Source: | Binary string: \??\C:\Users\user\Desktop\DLL\dhcpcsvc.pdbdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernel32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.00000000075A9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreUIComponents.pdbb source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ucrtbase.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007786000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\twinapi.appcore.pdbyK source: getscreen-226997704-x86.exe, 00000000.00000002.244222430201.000000000295F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A3C9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msvcrt.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.00000000075BA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ntdsapi.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000008F36000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\twinapi.appcore.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: e3samlib.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A426000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemcomn.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A1FC000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdb* source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreMessaging.pdbdllKP source: getscreen-226997704-x86.exe, 00000000.00000002.244222430201.000000000295F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: advapi32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.00000000075B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wsspicli.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.000000000941A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\WindowManagementAPI.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\samlib.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: .pdbll (10 source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \user\Desktop\symbols\dll\InputHost.pdbndow source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winspool.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000009349000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\rasadhlp.pdb! source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fwpuclnt.pdbi source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreMessaging.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009F5B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\mfperfhelper.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244222430201.000000000295F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: bcryptprimitives.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.00000000097EF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fwpuclnt.pdbb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: comdlg32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.000000000771E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ws2_32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MpOAV.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A315000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleacc.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000008F98000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winspool.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000009349000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MFWMAAEC.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009CD9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\fwpuclnt.pdb` source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\dhcpcsvc.pdbdb4 source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemsvc.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A201000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wmswsock.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A426000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\InputHost.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: secur32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000008FF3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wwin32u.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008387000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ole32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.000000000847F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.UI.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009DED000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FWPolicyIOMgr.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009AFD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\bcryptprimitives.pdb5 source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: rasadhlp.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A484000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cfgmgr32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009C72000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: combase.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007779000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.Storage.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009849000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernel32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.00000000075A9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fastprox.pdbbO source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinapi.appcore.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A0D5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\fwpuclnt.pdbR source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ntdsapi.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000008F36000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ole32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.000000000847F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: rasadhlp.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A484000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \user\Desktop\WindowManagementAPI.pdb\*0.0./ source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32full.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.000000000848A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wininet.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.000000000927D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Kernel.Appcore.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.00000000098AF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shell32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.000000000846E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\DLL\dhcpcsvc.pdb. source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A3C9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinapi.appcore.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A0D5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mfperfhelper.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009D33000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: comctl32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.000000000777F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: comdlg32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.000000000771E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: avrt.pdbe=C:SystemRoot=C:\W source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BCE000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\InputHost.pdbb{ source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: propsys.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A06B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleacc.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000008F98000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samcli.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.000000000940F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shell32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.000000000846E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\exe\getscreen-226997704-x86.pdbL source: getscreen-226997704-x86.exe, 00000000.00000002.244222430201.0000000002908000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wimm32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008479000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wtsapi32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000009409000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MFWMAAEC.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009CD9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WindowManagementAPI.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009E4C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: owManagementAPI.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\twinapi.appcore.pdbYH source: getscreen-226997704-x86.exe, 00000000.00000002.244222430201.000000000295F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wUxTheme.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009730000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winhttp.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000009220000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: d3d11.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000008DBD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\FWPolicyIOMgr.pdbYK source: getscreen-226997704-x86.exe, 00000000.00000002.244222430201.000000000295F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samlib.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244238163483.000000000A87A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\fwpuclnt.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\dhcpcsvc6.pdbb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: combase.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007779000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: d3d11.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000008DBD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: top\symbols\dll\InputHost.pdbSER3< source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: avrt.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BCE000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32full.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.000000000848A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: propsys.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A06B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MpOAV.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A315000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fastprox.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A25B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samlib.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244238163483.000000000A87A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemsvc.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A201000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fastprox.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A25B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msctf.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009791000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wbemcomn.pdbd source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FWPolicyIOMgr.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009AFD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: TextInputFramework.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009EA6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\samlib.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\mfperfhelper.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dnsapi.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.00000000099D5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdb*? source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: C:\Github-runner\_work\agent-windows\agent-windows\console\Win32\Release\getscreen.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.00000000010B2000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001952000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.00000000010B2000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000002.244243221966.00000000010B2000.00000040.00000001.01000000.00000003.sdmp |
Source: | Binary string: netapi32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000008ECE000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: bcryptprimitives.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.00000000097EF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mfperfhelper.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009D33000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.UI.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009DED000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: iphlpapi.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008641000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\samlib.pdb\*U3 source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wbemsvc.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\bcryptprimitives.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\DLL\dhcpcsvc.pdb] source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \user\Desktop\dll\WindowManagementAPI.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: InputHost.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009F00000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\Windows.UI.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wininet.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.000000000927D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CLBCatQ.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009916000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wmswsock.pdbb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cfgmgr32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009C72000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: profapi.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.00000000098A9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemcomn.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A1FC000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wrpcrt4.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.00000000076A4000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreMessaging.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009F5B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\DLL\dhcpcsvc6.pdb< source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\CoreMessaging.pdb* source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: userenv.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000009168000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\JSAMSIProvider32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CLBCatQ.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009916000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: DLL\audioses.pdbemory source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernelbase.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.00000000075AF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shlwapi.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000083F5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\JSAMSIProvider32.pdb: 3.2.D source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\wmswsock.pdbB source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samcli.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.000000000940F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: netapi32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000008ECE000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreUIComponents.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009FB6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wbemprox.pdbdbQ source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: i.appcore.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: InputHost.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009F00000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: advapi32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.00000000075B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: top\dll\TextInputFramework.pdb6. source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WinTypes.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A011000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: iphlpapi.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008641000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MMDevAPI.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009BBA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\JSAMSIProvider32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wrpcrt4.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.00000000076A4000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: PI.pdbv source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.000000000941A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\wmswsock.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wmswsock.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: secur32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000008FF3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: TextInputFramework.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009EA6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\samlib.pdb4) source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fwpuclnt.pdb*K source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WinTypes.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A011000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\rasadhlp.pdbl source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WindowManagementAPI.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009E4C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\fastprox.pdbM source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: UI.pdb2. source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shlwapi.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000083F5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleaut32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008484000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wsspicli.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.000000000941A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\wbemprox.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MMDevAPI.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009BBA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FirewallAPI.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009971000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\DLL\dhcpcsvc.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dll\InputHost.pdbows\M source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\rasadhlp.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\rasadhlp.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dnsapi.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.00000000099D5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: userenv.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000009168000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wimm32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008479000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreUIComponents.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004B8A000.00000004.00000020.00020000.00000000.sdmp, getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009FB6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\rasadhlp.pdbp source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wwin32u.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008387000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winhttp.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000009220000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.Storage.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009849000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: .pdbdbghel source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fastprox.pdbB source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemprox.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A1A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\JSAMSIProvider32.pdbdbf source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msvcrt.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.00000000075BA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: profapi.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.00000000098A9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc6.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A36E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\rasadhlp.pdb* source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: rk.pdb90 source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\exe\getscreen-226997704-x86.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244222430201.0000000002908000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\wbemcomn.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wmswsock.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A426000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\DLL\dhcpcsvc6.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Kernel.Appcore.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.00000000098AF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ws2_32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wUxTheme.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009730000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cryptbase.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000967B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\WinTypes.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msctf.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009791000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernelbase.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.00000000075AF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wtsapi32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000009409000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \user\Desktop\TextInputFramework.pdb\*\ntdll source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleaut32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008484000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: comctl32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.000000000777F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: UIComponents.pdbbdo source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemprox.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A1A2000.00000004.00000020.00020000.00000000.sdmp |
Source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001541000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000001.244201588893.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001541000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000001.244201588893.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://crl.comodoca.com/COMODOCertificationAuthority.crl0 |
Source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001541000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000001.244201588893.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.00000000010B2000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001952000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.00000000010B2000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000002.244243221966.00000000010B2000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://proxy.contoso.com:3128/ |
Source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001541000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000001.244201588893.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions-01 |
Source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001541000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000001.244201588893.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions-01http://www.webrtc.org/exper |
Source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001541000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000001.244201588893.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/abs-capture-time |
Source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001541000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000001.244201588893.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/abs-capture-timeurn:3gpp:video-orientationhttp://www.we |
Source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001541000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000001.244201588893.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/abs-send-time |
Source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001541000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000001.244201588893.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/color-space |
Source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001541000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000001.244201588893.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/generic-frame-descriptor-00 |
Source: getscreen-226997704-x86.exe, 00000005.00000001.244201588893.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/inband-cn |
Source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001541000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000001.244201588893.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/playout-delay |
Source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001541000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000001.244201588893.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/transport-wide-cc-02 |
Source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001541000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000001.244201588893.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-content-type |
Source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001541000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000001.244201588893.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-frame-tracking-id |
Source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001541000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000001.244201588893.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-layers-allocation00 |
Source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001541000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000001.244201588893.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-timing |
Source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.00000000010B2000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001952000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.00000000010B2000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000002.244243221966.00000000010B2000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.winimage.com/zLibDll |
Source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001541000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000001.244201588893.0000000000CA1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: https://aomediacodec.github.io/av1-rtp-spec/#dependency-descriptor-rtp-header-extension |
Source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.00000000010B2000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001952000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.00000000010B2000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000002.244243221966.00000000010B2000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: https://docs.g |
Source: getscreen-226997704-x86.exe, getscreen-226997704-x86.exe, 00000005.00000002.244243221966.00000000010B2000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: https://docs.ge |
Source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.00000000010B2000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001952000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.00000000010B2000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000002.244243221966.00000000010B2000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: https://docs.getsa |
Source: getscreen-226997704-x86.exe, 00000005.00000002.244243221966.00000000010B2000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: https://docs.getsc |
Source: getscreen-226997704-x86.exe | String found in binary or memory: https://docs.getscree |
Source: getscreen-226997704-x86.exe | String found in binary or memory: https://docs.getscreen.me/ |
Source: getscreen-226997704-x86.exe | String found in binary or memory: https://docs.getscreen.me/e |
Source: getscreen-226997704-x86.exe | String found in binary or memory: https://docs.getscreen.me/en |
Source: getscreen-226997704-x86.exe | String found in binary or memory: https://docs.getscreen.me/en/rules |
Source: getscreen-226997704-x86.exe | String found in binary or memory: https://docs.getscreen.me/en/rules/privacy-poli |
Source: getscreen-226997704-x86.exe, getscreen-226997704-x86.exe, 00000005.00000002.244249242964.0000000002A60000.00000004.00000020.00020000.00000000.sdmp, getscreen-226997704-x86.exe, 00000005.00000003.244241437357.0000000002A60000.00000004.00000020.00020000.00000000.sdmp, getscreen-226997704-x86.exe, 00000005.00000003.244241171383.0000000002A5B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://docs.getscreen.me/en/rules/privacy-polic |
Source: getscreen-226997704-x86.exe, 00000005.00000003.244241062309.0000000002A6C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://docs.getscreen.me/en/rules/privacy-policy/ |
Source: getscreen-226997704-x86.exe | String found in binary or memory: https://docs.getscreen.me/en/rules/ter |
Source: getscreen-226997704-x86.exe, 00000005.00000003.244241062309.0000000002A6C000.00000004.00000020.00020000.00000000.sdmp, getscreen-226997704-x86.exe, 00000005.00000002.244249069870.0000000002A3E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://docs.getscreen.me/en/rules/terms-of-use/ |
Source: getscreen-226997704-x86.exe, 00000004.00000003.244250288863.0000000007678000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://docs.getscreen.me/user-guides/agent/ |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: ntdsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: sas.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: dsparse.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: firewallapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: fwbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: fwpolicyiomgr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: mmdevapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: avrt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: mfwmaaec.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: mfperfhelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: audioses.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: avrt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: windows.ui.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: windowmanagementapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: inputhost.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: samlib.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: symsrv.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: ntdsapi.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: sas.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: dsparse.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: seclogon.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: ntdsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: sas.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: dsparse.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: d2d1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: dataexchange.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: dcomp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: directmanipulation.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: resourcepolicyclient.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: dxcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: mscms.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: coloradapterclient.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: icm32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: uiautomationcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: ntdsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: sas.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: dsparse.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-226997704-x86.exe | Section loaded: winsta.dll | Jump to behavior |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\dhcpcsvc.pdbdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernel32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.00000000075A9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreUIComponents.pdbb source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ucrtbase.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007786000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\twinapi.appcore.pdbyK source: getscreen-226997704-x86.exe, 00000000.00000002.244222430201.000000000295F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A3C9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msvcrt.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.00000000075BA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ntdsapi.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000008F36000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\twinapi.appcore.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: e3samlib.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A426000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemcomn.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A1FC000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdb* source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreMessaging.pdbdllKP source: getscreen-226997704-x86.exe, 00000000.00000002.244222430201.000000000295F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: advapi32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.00000000075B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wsspicli.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.000000000941A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\WindowManagementAPI.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\samlib.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: .pdbll (10 source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \user\Desktop\symbols\dll\InputHost.pdbndow source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winspool.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000009349000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\rasadhlp.pdb! source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fwpuclnt.pdbi source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreMessaging.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009F5B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\mfperfhelper.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244222430201.000000000295F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: bcryptprimitives.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.00000000097EF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fwpuclnt.pdbb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: comdlg32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.000000000771E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ws2_32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MpOAV.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A315000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleacc.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000008F98000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winspool.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000009349000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MFWMAAEC.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009CD9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\fwpuclnt.pdb` source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\dhcpcsvc.pdbdb4 source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemsvc.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A201000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wmswsock.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A426000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\InputHost.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: secur32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000008FF3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wwin32u.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008387000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ole32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.000000000847F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.UI.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009DED000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FWPolicyIOMgr.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009AFD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\bcryptprimitives.pdb5 source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: rasadhlp.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A484000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cfgmgr32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009C72000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: combase.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007779000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.Storage.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009849000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernel32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.00000000075A9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fastprox.pdbbO source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinapi.appcore.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A0D5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\fwpuclnt.pdbR source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ntdsapi.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000008F36000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ole32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.000000000847F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: rasadhlp.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A484000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \user\Desktop\WindowManagementAPI.pdb\*0.0./ source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32full.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.000000000848A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wininet.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.000000000927D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Kernel.Appcore.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.00000000098AF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shell32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.000000000846E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\DLL\dhcpcsvc.pdb. source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A3C9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinapi.appcore.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A0D5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mfperfhelper.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009D33000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: comctl32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.000000000777F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: comdlg32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.000000000771E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: avrt.pdbe=C:SystemRoot=C:\W source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BCE000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\InputHost.pdbb{ source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: propsys.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A06B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleacc.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000008F98000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samcli.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.000000000940F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shell32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.000000000846E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\exe\getscreen-226997704-x86.pdbL source: getscreen-226997704-x86.exe, 00000000.00000002.244222430201.0000000002908000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wimm32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008479000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wtsapi32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000009409000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MFWMAAEC.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009CD9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WindowManagementAPI.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009E4C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: owManagementAPI.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\twinapi.appcore.pdbYH source: getscreen-226997704-x86.exe, 00000000.00000002.244222430201.000000000295F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wUxTheme.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009730000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winhttp.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000009220000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: d3d11.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000008DBD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\FWPolicyIOMgr.pdbYK source: getscreen-226997704-x86.exe, 00000000.00000002.244222430201.000000000295F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samlib.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244238163483.000000000A87A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\fwpuclnt.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\dhcpcsvc6.pdbb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: combase.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007779000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: d3d11.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000008DBD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: top\symbols\dll\InputHost.pdbSER3< source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: avrt.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BCE000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32full.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.000000000848A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: propsys.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A06B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MpOAV.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A315000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fastprox.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A25B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samlib.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244238163483.000000000A87A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemsvc.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A201000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fastprox.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A25B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msctf.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009791000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wbemcomn.pdbd source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FWPolicyIOMgr.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009AFD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: TextInputFramework.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009EA6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\samlib.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\mfperfhelper.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dnsapi.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.00000000099D5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdb*? source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: C:\Github-runner\_work\agent-windows\agent-windows\console\Win32\Release\getscreen.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244216272390.00000000010B2000.00000040.00000001.01000000.00000003.sdmp, tqcebwhlhccnmvlzbgjdymdxhfnpwbt-elevate.exe, 00000002.00000002.244184170196.0000000001952000.00000040.00000001.01000000.00000004.sdmp, getscreen-226997704-x86.exe, 00000004.00000002.244271035507.00000000010B2000.00000040.00000001.01000000.00000003.sdmp, getscreen-226997704-x86.exe, 00000005.00000002.244243221966.00000000010B2000.00000040.00000001.01000000.00000003.sdmp |
Source: | Binary string: netapi32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000008ECE000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: bcryptprimitives.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.00000000097EF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mfperfhelper.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009D33000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.UI.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009DED000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: iphlpapi.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008641000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\samlib.pdb\*U3 source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wbemsvc.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\bcryptprimitives.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\DLL\dhcpcsvc.pdb] source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \user\Desktop\dll\WindowManagementAPI.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: InputHost.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009F00000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\Windows.UI.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wininet.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.000000000927D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CLBCatQ.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009916000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wmswsock.pdbb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cfgmgr32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009C72000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: profapi.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.00000000098A9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemcomn.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A1FC000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wrpcrt4.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.00000000076A4000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreMessaging.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009F5B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\DLL\dhcpcsvc6.pdb< source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\CoreMessaging.pdb* source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: userenv.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000009168000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\JSAMSIProvider32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CLBCatQ.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009916000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: DLL\audioses.pdbemory source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernelbase.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.00000000075AF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shlwapi.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000083F5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\JSAMSIProvider32.pdb: 3.2.D source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\wmswsock.pdbB source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samcli.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.000000000940F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: netapi32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000008ECE000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreUIComponents.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009FB6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wbemprox.pdbdbQ source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: i.appcore.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: InputHost.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009F00000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: advapi32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.00000000075B5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: top\dll\TextInputFramework.pdb6. source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WinTypes.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A011000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: iphlpapi.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008641000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MMDevAPI.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009BBA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\JSAMSIProvider32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wrpcrt4.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.00000000076A4000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: PI.pdbv source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.000000000941A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\wmswsock.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wmswsock.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: secur32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000008FF3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: TextInputFramework.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009EA6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\samlib.pdb4) source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fwpuclnt.pdb*K source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WinTypes.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A011000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\rasadhlp.pdbl source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WindowManagementAPI.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009E4C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\fastprox.pdbM source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: UI.pdb2. source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shlwapi.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000083F5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleaut32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008484000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wsspicli.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.000000000941A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\wbemprox.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MMDevAPI.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009BBA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FirewallAPI.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009971000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\DLL\dhcpcsvc.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dll\InputHost.pdbows\M source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\rasadhlp.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\rasadhlp.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dnsapi.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.00000000099D5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: userenv.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000009168000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wimm32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008479000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreUIComponents.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004B8A000.00000004.00000020.00020000.00000000.sdmp, getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009FB6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\rasadhlp.pdbp source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wwin32u.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008387000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winhttp.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000009220000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.Storage.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009849000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: .pdbdbghel source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fastprox.pdbB source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemprox.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A1A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\JSAMSIProvider32.pdbdbf source: getscreen-226997704-x86.exe, 00000000.00000002.244223787408.0000000004BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msvcrt.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.00000000075BA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: profapi.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.00000000098A9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc6.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A36E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\rasadhlp.pdb* source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: rk.pdb90 source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\exe\getscreen-226997704-x86.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244222430201.0000000002908000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\wbemcomn.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wmswsock.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A426000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\DLL\dhcpcsvc6.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Kernel.Appcore.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.00000000098AF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ws2_32.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008490000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wUxTheme.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009730000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cryptbase.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000967B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\WinTypes.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.0000000007590000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msctf.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.0000000009791000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernelbase.pdb( source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.00000000075AF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wtsapi32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244230163609.0000000009409000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \user\Desktop\TextInputFramework.pdb\*\ntdll source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleaut32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.0000000008484000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: comctl32.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244226458375.000000000777F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: UIComponents.pdbbdo source: getscreen-226997704-x86.exe, 00000000.00000002.244228105506.00000000084A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemprox.pdb source: getscreen-226997704-x86.exe, 00000000.00000002.244232628650.000000000A1A2000.00000004.00000020.00020000.00000000.sdmp |