IOC Report
SecuriteInfo.com.Program.Unwanted.4272.4089.31387.exe

loading gif

Files

File Path
Type
Category
Malicious
SecuriteInfo.com.Program.Unwanted.4272.4089.31387.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\7z\7-zip.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\7z\7z.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\7z\7z.exe
PE32 executable (console) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\7z\x64\7z.exe
PE32+ executable (console) x86-64, for MS Windows
dropped
malicious
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\AdvancedSystemRepairPro.exe
PE32 executable (GUI) Intel 80386, for MS Windows
modified
malicious
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\InfExtractor.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\Microsoft.Deployment.WindowsInstaller.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\Microsoft.Experimental.IO.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\Newtonsoft.Json.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\ZetaLongPaths.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\asrscan.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
malicious
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\dsutil.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\tscmon.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\ProgramData\TSR7Settings\uninstasr.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\pctskbr4.vbs
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Local\Temp\pctskbr5.vbs
ASCII text, with CRLF line terminators
dropped
malicious
C:\Windows\System32\drivers\asrdmon.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
malicious
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\7z\License.txt
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\7z\history.txt
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\7z\readme.txt
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\7z\x64\7-zip.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\7z\x64\7z.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\BouncyCastle.Crypto.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\SevenZipSharp.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\System.Security.Cryptography.Algorithms.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\System.Security.Cryptography.Encoding.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\System.Security.Cryptography.Primitives.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\System.Security.Cryptography.X509Certificates.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\lang.dat
Qt Translation file
dropped
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\pcw.pack
zlib compressed data
dropped
C:\ProgramData\TSR7Settings\dsutil.zip
Zip archive data, at least v2.0 to extract, compression method=deflate
dropped
C:\ProgramData\TSR7Settings\s.txt
ASCII text, with CRLF line terminators
dropped
C:\ProgramData\TSR7Settings\uninstasr.exe:Zone.Identifier
ASCII text, with CRLF line terminators
dropped
C:\Users\Public\Desktop\Advanced System Repair Pro.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Tue Apr 23 06:30:31 2024, mtime=Tue Apr 23 06:30:37 2024, atime=Tue Apr 23 06:30:31 2024, length=19981464, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Advanced System Repair Pro\Advanced System Repair Pro.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Tue Apr 23 06:30:31 2024, mtime=Tue Apr 23 06:30:36 2024, atime=Tue Apr 23 06:30:31 2024, length=19981464, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Advanced System Repair Pro\Uninstall Advanced System Repair Pro.lnk
MS Windows shortcut, Item id list present, Has Relative path, Has command line arguments, Icon number=0, ctime=Sun Dec 31 23:06:32 1600, mtime=Sun Dec 31 23:06:32 1600, atime=Sun Dec 31 23:06:32 1600, length=0, window=hide
dropped
There are 27 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.4272.4089.31387.exe
"C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.4272.4089.31387.exe"
malicious
C:\Windows\SysWOW64\wscript.exe
wscript.exe //B //T:10 "C:\Users\user\AppData\Local\Temp\pctskbr5.vbs"
malicious
C:\Windows\SysWOW64\wscript.exe
wscript.exe //B //T:10 "C:\Users\user\AppData\Local\Temp\pctskbr5.vbs"
malicious
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\tscmon.exe
"C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\tscmon.exe" -install yes
malicious
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\tscmon.exe
"C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\tscmon.exe" -remove yes
malicious
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\AdvancedSystemRepairPro.exe
"C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\AdvancedSystemRepairPro.exe" /minimize
malicious
C:\Windows\SysWOW64\wscript.exe
wscript.exe //B //T:10 "C:\Users\user\AppData\Local\Temp\pctskbr5.vbs"
malicious
C:\Windows\SysWOW64\wscript.exe
wscript.exe //B //T:10 "C:\Users\user\AppData\Local\Temp\pctskbr4.vbs"
malicious
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\tscmon.exe
"C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\tscmon.exe" -install yes
malicious

URLs

Name
IP
Malicious
http://asrupdates.com/app_upgrade/asr.php?a=%s&i=%i&r=%i&v=%s&l=%iInstallTime40asrinf%i.iniupdateNot
unknown
http://asrupdates.com/db3/1.db
unknown
http://www.winimage.com/zLibDll1.2.3rbr
unknown
http://www.advancedsystemrepair.com.
unknown
https://advancedsystemrepair.com/reg-premium-de.phphttps://advancedsystemrepair.com/reg-premium7-de.
unknown
http://ocsp.thawte.com0
unknown
http://wixtoolset.org/Whttp://wixtoolset.org/telemetry/v
unknown
http://advancedsystemrepair.com/Malware.phpWhat
unknown
http://advancedsystemrepair.com/inapp3_de.phphttp://advancedsystemrepair.com/inapp2_de.phphttp://adv
unknown
https://advancedsystemrepair.com/thank-you-page-german-t.php?id=%sSelect
unknown
http://advancedsystemrepair.com/Review-Apps.phphttp://advancedsystemrepair.com/reviews.php1OnTimerAn
unknown
http://wixtoolset.org/news/
unknown
http://qt.digia.com/product/licensing
unknown
https://advancedsystemrepair.com/Purchase/ASR-german-Upgrade-m7.php
unknown
https://advancedsystemrepair.com/certifications/Proof.phphttps://advancedsystemrepair.com/ASR_DLL_Ex
unknown
http://www.westcoastlabs.com/about-us/https://advancedsystemrepair.com/ASR-Antimalware-Checkmark-Cer
unknown
http://advancedsystemrepair.com/Support.phphttps://advancedsystemrepair.com/License-Key-Lookup.php:/
unknown
http://asrupdates.com/db3/0.db
unknown
http://asrupdates.com/db3/2.db
unknown
https://advancedsystemrepair.com/reg-premium-pro-de.phphttps://advancedsystemrepair.com/reg-premium-
unknown
http://qt.digia.com/
unknown
http://advancedsystemrepair.com/EULA.phphttp://advancedsystemrepair.com/Privacy-Policy.phpTXThttp://
unknown
http://crl.thawte.com/ThawteTimestampingCA.crl0
unknown
http://advancedsystemrepair.com/privacypolicy.php
unknown
http://www.winimage.com/zLibDll
unknown
http://asrupdates.com/wr/view_d3.php?id=%iVideoLocal
unknown
http://advancedsystemrepair.com/Privacy-Policy.phphttp://advancedsystemrepair.com/EULA.phphttp://adv
unknown
http://asrupdates.com/db3/0.dbhttp://asrupdates.com/db3/1.dbhttp://asrupdates.com/db3/2.db.tmpasrupd
unknown
There are 18 hidden URLs, click here to show them.

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted
C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.4272.4089.31387.exe
HKEY_CURRENT_USER\SOFTWARE\AdvancedSystemRepairPro
InstallDir
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AdvancedSystemRepairPro
InstallDir
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\AdvancedSystemRepairPro.exe
HKEY_CURRENT_USER\SOFTWARE\AdvancedSystemRepairPro
InstallDir
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AdvancedSystemRepairPro
InstallDir
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
DisplayName
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
Publisher
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
InstallLocation
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
VersionMajor
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
VersionMinor
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
DisplayVersion
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
DisplayIcon
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
UninstallString
HKEY_CURRENT_USER\SOFTWARE\AdvancedSystemRepairPro
InstallDir
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AdvancedSystemRepairPro
InstallDir
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
DisplayName
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
Publisher
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
InstallLocation
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
VersionMajor
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
VersionMinor
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{A245B088-41FA-478E-8DEA-86177F1394BB}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{A245B088-41FA-478E-8DEA-86177F1394BB}
LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\tscmon.exe
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\tscmon.exe
AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{233F8F82-F91E-4E49-2222-BD21AB39D1BB}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{233F8F82-F91E-4E49-2222-BD21AB39D1BB}
AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{233F8F82-F91E-4E49-2222-BD21AB39D1BB}\LocalServer32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{233F8F82-F91E-4E49-2222-BD21AB39D1BB}\ProgID
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{233F8F82-F91E-4E49-2222-BD21AB39D1BB}\VersionIndependentProgID
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{233F8F82-F91E-4E49-2222-BD21AB39D1BB}\TypeLib
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{23311E82-B997-11CF-2222-0080C7B2D6BB}\1.0
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{23311E82-B997-11CF-2222-0080C7B2D6BB}\1.0\FLAGS
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{23311E82-B997-11CF-2222-0080C7B2D6BB}\1.0\0\win32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{23311E82-B997-11CF-2222-0080C7B2D6BB}\1.0\HELPDIR
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{23387882-DEAA-4971-2222-5D5046F2B3BB}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{23387882-DEAA-4971-2222-5D5046F2B3BB}\ProxyStubClsid32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{23387882-DEAA-4971-2222-5D5046F2B3BB}\TypeLib
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{23387882-DEAA-4971-2222-5D5046F2B3BB}\TypeLib
Version
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{23387882-DEAA-4971-2222-5D5046F2B3BB}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{23387882-DEAA-4971-2222-5D5046F2B3BB}\ProxyStubClsid32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{23387882-DEAA-4971-2222-5D5046F2B3BB}\TypeLib
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{23387882-DEAA-4971-2222-5D5046F2B3BB}\TypeLib
Version
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{2F343382-EFC2-49C9-2222-FC0C403B0EBB}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{2F343382-EFC2-49C9-2222-FC0C403B0EBB}\ProxyStubClsid32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{2F343382-EFC2-49C9-2222-FC0C403B0EBB}\TypeLib
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{2F343382-EFC2-49C9-2222-FC0C403B0EBB}\TypeLib
Version
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2F343382-EFC2-49C9-2222-FC0C403B0EBB}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2F343382-EFC2-49C9-2222-FC0C403B0EBB}\ProxyStubClsid32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{2532D782-C4FC-4ED8-2222-D654E27AF7F8}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2532D782-C4FC-4ED8-2222-D654E27AF7F8}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\tscmon.Gate
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\tscmon.Gate\CLSID
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\tscmon.Gate\CurVer
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\tscmon.Gate.1
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\tscmon.Gate.1\CLSID
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{233F8F82-F91E-4E49-2222-BD21AB39D1BB}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{233F8F82-F91E-4E49-2222-BD21AB39D1BB}
LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{233F8F82-F91E-4E49-2222-BD21AB39D1BB}
AuthenticationLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asrdmon
ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asrdmon
Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asrdmon
Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asrdmon
ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asrdmon
Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asrdmon
DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asrdmon\Instances
DefaultInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asrdmon\Instances\asrdmon
Altitude
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asrdmon\Instances\asrdmon
Flags
There are 58 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
13E6000
unkown
page readonly
59A6000
heap
page read and write
274E000
stack
page read and write
540E000
stack
page read and write
4255000
heap
page read and write
2DB0000
heap
page read and write
5050000
heap
page read and write
1406000
unkown
page readonly
13A3000
unkown
page readonly
4A1000
unkown
page execute read
34AE000
stack
page read and write
13F1000
unkown
page readonly
34B0000
heap
page read and write
3A50000
trusted library allocation
page read and write
3951000
heap
page read and write
2A89000
heap
page read and write
4B7000
unkown
page readonly
31E0000
heap
page read and write
13D5000
unkown
page readonly
61C000
unkown
page read and write
2FAF000
stack
page read and write
30A8000
heap
page read and write
2C25000
heap
page read and write
2C28000
heap
page read and write
2D70000
heap
page read and write
4E2F000
stack
page read and write
27B8000
heap
page read and write
63C000
unkown
page readonly
3670000
heap
page read and write
3951000
heap
page read and write
4EF000
unkown
page readonly
60A000
unkown
page read and write
2EAE000
stack
page read and write
4A9F000
stack
page read and write
45BF000
stack
page read and write
3080000
heap
page read and write
621000
unkown
page execute read
4C1E000
stack
page read and write
30BF000
heap
page read and write
BB0000
heap
page read and write
4EC000
unkown
page read and write
469E000
stack
page read and write
E38000
heap
page read and write
2A66000
heap
page read and write
558E000
stack
page read and write
2C28000
heap
page read and write
2AAE000
stack
page read and write
6EA000
heap
page read and write
548E000
stack
page read and write
514F000
stack
page read and write
2C28000
heap
page read and write
411000
unkown
page execute read
57AD000
heap
page read and write
2C26000
heap
page read and write
411000
unkown
page execute read
3677000
heap
page read and write
2D10000
heap
page read and write
BE9000
unkown
page readonly
620000
unkown
page readonly
527E000
stack
page read and write
104B000
heap
page read and write
4EF000
unkown
page readonly
2570000
heap
page read and write
11CF000
stack
page read and write
3041000
heap
page read and write
63A6000
heap
page read and write
30BD000
heap
page read and write
13F1000
unkown
page readonly
3095000
heap
page read and write
329000
stack
page read and write
1380000
unkown
page write copy
61AD000
heap
page read and write
23C0000
heap
page read and write
60B000
unkown
page write copy
2BE8000
heap
page read and write
104B000
heap
page read and write
3088000
heap
page read and write
F90000
heap
page read and write
FC0000
heap
page read and write
11FA000
unkown
page readonly
2B6F000
heap
page read and write
621000
unkown
page execute read
35BE000
stack
page read and write
2950000
heap
page read and write
1380000
unkown
page write copy
410000
unkown
page readonly
11FA000
unkown
page readonly
1411000
unkown
page readonly
42A0000
heap
page read and write
3460000
heap
page read and write
429F000
stack
page read and write
29AF000
stack
page read and write
2D58000
stack
page read and write
13B0000
heap
page read and write
410000
unkown
page readonly
4B7000
unkown
page readonly
62E000
unkown
page write copy
2BE8000
heap
page read and write
2BC0000
heap
page read and write
411000
unkown
page execute read
410000
unkown
page readonly
3041000
heap
page read and write
1390000
heap
page read and write
307E000
stack
page read and write
56CF000
stack
page read and write
1411000
unkown
page readonly
571E000
stack
page read and write
2565000
heap
page read and write
3220000
heap
page read and write
3951000
heap
page read and write
2F30000
heap
page read and write
410000
unkown
page readonly
4D2E000
stack
page read and write
13D5000
unkown
page readonly
BDB000
stack
page read and write
495F000
stack
page read and write
D3C000
stack
page read and write
11F8000
heap
page read and write
FF0000
heap
page read and write
2BE8000
heap
page read and write
5220000
heap
page read and write
5E7000
unkown
page readonly
2BAF000
stack
page read and write
23D0000
heap
page read and write
12C0000
heap
page read and write
590000
heap
page read and write
4B7000
unkown
page readonly
4D9000
unkown
page write copy
5280000
heap
page read and write
AAF000
stack
page read and write
3698000
heap
page read and write
3098000
heap
page read and write
4DA000
unkown
page read and write
4630000
heap
page read and write
4D9000
unkown
page write copy
30A8000
heap
page read and write
C3C000
stack
page read and write
1BC000
stack
page read and write
13F7000
unkown
page readonly
34B5000
heap
page read and write
5DE000
stack
page read and write
386F000
stack
page read and write
541000
unkown
page execute read
E20000
heap
page read and write
25EB000
stack
page read and write
1204000
heap
page read and write
27B0000
heap
page read and write
1395000
heap
page read and write
411000
unkown
page execute read
2705000
heap
page read and write
581F000
stack
page read and write
303F000
stack
page read and write
3094000
heap
page read and write
4EC000
unkown
page read and write
122C000
heap
page read and write
27D1000
heap
page read and write
12FF000
heap
page read and write
620000
unkown
page readonly
278E000
stack
page read and write
4B1E000
stack
page read and write
13E6000
unkown
page readonly
345E000
stack
page read and write
4A0000
unkown
page readonly
4C55000
heap
page read and write
4FAE000
stack
page read and write
2A70000
heap
page read and write
11F0000
heap
page read and write
23F0000
heap
page read and write
AB0000
heap
page read and write
499E000
stack
page read and write
3077000
heap
page read and write
30A8000
heap
page read and write
485E000
stack
page read and write
13F5000
unkown
page readonly
DA0000
heap
page read and write
13D7000
unkown
page readonly
D90000
heap
page read and write
2FDB000
stack
page read and write
BD0000
heap
page read and write
2C28000
heap
page read and write
61F000
unkown
page readonly
4EAE000
stack
page read and write
2BD4000
heap
page read and write
E44000
heap
page read and write
13D7000
unkown
page readonly
4BCF000
stack
page read and write
3A56000
heap
page read and write
541000
unkown
page execute read
518E000
stack
page read and write
13A3000
unkown
page readonly
4EF000
unkown
page readonly
28F8000
stack
page read and write
4D9000
unkown
page write copy
30A8000
heap
page read and write
30AB000
heap
page read and write
580000
heap
page read and write
540000
unkown
page readonly
F8E000
stack
page read and write
22B000
stack
page read and write
504E000
stack
page read and write
2BD8000
heap
page read and write
2ECE000
stack
page read and write
3098000
heap
page read and write
609000
unkown
page write copy
30E8000
heap
page read and write
5E0000
unkown
page readonly
4650000
heap
page read and write
609000
unkown
page write copy
2B80000
heap
page read and write
104B000
heap
page read and write
4D9000
unkown
page write copy
2560000
heap
page read and write
2A30000
heap
page read and write
13F7000
unkown
page readonly
BC0000
unkown
page readonly
4850000
trusted library allocation
page read and write
32FA000
stack
page read and write
5DA1000
heap
page read and write
6FC000
heap
page read and write
4BA7000
heap
page read and write
4DA000
unkown
page read and write
4DB000
unkown
page write copy
4CDF000
stack
page read and write
4EF000
unkown
page readonly
2BC8000
heap
page read and write
30E5000
heap
page read and write
2970000
heap
page read and write
13F5000
unkown
page readonly
502E000
stack
page read and write
2BFF000
heap
page read and write
1406000
unkown
page readonly
9AF000
stack
page read and write
F40000
heap
page read and write
123C000
heap
page read and write
3980000
heap
page read and write
2A60000
heap
page read and write
FD0000
unkown
page readonly
630000
heap
page read and write
656000
heap
page read and write
2F35000
heap
page read and write
61F000
unkown
page readonly
2C5B000
stack
page read and write
BB000
stack
page read and write
DF0000
heap
page read and write
2C00000
heap
page read and write
4456000
heap
page read and write
2CFE000
stack
page read and write
6EE000
heap
page read and write
43D0000
trusted library allocation
page read and write
55A7000
heap
page read and write
540000
unkown
page readonly
5E7000
unkown
page readonly
512E000
stack
page read and write
E30000
heap
page read and write
3340000
heap
page read and write
4AC0000
heap
page read and write
4B7000
unkown
page readonly
53A1000
heap
page read and write
4DB000
unkown
page write copy
589E000
stack
page read and write
6E0000
heap
page read and write
30A8000
heap
page read and write
EFC000
stack
page read and write
61E000
stack
page read and write
2ED0000
heap
page read and write
3041000
heap
page read and write
599E000
stack
page read and write
530E000
stack
page read and write
42E0000
heap
page read and write
28E2000
heap
page read and write
BE9000
unkown
page readonly
46A0000
heap
page read and write
2700000
heap
page read and write
3050000
heap
page read and write
528F000
stack
page read and write
There are 265 hidden memdumps, click here to show them.