":"win","rdp":false,"os_user":"user","os_username":"","build":228,"version":"3.1.5","hardware":"{\"CPU\":\"Intel(R) Core(TM)2 CPU 6600 @ 2.40 GHz\",\"CPUSpeed\":2000,\"CPUCores\":4,\"CPUCoresLogical\":1,\"CPUFamily\":\"Intel64 Family 6 Model 143 Stepping 8\",\"BIOS\":\"48NUKDZM52\",\"BIOSVersion\":\"20221121\",\"BIOSDate\":\"\",\"RAMPhys\":8191,\"RAMPhysAvail\":2204,\"RAMVirt\":2047,\"RAMVirtAvail\":1865,\"RAMPageFile\":8191,\"RAMBanks\":[{\"Bank\":\"RAM slot #0\",\"Locator\":\"RAM slot #0\",\"DataWidth\":64,\"Manufacturer\":\"VMware Virtual RAM\",\"PartNumber\":\"VMW-4096MB\",\"SerialNumber\":\"00000001\",\"Capacity\":4096}],\"VideoName |
Source: getscreen-524501439-x86.exe, 00000004.00000003.1748674162.00000000006B6000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1727003171.0000000005EFA000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: {"CPU":"Intel(R) Core(TM)2 CPU 6600 @ 2.40 GHz","CPUSpeed":2000,"CPUCores":4,"CPUCoresLogical":1,"CPUFamily":"Intel64 Family 6 Model 143 Stepping 8","BIOS":"48NUKDZM52","BIOSVersion":"20221121","BIOSDate":"","RAMPhys":8191,"RAMPhysAvail":2204,"RAMVirt":2047,"RAMVirtAvail":1865,"RAMPageFile":8191,"RAMBanks":[{"Bank":"RAM slot #0","Locator":"RAM slot #0","DataWidth":64,"Manufacturer":"VMware Virtual RAM","PartNumber":"VMW-4096MB","SerialNumber":"00000001","Capacity":4096}],"VideoName":"LHG8FP6N","VideoRAM":1024,"VideoCards":[{"Name":"LHG8FP6N","RAM":1024,"Integrated":false}],"Locale":"0809","LocaleOemPage":"1252","LocaleCountry":"Switzerland","LocaleCurrency":"CHF","LocaleTimezone":60,"LocaleFormatTime":"HH:mm:ss","LocaleFormatDate":"dd\/MM\/yyyy","ComputerModel":"zALbofPG","ComputerDomain":"RWrlV","ComputerWorkgroup":"WORKGROUP","ComputerName":"user-PC","ComputerIP":["192.168.2.4","fe80::29b9:a951:1791:4eb3"],"OSName":"Microsoft Windows 10 Pro","OSVersion":"10.0.19045","HDD":[{"Model":"A562E5EE SCSI Disk Devi |
Source: getscreen-524501439-x86.exe, 00000000.00000002.1725788359.0000000004CB7000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: $VMware Virtual RAM" |