Source: |
Binary string: wkernel32.pdb source: WerFault.exe, 0000000A.00000003.343884757.000000000493B000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.347640493.0000000000684000.00000004.00000001.sdmp, WerFault.exe, 00000017.00000003.390865537.0000000005250000.00000004.00000001.sdmp, WerFault.exe, 0000001C.00000003.499498394.0000000003092000.00000004.00000001.sdmp |
Source: |
Binary string: sfc_os.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: bcrypt.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp |
Source: |
Binary string: ucrtbase.pdb source: WerFault.exe, 0000000A.00000003.352158662.0000000004EB1000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.483923294.0000000004B32000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501239275.00000000055A5000.00000004.00000040.sdmp |
Source: |
Binary string: msvcrt.pdb source: WerFault.exe, 0000000A.00000003.352158662.0000000004EB1000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.482963978.0000000004B61000.00000004.00000001.sdmp, WerFault.exe, 00000017.00000003.500658090.00000000055D1000.00000004.00000001.sdmp, WerFault.exe, 0000001C.00000002.519773343.0000000005391000.00000004.00000001.sdmp |
Source: |
Binary string: rasman.pdbe{ source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: wrpcrt4.pdb source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.485947047.0000000004B30000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.500658090.00000000055D1000.00000004.00000001.sdmp |
Source: |
Binary string: wntdll.pdb source: WerFault.exe, 0000000A.00000003.342065583.0000000000A1F000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.347540628.000000000067E000.00000004.00000001.sdmp, WerFault.exe, 00000017.00000003.500658090.00000000055D1000.00000004.00000001.sdmp, WerFault.exe, 0000001C.00000003.499460892.000000000308C000.00000004.00000001.sdmp |
Source: |
Binary string: fltLib.pdb$ source: WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: advapi32.pdb`n source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: CoreMessaging.pdb source: WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: advapi32.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.500658090.00000000055D1000.00000004.00000001.sdmp |
Source: |
Binary string: wsspicli.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.500658090.00000000055D1000.00000004.00000001.sdmp |
Source: |
Binary string: oCReportStore::Prune: MaxReportCount=%d MaxSizeInMb=%dRSDSwkernel32.pdb source: WerFault.exe, 0000000E.00000002.501546084.00000000000F2000.00000004.00000001.sdmp |
Source: |
Binary string: powrprof.pdbVn source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: ntmarta.pdb source: WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: wkernelbase.pdb source: WerFault.exe, 0000000A.00000003.345845744.0000000000A2B000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.348844819.000000000068A000.00000004.00000001.sdmp, WerFault.exe, 00000017.00000003.500658090.00000000055D1000.00000004.00000001.sdmp, WerFault.exe, 0000001C.00000002.519773343.0000000005391000.00000004.00000001.sdmp |
Source: |
Binary string: mpr.pdb source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.485947047.0000000004B30000.00000004.00000040.sdmp |
Source: |
Binary string: fltLib.pdbHn source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: shlwapi.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: sfc.pdb, source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: dwmapi.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: shcore.pdbk source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486379544.0000000004B35000.00000004.00000040.sdmp |
Source: |
Binary string: opengl32.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp |
Source: |
Binary string: ws2_32.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp |
Source: |
Binary string: winspool.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: ClusApi.pdb/ source: WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: dwmapi.pdbw source: WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: shell32.pdbk source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.483923294.0000000004B32000.00000004.00000040.sdmp |
Source: |
Binary string: iphlpapi.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp |
Source: |
Binary string: nsi.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501207923.00000000055A0000.00000004.00000040.sdmp |
Source: |
Binary string: ucrtbase.pdbk source: WerFault.exe, 0000000E.00000003.483923294.0000000004B32000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501239275.00000000055A5000.00000004.00000040.sdmp |
Source: |
Binary string: KiUserCallbackDispatcherRSDSwntdll.pdb source: WerFault.exe, 0000001C.00000002.509473746.0000000000922000.00000004.00000001.sdmp |
Source: |
Binary string: powrprof.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: WinTypes.pdb5 source: WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: ole32.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.500658090.00000000055D1000.00000004.00000001.sdmp |
Source: |
Binary string: AcLayers.pdb source: WerFault.exe, 0000000A.00000003.352158662.0000000004EB1000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.482963978.0000000004B61000.00000004.00000001.sdmp, WerFault.exe, 0000001C.00000002.519773343.0000000005391000.00000004.00000001.sdmp |
Source: |
Binary string: wUxTheme.pdbw{ source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: opengl32.pdbnn source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: FGERN.pdb source: rundll32.exe, 00000014.00000002.514218411.0000000010025000.00000002.00020000.sdmp, b8fe43e6_by_Libranalysis.dll |
Source: |
Binary string: cfgmgr32.pdb source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.483923294.0000000004B32000.00000004.00000040.sdmp |
Source: |
Binary string: combase.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.500685057.00000000055A2000.00000004.00000040.sdmp |
Source: |
Binary string: Windows.Storage.pdb source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.485947047.0000000004B30000.00000004.00000040.sdmp |
Source: |
Binary string: rundll32.pdb source: WerFault.exe, 0000000A.00000003.342061380.0000000000A19000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.347534673.0000000000678000.00000004.00000001.sdmp, WerFault.exe, 0000001C.00000002.519773343.0000000005391000.00000004.00000001.sdmp |
Source: |
Binary string: wkernel32.pdb( source: WerFault.exe, 0000000A.00000003.344185164.0000000000A25000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.347640493.0000000000684000.00000004.00000001.sdmp, WerFault.exe, 0000001C.00000003.499498394.0000000003092000.00000004.00000001.sdmp |
Source: |
Binary string: sfc.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: CoreUIComponents.pdb_ source: WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: rasapi32.pdb3{4 source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: apphelp.pdb source: WerFault.exe, 0000000A.00000003.352158662.0000000004EB1000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.482963978.0000000004B61000.00000004.00000001.sdmp, WerFault.exe, 00000017.00000003.500658090.00000000055D1000.00000004.00000001.sdmp, WerFault.exe, 0000001C.00000002.519773343.0000000005391000.00000004.00000001.sdmp |
Source: |
Binary string: KERNEL32C:\Windows\System32\KERNEL32.DLLC:\Windows\System32\KERNEL32.DLLRSDSwkernel32.pdb source: WerFault.exe, 0000001C.00000002.509473746.0000000000922000.00000004.00000001.sdmp |
Source: |
Binary string: combase.pdbrn source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: mpr.pdb^' source: WerFault.exe, 0000000E.00000003.485947047.0000000004B30000.00000004.00000040.sdmp |
Source: |
Binary string: WinTypes.pdb source: WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: iphlpapi.pdbtn source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: ClusApi.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp |
Source: |
Binary string: sfc.pdb]& source: WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: glu32.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp |
Source: |
Binary string: shcore.pdb source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486379544.0000000004B35000.00000004.00000040.sdmp |
Source: |
Binary string: winspool.pdbZn source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: wgdi32.pdb source: WerFault.exe, 0000000A.00000003.352158662.0000000004EB1000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.482963978.0000000004B61000.00000004.00000001.sdmp, WerFault.exe, 00000017.00000003.501207923.00000000055A0000.00000004.00000040.sdmp |
Source: |
Binary string: fltLib.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: rundll32.pdbk source: WerFault.exe, 0000000A.00000003.352158662.0000000004EB1000.00000004.00000001.sdmp |
Source: |
Binary string: shell32.pdb source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.483923294.0000000004B32000.00000004.00000040.sdmp |
Source: |
Binary string: msvcp_win.pdb source: WerFault.exe, 0000000A.00000003.352158662.0000000004EB1000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.482963978.0000000004B61000.00000004.00000001.sdmp, WerFault.exe, 00000017.00000003.501207923.00000000055A0000.00000004.00000040.sdmp |
Source: |
Binary string: dnsapi.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp |
Source: |
Binary string: rasapi32.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp |
Source: |
Binary string: wimm32.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp |
Source: |
Binary string: CoreUIComponents.pdb source: WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: wwin32u.pdb source: WerFault.exe, 0000000A.00000003.352158662.0000000004EB1000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.482963978.0000000004B61000.00000004.00000001.sdmp, WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp, WerFault.exe, 0000001C.00000002.519773343.0000000005391000.00000004.00000001.sdmp |
Source: |
Binary string: setupapi.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: imagehlp.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: wUxTheme.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: mpr.pdb/ source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp |
Source: |
Binary string: msctf.pdb{{ source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: wntdll.pdb( source: WerFault.exe, 0000000A.00000003.342065583.0000000000A1F000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.347540628.000000000067E000.00000004.00000001.sdmp, WerFault.exe, 0000001C.00000003.499460892.000000000308C000.00000004.00000001.sdmp |
Source: |
Binary string: oleaut32.pdbxn source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: profapi.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: wgdi32full.pdb source: WerFault.exe, 0000000A.00000003.352158662.0000000004EB1000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.482963978.0000000004B61000.00000004.00000001.sdmp, WerFault.exe, 00000017.00000003.501207923.00000000055A0000.00000004.00000040.sdmp |
Source: |
Binary string: sechost.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.500658090.00000000055D1000.00000004.00000001.sdmp |
Source: |
Binary string: wsspicli.pdb\n source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: rasman.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp |
Source: |
Binary string: propsys.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: cfgmgr32.pdbk source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.483923294.0000000004B32000.00000004.00000040.sdmp |
Source: |
Binary string: iphlpapi.pdb\! source: WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp |
Source: |
Binary string: msctf.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: rundll32.pdb( source: WerFault.exe, 0000000A.00000003.342061380.0000000000A19000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.347534673.0000000000678000.00000004.00000001.sdmp, WerFault.exe, 0000001C.00000003.499438158.0000000003086000.00000004.00000001.sdmp |
Source: |
Binary string: TextInputFramework.pdb source: WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: Kernel.Appcore.pdb source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.485947047.0000000004B30000.00000004.00000040.sdmp |
Source: |
Binary string: cryptbase.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.500658090.00000000055D1000.00000004.00000001.sdmp |
Source: |
Binary string: bcryptprimitives.pdb source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.485947047.0000000004B30000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.500658090.00000000055D1000.00000004.00000001.sdmp |
Source: |
Binary string: wkernelbase.pdb( source: WerFault.exe, 0000000A.00000003.345845744.0000000000A2B000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.348844819.000000000068A000.00000004.00000001.sdmp, WerFault.exe, 0000001C.00000003.499549411.0000000003098000.00000004.00000001.sdmp |
Source: |
Binary string: ClusApi.pdb{ source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: combase.pdbk source: WerFault.exe, 00000017.00000003.500685057.00000000055A2000.00000004.00000040.sdmp |
Source: |
Binary string: oleaut32.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: wuser32.pdb source: WerFault.exe, 0000000A.00000003.352158662.0000000004EB1000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.482963978.0000000004B61000.00000004.00000001.sdmp, WerFault.exe, 00000017.00000003.501207923.00000000055A0000.00000004.00000040.sdmp, WerFault.exe, 0000001C.00000002.519773343.0000000005391000.00000004.00000001.sdmp |
Source: |
Binary string: dnsapi.pdbG{ source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: unknown |
Process created: C:\Windows\System32\loaddll32.exe loaddll32.exe 'C:\Users\user\Desktop\b8fe43e6_by_Libranalysis.dll' |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe 'C:\Users\user\Desktop\b8fe43e6_by_Libranalysis.dll',#1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\b8fe43e6_by_Libranalysis.dll,LoxmtYt |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\b8fe43e6_by_Libranalysis.dll',#1 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 5544 -s 752 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 5512 -s 892 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\b8fe43e6_by_Libranalysis.dll',DllCanUnloadNow |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\b8fe43e6_by_Libranalysis.dll',DllGetClassObject |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\b8fe43e6_by_Libranalysis.dll',WdiAddFileToInstance |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\b8fe43e6_by_Libranalysis.dll',WdiAddParameter |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\b8fe43e6_by_Libranalysis.dll',WdiCancel |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 5604 -s 608 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 6976 -s 756 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe 'C:\Users\user\Desktop\b8fe43e6_by_Libranalysis.dll',#1 |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\b8fe43e6_by_Libranalysis.dll,LoxmtYt |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\b8fe43e6_by_Libranalysis.dll',DllCanUnloadNow |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\b8fe43e6_by_Libranalysis.dll',DllGetClassObject |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\b8fe43e6_by_Libranalysis.dll',WdiAddFileToInstance |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\b8fe43e6_by_Libranalysis.dll',WdiAddParameter |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\b8fe43e6_by_Libranalysis.dll',WdiCancel |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\b8fe43e6_by_Libranalysis.dll',#1 |
Jump to behavior |
Source: |
Binary string: wkernel32.pdb source: WerFault.exe, 0000000A.00000003.343884757.000000000493B000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.347640493.0000000000684000.00000004.00000001.sdmp, WerFault.exe, 00000017.00000003.390865537.0000000005250000.00000004.00000001.sdmp, WerFault.exe, 0000001C.00000003.499498394.0000000003092000.00000004.00000001.sdmp |
Source: |
Binary string: sfc_os.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: bcrypt.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp |
Source: |
Binary string: ucrtbase.pdb source: WerFault.exe, 0000000A.00000003.352158662.0000000004EB1000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.483923294.0000000004B32000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501239275.00000000055A5000.00000004.00000040.sdmp |
Source: |
Binary string: msvcrt.pdb source: WerFault.exe, 0000000A.00000003.352158662.0000000004EB1000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.482963978.0000000004B61000.00000004.00000001.sdmp, WerFault.exe, 00000017.00000003.500658090.00000000055D1000.00000004.00000001.sdmp, WerFault.exe, 0000001C.00000002.519773343.0000000005391000.00000004.00000001.sdmp |
Source: |
Binary string: rasman.pdbe{ source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: wrpcrt4.pdb source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.485947047.0000000004B30000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.500658090.00000000055D1000.00000004.00000001.sdmp |
Source: |
Binary string: wntdll.pdb source: WerFault.exe, 0000000A.00000003.342065583.0000000000A1F000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.347540628.000000000067E000.00000004.00000001.sdmp, WerFault.exe, 00000017.00000003.500658090.00000000055D1000.00000004.00000001.sdmp, WerFault.exe, 0000001C.00000003.499460892.000000000308C000.00000004.00000001.sdmp |
Source: |
Binary string: fltLib.pdb$ source: WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: advapi32.pdb`n source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: CoreMessaging.pdb source: WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: advapi32.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.500658090.00000000055D1000.00000004.00000001.sdmp |
Source: |
Binary string: wsspicli.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.500658090.00000000055D1000.00000004.00000001.sdmp |
Source: |
Binary string: oCReportStore::Prune: MaxReportCount=%d MaxSizeInMb=%dRSDSwkernel32.pdb source: WerFault.exe, 0000000E.00000002.501546084.00000000000F2000.00000004.00000001.sdmp |
Source: |
Binary string: powrprof.pdbVn source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: ntmarta.pdb source: WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: wkernelbase.pdb source: WerFault.exe, 0000000A.00000003.345845744.0000000000A2B000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.348844819.000000000068A000.00000004.00000001.sdmp, WerFault.exe, 00000017.00000003.500658090.00000000055D1000.00000004.00000001.sdmp, WerFault.exe, 0000001C.00000002.519773343.0000000005391000.00000004.00000001.sdmp |
Source: |
Binary string: mpr.pdb source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.485947047.0000000004B30000.00000004.00000040.sdmp |
Source: |
Binary string: fltLib.pdbHn source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: shlwapi.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: sfc.pdb, source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: dwmapi.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: shcore.pdbk source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486379544.0000000004B35000.00000004.00000040.sdmp |
Source: |
Binary string: opengl32.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp |
Source: |
Binary string: ws2_32.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp |
Source: |
Binary string: winspool.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: ClusApi.pdb/ source: WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: dwmapi.pdbw source: WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: shell32.pdbk source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.483923294.0000000004B32000.00000004.00000040.sdmp |
Source: |
Binary string: iphlpapi.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp |
Source: |
Binary string: nsi.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501207923.00000000055A0000.00000004.00000040.sdmp |
Source: |
Binary string: ucrtbase.pdbk source: WerFault.exe, 0000000E.00000003.483923294.0000000004B32000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501239275.00000000055A5000.00000004.00000040.sdmp |
Source: |
Binary string: KiUserCallbackDispatcherRSDSwntdll.pdb source: WerFault.exe, 0000001C.00000002.509473746.0000000000922000.00000004.00000001.sdmp |
Source: |
Binary string: powrprof.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: WinTypes.pdb5 source: WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: ole32.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.500658090.00000000055D1000.00000004.00000001.sdmp |
Source: |
Binary string: AcLayers.pdb source: WerFault.exe, 0000000A.00000003.352158662.0000000004EB1000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.482963978.0000000004B61000.00000004.00000001.sdmp, WerFault.exe, 0000001C.00000002.519773343.0000000005391000.00000004.00000001.sdmp |
Source: |
Binary string: wUxTheme.pdbw{ source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: opengl32.pdbnn source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: FGERN.pdb source: rundll32.exe, 00000014.00000002.514218411.0000000010025000.00000002.00020000.sdmp, b8fe43e6_by_Libranalysis.dll |
Source: |
Binary string: cfgmgr32.pdb source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.483923294.0000000004B32000.00000004.00000040.sdmp |
Source: |
Binary string: combase.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.500685057.00000000055A2000.00000004.00000040.sdmp |
Source: |
Binary string: Windows.Storage.pdb source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.485947047.0000000004B30000.00000004.00000040.sdmp |
Source: |
Binary string: rundll32.pdb source: WerFault.exe, 0000000A.00000003.342061380.0000000000A19000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.347534673.0000000000678000.00000004.00000001.sdmp, WerFault.exe, 0000001C.00000002.519773343.0000000005391000.00000004.00000001.sdmp |
Source: |
Binary string: wkernel32.pdb( source: WerFault.exe, 0000000A.00000003.344185164.0000000000A25000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.347640493.0000000000684000.00000004.00000001.sdmp, WerFault.exe, 0000001C.00000003.499498394.0000000003092000.00000004.00000001.sdmp |
Source: |
Binary string: sfc.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: CoreUIComponents.pdb_ source: WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: rasapi32.pdb3{4 source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: apphelp.pdb source: WerFault.exe, 0000000A.00000003.352158662.0000000004EB1000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.482963978.0000000004B61000.00000004.00000001.sdmp, WerFault.exe, 00000017.00000003.500658090.00000000055D1000.00000004.00000001.sdmp, WerFault.exe, 0000001C.00000002.519773343.0000000005391000.00000004.00000001.sdmp |
Source: |
Binary string: KERNEL32C:\Windows\System32\KERNEL32.DLLC:\Windows\System32\KERNEL32.DLLRSDSwkernel32.pdb source: WerFault.exe, 0000001C.00000002.509473746.0000000000922000.00000004.00000001.sdmp |
Source: |
Binary string: combase.pdbrn source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: mpr.pdb^' source: WerFault.exe, 0000000E.00000003.485947047.0000000004B30000.00000004.00000040.sdmp |
Source: |
Binary string: WinTypes.pdb source: WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: iphlpapi.pdbtn source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: ClusApi.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp |
Source: |
Binary string: sfc.pdb]& source: WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: glu32.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp |
Source: |
Binary string: shcore.pdb source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486379544.0000000004B35000.00000004.00000040.sdmp |
Source: |
Binary string: winspool.pdbZn source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: wgdi32.pdb source: WerFault.exe, 0000000A.00000003.352158662.0000000004EB1000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.482963978.0000000004B61000.00000004.00000001.sdmp, WerFault.exe, 00000017.00000003.501207923.00000000055A0000.00000004.00000040.sdmp |
Source: |
Binary string: fltLib.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: rundll32.pdbk source: WerFault.exe, 0000000A.00000003.352158662.0000000004EB1000.00000004.00000001.sdmp |
Source: |
Binary string: shell32.pdb source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.483923294.0000000004B32000.00000004.00000040.sdmp |
Source: |
Binary string: msvcp_win.pdb source: WerFault.exe, 0000000A.00000003.352158662.0000000004EB1000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.482963978.0000000004B61000.00000004.00000001.sdmp, WerFault.exe, 00000017.00000003.501207923.00000000055A0000.00000004.00000040.sdmp |
Source: |
Binary string: dnsapi.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp |
Source: |
Binary string: rasapi32.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp |
Source: |
Binary string: wimm32.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp |
Source: |
Binary string: CoreUIComponents.pdb source: WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: wwin32u.pdb source: WerFault.exe, 0000000A.00000003.352158662.0000000004EB1000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.482963978.0000000004B61000.00000004.00000001.sdmp, WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp, WerFault.exe, 0000001C.00000002.519773343.0000000005391000.00000004.00000001.sdmp |
Source: |
Binary string: setupapi.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: imagehlp.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: wUxTheme.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: mpr.pdb/ source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp |
Source: |
Binary string: msctf.pdb{{ source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: wntdll.pdb( source: WerFault.exe, 0000000A.00000003.342065583.0000000000A1F000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.347540628.000000000067E000.00000004.00000001.sdmp, WerFault.exe, 0000001C.00000003.499460892.000000000308C000.00000004.00000001.sdmp |
Source: |
Binary string: oleaut32.pdbxn source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: profapi.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: wgdi32full.pdb source: WerFault.exe, 0000000A.00000003.352158662.0000000004EB1000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.482963978.0000000004B61000.00000004.00000001.sdmp, WerFault.exe, 00000017.00000003.501207923.00000000055A0000.00000004.00000040.sdmp |
Source: |
Binary string: sechost.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.500658090.00000000055D1000.00000004.00000001.sdmp |
Source: |
Binary string: wsspicli.pdb\n source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: rasman.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp |
Source: |
Binary string: propsys.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: cfgmgr32.pdbk source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.483923294.0000000004B32000.00000004.00000040.sdmp |
Source: |
Binary string: iphlpapi.pdb\! source: WerFault.exe, 00000017.00000003.501272551.00000000055A8000.00000004.00000040.sdmp |
Source: |
Binary string: msctf.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: rundll32.pdb( source: WerFault.exe, 0000000A.00000003.342061380.0000000000A19000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.347534673.0000000000678000.00000004.00000001.sdmp, WerFault.exe, 0000001C.00000003.499438158.0000000003086000.00000004.00000001.sdmp |
Source: |
Binary string: TextInputFramework.pdb source: WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: Kernel.Appcore.pdb source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.485947047.0000000004B30000.00000004.00000040.sdmp |
Source: |
Binary string: cryptbase.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.500658090.00000000055D1000.00000004.00000001.sdmp |
Source: |
Binary string: bcryptprimitives.pdb source: WerFault.exe, 0000000A.00000003.352186128.0000000004E80000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.485947047.0000000004B30000.00000004.00000040.sdmp, WerFault.exe, 00000017.00000003.500658090.00000000055D1000.00000004.00000001.sdmp |
Source: |
Binary string: wkernelbase.pdb( source: WerFault.exe, 0000000A.00000003.345845744.0000000000A2B000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.348844819.000000000068A000.00000004.00000001.sdmp, WerFault.exe, 0000001C.00000003.499549411.0000000003098000.00000004.00000001.sdmp |
Source: |
Binary string: ClusApi.pdb{ source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: |
Binary string: combase.pdbk source: WerFault.exe, 00000017.00000003.500685057.00000000055A2000.00000004.00000040.sdmp |
Source: |
Binary string: oleaut32.pdb source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.486881658.0000000004B38000.00000004.00000040.sdmp |
Source: |
Binary string: wuser32.pdb source: WerFault.exe, 0000000A.00000003.352158662.0000000004EB1000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.482963978.0000000004B61000.00000004.00000001.sdmp, WerFault.exe, 00000017.00000003.501207923.00000000055A0000.00000004.00000040.sdmp, WerFault.exe, 0000001C.00000002.519773343.0000000005391000.00000004.00000001.sdmp |
Source: |
Binary string: dnsapi.pdbG{ source: WerFault.exe, 0000000A.00000003.352200487.0000000004E86000.00000004.00000040.sdmp |
Source: C:\Windows\SysWOW64\cmd.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |