IOCReport

loading gif

Files

File Path
Type
Category
Malicious
document-1771131239.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Thu Apr 1 10:53:30 2021, Security: 0
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\0104[1].gif
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
downloaded
malicious
C:\Users\user\fikftkm.thj
HTML document, ASCII text, with very long lines
dropped
malicious
C:\Users\user\fikftkm.thj2
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, 58596 bytes, 1 file
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E0F5C59F9FA661F6F4C50B87FEF3A15A
data
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E0F5C59F9FA661F6F4C50B87FEF3A15A
data
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{0D6695CC-9529-11EB-ADCF-ECF4BBB5915B}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{CCF30F48-9528-11EB-ADCF-ECF4BBB5915B}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{E7092821-9528-11EB-ADCF-ECF4BBB5915B}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{0D6695CE-9529-11EB-ADCF-ECF4BBB5915B}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{0D6695D0-9529-11EB-ADCF-ECF4BBB5915B}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{0D6695D2-9529-11EB-ADCF-ECF4BBB5915B}.dat
Microsoft Word Document
modified
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{CCF30F4A-9528-11EB-ADCF-ECF4BBB5915B}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{E7092823-9528-11EB-ADCF-ECF4BBB5915B}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\lr5drzg\imagestore.dat
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5JC0A1KN\HdepnBaFj-yarvouFUIlfV4Q9D8.gz[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5JC0A1KN\NGDGShwgz5vCvyjNFyZiaPlHGCE.gz[1].js
ASCII text, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5JC0A1KN\Xp-HPHGHOZznHBwdn7OWdva404Y.gz[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5JC0A1KN\dnserror[1]
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5JC0A1KN\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5JC0A1KN\n8-O_KIRNSMPFWQWrGjn0BRH6SM.gz[1].js
UTF-8 Unicode text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5JC0A1KN\ozS3T0fsBUPZy4zlY0UX_e0TUwY.gz[1].js
ASCII text, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\2BKDOK08[1].htm
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\4JDAW1W1.htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\5rqGloMo94v3vwNVR5OsxDNd8d0[1].svg
SVG Scalable Vector Graphics image
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\JDHEvZVDnqsG9UcxzgIdtGb6thw.gz[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\MstqcgNaYngCBavkktAoSE0--po.gz[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\ULJCe4CXM2DCjZgELMGm2K4PcPo[1].png
PNG image data, 1642 x 116, 8-bit colormap, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\favicon[1].ico
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\suspendedpage[1].htm
HTML document, ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\P3LN8DHh0udC9Pbh8UHnw5FJ8R8.gz[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\eRYlUYIMYsB_Pt8B7FTik-pl5cs.gz[1].js
ASCII text, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\favicon[1].ico
MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\hsq54HXv3E6bOWi_58PaE6vwTYM.gz[1].js
exported SGML document, ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\6sxhavkE4_SZHA_K4rwWmg67vF0.gz[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\NewErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\aU[1].htm
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\bLULVERLX4vU6bjspboNMw9vl_0.gz[1].js
very short file (no magic)
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\eaMqCdNxIXjLc0ATep7tsFkfmSA.gz[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\th[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 0x0, segment length 16, baseline, precision 8, 1920x1080, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\urlblockindex[1].bin
data
downloaded
clean
C:\Users\user\AppData\Local\Temp\05CE0000
data
dropped
clean
C:\Users\user\AppData\Local\Temp\CabCD4F.tmp
Microsoft Cabinet archive data, 58596 bytes, 1 file
dropped
clean
C:\Users\user\AppData\Local\Temp\TarCD50.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF0AFF9FFD650E40F3.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF0D3E41F0F821E6BD.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF0F9755593861B3EA.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF2ABEE36455B94053.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF41F1857FFE330BCF.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF56A129262371E0A4.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF7CF03B8C0F417635.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFFB4690FF7436F266.TMP
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Sun Apr 4 08:32:35 2021, atime=Sun Apr 4 08:32:35 2021, length=12288, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\document-1771131239.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:12 2020, mtime=Sun Apr 4 08:32:35 2021, atime=Sun Apr 4 08:32:36 2021, length=185344, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\14HKUKTQ.txt
ASCII text
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\2SCY25TS.txt
ASCII text
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\460PAFDF.txt
ASCII text
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\6AQYXAJN.txt
ASCII text
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\6PRKYCQ0.txt
ASCII text
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\B711W0F3.txt
ASCII text
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\D3LSEQT1.txt
ASCII text
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\FO92LQA2.txt
ASCII text
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J31WUCBG.txt
ASCII text
downloaded
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\N904USWI.txt
ASCII text
downloaded
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\RYK07S53.txt
ASCII text
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\UIKK4OT4.txt
ASCII text
downloaded
clean
C:\Users\user\Desktop\D5CE0000
Applesoft BASIC program data, first line number 16
dropped
clean
There are 62 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\fikftkm.thj,DllRegisterServer
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\fikftkm.thj1,DllRegisterServer
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\fikftkm.thj2,DllRegisterServer
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32 ..\fikftkm.thj2,DllRegisterServer
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\fikftkm.thj3,DllRegisterServer
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\fikftkm.thj4,DllRegisterServer
malicious
C:\Program Files\Internet Explorer\iexplore.exe
'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:620 CREDAT:275457 /prefetch:2
clean
C:\Program Files\Internet Explorer\iexplore.exe
'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:3064 CREDAT:275457 /prefetch:2
clean
C:\Program Files\Internet Explorer\iexplore.exe
'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:972 CREDAT:275457 /prefetch:2
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:972 CREDAT:603152 /prefetch:2
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:972 CREDAT:1520647 /prefetch:2
clean
There are 5 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://urs-world.com/joomla/DzJ1zVBWb/1fmYW7HPNqRQhz6Za_2F/CEQgEHh67hkPdvwOSdi/nEqyJXm1CwTWVs2C
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://investor.msn.com/
unknown
clean
http://urs-world.com/joomla/DzJ1zVBWb/1fmYW7HPNqRQhz6Za_2F/CEQgEHh67hkPdvwOSdi/nEqyJXm1CwTWVs2C_2Fr_2/BvjUBKxN9qSpN/cMrTRJ9N/ryJsB4qGY2XHLtxrLDi6xNR/Qw5QsDCu2a/1byqzLlxunqNEdxwm/2jiPBdqZB0a1/q3egY2VhZv3/_2B8x5gL2kXG3P/aL1YXODRbtNtTkBrj3PS7/G.akk
185.186.244.95
clean
http://urs-world.com/joomla/nFzk0Q7K/E1_2F1CEOHcU967kDpuCuCt/FPWRV6etYO/3uHaVD2_2B5fz4cnT/KUnSOvHj3DDx/LEjym6jOHzl/FeVIuhKblVVnxm/VI6rPV0WA0nCSJBKKjggZ/tlqJBc8y5_2Bbir_/2BCa9ubsQQgGaAg/T_2BNOyNXybfs33Qg4/rm7s6e4PI/6eyckn37N5jlypeo4jei/kAPiG95T_2BrCVeX6k0/F0E8zUcKkiS/aU.akk
185.186.244.95
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://urs-world.com/joomla/3aDSi90Odm4t/ZQseS7mEKQ6/SSE8Q3crCb0l7w/wIvpan0x1HXuZM3ORESMa/ajJiFPV258iNRovg/KQl9frzLJWGuawc/zcW8IHCp_2F8n02ZSX/SkuilVzI4/iu_2BjoqlDfmKu_2BuVf/kGitIl_2Bi7_2Fz9R6X/Y0sd4k8W3UrfPrzXwVLvdK/7G4iHN0OcM5_2/FPqyROS_/2BKDOK08.akk
185.186.244.95
clean
http://urs-world.com/favicon.ico
185.186.244.95
clean
There are 3 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
urs-world.com
185.186.244.95
malicious
accesslinksgroup.com
192.185.129.4
malicious
under17.com
185.243.114.196
malicious
mundotecnologiasolar.com
162.241.62.4
clean
ponchokhana.com
5.100.155.169
clean
vts.us.com
207.174.213.126
clean
comosairdoburaco.com.br
198.50.218.68
clean
login.microsoftonline.com
unknown
clean

IPs

IP
Domain
Country
Malicious
185.243.114.196
under17.com
Netherlands
malicious
192.185.129.4
accesslinksgroup.com
United States
malicious
185.186.244.95
urs-world.com
Netherlands
malicious
207.174.213.126
vts.us.com
United States
clean
162.241.62.4
mundotecnologiasolar.com
United States
clean
5.100.155.169
ponchokhana.com
United Kingdom
clean
198.50.218.68
comosairdoburaco.com.br
Canada
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
*(3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC053
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC330
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC478
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC5A0
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC6A9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
233
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\system32\qagentrt.dll,-10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-843
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-844
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\wuaueng.dll,-400
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
104FC5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
105C72
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SavedLegacySettings
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Internet Explorer\iexplore.exe
{CCF30F48-9528-11EB-ADCF-ECF4BBB5915B}
clean
C:\Program Files\Internet Explorer\iexplore.exe
NextCheckForUpdateLowDateTime
clean
C:\Program Files\Internet Explorer\iexplore.exe
NextCheckForUpdateHighDateTime
clean
C:\Program Files\Internet Explorer\iexplore.exe
SavedLegacySettings
clean
C:\Program Files\Internet Explorer\iexplore.exe
Count
clean
C:\Program Files\Internet Explorer\iexplore.exe
Time
clean
C:\Program Files\Internet Explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\Internet Explorer\iexplore.exe
NextCheckForUpdateLowDateTime
clean
C:\Program Files\Internet Explorer\iexplore.exe
NextCheckForUpdateHighDateTime
clean
C:\Program Files\Internet Explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\Internet Explorer\iexplore.exe
LastProcessed
clean
C:\Program Files\Internet Explorer\iexplore.exe
NavTimeArray
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
SavedLegacySettings
clean
C:\Program Files\Internet Explorer\iexplore.exe
{E7092821-9528-11EB-ADCF-ECF4BBB5915B}
clean
C:\Program Files\Internet Explorer\iexplore.exe
ChangeNotice
clean
C:\Program Files\Internet Explorer\iexplore.exe
FaviconPath
clean
C:\Program Files\Internet Explorer\iexplore.exe
SavedLegacySettings
clean
C:\Program Files\Internet Explorer\iexplore.exe
Count
clean
C:\Program Files\Internet Explorer\iexplore.exe
Time
clean
C:\Program Files\Internet Explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\Internet Explorer\iexplore.exe
88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977
clean
C:\Program Files\Internet Explorer\iexplore.exe
2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81
clean
C:\Program Files\Internet Explorer\iexplore.exe
88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977
clean
C:\Program Files\Internet Explorer\iexplore.exe
2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81
clean
C:\Program Files\Internet Explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\Internet Explorer\iexplore.exe
LastProcessed
clean
C:\Program Files\Internet Explorer\iexplore.exe
NavTimeArray
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
SavedLegacySettings
clean
C:\Program Files\Internet Explorer\iexplore.exe
{0D6695CC-9529-11EB-ADCF-ECF4BBB5915B}
clean
C:\Program Files\Internet Explorer\iexplore.exe
SavedLegacySettings
clean
C:\Program Files\Internet Explorer\iexplore.exe
Count
clean
C:\Program Files\Internet Explorer\iexplore.exe
Time
clean
C:\Program Files\Internet Explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\Internet Explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\Internet Explorer\iexplore.exe
LastProcessed
clean
C:\Program Files\Internet Explorer\iexplore.exe
Window_Placement
clean
C:\Program Files\Internet Explorer\iexplore.exe
Count
clean
C:\Program Files\Internet Explorer\iexplore.exe
Time
clean
C:\Program Files\Internet Explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\Internet Explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\Internet Explorer\iexplore.exe
LastProcessed
clean
C:\Program Files\Internet Explorer\iexplore.exe
NavTimeArray
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
SavedLegacySettings
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
SavedLegacySettings
clean
There are 158 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
2DD8000
heap private
page read and write
malicious
2C5B000
heap private
page read and write
malicious
2B5D000
heap private
page read and write
malicious
240000
unkown
page read and write
malicious
2A5F000
heap private
page read and write
malicious
2F0000
unkown
page read and write
clean
2A50000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
28C6000
unkown
page readonly
clean
60000
unkown
page readonly
clean
20000
unkown
page readonly
clean
2945000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2902000
unkown
page readonly
clean
110000
unkown
page readonly
clean
60000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2724000
unkown
page readonly
clean
2A0000
unkown
page write copy
clean
26E2000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
340000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
1CE0000
unkown
page readonly
clean
2802000
unkown
page readonly
clean
2109000
heap private
page read and write
clean
2959000
unkown
page readonly
clean
2905000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
B2F000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
1A4000
heap private
page read and write
clean
450000
unkown
page write copy
clean
580000
unkown
page readonly
clean
2080000
unkown
page readonly
clean
2AD2000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
28CE000
unkown
page read and write
clean
21C0000
heap private
page read and write
clean
35A2000
unkown
page read and write
clean
2CD0000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2528000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
4EA000
unkown
page read and write
clean
280D000
unkown
page readonly
clean
2220000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2889000
unkown
page readonly
clean
2C90000
heap private
page read and write
clean
25E8000
unkown
page readonly
clean
5C0000
unkown
page readonly
clean
60000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2D05000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2896000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
1B0000
heap private
page read and write
clean
2D59000
heap private
page read and write
clean
2622000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
5B4000
heap private
page read and write
clean
31D000
unkown
page read and write
clean
160000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
29DE000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
1E97000
unkown
page readonly
clean
2795000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
28D9000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
231F000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2240000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2779000
heap private
page read and write
clean
2975000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
28D6000
unkown
page readonly
clean
F0000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
2960000
heap private
page read and write
clean
2B70000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
1B30000
unkown
page readonly
clean
22A0000
unkown
page readonly
clean
400000
unkown
page readonly
clean
10001000
unkown image
page execute and read and write
clean
2400000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
23BE000
unkown
page read and write
clean
474000
heap default
page read and write
clean
2824000
unkown
page readonly
clean
2205000
heap private
page read and write
clean
2859000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2CCB000
heap private
page read and write
clean
2949000
unkown
page readonly
clean
1DB000
unkown
page read and write
clean
3FB000
heap default
page read and write
clean
30CD000
unkown
page read and write
clean
2B45000
heap private
page read and write
clean
27F8000
heap private
page read and write
clean
28B5000
unkown
page readonly
clean
58E000
unkown
page read and write
clean
38E000
heap default
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2722000
unkown
page readonly
clean
2FE0000
unkown
page read and write
clean
2000000
heap private
page read and write
clean
3B0000
heap default
page read and write
clean
2F0000
unkown
page read and write
clean
2765000
unkown
page readonly
clean
3F6000
heap default
page read and write
clean
3CE000
heap default
page read and write
clean
2324000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
28C5000
unkown
page readonly
clean
C1F000
unkown
page read and write
clean
25E2000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
310000
unkown
page read and write
clean
4C6000
unkown
page read and write
clean
27C5000
unkown
page readonly
clean
290000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
D0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
8B000
unkown
page read and write
clean
2875000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
14C000
unkown
page read and write
clean
27C4000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
256000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
1B7000
heap default
page read and write
clean
2280000
unkown
page readonly
clean
28E9000
unkown
page readonly
clean
25A2000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
311000
unkown
page execute read
clean
2889000
unkown
page readonly
clean
31C000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
20000
unkown
page readonly
clean
190000
heap private
page read and write
clean
160000
unkown
page read and write
clean
10A000
unkown
page read and write
clean
2812000
unkown
page readonly
clean
2965000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
27A2000
unkown
page readonly
clean
28F5000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
5C0000
unkown
page readonly
clean
770000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
28A5000
unkown
page readonly
clean
3050000
unkown
page read and write
clean
440000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
33B1000
unkown
page read and write
clean
28A2000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
3F0000
heap private
page read and write
clean
2782000
unkown
page readonly
clean
2832000
unkown
page readonly
clean
D0000
unkown
page read and write
clean
2F70000
unkown
page read and write
clean
1CB0000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
3B7000
heap default
page read and write
clean
2B30000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
27E5000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
31B0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
1D60000
unkown
page readonly
clean
48D000
heap default
page read and write
clean
290D000
unkown
page readonly
clean
27E4000
unkown
page readonly
clean
310000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2185000
heap private
page read and write
clean
27D2000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
346000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
1E0000
unkown
page execute and read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
34B0000
unkown
page read and write
clean
27E2000
unkown
page readonly
clean
1EE000
heap default
page read and write
clean
550000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
960000
unkown
page readonly
clean
2882000
unkown
page readonly
clean
30B0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2C6000
unkown
page read and write
clean
35A0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
27E000
heap default
page read and write
clean
F0000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
10000000
unkown image
page readonly
clean
2942000
unkown
page readonly
clean
2B40000
heap private
page read and write
clean
33B0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2822000
unkown
page readonly
clean
27A6000
unkown
page readonly
clean
2A53000
heap private
page read and write
clean
1B0000
heap default
page read and write
clean
220000
unkown
page read and write
clean
20000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
2919000
unkown
page readonly
clean
27E4000
unkown
page readonly
clean
7C0000
unkown
page readonly
clean
180000
unkown
page read and write
clean
1F47000
unkown
page readonly
clean
1B20000
unkown
page readonly
clean
2776000
unkown
page readonly
clean
21A0000
unkown
page readonly
clean
2D3B000
heap private
page read and write
clean
2722000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2DD8000
heap private
page read and write
clean
2815000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
20F5000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2040000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
240000
heap default
page read and write
clean
2F0000
unkown
page read and write
clean
2522000
unkown
page readonly
clean
228C000
unkown
page read and write
clean
2822000
unkown
page readonly
clean
25A8000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2DDA000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
2909000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
490000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
27F6000
unkown
page readonly
clean
2C55000
heap private
page read and write
clean
28A6000
unkown
page readonly
clean
2B0000
unkown
page read and write
clean
288D000
unkown
page readonly
clean
27D6000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2836000
unkown
page readonly
clean
1FD0000
heap private
page read and write
clean
2909000
unkown
page readonly
clean
32B0000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
2C95000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
F4000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2855000
unkown
page readonly
clean
2885000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
29A5000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2826000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2B7B000
heap private
page read and write
clean
2B50000
unkown
page readonly
clean
357000
heap default
page read and write
clean
20C0000
unkown
page readonly
clean
170000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
2852000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
442000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
740000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2189000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
2809000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
5B0000
heap private
page read and write
clean
28B2000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2E6000
unkown
page read and write
clean
2C8B000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
33AE000
unkown
page read and write
clean
27E2000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
1D0000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
24E000
heap default
page read and write
clean
27B2000
unkown
page readonly
clean
2AF0000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
26E2000
unkown
page readonly
clean
710000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
28F5000
unkown
page readonly
clean
1F00000
unkown
page write copy
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2762000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
1B60000
unkown
page readonly
clean
20000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2886000
unkown
page readonly
clean
2105000
heap private
page read and write
clean
3651000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
20F9000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
28D2000
unkown
page readonly
clean
2806000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2845000
unkown
page readonly
clean
27A4000
unkown
page readonly
clean
2912000
unkown
page readonly
clean
194000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
397000
heap default
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2100000
heap private
page read and write
clean
2B30000
unkown
page read and write
clean
28A2000
unkown
page readonly
clean
2D10000
unkown
page readonly
clean
23D000
unkown
page execute and read and write
clean
32B4000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2A92000
unkown
page readonly
clean
10000000
unkown image
page readonly
clean
2628000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2B90000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2875000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
60000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2865000
unkown
page readonly
clean
2A12000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
286E000
unkown
page read and write
clean
26A2000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
640000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
270000
heap default
page read and write
clean
60000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2320000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
28CD000
unkown
page readonly
clean
350000
heap default
page read and write
clean
3F4000
heap private
page read and write
clean
E0000
unkown
page read and write
clean
20000
unkown
page readonly
clean
2842000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
217000
heap default
page read and write
clean
340000
unkown
page read and write
clean
27F5000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
1A0000
unkown
page readonly
clean
2B10000
unkown
page readonly
clean
223D000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2929000
unkown
page readonly
clean
22CE000
unkown
page read and write
clean
2856000
unkown
page readonly
clean
2982000
unkown
page readonly
clean
1C0000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2872000
unkown
page readonly
clean
2180000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
410000
unkown
page readonly
clean
487000
heap default
page read and write
clean
2922000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2784000
unkown
page readonly
clean
2BC0000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
247000
heap default
page read and write
clean
2F0000
unkown
page read and write
clean
3ED000
heap default
page read and write
clean
2F0000
unkown
page read and write
clean
2A70000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2935000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2866000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
21BE000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2704000
unkown
page readonly
clean
457000
heap default
page read and write
clean
2180000
unkown
page readonly
clean
2825000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
28D000
unkown
page read and write
clean
2862000
unkown
page readonly
clean
2209000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2DE0000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2D00000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
2342000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
1EC7000
unkown
page readonly
clean
510000
heap private
page read and write
clean
2B10000
unkown
page readonly
clean
450000
heap default
page read and write
clean
28E2000
unkown
page readonly
clean
D0000
unkown
page read and write
clean
2B12000
unkown
page readonly
clean
210000
heap default
page read and write
clean
2906000
unkown
page readonly
clean
760000
unkown
page readonly
clean
32D2000
heap private
page read and write
clean
2804000
unkown
page readonly
clean
1A0000
heap private
page read and write
clean
2895000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
26E4000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2200000
unkown
page readonly
clean
28C5000
unkown
page readonly
clean
2B50000
unkown
page readonly
clean
21B000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2622000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
28E2000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
27E2000
unkown
page readonly
clean
2829000
unkown
page readonly
clean
2AD0000
unkown
page readonly
clean
28C9000
unkown
page readonly
clean
376000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
260000
heap private
page read and write
clean
2802000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
20000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
174000
heap private
page read and write
clean
27A2000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2852000
unkown
page readonly
clean
2A90000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
1D7000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
40E000
unkown
page read and write
clean
32E4000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
1D07000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2CA0000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2752000
unkown
page readonly
clean
27A4000
unkown
page readonly
clean
2876000
unkown
page readonly
clean
6BF000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
290E000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2882000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2B70000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
29C000
unkown
page read and write
clean
390000
unkown
page execute read
clean
2925000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2952000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
150000
unkown
page read and write
clean
1F10000
unkown
page write copy
clean
44D000
unkown
page read and write
clean
590000
unkown
page readonly
clean
336E000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
20F0000
heap private
page read and write
clean
28A9000
unkown
page readonly
clean
2200000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
1F8000
unkown
page execute and read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
390000
heap default
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2C50000
heap private
page read and write
clean
2845000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
27C2000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
1D47000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
110000
unkown
page readonly
clean
190000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
EB000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
1D17000
unkown
page readonly
clean
10005000
unkown image
page execute and read and write
clean
2F0000
unkown
page read and write
clean
2764000
unkown
page readonly
clean
590000
unkown
page readonly
clean
29E0000
heap private
page read and write
clean
2D80000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2702000
unkown
page readonly
clean
60000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2260000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
31F000
unkown
page readonly
clean
2989000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2782000
unkown
page readonly
clean
There are 635 hidden memdumps, click here to show them.