IOCReport

loading gif

Files

File Path
Type
Category
Malicious
FileSetup-v17.04.41.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences
ASCII text, with very long lines
dropped
malicious
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
UTF-8 Unicode text, with very long lines
dropped
malicious
C:\Users\user\AppData\Local\Temp\6852B33702F6B3BD.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\6852B33702F6B3BD.exe:Zone.Identifier
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Local\Cookies1611946677837
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Local\Cookies1611946694149
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\canopdahbphflpoibdjjgahoedkbdncm\1.0.0.0_0\background.js
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\canopdahbphflpoibdjjgahoedkbdncm\1.0.0.0_0\book.js
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\canopdahbphflpoibdjjgahoedkbdncm\1.0.0.0_0\icon.png
PNG image data, 30 x 30, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\canopdahbphflpoibdjjgahoedkbdncm\1.0.0.0_0\icon48.png
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\canopdahbphflpoibdjjgahoedkbdncm\1.0.0.0_0\jquery-1.8.3.min.js
ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\canopdahbphflpoibdjjgahoedkbdncm\1.0.0.0_0\manifest.json
ASCII text, with very long lines, with CRLF, LF line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\canopdahbphflpoibdjjgahoedkbdncm\1.0.0.0_0\popup.html
HTML document, ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\canopdahbphflpoibdjjgahoedkbdncm\1.0.0.0_0\popup.js
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Login Data1611946677837
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Local\Login Data1611946694087
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Local\Temp\1611946680743
7-zip archive data, version 0.3
dropped
clean
C:\Users\user\AppData\Local\Temp\1611946681946
7-zip archive data, version 0.3
dropped
clean
C:\Users\user\AppData\Local\Temp\MSI61C2.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Local\Temp\download\MiniThunderPlatform.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Local\Temp\download\ThunderFW.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Local\Temp\download\atl71.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Local\Temp\download\dl_peer_id.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Local\Temp\download\download_engine.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Local\Temp\download\msvcp71.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Local\Temp\download\msvcr71.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Local\Temp\download\zlib1.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Local\Temp\ecvAA35.tmp
Extensible storage engine DataBase, version 0x620, checksum 0x30c654ce, page size 32768, DirtyShutdown, Windows version 10.0
dropped
clean
C:\Users\user\AppData\Local\Temp\gdiview.msi
;1033
modified
clean
C:\Users\user\AppData\Local\Temp\xldl.dat
7-zip archive data, version 0.3
dropped
clean
C:\Users\user\AppData\Local\Temp\xldl.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Local\Web Data1611946694399
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Local\crx.7z
7-zip archive data, version 0.3
dropped
clean
C:\Users\user\AppData\Local\crx.json
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Localwebdata1611946694399
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Roaming\1611946678493.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\1611946678493.txt
Little-endian UTF-16 Unicode text, with very long lines, with CRLF, CR line terminators
dropped
clean
C:\Users\user\AppData\Local\Cookies1611913514530
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Local\Cookies1611913558680
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehcdpclapmggacanmpfjlemhjkoefcbh\1.0.0.0_0\background.js
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehcdpclapmggacanmpfjlemhjkoefcbh\1.0.0.0_0\book.js
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehcdpclapmggacanmpfjlemhjkoefcbh\1.0.0.0_0\icon.png
PNG image data, 30 x 30, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehcdpclapmggacanmpfjlemhjkoefcbh\1.0.0.0_0\icon48.png
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehcdpclapmggacanmpfjlemhjkoefcbh\1.0.0.0_0\jquery-1.8.3.min.js
ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehcdpclapmggacanmpfjlemhjkoefcbh\1.0.0.0_0\manifest.json
ASCII text, with very long lines, with CRLF, LF line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehcdpclapmggacanmpfjlemhjkoefcbh\1.0.0.0_0\popup.html
HTML document, ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehcdpclapmggacanmpfjlemhjkoefcbh\1.0.0.0_0\popup.js
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Login Data1611913514483
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Local\Login Data1611913558680
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Local\Temp\1611913516483
7-zip archive data, version 0.3
dropped
clean
C:\Users\user\AppData\Local\Temp\1611913547477
7-zip archive data, version 0.3
dropped
clean
C:\Users\user\AppData\Local\Temp\MSI2C5D.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Local\Temp\ecv732A.tmp
Extensible storage engine DataBase, version 0x620, checksum 0x18bd5d35, page size 32768, DirtyShutdown, Windows version 10.0
dropped
clean
C:\Users\user\AppData\Local\Web Data1611913558993
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Localwebdata1611913559039
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Roaming\1611913544586.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\1611913544586.txt
Little-endian UTF-16 Unicode text, with very long lines, with CRLF, CR line terminators
dropped
clean
There are 48 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\FileSetup-v17.04.41.exe
'C:\Users\user\Desktop\FileSetup-v17.04.41.exe'
malicious
C:\Users\user\AppData\Local\Temp\6852B33702F6B3BD.exe
C:\Users\user\AppData\Local\Temp\6852B33702F6B3BD.exe 0011 installp3
malicious
C:\Users\user\AppData\Local\Temp\6852B33702F6B3BD.exe
C:\Users\user\AppData\Local\Temp\6852B33702F6B3BD.exe 200 installp3
malicious
C:\Windows\SysWOW64\cmd.exe
cmd /c ping 127.0.0.1 -n 3 & del 'C:\Users\user\Desktop\FileSetup-v17.04.41.exe'
malicious
C:\Windows\SysWOW64\PING.EXE
ping 127.0.0.1 -n 3
malicious
C:\Windows\SysWOW64\cmd.exe
cmd.exe /c taskkill /f /im chrome.exe
malicious
C:\Windows\SysWOW64\cmd.exe
cmd /c ping 127.0.0.1 -n 3 & del 'C:\Users\user\AppData\Local\Temp\6852B33702F6B3BD.exe'
malicious
C:\Windows\SysWOW64\PING.EXE
ping 127.0.0.1 -n 3
malicious
C:\Windows\SysWOW64\cmd.exe
cmd /c ping 127.0.0.1 -n 3 & del 'C:\Users\user\AppData\Local\Temp\6852B33702F6B3BD.exe'
malicious
C:\Windows\SysWOW64\PING.EXE
ping 127.0.0.1 -n 3
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec.exe /i 'C:\Users\user\AppData\Local\Temp\gdiview.msi'
clean
C:\Windows\SysWOW64\msiexec.exe
C:\Windows\syswow64\MsiExec.exe -Embedding E90BF9A81DF75408BCAEC738866B933F C
clean
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
clean
C:\Users\user\AppData\Roaming\1611946678493.exe
'C:\Users\user\AppData\Roaming\1611946678493.exe' /sjson 'C:\Users\user\AppData\Roaming\1611946678493.txt'
clean
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
clean
C:\Windows\SysWOW64\taskkill.exe
taskkill /f /im chrome.exe
clean
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
clean
C:\Users\user\AppData\Local\Temp\download\ThunderFW.exe
C:\Users\user\AppData\Local\Temp\download\ThunderFW.exe ThunderFW 'C:\Users\user\AppData\Local\Temp\download\MiniThunderPlatform.exe'
clean
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
clean
C:\Windows\SysWOW64\msiexec.exe
C:\Windows\syswow64\MsiExec.exe -Embedding 4B33F9BC0983FC9804745233301A967F C
clean
C:\Users\user\AppData\Roaming\1611913544586.exe
'C:\Users\user\AppData\Roaming\1611913544586.exe' /sjson 'C:\Users\user\AppData\Roaming\1611913544586.txt'
clean
There are 11 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://www.msn.com/de-ch/entertainment/_h/c920645c/webcore/externalscripts/oneTrustV2/scripttemplate
unknown
clean
https://duckduckgo.com/chrome_newtab
unknown
clean
https://duckduckgo.com/ac/?q=
unknown
clean
http://84cfba021a5a6662.xyz/info_old/g
104.21.23.16
clean
https://www.messenger.com/
unknown
clean
http://84cfba021a5a6662.xyz/info_old/e
104.21.23.16
clean
http://www.msn.com
unknown
clean
http://84cfba021a5a6662.xyz/info_old/w
104.21.23.16
clean
http://www.nirsoft.net
unknown
clean
https://deff.nelreports.net/api/report?cat=msn
unknown
clean
https://A5D4CE54CC78B3CA.xyz/
unknown
clean
https://twitter.com/ookie:
unknown
clean
http://84cfba021a5a6662.xyz/info_old/r
104.21.23.16
clean
https://twitter.comsec-fetch-dest:
unknown
clean
https://assets.adobedtm.com/5ef092d1efb5/4d1d9f749fd3/434d91f2e635/RCc13122162a9a46c3b4cbf05ffccde0f
unknown
clean
http://www.interoperabilitybridges.com/wmp-extension-for-chrome
unknown
clean
http://ocsp.pki.goog/gts1o1core0
unknown
clean
https://maps.windows.com/windows-app-web-link
unknown
clean
http://www.msn.com/?ocid=iehp
unknown
clean
https://2542116.fls.doubleclick.net/activityi;src=2542116;type=chrom322;cat=chrom01g;ord=68568119166
unknown
clean
https://assets.adobedtm.com/5ef092d1efb5/4d1d9f749fd3/434d91f2e635/RCee0d4d5fd4424c8390d703b105f82c3
unknown
clean
https://srtb.msn.com/auction?a=de-ch&b=a8415ac9f9644a1396bc1648a4599445&c=MSN&d=http%3A%2F%2Fwww.msn
unknown
clean
http://crl.pki.goog/GTS1O1core.crl0
unknown
clean
https://www.messenger.com
unknown
clean
http://www.nirsoft.net/
unknown
clean
http://forms.real.com/real/realone/download.html?type=rpsp_us
unknown
clean
http://config.i.duba.net/lminstall/%d.json?time=%d
unknown
clean
http://ocsp.pki.goog/GTSGIAG30
unknown
clean
https://www.instagram.com/graphql/query/?query_hash=149bef52a3b2af88c0fec37913fe1cbc&variables=%7B%2
unknown
clean
https://logincdn.msauth.net/16.000/Converged_v21033_-0mnSwu67knBd7qR7YN9GQ2.css
unknown
clean
http://download.divx.com/player/divxdotcom/DivXWebPlayerInstaller.exe
unknown
clean
https://logincdn.msauth.net/16.000.28666.10/content/images/microsoft_logo_ee5c8d9fb6248c938fd0dc1937
unknown
clean
https://logincdn.msauth.net/16.000.28666.10/content/images/ellipsis_white_5ac590ee72bfe06a7cecfd75b5
unknown
clean
https://upload.twitter.com/i/media/upload.jsoncommand=FINALIZE&media_id=
unknown
clean
https://www.instagram.com/
unknown
clean
http://schemas.xmlsoap.org/soap/encoding/
unknown
clean
http://www.xunlei.com/GET
unknown
clean
http://84cfba021a5a6662.xyz/i
unknown
clean
https://assets.adobedtm.com/5ef092d1efb5/4d1d9f749fd3/434d91f2e635/RC5bdddb231cf54f958a5b6e76e9d8eee
unknown
clean
https://upload.twitter.com/i/media/upload.json%dcommand=INIT&total_bytes=&media_type=image%2Fjpeg&me
unknown
clean
http://84CFBA021A5A6662.xyz/xet(
unknown
clean
https://www.messenger.com/origin:
unknown
clean
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
unknown
clean
http://pki.goog/gsr2/GTS1O1.crt0
unknown
clean
https://contextual.media.net/medianet.php?cid=8CU157172&crid=858412214&size=306x271&https=1
unknown
clean
https://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml
unknown
clean
https://contextual.media.net/
unknown
clean
http://ocsp.pki.goog/gsr202
unknown
clean
https://pki.goog/repository/0
unknown
clean
https://api.twitter.com/1.1/statuses/update.json
unknown
clean
https://cvision.media.net/new/300x300/3/167/174/27/39ab3103-8560-4a55-bfc4-401f897cf6f2.jpg?v=9
unknown
clean
http://www.msn.com/
unknown
clean
https://upload.twitter.com/i/media/upload.json
unknown
clean
https://assets.adobedtm.com/5ef092d1efb5/4d1d9f749fd3/434d91f2e635/RC828bc1cde9f04b788c98b5423157734
unknown
clean
https://twitter.com/compose/tweetsec-fetch-mode:
unknown
clean
http://84CFBA021A5A6662.xyz/info_old/w
unknown
clean
https://2542116.fls.doubleclick.net/activityi;src=2542116;type=clien612;cat=chromx;ord=1;num=1463674
unknown
clean
https://www.messenger.com/accept:
unknown
clean
http://www.msn.com/de-ch/entertainment/_h/c920645c/webcore/externalscripts/oneTrustV2/consent/55a804
unknown
clean
https://contextual.media.net/803288796/fcmain.js?&gdpr=0&cid=8CU157172&cpcd=pC3JHgSCqY8UHihgrvGr0A%3
unknown
clean
https://contextual.media.net/48/nrrV18753.js
unknown
clean
http://crl.pki.goog/gsr2/gsr2.crl0?
unknown
clean
http://84CFBA021A5A6662.xyz/info_old/g
unknown
clean
http://pki.goog/gsr2/GTSGIAG3.crt0)
unknown
clean
https://upload.twitter.com/i/media/upload.json?command=APPEND&media_id=%s&segment_index=0
unknown
clean
https://feedback.googleusercontent.com
unknown
clean
https://www.messenger.comhttps://www.messenger.com/login/nonce/ookie:
unknown
clean
https://fsfba021a5a6662.xyz/
unknown
clean
http://www.xunlei.com/
unknown
clean
http://pki.goog/gsr2/GTS1O1.crt0#
unknown
clean
http://84CFBA021A5A6662.xyz/info_old/ddd
104.21.23.16
clean
https://aefd.nelreports.net/api/report?cat=bingth
unknown
clean
http://84CFBA021A5A6662.xyz/info_old/wN
unknown
clean
https://upload.twitter.com/i/media/upload.json?command=APPEND&media_id=%s&segment_index=0accept:
unknown
clean
http://schemas.xmlsoap.org/soap/envelope/
unknown
clean
https://exchangework%04d%02d%02d.xyz/http://changenewsys%04d%02d%02d.xyz/post_info.
unknown
clean
https://geolocation.onetrust.com/cookieconsentpub/v1/geo/location
unknown
clean
http://84cfba021a5a6662.xyz/
unknown
clean
https://assets.adobedtm.com/launch-EN7b3d710ac67a4a1195648458258f97dd.min.js
unknown
clean
https://assets.adobedtm.com/5ef092d1efb5/4d1d9f749fd3/434d91f2e635/RCfd484f9188564713bbc5d13d862ebbf
unknown
clean
https://curl.haxx.se/docs/http-cookies.html
unknown
clean
http://84CFBA021A5A6662.xyz/g
unknown
clean
http://www.openssl.org/support/faq.html
unknown
clean
https://www.instagram.comsec-fetch-mode:
unknown
clean
https://www.instagram.com/accounts/login/ajax/facebook/
unknown
clean
https://login.microsoftonline.com/common/oauth2/authorize?client_id=9ea1ad79-fdb6-4f9a-8bc3-2b70f96e
unknown
clean
http://crl.thawte.com/ThawteTimestampingCA.crl0
unknown
clean
https://contextual.media.net/checksync.php?&vsSync=1&cs=1&hb=1&cv=37&ndec=1&cid=8HBI57XIG&prvid=77%2
unknown
clean
https://www.instagram.com/sec-fetch-site:
unknown
clean
https://twitter.comReferer:
unknown
clean
http://www.interestvideo.com/video1.php
unknown
clean
http://config.i.duba.net/lminstall/%d.json?time=%dcheckinstallSOFTWARE
unknown
clean
https://www.instagram.com/accept:
unknown
clean
http://84CFBA021A5A6662.xyz/info_old/w&
unknown
clean
http://84CFBA021A5A6662.xyz/info_old/w%
unknown
clean
https://www.messenger.com/login/nonce/
unknown
clean
http://www.youtube.com
unknown
clean
https://twitter.com/compose/tweetsec-fetch-dest:
unknown
clean
http://crl.pki.goog/GTSGIAG3.crl0
unknown
clean
https://adservice.google.co.uk/ddm/fls/i/src=2542116;type=chrom322;cat=chrom01g;ord=6856811916691;gt
unknown
clean
http://84cfba021a5a6662.xyz/gAn
unknown
clean
http://84cfba021a5a6662.xyz/info_old/wdl
unknown
clean
https://contextual.media.net/__media__/js/util/nrrV9140.js
unknown
clean
https://mem.gfx.ms/me/MeControl/10.19168.0/en-US/meCore.min.js
unknown
clean
http://images.outbrainimg.com/transform/v3/eyJpdSI6Ijk4OGQ1ZDgwMWE2ODQ2NDNkM2ZkMmYyMGEwOTgwMWQ3MDE2Z
unknown
clean
https://logincdn.msauth.net/16.000.28230.00/ConvergedLoginPaginatedStrings.en.js
unknown
clean
https://s.yimg.com/lo/api/res/1.2/BXjlWewXmZ47HeV5NPvUYA--~A/Zmk9ZmlsbDt3PTYyMjtoPTM2ODthcHBpZD1nZW1
unknown
clean
http://charlesproxy.com/ssl
unknown
clean
https://cvision.media.net/new/286x175/3/148/118/158/6d596081-b574-4a8a-9662-8f180c6f659f.jpg?v=9
unknown
clean
https://logincdn.msauth.net/16.000.28230.00/images/ellipsis_white.svg?x=5ac590ee72bfe06a7cecfd75b588
unknown
clean
http://84CFBA021A5A6662.xyz/
unknown
clean
http://84CFBA021A5A6662.xyz//fine/sendh/
unknown
clean
https://logincdn.msauth.net/16.000.28666.10/content/images/ellipsis_grey_2b5d393db04a5e6e1f739cb266e
unknown
clean
https://optanon.blob.core.windows.net/skins/4.1.0/default_flat_top_two_button_black/v2/css/optanon.c
unknown
clean
https://cvision.media.net/new/100x75/2/249/241/157/ab7b8862-dfb2-4e59-a214-ff623600dbf5.jpg?v=9
unknown
clean
https://cvision.media.net/new/300x300/2/41/100/83/b5cbfa68-1c93-41c9-8797-4f9b532bc0b6.jpg?v=9
unknown
clean
https://logincdn.msauth.net/16.000.28230.00/Converged_v21033.css
unknown
clean
https://optanon.blob.core.windows.net/skins/4.1.0/default_flat_top_two_button_black/v2/images/cookie
unknown
clean
https://www.msn.com/
unknown
clean
https://mem.gfx.ms/meversion?partner=RetailStore2&market=en-us&uhf=1
unknown
clean
http://84cfba021a5a6662.xyz/~
unknown
clean
http://www.youtube.com8
unknown
clean
http://84CFBA021A5A6662.xyz/ll
unknown
clean
https://172.217.23.78/
unknown
clean
https://cvision.media.net/new/100x75/3/148/118/158/6d596081-b574-4a8a-9662-8f180c6f659f.jpg?v=9
unknown
clean
https://mem.gfx.ms/me/MeControl/10.19168.0/en-US/meBoot.min.js
unknown
clean
http://images.outbrainimg.com/transform/v3/eyJpdSI6IjVhZWEwOTA0MmYxYzJjMDRlMmU1NDg1YzZmNjY2NTU5N2E5N
unknown
clean
https://aefd.nelreports.net/api/report?cat=bingrms
unknown
clean
http://service.real.com/realplayer/security/02062012_player/en/r
unknown
clean
http://images.outbrainimg.com/transform/v3/eyJpdSI6ImYxODk5OTBhOWZjYjFmZjNjNmMxNDhmYjkzM2M3NzY1Mzk3Z
unknown
clean
https://srtb.msn.com/auction?a=de-ch&b=28e3747a031f4b2a8498142b7c961529&c=MSN&d=http%3A%2F%2Fwww.msn
unknown
clean
https://googleads.g.doubleclick.net/adsid/google/ui?gadsid=AORoGNQP1yCl9r5iywZTFTjpazv-DURVxDidzMfrF
unknown
clean
https://googleads.g.doubleclick.net/adsid/google/ui?gadsid=AORoGNSrZsXAj6n_sYvivJecwrpYgMhb9ihVGAlz2
unknown
clean
https://policies.yahoo.com/w3c/p3p.xml
unknown
clean
https://www.googleapis.c
unknown
clean
http://images.outbrainimg.com/transform/v3/eyJpdSI6IjAxYWZjY2Q0NWJhMmI1MGJkMWJjMzhmMGFlZWM2MDJmMjc2O
unknown
clean
There are 126 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
84CFBA021A5A6662.xyz
104.21.23.16
clean
84cfba021a5a6662.xyz
104.21.23.16
clean

IPs

IP
Domain
Country
Active
Malicious
127.0.0.1
unknown
unknown
unknown
malicious
104.21.23.16
unknown
United States
unknown
clean
192.168.2.1
unknown
unknown
unknown
clean

Registry

Path
Value
Malicious
C:\Users\user\Desktop\FileSetup-v17.04.41.exe
Blob
malicious
C:\Windows\SysWOW64\msiexec.exe
GlobalAssocChangedCounter
clean
C:\Users\user\AppData\Local\Temp\6852B33702F6B3BD.exe
1
clean
C:\Users\user\AppData\Local\Temp\download\ThunderFW.exe
@C:\Windows\SysWOW64\FirewallControlPanel.dll,-12122
clean
C:\Users\user\AppData\Local\Temp\download\ThunderFW.exe
@C:\Windows\SysWOW64\FirewallControlPanel.dll,-12122
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
222D8200000
unkown
page readonly
clean
7FF583434000
unkown
page readonly
clean
28B0000
unkown
page readonly
clean
7FF5B735C000
unkown
page readonly
clean
2E55000
unkown
page read and write
clean
7FF5DA358000
unkown
page readonly
clean
7FF51B326000
unkown
page readonly
clean
15E63F43000
unkown
page read and write
clean
237A000
heap private
page read and write
clean
23A0000
unkown
page read and write
clean
7FF5B735A000
unkown
page readonly
clean
15E65200000
unkown
page readonly
clean
2373000
unkown
page read and write
clean
7FF524351000
unkown
page readonly
clean
7FF54A5B7000
unkown
page readonly
clean
7FF5563DC000
unkown
page readonly
clean
21CEB002000
unkown
page read and write
clean
3CBF000
unkown
page read and write
clean
220E000
unkown
page read and write
clean
572C87E000
unkown
page read and write
clean
7FF524865000
unkown
page readonly
clean
7FF5E0FAC000
unkown
page readonly
clean
15E63C51000
unkown
page read and write
clean
3CBF000
unkown
page read and write
clean
21846EFF000
unkown
page read and write
clean
A5437E000
unkown
page read and write
clean
2750000
unkown
page read and write
clean
17C000
stack
page read and write
clean
7FF51B3B4000
unkown
page readonly
clean
7FF539347000
unkown
page readonly
clean
15E63CCE000
unkown
page read and write
clean
143D6300000
unkown
page readonly
clean
7FF524B47000
unkown
page readonly
clean
3CB9000
unkown
page read and write
clean
7FF539491000
unkown
page readonly
clean
A546FD000
unkown
page read and write
clean
127AC702000
unkown
page read and write
clean
2395000
unkown
page readonly
clean
2DFC3C51000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
50A000
unkown image
page read and write
clean
21CEB032000
unkown
page read and write
clean
7FF54A93A000
unkown
page readonly
clean
143D64C2000
unkown
page read and write
clean
127ACE02000
unkown
page read and write
clean
1D356FD0000
heap private
page read and write
clean
21846E29000
unkown
page read and write
clean
BFF000
unkown image
page read and write
clean
10000000
unkown
page read and write
clean
3A9000
unkown
page read and write
clean
C01000
unkown image
page readonly
clean
15E64210000
unkown
page read and write
clean
7FF5DA49C000
unkown
page readonly
clean
127AC602000
unkown
page read and write
clean
2184C260000
unkown
page read and write
clean
7FF52D327000
unkown
page readonly
clean
7FF4FFE66000
unkown
page readonly
clean
21CEB057000
unkown
page read and write
clean
3CE5000
unkown
page read and write
clean
338167C000
unkown
page read and write
clean
7FF4EF1D5000
unkown
page readonly
clean
21846E5A000
unkown
page read and write
clean
775000
unkown
page read and write
clean
2184C6A0000
unkown
page read and write
clean
7FF5E0C01000
unkown
page readonly
clean
21CEB05A000
unkown
page read and write
clean
222D8013000
unkown
page read and write
clean
2DFC3D08000
unkown
page read and write
clean
4C6000
unkown image
page readonly
clean
7FF5E1036000
unkown
page readonly
clean
7FF52D2ED000
unkown
page readonly
clean
2E28000
heap default
page read and write
clean
21CEB069000
unkown
page read and write
clean
7FF58341C000
unkown
page readonly
clean
3DDE000
unkown
page read and write
clean
BF1000
unkown image
page execute read
clean
21CEB06A000
unkown
page read and write
clean
27C1000
unkown
page read and write
clean
7FF54ADC6000
unkown
page readonly
clean
830000
unkown
page read and write
clean
1DF6B1D0000
heap default
page read and write
clean
7FF4EEDA8000
unkown
page readonly
clean
2EA8000
unkown
page read and write
clean
2184C232000
unkown
page read and write
clean
FDC467F000
unkown
page read and write
clean
2ED0000
unkown
page read and write
clean
7FF54ACBC000
unkown
page readonly
clean
21846F02000
unkown
page read and write
clean
246E000
stack
page read and write
clean
770000
unkown
page read and write
clean
2CD5000
heap default
page read and write
clean
2EE9000
unkown
page read and write
clean
7FF4FFD03000
unkown
page readonly
clean
15E61C9F000
unkown
page read and write
clean
2F06000
unkown
page read and write
clean
2EBA000
unkown
page read and write
clean
2DF0000
heap private
page read and write
clean
3E00000
unkown
page read and write
clean
1D357253000
unkown
page read and write
clean
7FF524B2C000
unkown
page readonly
clean
2184C580000
unkown
page read and write
clean
293B000
unkown
page read and write
clean
F18559E000
unkown
page read and write
clean
CD8C2FE000
unkown
page read and write
clean
2CC3000
heap default
page read and write
clean
2DFC3C90000
unkown
page read and write
clean
6C0000
unkown
page readonly
clean
15E61CA8000
unkown
page read and write
clean
81E000
unkown
page read and write
clean
2816000
unkown
page readonly
clean
2180000
unkown
page readonly
clean
7FF5393A6000
unkown
page readonly
clean
E632DEB000
unkown
page read and write
clean
2220000
heap private
page read and write
clean
2233000
heap private
page read and write
clean
7FF539344000
unkown
page readonly
clean
15E63CC9000
unkown
page read and write
clean
2D12B700000
unkown
page read and write
clean
7FF4FFE3F000
unkown
page readonly
clean
7FF5E0C98000
unkown
page readonly
clean
2DFC3AE0000
unkown
page readonly
clean
7FF556402000
unkown
page readonly
clean
7FF53934A000
unkown
page readonly
clean
30BF5FA000
unkown
page read and write
clean
3DED000
unkown
page read and write
clean
C643CFA000
unkown
page read and write
clean
3DD7000
unkown
page read and write
clean
4F0000
unkown
page read and write
clean
2E97000
unkown
page read and write
clean
7FF4EF4C8000
unkown
page readonly
clean
21846CF0000
unkown
page readonly
clean
33810FC000
unkown
page read and write
clean
2D129730000
unkown
page write copy
clean
A3E000
unkown
page read and write
clean
15E63D02000
unkown
page read and write
clean
7FF5E0D77000
unkown
page readonly
clean
A6B000
unkown
page read and write
clean
7FF5561A7000
unkown
page readonly
clean
7FF4EF5AE000
unkown
page readonly
clean
15E61C9E000
unkown
page read and write
clean
335000
unkown
page read and write
clean
222D7ED0000
heap private
page read and write
clean
21846F16000
unkown
page read and write
clean
B1B000
heap private
page read and write
clean
2865000
unkown
page readonly
clean
7FF54AD52000
unkown
page readonly
clean
21847718000
unkown
page read and write
clean
7FF524AA0000
unkown
page readonly
clean
31F0000
heap private
page read and write
clean
504000
unkown
page read and write
clean
497000
unkown image
page execute and write copy
clean
2340000
unkown
page read and write
clean
1F05FAD0000
heap private
page read and write
clean
2227000
unkown
page read and write
clean
2184C6E0000
unkown
page readonly
clean
21E1000
unkown
page read and write
clean
2340000
unkown
page readonly
clean
7FF4EEFB9000
unkown
page readonly
clean
2F06000
unkown
page read and write
clean
2EDA000
unkown
page read and write
clean
222D8002000
unkown
page read and write
clean
3E46000
unkown
page read and write
clean
7FF54AD58000
unkown
page readonly
clean
2D12B850000
unkown
page readonly
clean
7FF5E0CDF000
unkown
page readonly
clean
7FF5562C9000
unkown
page readonly
clean
7FF5833FD000
unkown
page readonly
clean
1DF6B520000
unkown
page readonly
clean
8B1000
heap default
page read and write
clean
7FF5DA206000
unkown
page readonly
clean
2230000
heap private
page read and write
clean
50B000
unkown image
page write copy
clean
232D000
unkown
page readonly
clean
3E04000
unkown
page read and write
clean
7FF52D306000
unkown
page readonly
clean
21847700000
unkown
page read and write
clean
CD8C27E000
unkown
page read and write
clean
2E65000
unkown
page read and write
clean
2E55000
unkown
page read and write
clean
30BF9F9000
unkown
page read and write
clean
2C8A000
heap default
page read and write
clean
288000
unkown
page read and write
clean
2930000
heap private
page read and write
clean
1F05FB50000
unkown
page readonly
clean
7FF5DA52C000
unkown
page readonly
clean
7FF53948E000
unkown
page readonly
clean
2D12B718000
unkown
page read and write
clean
2E7C000
unkown
page read and write
clean
15E63C53000
unkown
page read and write
clean
7FF539351000
unkown
page readonly
clean
7FF52D280000
unkown
page readonly
clean
7FF53914E000
unkown
page readonly
clean
2F06000
unkown
page read and write
clean
3D65000
unkown
page read and write
clean
1F05FC00000
unkown
page read and write
clean
27D4000
unkown
page read and write
clean
3D8E000
unkown
page read and write
clean
7FF5246DD000
unkown
page readonly
clean
222D000
unkown
page read and write
clean
7FF5B70E4000
unkown
page readonly
clean
2D12B820000
unkown
page read and write
clean
7FF539388000
unkown
page readonly
clean
2184C20D000
unkown
page read and write
clean
7FF4EEDF9000
unkown
page readonly
clean
7FF524A15000
unkown
page readonly
clean
10000000
unkown
page read and write
clean
7FF54ADE7000
unkown
page readonly
clean
23EB000
unkown
page readonly
clean
2DFC3E00000
unkown
page readonly
clean
7FF52D324000
unkown
page readonly
clean
3D14000
unkown
page read and write
clean
2650000
unkown
page readonly
clean
21848193000
unkown
page read and write
clean
7FF51B396000
unkown
page readonly
clean
50B000
unkown image
page write copy
clean
2344000
unkown
page readonly
clean
7FF5B7427000
unkown
page readonly
clean
2184C224000
unkown
page read and write
clean
7FF5833E9000
unkown
page readonly
clean
7FF4EEFAE000
unkown
page readonly
clean
7FF54AE41000
unkown
page readonly
clean
3DEC000
unkown
page read and write
clean
7FF5E1046000
unkown
page readonly
clean
2D12B810000
unkown
page readonly
clean
2DFC3C13000
unkown
page read and write
clean
9F0000
unkown
page readonly
clean
7FF5393E9000
unkown
page readonly
clean
15E63CDA000
unkown
page read and write
clean
3B2000
unkown
page read and write
clean
7FF5E102D000
unkown
page readonly
clean
781000
unkown
page read and write
clean
2DFC3C3C000
unkown
page read and write
clean
127AC629000
unkown
page read and write
clean
15E63F43000
unkown
page read and write
clean
3E07000
unkown
page read and write
clean
2DFC3A10000
unkown
page readonly
clean
505000
unkown image
page write copy
clean
30BF97D000
unkown
page read and write
clean
7FF524910000
unkown
page readonly
clean
7FF539107000
unkown
page readonly
clean
2D9E000
unkown
page read and write
clean
15E63AA0000
unkown
page readonly
clean
3E1A000
unkown
page read and write
clean
7FF4FFC1A000
unkown
page readonly
clean
7FF539392000
unkown
page readonly
clean
30BF0FB000
unkown
page read and write
clean
15E61CFD000
unkown
page read and write
clean
15E61D1C000
unkown
page read and write
clean
830000
unkown
page read and write
clean
7FF51B328000
unkown
page readonly
clean
A6B000
unkown
page read and write
clean
15E61C00000
unkown
page read and write
clean
293E000
unkown
page read and write
clean
2352000
unkown
page readonly
clean
3A8D000
stack
page read and write
clean
7FF5391EA000
unkown
page readonly
clean
21847704000
unkown
page read and write
clean
7FF52D2AA000
unkown
page readonly
clean
E4C2B7A000
unkown
page read and write
clean
2B80000
heap default
page read and write
clean
2648000
unkown
page readonly
clean
27DB000
unkown
page read and write
clean
7FF524A98000
unkown
page readonly
clean
7FF4EF4EE000
unkown
page readonly
clean
21846E93000
unkown
page read and write
clean
264E000
unkown
page readonly
clean
7FF524870000
unkown
page readonly
clean
F185A7F000
unkown
page read and write
clean
7FF4EF170000
unkown
page readonly
clean
2657000
unkown
page readonly
clean
7FF55647C000
unkown
page readonly
clean
7FF5E0E2E000
unkown
page readonly
clean
7FF583155000
unkown
page readonly
clean
7FF5831EA000
unkown
page readonly
clean
2B14000
unkown
page read and write
clean
3CBF000
unkown
page read and write
clean
1D357802000
unkown
page read and write
clean
572CBFE000
unkown
page read and write
clean
2E52000
heap default
page read and write
clean
2336000
unkown
page readonly
clean
DCA000
heap default
page read and write
clean
7FF4FFE97000
unkown
page readonly
clean
82B000
heap default
page read and write
clean
10337000
unkown
page readonly
clean
21847000000
unkown
page readonly
clean
2660000
unkown
page readonly
clean
21CEB200000
unkown
page readonly
clean
26C3000
unkown
page readonly
clean
7FF524A5A000
unkown
page readonly
clean
2D1297D0000
unkown
page readonly
clean
63E000
unkown
page read and write
clean
7FF55642E000
unkown
page readonly
clean
3E1B000
unkown
page read and write
clean
2E3D000
unkown
page read and write
clean
26C0000
unkown
page read and write
clean
2E54000
unkown
page read and write
clean
15E63C45000
unkown
page read and write
clean
3E5A000
unkown
page read and write
clean
7FF555D3E000
unkown
page readonly
clean
1DF6B302000
unkown
page read and write
clean
2EC9000
unkown
page read and write
clean
A542FC000
unkown
page read and write
clean
7FF524ACA000
unkown
page readonly
clean
2298F25E000
heap default
page read and write
clean
7FF52D37E000
unkown
page readonly
clean
7FF52CAF7000
unkown
page readonly
clean
10338000
unkown
page read and write
clean
30BF579000
unkown
page read and write
clean
7FF5DA536000
unkown
page readonly
clean
7FF51B419000
unkown
page readonly
clean
2E5C000
unkown
page read and write
clean
2D1298D3000
unkown
page read and write
clean
7FF539416000
unkown
page readonly
clean
15E61C40000
unkown
page read and write
clean
2822000
unkown
page readonly
clean
7FF51B38C000
unkown
page readonly
clean
283B000
unkown
page read and write
clean
21848171000
unkown
page read and write
clean
21CEB046000
unkown
page read and write
clean
1AC83013000
unkown
page read and write
clean
1AC832D0000
unkown
page readonly
clean
7FF51B37D000
unkown
page readonly
clean
2D1298F4000
unkown
page read and write
clean
2184C200000
unkown
page read and write
clean
338157B000
unkown
page read and write
clean
8DE000
unkown
page read and write
clean
3DD0000
unkown
page read and write
clean
7FF5E0FFE000
unkown
page readonly
clean
3380C9B000
unkown
page read and write
clean
BFF000
unkown image
page write copy
clean
4CB0000
heap private
page read and write
clean
222D9B70000
unkown
page readonly
clean
127ACB90000
unkown
page readonly
clean
7FF4FFE6C000
unkown
page readonly
clean
7FF4EF509000
unkown
page readonly
clean
7FF5DA509000
unkown
page readonly
clean
2D58000
unkown
page read and write
clean
A60000
unkown
page readonly
clean
21CEB03B000
unkown
page read and write
clean
401000
unkown image
page execute read
clean
7FF5E10C9000
unkown
page readonly
clean
3A5000
unkown
page read and write
clean
7FF5E0944000
unkown
page readonly
clean
7FF4EF5B1000
unkown
page readonly
clean
21CEAED0000
heap private
page read and write
clean
7FF5563CA000
unkown
page readonly
clean
2DFC3C8C000
unkown
page read and write
clean
7FF5561AE000
unkown
page readonly
clean
222D8029000
unkown
page read and write
clean
6D0000
unkown
page readonly
clean
127AC800000
unkown
page readonly
clean
7FF5E0D7E000
unkown
page readonly
clean
7FF5DA4B2000
unkown
page readonly
clean
2E9D000
unkown
page read and write
clean
2C0D000
unkown
page read and write
clean
50B000
unkown image
page write copy
clean
21CEB000000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
7FF4EEF2C000
unkown
page readonly
clean
7FF4FFCCA000
unkown
page readonly
clean
1DF6B202000
unkown
page read and write
clean
21E0000
unkown
page read and write
clean
7FF52D0AA000
unkown
page readonly
clean
2360000
unkown
page readonly
clean
7FF4EE77D000
unkown
page readonly
clean
9C000
unkown
page read and write
clean
7FF4FFDF2000
unkown
page readonly
clean
2F02000
unkown
page read and write
clean
4C80000
unkown
page read and write
clean
7FF5390F4000
unkown
page readonly
clean
572CCFF000
unkown
page read and write
clean
3D4F000
unkown
page read and write
clean
7FF54ADE0000
unkown
page readonly
clean
30BF67B000
unkown
page read and write
clean
127ACCA0000
unkown
page read and write
clean
21846F02000
unkown
page read and write
clean
15E61C13000
unkown
page read and write
clean
15E63CC7000
unkown
page read and write
clean
3DFE000
unkown
page read and write
clean
15E61CEE000
unkown
page read and write
clean
2184C560000
unkown
page read and write
clean
7FF5E103C000
unkown
page readonly
clean
4C6000
unkown image
page readonly
clean
7FF5DA4A8000
unkown
page readonly
clean
15E61D1D000
unkown
page read and write
clean
7FF52D2C5000
unkown
page readonly
clean
15E64110000
unkown
page read and write
clean
7FF4FFC7F000
unkown
page readonly
clean
7FF4FFEEE000
unkown
page readonly
clean
7FF54AD99000
unkown
page readonly
clean
283B000
unkown
page read and write
clean
19E000
stack
page read and write
clean
127ACCA0000
unkown
page read and write
clean
3CBA000
unkown
page read and write
clean
7FF5DA11E000
unkown
page readonly
clean
A56000
unkown
page read and write
clean
B16000
heap private
page read and write
clean
3E1A000
unkown
page read and write
clean
1AC83113000
unkown
page read and write
clean
27FB000
unkown
page read and write
clean
3CC1000
unkown
page read and write
clean
7FF5E0F81000
unkown
page readonly
clean
222D8102000
unkown
page read and write
clean
3CBF000
unkown
page read and write
clean
7FF51B35F000
unkown
page readonly
clean
7FF5564F9000
unkown
page readonly
clean
28D0000
unkown
page readonly
clean
15E63AB0000
unkown
page read and write
clean
7FF5E0FB8000
unkown
page readonly
clean
331000
unkown
page read and write
clean
22F1000
unkown
page readonly
clean
1D35723C000
unkown
page read and write
clean
495000
unkown image
page execute and read and write
clean
2D1298EF000
unkown
page read and write
clean
143D63E0000
unkown
page read and write
clean
1D357040000
unkown
page readonly
clean
2298F250000
heap default
page read and write
clean
2184C584000
unkown
page read and write
clean
1AC8303D000
unkown
page read and write
clean
15E61D6E000
unkown
page read and write
clean
7FF539377000
unkown
page readonly
clean
7FF524A87000
unkown
page readonly
clean
530000
unkown
page readonly
clean
15E64010000
unkown
page read and write
clean
7FF5B7424000
unkown
page readonly
clean
7FF4EF33F000
unkown
page readonly
clean
7FF4FFEF9000
unkown
page readonly
clean
2301000
unkown
page readonly
clean
7FF5B739A000
unkown
page readonly
clean
3CC5000
unkown
page read and write
clean
3290000
unkown
page read and write
clean
7FF556466000
unkown
page readonly
clean
E63347A000
unkown
page read and write
clean
B1B000
heap private
page read and write
clean
7FF5E0FA3000
unkown
page readonly
clean
27DB000
unkown
page read and write
clean
7FF524817000
unkown
page readonly
clean
A52000
unkown
page read and write
clean
2184C7C0000
unkown
page read and write
clean
7FF4EF52C000
unkown
page readonly
clean
7FF5DA31E000
unkown
page readonly
clean
2185000
unkown
page readonly
clean
7FF5B7420000
unkown
page readonly
clean
1AC82F50000
unkown
page readonly
clean
2253000
unkown
page read and write
clean
21846EAA000
unkown
page read and write
clean
6FA000
heap default
page read and write
clean
7FF5B7489000
unkown
page readonly
clean
1F05FC02000
unkown
page read and write
clean
A3E000
unkown
page read and write
clean
1D357288000
unkown
page read and write
clean
7FF4EF47B000
unkown
page readonly
clean
323F000
stack
page read and write
clean
2184C610000
unkown
page read and write
clean
FDC46FE000
unkown
page read and write
clean
7FF5DA33F000
unkown
page readonly
clean
7FF55643F000
unkown
page readonly
clean
1D357030000
heap default
page read and write
clean
7FF5392A3000
unkown
page readonly
clean
7FF5E0C57000
unkown
page readonly
clean
CD8C4FC000
unkown
page read and write
clean
2705000
unkown
page readonly
clean
7FF52D1C7000
unkown
page readonly
clean
2D129913000
unkown
page read and write
clean
7FF524B26000
unkown
page readonly
clean
A39000
unkown
page read and write
clean
2DFC3C49000
unkown
page read and write
clean
7FF5B7481000
unkown
page readonly
clean
7FF51B3B7000
unkown
page readonly
clean
7FF55625E000
unkown
page readonly
clean
73C000
heap default
page read and write
clean
10001000
unkown
page execute read
clean
7FF5DA4C8000
unkown
page readonly
clean
2184C660000
unkown
page read and write
clean
7FF539499000
unkown
page readonly
clean
2E66000
unkown
page read and write
clean
2D129882000
unkown
page read and write
clean
3D14000
unkown
page read and write
clean
7FF5393BA000
unkown
page readonly
clean
2ECB000
unkown
page read and write
clean
7FF51B3A5000
unkown
page readonly
clean
15E65102000
unkown
page read and write
clean
7FF5E0C40000
unkown
page readonly
clean
7FF52D30C000
unkown
page readonly
clean
2D129A00000
unkown
page readonly
clean
3D4D000
unkown
page read and write
clean
7460000
unkown
page read and write
clean
222D000
unkown
page readonly
clean
2470000
unkown
page read and write
clean
A30000
unkown
page read and write
clean
143D61B0000
heap private
page read and write
clean
2E6A000
unkown
page read and write
clean
61FB57A000
unkown
page read and write
clean
3D4D000
unkown
page read and write
clean
7FF52D14E000
unkown
page readonly
clean
30BFA7F000
unkown
page read and write
clean
7FF4EF53C000
unkown
page readonly
clean
232A000
unkown
page readonly
clean
7FF5E0FA7000
unkown
page readonly
clean
15E63A30000
unkown
page readonly
clean
3DFD000
unkown
page read and write
clean
1DF6CCC0000
unkown
page read and write
clean
7FF5E0FD8000
unkown
page readonly
clean
19E000
stack
page read and write
clean
7FF54ADCC000
unkown
page readonly
clean
764000
unkown
page read and write
clean
1D357400000
unkown
page readonly
clean
21CEB02F000
unkown
page read and write
clean
401000
unkown image
page execute and write copy
clean
A5457D000
unkown
page read and write
clean
61FB11C000
unkown
page read and write
clean
2E53000
unkown
page read and write
clean
2E72000
unkown
page read and write
clean
A5407B000
unkown
page read and write
clean
7FF52D296000
unkown
page readonly
clean
27D4000
unkown
page read and write
clean
15E64410000
unkown
page read and write
clean
3CAD000
unkown
page read and write
clean
21CEB049000
unkown
page read and write
clean
21848190000
unkown
page read and write
clean
7FF5B73CF000
unkown
page readonly
clean
7FF54A940000
unkown
page readonly
clean
AA7000
unkown
page read and write
clean
7FF5561C0000
unkown
page readonly
clean
A3E000
unkown
page read and write
clean
7FF524A1C000
unkown
page readonly
clean
3200000
unkown
page readonly
clean
28BB000
unkown
page readonly
clean
3E07000
unkown
page read and write
clean
690000
unkown
page readonly
clean
E4C2C7B000
unkown
page read and write
clean
7FF5B73C5000
unkown
page readonly
clean
2E7B000
unkown
page read and write
clean
2D5E000
unkown
page read and write
clean
E4C28FF000
unkown
page read and write
clean
34D0000
unkown
page read and write
clean
3DE8000
unkown
page read and write
clean
2184C650000
unkown
page read and write
clean
143D6513000
unkown
page read and write
clean
2931000
unkown
page read and write
clean
A3F000
stack
page read and write
clean
2E80000
unkown
page read and write
clean
143D6469000
unkown
page read and write
clean
3EFF000
stack
page read and write
clean
7FF556408000
unkown
page readonly
clean
7FF5E0CD6000
unkown
page readonly
clean
3CB2000
unkown
page read and write
clean
31F9000
heap private
page read and write
clean
15E61C9C000
unkown
page read and write
clean
338177E000
unkown
page read and write
clean
2D129840000
unkown
page read and write
clean
7FF539425000
unkown
page readonly
clean
7FF54ADBC000
unkown
page readonly
clean
7FF5B7337000
unkown
page readonly
clean
15E63F43000
unkown
page read and write
clean
7FF52490E000
unkown
page readonly
clean
1D357213000
unkown
page read and write
clean
143D6489000
unkown
page read and write
clean
15E63AB0000
unkown
page read and write
clean
222D9A70000
unkown
page read and write
clean
2184C690000
unkown
page read and write
clean
2184C6A0000
unkown
page read and write
clean
BF0000
unkown image
page readonly
clean
2DFC3C4F000
unkown
page read and write
clean
401000
unkown image
page execute and write copy
clean
412000
unkown image
page read and write
clean
2E72000
unkown
page read and write
clean
4890000
unkown
page readonly
clean
2830000
unkown
page readonly
clean
2BF0000
unkown
page readonly
clean
7FF5B7406000
unkown
page readonly
clean
21CEB013000
unkown
page read and write
clean
2D12B78A000
unkown
page read and write
clean
81C000
heap default
page read and write
clean
27CC000
unkown
page read and write
clean
1AC83029000
unkown
page read and write
clean
7FF51B13A000
unkown
page readonly
clean
1F05FE00000
unkown
page readonly
clean
2E74000
unkown
page read and write
clean
7FF524AEF000
unkown
page readonly
clean
7FF4EF184000
unkown
page readonly
clean
2DFC4740000
unkown
page readonly
clean
7FF5393D5000
unkown
page readonly
clean
2E4F000
unkown
page read and write
clean
7FF5833D5000
unkown
page readonly
clean
7FF524B11000
unkown
page readonly
clean
27C1000
unkown
page read and write
clean
C91898E000
unkown
page read and write
clean
5930000
unkown
page read and write
clean
1DF6B256000
unkown
page read and write
clean
286A000
unkown
page readonly
clean
15E64310000
unkown
page read and write
clean
15E63AB0000
unkown
page readonly
clean
7FF539406000
unkown
page readonly
clean
15E61CD5000
unkown
page read and write
clean
222D804B000
unkown
page read and write
clean
7FF5832A3000
unkown
page readonly
clean
3D27000
unkown
page read and write
clean
8EF000
stack
page read and write
clean
222D7F30000
heap default
page read and write
clean
1AC83000000
unkown
page read and write
clean
226D000
unkown
page read and write
clean
2223000
unkown
page read and write
clean
2184C1A0000
unkown
page read and write
clean
3CBF000
unkown
page read and write
clean
2E79000
unkown
page read and write
clean
3DD2000
unkown
page read and write
clean
21F3000
unkown
page read and write
clean
3CE5000
unkown
page read and write
clean
504000
unkown
page read and write
clean
27C9000
unkown
page read and write
clean
7FF4FFA00000
unkown
page readonly
clean
7A5D000
stack
page read and write
clean
7FF51B3B0000
unkown
page readonly
clean
B5CA9F5000
unkown
page read and write
clean
1F05FD13000
unkown
page read and write
clean
3CBD000
unkown
page read and write
clean
222D7F40000
unkown
page write copy
clean
7FF5DA4BD000
unkown
page readonly
clean
2D48000
heap private
page read and write
clean
1F05FB60000
unkown
page read and write
clean
7FF538FA3000
unkown
page readonly
clean
2855000
unkown
page readonly
clean
7FF51B419000
unkown
page readonly
clean
2DFC3BC0000
unkown
page readonly
clean
7FF5DA3D0000
unkown
page readonly
clean
2D12B789000
unkown
page read and write
clean
7FF556449000
unkown
page readonly
clean
4CB4000
heap private
page read and write
clean
30BF379000
unkown
page read and write
clean
7FF52D381000
unkown
page readonly
clean
2F40000
unkown
page readonly
clean
77B000
unkown
page read and write
clean
7FF52D15A000
unkown
page readonly
clean
2E50000
unkown
page read and write
clean
27FD000
unkown
page readonly
clean
420000
unkown
page readonly
clean
400000
unkown image
page readonly
clean
7FF524BA9000
unkown
page readonly
clean
15E61D02000
unkown
page read and write
clean
127ACCA0000
unkown
page read and write
clean
7C0000
heap default
page read and write
clean
7FF5E0F8B000
unkown
page readonly
clean
7FF5B6C2D000
unkown
page readonly
clean
848000
heap default
page read and write
clean
28D8000
unkown
page readonly
clean
2E7A000
unkown
page read and write
clean
15E61D2C000
unkown
page read and write
clean
15E63C41000
unkown
page read and write
clean
7FF539437000
unkown
page readonly
clean
3DEC000
unkown
page read and write
clean
26B2000
unkown
page readonly
clean
1AC83075000
unkown
page read and write
clean
30BF17E000
unkown
page read and write
clean
7FF556298000
unkown
page readonly
clean
15E61AE0000
heap default
page read and write
clean
2C4D000
stack
page read and write
clean
7FF5560C8000
unkown
page readonly
clean
2184C430000
unkown
page read and write
clean
865000
heap default
page read and write
clean
2850000
unkown
page readonly
clean
7FF5B747E000
unkown
page readonly
clean
2D129660000
unkown
page readonly
clean
127AC4B0000
heap private
page read and write
clean
30BF2FB000
unkown
page read and write
clean
7FF5DA521000
unkown
page readonly
clean
BF0000
unkown image
page readonly
clean
7FF5E0FEA000
unkown
page readonly
clean
2184C20E000
unkown
page read and write
clean
7FF524804000
unkown
page readonly
clean
2E67000
unkown
page read and write
clean
7FF5E1067000
unkown
page readonly
clean
15E61C29000
unkown
page read and write
clean
2235000
heap private
page read and write
clean
15E65142000
unkown
page read and write
clean
830000
unkown
page read and write
clean
26E9000
unkown
page readonly
clean
3D27000
unkown
page read and write
clean
7FF524A83000
unkown
page readonly
clean
1D35724C000
unkown
page read and write
clean
7FF4FFE85000
unkown
page readonly
clean
B20000
unkown
page readonly
clean
D0F000
stack
page read and write
clean
7FF4EEEF5000
unkown
page readonly
clean
143D6600000
unkown
page readonly
clean
7FF54AD7E000
unkown
page readonly
clean
143D643E000
unkown
page read and write
clean
7FF5DA437000
unkown
page readonly
clean
2DFC3D13000
unkown
page read and write
clean
15E64310000
unkown
page read and write
clean
21847718000
unkown
page read and write
clean
2340000
unkown
page read and write
clean
3DEC000
unkown
page read and write
clean
33813FC000
unkown
page read and write
clean
15E61A80000
heap private
page read and write
clean
F185B7C000
unkown
page read and write
clean
21CEB802000
unkown
page read and write
clean
3CA1000
unkown
page read and write
clean
7FF5B71DA000
unkown
page readonly
clean
3CC0000
unkown
page read and write
clean
7FF54AC5D000
unkown
page readonly
clean
7FF5246B3000
unkown
page readonly
clean
500000
heap default
page read and write
clean
2184C610000
unkown
page read and write
clean
7FF583406000
unkown
page readonly
clean
73E000
unkown
page read and write
clean
15E61C9B000
unkown
page read and write
clean
B10000
heap private
page read and write
clean
7FF5DA557000
unkown
page readonly
clean
338187D000
unkown
page read and write
clean
28B000
unkown
page read and write
clean
21846E93000
unkown
page read and write
clean
7FF5B7278000
unkown
page readonly
clean
27C000
unkown
page read and write
clean
2360000
unkown
page read and write
clean
2F65000
heap default
page read and write
clean
2E4F000
unkown
page read and write
clean
3CE5000
unkown
page read and write
clean
21CEB042000
unkown
page read and write
clean
15E61C80000
unkown
page read and write
clean
B5CA5AB000
unkown
page read and write
clean
2ED3000
unkown
page read and write
clean
21CEB060000
unkown
page read and write
clean
7FF4FFCE8000
unkown
page readonly
clean
23E0000
unkown
page readonly
clean
2E7C000
unkown
page read and write
clean
7FF52CE80000
unkown
page readonly
clean
40F000
unkown image
page readonly
clean
2B4E000
unkown
page read and write
clean
15E63F83000
unkown
page read and write
clean
776000
unkown
page read and write
clean
E6331F9000
unkown
page read and write
clean
2D1297E0000
heap private
page read and write
clean
7FF4EEF36000
unkown
page readonly
clean
7FF52D315000
unkown
page readonly
clean
7FF54ADD5000
unkown
page readonly
clean
2184C2B4000
unkown
page read and write
clean
7FF4FFEF1000
unkown
page readonly
clean
3CA7000
unkown
page read and write
clean
9D000
unkown
page read and write
clean
C643DFF000
unkown
page read and write
clean
7FF54AC81000
unkown
page readonly
clean
7FF524998000
unkown
page readonly
clean
746000
heap default
page read and write
clean
3FD1000
unkown
page read and write
clean
7FF5563F0000
unkown
page readonly
clean
15E63E53000
unkown
page read and write
clean
10001000
unkown
page execute read
clean
7FF54ABCF000
unkown
page readonly
clean
2D12B860000
unkown
page readonly
clean
781000
unkown
page read and write
clean
7FF5249B7000
unkown
page readonly
clean
28C4000
unkown
page readonly
clean
7FF4EF177000
unkown
page readonly
clean
7FF4EF5B9000
unkown
page readonly
clean
7FF5391FE000
unkown
page readonly
clean
2DFC3D02000
unkown
page read and write
clean
2E79000
unkown
page read and write
clean
36AC000
unkown
page read and write
clean
15E63C0B000
unkown
page read and write
clean
2E6E000
unkown
page read and write
clean
7FF5DA550000
unkown
page readonly
clean
7FF5E0E88000
unkown
page readonly
clean
1F05FC3C000
unkown
page read and write
clean
15E64410000
unkown
page read and write
clean
7FF4FFE35000
unkown
page readonly
clean
2F06000
unkown
page read and write
clean
7FF5B70F7000
unkown
page readonly
clean
C918D75000
unkown
page read and write
clean
7FF58348E000
unkown
page readonly
clean
1AC83102000
unkown
page read and write
clean
572C8FE000
unkown
page read and write
clean
21CEB07A000
unkown
page read and write
clean
2EA9000
unkown
page read and write
clean
3CBF000
unkown
page read and write
clean
4C6000
unkown image
page readonly
clean
2780000
unkown
page write copy
clean
15E61C7D000
unkown
page read and write
clean
7FF556476000
unkown
page readonly
clean
64E000
unkown
page read and write
clean
2E6F000
unkown
page read and write
clean
7FF4EF4B0000
unkown
page readonly
clean
7FF54A950000
unkown
page readonly
clean
89D000
heap default
page read and write
clean
4D90000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
2184C213000
unkown
page read and write
clean
2350000
heap private
page read and write
clean
2187000
unkown
page readonly
clean
2D1298BF000
unkown
page read and write
clean
495000
unkown image
page execute and read and write
clean
7FF5393A8000
unkown
page readonly
clean
3CBA000
unkown
page read and write
clean
3D4E000
unkown
page read and write
clean
2A80000
heap private
page read and write
clean
7FF5DA192000
unkown
page readonly
clean
7FF5E1005000
unkown
page readonly
clean
15E63CC7000
unkown
page read and write
clean
7FF5B733A000
unkown
page readonly
clean
10BE000
stack
page read and write
clean
143D6B14000
unkown
page read and write
clean
3CA1000
unkown
page read and write
clean
504000
unkown
page read and write
clean
7FF524857000
unkown
page readonly
clean
7FF524B37000
unkown
page readonly
clean
2D129902000
unkown
page read and write
clean
2D1295F0000
heap private
page read and write
clean
2D4C000
unkown
page read and write
clean
2DFC3C7F000
unkown
page read and write
clean
3E46000
unkown
page read and write
clean
127AC624000
unkown
page read and write
clean
497000
unkown image
page execute and write copy
clean
15E61C83000
unkown
page read and write
clean
15E61CC4000
unkown
page read and write
clean
3CC6000
unkown
page read and write
clean
28E000
unkown
page read and write
clean
15E63C50000
unkown
page read and write
clean
1D3571F0000
unkown
page readonly
clean
E63357B000
unkown
page read and write
clean
2E4C000
unkown
page read and write
clean
10332000
unkown
page read and write
clean
4FFD000
stack
page read and write
clean
3CBF000
unkown
page read and write
clean
2DFC3D00000
unkown
page read and write
clean
DC0000
heap default
page read and write
clean
7FF5833CE000
unkown
page readonly
clean
3DFC000
unkown
page read and write
clean
7FF556490000
unkown
page readonly
clean
7FF4FFE7C000
unkown
page readonly
clean
3E06000
unkown
page read and write
clean
21CEB061000
unkown
page read and write
clean
2D12B820000
unkown
page read and write
clean
2E49000
unkown
page read and write
clean
1DF6B22A000
unkown
page read and write
clean
3DD7000
unkown
page read and write
clean
804000
heap default
page read and write
clean
2223000
unkown
page read and write
clean
3950000
unkown
page readonly
clean
15E63F83000
unkown
page read and write
clean
28B2000
unkown
page read and write
clean
7FF53936C000
unkown
page readonly
clean
1F060600000
unkown
page readonly
clean
7FF5B7396000
unkown
page readonly
clean
3CBF000
unkown
page read and write
clean
7FF5E10BE000
unkown
page readonly
clean
10000000
unkown image
page readonly
clean
7FF5E1060000
unkown
page readonly
clean
21CEB2D0000
unkown
page readonly
clean
3E01000
unkown
page read and write
clean
F18549C000
unkown
page read and write
clean
1D357302000
unkown
page read and write
clean
3B8000
unkown
page read and write
clean
7FF54AD85000
unkown
page readonly
clean
7FF52D1FC000
unkown
page readonly
clean
15E65082000
unkown
page read and write
clean
15E64310000
unkown
page read and write
clean
7FF52492F000
unkown
page readonly
clean
2DF0000
unkown
page read and write
clean
E4C287B000
unkown
page read and write
clean
7FF583491000
unkown
page readonly
clean
1F05FB30000
heap default
page read and write
clean
15E61C54000
unkown
page read and write
clean
2184C561000
unkown
page read and write
clean
773000
heap default
page read and write
clean
1F05FC7C000
unkown
page read and write
clean
3CC3000
unkown
page read and write
clean
B6E000
unkown
page read and write
clean
23E6000
unkown
page readonly
clean
15E63E00000
unkown
page read and write
clean
1F05FC22000
unkown
page read and write
clean
1DF6B4D0000
unkown
page write copy
clean
2184C213000
unkown
page read and write
clean
2EA9000
unkown
page read and write
clean
2ED0000
unkown
page read and write
clean
27F2000
unkown
page readonly
clean
CD8C3FA000
unkown
page read and write
clean
2E51000
unkown
page read and write
clean
127ACC70000
unkown
page read and write
clean
2E62000
unkown
page read and write
clean
7FF4EEF45000
unkown
page readonly
clean
2E74000
unkown
page read and write
clean
127AC600000
unkown
page read and write
clean
7FF54AD6A000
unkown
page readonly
clean
31D0000
unkown
page readonly
clean
1AC82EE0000
heap private
page read and write
clean
2184C670000
unkown
page read and write
clean
7FF51B40E000
unkown
page readonly
clean
21CEB066000
unkown
page read and write
clean
7FF5561B5000
unkown
page readonly
clean
3E5B000
unkown
page read and write
clean
7FF524AA2000
unkown
page readonly
clean
15E61BC0000
unkown
page readonly
clean
A3E000
unkown
page read and write
clean
7FF52D1C1000
unkown
page readonly
clean
E4C2E7B000
unkown
page read and write
clean
2801000
unkown
page readonly
clean
530000
unkown
page read and write
clean
2DBE000
unkown
page read and write
clean
7FF524B40000
unkown
page readonly
clean
10001000
unkown
page execute read
clean
7FF52CE90000
unkown
page readonly
clean
7FF51B411000
unkown
page readonly
clean
21846EA8000
unkown
page read and write
clean
7FF524A41000
unkown
page readonly
clean
B5CAA7E000
unkown
page read and write
clean
488E000
stack
page read and write
clean
2EE6000
unkown
page read and write
clean
10023000
unkown
page readonly
clean
7FF51B33A000
unkown
page readonly
clean
143D6C00000
unkown
page readonly
clean
7FF55641A000
unkown
page readonly
clean
2298F1A0000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
2DFC3A00000
heap default
page read and write
clean
53B000
heap default
page read and write
clean
21CEB05E000
unkown
page read and write
clean
2184C630000
unkown
page read and write
clean
7FF52D178000
unkown
page readonly
clean
2210000
unkown
page read and write
clean
27C8000
unkown
page read and write
clean
2ED2000
unkown
page read and write
clean
50A000
unkown image
page read and write
clean
3CC1000
unkown
page read and write
clean
7FF52D320000
unkown
page readonly
clean
2E7A000
unkown
page read and write
clean
3E47000
unkown
page read and write
clean
2362000
unkown
page readonly
clean
CD8BFAB000
unkown
page read and write
clean
27B4000
unkown
page readonly
clean
283B000
unkown
page read and write
clean
7FF5B7297000
unkown
page readonly
clean
7FF5DA5AE000
unkown
page readonly
clean
226D000
unkown
page read and write
clean
22D0000
unkown
page readonly
clean
27DB000
unkown
page read and write
clean
1D357249000
unkown
page read and write
clean
2184C54E000
unkown
page read and write
clean
7FF524AB6000
unkown
page readonly
clean
1DF6CDC0000
unkown
page readonly
clean
230F000
unkown
page readonly
clean
1D357270000
unkown
page read and write
clean
1D35724E000
unkown
page read and write
clean
2298F258000
heap default
page read and write
clean
21846E00000
unkown
page read and write
clean
15E63CD9000
unkown
page read and write
clean
A41000
unkown
page read and write
clean
1AC82F90000
unkown
page readonly
clean
7FF54AC0E000
unkown
page readonly
clean
504000
unkown
page read and write
clean
7FF52D389000
unkown
page readonly
clean
C918E7B000
unkown
page read and write
clean
15E61C6D000
unkown
page read and write
clean
7FF4FFE90000
unkown
page readonly
clean
3DD2000
unkown
page read and write
clean
3DE2000
unkown
page read and write
clean
7FF4FFE49000
unkown
page readonly
clean
2D129650000
heap default
page read and write
clean
7FF5DA37B000
unkown
page readonly
clean
1F05FD02000
unkown
page read and write
clean
7FF583288000
unkown
page readonly
clean
7FF538C3D000
unkown
page readonly
clean
15E61CA0000
unkown
page read and write
clean
7FF5249B3000
unkown
page readonly
clean
15E63CC9000
unkown
page read and write
clean
2184C6F0000
unkown
page readonly
clean
2184C770000
unkown
page readonly
clean
3D4D000
unkown
page read and write
clean
143D64BB000
unkown
page read and write
clean
21846DC0000
unkown
page readonly
clean
28E0000
unkown
page execute and read and write
clean
2210000
unkown
page readonly
clean
33814FD000
unkown
page read and write
clean
7FF556406000
unkown
page readonly
clean
2DFF000
stack
page read and write
clean
A30000
unkown
page readonly
clean
27DB000
unkown
page read and write
clean
30BF07E000
unkown
page read and write
clean
7FF5E1019000
unkown
page readonly
clean
194000
stack
page read and write
clean
3D4E000
unkown
page read and write
clean
2184C2B7000
unkown
page read and write
clean
7FF5B6C31000
unkown
page readonly
clean
2D12989E000
unkown
page read and write
clean
266B000
unkown
page readonly
clean
2DFC3BD0000
unkown
page read and write
clean
340F000
unkown
page read and write
clean
7FF5DA2E6000
unkown
page readonly
clean
2373000
unkown
page readonly
clean
BF1000
unkown image
page execute read
clean
143D62F0000
unkown
page readonly
clean
2810000
unkown
page execute and read and write
clean
7520000
unkown
page read and write
clean
7FF4EF557000
unkown
page readonly
clean
2E80000
unkown
page read and write
clean
127ACC60000
unkown
page readonly
clean
2184C540000
unkown
page read and write
clean
2238000
heap private
page read and write
clean
2E68000
unkown
page read and write
clean
CD8C379000
unkown
page read and write
clean
2C4C000
stack
page read and write
clean
7FF5E0CDC000
unkown
page readonly
clean
27D0000
unkown
page execute and read and write
clean
7FF51B19F000
unkown
page readonly
clean
BB0000
heap private
page read and write
clean
2223000
unkown
page read and write
clean
143D6502000
unkown
page read and write
clean
7FF5B71F0000
unkown
page readonly
clean
2308000
unkown
page readonly
clean
412000
unkown image
page write copy
clean
7FF5E0F47000
unkown
page readonly
clean
2EB7000
unkown
page read and write
clean
7FF539160000
unkown
page readonly
clean
7FF524A61000
unkown
page readonly
clean
7FF52D389000
unkown
page readonly
clean
7FF5B740C000
unkown
page readonly
clean
B5CAC77000
unkown
page read and write
clean
7FF4FFE1A000
unkown
page readonly
clean
2D129857000
unkown
page read and write
clean
7FF583107000
unkown
page readonly
clean
15E61CCD000
unkown
page read and write
clean
7FF5833BA000
unkown
page readonly
clean
15E65100000
unkown
page read and write
clean
512000
unkown image
page readonly
clean
1D357229000
unkown
page read and write
clean
394D000
stack
page read and write
clean
820000
unkown
page readonly
clean
504000
unkown
page read and write
clean
7FF4EF526000
unkown
page readonly
clean
28B6000
unkown
page readonly
clean
15E61AF0000
unkown
page readonly
clean
3D79000
unkown
page read and write
clean
1F05FC4F000
unkown
page read and write
clean
7FF53933A000
unkown
page readonly
clean
27BB000
unkown
page readonly
clean
346C000
unkown
page read and write
clean
15E64210000
unkown
page read and write
clean
6F0000
heap default
page read and write
clean
AA7000
unkown
page read and write
clean
7FF4EF545000
unkown
page readonly
clean
21CEB06C000
unkown
page read and write
clean
7FF4FFE08000
unkown
page readonly
clean
7FF4FFE2E000
unkown
page readonly
clean
2E20000
heap default
page read and write
clean
2D12B749000
unkown
page read and write
clean
7A1C000
unkown
page read and write
clean
7FF4FFE5D000
unkown
page readonly
clean
770000
heap default
page read and write
clean
7FF5DA1A1000
unkown
page readonly
clean
143D6F40000
unkown
page write copy
clean
7FF5562B8000
unkown
page readonly
clean
3DDF000
unkown
page read and write
clean
7FF5E1055000
unkown
page readonly
clean
512000
unkown image
page readonly
clean
10338000
unkown
page read and write
clean
1DF6B400000
unkown
page readonly
clean
E6335FD000
unkown
page read and write
clean
15E61D13000
unkown
page read and write
clean
2DFC4400000
unkown
page readonly
clean
A10000
unkown
page read and write
clean
15E63C00000
unkown
page read and write
clean
572C5CC000
unkown
page read and write
clean
1F060402000
unkown
page read and write
clean
7FF524A7C000
unkown
page readonly
clean
495000
unkown image
page execute and read and write
clean
2EC9000
unkown
page read and write
clean
7FF54AC53000
unkown
page readonly
clean
3DF3000
unkown
page read and write
clean
61FBAFE000
unkown
page read and write
clean
7FF5393CE000
unkown
page readonly
clean
231D000
unkown
page read and write
clean
3CE5000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
7FF4FFD0D000
unkown
page readonly
clean
57E000
unkown
page read and write
clean
15E64000000
unkown
page read and write
clean
7FF524A54000
unkown
page readonly
clean
5E0000
heap default
page read and write
clean
512000
unkown image
page readonly
clean
7FF5E0C03000
unkown
page readonly
clean
15E61C7A000
unkown
page read and write
clean
7FF5B7145000
unkown
page readonly
clean
21847615000
unkown
page read and write
clean
196000
stack
page read and write
clean
2EA0000
heap private
page read and write
clean
3CC0000
unkown
page read and write
clean
2E50000
unkown
page read and write
clean
3CA0000
unkown
page read and write
clean
2E58000
unkown
page read and write
clean
BFC000
unkown image
page readonly
clean
3E12000
unkown
page read and write
clean
2E7E000
unkown
page read and write
clean
3FCF000
stack
page read and write
clean
30BF4FB000
unkown
page read and write
clean
2210000
unkown
page read and write
clean
143D6210000
heap default
page read and write
clean
15E63C53000
unkown
page read and write
clean
A3E000
unkown
page read and write
clean
7FF54A635000
unkown
page readonly
clean
3D1A000
unkown
page read and write
clean
2184C548000
unkown
page read and write
clean
7FF54AB6A000
unkown
page readonly
clean
15E61C49000
unkown
page read and write
clean
7FF583347000
unkown
page readonly
clean
7FF5DA4DA000
unkown
page readonly
clean
384D000
stack
page read and write
clean
2E5E000
unkown
page read and write
clean
2DF5000
heap private
page read and write
clean
7FF4FFD6C000
unkown
page readonly
clean
BFC000
unkown image
page readonly
clean
400000
unkown image
page readonly
clean
15E63E73000
unkown
page read and write
clean
7FF52CE7A000
unkown
page readonly
clean
7FF58334A000
unkown
page readonly
clean
15E63C41000
unkown
page read and write
clean
2E55000
unkown
page read and write
clean
2D12986E000
unkown
page read and write
clean
2E4E000
unkown
page read and write
clean
C6439EE000
unkown
page read and write
clean
7FF4EF521000
unkown
page readonly
clean
E4C31FA000
unkown
page read and write
clean
512000
unkown image
page readonly
clean
788000
unkown
page read and write
clean
127AC520000
unkown
page readonly
clean
1AC83065000
unkown
page read and write
clean
18D000
stack
page read and write
clean
3D8E000
unkown
page read and write
clean
484E000
unkown
page read and write
clean
7FF4FFE94000
unkown
page readonly
clean
2184C440000
unkown
page read and write
clean
75C000
stack
page read and write
clean
7FF4EF487000
unkown
page readonly
clean
21CEAF50000
unkown
page readonly
clean
A2E000
unkown
page read and write
clean
2E4E000
unkown
page read and write
clean
7FF5DA445000
unkown
page readonly
clean
7FF51B310000
unkown
page readonly
clean
7FF5DA3DC000
unkown
page readonly
clean
B5CAE7F000
unkown
page read and write
clean
2EB6000
unkown
page read and write
clean
2E7D000
stack
page read and write
clean
7FF4EF173000
unkown
page readonly
clean
A9E000
unkown
page read and write
clean
3FE1000
unkown
page read and write
clean
15E61C98000
unkown
page read and write
clean
2184C570000
unkown
page read and write
clean
143D6413000
unkown
page read and write
clean
2D12B2A0000
unkown
page readonly
clean
7FF53937C000
unkown
page readonly
clean
30BF7FA000
unkown
page read and write
clean
15E64110000
unkown
page read and write
clean
3DFC000
unkown
page read and write
clean
7FF5B7489000
unkown
page readonly
clean
30BF77B000
unkown
page read and write
clean
30BF8FB000
unkown
page read and write
clean
7FF5B73ED000
unkown
page readonly
clean
7FF5B7398000
unkown
page readonly
clean
15E61C7A000
unkown
page read and write
clean
21847E30000
unkown
page readonly
clean
15E61C7A000
unkown
page read and write
clean
2D12B830000
unkown
page readonly
clean
1F05FED0000
unkown
page readonly
clean
1D357202000
unkown
page read and write
clean
15E63E84000
unkown
page read and write
clean
7FF5E0F77000
unkown
page readonly
clean
143D64CA000
unkown
page read and write
clean
2DFC39A0000
heap private
page read and write
clean
4F7E000
stack
page read and write
clean
1AC8305A000
unkown
page read and write
clean
512000
unkown image
page readonly
clean
30BF3FB000
unkown
page read and write
clean
27EB000
unkown
page read and write
clean
2DA0000
unkown
page read and write
clean
127AC63D000
unkown
page read and write
clean
7FF55645D000
unkown
page readonly
clean
7FF52D292000
unkown
page readonly
clean
3CE3000
unkown
page read and write
clean
7FF524A57000
unkown
page readonly
clean
401000
unkown image
page execute and write copy
clean
3D1C000
unkown
page read and write
clean
7FF5E10C0000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
7FF5DA51D000
unkown
page readonly
clean
3CE5000
unkown
page read and write
clean
21847602000
unkown
page read and write
clean
187000
stack
page read and write
clean
7FF5E0FC0000
unkown
page readonly
clean
7FF5E0D18000
unkown
page readonly
clean
7FF4EEFB1000
unkown
page readonly
clean
7FF5E104C000
unkown
page readonly
clean
27DB000
unkown
page read and write
clean
1F05FC56000
unkown
page read and write
clean
143D6A02000
unkown
page read and write
clean
7FF5DA4FF000
unkown
page readonly
clean
2184C2A0000
unkown
page read and write
clean
2DFC3C00000
unkown
page read and write
clean
2E7C000
unkown
page read and write
clean
7FF4EF554000
unkown
page readonly
clean
2F20000
unkown
page read and write
clean
4FBC000
unkown
page read and write
clean
77B000
unkown
page read and write
clean
7FF54AC38000
unkown
page readonly
clean
2D1298A8000
unkown
page read and write
clean
269C000
unkown
page read and write
clean
7FF583200000
unkown
page readonly
clean
15E63C4F000
unkown
page read and write
clean
5090000
unkown
page read and write
clean
87B000
heap default
page read and write
clean
401000
unkown image
page execute and write copy
clean
237D000
unkown
page read and write
clean
2A90000
unkown
page readonly
clean
4C6000
unkown image
page readonly
clean
7CA000
heap default
page read and write
clean
2D48000
heap private
page read and write
clean
2280000
unkown
page read and write
clean
7FF5E0905000
unkown
page readonly
clean
1D357110000
unkown
page readonly
clean
2E5C000
unkown
page read and write
clean
3CE5000
unkown
page read and write
clean
26DA000
stack
page read and write
clean
34E0000
unkown
page read and write
clean
2E81000
unkown
page read and write
clean
21CEB040000
unkown
page read and write
clean
3DE9000
unkown
page read and write
clean
2D1298C8000
unkown
page read and write
clean
600000
unkown
page read and write
clean
E6334FA000
unkown
page read and write
clean
7FF583416000
unkown
page readonly
clean
3D8E000
unkown
page read and write
clean
2E00000
unkown
page readonly
clean
1DF6B23F000
unkown
page read and write
clean
77F000
stack
page read and write
clean
2DFC3C4A000
unkown
page read and write
clean
7FF5833DF000
unkown
page readonly
clean
7FF5248CB000
unkown
page readonly
clean
7FF524BA9000
unkown
page readonly
clean
3CD9000
unkown
page read and write
clean
218481A0000
unkown
page read and write
clean
237C000
unkown
page read and write
clean
31F5000
heap private
page read and write
clean
7FF5E0E81000
unkown
page readonly
clean
27C9000
unkown
page read and write
clean
6F9000
unkown
page read and write
clean
7FF5B73F6000
unkown
page readonly
clean
7FF524AF9000
unkown
page readonly
clean
21CEB044000
unkown
page read and write
clean
C91917F000
unkown
page read and write
clean
1AC83002000
unkown
page read and write
clean
7FF524813000
unkown
page readonly
clean
7FF5DA5B0000
unkown
page readonly
clean
2D5D000
unkown
page read and write
clean
FDC447B000
unkown
page read and write
clean
27C9000
unkown
page read and write
clean
3DF9000
unkown
page read and write
clean
B16000
heap private
page read and write
clean
21846E7B000
unkown
page read and write
clean
2DFC4202000
unkown
page read and write
clean
2EA2000
unkown
page read and write
clean
7FF524B16000
unkown
page readonly
clean
4650000
unkown
page readonly
clean
E4C2A77000
unkown
page read and write
clean
7FF4FF9F0000
unkown
page readonly
clean
9D000
unkown
page read and write
clean
F185D7F000
unkown
page read and write
clean
3CE5000
unkown
page read and write
clean
2298F535000
heap private
page read and write
clean
143D6400000
unkown
page read and write
clean
1AC82F40000
heap default
page read and write
clean
7FF53940C000
unkown
page readonly
clean
2EBD000
unkown
page read and write
clean
7FF5B7293000
unkown
page readonly
clean
27EB000
unkown
page read and write
clean
27D4000
unkown
page read and write
clean
21CEB102000
unkown
page read and write
clean
15E63C5A000
unkown
page read and write
clean
CD8C47E000
unkown
page read and write
clean
21CEAF40000
unkown
page readonly
clean
10337000
unkown
page readonly
clean
F185C77000
unkown
page read and write
clean
7FF4EEFB9000
unkown
page readonly
clean
7FF51B39C000
unkown
page readonly
clean
1DF6B1E0000
unkown
page readonly
clean
414000
unkown image
page readonly
clean
2CCF000
heap default
page read and write
clean
7FF5564EE000
unkown
page readonly
clean
2F1B000
unkown
page read and write
clean
1DF6B200000
unkown
page read and write
clean
7FF5391D8000
unkown
page readonly
clean
497000
unkown image
page execute and write copy
clean
7FF5E0D08000
unkown
page readonly
clean
7FF524B0D000
unkown
page readonly
clean
27EB000
unkown
page read and write
clean
3E12000
unkown
page read and write
clean
7FF5DA53C000
unkown
page readonly
clean
194000
stack
page read and write
clean
10337000
unkown
page readonly
clean
2D12B749000
unkown
page read and write
clean
7FF539499000
unkown
page readonly
clean
2240000
unkown
page read and write
clean
2F60000
heap default
page read and write
clean
18E000
stack
page read and write
clean
143D6B00000
unkown
page read and write
clean
7FF538C41000
unkown
page readonly
clean
21846E8F000
unkown
page read and write
clean
364F000
unkown
page read and write
clean
505000
unkown image
page write copy
clean
7FF5564F1000
unkown
page readonly
clean
400000
unkown image
page readonly
clean
15E63F43000
unkown
page read and write
clean
C643D7F000
unkown
page read and write
clean
7FF51B369000
unkown
page readonly
clean
3CB6000
unkown
page read and write
clean
7FF53941C000
unkown
page readonly
clean
7FF539390000
unkown
page readonly
clean
2E49000
unkown
page read and write
clean
7E9000
heap default
page read and write
clean
21846EFF000
unkown
page read and write
clean
1D357313000
unkown
page read and write
clean
15E61C6D000
unkown
page read and write
clean
7FF54ADB6000
unkown
page readonly
clean
7FF5DA4C6000
unkown
page readonly
clean
143D69F0000
unkown
page readonly
clean
2400000
unkown
page readonly
clean
7FF4EF51D000
unkown
page readonly
clean
505000
unkown image
page write copy
clean
E63367F000
unkown
page read and write
clean
3CFA000
unkown
page read and write
clean
811000
heap default
page read and write
clean
21846E13000
unkown
page read and write
clean
A39000
unkown
page read and write
clean
3DA0000
unkown
page read and write
clean
A5477E000
unkown
page read and write
clean
7FF539103000
unkown
page readonly
clean
7FF5E0C5E000
unkown
page readonly
clean
4F3C000
unkown
page read and write
clean
7FF5B7150000
unkown
page readonly
clean
83C000
unkown
page read and write
clean
7FF524AB2000
unkown
page readonly
clean
27BD000
unkown
page readonly
clean
21846DE0000
unkown
page read and write
clean
779000
unkown
page read and write
clean
7FF583103000
unkown
page readonly
clean
7FF53930C000
unkown
page readonly
clean
27C0000
unkown
page read and write
clean
3DDB000
unkown
page read and write
clean
7FF5833A2000
unkown
page readonly
clean
7FF51B355000
unkown
page readonly
clean
2238000
heap private
page read and write
clean
1F05FB40000
unkown
page readonly
clean
2227000
heap private
page read and write
clean
7FF4FFEF9000
unkown
page readonly
clean
3CBF000
unkown
page read and write
clean
15E61D1A000
unkown
page read and write
clean
89F000
stack
page read and write
clean
7FF52D2CF000
unkown
page readonly
clean
B19000
heap private
page read and write
clean
15E63C54000
unkown
page read and write
clean
2D5C000
unkown
page read and write
clean
7FF4EEE45000
unkown
page readonly
clean
3E12000
unkown
page read and write
clean
15E63AB0000
unkown
page read and write
clean
6E0000
unkown
page readonly
clean
26FD000
unkown
page readonly
clean
1D35724A000
unkown
page read and write
clean
7FF5391BB000
unkown
page readonly
clean
1D357790000
unkown
page read and write
clean
2F0E000
unkown
page read and write
clean
2D49000
unkown
page read and write
clean
2655000
unkown
page readonly
clean
30BF6FB000
unkown
page read and write
clean
A31000
unkown
page read and write
clean
F1858F5000
unkown
page read and write
clean
7FF5830F4000
unkown
page readonly
clean
7FF539305000
unkown
page readonly
clean
61FBDFF000
unkown
page read and write
clean
21CEB041000
unkown
page read and write
clean
B5CAD7F000
unkown
page read and write
clean
15E61C7F000
unkown
page read and write
clean
22FE000
unkown
page readonly
clean
7FF5833A6000
unkown
page readonly
clean
7FF5564F9000
unkown
page readonly
clean
3DE2000
unkown
page read and write
clean
3B5000
unkown
page read and write
clean
3CE000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
7FF524ADE000
unkown
page readonly
clean
2F50000
unkown
page write copy
clean
B19000
heap private
page read and write
clean
7FF5B7341000
unkown
page readonly
clean
2A00000
unkown
page readonly
clean
E633179000
unkown
page read and write
clean
7FF5B73AA000
unkown
page readonly
clean
2F00000
unkown
page read and write
clean
2827000
unkown
page readonly
clean
222D8057000
unkown
page read and write
clean
B17000
heap private
page read and write
clean
3A90000
unkown
page readonly
clean
7FF5E10C9000
unkown
page readonly
clean
2184C790000
unkown
page readonly
clean
A49000
unkown
page read and write
clean
7FF58336C000
unkown
page readonly
clean
26C1000
unkown
page read and write
clean
21CEB05F000
unkown
page read and write
clean
2EB9000
unkown
page read and write
clean
840000
heap default
page read and write
clean
7FF5E0F97000
unkown
page readonly
clean
2E6B000
unkown
page read and write
clean
26C1000
unkown
page read and write
clean
7FF52D2D9000
unkown
page readonly
clean
B5CAB7B000
unkown
page read and write
clean
E63327E000
unkown
page read and write
clean
792000
unkown
page read and write
clean
79E000
unkown
page read and write
clean
7FF539373000
unkown
page readonly
clean
2F02000
unkown
page read and write
clean
2239000
unkown
page read and write
clean
7FF5DA122000
unkown
page readonly
clean
7FF4EF4C2000
unkown
page readonly
clean
7DF000
stack
page read and write
clean
2E53000
unkown
page read and write
clean
3DFC000
unkown
page read and write
clean
2D12B1A0000
unkown
page read and write
clean
7FF556033000
unkown
page readonly
clean
2340000
unkown
page readonly
clean
72E000
heap default
page read and write
clean
A85000
unkown
page read and write
clean
27F3000
unkown
page read and write
clean
7FF5E093A000
unkown
page readonly
clean
7ADE000
stack
page read and write
clean
15E635F0000
unkown
page read and write
clean
504000
unkown
page read and write
clean
7FF52D221000
unkown
page readonly
clean
5F0000
unkown
page readonly
clean
2E74000
unkown
page read and write
clean
27CE000
unkown
page readonly
clean
10023000
unkown
page readonly
clean
7FF52D19D000
unkown
page readonly
clean
15E65042000
unkown
page read and write
clean
C643C7A000
unkown
page read and write
clean
2184C564000
unkown
page read and write
clean
3D2000
unkown
page read and write
clean
2E67000
unkown
page read and write
clean
9D000
unkown
page read and write
clean
7FF556485000
unkown
page readonly
clean
7510000
heap private
page read and write
clean
1F060940000
unkown
page readonly
clean
2F02000
unkown
page read and write
clean
27C9000
unkown
page read and write
clean
21CEAF30000
heap default
page read and write
clean
7FF539401000
unkown
page readonly
clean
1F05FC6D000
unkown
page read and write
clean
888000
heap default
page read and write
clean
7FF4EEF09000
unkown
page readonly
clean
7FF5E0FD6000
unkown
page readonly
clean
3CE7000
unkown
page read and write
clean
7FF5E0D90000
unkown
page readonly
clean
3DF4000
unkown
page read and write
clean
2184C29B000
unkown
page read and write
clean
A9A000
unkown
page read and write
clean
877000
heap default
page read and write
clean
2280000
unkown
page read and write
clean
2184C6A0000
unkown
page read and write
clean
2D12B820000
unkown
page read and write
clean
222D82D0000
unkown
page readonly
clean
282E000
unkown
page readonly
clean
1AC83A00000
unkown
page readonly
clean
143D6467000
unkown
page read and write
clean
15E61D5D000
unkown
page read and write
clean
2EDF000
unkown
page read and write
clean
3CC2000
unkown
page read and write
clean
7FF5E0E7C000
unkown
page readonly
clean
2D129813000
unkown
page read and write
clean
2BCF000
stack
page read and write
clean
1AC82F60000
unkown
page readonly
clean
7FF582C3D000
unkown
page readonly
clean
15E63CC7000
unkown
page read and write
clean
15E63F00000
unkown
page read and write
clean
2D1297C0000
unkown
page read and write
clean
2DFC3C4B000
unkown
page read and write
clean
7FF4FFD37000
unkown
page readonly
clean
2346000
unkown
page readonly
clean
7FF52D298000
unkown
page readonly
clean
2B6A000
unkown
page read and write
clean
505000
unkown image
page write copy
clean
4C4E000
stack
page read and write
clean
2372000
heap private
page read and write
clean
15E63F83000
unkown
page read and write
clean
10C0000
unkown
page readonly
clean
220D000
unkown
page read and write
clean
7FF51AC59000
unkown
page readonly
clean
2843000
unkown
page readonly
clean
4EE0000
unkown
page read and write
clean
2408000
unkown
page readonly
clean
21CEB04E000
unkown
page read and write
clean
505000
unkown
page read and write
clean
7FF539147000
unkown
page readonly
clean
2770000
unkown
page readonly
clean
3FC0000
heap private
page read and write
clean
2184C263000
unkown
page read and write
clean
2D43000
heap private
page read and write
clean
4CC0000
unkown
page readonly
clean
893000
heap default
page read and write
clean
222D803F000
unkown
page read and write
clean
2390000
heap private
page read and write
clean
333F000
stack
page read and write
clean
21847CF0000
unkown
page read and write
clean
2935000
unkown
page read and write
clean
21CEB05C000
unkown
page read and write
clean
15E61CC4000
unkown
page read and write
clean
1D357200000
unkown
page read and write
clean
22DE000
unkown
page read and write
clean
507F000
stack
page read and write
clean
B5CA8FE000
unkown
page read and write
clean
9EE000
unkown
page read and write
clean
15E61CE9000
unkown
page read and write
clean
7FF4EF536000
unkown
page readonly
clean
7FF5DA554000
unkown
page readonly
clean
7FF524A7A000
unkown
page readonly
clean
650000
unkown
page readonly
clean
F18551E000
unkown
page read and write
clean
2184C1B0000
unkown
page read and write
clean
E63337B000
unkown
page read and write
clean
2DFC3C4D000
unkown
page read and write
clean
3CB4000
unkown
page read and write
clean
6FD000
unkown
page read and write
clean
7FF5DA48A000
unkown
page readonly
clean
2E5E000
unkown
page read and write
clean
2227000
unkown
page read and write
clean
127AC658000
unkown
page read and write
clean
9FE000
unkown
page read and write
clean
65E000
unkown
page read and write
clean
FDC45FF000
unkown
page read and write
clean
771000
unkown
page read and write
clean
7FF524A4A000
unkown
page readonly
clean
15E63E3A000
unkown
page read and write
clean
15E63C76000
unkown
page read and write
clean
21846E3D000
unkown
page read and write
clean
3CA1000
unkown
page read and write
clean
7FF52D2FC000
unkown
page readonly
clean
15E65042000
unkown
page read and write
clean
7FF4FFE76000
unkown
page readonly
clean
198000
stack
page read and write
clean
2E6A000
unkown
page read and write
clean
15E61D3C000
unkown
page read and write
clean
61FB9FD000
unkown
page read and write
clean
2814000
unkown
page readonly
clean
3DD8000
unkown
page read and write
clean
7FF556435000
unkown
page readonly
clean
3030000
unkown
page read and write
clean
222D000
unkown
page read and write
clean
21846E8D000
unkown
page read and write
clean
1AC82F70000
unkown
page read and write
clean
A38000
unkown
page read and write
clean
7FF5E0E6E000
unkown
page readonly
clean
401000
unkown image
page execute read
clean
505000
unkown image
page write copy
clean
1F05FC89000
unkown
page read and write
clean
7FF5248E8000
unkown
page readonly
clean
3CB5000
unkown
page read and write
clean
338137E000
unkown
page read and write
clean
2E4E000
unkown
page read and write
clean
77B000
unkown
page read and write
clean
2810000
unkown
page readonly
clean
15E61C9B000
unkown
page read and write
clean
7FF5B73FC000
unkown
page readonly
clean
2ED5000
unkown
page read and write
clean
27F3000
unkown
page read and write
clean
7FF5833AA000
unkown
page readonly
clean
503E000
unkown
page read and write
clean
15E64110000
unkown
page read and write
clean
2DFC3C28000
unkown
page read and write
clean
7FF556385000
unkown
page readonly
clean
27CC000
unkown
page read and write
clean
15E61CC2000
unkown
page read and write
clean
59F0000
unkown
page readonly
clean
2184C7B0000
unkown
page readonly
clean
7FF5DA5B9000
unkown
page readonly
clean
2184C24C000
unkown
page read and write
clean
E4C337B000
unkown
page read and write
clean
143D6429000
unkown
page read and write
clean
746000
unkown
page read and write
clean
78E000
unkown
page read and write
clean
3CE5000
unkown
page read and write
clean
7FF5DA4C2000
unkown
page readonly
clean
7FF5DA545000
unkown
page readonly
clean
2EC6000
unkown
page read and write
clean
2806000
unkown
page readonly
clean
7FF5393A2000
unkown
page readonly
clean
3DE3000
unkown
page read and write
clean
21847758000
unkown
page read and write
clean
15E63CAD000
unkown
page read and write
clean
2210000
unkown
page read and write
clean
27CC000
unkown
page read and write
clean
E63307E000
unkown
page read and write
clean
27C1000
unkown
page readonly
clean
772000
unkown
page read and write
clean
2D40000
heap private
page read and write
clean
7FF54AD8F000
unkown
page readonly
clean
2E72000
unkown
page read and write
clean
4C6000
unkown image
page readonly
clean
510000
unkown
page readonly
clean
2E67000
unkown
page read and write
clean
2B50000
unkown
page readonly
clean
30BF47B000
unkown
page read and write
clean
143D63D0000
unkown
page readonly
clean
A39000
unkown
page read and write
clean
2ECC000
unkown
page read and write
clean
30BF87D000
unkown
page read and write
clean
3CE7000
unkown
page read and write
clean
21CEB02D000
unkown
page read and write
clean
768000
heap default
page read and write
clean
2330000
unkown
page readonly
clean
283B000
unkown
page read and write
clean
E6332FF000
unkown
page read and write
clean
7FF5B7417000
unkown
page readonly
clean
28D8000
unkown
page readonly
clean
30BF27F000
unkown
page read and write
clean
2184C540000
unkown
page read and write
clean
3D1A000
unkown
page read and write
clean
7FF5E0FD2000
unkown
page readonly
clean
7FF52D2F6000
unkown
page readonly
clean
520000
heap default
page read and write
clean
3E04000
unkown
page read and write
clean
7FF538FCD000
unkown
page readonly
clean
15E63C42000
unkown
page read and write
clean
21846E7D000
unkown
page read and write
clean
2184C1F0000
unkown
page read and write
clean
93B000
stack
page read and write
clean
21846DD0000
unkown
page readonly
clean
2C8E000
unkown
page read and write
clean
7FF5E1064000
unkown
page readonly
clean
7FF5E0E99000
unkown
page readonly
clean
2E62000
unkown
page read and write
clean
21846C80000
heap private
page read and write
clean
505000
unkown image
page write copy
clean
237C000
heap private
page read and write
clean
7FF582C41000
unkown
page readonly
clean
40F000
unkown image
page readonly
clean
18A000
stack
page read and write
clean
7FF54ADE4000
unkown
page readonly
clean
15E64410000
unkown
page read and write
clean
15E63A40000
unkown
page read and write
clean
7FF52482C000
unkown
page readonly
clean
3CC6000
unkown
page read and write
clean
7FF4EEF3C000
unkown
page readonly
clean
A39000
unkown
page read and write
clean
27C9000
unkown
page read and write
clean
3CFA000
unkown
page read and write
clean
21CEB059000
unkown
page read and write
clean
7FF55627F000
unkown
page readonly
clean
2E99000
unkown
page read and write
clean
B5CA87E000
unkown
page read and write
clean
7FF52D282000
unkown
page readonly
clean
2320000
unkown
page readonly
clean
82D000
heap default
page read and write
clean
2EC1000
unkown
page read and write
clean
2D129918000
unkown
page read and write
clean
7FF5B70F3000
unkown
page readonly
clean
5C0000
unkown
page readonly
clean
7FF5248DC000
unkown
page readonly
clean
9A0000
unkown
page read and write
clean
15E63CC6000
unkown
page read and write
clean
71B000
heap default
page read and write
clean
19B000
stack
page read and write
clean
27B6000
unkown
page readonly
clean
7FF524AE5000
unkown
page readonly
clean
400000
unkown image
page readonly
clean
222D8000000
unkown
page read and write
clean
7FF4EEECA000
unkown
page readonly
clean
1F05FD08000
unkown
page read and write
clean
9DF000
stack
page read and write
clean
1DF6B170000
heap private
page read and write
clean
C6438EB000
unkown
page read and write
clean
68E000
unkown
page read and write
clean
3CAE000
unkown
page read and write
clean
7FF54AD56000
unkown
page readonly
clean
15E63A50000
heap private
page read and write
clean
15E65082000
unkown
page read and write
clean
7FF5DA4B0000
unkown
page readonly
clean
7FF5DA42C000
unkown
page readonly
clean
7FF53936A000
unkown
page readonly
clean
15E61D1C000
unkown
page read and write
clean
21CEB07D000
unkown
page read and write
clean
2408000
unkown
page readonly
clean
7FF5393DF000
unkown
page readonly
clean
2E9A000
unkown
page read and write
clean
15E61CD3000
unkown
page read and write
clean
21CEB079000
unkown
page read and write
clean
7FF5DA4EE000
unkown
page readonly
clean
338197E000
unkown
page read and write
clean
2184C6A0000
unkown
page read and write
clean
7FF524B44000
unkown
page readonly
clean
3DE1000
unkown
page read and write
clean
223C000
unkown
page read and write
clean
15E63C71000
unkown
page read and write
clean
7FF54AC1A000
unkown
page readonly
clean
2E6A000
unkown
page read and write
clean
572CAFE000
unkown
page read and write
clean
3CC3000
unkown
page read and write
clean
30BEDDB000
unkown
page read and write
clean
21846E8F000
unkown
page read and write
clean
21846E78000
unkown
page read and write
clean
1D357300000
unkown
page read and write
clean
21CEB029000
unkown
page read and write
clean
7FF4EF4F5000
unkown
page readonly
clean
222D7F90000
unkown
page readonly
clean
21CEB083000
unkown
page read and write
clean
1F05FC2A000
unkown
page read and write
clean
15E65000000
unkown
page read and write
clean
7FF524B1C000
unkown
page readonly
clean
7FF54AC87000
unkown
page readonly
clean
A39000
unkown
page read and write
clean
2385000
unkown
page readonly
clean
7FF556497000
unkown
page readonly
clean
15E63E12000
unkown
page read and write
clean
2DFC3C89000
unkown
page read and write
clean
75E000
unkown
page read and write
clean
2E52000
unkown
page read and write
clean
414000
unkown image
page readonly
clean
2DFC3C4E000
unkown
page read and write
clean
2340000
unkown
page read and write
clean
FBE000
stack
page read and write
clean
A4B000
unkown
page read and write
clean
2184C610000
unkown
page read and write
clean
2184C2B6000
unkown
page read and write
clean
21CEB058000
unkown
page read and write
clean
7FF524A8C000
unkown
page readonly
clean
50A000
unkown image
page read and write
clean
2EC9000
unkown
page read and write
clean
3DE5000
unkown
page read and write
clean
15E65002000
unkown
page read and write
clean
278000
unkown
page read and write
clean
512000
unkown image
page readonly
clean
5080000
unkown
page readonly
clean
7FF5B7392000
unkown
page readonly
clean
143D64CC000
unkown
page read and write
clean
127AC613000
unkown
page read and write
clean
2298F1C0000
unkown
page read and write
clean
15E636F0000
unkown
page readonly
clean
4D80000
unkown
page read and write
clean
15E61E00000
unkown
page write copy
clean
1F05FD00000
unkown
page read and write
clean
7FF5DA3C7000
unkown
page readonly
clean
27C0000
unkown
page read and write
clean
C918C7E000
unkown
page read and write
clean
61FB7FE000
unkown
page read and write
clean
2E80000
unkown
page read and write
clean
2D12B702000
unkown
page read and write
clean
7FF5392A7000
unkown
page readonly
clean
220D000
unkown
page read and write
clean
2D1D000
stack
page read and write
clean
7FF5DA4F5000
unkown
page readonly
clean
5110000
unkown
page read and write
clean
143D6470000
unkown
page read and write
clean
7FF54AE3E000
unkown
page readonly
clean
2D129800000
unkown
page read and write
clean
670000
heap default
page read and write
clean
21846E9F000
unkown
page read and write
clean
15E61C72000
unkown
page read and write
clean
27D8000
unkown
page readonly
clean
1AC83660000
unkown
page readonly
clean
7FF539434000
unkown
page readonly
clean
3DFA000
unkown
page read and write
clean
21CD000
unkown
page read and write
clean
7FF5DA18F000
unkown
page readonly
clean
7FF583430000
unkown
page readonly
clean
21CEAF60000
unkown
page read and write
clean
A3D000
unkown
page read and write
clean
15E63C1F000
unkown
page read and write
clean
2D45000
heap private
page read and write
clean
3CA7000
unkown
page read and write
clean
7FF4FFE06000
unkown
page readonly
clean
1D357A00000
unkown
page readonly
clean
27C9000
unkown
page read and write
clean
2298F350000
unkown
page readonly
clean
A5F000
unkown
page read and write
clean
E4C357F000
unkown
page read and write
clean
7FF5563F2000
unkown
page readonly
clean
A40000
unkown
page read and write
clean
19C000
stack
page read and write
clean
7FF583427000
unkown
page readonly
clean
7FF51B386000
unkown
page readonly
clean
21847600000
unkown
page read and write
clean
10332000
unkown
page read and write
clean
2E5D000
unkown
page read and write
clean
7FF5E0D85000
unkown
page readonly
clean
7DFAFBE86000
unkown
page readonly
clean
3D8E000
unkown
page read and write
clean
7FF5248FA000
unkown
page readonly
clean
E6330FE000
unkown
page read and write
clean
7FF539427000
unkown
page readonly
clean
2F70000
unkown
page readonly
clean
15E61C9C000
unkown
page read and write
clean
A50000
heap default
page read and write
clean
1D357D40000
unkown
page readonly
clean
7FF5E0F3C000
unkown
page readonly
clean
2D12B602000
unkown
page read and write
clean
61FBEFF000
unkown
page read and write
clean
15E64110000
unkown
page read and write
clean
7FF51AC0D000
unkown
page readonly
clean
21847713000
unkown
page read and write
clean
4C90000
unkown
page readonly
clean
7FF53911C000
unkown
page readonly
clean
1D357308000
unkown
page read and write
clean
7FF556494000
unkown
page readonly
clean
4C6000
unkown image
page readonly
clean
127AC510000
heap default
page read and write
clean
7FF524BA1000
unkown
page readonly
clean
2C80000
heap default
page read and write
clean
15E63EA4000
unkown
page read and write
clean
7FF4FFDF0000
unkown
page readonly
clean
7FF583499000
unkown
page readonly
clean
7FF539288000
unkown
page readonly
clean
2D129870000
unkown
page read and write
clean
2B0E000
stack
page read and write
clean
2BA9000
stack
page read and write
clean
143D6220000
unkown
page readonly
clean
61FB6FC000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
7FF583160000
unkown
page readonly
clean
2DFC3C6C000
unkown
page read and write
clean
830000
unkown
page readonly
clean
401000
unkown image
page execute and write copy
clean
27F4000
unkown
page read and write
clean
7FF5393FD000
unkown
page readonly
clean
7A9C000
unkown
page read and write
clean
23F4000
unkown
page readonly
clean
7FF5563E8000
unkown
page readonly
clean
3CBF000
unkown
page read and write
clean
15E63CDA000
unkown
page read and write
clean
2184C570000
unkown
page read and write
clean
1F05FC13000
unkown
page read and write
clean
7FF4FF9EA000
unkown
page readonly
clean
2EA3000
unkown
page read and write
clean
2832000
unkown
page readonly
clean
7FF5E0F35000
unkown
page readonly
clean
A545FF000
unkown
page read and write
clean
3CCE000
unkown
page read and write
clean
2184C680000
unkown
page read and write
clean
1D35724F000
unkown
page read and write
clean
15E63C54000
unkown
page read and write
clean
2944000
unkown
page read and write
clean
BF0000
unkown image
page readonly
clean
7FF583351000
unkown
page readonly
clean
2380000
unkown
page readonly
clean
2241000
unkown
page read and write
clean
B1A000
heap private
page read and write
clean
2D1298DB000
unkown
page read and write
clean
27CE000
unkown
page read and write
clean
7FF583499000
unkown
page readonly
clean
7FF4EEF1E000
unkown
page readonly
clean
A31000
unkown
page read and write
clean
2E5E000
unkown
page read and write
clean
30BF1FB000
unkown
page read and write
clean
7FF5E100F000
unkown
page readonly
clean
2D129780000
unkown
page readonly
clean
4C0D000
unkown
page read and write
clean
1D35724B000
unkown
page read and write
clean
AA7000
unkown
page read and write
clean
9E0000
unkown
page read and write
clean
E6333FB000
unkown
page read and write
clean
15E63C34000
unkown
page read and write
clean
7FF5E0E90000
unkown
page readonly
clean
7FF4FFCBE000
unkown
page readonly
clean
7FF4EF5B9000
unkown
page readonly
clean
F1859FB000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
3CE5000
unkown
page read and write
clean
7FF52434D000
unkown
page readonly
clean
127ACCB0000
unkown
page read and write
clean
283B000
unkown
page read and write
clean
222E000
unkown
page read and write
clean
7FF4FFE02000
unkown
page readonly
clean
7FF54ADAD000
unkown
page readonly
clean
7FF5B73BE000
unkown
page readonly
clean
C918F77000
unkown
page read and write
clean
15E61CC0000
unkown
page read and write
clean
7FF5DA1EE000
unkown
page readonly
clean
2E66000
unkown
page read and write
clean
2740000
unkown
page readonly
clean
2ECF000
unkown
page read and write
clean
7FF583437000
unkown
page readonly
clean
26F0000
unkown
page readonly
clean
7FF52D193000
unkown
page readonly
clean
2370000
heap private
page read and write
clean
21CEB03D000
unkown
page read and write
clean
7FF54AD40000
unkown
page readonly
clean
26B7000
unkown
page readonly
clean
2F02000
unkown
page read and write
clean
338127E000
unkown
page read and write
clean
21CEB045000
unkown
page read and write
clean
1D357257000
unkown
page read and write
clean
9BF000
stack
page read and write
clean
2330000
unkown
page read and write
clean
3FD0000
unkown
page read and write
clean
7FF5E0FC2000
unkown
page readonly
clean
27DF000
unkown
page readonly
clean
239A000
unkown
page readonly
clean
7FF5833A8000
unkown
page readonly
clean
231D000
unkown
page read and write
clean
27FA000
unkown
page readonly
clean
217E000
unkown
page readonly
clean
2D12995A000
unkown
page read and write
clean
1AC83802000
unkown
page read and write
clean
7FF5B73D9000
unkown
page readonly
clean
7FF52D10F000
unkown
page readonly
clean
15E61C76000
unkown
page read and write
clean
7FF4EEEC8000
unkown
page readonly
clean
7FF5E0DFC000
unkown
page readonly
clean
7FF524B35000
unkown
page readonly
clean
7FF5391CC000
unkown
page readonly
clean
A3E000
unkown
page read and write
clean
7FF5E0E4F000
unkown
page readonly
clean
2360000
heap private
page read and write
clean
C91907F000
unkown
page read and write
clean
19E000
stack
page read and write
clean
2357000
unkown
page readonly
clean
7FF4EF4FF000
unkown
page readonly
clean
2E7E000
unkown
page read and write
clean
7FF5E0E08000
unkown
page readonly
clean
143D6FA0000
unkown
page readonly
clean
2D12B820000
unkown
page read and write
clean
7FF539430000
unkown
page readonly
clean
2184C224000
unkown
page read and write
clean
7FF54AE49000
unkown
page readonly
clean
7FF524AB8000
unkown
page readonly
clean
7FF5E0CCD000
unkown
page readonly
clean
1AC83200000
unkown
page readonly
clean
6D0000
heap default
page read and write
clean
640000
unkown
page read and write
clean
2EB0000
unkown
page readonly
clean
27C9000
unkown
page read and write
clean
15E63AD0000
unkown
page readonly
clean
7FF5832A7000
unkown
page readonly
clean
15E63C9C000
unkown
page read and write
clean
504000
unkown
page read and write
clean
15E63E77000
unkown
page read and write
clean
21846E73000
unkown
page read and write
clean
2184C23F000
unkown
page read and write
clean
21846E9F000
unkown
page read and write
clean
A40000
unkown
page readonly
clean
B00000
unkown
page readonly
clean
A85000
unkown
page read and write
clean
7FF4FFD31000
unkown
page readonly
clean
7FF54AD42000
unkown
page readonly
clean
21CEB03B000
unkown
page read and write
clean
194000
stack
page read and write
clean
400000
unkown image
page readonly
clean
2E58000
unkown
page read and write
clean
7FF539155000
unkown
page readonly
clean
1DF6B213000
unkown
page read and write
clean
2184C780000
unkown
page read and write
clean
2184C6A0000
unkown
page readonly
clean
1AC8306E000
unkown
page read and write
clean
7F0000
heap default
page read and write
clean
2227000
unkown
page read and write
clean
27C9000
unkown
page read and write
clean
2E74000
unkown
page read and write
clean
21847759000
unkown
page read and write
clean
2E71000
unkown
page read and write
clean
61FBBFF000
unkown
page read and write
clean
7BE000
unkown
page read and write
clean
2D129829000
unkown
page read and write
clean
2235000
unkown
page readonly
clean
61FBCFF000
unkown
page read and write
clean
527000
heap default
page read and write
clean
15E64010000
unkown
page read and write
clean
21846F07000
unkown
page read and write
clean
21846CE0000
heap default
page read and write
clean
400000
unkown image
page readonly
clean
6B0000
unkown
page read and write
clean
2190000
unkown
page readonly
clean
C64396F000
unkown
page read and write
clean
7FF4EF4B2000
unkown
page readonly
clean
7FF53921F000
unkown
page readonly
clean
10023000
unkown
page readonly
clean
7FF51B34E000
unkown
page readonly
clean
10000000
unkown
page read and write
clean
27EB000
unkown
page read and write
clean
1D35727B000
unkown
page read and write
clean
A78000
unkown
page read and write
clean
15E61E50000
unkown
page readonly
clean
21CEB076000
unkown
page read and write
clean
21847702000
unkown
page read and write
clean
7FF524B9E000
unkown
page readonly
clean
7FF5E0D4C000
unkown
page readonly
clean
7FF54AE49000
unkown
page readonly
clean
27DB000
unkown
page read and write
clean
7FF58336A000
unkown
page readonly
clean
7FF5DA5B9000
unkown
page readonly
clean
7FF55646C000
unkown
page readonly
clean
C91890B000
unkown
page read and write
clean
401000
unkown image
page execute and write copy
clean
530000
unkown
page readonly
clean
2E52000
unkown
page read and write
clean
127AC5F0000
unkown
page readonly
clean
7FF539200000
unkown
page readonly
clean
15E65082000
unkown
page read and write
clean
AFF000
stack
page read and write
clean
7FF52D2BE000
unkown
page readonly
clean
2D12C010000
unkown
page read and write
clean
7FF52485E000
unkown
page readonly
clean
2298F530000
heap private
page read and write
clean
E4C2D7E000
unkown
page read and write
clean
C01000
unkown image
page readonly
clean
10332000
unkown
page read and write
clean
10338000
unkown
page read and write
clean
504000
unkown
page read and write
clean
7FF5E0C05000
unkown
page readonly
clean
7FF5E1031000
unkown
page readonly
clean
7FF58340C000
unkown
page readonly
clean
7FF5DA526000
unkown
page readonly
clean
7FF5E0DEB000
unkown
page readonly
clean
400000
unkown image
page readonly
clean
3CC4000
unkown
page read and write
clean
There are 2004 hidden memdumps, click here to show them.