Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
SecuriteInfo.com.Program.Unwanted.4272.4089.31387.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\7z\7-zip.dll
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\7z\7z.dll
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\7z\7z.exe
|
PE32 executable (console) Intel 80386, for MS Windows
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\7z\x64\7z.exe
|
PE32+ executable (console) x86-64, for MS Windows
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\AdvancedSystemRepairPro.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
modified
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\InfExtractor.dll
|
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\Microsoft.Deployment.WindowsInstaller.dll
|
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\Microsoft.Experimental.IO.dll
|
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\Newtonsoft.Json.dll
|
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\ZetaLongPaths.dll
|
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\asrscan.sys
|
PE32+ executable (native) x86-64, for MS Windows
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\dsutil.exe
|
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\tscmon.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\ProgramData\TSR7Settings\uninstasr.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\pctskbr4.vbs
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\pctskbr5.vbs
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Windows\System32\drivers\asrdmon.sys
|
PE32+ executable (native) x86-64, for MS Windows
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\7z\License.txt
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\7z\history.txt
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\7z\readme.txt
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\7z\x64\7-zip.dll
|
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\7z\x64\7z.dll
|
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\BouncyCastle.Crypto.dll
|
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\SevenZipSharp.dll
|
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\System.Security.Cryptography.Algorithms.dll
|
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\System.Security.Cryptography.Encoding.dll
|
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\System.Security.Cryptography.Primitives.dll
|
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\System.Security.Cryptography.X509Certificates.dll
|
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\lang.dat
|
Qt Translation file
|
dropped
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\pcw.pack
|
zlib compressed data
|
dropped
|
||
C:\ProgramData\TSR7Settings\dsutil.zip
|
Zip archive data, at least v2.0 to extract, compression method=deflate
|
dropped
|
||
C:\ProgramData\TSR7Settings\s.txt
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\ProgramData\TSR7Settings\uninstasr.exe:Zone.Identifier
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\Public\Desktop\Advanced System Repair Pro.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Tue Apr 23 06:30:31
2024, mtime=Tue Apr 23 06:30:37 2024, atime=Tue Apr 23 06:30:31 2024, length=19981464, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Advanced System Repair Pro\Advanced System Repair Pro.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Tue Apr 23 06:30:31
2024, mtime=Tue Apr 23 06:30:36 2024, atime=Tue Apr 23 06:30:31 2024, length=19981464, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Advanced System Repair Pro\Uninstall Advanced System Repair
Pro.lnk
|
MS Windows shortcut, Item id list present, Has Relative path, Has command line arguments, Icon number=0, ctime=Sun Dec 31
23:06:32 1600, mtime=Sun Dec 31 23:06:32 1600, atime=Sun Dec 31 23:06:32 1600, length=0, window=hide
|
dropped
|
There are 27 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.4272.4089.31387.exe
|
"C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.4272.4089.31387.exe"
|
||
C:\Windows\SysWOW64\wscript.exe
|
wscript.exe //B //T:10 "C:\Users\user\AppData\Local\Temp\pctskbr5.vbs"
|
||
C:\Windows\SysWOW64\wscript.exe
|
wscript.exe //B //T:10 "C:\Users\user\AppData\Local\Temp\pctskbr5.vbs"
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\tscmon.exe
|
"C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\tscmon.exe" -install yes
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\tscmon.exe
|
"C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\tscmon.exe" -remove yes
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\AdvancedSystemRepairPro.exe
|
"C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\AdvancedSystemRepairPro.exe" /minimize
|
||
C:\Windows\SysWOW64\wscript.exe
|
wscript.exe //B //T:10 "C:\Users\user\AppData\Local\Temp\pctskbr5.vbs"
|
||
C:\Windows\SysWOW64\wscript.exe
|
wscript.exe //B //T:10 "C:\Users\user\AppData\Local\Temp\pctskbr4.vbs"
|
||
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\tscmon.exe
|
"C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\tscmon.exe" -install yes
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://asrupdates.com/app_upgrade/asr.php?a=%s&i=%i&r=%i&v=%s&l=%iInstallTime40asrinf%i.iniupdateNot
|
unknown
|
||
http://asrupdates.com/db3/1.db
|
unknown
|
||
http://www.winimage.com/zLibDll1.2.3rbr
|
unknown
|
||
http://www.advancedsystemrepair.com.
|
unknown
|
||
https://advancedsystemrepair.com/reg-premium-de.phphttps://advancedsystemrepair.com/reg-premium7-de.
|
unknown
|
||
http://ocsp.thawte.com0
|
unknown
|
||
http://wixtoolset.org/Whttp://wixtoolset.org/telemetry/v
|
unknown
|
||
http://advancedsystemrepair.com/Malware.phpWhat
|
unknown
|
||
http://advancedsystemrepair.com/inapp3_de.phphttp://advancedsystemrepair.com/inapp2_de.phphttp://adv
|
unknown
|
||
https://advancedsystemrepair.com/thank-you-page-german-t.php?id=%sSelect
|
unknown
|
||
http://advancedsystemrepair.com/Review-Apps.phphttp://advancedsystemrepair.com/reviews.php1OnTimerAn
|
unknown
|
||
http://wixtoolset.org/news/
|
unknown
|
||
http://qt.digia.com/product/licensing
|
unknown
|
||
https://advancedsystemrepair.com/Purchase/ASR-german-Upgrade-m7.php
|
unknown
|
||
https://advancedsystemrepair.com/certifications/Proof.phphttps://advancedsystemrepair.com/ASR_DLL_Ex
|
unknown
|
||
http://www.westcoastlabs.com/about-us/https://advancedsystemrepair.com/ASR-Antimalware-Checkmark-Cer
|
unknown
|
||
http://advancedsystemrepair.com/Support.phphttps://advancedsystemrepair.com/License-Key-Lookup.php:/
|
unknown
|
||
http://asrupdates.com/db3/0.db
|
unknown
|
||
http://asrupdates.com/db3/2.db
|
unknown
|
||
https://advancedsystemrepair.com/reg-premium-pro-de.phphttps://advancedsystemrepair.com/reg-premium-
|
unknown
|
||
http://qt.digia.com/
|
unknown
|
||
http://advancedsystemrepair.com/EULA.phphttp://advancedsystemrepair.com/Privacy-Policy.phpTXThttp://
|
unknown
|
||
http://crl.thawte.com/ThawteTimestampingCA.crl0
|
unknown
|
||
http://advancedsystemrepair.com/privacypolicy.php
|
unknown
|
||
http://www.winimage.com/zLibDll
|
unknown
|
||
http://asrupdates.com/wr/view_d3.php?id=%iVideoLocal
|
unknown
|
||
http://advancedsystemrepair.com/Privacy-Policy.phphttp://advancedsystemrepair.com/EULA.phphttp://adv
|
unknown
|
||
http://asrupdates.com/db3/0.dbhttp://asrupdates.com/db3/1.dbhttp://asrupdates.com/db3/2.db.tmpasrupd
|
unknown
|
There are 18 hidden URLs, click here to show them.
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted
|
C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.4272.4089.31387.exe
|
||
HKEY_CURRENT_USER\SOFTWARE\AdvancedSystemRepairPro
|
InstallDir
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AdvancedSystemRepairPro
|
InstallDir
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
|
C:\Program Files (x86)\Advanced System Repair Pro 1.8.2.3.0\AdvancedSystemRepairPro.exe
|
||
HKEY_CURRENT_USER\SOFTWARE\AdvancedSystemRepairPro
|
InstallDir
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AdvancedSystemRepairPro
|
InstallDir
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
|
DisplayName
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
|
Publisher
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
|
InstallLocation
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
|
VersionMajor
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
|
VersionMinor
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
|
DisplayVersion
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
|
DisplayIcon
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
|
UninstallString
|
||
HKEY_CURRENT_USER\SOFTWARE\AdvancedSystemRepairPro
|
InstallDir
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AdvancedSystemRepairPro
|
InstallDir
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
|
DisplayName
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
|
Publisher
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
|
InstallLocation
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
|
VersionMajor
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Repair Pro
|
VersionMinor
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{A245B088-41FA-478E-8DEA-86177F1394BB}
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{A245B088-41FA-478E-8DEA-86177F1394BB}
|
LocalService
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\tscmon.exe
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\tscmon.exe
|
AppID
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{233F8F82-F91E-4E49-2222-BD21AB39D1BB}
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{233F8F82-F91E-4E49-2222-BD21AB39D1BB}
|
AppID
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{233F8F82-F91E-4E49-2222-BD21AB39D1BB}\LocalServer32
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{233F8F82-F91E-4E49-2222-BD21AB39D1BB}\ProgID
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{233F8F82-F91E-4E49-2222-BD21AB39D1BB}\VersionIndependentProgID
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{233F8F82-F91E-4E49-2222-BD21AB39D1BB}\TypeLib
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{23311E82-B997-11CF-2222-0080C7B2D6BB}\1.0
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{23311E82-B997-11CF-2222-0080C7B2D6BB}\1.0\FLAGS
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{23311E82-B997-11CF-2222-0080C7B2D6BB}\1.0\0\win32
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{23311E82-B997-11CF-2222-0080C7B2D6BB}\1.0\HELPDIR
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{23387882-DEAA-4971-2222-5D5046F2B3BB}
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{23387882-DEAA-4971-2222-5D5046F2B3BB}\ProxyStubClsid32
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{23387882-DEAA-4971-2222-5D5046F2B3BB}\TypeLib
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{23387882-DEAA-4971-2222-5D5046F2B3BB}\TypeLib
|
Version
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{23387882-DEAA-4971-2222-5D5046F2B3BB}
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{23387882-DEAA-4971-2222-5D5046F2B3BB}\ProxyStubClsid32
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{23387882-DEAA-4971-2222-5D5046F2B3BB}\TypeLib
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{23387882-DEAA-4971-2222-5D5046F2B3BB}\TypeLib
|
Version
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{2F343382-EFC2-49C9-2222-FC0C403B0EBB}
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{2F343382-EFC2-49C9-2222-FC0C403B0EBB}\ProxyStubClsid32
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{2F343382-EFC2-49C9-2222-FC0C403B0EBB}\TypeLib
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{2F343382-EFC2-49C9-2222-FC0C403B0EBB}\TypeLib
|
Version
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2F343382-EFC2-49C9-2222-FC0C403B0EBB}
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2F343382-EFC2-49C9-2222-FC0C403B0EBB}\ProxyStubClsid32
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{2532D782-C4FC-4ED8-2222-D654E27AF7F8}
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2532D782-C4FC-4ED8-2222-D654E27AF7F8}
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\tscmon.Gate
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\tscmon.Gate\CLSID
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\tscmon.Gate\CurVer
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\tscmon.Gate.1
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\tscmon.Gate.1\CLSID
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{233F8F82-F91E-4E49-2222-BD21AB39D1BB}
|
NULL
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{233F8F82-F91E-4E49-2222-BD21AB39D1BB}
|
LocalService
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{233F8F82-F91E-4E49-2222-BD21AB39D1BB}
|
AuthenticationLevel
|
||
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asrdmon
|
ImagePath
|
||
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asrdmon
|
Type
|
||
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asrdmon
|
Start
|
||
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asrdmon
|
ErrorControl
|
||
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asrdmon
|
Group
|
||
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asrdmon
|
DependOnService
|
||
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asrdmon\Instances
|
DefaultInstance
|
||
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asrdmon\Instances\asrdmon
|
Altitude
|
||
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asrdmon\Instances\asrdmon
|
Flags
|
There are 58 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
13E6000
|
unkown
|
page readonly
|
||
59A6000
|
heap
|
page read and write
|
||
274E000
|
stack
|
page read and write
|
||
540E000
|
stack
|
page read and write
|
||
4255000
|
heap
|
page read and write
|
||
2DB0000
|
heap
|
page read and write
|
||
5050000
|
heap
|
page read and write
|
||
1406000
|
unkown
|
page readonly
|
||
13A3000
|
unkown
|
page readonly
|
||
4A1000
|
unkown
|
page execute read
|
||
34AE000
|
stack
|
page read and write
|
||
13F1000
|
unkown
|
page readonly
|
||
34B0000
|
heap
|
page read and write
|
||
3A50000
|
trusted library allocation
|
page read and write
|
||
3951000
|
heap
|
page read and write
|
||
2A89000
|
heap
|
page read and write
|
||
4B7000
|
unkown
|
page readonly
|
||
31E0000
|
heap
|
page read and write
|
||
13D5000
|
unkown
|
page readonly
|
||
61C000
|
unkown
|
page read and write
|
||
2FAF000
|
stack
|
page read and write
|
||
30A8000
|
heap
|
page read and write
|
||
2C25000
|
heap
|
page read and write
|
||
2C28000
|
heap
|
page read and write
|
||
2D70000
|
heap
|
page read and write
|
||
4E2F000
|
stack
|
page read and write
|
||
27B8000
|
heap
|
page read and write
|
||
63C000
|
unkown
|
page readonly
|
||
3670000
|
heap
|
page read and write
|
||
3951000
|
heap
|
page read and write
|
||
4EF000
|
unkown
|
page readonly
|
||
60A000
|
unkown
|
page read and write
|
||
2EAE000
|
stack
|
page read and write
|
||
4A9F000
|
stack
|
page read and write
|
||
45BF000
|
stack
|
page read and write
|
||
3080000
|
heap
|
page read and write
|
||
621000
|
unkown
|
page execute read
|
||
4C1E000
|
stack
|
page read and write
|
||
30BF000
|
heap
|
page read and write
|
||
BB0000
|
heap
|
page read and write
|
||
4EC000
|
unkown
|
page read and write
|
||
469E000
|
stack
|
page read and write
|
||
E38000
|
heap
|
page read and write
|
||
2A66000
|
heap
|
page read and write
|
||
558E000
|
stack
|
page read and write
|
||
2C28000
|
heap
|
page read and write
|
||
2AAE000
|
stack
|
page read and write
|
||
6EA000
|
heap
|
page read and write
|
||
548E000
|
stack
|
page read and write
|
||
514F000
|
stack
|
page read and write
|
||
2C28000
|
heap
|
page read and write
|
||
411000
|
unkown
|
page execute read
|
||
57AD000
|
heap
|
page read and write
|
||
2C26000
|
heap
|
page read and write
|
||
411000
|
unkown
|
page execute read
|
||
3677000
|
heap
|
page read and write
|
||
2D10000
|
heap
|
page read and write
|
||
BE9000
|
unkown
|
page readonly
|
||
620000
|
unkown
|
page readonly
|
||
527E000
|
stack
|
page read and write
|
||
104B000
|
heap
|
page read and write
|
||
4EF000
|
unkown
|
page readonly
|
||
2570000
|
heap
|
page read and write
|
||
11CF000
|
stack
|
page read and write
|
||
3041000
|
heap
|
page read and write
|
||
63A6000
|
heap
|
page read and write
|
||
30BD000
|
heap
|
page read and write
|
||
13F1000
|
unkown
|
page readonly
|
||
3095000
|
heap
|
page read and write
|
||
329000
|
stack
|
page read and write
|
||
1380000
|
unkown
|
page write copy
|
||
61AD000
|
heap
|
page read and write
|
||
23C0000
|
heap
|
page read and write
|
||
60B000
|
unkown
|
page write copy
|
||
2BE8000
|
heap
|
page read and write
|
||
104B000
|
heap
|
page read and write
|
||
3088000
|
heap
|
page read and write
|
||
F90000
|
heap
|
page read and write
|
||
FC0000
|
heap
|
page read and write
|
||
11FA000
|
unkown
|
page readonly
|
||
2B6F000
|
heap
|
page read and write
|
||
621000
|
unkown
|
page execute read
|
||
35BE000
|
stack
|
page read and write
|
||
2950000
|
heap
|
page read and write
|
||
1380000
|
unkown
|
page write copy
|
||
410000
|
unkown
|
page readonly
|
||
11FA000
|
unkown
|
page readonly
|
||
1411000
|
unkown
|
page readonly
|
||
42A0000
|
heap
|
page read and write
|
||
3460000
|
heap
|
page read and write
|
||
429F000
|
stack
|
page read and write
|
||
29AF000
|
stack
|
page read and write
|
||
2D58000
|
stack
|
page read and write
|
||
13B0000
|
heap
|
page read and write
|
||
410000
|
unkown
|
page readonly
|
||
4B7000
|
unkown
|
page readonly
|
||
62E000
|
unkown
|
page write copy
|
||
2BE8000
|
heap
|
page read and write
|
||
2BC0000
|
heap
|
page read and write
|
||
411000
|
unkown
|
page execute read
|
||
410000
|
unkown
|
page readonly
|
||
3041000
|
heap
|
page read and write
|
||
1390000
|
heap
|
page read and write
|
||
307E000
|
stack
|
page read and write
|
||
56CF000
|
stack
|
page read and write
|
||
1411000
|
unkown
|
page readonly
|
||
571E000
|
stack
|
page read and write
|
||
2565000
|
heap
|
page read and write
|
||
3220000
|
heap
|
page read and write
|
||
3951000
|
heap
|
page read and write
|
||
2F30000
|
heap
|
page read and write
|
||
410000
|
unkown
|
page readonly
|
||
4D2E000
|
stack
|
page read and write
|
||
13D5000
|
unkown
|
page readonly
|
||
BDB000
|
stack
|
page read and write
|
||
495F000
|
stack
|
page read and write
|
||
D3C000
|
stack
|
page read and write
|
||
11F8000
|
heap
|
page read and write
|
||
FF0000
|
heap
|
page read and write
|
||
2BE8000
|
heap
|
page read and write
|
||
5220000
|
heap
|
page read and write
|
||
5E7000
|
unkown
|
page readonly
|
||
2BAF000
|
stack
|
page read and write
|
||
23D0000
|
heap
|
page read and write
|
||
12C0000
|
heap
|
page read and write
|
||
590000
|
heap
|
page read and write
|
||
4B7000
|
unkown
|
page readonly
|
||
4D9000
|
unkown
|
page write copy
|
||
5280000
|
heap
|
page read and write
|
||
AAF000
|
stack
|
page read and write
|
||
3698000
|
heap
|
page read and write
|
||
3098000
|
heap
|
page read and write
|
||
4DA000
|
unkown
|
page read and write
|
||
4630000
|
heap
|
page read and write
|
||
4D9000
|
unkown
|
page write copy
|
||
30A8000
|
heap
|
page read and write
|
||
C3C000
|
stack
|
page read and write
|
||
1BC000
|
stack
|
page read and write
|
||
13F7000
|
unkown
|
page readonly
|
||
34B5000
|
heap
|
page read and write
|
||
5DE000
|
stack
|
page read and write
|
||
386F000
|
stack
|
page read and write
|
||
541000
|
unkown
|
page execute read
|
||
E20000
|
heap
|
page read and write
|
||
25EB000
|
stack
|
page read and write
|
||
1204000
|
heap
|
page read and write
|
||
27B0000
|
heap
|
page read and write
|
||
1395000
|
heap
|
page read and write
|
||
411000
|
unkown
|
page execute read
|
||
2705000
|
heap
|
page read and write
|
||
581F000
|
stack
|
page read and write
|
||
303F000
|
stack
|
page read and write
|
||
3094000
|
heap
|
page read and write
|
||
4EC000
|
unkown
|
page read and write
|
||
122C000
|
heap
|
page read and write
|
||
27D1000
|
heap
|
page read and write
|
||
12FF000
|
heap
|
page read and write
|
||
620000
|
unkown
|
page readonly
|
||
278E000
|
stack
|
page read and write
|
||
4B1E000
|
stack
|
page read and write
|
||
13E6000
|
unkown
|
page readonly
|
||
345E000
|
stack
|
page read and write
|
||
4A0000
|
unkown
|
page readonly
|
||
4C55000
|
heap
|
page read and write
|
||
4FAE000
|
stack
|
page read and write
|
||
2A70000
|
heap
|
page read and write
|
||
11F0000
|
heap
|
page read and write
|
||
23F0000
|
heap
|
page read and write
|
||
AB0000
|
heap
|
page read and write
|
||
499E000
|
stack
|
page read and write
|
||
3077000
|
heap
|
page read and write
|
||
30A8000
|
heap
|
page read and write
|
||
485E000
|
stack
|
page read and write
|
||
13F5000
|
unkown
|
page readonly
|
||
DA0000
|
heap
|
page read and write
|
||
13D7000
|
unkown
|
page readonly
|
||
D90000
|
heap
|
page read and write
|
||
2FDB000
|
stack
|
page read and write
|
||
BD0000
|
heap
|
page read and write
|
||
2C28000
|
heap
|
page read and write
|
||
61F000
|
unkown
|
page readonly
|
||
4EAE000
|
stack
|
page read and write
|
||
2BD4000
|
heap
|
page read and write
|
||
E44000
|
heap
|
page read and write
|
||
13D7000
|
unkown
|
page readonly
|
||
4BCF000
|
stack
|
page read and write
|
||
3A56000
|
heap
|
page read and write
|
||
541000
|
unkown
|
page execute read
|
||
518E000
|
stack
|
page read and write
|
||
13A3000
|
unkown
|
page readonly
|
||
4EF000
|
unkown
|
page readonly
|
||
28F8000
|
stack
|
page read and write
|
||
4D9000
|
unkown
|
page write copy
|
||
30A8000
|
heap
|
page read and write
|
||
30AB000
|
heap
|
page read and write
|
||
580000
|
heap
|
page read and write
|
||
540000
|
unkown
|
page readonly
|
||
F8E000
|
stack
|
page read and write
|
||
22B000
|
stack
|
page read and write
|
||
504E000
|
stack
|
page read and write
|
||
2BD8000
|
heap
|
page read and write
|
||
2ECE000
|
stack
|
page read and write
|
||
3098000
|
heap
|
page read and write
|
||
609000
|
unkown
|
page write copy
|
||
30E8000
|
heap
|
page read and write
|
||
5E0000
|
unkown
|
page readonly
|
||
4650000
|
heap
|
page read and write
|
||
609000
|
unkown
|
page write copy
|
||
2B80000
|
heap
|
page read and write
|
||
104B000
|
heap
|
page read and write
|
||
4D9000
|
unkown
|
page write copy
|
||
2560000
|
heap
|
page read and write
|
||
2A30000
|
heap
|
page read and write
|
||
13F7000
|
unkown
|
page readonly
|
||
BC0000
|
unkown
|
page readonly
|
||
4850000
|
trusted library allocation
|
page read and write
|
||
32FA000
|
stack
|
page read and write
|
||
5DA1000
|
heap
|
page read and write
|
||
6FC000
|
heap
|
page read and write
|
||
4BA7000
|
heap
|
page read and write
|
||
4DA000
|
unkown
|
page read and write
|
||
4DB000
|
unkown
|
page write copy
|
||
4CDF000
|
stack
|
page read and write
|
||
4EF000
|
unkown
|
page readonly
|
||
2BC8000
|
heap
|
page read and write
|
||
30E5000
|
heap
|
page read and write
|
||
2970000
|
heap
|
page read and write
|
||
13F5000
|
unkown
|
page readonly
|
||
502E000
|
stack
|
page read and write
|
||
2BFF000
|
heap
|
page read and write
|
||
1406000
|
unkown
|
page readonly
|
||
9AF000
|
stack
|
page read and write
|
||
F40000
|
heap
|
page read and write
|
||
123C000
|
heap
|
page read and write
|
||
3980000
|
heap
|
page read and write
|
||
2A60000
|
heap
|
page read and write
|
||
FD0000
|
unkown
|
page readonly
|
||
630000
|
heap
|
page read and write
|
||
656000
|
heap
|
page read and write
|
||
2F35000
|
heap
|
page read and write
|
||
61F000
|
unkown
|
page readonly
|
||
2C5B000
|
stack
|
page read and write
|
||
BB000
|
stack
|
page read and write
|
||
DF0000
|
heap
|
page read and write
|
||
2C00000
|
heap
|
page read and write
|
||
4456000
|
heap
|
page read and write
|
||
2CFE000
|
stack
|
page read and write
|
||
6EE000
|
heap
|
page read and write
|
||
43D0000
|
trusted library allocation
|
page read and write
|
||
55A7000
|
heap
|
page read and write
|
||
540000
|
unkown
|
page readonly
|
||
5E7000
|
unkown
|
page readonly
|
||
512E000
|
stack
|
page read and write
|
||
E30000
|
heap
|
page read and write
|
||
3340000
|
heap
|
page read and write
|
||
4AC0000
|
heap
|
page read and write
|
||
4B7000
|
unkown
|
page readonly
|
||
53A1000
|
heap
|
page read and write
|
||
4DB000
|
unkown
|
page write copy
|
||
589E000
|
stack
|
page read and write
|
||
6E0000
|
heap
|
page read and write
|
||
30A8000
|
heap
|
page read and write
|
||
EFC000
|
stack
|
page read and write
|
||
61E000
|
stack
|
page read and write
|
||
2ED0000
|
heap
|
page read and write
|
||
3041000
|
heap
|
page read and write
|
||
599E000
|
stack
|
page read and write
|
||
530E000
|
stack
|
page read and write
|
||
42E0000
|
heap
|
page read and write
|
||
28E2000
|
heap
|
page read and write
|
||
BE9000
|
unkown
|
page readonly
|
||
46A0000
|
heap
|
page read and write
|
||
2700000
|
heap
|
page read and write
|
||
3050000
|
heap
|
page read and write
|
||
528F000
|
stack
|
page read and write
|
There are 265 hidden memdumps, click here to show them.