IOCReport

loading gif

Files

File Path
Type
Category
Malicious
papers (71).xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1251, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Mon Feb 15 09:57:52 2021, Security: 0
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\1502[1].gif
MS-DOS executable, MZ for MS-DOS
downloaded
malicious
C:\Users\user\kdfe.vbox
MS-DOS executable, MZ for MS-DOS
dropped
malicious
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, 59134 bytes, 1 file
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
dropped
clean
C:\Users\user\AppData\Local\Temp\37CE0000
data
dropped
clean
C:\Users\user\AppData\Local\Temp\CabCFCE.tmp
Microsoft Cabinet archive data, 59134 bytes, 1 file
dropped
clean
C:\Users\user\AppData\Local\Temp\TarCFCF.tmp
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Fri Feb 26 05:38:36 2021, atime=Fri Feb 26 05:38:36 2021, length=8192, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\papers (71).LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:13 2020, mtime=Fri Feb 26 05:38:36 2021, atime=Fri Feb 26 05:38:36 2021, length=325632, window=hide
dropped
clean
C:\Users\user\Desktop\C8CE0000
Applesoft BASIC program data, first line number 16
dropped
clean
There are 2 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\kdfe.vbox,DllRegisterServer
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32 ..\kdfe.vbox,DllRegisterServer
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\SysWOW64\schtasks.exe
'C:\Windows\system32\schtasks.exe' /Create /RU 'NT AUTHORITY\SYSTEM' /tn sgovokol /tr 'regsvr32.exe -s \'C:\Users\user\kdfe.vbox\'' /SC ONCE /Z /ST 22:40 /ET 22:52
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\kdfe.vbox'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\kdfe.vbox'
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\kdfe.vbox'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\kdfe.vbox'
malicious
C:\Windows\System32\taskeng.exe
taskeng.exe {DA6299CA-95CA-4E9D-8974-2CC05321254C} S-1-5-18:NT AUTHORITY\System:Service:
clean

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://investor.msn.com/
unknown
clean
There are 1 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
remedial.aaua.edu.ng
unknown
malicious
aaua.edu.ng
104.196.7.213
clean

IPs

IP
Domain
Country
Active
Malicious
104.196.7.213
unknown
United States
unknown
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
bp4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC2E2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC60D
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC6F7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC89C
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC90A
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
pz4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\system32\qagentrt.dll,-10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-843
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-844
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\wuaueng.dll,-400
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F48C3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F4CF8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SavedLegacySettings
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Windows\SysWOW64\explorer.exe
8e79298b
clean
C:\Windows\SysWOW64\explorer.exe
bbe6f9c5
clean
C:\Windows\SysWOW64\explorer.exe
11bbedc
clean
C:\Windows\SysWOW64\explorer.exe
7c13f156
clean
C:\Windows\SysWOW64\explorer.exe
b9a7d9b9
clean
C:\Windows\SysWOW64\explorer.exe
c4af9633
clean
C:\Windows\SysWOW64\explorer.exe
35a9ea0
clean
C:\Windows\SysWOW64\explorer.exe
f130467d
clean
C:\Windows\SysWOW64\explorer.exe
8e79298b
clean
C:\Windows\System32\taskeng.exe
data
clean
There are 115 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
300000
unkown
page execute and read and write
malicious
3A0000
unkown
page execute and read and write
malicious
6EB000
unkown
page read and write
clean
28E0000
heap private
page read and write
clean
251000
unkown
page read and write
clean
600000
unkown
page readonly
clean
B4E000
unkown
page read and write
clean
90000
unkown
page readonly
clean
510000
unkown
page readonly
clean
650000
unkown
page readonly
clean
A9F000
unkown
page read and write
clean
1CC000
unkown
page read and write
clean
150000
unkown
page read and write
clean
2022000
heap private
page read and write
clean
840000
unkown
page readonly
clean
3A0000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
7C0000
unkown
page readonly
clean
63E000
unkown
page read and write
clean
14C000
unkown
page read and write
clean
640000
unkown
page readonly
clean
150000
unkown
page read and write
clean
2740000
heap private
page read and write
clean
860000
unkown
page readonly
clean
21D000
stack
page read and write
clean
7EFDF000
unkown
page read and write
clean
B70000
unkown
page readonly
clean
B60000
heap private
page read and write
clean
7EFDF000
unkown
page read and write
clean
5C7000
heap default
page read and write
clean
120000
unkown
page readonly
clean
7B0000
unkown
page readonly
clean
3F7000
heap default
page read and write
clean
29C000
unkown
page read and write
clean
27D000
stack
page read and write
clean
480000
unkown
page read and write
clean
97E000
unkown
page read and write
clean
100000
unkown
page read and write
clean
2B4000
heap private
page read and write
clean
E0000
unkown
page read and write
clean
8D0000
unkown
page readonly
clean
9C0000
heap private
page read and write
clean
CFD000
unkown
page read and write
clean
620000
heap default
page read and write
clean
20E000
heap default
page read and write
clean
20000
unkown
page readonly
clean
D6B000
heap private
page read and write
clean
6F8000
unkown
page read and write
clean
460000
unkown
page read and write
clean
1DD7000
unkown
page readonly
clean
4A0000
unkown
page read and write
clean
B64000
heap private
page read and write
clean
26CE000
stack
page read and write
clean
297000
heap default
page read and write
clean
1BF0000
unkown
page readonly
clean
1010000
unkown
page readonly
clean
370000
heap private
page read and write
clean
6D0000
unkown
page readonly
clean
1EC000
unkown
page read and write
clean
170000
unkown
page read and write
clean
2B0000
heap private
page read and write
clean
14C000
unkown
page read and write
clean
20000
unkown
page readonly
clean
5B0000
unkown
page readonly
clean
616000
heap default
page read and write
clean
1A0000
unkown
page readonly
clean
6F6000
unkown
page read and write
clean
60B000
heap default
page read and write
clean
A7000
heap default
page read and write
clean
90000
unkown
page readonly
clean
A00000
unkown
page readonly
clean
DD000
heap default
page read and write
clean
2E3000
heap default
page read and write
clean
240000
unkown
page read and write
clean
244D000
unkown
page read and write
clean
546000
unkown
page read and write
clean
6A7000
heap default
page read and write
clean
9D0000
unkown
page readonly
clean
247000
unkown
page read and write
clean
20000
unkown
page readonly
clean
B82000
heap private
page read and write
clean
624000
heap private
page read and write
clean
BD0000
unkown
page read and write
clean
254000
unkown
page read and write
clean
7DF000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
D97000
heap private
page read and write
clean
90000
unkown
page readonly
clean
180000
unkown
page readonly
clean
2C9000
heap default
page read and write
clean
363000
heap default
page read and write
clean
234000
heap private
page read and write
clean
D2D000
unkown
page read and write
clean
620000
heap private
page read and write
clean
70000
unkown
page readonly
clean
34E000
heap default
page read and write
clean
875000
heap private
page read and write
clean
60000
unkown
page readonly
clean
4D0000
unkown
page readonly
clean
396000
heap private
page read and write
clean
272F000
unkown
page read and write
clean
1FBE000
unkown
page read and write
clean
6EF000
unkown
page read and write
clean
160000
unkown
page read and write
clean
5F7000
heap default
page read and write
clean
6E5000
heap default
page read and write
clean
2DE0000
unkown
page readonly
clean
42F000
heap default
page read and write
clean
3B6000
unkown
page read and write
clean
25EF000
heap private
page read and write
clean
1090000
unkown
page write copy
clean
470000
unkown
page write copy
clean
2BE000
heap default
page read and write
clean
E0000
unkown
page read and write
clean
480000
unkown
page readonly
clean
6ED000
heap default
page read and write
clean
3F0000
heap default
page read and write
clean
160000
heap default
page read and write
clean
8EF000
heap private
page read and write
clean
AB000
unkown
page read and write
clean
630000
heap private
page read and write
clean
24F000
unkown
page read and write
clean
120000
heap private
page read and write
clean
287000
heap default
page read and write
clean
390000
unkown
page readonly
clean
317000
heap default
page read and write
clean
310000
heap default
page read and write
clean
160000
unkown
page read and write
clean
390000
heap private
page read and write
clean
590000
heap default
page read and write
clean
3D6000
unkown
page read and write
clean
3B0000
heap default
page read and write
clean
100000
unkown
page read and write
clean
A20000
unkown
page readonly
clean
124000
heap private
page read and write
clean
E6F000
unkown
page read and write
clean
27F000
unkown
page read and write
clean
480000
unkown
page read and write
clean
7A0000
unkown
page readonly
clean
4F0000
unkown
page readonly
clean
406000
unkown
page read and write
clean
414000
heap default
page read and write
clean
2387000
unkown
page readonly
clean
280000
heap default
page read and write
clean
394000
heap private
page read and write
clean
DE0000
unkown
page readonly
clean
65E000
unkown
page read and write
clean
21A0000
unkown
page readonly
clean
D90000
heap private
page read and write
clean
634000
heap private
page read and write
clean
6E3000
unkown
page read and write
clean
510000
unkown
page read and write
clean
190000
heap default
page read and write
clean
380000
unkown
page read and write
clean
2CEE000
unkown
page read and write
clean
2D8E000
unkown
page read and write
clean
830000
heap private
page read and write
clean
D0000
unkown
page read and write
clean
430000
unkown
page readonly
clean
2570000
heap private
page read and write
clean
6C4000
heap default
page read and write
clean
20000
unkown
page readonly
clean
6A0000
heap default
page read and write
clean
5C0000
heap default
page read and write
clean
220000
unkown image
page readonly
clean
A0000
heap default
page read and write
clean
D30000
heap private
page read and write
clean
893000
heap private
page read and write
clean
20000
unkown
page readonly
clean
290000
heap default
page read and write
clean
230000
heap private
page read and write
clean
380000
unkown
page read and write
clean
69E000
unkown
page read and write
clean
EB000
heap default
page read and write
clean
2B4000
heap default
page read and write
clean
26DF000
unkown
page read and write
clean
280000
unkown
page execute and read and write
clean
390000
heap private
page read and write
clean
2CF000
heap default
page read and write
clean
7EFDF000
unkown
page read and write
clean
410000
unkown
page read and write
clean
CA0000
heap private
page read and write
clean
2BF0000
unkown
page readonly
clean
25CE000
unkown
page read and write
clean
4B6000
unkown
page read and write
clean
2F5F000
unkown
page read and write
clean
25EF000
heap private
page read and write
clean
3E0000
unkown
page read and write
clean
30E000
heap default
page read and write
clean
36A000
heap default
page read and write
clean
A1F000
unkown
page read and write
clean
2004000
heap private
page read and write
clean
22A000
heap default
page read and write
clean
20000
unkown
page readonly
clean
F0000
unkown
page readonly
clean
B40000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
E6000
heap default
page read and write
clean
25EF000
heap private
page read and write
clean
D34000
heap private
page read and write
clean
1D0000
heap default
page read and write
clean
2ED000
stack
page read and write
clean
137F000
unkown
page read and write
clean
630000
unkown
page readonly
clean
2D0000
heap default
page read and write
clean
840000
heap private
page read and write
clean
20000
unkown
page readonly
clean
1AB000
unkown
page read and write
clean
223000
heap default
page read and write
clean
150000
unkown
page read and write
clean
39C000
unkown
page read and write
clean
2BFB000
unkown
page read and write
clean
2430000
unkown
page read and write
clean
2F0000
heap private
page read and write
clean
100000
unkown
page read and write
clean
2120000
heap private
page read and write
clean
1D7000
heap default
page read and write
clean
B5D000
unkown
page read and write
clean
F10000
unkown
page read and write
clean
4FC000
unkown
page read and write
clean
670000
unkown
page readonly
clean
5E4000
heap default
page read and write
clean
25EF000
heap private
page read and write
clean
2DDF000
unkown
page read and write
clean
3AE000
stack
page read and write
clean
29D000
unkown
page read and write
clean
3B6000
unkown
page read and write
clean
6CE000
unkown
page read and write
clean
CA0000
unkown
page readonly
clean
27E0000
unkown
page readonly
clean
780000
heap private
page read and write
clean
850000
unkown
page readonly
clean
20000
unkown
page readonly
clean
244000
heap default
page read and write
clean
120000
heap private
page read and write
clean
3F0000
unkown
page readonly
clean
150000
unkown
page read and write
clean
446000
unkown
page read and write
clean
D5F000
stack
page read and write
clean
BD0000
unkown
page write copy
clean
800000
heap private
page read and write
clean
2000000
heap private
page read and write
clean
429000
heap default
page read and write
clean
2D7000
heap default
page read and write
clean
26E0000
unkown
page read and write
clean
130000
unkown
page execute and read and write
clean
2040000
unkown
page readonly
clean
60000
unkown
page readonly
clean
6F2000
unkown
page read and write
clean
870000
heap private
page read and write
clean
846000
heap private
page read and write
clean
5FD000
heap default
page read and write
clean
950000
unkown
page readonly
clean
2920000
unkown
page readonly
clean
CE0000
unkown
page read and write
clean
374000
heap private
page read and write
clean
There are 246 hidden memdumps, click here to show them.