Source: C:\Users\user\AppData\Local\0TU9HPJqFrjaMH2ab2eutLT6.exe |
ReversingLabs: Detection: 34% |
Source: C:\Users\user\AppData\Local\0TU9HPJqFrjaMH2ab2eutLT6.exe |
Virustotal: Detection: 34% |
Perma Link |
Source: C:\Users\user\AppData\Local\0UUxNGvo5SBoNXrhVKNnInBZ.exe |
ReversingLabs: Detection: 34% |
Source: C:\Users\user\AppData\Local\0UUxNGvo5SBoNXrhVKNnInBZ.exe |
Virustotal: Detection: 34% |
Perma Link |
Source: C:\Users\user\AppData\Local\1xM2kELmlEwT0ZdAXbxTFlAd.exe |
ReversingLabs: Detection: 62% |
Source: C:\Users\user\AppData\Local\1xM2kELmlEwT0ZdAXbxTFlAd.exe |
Virustotal: Detection: 47% |
Perma Link |
Source: C:\Users\user\AppData\Local\25hX7FI1dURDmB4jtoeQIHHK.exe |
ReversingLabs: Detection: 36% |
Source: C:\Users\user\AppData\Local\25hX7FI1dURDmB4jtoeQIHHK.exe |
Virustotal: Detection: 44% |
Perma Link |
Source: C:\Users\user\AppData\Local\4LMGAkDVX3uzZmWUtCmUEDjB.exe |
ReversingLabs: Detection: 34% |
Source: C:\Users\user\AppData\Local\4LMGAkDVX3uzZmWUtCmUEDjB.exe |
Virustotal: Detection: 34% |
Perma Link |
Source: C:\Users\user\AppData\Local\5gwWc5VKcUZ5WZf8qmiy07XG.exe |
ReversingLabs: Detection: 44% |
Source: C:\Users\user\AppData\Local\5gwWc5VKcUZ5WZf8qmiy07XG.exe |
Virustotal: Detection: 57% |
Perma Link |
Source: C:\Users\user\AppData\Local\5tBur4jOD2uiOR7o9hLJxfah.exe |
ReversingLabs: Detection: 34% |
Source: C:\Users\user\AppData\Local\5tBur4jOD2uiOR7o9hLJxfah.exe |
Virustotal: Detection: 34% |
Perma Link |
Source: C:\Users\user\AppData\Local\6MTG5E8zAXefmLFaBJ11MZso.exe |
ReversingLabs: Detection: 36% |
Source: C:\Users\user\AppData\Local\6MTG5E8zAXefmLFaBJ11MZso.exe |
Virustotal: Detection: 44% |
Perma Link |
Source: C:\Users\user\AppData\Local\6gZRu0dCotZWu6pX7Uek4x9E.exe |
ReversingLabs: Detection: 34% |
Source: C:\Users\user\AppData\Local\6gZRu0dCotZWu6pX7Uek4x9E.exe |
Virustotal: Detection: 34% |
Perma Link |
Source: C:\Users\user\AppData\Local\7eNXk0Z1HqnaBEGvizZr7Der.exe |
ReversingLabs: Detection: 36% |
Source: C:\Users\user\AppData\Local\7eNXk0Z1HqnaBEGvizZr7Der.exe |
Virustotal: Detection: 44% |
Perma Link |
Source: C:\Users\user\AppData\Local\8b0TqH5XXd1pMSAXbXhjKZq0.exe |
ReversingLabs: Detection: 62% |
Source: C:\Users\user\AppData\Local\8b0TqH5XXd1pMSAXbXhjKZq0.exe |
Virustotal: Detection: 47% |
Perma Link |
Source: C:\Users\user\AppData\Local\92kAaDTkDhRrMy0DmXOUqiGt.exe |
ReversingLabs: Detection: 62% |
Source: C:\Users\user\AppData\Local\92kAaDTkDhRrMy0DmXOUqiGt.exe |
Virustotal: Detection: 47% |
Perma Link |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_00409540 CryptUnprotectData,LocalAlloc,LocalFree, |
18_2_00409540 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_004155A0 CryptBinaryToStringA,GetProcessHeap,RtlAllocateHeap,CryptBinaryToStringA, |
18_2_004155A0 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_00406C10 GetProcessHeap,HeapAlloc,CryptUnprotectData,WideCharToMultiByte,LocalFree, |
18_2_00406C10 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_004094A0 CryptStringToBinaryA,LocalAlloc,CryptStringToBinaryA,LocalFree, |
18_2_004094A0 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_0040BF90 memset,lstrlen,CryptStringToBinaryA,memcpy,lstrcat,lstrcat,lstrcat, |
18_2_0040BF90 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_03659707 CryptStringToBinaryA,LocalAlloc,CryptStringToBinaryA,LocalFree, |
18_2_03659707 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_036597A7 CryptUnprotectData,LocalAlloc,LocalFree, |
18_2_036597A7 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_03656E77 GetProcessHeap,RtlAllocateHeap,CryptUnprotectData,WideCharToMultiByte,LocalFree, |
18_2_03656E77 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_0365C1F7 memset,lstrlen,CryptStringToBinaryA,memcpy,lstrcat,lstrcat,lstrcat, |
18_2_0365C1F7 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_03665807 CryptBinaryToStringA,GetProcessHeap,RtlAllocateHeap,CryptBinaryToStringA, |
18_2_03665807 |
Source: |
Binary string: C:\yicukewiceyal\ge.pdb source: KB7dlYN3AfN1oeAtjoqEId5Q.exe, 0000000A.00000003.2076217074.0000000003751000.00000004.00000020.00020000.00000000.sdmp, u4n8.0.exe, 00000012.00000000.2074815643.000000000041B000.00000002.00000001.01000000.00000012.sdmp, qVgCKtvfJNb4NfGV6kK2PcSn.exe, 00000018.00000003.2166185579.0000000003821000.00000004.00000020.00020000.00000000.sdmp, u3a8.0.exe, 0000002F.00000000.2232630667.000000000041B000.00000002.00000001.01000000.00000026.sdmp |
Source: |
Binary string: Age does not matchThe module age and .pdb age do not match. source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004E5B000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004ECB000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000ACD000.00000040.00000001.01000000.00000009.sdmp |
Source: |
Binary string: symsrv.pdb source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000005008000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000005078000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000C7A000.00000040.00000001.01000000.00000009.sdmp |
Source: |
Binary string: C:\nedadovisiguc\bibufedepisoh\jegode\yapogiboj\hi.pdb source: DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2174618549.00000191A3BE7000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2172221081.00000191A3C49000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2188372013.00000191A3EDF000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2174987664.00000191A3C54000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2174618549.00000191A3C51000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2193224291.00000191A420C000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: PDB not foundUnable to locate the .pdb file in any of the symbol search path locations. source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004E5B000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004ECB000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000ACD000.00000040.00000001.01000000.00000009.sdmp |
Source: |
Binary string: c:\srv\slave\workdir\repos\opera\chromium\src\out\Release\installer_lib.dll.pdb source: 09JXLFzEJOC5kWQEY7XIw75i.exe, 0000000E.00000000.2054530852.000000000091A000.00000002.00000001.01000000.0000000B.sdmp, 09JXLFzEJOC5kWQEY7XIw75i.exe, 00000010.00000000.2058946527.000000000091A000.00000002.00000001.01000000.0000000B.sdmp, 09JXLFzEJOC5kWQEY7XIw75i.exe, 00000011.00000000.2063634359.0000000000CFA000.00000002.00000001.01000000.0000000F.sdmp, 09JXLFzEJOC5kWQEY7XIw75i.exe, 00000016.00000000.2082165285.000000000091A000.00000002.00000001.01000000.0000000B.sdmp, 09JXLFzEJOC5kWQEY7XIw75i.exe, 00000017.00000000.2090318998.000000000091A000.00000002.00000001.01000000.0000000B.sdmp |
Source: |
Binary string: c:\Users\Admin\documents\visual studio 2015\Projects\Winmon\Release\Winmon.pdb source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004BD2000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000843000.00000040.00000001.01000000.00000009.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004C42000.00000004.00001000.00020000.00000000.sdmp, TXqT6X30DuHmvWeCAIdAJgkl.exe, 0000001A.00000003.2105064289.0000000004CB2000.00000004.00001000.00020000.00000000.sdmp |
Source: |
Binary string: C:\javagevo77\xonete\zedikacap-kumefuhan_yevezocusir\nisev.pdb source: DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2224713944.00000191A3CF1000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2215504283.00000191A3BE6000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2222570320.00000191A3BE7000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2212637662.00000191A3CA0000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: Error while loading symbolsUnable to locate the .pdb file in any of the symbol search source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004E5B000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004ECB000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000ACD000.00000040.00000001.01000000.00000009.sdmp |
Source: |
Binary string: C:\Users\Admin\documents\visual studio 2015\Projects\WinmonFS\x64\Release\WinmonFS.pdb source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004BD2000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000843000.00000040.00000001.01000000.00000009.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004C42000.00000004.00001000.00020000.00000000.sdmp, TXqT6X30DuHmvWeCAIdAJgkl.exe, 0000001A.00000003.2105064289.0000000004CB2000.00000004.00001000.00020000.00000000.sdmp |
Source: |
Binary string: DC:\yicukewiceyal\ge.pdb source: KB7dlYN3AfN1oeAtjoqEId5Q.exe, 0000000A.00000003.2076217074.0000000003751000.00000004.00000020.00020000.00000000.sdmp, u4n8.0.exe, 00000012.00000000.2074815643.000000000041B000.00000002.00000001.01000000.00000012.sdmp, qVgCKtvfJNb4NfGV6kK2PcSn.exe, 00000018.00000003.2166185579.0000000003821000.00000004.00000020.00020000.00000000.sdmp, u3a8.0.exe, 0000002F.00000000.2232630667.000000000041B000.00000002.00000001.01000000.00000026.sdmp |
Source: |
Binary string: symsrv.pdbGCTL source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000005008000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000005078000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000C7A000.00000040.00000001.01000000.00000009.sdmp |
Source: |
Binary string: C:\Users\Admin\documents\visual studio 2015\Projects\WinmonFS\Release\WinmonFS.pdb source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004BD2000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000843000.00000040.00000001.01000000.00000009.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004C42000.00000004.00001000.00020000.00000000.sdmp, TXqT6X30DuHmvWeCAIdAJgkl.exe, 0000001A.00000003.2105064289.0000000004CB2000.00000004.00001000.00020000.00000000.sdmp |
Source: |
Binary string: C:\Users\admin\source\repos\driver-process-monitor-master\x64\Release\WinmonProcessMonitor.pdb source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004BD2000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000843000.00000040.00000001.01000000.00000009.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004C42000.00000004.00001000.00020000.00000000.sdmp, TXqT6X30DuHmvWeCAIdAJgkl.exe, 0000001A.00000003.2105064289.0000000004CB2000.00000004.00001000.00020000.00000000.sdmp |
Source: |
Binary string: EfiGuardDxe.pdb source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004E5B000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004ECB000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000ACD000.00000040.00000001.01000000.00000009.sdmp, TXqT6X30DuHmvWeCAIdAJgkl.exe, 0000001A.00000003.2105064289.0000000004F3B000.00000004.00001000.00020000.00000000.sdmp |
Source: |
Binary string: 8>C:\javagevo77\xonete\zedikacap-kumefuhan_yevezocusir\nisev.pdb source: DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2224713944.00000191A3CF1000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2215504283.00000191A3BE6000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2222570320.00000191A3BE7000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2212637662.00000191A3CA0000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: C:\bivonare pif.pdb source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000000.2044586554.000000000041B000.00000002.00000001.01000000.00000008.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000000.2044626083.000000000041B000.00000002.00000001.01000000.00000009.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2229512304.00000191A4D81000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2243509355.00000191A47D8000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2221228866.00000191A3EDF000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2223589423.00000191A3EDF000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2212781209.00000191A3C33000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2212312951.00000191A3CF1000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2223589423.00000191A3F08000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2231025618.00000191A446A000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2223860055.00000191A3F8A000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2224712272.00000191A50DB000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2226978323.00000191A457E000.00000004.00000020.00020000.00000000.sdmp, 7h3MwjMZ6vEaBgd6kdodu3Pw.exe, 00000019.00000000.2099968954.000000000041B000.00000002.00000001.01000000.00000017.sdmp, TXqT6X30DuHmvWeCAIdAJgkl.exe, 0000001A.00000000.2099955782.000000000041B000.00000002.00000001.01000000.00000018.sdmp |
Source: |
Binary string: Signature does not matchThe module signature does not match with .pdb signature source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004E5B000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004ECB000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000ACD000.00000040.00000001.01000000.00000009.sdmp |
Source: |
Binary string: dbghelp.pdb source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004E5B000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004ECB000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000ACD000.00000040.00000001.01000000.00000009.sdmp |
Source: |
Binary string: dbghelp.pdbGCTL source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004E5B000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004ECB000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000ACD000.00000040.00000001.01000000.00000009.sdmp |
Source: |
Binary string: Loader.pdb source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004BD2000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000843000.00000040.00000001.01000000.00000009.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004C42000.00000004.00001000.00020000.00000000.sdmp, TXqT6X30DuHmvWeCAIdAJgkl.exe, 0000001A.00000003.2105064289.0000000004CB2000.00000004.00001000.00020000.00000000.sdmp |
Source: |
Binary string: RC:\nedadovisiguc\bibufedepisoh\jegode\yapogiboj\hi.pdb source: DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2174618549.00000191A3BE7000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2172221081.00000191A3C49000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2188372013.00000191A3EDF000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2174987664.00000191A3C54000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2174618549.00000191A3C51000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2193224291.00000191A420C000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: EfiGuardDxe.pdb7 source: OOMSHFu8BfhOzlMYdVgLGKxh.exe, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3370822127.0000000003A09000.00000040.00000020.00020000.00000000.sdmp |
Source: |
Binary string: c:\srv\slave\workdir\repos\opera\chromium\src\out\Release\installer.exe.pdb source: 09JXLFzEJOC5kWQEY7XIw75i.exe, 0000000E.00000000.2054480906.0000000000907000.00000002.00000001.01000000.0000000B.sdmp, 09JXLFzEJOC5kWQEY7XIw75i.exe, 00000010.00000000.2058903181.0000000000907000.00000002.00000001.01000000.0000000B.sdmp, 09JXLFzEJOC5kWQEY7XIw75i.exe, 00000011.00000000.2063547278.0000000000CE7000.00000002.00000001.01000000.0000000F.sdmp, 09JXLFzEJOC5kWQEY7XIw75i.exe, 00000011.00000002.2070475938.0000000000CE7000.00000002.00000001.01000000.0000000F.sdmp, 09JXLFzEJOC5kWQEY7XIw75i.exe, 00000016.00000000.2081878811.0000000000907000.00000002.00000001.01000000.0000000B.sdmp, 09JXLFzEJOC5kWQEY7XIw75i.exe, 00000017.00000000.2090225681.0000000000907000.00000002.00000001.01000000.0000000B.sdmp |
Source: |
Binary string: Unrecognized pdb formatThis error indicates attempting to access a .pdb file with source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004E5B000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004ECB000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000ACD000.00000040.00000001.01000000.00000009.sdmp |
Source: |
Binary string: A connection with the server could not be establishedAn extended error was returned from the WinHttp serverThe .pdb file is probably no longer indexed in the symbol server share location. source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004E5B000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004ECB000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000ACD000.00000040.00000001.01000000.00000009.sdmp |
Source: |
Binary string: D:\Projects\WinRAR\sfx\build\sfxzip32\Release\sfxzip.pdb source: DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2177073279.00000191A3CA0000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2176633575.00000191A3D63000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2179182546.00000191A3EDE000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2179501454.00000191A3EDF000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2178658771.00000191A3B51000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2179182546.00000191A3DAF000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2176852284.00000191A3C86000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: C:\yixeki-ciguwan38_buyej\jobo.pdb source: DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2170309443.00000191A3BE6000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2172221081.00000191A3C1E000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2170431588.00000191A3BFE000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2172136795.00000191A3CF1000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: ntdll.pdbUGP source: Qg_Appv5.exe, 00000031.00000002.3153910263.00000252B15C0000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: Cvinfo is corruptThe .pdb file contains a corrupted debug codeview information. source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004E5B000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004ECB000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000ACD000.00000040.00000001.01000000.00000009.sdmp |
Source: |
Binary string: Downloading symbols for [%s] %ssrv*symsrv*http://https://_bad_pdb_file.pdb source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004E5B000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004ECB000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000ACD000.00000040.00000001.01000000.00000009.sdmp |
Source: |
Binary string: The symbol server has never indexed any version of this symbol fileNo version of the .pdb file with the given name has ever been registered. source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004E5B000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004ECB000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000ACD000.00000040.00000001.01000000.00000009.sdmp |
Source: |
Binary string: C:\vbox\branch\w64-1.6\out\win.amd64\release\obj\src\VBox\HostDrivers\VBoxDrv\VBoxDrv.pdb source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004BD2000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000843000.00000040.00000001.01000000.00000009.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004C42000.00000004.00001000.00020000.00000000.sdmp, TXqT6X30DuHmvWeCAIdAJgkl.exe, 0000001A.00000003.2105064289.0000000004CB2000.00000004.00001000.00020000.00000000.sdmp |
Source: |
Binary string: c:\Users\Admin\documents\visual studio 2015\Projects\Winmon\x64\Release\Winmon.pdb source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004BD2000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000843000.00000040.00000001.01000000.00000009.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004C42000.00000004.00001000.00020000.00000000.sdmp, TXqT6X30DuHmvWeCAIdAJgkl.exe, 0000001A.00000003.2105064289.0000000004CB2000.00000004.00001000.00020000.00000000.sdmp |
Source: |
Binary string: Drive not readyThis error indicates a .pdb file related failure. source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004E5B000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004ECB000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000ACD000.00000040.00000001.01000000.00000009.sdmp |
Source: |
Binary string: zzz_AsmCodeRange_*FrameDatainvalid string positionstring too long.pdb source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004E5B000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004ECB000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000ACD000.00000040.00000001.01000000.00000009.sdmp |
Source: |
Binary string: Pdb read access deniedYou may be attempting to access a .pdb file with read-only attributes source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004E5B000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004ECB000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000ACD000.00000040.00000001.01000000.00000009.sdmp |
Source: |
Binary string: Unable to locate the .pdb file in this location source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004E5B000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004ECB000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000ACD000.00000040.00000001.01000000.00000009.sdmp |
Source: |
Binary string: The module signature does not match with .pdb signature. source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004E5B000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004ECB000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000ACD000.00000040.00000001.01000000.00000009.sdmp |
Source: |
Binary string: .pdb.dbg source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004E5B000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004ECB000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000ACD000.00000040.00000001.01000000.00000009.sdmp |
Source: |
Binary string: '(EfiGuardDxe.pdbx source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004E5B000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004ECB000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000ACD000.00000040.00000001.01000000.00000009.sdmp, TXqT6X30DuHmvWeCAIdAJgkl.exe, 0000001A.00000003.2105064289.0000000004F3B000.00000004.00001000.00020000.00000000.sdmp |
Source: |
Binary string: ntdll.pdb source: Qg_Appv5.exe, 00000031.00000002.3153910263.00000252B15C0000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: LNC:\noyofalivam\xeguhukur.pdb source: KB7dlYN3AfN1oeAtjoqEId5Q.exe, 0000000A.00000000.2032754701.000000000041B000.00000002.00000001.01000000.00000007.sdmp, KB7dlYN3AfN1oeAtjoqEId5Q.exe, 0000000A.00000002.2684591676.0000000001C98000.00000004.00000020.00020000.00000000.sdmp, qVgCKtvfJNb4NfGV6kK2PcSn.exe, 00000018.00000002.2675239063.0000000001D58000.00000004.00000020.00020000.00000000.sdmp, qVgCKtvfJNb4NfGV6kK2PcSn.exe, 00000018.00000000.2090215768.000000000041B000.00000002.00000001.01000000.00000015.sdmp, bOYJAXg8qqrEFblwExl79wvd.exe, 00000024.00000003.2378051986.0000000001C5E000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: C:\Users\admin\source\repos\driver-process-monitor-master\Release\WinmonProcessMonitor.pdb source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004BD2000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000843000.00000040.00000001.01000000.00000009.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004C42000.00000004.00001000.00020000.00000000.sdmp, TXqT6X30DuHmvWeCAIdAJgkl.exe, 0000001A.00000003.2105064289.0000000004CB2000.00000004.00001000.00020000.00000000.sdmp |
Source: |
Binary string: C:\noyofalivam\xeguhukur.pdb source: KB7dlYN3AfN1oeAtjoqEId5Q.exe, 0000000A.00000000.2032754701.000000000041B000.00000002.00000001.01000000.00000007.sdmp, KB7dlYN3AfN1oeAtjoqEId5Q.exe, 0000000A.00000002.2684591676.0000000001C98000.00000004.00000020.00020000.00000000.sdmp, qVgCKtvfJNb4NfGV6kK2PcSn.exe, 00000018.00000002.2675239063.0000000001D58000.00000004.00000020.00020000.00000000.sdmp, qVgCKtvfJNb4NfGV6kK2PcSn.exe, 00000018.00000000.2090215768.000000000041B000.00000002.00000001.01000000.00000015.sdmp, bOYJAXg8qqrEFblwExl79wvd.exe, 00000024.00000003.2378051986.0000000001C5E000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: or you do not have access permission to the .pdb location. source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004E5B000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004ECB000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000ACD000.00000040.00000001.01000000.00000009.sdmp |
Source: |
Binary string: An Exception happened while downloading the module .pdbPlease open a bug if this is a consistent repro. source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000003.2053143203.0000000004E5B000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000003.2053288422.0000000004ECB000.00000004.00001000.00020000.00000000.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000002.3320561795.0000000000ACD000.00000040.00000001.01000000.00000009.sdmp |
Source: |
Binary string: GC:\bivonare pif.pdb source: oV9qcl4WOt6pr8Qw3ls1WbNr.exe, 0000000B.00000000.2044586554.000000000041B000.00000002.00000001.01000000.00000008.sdmp, OOMSHFu8BfhOzlMYdVgLGKxh.exe, 0000000C.00000000.2044626083.000000000041B000.00000002.00000001.01000000.00000009.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2229512304.00000191A4D81000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2243509355.00000191A47D8000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2221228866.00000191A3EDF000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2223589423.00000191A3EDF000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2212781209.00000191A3C33000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2212312951.00000191A3CF1000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2223589423.00000191A3F08000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2231025618.00000191A446A000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2223860055.00000191A3F8A000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2224712272.00000191A50DB000.00000004.00000020.00020000.00000000.sdmp, DAzvKQG6Ksqk3AfqsZxaFtPP.exe, 0000000D.00000003.2226978323.00000191A457E000.00000004.00000020.00020000.00000000.sdmp, 7h3MwjMZ6vEaBgd6kdodu3Pw.exe, 00000019.00000000.2099968954.000000000041B000.00000002.00000001.01000000.00000017.sdmp, TXqT6X30DuHmvWeCAIdAJgkl.exe, 0000001A.00000000.2099955782.000000000041B000.00000002.00000001.01000000.00000018.sdmp |
Source: |
Binary string: c:\srv\slave\workdir\repos\opera\chromium\src\out\Release\installer.exe.pdb@ source: 09JXLFzEJOC5kWQEY7XIw75i.exe, 0000000E.00000000.2054480906.0000000000907000.00000002.00000001.01000000.0000000B.sdmp, 09JXLFzEJOC5kWQEY7XIw75i.exe, 00000010.00000000.2058903181.0000000000907000.00000002.00000001.01000000.0000000B.sdmp, 09JXLFzEJOC5kWQEY7XIw75i.exe, 00000011.00000000.2063547278.0000000000CE7000.00000002.00000001.01000000.0000000F.sdmp, 09JXLFzEJOC5kWQEY7XIw75i.exe, 00000011.00000002.2070475938.0000000000CE7000.00000002.00000001.01000000.0000000F.sdmp, 09JXLFzEJOC5kWQEY7XIw75i.exe, 00000016.00000000.2081878811.0000000000907000.00000002.00000001.01000000.0000000B.sdmp, 09JXLFzEJOC5kWQEY7XIw75i.exe, 00000017.00000000.2090225681.0000000000907000.00000002.00000001.01000000.0000000B.sdmp |
Source: C:\Users\user\Pictures\KB7dlYN3AfN1oeAtjoqEId5Q.exe |
Code function: 10_2_0041D9E1 FindFirstFileExA, |
10_2_0041D9E1 |
Source: C:\Users\user\Pictures\KB7dlYN3AfN1oeAtjoqEId5Q.exe |
Code function: 10_2_036FDC48 FindFirstFileExA, |
10_2_036FDC48 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_00412570 wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,wsprintfA,StrCmpCA,wsprintfA,wsprintfA,PathMatchSpecA,lstrcat,lstrcat,lstrcat,lstrcat,lstrcat,CopyFileA,DeleteFileA,FindNextFileA,FindClose, |
18_2_00412570 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_0040D1C0 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,FindNextFileA,FindClose, |
18_2_0040D1C0 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_004015C0 FindFirstFileA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, |
18_2_004015C0 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_00411650 wsprintfA,FindFirstFileA,lstrcat,StrCmpCA,StrCmpCA,wsprintfA,PathMatchSpecA,CoInitialize,lstrcat,lstrlen,StrCmpCA,wsprintfA,wsprintfA,PathMatchSpecA,wsprintfA,CopyFileA,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,DeleteFileA,FindNextFileA,FindClose, |
18_2_00411650 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_0040B610 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,CopyFileA,StrCmpCA,DeleteFileA,StrCmpCA,FindNextFileA,FindClose, |
18_2_0040B610 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_0040DB60 FindFirstFileA,StrCmpCA,StrCmpCA,FindNextFileA, |
18_2_0040DB60 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_00411B80 wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,lstrcat,lstrcat,lstrcat,lstrcat,lstrcat,lstrcat,FindNextFileA,FindClose, |
18_2_00411B80 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_0040D540 FindFirstFileA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, |
18_2_0040D540 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_004121F0 GetProcessHeap,HeapAlloc,wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,wsprintfA,CopyFileA,DeleteFileA,FindNextFileA,FindClose,lstrcat,lstrcat,lstrlen,lstrlen, |
18_2_004121F0 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_036627D7 wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,wsprintfA,StrCmpCA,wsprintfA,wsprintfA,PathMatchSpecA,lstrcat,lstrcat,lstrcat,lstrcat,lstrcat,CopyFileA,DeleteFileA,FindNextFileA,FindClose, |
18_2_036627D7 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_0365D7A7 FindFirstFileA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, |
18_2_0365D7A7 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_03661DE7 wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,lstrcat,lstrcat,lstrcat,lstrcat,lstrcat,lstrcat,FindNextFileA,FindClose, |
18_2_03661DE7 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_0365DDC7 FindFirstFileA,StrCmpCA,StrCmpCA,FindNextFileA, |
18_2_0365DDC7 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_0365B877 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,CopyFileA,StrCmpCA,DeleteFileA,StrCmpCA,FindNextFileA,FindClose, |
18_2_0365B877 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_03662457 GetProcessHeap,RtlAllocateHeap,wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,wsprintfA,CopyFileA,DeleteFileA,FindNextFileA,FindClose,lstrcat,lstrcat,lstrlen,lstrlen, |
18_2_03662457 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_0365D427 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,FindNextFileA,FindClose, |
18_2_0365D427 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_03651827 FindFirstFileA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, |
18_2_03651827 |
Source: C:\Users\user\AppData\Local\Temp\u4n8.0.exe |
Code function: 18_2_036618B7 wsprintfA,FindFirstFileA,lstrcat,StrCmpCA,StrCmpCA,wsprintfA,PathMatchSpecA,CoInitialize,lstrcat,lstrlen,StrCmpCA,wsprintfA,wsprintfA,PathMatchSpecA,wsprintfA,CopyFileA,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,DeleteFileA,FindNextFileA,FindClose, |
18_2_036618B7 |
Source: C:\Users\user\Pictures\qVgCKtvfJNb4NfGV6kK2PcSn.exe |
Code function: 24_2_0041D9E1 FindFirstFileExA, |
24_2_0041D9E1 |
Source: C:\Users\user\Pictures\qVgCKtvfJNb4NfGV6kK2PcSn.exe |
Code function: 24_2_035BDC48 FindFirstFileExA, |
24_2_035BDC48 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: JdfOLq5feVdmvpgs0LjMwnYk.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: YmxvYosqIkD3WGgGEugsGOqb.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: 4bYBkn0K6Viq0whmT9GrOAT2.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: LN0iazJKg4ouG4Cdljww54MB.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: QWg34yKRBz8JiYYvcjdOCF7u.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: HEvON99qUwgGwLduKeIY9m3g.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: 3CnPiCdeLO8CgUrP4UbQAnuT.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: AcCKWAY2rit0NCEEiGbFUfH5.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: g35TT2UeUHsZDKZA6nJGp8gx.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: 23pMxNJ8xL8sMiQ1yqjR9K8c.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: AzH3HDqfE4sJkRPVWQxgTBGK.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: AGh4ngOKjyPTA1MhPSfxzINB.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: FsjNHv7s5NA6IdBlB5tiEDD0.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: NQrrqi323gUUzwpQ07ZaUtyD.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: c8NFJMLMDBLJHMdfk3CHDEaB.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: IIk86V9YiLn4TNjhwK5b88VE.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: LaMODovStv6L44RtxbPHwqiL.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: OqOO75a2wSIKDIG5IWuKGcqB.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: eC33Ifke2AUsZVZLjjOpDedu.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: ye3UEN0w9Mq4jWow0YS4nlkv.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: 2SYOkWYTvk5LGtvF2lao7jGV.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: MRPKgRkTLDF1UQ6oHCHgO2XR.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: b2NFEf9NNOHrrOJOfbafhFbt.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: UvqvvueWaeqDSywUKVjveKLn.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: FuozRGJXp2ydaW23lwZTemn8.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: aiwK2P0Fl1cIEArMCknG8Xc8.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: TbSdEIYEOocU4YUObNRWEQIE.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: 09gwdWVOD7BhA0wyn6sTP2SG.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: Eaym9owfXDILaNOlOfhlL9pL.exe.4.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File created: j9tdOKRFunkFVu41ydteJnDU.exe.4.dr |
Source: C:\Users\user\Pictures\DAzvKQG6Ksqk3AfqsZxaFtPP.exe |
File created: EraiE9gAjnpZjbi1KlfzUCf5.exe.13.dr |
Source: C:\Users\user\Pictures\DAzvKQG6Ksqk3AfqsZxaFtPP.exe |
File created: pX6Lc7mgFLX2WPHvpZCKNPOu.exe.13.dr |