IOCReport

loading gif

Files

File Path
Type
Category
Malicious
sample20210113-01.xlsm
Microsoft Excel 2007+
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\dyu828kp[1].rar
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\lpxtpiw[1].zip
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Local\Temp\ndrztpo.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\pgjasrqd.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Desktop\~$sample20210113-01.xlsm
data
dropped
malicious
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, 58936 bytes, 1 file
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\272CF97F.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\46184574.png
PNG image data, 496 x 323, 8-bit colormap, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\Cab7485.tmp
Microsoft Cabinet archive data, 58936 bytes, 1 file
dropped
clean
C:\Users\user\AppData\Local\Temp\Excel8.0\MSForms.exd
data
dropped
clean
C:\Users\user\AppData\Local\Temp\FDFE0000
data
dropped
clean
C:\Users\user\AppData\Local\Temp\Tar7486.tmp
data
modified
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Wed Jan 13 23:38:54 2021, atime=Wed Jan 13 23:38:54 2021, length=8192, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\sample20210113-01.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:13 2020, mtime=Wed Jan 13 23:38:54 2021, atime=Wed Jan 13 23:38:57 2021, length=61904, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\WBLPQVYT.txt
ASCII text
downloaded
clean
C:\Users\user\Desktop\EF0F0000
data
dropped
clean
There are 9 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' -s C:\Users\user\AppData\Local\Temp\pgjasrqd.dll.
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s C:\Users\user\AppData\Local\Temp\pgjasrqd.dll.
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' -s C:\Users\user\AppData\Local\Temp\ndrztpo.dll.
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s C:\Users\user\AppData\Local\Temp\ndrztpo.dll.
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' -s C:\Users\user\AppData\Local\Temp\jvkhmoba.dll.
malicious

URLs

Name
IP
Malicious
http://bipolarmalta.mccarthy.ws/lpxtpiw.zip
35.214.225.210
malicious
http://crl.entrust.net/server1.crl0
unknown
clean
http://ocsp.entrust.net03
unknown
clean
https://221.126.244.72/3
unknown
clean
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
unknown
clean
https://157.7.166.26:5353/
unknown
clean
https://221.126.244.72/O
unknown
clean
http://sendgrid.invoteqleads.com/usc3d1.rar
104.24.124.127
clean
http://www.diginotar.nl/cps/pkioverheid0
unknown
clean
https://221.126.244.72/
unknown
clean
https://157.7.166.26/
unknown
clean
https://195.231.69.151:3889/G
unknown
clean
https://195.231.69.151/c7
unknown
clean
http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
unknown
clean
http://oudtshoornpharmacies.co.za/dyu828kp.rar
154.66.197.71
clean
http://www.%s.comPA
unknown
clean
https://195.231.69.151:3889/
unknown
clean
http://crl.microsoft.v&
unknown
clean
http://ocsp.entrust.net0D
unknown
clean
https://195.231.69.151/
unknown
clean
https://195.231.69.151:3889/hy
unknown
clean
https://secure.comodo.com/CPS0
unknown
clean
http://servername/isapibackend.dll
unknown
clean
https://195.231.69.151/d7
unknown
clean
http://crl.entrust.net/2048ca.crl0
unknown
clean
There are 15 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
sendgrid.invoteqleads.com
104.24.124.127
clean
bipolarmalta.mccarthy.ws
35.214.225.210
clean
oudtshoornpharmacies.co.za
154.66.197.71
clean

IPs

IP
Domain
Country
Active
Malicious
195.231.69.151
unknown
Italy
unknown
malicious
157.7.166.26
unknown
Japan
unknown
malicious
221.126.244.72
unknown
Hong Kong
unknown
malicious
154.66.197.71
unknown
South Africa
unknown
clean
104.24.124.127
unknown
United States
unknown
clean
35.214.225.210
unknown
United States
unknown
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
)`7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EEB97
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
FontCachePath
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EFD43
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductNonBootFilesIntl_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F0C40
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F196A
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
u=8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F7ED1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F8B10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SavedLegacySettings
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductNonBootFilesIntl_1033
clean
C:\Windows\SysWOW64\regsvr32.exe
SavedLegacySettings
clean
C:\Windows\SysWOW64\regsvr32.exe
Blob
clean
C:\Windows\SysWOW64\regsvr32.exe
Blob
clean
C:\Windows\SysWOW64\regsvr32.exe
Blob
clean
C:\Windows\SysWOW64\regsvr32.exe
Blob
clean
C:\Windows\SysWOW64\regsvr32.exe
Blob
clean
C:\Windows\SysWOW64\regsvr32.exe
Blob
clean
C:\Windows\SysWOW64\regsvr32.exe
SavedLegacySettings
clean
There are 265 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
E29000
heap private
page read and write
clean
4C4000
heap private
page read and write
clean
9B0000
unkown
page readonly
clean
671000
heap default
page read and write
clean
340000
heap default
page read and write
clean
3425000
unkown
page read and write
clean
4C4000
unkown
page read and write
clean
240000
heap private
page read and write
clean
E20000
heap private
page read and write
clean
32EA000
unkown
page read and write
clean
329C000
unkown
page read and write
clean
9BF000
unkown
page read and write
clean
3292000
unkown
page read and write
clean
250000
unkown
page execute and read and write
clean
65A000
heap default
page read and write
clean
3425000
unkown
page read and write
clean
205000
heap private
page read and write
clean
280000
unkown
page readonly
clean
E1D000
unkown
page read and write
clean
4D4000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
544000
heap default
page read and write
clean
591000
heap default
page read and write
clean
3401000
unkown
page read and write
clean
E47000
heap private
page read and write
clean
1DA000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
120000
unkown
page readonly
clean
1D0000
unkown
page readonly
clean
450000
heap default
page read and write
clean
4C0000
heap private
page read and write
clean
671000
unkown
page read and write
clean
90000
unkown
page readonly
clean
146000
heap private
page read and write
clean
130000
unkown
page readonly
clean
329C000
unkown
page read and write
clean
120000
heap private
page read and write
clean
880000
unkown
page readonly
clean
F80000
unkown
page readonly
clean
20000
unkown
page readonly
clean
F0000
unkown
page read and write
clean
550000
unkown
page read and write
clean
3459000
unkown
page read and write
clean
586000
unkown
page read and write
clean
A90000
heap private
page read and write
clean
EAD000
unkown
page read and write
clean
20000
unkown
page readonly
clean
20000
unkown
page readonly
clean
4C4000
heap private
page read and write
clean
187000
heap default
page read and write
clean
140000
heap private
page read and write
clean
D5D000
unkown
page read and write
clean
BF0000
unkown
page execute and read and write
clean
E45000
heap private
page read and write
clean
E0000
unkown
page read and write
clean
527000
heap default
page read and write
clean
2DE000
heap default
page read and write
clean
4AA000
heap default
page read and write
clean
D00000
unkown
page readonly
clean
21B5000
heap private
page read and write
clean
3C0000
unkown
page read and write
clean
22B0000
heap private
page read and write
clean
5B4000
heap default
page read and write
clean
19B000
unkown
page read and write
clean
2A6000
unkown
page read and write
clean
1FF0000
unkown
page readonly
clean
10000000
unkown image
page readonly
clean
2A0000
heap default
page read and write
clean
5D0000
unkown
page readonly
clean
EBE000
unkown
page read and write
clean
20D0000
unkown
page write copy
clean
32C6000
unkown
page read and write
clean
3FF000
unkown
page read and write
clean
326D000
unkown
page read and write
clean
20000
unkown
page readonly
clean
5E6000
heap default
page read and write
clean
130000
unkown
page readonly
clean
290000
unkown
page execute and read and write
clean
C60000
heap private
page read and write
clean
65A000
unkown
page read and write
clean
4D8000
unkown
page read and write
clean
4D3000
unkown
page read and write
clean
690000
unkown
page readonly
clean
CB0000
unkown
page readonly
clean
10000000
unkown image
page readonly
clean
810000
heap private
page read and write
clean
3292000
unkown
page read and write
clean
1C4000
heap private
page read and write
clean
21B0000
heap private
page read and write
clean
CB0000
unkown
page execute and read and write
clean
3449000
unkown
page read and write
clean
22EB000
heap private
page read and write
clean
48E000
heap default
page read and write
clean
F5D000
unkown
page read and write
clean
200000
heap private
page read and write
clean
13C000
unkown
page read and write
clean
590000
heap default
page read and write
clean
597000
heap default
page read and write
clean
329C000
unkown
page read and write
clean
652000
unkown
page read and write
clean
1C0000
heap private
page read and write
clean
32AF000
unkown
page read and write
clean
20000
unkown
page readonly
clean
328B000
unkown
page read and write
clean
3292000
unkown
page read and write
clean
6F0000
heap private
page read and write
clean
3290000
unkown
page read and write
clean
329C000
unkown
page read and write
clean
61A000
heap default
page read and write
clean
520000
heap default
page read and write
clean
ED5000
heap private
page read and write
clean
EE0000
heap private
page read and write
clean
330000
unkown
page readonly
clean
70000
unkown
page read and write
clean
328B000
unkown
page read and write
clean
700000
unkown
page readonly
clean
3290000
unkown
page read and write
clean
9D4000
unkown
page read and write
clean
506000
unkown
page read and write
clean
70000
unkown
page readonly
clean
AB2000
heap private
page read and write
clean
5CA000
heap default
page read and write
clean
23B000
heap private
page read and write
clean
404000
unkown
page read and write
clean
124000
heap private
page read and write
clean
3241000
unkown
page read and write
clean
604000
heap default
page read and write
clean
329C000
unkown
page read and write
clean
22B5000
heap private
page read and write
clean
576000
heap default
page read and write
clean
1E20000
unkown
page readonly
clean
326000
unkown
page read and write
clean
990000
unkown
page read and write
clean
90000
unkown
page readonly
clean
E20000
heap private
page read and write
clean
32FA000
unkown
page read and write
clean
D10000
unkown
page read and write
clean
9CF000
unkown
page read and write
clean
5D0000
unkown
page readonly
clean
500000
unkown
page read and write
clean
457000
heap default
page read and write
clean
E0E000
unkown
page read and write
clean
BB0000
unkown
page execute and read and write
clean
80000
unkown
page read and write
clean
EB8000
heap private
page read and write
clean
58F000
heap default
page read and write
clean
4CC000
unkown
page read and write
clean
2F3000
heap default
page read and write
clean
1BE000
heap default
page read and write
clean
2E0000
heap private
page read and write
clean
A0000
heap private
page read and write
clean
55A000
heap default
page read and write
clean
1CF0000
unkown
page readonly
clean
DA0000
heap private
page read and write
clean
620000
unkown
page readonly
clean
E50000
heap private
page read and write
clean
D10000
unkown
page read and write
clean
2E4000
heap private
page read and write
clean
3D6000
unkown
page read and write
clean
500000
unkown
page read and write
clean
4C0000
heap private
page read and write
clean
A94000
heap private
page read and write
clean
5E1000
heap default
page read and write
clean
4A3000
heap default
page read and write
clean
F0000
unkown
page read and write
clean
5CF000
heap default
page read and write
clean
1D3000
heap default
page read and write
clean
350000
unkown
page readonly
clean
4D0000
unkown
page read and write
clean
18B000
unkown
page read and write
clean
8F0000
unkown
page readonly
clean
1DA000
heap default
page read and write
clean
4D0000
unkown
page read and write
clean
F80000
unkown
page readonly
clean
329C000
unkown
page read and write
clean
1CC000
unkown
page read and write
clean
506000
unkown
page read and write
clean
2380000
unkown
page readonly
clean
32A7000
unkown
page read and write
clean
3DD000
unkown
page read and write
clean
C70000
unkown
page execute and read and write
clean
3260000
unkown
page read and write
clean
6F4000
heap private
page read and write
clean
26B000
unkown
page read and write
clean
E28000
heap private
page read and write
clean
7A0000
unkown
page readonly
clean
3449000
unkown
page read and write
clean
3290000
unkown
page read and write
clean
329C000
unkown
page read and write
clean
370000
unkown
page readonly
clean
100000
unkown
page read and write
clean
4D6000
unkown
page read and write
clean
70000
unkown
page readonly
clean
750000
unkown
page readonly
clean
4D2000
unkown
page read and write
clean
1CA000
unkown
page read and write
clean
180000
heap default
page read and write
clean
55F000
heap default
page read and write
clean
1CF0000
unkown
page readonly
clean
270000
unkown
page read and write
clean
3EF000
unkown
page read and write
clean
EB0000
heap private
page read and write
clean
2FA000
heap default
page read and write
clean
A4000
heap private
page read and write
clean
3292000
unkown
page read and write
clean
100000
unkown
page read and write
clean
3A0000
unkown
page read and write
clean
816000
heap private
page read and write
clean
598000
heap default
page read and write
clean
370000
heap default
page read and write
clean
2A7000
heap default
page read and write
clean
302000
heap private
page read and write
clean
2380000
unkown
page readonly
clean
1FF0000
unkown
page readonly
clean
AD0000
unkown
page readonly
clean
750000
unkown
page readonly
clean
1E0000
unkown
page execute and read and write
clean
140000
unkown
page readonly
clean
A20000
unkown
page readonly
clean
4C0000
unkown
page execute and read and write
clean
329C000
unkown
page read and write
clean
DAC000
unkown
page read and write
clean
9AD000
unkown
page read and write
clean
21EB000
heap private
page read and write
clean
4C8000
heap default
page read and write
clean
3290000
unkown
page read and write
clean
5FF000
heap default
page read and write
clean
There are 217 hidden memdumps, click here to show them.