Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\rsatcustominstaller.exe
|
"C:\Users\user\Desktop\rsatcustominstaller.exe"
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
Start_AdminToolsRoot
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
StartMenuAdminTools
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
7FF60C034000
|
unkown
|
page readonly
|
||
1ED9C110000
|
heap
|
page read and write
|
||
7FF60C031000
|
unkown
|
page execute read
|
||
415367F000
|
stack
|
page read and write
|
||
7FF60C030000
|
unkown
|
page readonly
|
||
7FF60C038000
|
unkown
|
page readonly
|
||
1ED9C470000
|
heap
|
page read and write
|
||
7FF60C031000
|
unkown
|
page execute read
|
||
1ED9C1F0000
|
heap
|
page read and write
|
||
7FF60C037000
|
unkown
|
page write copy
|
||
7FF60C034000
|
unkown
|
page readonly
|
||
1ED9C2C0000
|
heap
|
page read and write
|
||
1ED9C2C7000
|
heap
|
page read and write
|
||
1ED9C210000
|
heap
|
page read and write
|
||
1ED9C475000
|
heap
|
page read and write
|
||
7FF60C037000
|
unkown
|
page read and write
|
||
7FF60C038000
|
unkown
|
page readonly
|
||
415332C000
|
stack
|
page read and write
|
||
41533AE000
|
stack
|
page read and write
|
||
7FF60C030000
|
unkown
|
page readonly
|
There are 10 hidden memdumps, click here to show them.