IOCReport

loading gif

Files

File Path
Type
Category
Malicious
document-1055791644.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1251, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Mon Feb 8 08:27:11 2021, Security: 0
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\0702[1].gif
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
downloaded
malicious
C:\Users\user\iojhsfgv.dvers
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, 58596 bytes, 1 file
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E0F5C59F9FA661F6F4C50B87FEF3A15A
data
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E0F5C59F9FA661F6F4C50B87FEF3A15A
data
dropped
clean
C:\Users\user\AppData\Local\Temp\06DE0000
data
dropped
clean
C:\Users\user\AppData\Local\Temp\CabE310.tmp
Microsoft Cabinet archive data, 58596 bytes, 1 file
dropped
clean
C:\Users\user\AppData\Local\Temp\TarE311.tmp
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Wed Apr 7 00:40:40 2021, atime=Wed Apr 7 00:40:40 2021, length=8192, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\document-1055791644.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:15 2020, mtime=Wed Apr 7 00:40:40 2021, atime=Wed Apr 7 00:40:40 2021, length=323072, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
modified
clean
C:\Users\user\Desktop\C7DE0000
Applesoft BASIC program data, first line number 16
dropped
clean
There are 4 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\iojhsfgv.dvers,DllRegisterServer
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32 ..\iojhsfgv.dvers,DllRegisterServer
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\SysWOW64\schtasks.exe
'C:\Windows\system32\schtasks.exe' /Create /RU 'NT AUTHORITY\SYSTEM' /tn wwzkbggu /tr 'regsvr32.exe -s \'C:\Users\user\iojhsfgv.dvers\'' /SC ONCE /Z /ST 18:42 /ET 18:54
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\iojhsfgv.dvers'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\iojhsfgv.dvers'
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\iojhsfgv.dvers'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\iojhsfgv.dvers'
malicious
C:\Windows\System32\taskeng.exe
taskeng.exe {E6DEB525-2047-4F0F-A2D9-FEDA7F895D14} S-1-5-18:NT AUTHORITY\System:Service:
clean

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://investor.msn.com/
unknown
clean
There are 1 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
tidymasters.com.au
103.50.162.157
clean

IPs

IP
Domain
Country
Malicious
103.50.162.157
tidymasters.com.au
India
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
$*3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED1FF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED597
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED77B
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED817
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
}53
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\system32\qagentrt.dll,-10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-843
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-844
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\wuaueng.dll,-400
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F46B1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F46FF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 21
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SavedLegacySettings
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F46B1
clean
C:\Windows\SysWOW64\explorer.exe
5650f5b8
clean
C:\Windows\SysWOW64\explorer.exe
63cf25f6
clean
C:\Windows\SysWOW64\explorer.exe
d93262ef
clean
C:\Windows\SysWOW64\explorer.exe
a43a2d65
clean
C:\Windows\SysWOW64\explorer.exe
618e058a
clean
C:\Windows\SysWOW64\explorer.exe
1c864a00
clean
C:\Windows\SysWOW64\explorer.exe
db734293
clean
C:\Windows\SysWOW64\explorer.exe
29199a4e
clean
C:\Windows\SysWOW64\explorer.exe
5650f5b8
clean
C:\Windows\System32\taskeng.exe
data
clean
There are 117 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
420000
unkown
page execute and read and write
malicious
230000
unkown
page execute and read and write
malicious
3E0000
unkown
page execute and read and write
malicious
80000
unkown
page execute and read and write
malicious
710000
unkown
page readonly
clean
8FA000
unkown image
page write copy
clean
13B000
unkown
page read and write
clean
985000
unkown
page read and write
clean
43D000
unkown
page read and write
clean
278F000
unkown
page read and write
clean
1E07000
unkown
page readonly
clean
3062000
unkown
page readonly
clean
D40000
unkown
page readonly
clean
467000
heap default
page read and write
clean
B0D000
unkown
page read and write
clean
27E5000
heap private
page read and write
clean
510000
heap private
page read and write
clean
8A1000
unkown image
page execute read
clean
3E4000
unkown
page read and write
clean
500000
unkown
page readonly
clean
4E0000
heap default
page read and write
clean
2924000
heap private
page read and write
clean
2E0000
heap private
page read and write
clean
994000
unkown
page read and write
clean
3A0000
heap default
page read and write
clean
3A0000
unkown
page write copy
clean
51F000
unkown
page read and write
clean
19C000
unkown
page read and write
clean
780000
unkown
page readonly
clean
285F000
heap private
page read and write
clean
1CC000
unkown
page read and write
clean
729000
heap default
page read and write
clean
460000
heap default
page read and write
clean
367000
heap default
page read and write
clean
345F000
stack
page read and write
clean
22D0000
unkown
page readonly
clean
3250000
unkown
page readonly
clean
3D4000
heap default
page read and write
clean
8A0000
unkown image
page readonly
clean
C0000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
14BD000
unkown
page read and write
clean
3E1000
unkown
page read and write
clean
ED0000
unkown
page readonly
clean
274000
heap private
page read and write
clean
2D08000
unkown
page readonly
clean
90000
unkown
page readonly
clean
370000
unkown
page read and write
clean
20000
unkown
page readonly
clean
3A0000
heap default
page read and write
clean
3DF000
unkown
page read and write
clean
998000
unkown
page read and write
clean
270000
heap default
page read and write
clean
340000
unkown
page read and write
clean
200000
heap private
page read and write
clean
350000
heap private
page read and write
clean
4F4000
heap private
page read and write
clean
20000
unkown
page readonly
clean
361E000
unkown
page read and write
clean
536000
unkown
page read and write
clean
206000
unkown
page read and write
clean
31F000
heap private
page read and write
clean
353000
heap default
page read and write
clean
560000
unkown
page readonly
clean
3BA000
heap default
page read and write
clean
330000
heap private
page read and write
clean
6F0000
heap private
page read and write
clean
2F32000
unkown
page readonly
clean
2DEF000
unkown
page read and write
clean
110000
unkown
page read and write
clean
BB0000
unkown
page readonly
clean
AFF000
unkown
page read and write
clean
24F0000
unkown
page readonly
clean
646000
unkown
page read and write
clean
C50000
heap private
page read and write
clean
E2F000
unkown
page read and write
clean
2F45000
unkown
page readonly
clean
292B000
heap private
page read and write
clean
2F62000
unkown
page readonly
clean
130000
heap private
page read and write
clean
3055000
unkown
page readonly
clean
2840000
unkown
page read and write
clean
60000
unkown
page readonly
clean
2F02000
unkown
page readonly
clean
4D0000
unkown
page readonly
clean
98A000
heap default
page read and write
clean
34CE000
unkown
page read and write
clean
ED000
stack
page read and write
clean
2390000
unkown
page readonly
clean
C54000
heap private
page read and write
clean
72F000
heap default
page read and write
clean
436000
unkown
page read and write
clean
39E000
heap default
page read and write
clean
100000
unkown
page read and write
clean
60000
unkown
page readonly
clean
3025000
unkown
page readonly
clean
1D0000
unkown
page read and write
clean
890000
unkown
page readonly
clean
1D0000
unkown
page execute and read and write
clean
499000
heap default
page read and write
clean
170000
unkown
page readonly
clean
110000
heap private
page read and write
clean
2800000
heap private
page read and write
clean
60000
unkown
page readonly
clean
3085000
unkown
page readonly
clean
E0000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
3A0000
unkown image
page readonly
clean
714000
heap default
page read and write
clean
320000
heap default
page read and write
clean
2AE000
heap default
page read and write
clean
3002000
unkown
page readonly
clean
49F000
heap default
page read and write
clean
3D0000
unkown
page readonly
clean
C8B000
heap private
page read and write
clean
27C000
unkown
page read and write
clean
3032000
unkown
page readonly
clean
27E0000
heap private
page read and write
clean
6E0000
unkown
page readonly
clean
70000
unkown
page readonly
clean
947000
heap default
page read and write
clean
20000
unkown
page readonly
clean
200000
unkown
page read and write
clean
300000
heap default
page read and write
clean
20000
unkown
page readonly
clean
236000
unkown
page read and write
clean
2F75000
unkown
page readonly
clean
360000
heap default
page read and write
clean
9B0000
heap private
page read and write
clean
7F0000
unkown
page readonly
clean
2D02000
unkown
page readonly
clean
4A4000
heap default
page read and write
clean
D0000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
2BC000
stack
page read and write
clean
514000
heap private
page read and write
clean
27EA000
unkown
page read and write
clean
100000
unkown
page readonly
clean
D0000
unkown
page read and write
clean
114000
heap private
page read and write
clean
6A0000
unkown
page readonly
clean
520000
heap private
page read and write
clean
98F000
heap default
page read and write
clean
2EE2000
unkown
page readonly
clean
98D000
unkown
page read and write
clean
A90000
unkown
page read and write
clean
2F86000
unkown
page readonly
clean
204000
heap private
page read and write
clean
3270000
unkown
page readonly
clean
610000
unkown
page read and write
clean
30E000
heap default
page read and write
clean
3B3000
heap default
page read and write
clean
A50000
heap private
page read and write
clean
2A20000
unkown
page readonly
clean
101C000
unkown
page read and write
clean
400000
unkown
page read and write
clean
BA6000
heap private
page read and write
clean
524000
heap private
page read and write
clean
D10000
unkown
page readonly
clean
700000
unkown
page readonly
clean
20000
unkown
page readonly
clean
BF0000
unkown image
page write copy
clean
989000
unkown
page read and write
clean
2FD5000
unkown
page readonly
clean
2FED000
unkown
page readonly
clean
600000
heap private
page read and write
clean
991000
unkown
page read and write
clean
2FB6000
unkown
page readonly
clean
8BE000
unkown
page read and write
clean
8A0000
unkown image
page readonly
clean
890000
unkown
page readonly
clean
EEF000
unkown
page read and write
clean
24B4000
heap private
page read and write
clean
120000
unkown
page readonly
clean
BAD000
unkown
page read and write
clean
BA0000
heap private
page read and write
clean
140000
unkown
page readonly
clean
137000
heap private
page read and write
clean
484000
heap default
page read and write
clean
487000
heap default
page read and write
clean
33EE000
stack
page read and write
clean
BA0000
heap private
page read and write
clean
1D0000
unkown
page read and write
clean
940000
heap default
page read and write
clean
8F6000
unkown image
page read and write
clean
3EB000
heap default
page read and write
clean
3069000
unkown
page readonly
clean
2FE9000
unkown
page readonly
clean
16C000
unkown
page read and write
clean
2EE4000
unkown
page readonly
clean
170000
heap private
page read and write
clean
4B7000
heap default
page read and write
clean
7EFDF000
unkown
page read and write
clean
6F7000
heap default
page read and write
clean
2D0000
heap default
page read and write
clean
1C8000
unkown
page read and write
clean
1FB000
unkown
page read and write
clean
2F92000
unkown
page readonly
clean
987000
heap default
page read and write
clean
307000
heap default
page read and write
clean
5FE000
unkown
page read and write
clean
2FC2000
unkown
page readonly
clean
35BE000
stack
page read and write
clean
D00000
heap private
page read and write
clean
2D7E000
unkown
page read and write
clean
BF0000
unkown
page write copy
clean
1120000
unkown
page readonly
clean
1C20000
unkown
page readonly
clean
16C000
unkown
page read and write
clean
4F0000
heap private
page read and write
clean
500000
unkown
page read and write
clean
6F0000
heap default
page read and write
clean
600000
unkown
page readonly
clean
3A6000
unkown
page read and write
clean
3DD000
heap default
page read and write
clean
170000
unkown
page readonly
clean
4BD000
heap default
page read and write
clean
160000
unkown
page readonly
clean
8FB000
unkown image
page readonly
clean
24D2000
heap private
page read and write
clean
80000
unkown
page read and write
clean
21A0000
heap private
page read and write
clean
F0000
unkown
page read and write
clean
E0000
unkown
page write copy
clean
1CD000
unkown
page read and write
clean
354000
heap private
page read and write
clean
206000
unkown
page read and write
clean
6F6000
heap private
page read and write
clean
E0000
unkown
page read and write
clean
2F04000
unkown
page readonly
clean
BCF000
unkown
page read and write
clean
3E8000
heap default
page read and write
clean
604000
heap private
page read and write
clean
F0000
unkown
page read and write
clean
B90000
unkown
page read and write
clean
3E6000
heap default
page read and write
clean
2EC2000
unkown
page readonly
clean
86E000
unkown
page read and write
clean
680000
unkown
page readonly
clean
3009000
unkown
page readonly
clean
2A1E000
unkown
page read and write
clean
1FB0000
unkown
page readonly
clean
2960000
unkown
page readonly
clean
3620000
unkown
page readonly
clean
730000
unkown
page readonly
clean
8FF000
unkown
page read and write
clean
28F0000
unkown
page read and write
clean
2803000
heap private
page read and write
clean
360000
heap default
page read and write
clean
277000
heap default
page read and write
clean
24B0000
heap private
page read and write
clean
20000
unkown
page readonly
clean
100000
unkown
page read and write
clean
2C0000
unkown
page read and write
clean
3D7000
unkown
page read and write
clean
99A000
unkown
page read and write
clean
480000
heap default
page read and write
clean
520000
unkown
page readonly
clean
2A0000
heap private
page read and write
clean
14C000
unkown
page read and write
clean
140000
unkown
page execute and read and write
clean
A20000
heap private
page read and write
clean
372000
heap private
page read and write
clean
2E02000
unkown
page readonly
clean
352E000
unkown
page read and write
clean
840000
unkown
page readonly
clean
2D7000
heap default
page read and write
clean
A30000
unkown
page readonly
clean
35A000
heap default
page read and write
clean
E0000
unkown
page read and write
clean
4DF000
heap default
page read and write
clean
1020000
unkown
page read and write
clean
2EC4000
unkown
page readonly
clean
33E000
heap default
page read and write
clean
366000
heap default
page read and write
clean
3230000
unkown
page readonly
clean
2980000
unkown
page readonly
clean
1F0000
heap private
page read and write
clean
90000
unkown
page read and write
clean
964000
heap default
page read and write
clean
D0000
unkown
page read and write
clean
2F56000
unkown
page readonly
clean
4D7000
heap default
page read and write
clean
3A7000
heap default
page read and write
clean
2E6000
heap private
page read and write
clean
2197000
unkown
page readonly
clean
2FE6000
unkown
page readonly
clean
20000
unkown
page readonly
clean
420000
unkown
page read and write
clean
3039000
unkown
page readonly
clean
28F0000
unkown
page readonly
clean
7EFDF000
unkown
page read and write
clean
3290000
unkown
page read and write
clean
340000
unkown
page read and write
clean
2920000
heap private
page read and write
clean
270000
heap private
page read and write
clean
2FA5000
unkown
page readonly
clean
2928000
heap private
page read and write
clean
70000
unkown
page read and write
clean
90000
unkown
page readonly
clean
20000
unkown
page readonly
clean
B4F000
unkown
page read and write
clean
31F2000
unkown
page readonly
clean
9E0000
unkown
page readonly
clean
B8E000
unkown
page read and write
clean
25D000
stack
page read and write
clean
CD0000
heap private
page read and write
clean
170000
unkown
page write copy
clean
350000
unkown
page readonly
clean
D30000
unkown
page readonly
clean
AF0000
unkown
page read and write
clean
580000
unkown
page readonly
clean
There are 302 hidden memdumps, click here to show them.