Source: | Binary string: \??\C:\Users\user\Desktop\DLL\dhcpcsvc.pdbdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wmswsock.pdbbyIc source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernel32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000763C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ucrtbase.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007814000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fwbase.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000987E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A1AD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msvcrt.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000764D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: e3samlib.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A20A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\rasadhlp.pdbyPorts source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fwpuclnt.pdbA source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\rasadhlp.pdbFwAd source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: advapi32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007647000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\samlib.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\WindowManagementAPI.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BBF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: bcrypt.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.0000000008E38000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: usp10.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.000000000912F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winspool.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.000000000918B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fwpuclnt.pdbi source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: usp10.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.000000000912F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\mfperfhelper.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BD6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreMessaging.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009D98000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: bcryptprimitives.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009575000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\avrt.pdbdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cryptbase.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.000000000920C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\TextInputFramework.pdbed source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BBF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\JSAMSIProvider32.pdbtd source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BBF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winspool.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.000000000918B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MFWMAAEC.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009ABC000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fwbase.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000987E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemsvc.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009FE5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fastprox.pdbsFw source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wmswsock.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A20A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\TextInputFramework.pdbN source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreUIComponents.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BBF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreMessaging.pdbk source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BD6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreMessaging.pdbn5 source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BD6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\rasadhlp.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FWPolicyIOMgr.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.00000000098E1000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.UI.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009BD0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wmswsock.pdbdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dhcpcsvc.pdbbFw source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: rasadhlp.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A268000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cfgmgr32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009A54000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: combase.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000780F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.Storage.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000962D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wuser32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.00000000081D9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernel32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000763C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinapi.appcore.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009E4E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wmswsock.pdbdbl source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shcore.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.0000000008176000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: rasadhlp.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A268000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32full.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.00000000081E4000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: UMPDC.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.0000000009206000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Kernel.Appcore.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009693000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A1AD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinapi.appcore.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009E4E000.00000004.00000020.00020000.00000000.sdmp, getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004B90000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mfperfhelper.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009B16000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\MpOAV.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: propsys.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009EB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\JSAMSIProvider32.pdbb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BBF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\MpOAV.pdbb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\Amsi.pdbll source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wbemcomn.pdbX source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msvcp_win.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.0000000008267000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wimm32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.0000000008272000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wtsapi32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.00000000091F0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MFWMAAEC.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009ABC000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WindowManagementAPI.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009C2F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\twinapi.appcore.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\dhcpcsvc.pdbh source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\MMDevAPI.pdbdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wUxTheme.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009515000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreUIComponents.pdbug source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BBF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: d3d11.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.0000000008B3A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\FWPolicyIOMgr.pdbdll.J source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BD6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samlib.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A273000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\fwpuclnt.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6121869920.0000000002B3F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dbghelp.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.000000000849B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\dhcpcsvc6.pdbb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: combase.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000780F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: d3d11.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.0000000008B3A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32full.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.00000000081E4000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fastprox.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: propsys.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009EB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\WinTypes.pdbbE source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fastprox.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A03F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samlib.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A273000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemsvc.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009FE5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fastprox.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A03F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FWPolicyIOMgr.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.00000000098E1000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: TextInputFramework.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009C88000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\samlib.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: UMPDC.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.0000000009206000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dbghelp.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.000000000849B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: C:\Github-runner\_work\agent-windows\agent-windows\console\Win32\Release\getscreen.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000001345000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001D45000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000001345000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000001345000.00000040.00000001.01000000.00000003.sdmp |
Source: | Binary string: fwpuclnt.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A26D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: netapi32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.0000000008CB3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dhcpcsvc.pdb\* source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\JSAMSIProvider32.pdbdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\samlib.pdbeAK source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: bcryptprimitives.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009575000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdb*; source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\ws2_32.pdbF source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdb\* source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mfperfhelper.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009B16000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.UI.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009BD0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: iphlpapi.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.0000000008A74000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\JSAMSIProvider32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wuser32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.00000000081D9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: InputHost.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009CE3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\Windows.UI.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CLBCatQ.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.00000000096FB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wmswsock.pdbb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winsta.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009F21000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: profapi.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000968E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: bcrypt.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.0000000008E38000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\twinapi.appcore.pdbR source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wrpcrt4.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007738000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\Kernel.Appcore.pdb~5 source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BD6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdb\*w source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreMessaging.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009D98000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\CoreMessaging.pdb* source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ucrtbase.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007814000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CLBCatQ.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.00000000096FB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wmswsock.pdb\*yp source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernelbase.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007641000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shlwapi.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.00000000081EA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\CoreUIComponents.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: netapi32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.0000000008CB3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\rasadhlp.pdbpv source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fastprox.pdbdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreUIComponents.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009DF3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\Windows.Storage.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BD6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: InputHost.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009CE3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: advapi32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007647000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WinTypes.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009D3E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: iphlpapi.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.0000000008A74000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MMDevAPI.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000999E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wrpcrt4.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007738000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FirewallAPI.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009756000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\twinapi.appcore.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BD6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fastprox.pdb* source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\twinapi.appcore.pdb.5 source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BD6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\twinapi.appcore.pdb6 source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\TextInputFramework.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wmswsock.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\exe\getscreen-524501439-x86.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BD6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wbemcomn.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winsta.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009F21000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: TextInputFramework.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009C88000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dhcpcsvc.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dsparse.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.00000000091FB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msvcp_win.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.0000000008267000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\rasadhlp.pdbui1 source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WinTypes.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009D3E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\exe\getscreen-524501439-x86.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6121869920.0000000002A98000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WindowManagementAPI.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009C2F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wbemcomn.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shcore.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.0000000008176000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\samlib.pdb$ source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shlwapi.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.00000000081EA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleaut32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.00000000082D8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MMDevAPI.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000999E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FirewallAPI.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009756000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\FWPolicyIOMgr.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BD6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\rasadhlp.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wimm32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.0000000008272000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreUIComponents.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009DF3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\CoreMessaging.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdbGetR_ source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\samlib.pdb\**' source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\rasadhlp.pdbi+ source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc6.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A152000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fwpuclnt.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A26D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdbrfac source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc6.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A152000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: profapi.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000968E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msvcrt.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000764D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\MpOAV.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wmswsock.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A20A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\JSAMSIProvider32.pdb\* source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fwpuclnt.pdbiN source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dsparse.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.00000000091FB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Kernel.Appcore.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009693000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wmswsock.pdbdbS source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wUxTheme.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009515000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cryptbase.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.000000000920C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdbb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\samlib.pdbpo source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\winsta.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wtsapi32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.00000000091F0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleaut32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.00000000082D8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\WindowManagementAPI.pdbRd source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BBF000.00000004.00000020.00020000.00000000.sdmp |
Source: getscreen-524501439-x86.exe, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: getscreen-524501439-x86.exe, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: getscreen-524501439-x86.exe, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001961000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000000F61000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001961000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000000F61000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://crl.comodoca.com/COMODOCertificationAuthority.crl0 |
Source: getscreen-524501439-x86.exe, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe.0.dr | String found in binary or memory: http://crl.globalsign.com/codesigningrootr45.crl0U |
Source: getscreen-524501439-x86.exe, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe.0.dr | String found in binary or memory: http://crl.globalsign.com/gsgccr45evcodesignca2020.crl0 |
Source: getscreen-524501439-x86.exe, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe.0.dr | String found in binary or memory: http://crl.globalsign.com/root-r3.crl0G |
Source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001961000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000000F61000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: getscreen-524501439-x86.exe, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: getscreen-524501439-x86.exe, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: getscreen-524501439-x86.exe, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: getscreen-524501439-x86.exe, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe.0.dr | String found in binary or memory: http://ocsp.digicert.com0A |
Source: getscreen-524501439-x86.exe, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe.0.dr | String found in binary or memory: http://ocsp.digicert.com0C |
Source: getscreen-524501439-x86.exe, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe.0.dr | String found in binary or memory: http://ocsp.digicert.com0X |
Source: getscreen-524501439-x86.exe, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe.0.dr | String found in binary or memory: http://ocsp.globalsign.com/codesigningrootr450F |
Source: getscreen-524501439-x86.exe, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe.0.dr | String found in binary or memory: http://ocsp.globalsign.com/gsgccr45evcodesignca20200U |
Source: getscreen-524501439-x86.exe, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe.0.dr | String found in binary or memory: http://ocsp.globalsign.com/rootr30; |
Source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000001345000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001D45000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000001345000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000001345000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://proxy.contoso.com:3128/ |
Source: getscreen-524501439-x86.exe, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe.0.dr | String found in binary or memory: http://secure.globalsign.com/cacert/codesigningrootr45.crt0A |
Source: getscreen-524501439-x86.exe, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe.0.dr | String found in binary or memory: http://secure.globalsign.com/cacert/gsgccr45evcodesignca2020.crt0? |
Source: getscreen-524501439-x86.exe, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe.0.dr | String found in binary or memory: http://secure.globalsign.com/cacert/root-r3.crt06 |
Source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001961000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000000F61000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions-01 |
Source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001961000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000000F61000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions-01http://www.webrtc.org/exper |
Source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001961000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000000F61000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/abs-capture-time |
Source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001961000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000000F61000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/abs-capture-timeurn:3gpp:video-orientationhttp://www.we |
Source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001961000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000000F61000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/abs-send-time |
Source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001961000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000000F61000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/color-space |
Source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001961000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000000F61000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/generic-frame-descriptor-00 |
Source: getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000000F61000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/inband-cn |
Source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001961000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000000F61000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/playout-delay |
Source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001961000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000000F61000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/transport-wide-cc-02 |
Source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001961000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000000F61000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-content-type |
Source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001961000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000000F61000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-frame-tracking-id |
Source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001961000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000000F61000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-layers-allocation00 |
Source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001961000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000000F61000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-timing |
Source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000001345000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001D45000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000001345000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000001345000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.winimage.com/zLibDll |
Source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001961000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000000F61000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000000F61000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: https://aomediacodec.github.io/av1-rtp-spec/#dependency-descriptor-rtp-header-extension |
Source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000001345000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001D45000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000001345000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000001345000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: https://docs.g |
Source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000001345000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001D45000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000001345000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000001345000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: https://docs.ge |
Source: getscreen-524501439-x86.exe, 00000004.00000002.6148978081.0000000002959000.00000004.00000010.00020000.00000000.sdmp | String found in binary or memory: https://docs.gets |
Source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000001345000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001D45000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000001345000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000001345000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: https://docs.getsa |
Source: getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000001345000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: https://docs.getsc |
Source: getscreen-524501439-x86.exe, 00000004.00000003.6144064297.0000000002D6C000.00000004.00000020.00020000.00000000.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6149514809.0000000002D6C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://docs.getscreen.me/en/rules/privacy- |
Source: getscreen-524501439-x86.exe, 00000004.00000003.6143022764.0000000002DA0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://docs.getscreen.me/en/rules/privacy-policy/ |
Source: getscreen-524501439-x86.exe, 00000004.00000003.6143022764.0000000002DA0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://docs.getscreen.me/en/rules/terms-of-use/ |
Source: getscreen-524501439-x86.exe, 00000003.00000003.6108953540.00000000078AC000.00000004.00000020.00020000.00000000.sdmp, getscreen-524501439-x86.exe, 00000003.00000003.6158761650.0000000007907000.00000004.00000020.00020000.00000000.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6170451232.0000000007909000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://docs.getscreen.me/user-guides/agent/ |
Source: getscreen-524501439-x86.exe, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe.0.dr | String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: ntdsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: sas.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dsparse.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: firewallapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: fwbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: fwpolicyiomgr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: mmdevapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: avrt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: mfwmaaec.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: mfperfhelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: audioses.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: avrt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: windows.ui.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: windowmanagementapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: inputhost.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: samlib.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: symsrv.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: ntdsapi.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: sas.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: dsparse.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: seclogon.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: ntdsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: sas.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dsparse.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: d2d1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dataexchange.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dcomp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: directmanipulation.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: resourcepolicyclient.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dxcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: mscms.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: coloradapterclient.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: icm32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: uiautomationcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: ntdsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: sas.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: dsparse.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-524501439-x86.exe | Section loaded: winsta.dll | Jump to behavior |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\dhcpcsvc.pdbdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wmswsock.pdbbyIc source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernel32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000763C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ucrtbase.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007814000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fwbase.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000987E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A1AD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msvcrt.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000764D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: e3samlib.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A20A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\rasadhlp.pdbyPorts source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fwpuclnt.pdbA source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\rasadhlp.pdbFwAd source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: advapi32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007647000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\samlib.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\WindowManagementAPI.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BBF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: bcrypt.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.0000000008E38000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: usp10.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.000000000912F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winspool.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.000000000918B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fwpuclnt.pdbi source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: usp10.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.000000000912F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\mfperfhelper.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BD6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreMessaging.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009D98000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: bcryptprimitives.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009575000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\avrt.pdbdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cryptbase.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.000000000920C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\TextInputFramework.pdbed source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BBF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\JSAMSIProvider32.pdbtd source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BBF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winspool.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.000000000918B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MFWMAAEC.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009ABC000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fwbase.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000987E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemsvc.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009FE5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fastprox.pdbsFw source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wmswsock.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A20A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\TextInputFramework.pdbN source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreUIComponents.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BBF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreMessaging.pdbk source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BD6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreMessaging.pdbn5 source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BD6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\rasadhlp.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FWPolicyIOMgr.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.00000000098E1000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.UI.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009BD0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wmswsock.pdbdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dhcpcsvc.pdbbFw source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: rasadhlp.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A268000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cfgmgr32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009A54000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: combase.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000780F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.Storage.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000962D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wuser32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.00000000081D9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernel32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000763C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinapi.appcore.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009E4E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wmswsock.pdbdbl source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shcore.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.0000000008176000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: rasadhlp.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A268000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32full.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.00000000081E4000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: UMPDC.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.0000000009206000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Kernel.Appcore.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009693000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A1AD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinapi.appcore.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009E4E000.00000004.00000020.00020000.00000000.sdmp, getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004B90000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mfperfhelper.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009B16000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\MpOAV.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: propsys.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009EB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\JSAMSIProvider32.pdbb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BBF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\MpOAV.pdbb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\Amsi.pdbll source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wbemcomn.pdbX source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msvcp_win.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.0000000008267000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wimm32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.0000000008272000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wtsapi32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.00000000091F0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MFWMAAEC.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009ABC000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WindowManagementAPI.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009C2F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\twinapi.appcore.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\dhcpcsvc.pdbh source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\MMDevAPI.pdbdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wUxTheme.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009515000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreUIComponents.pdbug source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BBF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: d3d11.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.0000000008B3A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\FWPolicyIOMgr.pdbdll.J source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BD6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samlib.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A273000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\fwpuclnt.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6121869920.0000000002B3F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dbghelp.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.000000000849B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\dhcpcsvc6.pdbb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: combase.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000780F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: d3d11.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.0000000008B3A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32full.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.00000000081E4000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fastprox.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: propsys.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009EB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\WinTypes.pdbbE source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fastprox.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A03F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samlib.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A273000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemsvc.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009FE5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fastprox.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A03F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FWPolicyIOMgr.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.00000000098E1000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: TextInputFramework.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009C88000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\samlib.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: UMPDC.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.0000000009206000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dbghelp.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.000000000849B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: C:\Github-runner\_work\agent-windows\agent-windows\console\Win32\Release\getscreen.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6117736735.0000000001345000.00000040.00000001.01000000.00000003.sdmp, upbvylsrnawdqypxwwbrupmvdvvwzyz-elevate.exe, 00000001.00000002.6086631653.0000000001D45000.00000040.00000001.01000000.00000004.sdmp, getscreen-524501439-x86.exe, 00000003.00000002.6163082020.0000000001345000.00000040.00000001.01000000.00000003.sdmp, getscreen-524501439-x86.exe, 00000004.00000002.6144758915.0000000001345000.00000040.00000001.01000000.00000003.sdmp |
Source: | Binary string: fwpuclnt.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A26D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: netapi32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.0000000008CB3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dhcpcsvc.pdb\* source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\JSAMSIProvider32.pdbdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\samlib.pdbeAK source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: bcryptprimitives.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009575000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdb*; source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\ws2_32.pdbF source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdb\* source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mfperfhelper.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009B16000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.UI.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009BD0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: iphlpapi.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.0000000008A74000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\JSAMSIProvider32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wuser32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.00000000081D9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: InputHost.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009CE3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\Windows.UI.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CLBCatQ.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.00000000096FB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wmswsock.pdbb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winsta.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009F21000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: profapi.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000968E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: bcrypt.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.0000000008E38000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\twinapi.appcore.pdbR source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wrpcrt4.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007738000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\Kernel.Appcore.pdb~5 source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BD6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdb\*w source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreMessaging.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009D98000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\CoreMessaging.pdb* source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ucrtbase.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007814000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CLBCatQ.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.00000000096FB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wmswsock.pdb\*yp source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernelbase.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007641000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shlwapi.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.00000000081EA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\CoreUIComponents.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: netapi32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.0000000008CB3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\rasadhlp.pdbpv source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fastprox.pdbdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreUIComponents.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009DF3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\Windows.Storage.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BD6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: InputHost.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009CE3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: advapi32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007647000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WinTypes.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009D3E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: iphlpapi.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.0000000008A74000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MMDevAPI.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000999E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wrpcrt4.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007738000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FirewallAPI.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009756000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\twinapi.appcore.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BD6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fastprox.pdb* source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\twinapi.appcore.pdb.5 source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BD6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\twinapi.appcore.pdb6 source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\TextInputFramework.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wmswsock.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\exe\getscreen-524501439-x86.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BD6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wbemcomn.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winsta.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009F21000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: TextInputFramework.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009C88000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dhcpcsvc.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dsparse.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.00000000091FB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msvcp_win.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.0000000008267000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\rasadhlp.pdbui1 source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WinTypes.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009D3E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\exe\getscreen-524501439-x86.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6121869920.0000000002A98000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WindowManagementAPI.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009C2F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wbemcomn.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shcore.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.0000000008176000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\samlib.pdb$ source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shlwapi.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.00000000081EA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleaut32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.00000000082D8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MMDevAPI.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000999E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FirewallAPI.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009756000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\FWPolicyIOMgr.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BD6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\rasadhlp.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wimm32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.0000000008272000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreUIComponents.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009DF3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\CoreMessaging.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdbGetR_ source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\samlib.pdb\**' source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\rasadhlp.pdbi+ source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc6.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A152000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fwpuclnt.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A26D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdbrfac source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc6.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A152000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: profapi.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000968E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msvcrt.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000764D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\MpOAV.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wmswsock.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.000000000A20A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\JSAMSIProvider32.pdb\* source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fwpuclnt.pdbiN source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.0000000007620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dsparse.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.00000000091FB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Kernel.Appcore.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009693000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wmswsock.pdbdbS source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wUxTheme.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6130251247.0000000009515000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cryptbase.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.000000000920C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32.pdb( source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdbb source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\samlib.pdbpo source: getscreen-524501439-x86.exe, 00000000.00000002.6125005102.000000000781C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\winsta.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BF8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wtsapi32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6127956715.00000000091F0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleaut32.pdb source: getscreen-524501439-x86.exe, 00000000.00000002.6126158180.00000000082D8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\WindowManagementAPI.pdbRd source: getscreen-524501439-x86.exe, 00000000.00000002.6122763249.0000000004BBF000.00000004.00000020.00020000.00000000.sdmp |