Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
2LksWs2xq7.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Roaming\thjwhdg
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Roaming\thjwhdg:Zone.Identifier
|
ASCII text, with CRLF line terminators
|
modified
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\2LksWs2xq7.exe
|
"C:\Users\user\Desktop\2LksWs2xq7.exe"
|
||
C:\Windows\explorer.exe
|
C:\Windows\Explorer.EXE
|
||
C:\Users\user\AppData\Roaming\thjwhdg
|
C:\Users\user\AppData\Roaming\thjwhdg
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://talesofpirates.net/tmp/index.php
|
|||
http://uama.com.ua/tmp/index.php
|
|||
http://sodez.ru/tmp/index.php
|
|||
http://nidoe.org/tmp/index.php
|
175.119.10.231
|
||
https://api.msn.com/v1/news/Feed/Windows?
|
unknown
|
||
https://api.msn.com/I
|
unknown
|
||
https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DV
|
unknown
|
||
https://www.msn.com/en-us/money/savingandinvesting/americans-average-net-worth-by-age/ar-AA1h4ngF
|
unknown
|
||
https://assets.msn.com/weathermapdata/1/static/finance/1stparty/FinanceTaskbarIcons/Finance_Earnings
|
unknown
|
||
https://api.msn.com:443/v1/news/Feed/Windows?
|
unknown
|
||
https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gMhz
|
unknown
|
||
https://excel.office.com-
|
unknown
|
||
https://word.office.comM
|
unknown
|
||
https://api.msn.com/v1/news/Feed/Windows?activityId=435B7A89D7D74BDF801F2DA188906BAF&timeOut=5000&oc
|
unknown
|
||
https://assets.msn.com/weathermapdata/1/static/weather/Icons/JyNGQgA=/Condition/AAehwh2.svg
|
unknown
|
||
https://windows.msn.com:443/shell?osLocale=en-GB&chosenMarketReason=ImplicitNew
|
unknown
|
||
https://www.msn.com/en-us/money/realestate/why-this-florida-city-is-a-safe-haven-from-hurricanes/ar-
|
unknown
|
||
https://www.msn.com/en-us/travel/news/you-can-t-beat-bobby-flay-s-phoenix-airport-restaurant-one-of-
|
unknown
|
||
http://schemas.micro
|
unknown
|
||
https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gMhz-dark
|
unknown
|
||
https://www.msn.com/en-us/news/politics/how-donald-trump-helped-kari-lake-become-arizona-s-and-ameri
|
unknown
|
||
https://www.msn.com/en-us/money/personalfinance/money-matters-changing-institution-of-marriage/ar-AA
|
unknown
|
||
https://www.msn.com/en-us/news/us/biden-administration-waives-26-federal-laws-to-allow-border-wall-c
|
unknown
|
||
https://www.msn.com/en-us/weather/topstories/california-s-reservoirs-runneth-over-in-astounding-reve
|
unknown
|
||
https://powerpoint.office.comEMd
|
unknown
|
||
https://windows.msn.com:443/shellv2?osLocale=en-GB&chosenMarketReason=ImplicitNew
|
unknown
|
||
https://android.notify.windows.com/iOS
|
unknown
|
||
https://outlook.come
|
unknown
|
||
https://www.msn.com/en-us/news/technology/a-federal-emergency-alert-will-be-sent-to-us-phones-nation
|
unknown
|
||
https://activity.windows.com/UserActivity.ReadWrite.CreatedByApp
|
unknown
|
||
https://www.msn.com/en-us/news/us/dumb-and-dumber-12-states-with-the-absolute-worst-education-in-the
|
unknown
|
||
https://api.msn.com/
|
unknown
|
||
https://www.msn.com/en-us/news/politics/republicans-already-barred-trump-from-being-speaker-of-the-h
|
unknown
|
||
https://www.msn.com/en-us/news/politics/trump-campaign-says-he-raised-more-than-45-million-in-3rd-qu
|
unknown
|
||
https://wns.windows.com/e
|
unknown
|
||
https://www.msn.com/en-us/news/politics/kevin-mccarthy-s-ouster-as-house-speaker-could-cost-gop-its-
|
unknown
|
||
https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DV-dark
|
unknown
|
||
https://www.msn.com:443/en-us/feed
|
unknown
|
||
https://www.msn.com/en-us/news/world/us-supplies-ukraine-with-a-million-rounds-of-ammunition-seized-
|
unknown
|
||
https://www.msn.com/en-us/money/personalfinance/10-things-rich-people-never-buy-and-you-shouldn-t-ei
|
unknown
|
There are 30 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
nidoe.org
|
175.119.10.231
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
95.86.30.3
|
unknown
|
Macedonia
|
||
175.119.10.231
|
nidoe.org
|
Korea Republic of
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
|
{A38B883C-1682-497E-97B0-0A3A9E801682} {886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99} 0xFFFF
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithProgids
|
Unpacker
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER_Classes\Local Settings\MuiCache\1e\417C44EB
|
@explorerframe.dll,-13137
|
||
HKEY_CURRENT_USER_Classes\Local Settings\MuiCache\1e\417C44EB
|
@explorerframe.dll,-13138
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
|
{33154C99-BF49-443D-A73C-303A23ABBE97} {886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99} 0xFFFF
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop
|
IconLayouts
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Security and Maintenance\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.102
|
CheckSetting
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
|
SlowContextMenuEntries
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
|
SlowContextMenuEntries
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
|
SlowContextMenuEntries
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
|
SlowContextMenuEntries
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2\OpenWithProgids
|
WMP11.AssocFile.3G2
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp\OpenWithProgids
|
WMP11.AssocFile.3GP
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2\OpenWithProgids
|
WMP11.AssocFile.3G2
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp\OpenWithProgids
|
WMP11.AssocFile.3GP
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aac\OpenWithProgids
|
WMP11.AssocFile.ADTS
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.adt\OpenWithProgids
|
WMP11.AssocFile.ADTS
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\OpenWithProgids
|
WMP11.AssocFile.AIFF
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\OpenWithProgids
|
WMP11.AssocFile.ASF
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asx\OpenWithProgids
|
WMP11.AssocFile.ASX
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\OpenWithProgids
|
WMP11.AssocFile.AU
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au3\OpenWithProgids
|
AutoIt3Script
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\OpenWithProgids
|
WMP11.AssocFile.AVI
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\OpenWithProgids
|
Paint.Picture
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cab\OpenWithProgids
|
CABFolder
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cdxml\OpenWithProgids
|
Microsoft.PowerShellCmdletDefinitionXML.1
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.css\OpenWithProgids
|
CSSfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.csv\OpenWithProgids
|
Excel.CSV
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dds\OpenWithProgids
|
ddsfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\OpenWithProgids
|
Paint.Picture
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dll\OpenWithProgids
|
dllfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.doc\OpenWithProgids
|
Word.Document.8
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.docm\OpenWithProgids
|
Word.DocumentMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.docx\OpenWithProgids
|
Word.Document.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dot\OpenWithProgids
|
Word.Template.8
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotm\OpenWithProgids
|
Word.TemplateMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotx\OpenWithProgids
|
Word.Template.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\OpenWithProgids
|
emffile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\OpenWithProgids
|
exefile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\OpenWithProgids
|
WMP11.AssocFile.FLAC
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fon\OpenWithProgids
|
fonfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\OpenWithProgids
|
giffile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\OpenWithProgids
|
htmlfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ico\OpenWithProgids
|
icofile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inf\OpenWithProgids
|
inffile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ini\OpenWithProgids
|
inifile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\OpenWithProgids
|
pjpegfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\OpenWithProgids
|
jpegfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jxr\OpenWithProgids
|
wdpfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lnk\OpenWithProgids
|
lnkfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v\OpenWithProgids
|
WMP11.AssocFile.MPEG
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2t\OpenWithProgids
|
WMP11.AssocFile.M2TS
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\OpenWithProgids
|
WMP11.AssocFile.m3u
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\OpenWithProgids
|
WMP11.AssocFile.M4A
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v\OpenWithProgids
|
WMP11.AssocFile.MP4
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\OpenWithProgids
|
mhtmlfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\OpenWithProgids
|
WMP11.AssocFile.MIDI
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mk3d\OpenWithProgids
|
WMP11.AssocFile.MK3D
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mka\OpenWithProgids
|
WMP11.AssocFile.MKA
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mkv\OpenWithProgids
|
WMP11.AssocFile.MKV
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mod\OpenWithProgids
|
WMP11.AssocFile.MPEG
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov\OpenWithProgids
|
WMP11.AssocFile.MOV
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MP2\OpenWithProgids
|
WMP11.AssocFile.MP3
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\OpenWithProgids
|
WMP11.AssocFile.MP4
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.msg\OpenWithProgids
|
Outlook.File.msg.15
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ocx\OpenWithProgids
|
ocxfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odp\OpenWithProgids
|
PowerPoint.OpenDocumentPresentation.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ods\OpenWithProgids
|
Excel.OpenDocumentSpreadsheet.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odt\OpenWithProgids
|
Word.OpenDocumentText.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.otf\OpenWithProgids
|
otffile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\OpenWithProgids
|
pngfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pot\OpenWithProgids
|
PowerPoint.Template.8
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potm\OpenWithProgids
|
PowerPoint.TemplateMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potx\OpenWithProgids
|
PowerPoint.Template.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppam\OpenWithProgids
|
PowerPoint.Addin.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsm\OpenWithProgids
|
PowerPoint.SlideShowMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsx\OpenWithProgids
|
PowerPoint.SlideShow.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppt\OpenWithProgids
|
PowerPoint.Show.8
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pptm\OpenWithProgids
|
PowerPoint.ShowMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pptx\OpenWithProgids
|
PowerPoint.Show.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ps1\OpenWithProgids
|
Microsoft.PowerShellScript.1
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ps1xml\OpenWithProgids
|
Microsoft.PowerShellXMLData.1
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd1\OpenWithProgids
|
Microsoft.PowerShellData.1
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psm1\OpenWithProgids
|
Microsoft.PowerShellModule.1
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pssc\OpenWithProgids
|
Microsoft.PowerShellSessionConfiguration.1
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\OpenWithProgids
|
rlefile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi\OpenWithProgids
|
WMP11.AssocFile.MIDI
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rtf\OpenWithProgids
|
Word.RTF.8
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.scf\OpenWithProgids
|
SHCmdFile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.search-ms\OpenWithProgids
|
SearchFolder
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\OpenWithProgids
|
shtmlfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sldm\OpenWithProgids
|
PowerPoint.SlideMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sldx\OpenWithProgids
|
PowerPoint.Slide.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\OpenWithProgids
|
WMP11.AssocFile.AU
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sys\OpenWithProgids
|
sysfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\OpenWithProgids
|
TIFImage.Document
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TS\OpenWithProgids
|
WMP11.AssocFile.TTS
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\OpenWithProgids
|
ttcfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\OpenWithProgids
|
ttffile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt\OpenWithProgids
|
txtfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vsto\OpenWithProgids
|
bootstrap.vsto.1
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\OpenWithProgids
|
WMP11.AssocFile.WAV
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wax\OpenWithProgids
|
WMP11.AssocFile.WAX
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wdp\OpenWithProgids
|
wdpfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\OpenWithProgids
|
WMP11.AssocFile.ASF
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\OpenWithProgids
|
WMP11.AssocFile.WMA
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\OpenWithProgids
|
wmffile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\OpenWithProgids
|
WMP11.AssocFile.WMV
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmx\OpenWithProgids
|
WMP11.AssocFile.ASX
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.WPL\OpenWithProgids
|
WMP11.AssocFile.WPL
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wvx\OpenWithProgids
|
WMP11.AssocFile.WVX
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlam\OpenWithProgids
|
Excel.AddInMacroEnabled
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xls\OpenWithProgids
|
Excel.Sheet.8
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsb\OpenWithProgids
|
Excel.SheetBinaryMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsm\OpenWithProgids
|
Excel.SheetMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsx\OpenWithProgids
|
Excel.Sheet.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlt\OpenWithProgids
|
Excel.Template.8
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xltm\OpenWithProgids
|
Excel.TemplateMacroEnabled
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xltx\OpenWithProgids
|
Excel.Template
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xml\OpenWithProgids
|
xmlfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xsl\OpenWithProgids
|
xslfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
TaskbarStateLastRun
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories64\{00021492-0000-0000-C000-000000000046}\Enum
|
Implementing
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
|
SlowContextMenuEntries
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
|
SlowContextMenuEntries
|
There are 173 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
2170000
|
direct allocation
|
page read and write
|
||
21B1000
|
unclassified section
|
page read and write
|
||
7D0000
|
direct allocation
|
page read and write
|
||
2191000
|
unclassified section
|
page read and write
|
||
ADAD000
|
stack
|
page read and write
|
||
B830000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF53F000
|
unkown
|
page readonly
|
||
7FF5DF16B000
|
unkown
|
page readonly
|
||
EA0000
|
unkown
|
page read and write
|
||
7FF5DF392000
|
unkown
|
page readonly
|
||
7FF5DF567000
|
unkown
|
page readonly
|
||
2DE0000
|
unkown
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
FEC4000
|
unkown
|
page read and write
|
||
7870000
|
unkown
|
page read and write
|
||
7FF5DE535000
|
unkown
|
page readonly
|
||
914B000
|
stack
|
page read and write
|
||
4750000
|
unkown
|
page read and write
|
||
2F40000
|
unkown
|
page read and write
|
||
2FC0000
|
unkown
|
page read and write
|
||
7FF5DF5B0000
|
unkown
|
page readonly
|
||
E91000
|
unkown
|
page read and write
|
||
2C40000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
A106000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
7FF5DEFFC000
|
unkown
|
page readonly
|
||
87E0000
|
stack
|
page read and write
|
||
9B99000
|
stack
|
page read and write
|
||
901B000
|
stack
|
page read and write
|
||
47F1000
|
unkown
|
page read and write
|
||
2FE0000
|
unkown
|
page read and write
|
||
2FE0000
|
unkown
|
page read and write
|
||
2C30000
|
unkown
|
page read and write
|
||
7FF5DF55A000
|
unkown
|
page readonly
|
||
8390000
|
unkown
|
page read and write
|
||
7FF5DF045000
|
unkown
|
page readonly
|
||
7FF5DF349000
|
unkown
|
page readonly
|
||
7991000
|
unkown
|
page read and write
|
||
2C30000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF52D000
|
unkown
|
page readonly
|
||
A0A7000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2C30000
|
unkown
|
page read and write
|
||
9718000
|
unkown
|
page read and write
|
||
BF40000
|
unkown
|
page read and write
|
||
429000
|
unkown
|
page read and write
|
||
1F4000
|
heap
|
page read and write
|
||
3010000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
8670000
|
unkown
|
page read and write
|
||
8660000
|
unkown
|
page read and write
|
||
2E10000
|
unkown
|
page read and write
|
||
EDAE000
|
unkown
|
page read and write
|
||
2F40000
|
unkown
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2F40000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
A6CF000
|
unkown
|
page read and write
|
||
2C40000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
BFA5000
|
unkown
|
page read and write
|
||
2C30000
|
unkown
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
7FF5DF23A000
|
unkown
|
page readonly
|
||
2E60000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
7FF5DF5A8000
|
unkown
|
page readonly
|
||
2FF0000
|
unkown
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
1190000
|
heap
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
40B000
|
unkown
|
page execute read
|
||
7FF5DF59E000
|
unkown
|
page readonly
|
||
2F40000
|
unkown
|
page read and write
|
||
7FF5DF5B5000
|
unkown
|
page readonly
|
||
411000
|
unkown
|
page readonly
|
||
7DF4E6781000
|
unkown
|
page execute read
|
||
2FC0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7CF000
|
stack
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2FC0000
|
unkown
|
page read and write
|
||
7FF5DEFBD000
|
unkown
|
page readonly
|
||
2E60000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF5AE000
|
unkown
|
page readonly
|
||
7800000
|
unkown
|
page read and write
|
||
A6D2000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2EB0000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF081000
|
unkown
|
page readonly
|
||
28A0000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
BF7E000
|
unkown
|
page read and write
|
||
2FC0000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
2FC0000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
2E10000
|
unkown
|
page read and write
|
||
A744000
|
unkown
|
page read and write
|
||
77F0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2FC0000
|
unkown
|
page read and write
|
||
2D5F000
|
unkown
|
page read and write
|
||
2F40000
|
unkown
|
page read and write
|
||
83E0000
|
unkown
|
page read and write
|
||
B259000
|
stack
|
page read and write
|
||
52E000
|
unkown
|
page readonly
|
||
C013000
|
unkown
|
page read and write
|
||
13A0000
|
unkown
|
page readonly
|
||
BFAD000
|
unkown
|
page read and write
|
||
7830000
|
unkown
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
2D1E000
|
stack
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
7DF5E895F000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
7ACE000
|
stack
|
page read and write
|
||
2C20000
|
unkown
|
page read and write
|
||
7FF5DF284000
|
unkown
|
page readonly
|
||
2DE0000
|
unkown
|
page read and write
|
||
95EE000
|
stack
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
2F40000
|
unkown
|
page read and write
|
||
BFA1000
|
unkown
|
page read and write
|
||
7DF5E896A000
|
unkown
|
page readonly
|
||
3000000
|
unkown
|
page read and write
|
||
2FC0000
|
unkown
|
page read and write
|
||
73A7000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2C20000
|
unkown
|
page read and write
|
||
2C20000
|
unkown
|
page read and write
|
||
2F10000
|
unkown
|
page read and write
|
||
3010000
|
unkown
|
page read and write
|
||
6D1000
|
heap
|
page execute and read and write
|
||
FF8B000
|
unkown
|
page read and write
|
||
9F92000
|
unkown
|
page read and write
|
||
7FF5DF50F000
|
unkown
|
page readonly
|
||
2DE0000
|
unkown
|
page read and write
|
||
7810000
|
unkown
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
42B000
|
unkown
|
page read and write
|
||
9F0000
|
heap
|
page read and write
|
||
962B000
|
unkown
|
page read and write
|
||
7FF5DEF57000
|
unkown
|
page readonly
|
||
83F0000
|
unkown
|
page read and write
|
||
2C40000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
2E10000
|
unkown
|
page read and write
|
||
8670000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
7FF5DF2CB000
|
unkown
|
page readonly
|
||
2FD0000
|
unkown
|
page read and write
|
||
3394000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
2FC0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
6AE000
|
stack
|
page read and write
|
||
6C0000
|
heap
|
page read and write
|
||
A6EE000
|
unkown
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
EA0000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
28D3000
|
heap
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
27F0000
|
unkown
|
page readonly
|
||
87E0000
|
unkown
|
page read and write
|
||
7FF5DF3DF000
|
unkown
|
page readonly
|
||
487A000
|
unkown
|
page read and write
|
||
B500000
|
unkown
|
page readonly
|
||
8B60000
|
unkown
|
page read and write
|
||
980000
|
unkown
|
page readonly
|
||
87E0000
|
unkown
|
page read and write
|
||
7FF5DF435000
|
unkown
|
page readonly
|
||
34B0000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
8890000
|
unkown
|
page read and write
|
||
7FF5DF038000
|
unkown
|
page readonly
|
||
8B60000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
7FF5DF06F000
|
unkown
|
page readonly
|
||
7FF5DF310000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2E30000
|
unkown
|
page read and write
|
||
7FF5DF21F000
|
unkown
|
page readonly
|
||
3000000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
7FF5DF3C6000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
620000
|
heap
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2C30000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
7FF5DF09B000
|
unkown
|
page readonly
|
||
47A2000
|
unkown
|
page read and write
|
||
400000
|
unkown
|
page execute and read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
2E10000
|
unkown
|
page read and write
|
||
19D000
|
stack
|
page read and write
|
||
65E000
|
stack
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2FC0000
|
unkown
|
page read and write
|
||
2C40000
|
unkown
|
page read and write
|
||
A6F1000
|
unkown
|
page read and write
|
||
2C30000
|
unkown
|
page read and write
|
||
ED40000
|
unkown
|
page read and write
|
||
87E0000
|
unkown
|
page read and write
|
||
7FF5DF029000
|
unkown
|
page readonly
|
||
2E10000
|
unkown
|
page read and write
|
||
7FF5DF25B000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
2E60000
|
unkown
|
page read and write
|
||
51DC000
|
stack
|
page read and write
|
||
42B000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
C34E000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
7FF5DEF84000
|
unkown
|
page readonly
|
||
6DF000
|
heap
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
7FF5DF478000
|
unkown
|
page readonly
|
||
2C20000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
9F74000
|
unkown
|
page read and write
|
||
2E10000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
A734000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2C40000
|
unkown
|
page read and write
|
||
2FC0000
|
unkown
|
page read and write
|
||
74D6000
|
unkown
|
page read and write
|
||
2E60000
|
unkown
|
page read and write
|
||
92DD000
|
stack
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
9F78000
|
unkown
|
page read and write
|
||
7FF5DF0A2000
|
unkown
|
page readonly
|
||
2FE0000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
7FF5C0B65000
|
unkown
|
page readonly
|
||
3000000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
73C3000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
BF6D000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
73AF000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
52D9000
|
unkown
|
page read and write
|
||
A0A5000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
7FF5DF0F1000
|
unkown
|
page readonly
|
||
2E10000
|
unkown
|
page read and write
|
||
9509000
|
stack
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
7FF5DF18E000
|
unkown
|
page readonly
|
||
2FF0000
|
unkown
|
page read and write
|
||
7FF5DF207000
|
unkown
|
page readonly
|
||
2FC0000
|
unkown
|
page read and write
|
||
C4E9000
|
unkown
|
page read and write
|
||
7FF5DF3D4000
|
unkown
|
page readonly
|
||
2DE0000
|
unkown
|
page read and write
|
||
C24C000
|
unkown
|
page read and write
|
||
9C1F000
|
stack
|
page read and write
|
||
AB8C000
|
stack
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
73BA000
|
unkown
|
page read and write
|
||
66E000
|
stack
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
7DF4E67A1000
|
unkown
|
page execute read
|
||
FF46000
|
unkown
|
page read and write
|
||
7FF5DF21B000
|
unkown
|
page readonly
|
||
2FF0000
|
unkown
|
page read and write
|
||
47D9000
|
unkown
|
page read and write
|
||
BEF0000
|
heap
|
page read and write
|
||
2FC0000
|
unkown
|
page read and write
|
||
9C9E000
|
stack
|
page read and write
|
||
52C3000
|
unkown
|
page read and write
|
||
A08D000
|
unkown
|
page read and write
|
||
7FF5DF4BD000
|
unkown
|
page readonly
|
||
7FF5DF4AB000
|
unkown
|
page readonly
|
||
7FF5DF458000
|
unkown
|
page readonly
|
||
2C20000
|
unkown
|
page read and write
|
||
A104000
|
unkown
|
page read and write
|
||
2240000
|
heap
|
page read and write
|
||
11A0000
|
unkown
|
page readonly
|
||
9C000
|
stack
|
page read and write
|
||
C18A000
|
unkown
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
7910000
|
unkown
|
page readonly
|
||
EA0000
|
unkown
|
page read and write
|
||
8AF000
|
stack
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF3EA000
|
unkown
|
page readonly
|
||
3356000
|
unkown
|
page read and write
|
||
BF9B000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
87E0000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
7FF5DF488000
|
unkown
|
page readonly
|
||
3349000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
E70000
|
unkown
|
page readonly
|
||
7FF5DF25E000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DEFF5000
|
unkown
|
page readonly
|
||
EA0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
AB0D000
|
stack
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7E0000
|
heap
|
page read and write
|
||
A74D000
|
unkown
|
page read and write
|
||
7FF5DEF90000
|
unkown
|
page readonly
|
||
2C40000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF067000
|
unkown
|
page readonly
|
||
2FF0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
BF84000
|
unkown
|
page read and write
|
||
7FF5DF1CD000
|
unkown
|
page readonly
|
||
2FF0000
|
unkown
|
page read and write
|
||
429000
|
unkown
|
page read and write
|
||
C01A000
|
unkown
|
page read and write
|
||
A098000
|
unkown
|
page read and write
|
||
2FC0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
9AF000
|
stack
|
page read and write
|
||
2C9A000
|
stack
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
2C30000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
4788000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
3373000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
9716000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
320C000
|
stack
|
page read and write
|
||
909B000
|
stack
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
87E0000
|
unkown
|
page read and write
|
||
7FF5DEFCB000
|
unkown
|
page readonly
|
||
74F1000
|
unkown
|
page read and write
|
||
48B0000
|
unkown
|
page read and write
|
||
7FF5DF4F3000
|
unkown
|
page readonly
|
||
2E10000
|
unkown
|
page read and write
|
||
BF9F000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
8EA9000
|
stack
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
80F000
|
heap
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
D50000
|
unkown
|
page read and write
|
||
336F000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
7FF5DF156000
|
unkown
|
page readonly
|
||
2E10000
|
unkown
|
page read and write
|
||
8660000
|
unkown
|
page read and write
|
||
C1C4000
|
unkown
|
page read and write
|
||
2C30000
|
unkown
|
page read and write
|
||
335B000
|
unkown
|
page read and write
|
||
7FF5DF486000
|
unkown
|
page readonly
|
||
B359000
|
stack
|
page read and write
|
||
4760000
|
unkown
|
page read and write
|
||
C23D000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
7FF5DEF06000
|
unkown
|
page readonly
|
||
2F40000
|
unkown
|
page read and write
|
||
7FF5DF1D1000
|
unkown
|
page readonly
|
||
8B60000
|
unkown
|
page read and write
|
||
2FC0000
|
unkown
|
page read and write
|
||
7FF5DF2ED000
|
unkown
|
page readonly
|
||
3000000
|
unkown
|
page read and write
|
||
2E60000
|
unkown
|
page read and write
|
||
7FF5DF4EC000
|
unkown
|
page readonly
|
||
98AD000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
2C30000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
BF10000
|
unkown
|
page readonly
|
||
3371000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
A690000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
7FF5DF07D000
|
unkown
|
page readonly
|
||
2FF0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
6B0000
|
direct allocation
|
page execute and read and write
|
||
2FC0000
|
unkown
|
page read and write
|
||
7FF5DF382000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF4F7000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2F40000
|
unkown
|
page read and write
|
||
7230000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2F40000
|
unkown
|
page read and write
|
||
34C0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
ADC0000
|
unkown
|
page readonly
|
||
2FE0000
|
unkown
|
page read and write
|
||
F80000
|
unkown
|
page read and write
|
||
A02D000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
88E0000
|
unkown
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
7FF5DF5E9000
|
unkown
|
page readonly
|
||
23E0000
|
heap
|
page read and write
|
||
87E0000
|
unkown
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
3010000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
33C0000
|
unkown
|
page readonly
|
||
A73C000
|
unkown
|
page read and write
|
||
87E0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
F48000
|
stack
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7C89000
|
stack
|
page read and write
|
||
ED82000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF3C2000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
47EC000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
C187000
|
unkown
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
7FF5DF12A000
|
unkown
|
page readonly
|
||
98A1000
|
unkown
|
page read and write
|
||
41A000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
E90000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
2180000
|
unclassified section
|
page read and write
|
||
EE50000
|
heap
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DEE56000
|
unkown
|
page readonly
|
||
7FF5DEFA6000
|
unkown
|
page readonly
|
||
A072000
|
unkown
|
page read and write
|
||
2F40000
|
unkown
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
7FF5DF41B000
|
unkown
|
page readonly
|
||
7FF5DEFC2000
|
unkown
|
page readonly
|
||
8860000
|
unkown
|
page read and write
|
||
28D0000
|
heap
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
9F51000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF5F0000
|
unkown
|
page readonly
|
||
2FC0000
|
unkown
|
page read and write
|
||
99AB000
|
unkown
|
page read and write
|
||
411000
|
unkown
|
page readonly
|
||
3000000
|
unkown
|
page read and write
|
||
7FF5DF126000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF539000
|
unkown
|
page readonly
|
||
8910000
|
unkown
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
C13C000
|
unkown
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
2FC0000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
A08A000
|
unkown
|
page read and write
|
||
7FF5DF3F7000
|
unkown
|
page readonly
|
||
9C000
|
stack
|
page read and write
|
||
9D1F000
|
stack
|
page read and write
|
||
AEEE000
|
stack
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF606000
|
unkown
|
page readonly
|
||
7FF5DF57F000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
B589000
|
stack
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
987C000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
9E0000
|
unkown
|
page readonly
|
||
2FC0000
|
unkown
|
page read and write
|
||
2FC0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
C003000
|
unkown
|
page read and write
|
||
ED7D000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2FC0000
|
unkown
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
7FF5DF49C000
|
unkown
|
page readonly
|
||
8B60000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
2E60000
|
unkown
|
page read and write
|
||
7909000
|
stack
|
page read and write
|
||
4766000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
C192000
|
unkown
|
page read and write
|
||
2F40000
|
unkown
|
page read and write
|
||
7FF5DEEEB000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DEE43000
|
unkown
|
page readonly
|
||
87E0000
|
unkown
|
page read and write
|
||
BE80000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2F40000
|
unkown
|
page read and write
|
||
4860000
|
unkown
|
page read and write
|
||
7FF5DF39C000
|
unkown
|
page readonly
|
||
2DE0000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
87E0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
48A0000
|
unkown
|
page read and write
|
||
3010000
|
unkown
|
page read and write
|
||
7FF5DF091000
|
unkown
|
page readonly
|
||
7FF5DF5FC000
|
unkown
|
page readonly
|
||
2DE0000
|
unkown
|
page read and write
|
||
2E60000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7DF4E6791000
|
unkown
|
page execute read
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
7FF5DF388000
|
unkown
|
page readonly
|
||
BE80000
|
unkown
|
page read and write
|
||
2250000
|
heap
|
page read and write
|
||
2E60000
|
unkown
|
page read and write
|
||
3382000
|
unkown
|
page read and write
|
||
B11C000
|
stack
|
page read and write
|
||
8670000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
C298000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF54D000
|
unkown
|
page readonly
|
||
B2DB000
|
stack
|
page read and write
|
||
2FE0000
|
unkown
|
page read and write
|
||
7399000
|
unkown
|
page read and write
|
||
ED86000
|
unkown
|
page read and write
|
||
7B50000
|
unkown
|
page readonly
|
||
7FF5DF095000
|
unkown
|
page readonly
|
||
7FF5DF60D000
|
unkown
|
page readonly
|
||
8B60000
|
unkown
|
page read and write
|
||
1195000
|
heap
|
page read and write
|
||
21A0000
|
heap
|
page read and write
|
||
3107000
|
stack
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
2E10000
|
unkown
|
page read and write
|
||
7FF5DF248000
|
unkown
|
page readonly
|
||
2FF0000
|
unkown
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
7FF5DF577000
|
unkown
|
page readonly
|
||
7FF5DF5F6000
|
unkown
|
page readonly
|
||
8B60000
|
unkown
|
page read and write
|
||
42A000
|
unkown
|
page write copy
|
||
738E000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DEE52000
|
unkown
|
page readonly
|
||
AF7E000
|
stack
|
page read and write
|
||
7FF5DEFF0000
|
unkown
|
page readonly
|
||
8670000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8650000
|
unkown
|
page read and write
|
||
87E0000
|
unkown
|
page read and write
|
||
2C20000
|
unkown
|
page read and write
|
||
6BA000
|
heap
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
2FC0000
|
unkown
|
page read and write
|
||
BA76000
|
stack
|
page read and write
|
||
7FF5DF5A3000
|
unkown
|
page readonly
|
||
C149000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
E90000
|
unkown
|
page read and write
|
||
7FF5DF366000
|
unkown
|
page readonly
|
||
2FD0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
D69000
|
heap
|
page read and write
|
||
7FF5DF429000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF5FF000
|
unkown
|
page readonly
|
||
B60A000
|
stack
|
page read and write
|
||
7FF5DF191000
|
unkown
|
page readonly
|
||
EA0000
|
unkown
|
page read and write
|
||
7FF5DF3B5000
|
unkown
|
page readonly
|
||
7940000
|
unkown
|
page readonly
|
||
2E60000
|
unkown
|
page read and write
|
||
A0B1000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
2E10000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DEFAF000
|
unkown
|
page readonly
|
||
9489000
|
stack
|
page read and write
|
||
7FF5DF571000
|
unkown
|
page readonly
|
||
B120000
|
unkown
|
page readonly
|
||
411000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
83D0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
40B000
|
unkown
|
page execute read
|
||
C140000
|
unkown
|
page read and write
|
||
7380000
|
unkown
|
page read and write
|
||
2E60000
|
unkown
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
96DF000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
7FF5DF3F5000
|
unkown
|
page readonly
|
||
6BE000
|
heap
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
2F40000
|
unkown
|
page read and write
|
||
19D000
|
stack
|
page read and write
|
||
3364000
|
unkown
|
page read and write
|
||
8890000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
971C000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
A0F7000
|
unkown
|
page read and write
|
||
B9F0000
|
unkown
|
page read and write
|
||
AD2B000
|
stack
|
page read and write
|
||
95F0000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
7FF5DEE4E000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
2E60000
|
unkown
|
page read and write
|
||
9700000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
2870000
|
unkown
|
page read and write
|
||
BF82000
|
unkown
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
7FF5DF3FC000
|
unkown
|
page readonly
|
||
87E0000
|
unkown
|
page read and write
|
||
970000
|
unkown
|
page readonly
|
||
2F40000
|
unkown
|
page read and write
|
||
7FF5DF582000
|
unkown
|
page readonly
|
||
2FF0000
|
unkown
|
page read and write
|
||
3281000
|
stack
|
page read and write
|
||
B9BF000
|
stack
|
page read and write
|
||
87E0000
|
unkown
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
E0F000
|
heap
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
7FF5DF443000
|
unkown
|
page readonly
|
||
2FC0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
BFC3000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
2C30000
|
unkown
|
page read and write
|
||
7FF5DF537000
|
unkown
|
page readonly
|
||
2FF0000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
FFC4000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF08F000
|
unkown
|
page readonly
|
||
B1C0000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
838B000
|
stack
|
page read and write
|
||
E06000
|
heap
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
2E60000
|
unkown
|
page read and write
|
||
7FF5DE9C3000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
7860000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
73CD000
|
unkown
|
page read and write
|
||
7DF4E6771000
|
unkown
|
page execute read
|
||
2DE0000
|
unkown
|
page read and write
|
||
2E10000
|
unkown
|
page read and write
|
||
9564000
|
unkown
|
page read and write
|
||
C159000
|
unkown
|
page read and write
|
||
7840000
|
unkown
|
page read and write
|
||
7FF5DF584000
|
unkown
|
page readonly
|
||
2FC0000
|
unkown
|
page read and write
|
||
2C20000
|
unkown
|
page read and write
|
||
2E60000
|
unkown
|
page read and write
|
||
2C30000
|
unkown
|
page read and write
|
||
E90000
|
unkown
|
page read and write
|
||
C048000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF0C3000
|
unkown
|
page readonly
|
||
1F0000
|
heap
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
83B0000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF507000
|
unkown
|
page readonly
|
||
2251000
|
heap
|
page read and write
|
||
FF99000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
7FF5DE539000
|
unkown
|
page readonly
|
||
7FF5DF45C000
|
unkown
|
page readonly
|
||
2DE0000
|
unkown
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
7FF5DF551000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
479B000
|
unkown
|
page read and write
|
||
7FF5DEE5A000
|
unkown
|
page readonly
|
||
2FD0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
7FF5DF4FB000
|
unkown
|
page readonly
|
||
7FF5DF42F000
|
unkown
|
page readonly
|
||
2DE0000
|
unkown
|
page read and write
|
||
489A000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DE4F2000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
47F3000
|
unkown
|
page read and write
|
||
BFB3000
|
unkown
|
page read and write
|
||
32B0000
|
unkown
|
page read and write
|
||
8400000
|
heap
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
973C000
|
unkown
|
page read and write
|
||
2F40000
|
unkown
|
page read and write
|
||
970C000
|
unkown
|
page read and write
|
||
73B6000
|
unkown
|
page read and write
|
||
7FF5DF398000
|
unkown
|
page readonly
|
||
7FF5DF364000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
79E0000
|
unkown
|
page readonly
|
||
A0FC000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
FF82000
|
unkown
|
page read and write
|
||
FF03000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
E90000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
739B000
|
unkown
|
page read and write
|
||
BE80000
|
unkown
|
page read and write
|
||
3010000
|
unkown
|
page read and write
|
||
7FF5DF0C9000
|
unkown
|
page readonly
|
||
3362000
|
unkown
|
page read and write
|
||
EE5A000
|
heap
|
page read and write
|
||
87E0000
|
unkown
|
page read and write
|
||
1F0000
|
heap
|
page read and write
|
||
801000
|
heap
|
page execute and read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
27D0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
7499000
|
unkown
|
page read and write
|
||
A757000
|
unkown
|
page read and write
|
||
87E0000
|
unkown
|
page read and write
|
||
87E0000
|
unkown
|
page read and write
|
||
87E0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
2F40000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
7FF5C0B6B000
|
unkown
|
page readonly
|
||
2160000
|
direct allocation
|
page execute and read and write
|
||
9DF000
|
stack
|
page read and write
|
||
2F40000
|
unkown
|
page read and write
|
||
2C40000
|
unkown
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
98A7000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
73B8000
|
unkown
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
7FF5DF422000
|
unkown
|
page readonly
|
||
7FF5DF361000
|
unkown
|
page readonly
|
||
2FC0000
|
unkown
|
page read and write
|
||
7FF5DE5CC000
|
unkown
|
page readonly
|
||
935B000
|
stack
|
page read and write
|
||
97C4000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
336C000
|
unkown
|
page read and write
|
||
2F40000
|
unkown
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
7FF5DF532000
|
unkown
|
page readonly
|
||
7FF5DF0CC000
|
unkown
|
page readonly
|
||
8890000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF0D2000
|
unkown
|
page readonly
|
||
EA0000
|
unkown
|
page read and write
|
||
7FF5DEFE2000
|
unkown
|
page readonly
|
||
42A000
|
unkown
|
page write copy
|
||
7FF5DF04D000
|
unkown
|
page readonly
|
||
EA0000
|
unkown
|
page read and write
|
||
978C000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
FE0000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
2F40000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
2E60000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2E60000
|
unkown
|
page read and write
|
||
2FE0000
|
unkown
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
7FF5DF4C6000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
9605000
|
unkown
|
page read and write
|
||
2E10000
|
unkown
|
page read and write
|
||
830F000
|
stack
|
page read and write
|
||
87E0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7EE000
|
heap
|
page read and write
|
||
EEE0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
3010000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF549000
|
unkown
|
page readonly
|
||
B45A000
|
stack
|
page read and write
|
||
9F10000
|
unkown
|
page read and write
|
||
C319000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
8860000
|
unkown
|
page read and write
|
||
2280000
|
heap
|
page read and write
|
||
429000
|
unkown
|
page write copy
|
||
2FC0000
|
unkown
|
page read and write
|
||
4855000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
E00000
|
heap
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
BF8C000
|
unkown
|
page read and write
|
||
4828000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8670000
|
unkown
|
page read and write
|
||
C354000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
2E10000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
7FF5DF221000
|
unkown
|
page readonly
|
||
9729000
|
unkown
|
page read and write
|
||
2FE0000
|
unkown
|
page read and write
|
||
7FF5DF211000
|
unkown
|
page readonly
|
||
2FE0000
|
unkown
|
page read and write
|
||
488A000
|
unkown
|
page read and write
|
||
41A000
|
unkown
|
page readonly
|
||
2FF0000
|
unkown
|
page read and write
|
||
87E0000
|
unkown
|
page read and write
|
||
73E5000
|
unkown
|
page read and write
|
||
48E0000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
2FE0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF24E000
|
unkown
|
page readonly
|
||
2E60000
|
unkown
|
page read and write
|
||
BF98000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DE9CB000
|
unkown
|
page readonly
|
||
EA0000
|
unkown
|
page read and write
|
||
3304000
|
unkown
|
page read and write
|
||
8660000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
7FF5DEFE8000
|
unkown
|
page readonly
|
||
2F40000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
9F63000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF3B9000
|
unkown
|
page readonly
|
||
E80000
|
unkown
|
page read and write
|
||
7FF5DF623000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
52E000
|
unkown
|
page readonly
|
||
C1A9000
|
unkown
|
page read and write
|
||
2FE0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
BF90000
|
unkown
|
page read and write
|
||
9F23000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
7A40000
|
unkown
|
page readonly
|
||
AE6F000
|
stack
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF26F000
|
unkown
|
page readonly
|
||
96ED000
|
unkown
|
page read and write
|
||
7D0D000
|
stack
|
page read and write
|
||
C2E4000
|
unkown
|
page read and write
|
||
429000
|
unkown
|
page write copy
|
||
7EA000
|
heap
|
page read and write
|
||
7FF5DF2FE000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
9FA0000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
5241000
|
unkown
|
page read and write
|
||
7FF5DF4E3000
|
unkown
|
page readonly
|
||
2C20000
|
unkown
|
page read and write
|
||
2C20000
|
unkown
|
page read and write
|
||
7FF5DEFB7000
|
unkown
|
page readonly
|
||
7FF5DEF4B000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
7FF5DF2F3000
|
unkown
|
page readonly
|
||
8C28000
|
stack
|
page read and write
|
||
874C000
|
stack
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
41A000
|
unkown
|
page readonly
|
||
9E1E000
|
stack
|
page read and write
|
||
7FF5DF4E7000
|
unkown
|
page readonly
|
||
87E0000
|
unkown
|
page read and write
|
||
B9E0000
|
unkown
|
page read and write
|
||
A6EA000
|
unkown
|
page read and write
|
||
9F3E000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
9D9F000
|
stack
|
page read and write
|
||
8757000
|
unkown
|
page read and write
|
||
7A30000
|
unkown
|
page read and write
|
||
7FF5DF45A000
|
unkown
|
page readonly
|
||
3290000
|
unkown
|
page readonly
|
||
EA0000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
7FF5DEFDD000
|
unkown
|
page readonly
|
||
2EC0000
|
unkown
|
page readonly
|
||
2DE0000
|
unkown
|
page read and write
|
||
7FF5DF47E000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
BD7F000
|
stack
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
9714000
|
unkown
|
page read and write
|
||
7FF5DEF87000
|
unkown
|
page readonly
|
||
88DE000
|
stack
|
page read and write
|
||
3185000
|
stack
|
page read and write
|
||
C525000
|
unkown
|
page read and write
|
||
BF9D000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF169000
|
unkown
|
page readonly
|
||
9380000
|
unkown
|
page readonly
|
||
2DE0000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
6B0000
|
heap
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
7FF5DF5BE000
|
unkown
|
page readonly
|
||
7FF5DF4A6000
|
unkown
|
page readonly
|
||
73B4000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
E90000
|
unkown
|
page read and write
|
||
7FF5DF195000
|
unkown
|
page readonly
|
||
97F3000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2F40000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
BFA3000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
9F2A000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF43C000
|
unkown
|
page readonly
|
||
7FF5DF4D5000
|
unkown
|
page readonly
|
||
FF1000
|
unkown
|
page readonly
|
||
2F40000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
7FF5DF58A000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
9A6C000
|
stack
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
2310000
|
heap
|
page read and write
|
||
69E000
|
stack
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
7FF5DF591000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF2E5000
|
unkown
|
page readonly
|
||
EDA2000
|
unkown
|
page read and write
|
||
87E0000
|
unkown
|
page read and write
|
||
7FF5DF20A000
|
unkown
|
page readonly
|
||
74A9000
|
unkown
|
page read and write
|
||
BFAB000
|
unkown
|
page read and write
|
||
8660000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
ED71000
|
unkown
|
page read and write
|
||
8890000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
73BC000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
2E60000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2F40000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
9F7C000
|
unkown
|
page read and write
|
||
73B2000
|
unkown
|
page read and write
|
||
7FF5DF089000
|
unkown
|
page readonly
|
||
7FF5DF0A5000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
7FF5DEF94000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
2C20000
|
unkown
|
page read and write
|
||
7FF5DF01B000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
3010000
|
unkown
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
8790000
|
unkown
|
page read and write
|
||
9FC3000
|
unkown
|
page read and write
|
||
848E000
|
stack
|
page read and write
|
||
7930000
|
unkown
|
page readonly
|
||
3010000
|
unkown
|
page read and write
|
||
7FF5DF2DA000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF48B000
|
unkown
|
page readonly
|
||
7FF5DF62C000
|
unkown
|
page readonly
|
||
2FF0000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
87E0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
2E60000
|
unkown
|
page read and write
|
||
2C20000
|
stack
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
7DF4E6761000
|
unkown
|
page execute read
|
||
BFAF000
|
unkown
|
page read and write
|
||
9704000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF519000
|
unkown
|
page readonly
|
||
2FC0000
|
unkown
|
page read and write
|
||
7395000
|
unkown
|
page read and write
|
||
2E10000
|
unkown
|
page read and write
|
||
7D89000
|
stack
|
page read and write
|
||
2E60000
|
unkown
|
page read and write
|
||
2FE0000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
400000
|
unkown
|
page execute and read and write
|
||
52E000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF0C1000
|
unkown
|
page readonly
|
||
2FD0000
|
unkown
|
page read and write
|
||
ACAF000
|
stack
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
940F000
|
stack
|
page read and write
|
||
96F1000
|
unkown
|
page read and write
|
||
8A36000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
810000
|
heap
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
4824000
|
unkown
|
page read and write
|
||
2E10000
|
unkown
|
page read and write
|
||
BFA7000
|
unkown
|
page read and write
|
||
7DF4E6760000
|
unkown
|
page readonly
|
||
D60000
|
heap
|
page read and write
|
||
2FC0000
|
unkown
|
page read and write
|
||
B09F000
|
stack
|
page read and write
|
||
7FF5DF3BE000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
9B1E000
|
stack
|
page read and write
|
||
7FF5DE531000
|
unkown
|
page readonly
|
||
7FF5DF122000
|
unkown
|
page readonly
|
||
7D0000
|
direct allocation
|
page read and write
|
||
7DF4E6780000
|
unkown
|
page readonly
|
||
2FF0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
C75000
|
stack
|
page read and write
|
||
2200000
|
heap
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
AEF0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8660000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
52E000
|
unkown
|
page readonly
|
||
2180000
|
unclassified section
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
ED8A000
|
unkown
|
page read and write
|
||
24D0000
|
heap
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2FC0000
|
unkown
|
page read and write
|
||
7FF5DF229000
|
unkown
|
page readonly
|
||
2C20000
|
unkown
|
page read and write
|
||
2F40000
|
unkown
|
page read and write
|
||
2C20000
|
unkown
|
page read and write
|
||
EE52000
|
heap
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
7FF5DF452000
|
unkown
|
page readonly
|
||
3000000
|
unkown
|
page read and write
|
||
2C20000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF3A1000
|
unkown
|
page readonly
|
||
7FF5DF5D6000
|
unkown
|
page readonly
|
||
7FF5DF0F6000
|
unkown
|
page readonly
|
||
7B60000
|
unkown
|
page readonly
|
||
7FF5DF5CC000
|
unkown
|
page readonly
|
||
2FC0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
2FE0000
|
unkown
|
page read and write
|
||
9E9E000
|
stack
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
2C40000
|
unkown
|
page read and write
|
||
76F0000
|
unkown
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
87E0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF2BA000
|
unkown
|
page readonly
|
||
BFEF000
|
unkown
|
page read and write
|
||
41A000
|
unkown
|
page readonly
|
||
2DE0000
|
unkown
|
page read and write
|
||
24D1000
|
heap
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2FC0000
|
unkown
|
page read and write
|
||
D99000
|
heap
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
5110000
|
unkown
|
page write copy
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF3AA000
|
unkown
|
page readonly
|
||
BFDF000
|
unkown
|
page read and write
|
||
7FF5DF5B3000
|
unkown
|
page readonly
|
||
2E60000
|
unkown
|
page read and write
|
||
7FF5DF1F8000
|
unkown
|
page readonly
|
||
96F5000
|
unkown
|
page read and write
|
||
7D90000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
7FF5DF08B000
|
unkown
|
page readonly
|
||
7FF5DF2E2000
|
unkown
|
page readonly
|
||
C183000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
7B4B000
|
stack
|
page read and write
|
||
AFFC000
|
stack
|
page read and write
|
||
7FF5DF380000
|
unkown
|
page readonly
|
||
2FF0000
|
unkown
|
page read and write
|
||
A09A000
|
unkown
|
page read and write
|
||
971A000
|
unkown
|
page read and write
|
||
2FC0000
|
unkown
|
page read and write
|
||
9F60000
|
unkown
|
page read and write
|
||
989F000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
7FF5DF626000
|
unkown
|
page readonly
|
||
2FF0000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF3F1000
|
unkown
|
page readonly
|
||
2FC0000
|
unkown
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
AC0D000
|
stack
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
7FF5DEFF8000
|
unkown
|
page readonly
|
||
FF4B000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
7FF5DF36A000
|
unkown
|
page readonly
|
||
C1CC000
|
unkown
|
page read and write
|
||
6C4000
|
heap
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
610000
|
heap
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
B4DB000
|
stack
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2170000
|
direct allocation
|
page read and write
|
||
C474000
|
unkown
|
page read and write
|
||
7FF5DF396000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
87E0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
7FF5DF017000
|
unkown
|
page readonly
|
||
83F0000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
BE80000
|
unkown
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
2C30000
|
unkown
|
page read and write
|
||
9F27000
|
unkown
|
page read and write
|
||
3375000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
7FF5DF341000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
7A01000
|
unkown
|
page read and write
|
||
411000
|
unkown
|
page readonly
|
||
2E50000
|
unkown
|
page readonly
|
||
2890000
|
unkown
|
page readonly
|
||
73A3000
|
unkown
|
page read and write
|
||
C034000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
47B6000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
8590000
|
unkown
|
page readonly
|
||
7FF5DF343000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
540000
|
heap
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
2DE0000
|
unkown
|
page read and write
|
||
8B60000
|
unkown
|
page read and write
|
||
7FF5DF3E4000
|
unkown
|
page readonly
|
||
C19D000
|
unkown
|
page read and write
|
||
3000000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
885E000
|
stack
|
page read and write
|
||
B010000
|
unkown
|
page read and write
|
||
7DF4E6770000
|
unkown
|
page readonly
|
||
8790000
|
unkown
|
page read and write
|
||
2FF0000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2E10000
|
unkown
|
page read and write
|
||
8790000
|
unkown
|
page read and write
|
||
2E10000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
2FD0000
|
unkown
|
page read and write
|
||
7FF5DEFAC000
|
unkown
|
page readonly
|
||
EA0000
|
unkown
|
page read and write
|
There are 1342 hidden memdumps, click here to show them.