IOCReport

loading gif

Files

File Path
Type
Category
Malicious
1_Total New Invoices-Thursday January 21_2021.xlsm
Microsoft Excel 2007+
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5JC0A1KN\gjeicn6u9[1].rar
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\or3peb[1].rar
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\hknmwj[1].zip
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\clh6qq[1].zip
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
modified
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\l3v7tq4[1].rar
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Local\Temp\kxwni.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\nnmumzom.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\sxzjqf.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Desktop\~$1_Total New Invoices-Thursday January 21_2021.xlsm
data
dropped
malicious
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, 58936 bytes, 1 file
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E0F5C59F9FA661F6F4C50B87FEF3A15A
data
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E0F5C59F9FA661F6F4C50B87FEF3A15A
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\A64C1FA3.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\B460DCA9.png
PNG image data, 200 x 254, 8-bit colormap, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\DD638D48.png
PNG image data, 247 x 76, 8-bit colormap, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\561F0000
data
dropped
clean
C:\Users\user\AppData\Local\Temp\Cab290.tmp
Microsoft Cabinet archive data, 58936 bytes, 1 file
dropped
clean
C:\Users\user\AppData\Local\Temp\Excel8.0\MSForms.exd
data
dropped
clean
C:\Users\user\AppData\Local\Temp\Tar2A1.tmp
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\1_Total New Invoices-Thursday January 21_2021.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:15 2020, mtime=Thu Jan 21 23:03:04 2021, atime=Thu Jan 21 23:03:08 2021, length=51781, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Thu Jan 21 23:03:04 2021, atime=Thu Jan 21 23:03:04 2021, length=8192, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\Desktop\863F0000
data
dropped
clean
There are 15 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' -s C:\Users\user\AppData\Local\Temp\kxwni.dll
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' -s C:\Users\user\AppData\Local\Temp\kxwni.dll
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' -s C:\Users\user\AppData\Local\Temp\uveoybvk.dll
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s C:\Users\user\AppData\Local\Temp\kxwni.dll
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' -s C:\Users\user\AppData\Local\Temp\nnmumzom.dll
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' -s C:\Users\user\AppData\Local\Temp\nnmumzom.dll
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s C:\Users\user\AppData\Local\Temp\nnmumzom.dll
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' -s C:\Users\user\AppData\Local\Temp\nnmumzom.dll
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s C:\Users\user\AppData\Local\Temp\nnmumzom.dll
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' -s C:\Users\user\AppData\Local\Temp\jxacpz.dll
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' -s C:\Users\user\AppData\Local\Temp\sxzjqf.dll
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' -s C:\Users\user\AppData\Local\Temp\sxzjqf.dll
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s C:\Users\user\AppData\Local\Temp\sxzjqf.dll
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' -s C:\Users\user\AppData\Local\Temp\sxzjqf.dll
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s C:\Users\user\AppData\Local\Temp\sxzjqf.dll
malicious
There are 6 hidden processes, click here to show them.

URLs

Name
IP
Malicious
https://211.110.44.63:5353/
unknown
clean
https://69.164.207.140/
unknown
clean
https://69.164.207.140:3388/C
unknown
clean
http://crl.entrust.net/server1.crl0
unknown
clean
http://ocsp.entrust.net03
unknown
clean
https://194.225.58.214/
unknown
clean
https://211.110.44.63:5353/8
unknown
clean
https://69.164.207.140/T
unknown
clean
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
unknown
clean
https://69.164.207.140:3388/7
unknown
clean
https://69.164.207.140:3388/hy
unknown
clean
http://www.diginotar.nl/cps/pkioverheid0
unknown
clean
http://stellarum.com.br/hknmwj.zip
191.252.144.65
clean
https://198.57.200.100:3786/XE
unknown
clean
https://69.164.207.140:3388/
unknown
clean
https://198.57.200.100:3786/
unknown
clean
http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
unknown
clean
https://198.57.200.100/
unknown
clean
https://194.225.58.214/P
unknown
clean
https://194.225.58.214/Y
unknown
clean
http://crl.co
unknown
clean
https://211.110.44.63/
unknown
clean
https://194.225.58.214/X
unknown
clean
https://198.57.200.100:3786/hy
unknown
clean
https://69.164.207.140/M
unknown
clean
http://ocsp.entrust.net0D
unknown
clean
https://198.57.200.100/_
unknown
clean
https://secure.comodo.com/CPS0
unknown
clean
https://194.225.58.214/C
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://crl.entrust.net/2048ca.crl0
unknown
clean
https://69.164.207.140:3388/JE
unknown
clean
https://198.57.200.100:3786/&
unknown
clean
There are 23 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
creditoenusa.com
192.185.224.50
clean
stellarum.com.br
191.252.144.65
clean
qsf.surfescape.net
64.37.52.172
clean
reliablelifts.co.in
103.83.81.27
clean
shopandmartonline.com
198.136.54.91
clean

IPs

IP
Domain
Country
Active
Malicious
69.164.207.140
unknown
United States
unknown
malicious
211.110.44.63
unknown
Korea Republic of
unknown
malicious
194.225.58.214
unknown
Iran (ISLAMIC Republic Of)
unknown
malicious
198.57.200.100
unknown
United States
unknown
malicious
192.185.224.50
unknown
United States
unknown
clean
191.252.144.65
unknown
Brazil
unknown
clean
103.83.81.27
unknown
India
unknown
clean
198.136.54.91
unknown
United States
unknown
clean
64.37.52.172
unknown
United States
unknown
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
h 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EF400
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
FontCachePath
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\system32\qagentrt.dll,-10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-843
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-844
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\wuaueng.dll,-400
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F11FB
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductNonBootFilesIntl_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F2175
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F4569
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
' 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
FE0FC
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
FEEF1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SavedLegacySettings
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductNonBootFilesIntl_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Windows\SysWOW64\regsvr32.exe
SavedLegacySettings
clean
C:\Windows\SysWOW64\regsvr32.exe
Blob
clean
C:\Windows\SysWOW64\regsvr32.exe
SavedLegacySettings
clean
C:\Windows\SysWOW64\regsvr32.exe
SavedLegacySettings
clean
C:\Windows\SysWOW64\regsvr32.exe
SavedLegacySettings
clean
C:\Windows\SysWOW64\regsvr32.exe
SavedLegacySettings
clean
There are 278 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
80F000
unkown
page read and write
clean
990000
heap private
page read and write
clean
335000
heap private
page read and write
clean
5B4000
heap private
page read and write
clean
2E0000
heap default
page read and write
clean
760000
unkown
page readonly
clean
39F000
heap default
page read and write
clean
20000
unkown
page readonly
clean
FA000
unkown
page read and write
clean
286000
unkown
page read and write
clean
5B0000
heap private
page read and write
clean
490000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
98E000
unkown
page read and write
clean
6FAF0000
unkown image
page readonly
clean
ABD000
unkown
page read and write
clean
1DF0000
unkown
page readonly
clean
570000
unkown
page readonly
clean
190000
unkown
page readonly
clean
3A6000
unkown
page read and write
clean
39A000
heap default
page read and write
clean
1A0000
unkown
page readonly
clean
227B000
heap private
page read and write
clean
148000
unkown
page read and write
clean
20000
unkown
page readonly
clean
560000
unkown
page readonly
clean
E0000
unkown
page read and write
clean
3D3000
heap default
page read and write
clean
180000
unkown
page read and write
clean
8FD000
unkown
page read and write
clean
416000
unkown
page read and write
clean
657000
heap default
page read and write
clean
BB000
unkown
page read and write
clean
5D4000
heap private
page read and write
clean
297000
heap default
page read and write
clean
409000
heap default
page read and write
clean
134000
unkown
page read and write
clean
1CE0000
unkown
page readonly
clean
244000
heap private
page read and write
clean
490000
unkown
page read and write
clean
2C7000
heap default
page read and write
clean
370000
unkown
page read and write
clean
68A000
heap default
page read and write
clean
9B2000
heap private
page read and write
clean
730000
unkown
page readonly
clean
2E3000
heap default
page read and write
clean
21C000
unkown
page read and write
clean
1D50000
unkown
page readonly
clean
9F0000
unkown
page readonly
clean
1C0000
heap default
page read and write
clean
3EE000
unkown
page read and write
clean
17C000
unkown
page read and write
clean
620000
heap default
page read and write
clean
2100000
heap private
page read and write
clean
2E4000
heap private
page read and write
clean
2130000
unkown
page readonly
clean
1F0000
unkown
page readonly
clean
2E0000
unkown
page read and write
clean
A45000
unkown
page readonly
clean
21A000
heap default
page read and write
clean
9F0000
unkown
page readonly
clean
990000
unkown
page readonly
clean
E0000
unkown
page readonly
clean
113000
heap default
page read and write
clean
5C0000
unkown
page readonly
clean
9F0000
unkown
page readonly
clean
5CF000
heap default
page read and write
clean
520000
unkown
page readonly
clean
240000
unkown
page readonly
clean
1C7000
heap default
page read and write
clean
91F000
unkown
page read and write
clean
710000
heap private
page read and write
clean
820000
unkown
page read and write
clean
540000
unkown
page readonly
clean
920000
unkown
page execute and read and write
clean
100000
unkown
page read and write
clean
9B0000
heap private
page read and write
clean
630000
unkown
page readonly
clean
574000
heap private
page read and write
clean
4D6000
unkown
page read and write
clean
3DE000
heap default
page read and write
clean
1E0000
unkown
page readonly
clean
53C000
heap default
page read and write
clean
70000
unkown
page readonly
clean
30C000
unkown
page read and write
clean
5CA000
heap default
page read and write
clean
2F0000
unkown
page readonly
clean
227000
heap private
page read and write
clean
1A0000
unkown
page readonly
clean
213B000
heap private
page read and write
clean
70000
unkown
page readonly
clean
460000
unkown
page read and write
clean
6CE000
heap default
page read and write
clean
406000
heap private
page read and write
clean
20000
unkown
page readonly
clean
350000
heap default
page read and write
clean
760000
unkown
page readonly
clean
21D0000
unkown
page read and write
clean
2EA000
heap default
page read and write
clean
6E0000
unkown
page readonly
clean
6E4A0000
unkown image
page readonly
clean
794000
heap private
page read and write
clean
23A000
unkown
page read and write
clean
130000
unkown
page readonly
clean
3E0000
unkown
page read and write
clean
70000
unkown
page readonly
clean
AA000
unkown
page read and write
clean
2F0000
heap default
page read and write
clean
1C4000
heap private
page read and write
clean
550000
heap private
page read and write
clean
880000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
20000
unkown
page readonly
clean
B0000
unkown
page readonly
clean
7FF000
unkown
page read and write
clean
B2F000
unkown
page read and write
clean
209B000
heap private
page read and write
clean
3BE000
heap default
page read and write
clean
2B0000
heap private
page read and write
clean
7B0000
unkown
page readonly
clean
4D0000
heap private
page read and write
clean
BB0000
unkown
page readonly
clean
20000
unkown
page readonly
clean
F0000
unkown
page read and write
clean
556000
heap private
page read and write
clean
390000
unkown
page read and write
clean
790000
heap private
page read and write
clean
28A000
heap default
page read and write
clean
3F3000
heap default
page read and write
clean
5D0000
heap private
page read and write
clean
20000
unkown
page readonly
clean
240000
heap private
page read and write
clean
3A0000
unkown
page readonly
clean
138000
heap default
page read and write
clean
E0000
unkown
page read and write
clean
5E0000
unkown
page readonly
clean
560000
heap private
page read and write
clean
32F000
heap default
page read and write
clean
608000
heap default
page read and write
clean
1D00000
unkown
page readonly
clean
1A0000
unkown
page execute and read and write
clean
20000
unkown
page readonly
clean
2AA000
unkown
page read and write
clean
5D0000
heap private
page read and write
clean
6F6000
heap default
page read and write
clean
620000
heap private
page read and write
clean
280000
unkown
page read and write
clean
2D2000
heap private
page read and write
clean
3C1000
heap default
page read and write
clean
20E0000
unkown
page readonly
clean
1D0000
unkown
page readonly
clean
360000
heap private
page read and write
clean
5F0000
unkown
page readonly
clean
45D000
unkown
page read and write
clean
114000
heap private
page read and write
clean
2A0000
heap default
page read and write
clean
17C000
unkown
page read and write
clean
604000
heap default
page read and write
clean
674000
heap default
page read and write
clean
369000
heap default
page read and write
clean
670000
unkown
page readonly
clean
480000
unkown
page read and write
clean
1D0000
unkown
page readonly
clean
390000
unkown
page read and write
clean
1DF0000
unkown
page readonly
clean
BA000
unkown
page read and write
clean
447000
heap default
page read and write
clean
51F000
heap default
page read and write
clean
20000
unkown
page readonly
clean
3FA000
heap default
page read and write
clean
6FAF0000
unkown image
page readonly
clean
456000
heap default
page read and write
clean
590000
heap default
page read and write
clean
6E0000
unkown
page readonly
clean
1B0000
unkown
page readonly
clean
C0000
heap default
page read and write
clean
70000
unkown
page readonly
clean
70000
unkown
page read and write
clean
20000
unkown
page readonly
clean
700000
unkown
page readonly
clean
2E0000
unkown
page read and write
clean
200000
heap private
page read and write
clean
142000
unkown
page read and write
clean
367000
heap default
page read and write
clean
313000
heap default
page read and write
clean
740000
unkown
page readonly
clean
D0000
unkown
page read and write
clean
2C0000
heap default
page read and write
clean
6C4000
heap private
page read and write
clean
4D4000
heap default
page read and write
clean
110000
heap default
page read and write
clean
980000
unkown
page read and write
clean
33A000
heap default
page read and write
clean
31E000
heap default
page read and write
clean
100000
unkown
page read and write
clean
49A000
heap default
page read and write
clean
3B0000
unkown
page readonly
clean
32A000
heap default
page read and write
clean
100000
unkown
page read and write
clean
55E000
heap default
page read and write
clean
800000
unkown
page readonly
clean
280000
unkown
page read and write
clean
47E000
heap default
page read and write
clean
3C6000
unkown
page read and write
clean
130000
unkown
page readonly
clean
90000
unkown
page readonly
clean
20EB000
heap private
page read and write
clean
2E3000
heap default
page read and write
clean
366000
unkown
page read and write
clean
540000
unkown
page read and write
clean
8AF000
unkown
page read and write
clean
2FE000
heap default
page read and write
clean
516000
unkown
page read and write
clean
470000
unkown
page readonly
clean
4E0000
unkown
page read and write
clean
180000
unkown
page read and write
clean
650000
heap default
page read and write
clean
18B000
unkown
page read and write
clean
1C0000
unkown
page readonly
clean
190000
unkown
page readonly
clean
2120000
heap private
page read and write
clean
2E7000
heap default
page read and write
clean
160000
unkown
page read and write
clean
1C0000
heap private
page read and write
clean
570000
heap private
page read and write
clean
4A0000
unkown
page read and write
clean
20B0000
heap private
page read and write
clean
10C000
unkown
page read and write
clean
9A0000
unkown
page readonly
clean
70000
unkown
page readonly
clean
1EC000
unkown
page read and write
clean
120000
unkown
page readonly
clean
3C0000
unkown
page read and write
clean
1FA0000
unkown
page readonly
clean
460000
unkown
page read and write
clean
320000
unkown
page readonly
clean
100000
unkown
page readonly
clean
13C000
unkown
page read and write
clean
994000
heap private
page read and write
clean
390000
heap private
page read and write
clean
FE000
heap default
page read and write
clean
130000
heap private
page read and write
clean
9C5000
heap private
page read and write
clean
366000
unkown
page read and write
clean
3F6000
unkown
page read and write
clean
376000
heap default
page read and write
clean
27B000
unkown
page read and write
clean
2105000
heap private
page read and write
clean
250000
unkown
page read and write
clean
440000
heap default
page read and write
clean
220000
unkown
page write copy
clean
20F0000
unkown
page readonly
clean
26E000
heap default
page read and write
clean
9F0000
unkown
page readonly
clean
20000
unkown
page readonly
clean
1DF0000
unkown
page readonly
clean
9D0000
heap private
page read and write
clean
B9E000
unkown
page read and write
clean
80000
unkown
page read and write
clean
4B0000
heap default
page read and write
clean
213000
heap default
page read and write
clean
110000
heap private
page read and write
clean
2060000
heap private
page read and write
clean
1B0000
unkown
page readonly
clean
2D0000
unkown
page readonly
clean
430000
unkown
page read and write
clean
5D6000
unkown
page read and write
clean
20F0000
unkown
page execute and read and write
clean
1FE0000
unkown
page readonly
clean
44E000
heap default
page read and write
clean
9A0000
heap private
page read and write
clean
145000
unkown
page read and write
clean
130000
unkown
page readonly
clean
2B6000
unkown
page read and write
clean
1F0000
unkown
page execute and read and write
clean
8E0000
unkown
page read and write
clean
340000
heap private
page read and write
clean
320000
heap private
page read and write
clean
410000
unkown
page execute and read and write
clean
120000
unkown
page readonly
clean
1DA0000
unkown
page readonly
clean
318000
heap private
page read and write
clean
387000
heap default
page read and write
clean
5B4000
heap default
page read and write
clean
134000
heap private
page read and write
clean
1FB0000
unkown
page readonly
clean
6E6000
heap default
page read and write
clean
90000
unkown
page readonly
clean
2CE000
heap default
page read and write
clean
F0000
unkown
page read and write
clean
200000
heap private
page read and write
clean
17C000
unkown
page read and write
clean
8B0000
unkown
page readonly
clean
1E0000
unkown
page execute and read and write
clean
210000
unkown
page readonly
clean
2EA000
heap default
page read and write
clean
3AC000
unkown
page read and write
clean
140000
heap default
page read and write
clean
493000
heap default
page read and write
clean
2B4000
heap private
page read and write
clean
1C0000
heap private
page read and write
clean
3A0000
heap default
page read and write
clean
300000
unkown
page execute and read and write
clean
2F7000
heap default
page read and write
clean
92D000
unkown
page read and write
clean
394000
heap private
page read and write
clean
3C6000
unkown
page read and write
clean
144000
unkown
page read and write
clean
24E0000
unkown
page execute and read and write
clean
230000
heap default
page read and write
clean
C7000
heap default
page read and write
clean
814000
unkown
page read and write
clean
596000
heap private
page read and write
clean
333000
heap default
page read and write
clean
9A8000
heap private
page read and write
clean
7D0000
unkown
page read and write
clean
24C000
unkown
page read and write
clean
230000
unkown
page execute and read and write
clean
350000
unkown
page readonly
clean
360000
heap default
page read and write
clean
570000
heap private
page read and write
clean
2245000
heap private
page read and write
clean
136000
unkown
page read and write
clean
70000
unkown
page read and write
clean
20B5000
heap private
page read and write
clean
674000
heap private
page read and write
clean
220000
unkown
page execute and read and write
clean
2065000
heap private
page read and write
clean
F0000
unkown
page read and write
clean
143000
unkown
page read and write
clean
970000
unkown
page readonly
clean
6D1000
heap default
page read and write
clean
1DF0000
unkown
page readonly
clean
F0000
unkown
page read and write
clean
7B2000
heap private
page read and write
clean
3A7000
heap default
page read and write
clean
1DF0000
unkown
page readonly
clean
980000
unkown
page read and write
clean
714000
heap private
page read and write
clean
290000
heap default
page read and write
clean
364000
heap private
page read and write
clean
570000
unkown
page read and write
clean
4B6000
unkown
page read and write
clean
5D4000
heap private
page read and write
clean
360000
heap private
page read and write
clean
564000
heap private
page read and write
clean
23B000
unkown
page read and write
clean
7ED000
unkown
page read and write
clean
4C6000
unkown
page read and write
clean
276000
heap private
page read and write
clean
283000
heap default
page read and write
clean
2210000
unkown
page write copy
clean
83D000
unkown
page read and write
clean
5F1000
heap default
page read and write
clean
470000
unkown
page readonly
clean
924000
unkown
page read and write
clean
6E4A0000
unkown image
page readonly
clean
1A0000
unkown
page readonly
clean
24000
heap private
page read and write
clean
5E0000
unkown
page read and write
clean
6D0000
unkown
page readonly
clean
6C0000
unkown
page readonly
clean
64E000
unkown
page read and write
clean
994000
heap private
page read and write
clean
410000
unkown
page readonly
clean
380000
heap default
page read and write
clean
6B1000
heap default
page read and write
clean
400000
heap private
page read and write
clean
2180000
unkown
page write copy
clean
BA0000
heap private
page read and write
clean
3F0000
heap default
page read and write
clean
90F000
unkown
page read and write
clean
70000
unkown
page readonly
clean
85F000
unkown
page read and write
clean
20000
unkown
page readonly
clean
4D4000
heap private
page read and write
clean
4EF000
heap default
page read and write
clean
320000
heap default
page read and write
clean
9B2000
heap private
page read and write
clean
2240000
heap private
page read and write
clean
8C4000
unkown
page read and write
clean
330000
unkown
page read and write
clean
65D000
heap default
page read and write
clean
597000
heap default
page read and write
clean
860000
unkown
page readonly
clean
511000
heap default
page read and write
clean
6C0000
heap private
page read and write
clean
670000
heap private
page read and write
clean
140000
unkown
page readonly
clean
120000
unkown
page readonly
clean
3DA000
heap default
page read and write
clean
20000
unkown
page readonly
clean
2CE000
heap default
page read and write
clean
2E0000
heap private
page read and write
clean
8BF000
unkown
page read and write
clean
D0000
unkown
page read and write
clean
290000
heap default
page read and write
clean
5A0000
unkown
page read and write
clean
850000
unkown
page readonly
clean
530000
unkown
page execute and read and write
clean
200000
unkown
page readonly
clean
1C0000
unkown
page readonly
clean
8D0000
unkown
page readonly
clean
21D0000
unkown
page read and write
clean
580000
unkown
page readonly
clean
310000
heap private
page read and write
clean
3F0000
unkown
page readonly
clean
950000
unkown
page readonly
clean
130000
unkown
page readonly
clean
20000
heap private
page read and write
clean
20000
unkown
page readonly
clean
4EA000
heap default
page read and write
clean
624000
heap private
page read and write
clean
1B6000
unkown
page read and write
clean
110000
unkown
page readonly
clean
110000
unkown
page readonly
clean
310000
heap private
page read and write
clean
240000
unkown
page execute and read and write
clean
6C2000
heap default
page read and write
clean
280000
unkown
page readonly
clean
7F0000
unkown
page readonly
clean
466000
unkown
page read and write
clean
12A000
unkown
page read and write
clean
990000
heap private
page read and write
clean
170000
unkown
page read and write
clean
540000
unkown
page read and write
clean
21A0000
unkown
page write copy
clean
25E000
unkown
page read and write
clean
89D000
unkown
page read and write
clean
84F000
unkown
page read and write
clean
864000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
68F000
heap default
page read and write
clean
703D0000
unkown image
page readonly
clean
1E00000
unkown
page readonly
clean
E0000
unkown
page read and write
clean
460000
unkown
page readonly
clean
11A000
heap default
page read and write
clean
2B0000
unkown
page execute and read and write
clean
70000
unkown
page readonly
clean
616000
unkown
page read and write
clean
A00000
unkown
page readonly
clean
324000
heap private
page read and write
clean
204000
heap private
page read and write
clean
629000
heap default
page read and write
clean
20000
unkown
page readonly
clean
96D000
unkown
page read and write
clean
209000
heap private
page read and write
clean
4C6000
unkown
page read and write
clean
590000
heap private
page read and write
clean
384000
heap default
page read and write
clean
5E0000
unkown
page readonly
clean
580000
unkown
page readonly
clean
2A0000
unkown
page readonly
clean
680000
unkown
page readonly
clean
1FE000
heap default
page read and write
clean
1D90000
unkown
page readonly
clean
2125000
heap private
page read and write
clean
297000
heap default
page read and write
clean
5A6000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
80000
unkown
page read and write
clean
5B0000
unkown
page readonly
clean
1CA0000
unkown
page readonly
clean
E0000
unkown
page read and write
clean
21C0000
unkown
page write copy
clean
576000
heap private
page read and write
clean
E0000
unkown
page read and write
clean
215B000
heap private
page read and write
clean
1CB0000
unkown
page readonly
clean
4B7000
heap default
page read and write
clean
AC000
unkown
page read and write
clean
2AA000
unkown
page read and write
clean
1D00000
unkown
page readonly
clean
403000
heap default
page read and write
clean
31A000
heap default
page read and write
clean
20A000
unkown
page read and write
clean
314000
heap default
page read and write
clean
F0000
unkown
page readonly
clean
1F0000
unkown
page execute and read and write
clean
1B0000
unkown
page execute and read and write
clean
F0000
unkown
page readonly
clean
270000
heap private
page read and write
clean
330000
unkown
page read and write
clean
237000
heap default
page read and write
clean
There are 475 hidden memdumps, click here to show them.