IOCReport

loading gif

Files

File Path
Type
Category
Malicious
document-1251000362.xlsm
Microsoft Excel 2007+
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\3003[1].gif
PE32+ executable (DLL) (native) x86-64, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\3003[1].gif
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
downloaded
malicious
C:\Users\user\Desktop\~$document-1251000362.xlsm
data
dropped
malicious
C:\Users\user\ksjvoefv.skd
PE32+ executable (DLL) (native) x86-64, for MS Windows
dropped
malicious
C:\Users\user\ksjvoefv.skd3
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
malicious
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, 58596 bytes, 1 file
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E0F5C59F9FA661F6F4C50B87FEF3A15A
data
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E0F5C59F9FA661F6F4C50B87FEF3A15A
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\53446F21.png
PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\58F9CAAE.png
PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\95DC83A0.png
PNG image data, 205 x 58, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\D66E9ED7.png
PNG image data, 485 x 185, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\8BCE0000
data
dropped
clean
C:\Users\user\AppData\Local\Temp\CabD644.tmp
Microsoft Cabinet archive data, 58596 bytes, 1 file
dropped
clean
C:\Users\user\AppData\Local\Temp\TarD645.tmp
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Wed Apr 7 01:39:37 2021, atime=Wed Apr 7 01:39:37 2021, length=8192, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\document-1251000362.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:14 2020, mtime=Wed Apr 7 01:39:37 2021, atime=Wed Apr 7 01:39:37 2021, length=108032, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\Desktop\5CCE0000
data
dropped
clean
There are 11 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\ksjvoefv.skd,DllRegisterServer
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\ksjvoefv.skd1,DllRegisterServer
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\ksjvoefv.skd2,DllRegisterServer
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\ksjvoefv.skd3,DllRegisterServer
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\ksjvoefv.skd4,DllRegisterServer
malicious

URLs

Name
IP
Malicious
https://twitter.com/awscloud
unknown
clean
https://a0.awsstatic.com/libra-css/images/logo
unknown
clean
https://aws.amazon.com/terms/?nc1=f_pr
unknown
clean
https://dc.ads.linkedin.com/collect/?pid=3038&fmt=gif
unknown
clean
https://s0.awsstatic.com/en_US/nav/v3/panel-content/mobile/index.html
unknown
clean
https://a0.awsstatic.com/plc/js/1.0.108/plc
unknown
clean
https://aws.amazon.com/cn/
unknown
clean
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
unknown
clean
http://www.diginotar.nl/cps/pkioverheid0
unknown
clean
https://a0.awsstatic.com/libra-css/images
unknown
clean
https://a0.awsstatic.com/psf/null
unknown
clean
https://aws.amazon.com/ar/
unknown
clean
https://www.honeycode.aws/?&trk=el_a134p000003yC6YAAU&trkCampaign=pac-edm-2020-honeycode-hom
unknown
clean
https://pages.awscloud.com/zillow-case-study?hp=tile&story=zllw
unknown
clean
https://pages.awscloud.com/communication-preferences?trk=homepage
unknown
clean
http://ocsp.rootg2.amazontrust.com08
unknown
clean
https://aws.amazon.com/cn/?nc1=h_ls
unknown
clean
https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc1=f_ct&src=default
unknown
clean
https://aws.amazon.com/ru/
unknown
clean
https://aws.amazon.com/tw/?nc1=h_ls
unknown
clean
https://fls-na.amazon.com/1/action-impressions/1/OE/aws-mktg/action/awsm_:comp_DeprecatedBrowser
unknown
clean
https://i18n-string.us-west-2.prod.pricing.aws.a2z.com
unknown
clean
https://aws.amazon.com/ko/
unknown
clean
https://aws.amazon.com/ru/?nc1=h_ls
unknown
clean
https://a0.awsstatic.com/libra-css/images/site/fav/favicon.ico
unknown
clean
https://aws.amazon.com/es/
unknown
clean
http://crl.sca1b.amazontrust.com/sca1b.crl0
unknown
clean
https://a0.awsstatic.com/target/1.0.113/aws-target-mediator.js
unknown
clean
https://docs.aws.amazon.com/index.html?nc2=h_ql_doc
unknown
clean
http://tvorartificialnature.xyz/
unknown
clean
https://aws.amazon.com/ar/?nc1=h_ls
unknown
clean
https://aws.amazon.com/j
unknown
clean
http://tvorartificialnature.xyz/vorarti
unknown
clean
https://aws.amazon.com/th/
unknown
clean
http://www.windows.com/pctv.
unknown
clean
https://a0.awsstatic.com/pricing-calculator/js/1.0.2
unknown
clean
https://aws.amazon.com/marketplace/?nc2=h_mo
unknown
clean
http://ocsp.sca1b.amazontrust.com06
unknown
clean
https://amazon.com/
unknown
clean
https://a0.awsstatic.com/libra-css/images/logos/aws_logo_smile_179x109.png
unknown
clean
https://console.aws.amazon.com/support/home/?nc2=h_ql_cu
unknown
clean
http://crl.rootca1.amazontrust.com/rootca1.crl0
unknown
clean
https://aws.amazon.com/search/
unknown
clean
https://console.aws.amazon.com/iam/home?nc2=h_m_sc#security_credential
unknown
clean
https://aws.amazon.com/?nc2=h_lg
unknown
clean
http://ocsp.rootca1.amazontrust.com0:
unknown
clean
https://console.aws.amazon.com/support/home/?nc1=f_dr
unknown
clean
https://a0.awsstatic.com/aws-blog/1.0.46/js
unknown
clean
https://aws.amazon.com/fr/
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
https://console.aws.amazon.com/console/home?nc1=f_ct&src=footer-signin-mobile
unknown
clean
http://usaaforced.fun/j
unknown
clean
https://aws.amazon.com/vi/
unknown
clean
https://www.twitch.tv/aws
unknown
clean
https://aws.amazon.com/marketplace/?nc2=h_ql_mp
unknown
clean
https://aws.amazon.com/search
unknown
clean
http://crl.rootg2.amazontrust.com/rootg2.crl0
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
https://a0.awsstatic.com/da/js/1.0.47/aws-da.js
unknown
clean
https://aws.amazon.com/tw/
unknown
clean
https://aws.amazon.com/tr/?nc1=h_ls
unknown
clean
https://console.aws.amazon.com/?nc2=h_m_mc
unknown
clean
https://aws.amazon.com/fr/?nc1=h_ls
unknown
clean
https://a0.aws
unknown
clean
http://o.ss2.us/0
unknown
clean
https://aws.amazon.com/search/?searchQuery=
unknown
clean
https://a0.awsstatic.com/libra-search/1.0.13/js
unknown
clean
https://aws.amazon.com/privacy/?nc1=f_pr
unknown
clean
https://aws.amazon.com/pt/?nc1=h_ls
unknown
clean
https://aws.amazon.com/jp/?nc1=h_ls
unknown
clean
http://crl.entrust.net/2048ca.crl0
unknown
clean
https://aws.amazon.com/marketplace?aws=hp
unknown
clean
https://aws.amazon.com/
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
https://a0.awsstatic.com/libra-css/images/site/touch-icon-ipad-144-smile.png
unknown
clean
https://a0.awsstatic.com/s_code/js/3.0/awshome_s_code.js
unknown
clean
https://aws.amazon.com/podcasts/aws-podcast/
unknown
clean
http://ocsp.entrust.net03
unknown
clean
https://aws.amazon.com/jp/
unknown
clean
http://crt.rootg2.amazontrust.com/rootg2.cer0=
unknown
clean
https://aws.amazon.com/pt/
unknown
clean
https://aws.amazon.com/?nc1=h_ls
unknown
clean
https://s0.awsstatic.com/en_US/nav/v3/panel-content/desktop/index.html
unknown
clean
http://crt.comod
unknown
clean
https://aws.amazon.com/es/?nc1=h_ls
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
https://d1.awsstatic.com
unknown
clean
https://aws.amazon.com/de/
unknown
clean
http://investor.msn.com/
unknown
clean
https://phd.aws.amazon.com/?nc2=h_m_sc
unknown
clean
https://a0.awsstatic.com/libra/1.0.376/librastandardlib
unknown
clean
https://aws.amazon.com/id/?nc1=h_ls
unknown
clean
https://a0.awsstatic.com/libra-css/images/logos/aws_logo_smile_1200x630.png
unknown
clean
http://www.%s.comPA
unknown
clean
https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct&src=default
unknown
clean
https://a0.awsstatic.com
unknown
clean
http://ocsp.entrust.net0D
unknown
clean
https://pages.awscloud.com/fico-case-study.html?hp=tile&story=fico
unknown
clean
http://s.ss2.us/r.crl0
unknown
clean
https://aws.amazon.com/th/?nc1=f_ls
unknown
clean
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
agenbolatermurah.com
unknown
malicious
usaaforced.fun
unknown
malicious
tvorartificialnature.xyz
unknown
malicious
metaflip.io
192.185.48.186
clean
tajushariya.com
199.79.62.99
clean
columbia.aula-web.net
50.87.146.86
clean
dr49lng3n1n2s.cloudfront.net
143.204.3.74
clean
partsapp.com.br
192.185.214.87
clean
aws.amazon.com
unknown
clean

IPs

IP
Domain
Country
Malicious
50.87.146.86
columbia.aula-web.net
United States
clean
199.79.62.99
tajushariya.com
United States
clean
192.185.214.87
partsapp.com.br
United States
clean
143.204.3.74
dr49lng3n1n2s.cloudfront.net
United States
clean
192.185.48.186
metaflip.io
United States
clean
192.168.2.255
unknown
unknown
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
&<7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC7C2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECACE
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECC06
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECCE0
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{e7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\system32\qagentrt.dll,-10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-843
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-844
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\wuaueng.dll,-400
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
10DA39
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
10EF5E
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SavedLegacySettings
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
There are 109 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
38E000
heap default
page read and write
malicious
2E3000
unkown
page read and write
malicious
2E3000
unkown
page read and write
malicious
2E3000
unkown
page read and write
malicious
2E1000
heap default
page read and write
malicious
2E3000
unkown
page read and write
malicious
2E3000
unkown
page read and write
malicious
374000
unkown
page read and write
clean
37A000
unkown
page read and write
clean
29D5000
unkown
page read and write
clean
374000
unkown
page read and write
clean
2982000
unkown
page readonly
clean
326000
heap default
page read and write
clean
2120000
heap private
page read and write
clean
2802000
unkown
page readonly
clean
2FC3000
unkown
page read and write
clean
273F000
heap private
page read and write
clean
1CB7000
unkown
page readonly
clean
37A000
unkown
page read and write
clean
29D5000
unkown
page read and write
clean
374000
unkown
page read and write
clean
2939000
unkown
page readonly
clean
150000
unkown
page read and write
clean
1E0000
heap private
page read and write
clean
29E2000
unkown
page read and write
clean
2909000
unkown
page readonly
clean
37A000
unkown
page read and write
clean
397000
unkown
page read and write
clean
29EC000
unkown
page read and write
clean
1FC000
unkown
page read and write
clean
35B000
heap default
page read and write
clean
27A2000
unkown
page readonly
clean
21A0000
unkown
page readonly
clean
37B000
unkown
page read and write
clean
3A7000
unkown
page read and write
clean
29F3000
unkown
page read and write
clean
20000
unkown
page readonly
clean
2722000
unkown
page readonly
clean
287000
heap default
page read and write
clean
359000
unkown
page read and write
clean
340000
heap default
page read and write
clean
29CF000
unkown
page read and write
clean
240000
unkown
page read and write
clean
2A26000
unkown
page read and write
clean
27B4000
unkown
page readonly
clean
3A2000
unkown
page read and write
clean
2622000
unkown
page readonly
clean
37A000
unkown
page read and write
clean
37E000
heap default
page read and write
clean
2D7B000
heap private
page read and write
clean
1FD0000
unkown
page write copy
clean
28A6000
unkown
page readonly
clean
2FCB000
unkown
page read and write
clean
37B000
unkown
page read and write
clean
1E77000
unkown
page readonly
clean
28A2000
unkown
page readonly
clean
2B7000
heap default
page read and write
clean
2A26000
unkown
page read and write
clean
374000
unkown
page read and write
clean
374000
unkown
page read and write
clean
2A26000
unkown
page read and write
clean
29D5000
unkown
page read and write
clean
7FEF4613000
unkown image
page write copy
clean
29C1000
unkown
page read and write
clean
190000
unkown
page read and write
clean
2F51000
unkown
page read and write
clean
2879000
unkown
page readonly
clean
2A26000
unkown
page read and write
clean
2628000
unkown
page readonly
clean
2205000
heap private
page read and write
clean
2250000
unkown
page readonly
clean
397000
unkown
page read and write
clean
2A26000
unkown
page read and write
clean
2822000
unkown
page readonly
clean
2A26000
unkown
page read and write
clean
2802000
unkown
page readonly
clean
29CF000
unkown
page read and write
clean
3E6000
unkown
page read and write
clean
2FB0000
unkown
page read and write
clean
374000
unkown
page read and write
clean
234000
unkown
page execute and read and write
clean
2F87000
unkown
page read and write
clean
32DC000
unkown
page read and write
clean
2115000
heap private
page read and write
clean
2742000
unkown
page readonly
clean
220000
unkown
page read and write
clean
60000
unkown
page readonly
clean
270000
unkown
page read and write
clean
2AE0000
heap private
page read and write
clean
26BF000
unkown
page read and write
clean
2E0000
heap default
page read and write
clean
2922000
unkown
page readonly
clean
280000
heap default
page read and write
clean
21B0000
heap private
page read and write
clean
2849000
unkown
page readonly
clean
2CE0000
unkown
page readonly
clean
374000
unkown
page read and write
clean
29DA000
unkown
page read and write
clean
374000
unkown
page read and write
clean
367000
unkown
page read and write
clean
37A000
unkown
page read and write
clean
2B00000
unkown
page readonly
clean
2E7000
heap default
page read and write
clean
397000
unkown
page read and write
clean
29CF000
unkown
page read and write
clean
29D5000
unkown
page read and write
clean
29C1000
unkown
page read and write
clean
27D2000
unkown
page readonly
clean
37A000
unkown
page read and write
clean
2C60000
heap private
page read and write
clean
3A2000
unkown
page read and write
clean
2A26000
unkown
page read and write
clean
2824000
unkown
page readonly
clean
29EC000
unkown
page read and write
clean
28A9000
unkown
page readonly
clean
2842000
unkown
page readonly
clean
52D000
unkown
page read and write
clean
2952000
unkown
page readonly
clean
29E2000
unkown
page read and write
clean
29DA000
unkown
page read and write
clean
7FEF4612000
unkown image
page readonly
clean
2FCB000
unkown
page read and write
clean
2724000
unkown
page readonly
clean
2D40000
heap private
page read and write
clean
27E2000
unkown
page readonly
clean
29E2000
unkown
page read and write
clean
29E2000
unkown
page read and write
clean
2826000
unkown
page readonly
clean
37A000
unkown
page read and write
clean
1BF0000
unkown
page readonly
clean
2802000
unkown
page readonly
clean
374000
unkown
page read and write
clean
29E2000
unkown
page read and write
clean
20DF000
unkown
page read and write
clean
35B000
unkown
page read and write
clean
2110000
heap private
page read and write
clean
28E2000
unkown
page readonly
clean
374000
unkown
page read and write
clean
29F4000
unkown
page read and write
clean
351000
unkown
page read and write
clean
29C1000
unkown
page read and write
clean
37A000
unkown
page read and write
clean
29D5000
unkown
page read and write
clean
2A26000
unkown
page read and write
clean
37A000
unkown
page read and write
clean
2FC3000
unkown
page read and write
clean
374000
unkown
page read and write
clean
2FCB000
unkown
page read and write
clean
359000
heap default
page read and write
clean
290D000
unkown
page readonly
clean
2A28000
unkown
page read and write
clean
2548000
unkown
page readonly
clean
29E2000
unkown
page read and write
clean
2945000
unkown
page readonly
clean
37A000
unkown
page read and write
clean
374000
unkown
page read and write
clean
2B0000
heap default
page read and write
clean
2A26000
unkown
page read and write
clean
2796000
unkown
page readonly
clean
37E000
unkown
page read and write
clean
397000
unkown
page read and write
clean
2280000
unkown
page readonly
clean
2FC3000
unkown
page read and write
clean
E0000
unkown
page readonly
clean
1C90000
unkown
page readonly
clean
E0000
unkown
page read and write
clean
2FCB000
unkown
page read and write
clean
38E000
unkown
page read and write
clean
2A26000
unkown
page read and write
clean
359000
unkown
page read and write
clean
2FCB000
unkown
page read and write
clean
29EC000
unkown
page read and write
clean
D0000
unkown
page read and write
clean
2F87000
unkown
page read and write
clean
330000
heap default
page read and write
clean
37A000
unkown
page read and write
clean
29CF000
unkown
page read and write
clean
295C000
unkown
page read and write
clean
37B000
unkown
page read and write
clean
367000
unkown
page read and write
clean
37A000
unkown
page read and write
clean
1FC000
unkown
page read and write
clean
34F000
unkown
page read and write
clean
34F000
unkown
page read and write
clean
3A2000
unkown
page read and write
clean
37B000
unkown
page read and write
clean
21C000
unkown
page read and write
clean
2F50000
unkown
page read and write
clean
2B7000
heap default
page read and write
clean
374000
unkown
page read and write
clean
3DE000
heap default
page read and write
clean
35B000
unkown
page read and write
clean
29DA000
unkown
page read and write
clean
29C0000
heap private
page read and write
clean
351000
unkown
page read and write
clean
29E2000
unkown
page read and write
clean
2AA0000
heap private
page read and write
clean
37E000
unkown
page read and write
clean
374000
unkown
page read and write
clean
1F60000
unkown
page write copy
clean
306000
unkown
page read and write
clean
4A0000
unkown
page readonly
clean
2FC3000
unkown
page read and write
clean
37A000
unkown
page read and write
clean
37A000
unkown
page read and write
clean
2FC3000
unkown
page read and write
clean
29EC000
unkown
page read and write
clean
7FEF4610000
unkown image
page readonly
clean
373000
unkown
page read and write
clean
2542000
unkown
page readonly
clean
25D2000
unkown
page readonly
clean
2230000
unkown
page readonly
clean
29E2000
unkown
page read and write
clean
115000
heap private
page read and write
clean
351000
heap default
page read and write
clean
37B000
unkown
page read and write
clean
28A5000
unkown
page readonly
clean
29E2000
unkown
page read and write
clean
29C2000
unkown
page read and write
clean
20000
unkown
page readonly
clean
2A26000
unkown
page read and write
clean
564000
heap private
page read and write
clean
367000
unkown
page read and write
clean
351000
unkown
page read and write
clean
397000
unkown
page read and write
clean
654000
heap private
page read and write
clean
2F51000
unkown
page read and write
clean
29D9000
unkown
page read and write
clean
37E000
unkown
page read and write
clean
2702000
unkown
page readonly
clean
2BE000
heap default
page read and write
clean
2300000
unkown
page readonly
clean
264000
heap private
page read and write
clean
28BD000
unkown
page readonly
clean
2900000
heap private
page read and write
clean
21B000
heap private
page read and write
clean
34F000
heap default
page read and write
clean
260000
heap private
page read and write
clean
2852000
unkown
page readonly
clean
2FCB000
unkown
page read and write
clean
2862000
unkown
page readonly
clean
29C1000
unkown
page read and write
clean
236000
unkown
page read and write
clean
374000
unkown
page read and write
clean
7A0000
unkown
page readonly
clean
1AD0000
unkown
page readonly
clean
1DC000
unkown
page read and write
clean
280B000
unkown
page read and write
clean
480000
unkown
page readonly
clean
2700000
heap private
page read and write
clean
2AC2000
unkown
page readonly
clean
282D000
unkown
page readonly
clean
37A000
unkown
page read and write
clean
3A2000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
720000
unkown
page readonly
clean
2260000
heap private
page read and write
clean
186000
unkown
page read and write
clean
29C1000
unkown
page read and write
clean
29C1000
unkown
page read and write
clean
2F87000
unkown
page read and write
clean
2FC3000
unkown
page read and write
clean
374000
unkown
page read and write
clean
2A90000
unkown
page readonly
clean
37A000
unkown
page read and write
clean
2709000
heap private
page read and write
clean
186000
unkown
page read and write
clean
600000
unkown
page readonly
clean
3A7000
heap default
page read and write
clean
37B000
unkown
page read and write
clean
35B000
unkown
page read and write
clean
37B000
unkown
page read and write
clean
60000
unkown
page readonly
clean
2832000
unkown
page readonly
clean
27C6000
unkown
page readonly
clean
359000
unkown
page read and write
clean
37E000
unkown
page read and write
clean
2C65000
heap private
page read and write
clean
2A26000
unkown
page read and write
clean
367000
unkown
page read and write
clean
35B000
unkown
page read and write
clean
374000
unkown
page read and write
clean
374000
unkown
page read and write
clean
2FCB000
unkown
page read and write
clean
2772000
unkown
page readonly
clean
29C1000
unkown
page read and write
clean
3A8000
unkown
page read and write
clean
2F87000
unkown
page read and write
clean
29C1000
unkown
page read and write
clean
29F3000
unkown
page read and write
clean
29DA000
unkown
page read and write
clean
7FEF4690000
unkown image
page readonly
clean
29E2000
unkown
page read and write
clean
27F6000
unkown
page readonly
clean
200000
unkown
page read and write
clean
384000
heap default
page read and write
clean
374000
unkown
page read and write
clean
359000
unkown
page read and write
clean
200000
unkown
page read and write
clean
37B000
unkown
page read and write
clean
2815000
unkown
page readonly
clean
2A26000
unkown
page read and write
clean
367000
heap default
page read and write
clean
37B000
unkown
page read and write
clean
29DA000
unkown
page read and write
clean
37A000
unkown
page read and write
clean
2815000
unkown
page readonly
clean
130000
unkown
page read and write
clean
144000
unkown
page execute and read and write
clean
20000
unkown
page readonly
clean
2A26000
unkown
page read and write
clean
31D000
heap default
page read and write
clean
29C1000
unkown
page read and write
clean
374000
unkown
page read and write
clean
28B9000
unkown
page readonly
clean
306000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
150000
unkown
page read and write
clean
2B0000
heap default
page read and write
clean
351000
unkown
page read and write
clean
29CA000
unkown
page read and write
clean
2A26000
unkown
page read and write
clean
2DC0000
unkown
page readonly
clean
29D5000
unkown
page read and write
clean
D0000
unkown
page read and write
clean
D0000
unkown
page read and write
clean
2F59000
unkown
page read and write
clean
2CD0000
unkown
page readonly
clean
570000
unkown
page readonly
clean
2AD0000
unkown
page readonly
clean
2F51000
unkown
page read and write
clean
2812000
unkown
page read and write
clean
3B6000
unkown
page read and write
clean
3A2000
unkown
page read and write
clean
28B2000
unkown
page readonly
clean
27D4000
unkown
page readonly
clean
351000
unkown
page read and write
clean
1DD7000
unkown
page readonly
clean
306000
heap default
page read and write
clean
29D5000
unkown
page read and write
clean
3B0000
unkown
page readonly
clean
29C1000
unkown
page read and write
clean
3A7000
unkown
page read and write
clean
250000
unkown
page read and write
clean
60000
unkown
page readonly
clean
2070000
unkown
page readonly
clean
1F80000
unkown
page readonly
clean
14B000
heap private
page read and write
clean
2A32000
unkown
page readonly
clean
22E0000
unkown
page readonly
clean
2B60000
unkown
page readonly
clean
2856000
unkown
page readonly
clean
2C8B000
heap private
page read and write
clean
2A26000
unkown
page read and write
clean
22FD000
unkown
page read and write
clean
2952000
unkown
page read and write
clean
590000
unkown
page readonly
clean
380000
unkown
page read and write
clean
306000
unkown
page read and write
clean
21C0000
unkown
page readonly
clean
2845000
unkown
page readonly
clean
2A26000
unkown
page read and write
clean
374000
unkown
page read and write
clean
2F6D000
unkown
page read and write
clean
47F000
unkown
page read and write
clean
28F5000
unkown
page readonly
clean
29C2000
unkown
page read and write
clean
374000
unkown
page read and write
clean
2DE000
unkown
page read and write
clean
37B000
unkown
page read and write
clean
7FEF46BA000
unkown image
page readonly
clean
2B50000
unkown
page readonly
clean
2FC3000
unkown
page read and write
clean
2876000
unkown
page readonly
clean
28D9000
unkown
page readonly
clean
2020000
unkown
page readonly
clean
2A26000
unkown
page read and write
clean
2FC3000
unkown
page read and write
clean
2929000
unkown
page readonly
clean
367000
unkown
page read and write
clean
2C50000
heap private
page read and write
clean
27E4000
unkown
page readonly
clean
37A000
unkown
page read and write
clean
2A26000
unkown
page read and write
clean
29D5000
unkown
page read and write
clean
2875000
unkown
page readonly
clean
1E97000
unkown
page readonly
clean
29D5000
unkown
page read and write
clean
263F000
unkown
page read and write
clean
25D8000
unkown
page readonly
clean
2865000
unkown
page readonly
clean
29C8000
unkown
page read and write
clean
7FEF46C0000
unkown image
page write copy
clean
236000
unkown
page read and write
clean
29CF000
unkown
page read and write
clean
2B40000
unkown
page readonly
clean
29E2000
unkown
page read and write
clean
2FCB000
unkown
page read and write
clean
2A26000
unkown
page read and write
clean
28C5000
unkown
page readonly
clean
890000
unkown
page readonly
clean
2EE000
heap default
page read and write
clean
35B000
unkown
page read and write
clean
359000
unkown
page read and write
clean
29E2000
unkown
page read and write
clean
110000
unkown
page readonly
clean
37A000
unkown
page read and write
clean
620000
unkown
page readonly
clean
397000
unkown
page read and write
clean
29EC000
unkown
page read and write
clean
2F87000
unkown
page read and write
clean
29C1000
unkown
page read and write
clean
351000
unkown
page read and write
clean
3A0000
heap default
page read and write
clean
29C1000
unkown
page read and write
clean
2FCB000
unkown
page read and write
clean
2A26000
unkown
page read and write
clean
2882000
unkown
page readonly
clean
7FEF4690000
unkown image
page readonly
clean
21B9000
heap private
page read and write
clean
240000
unkown
page read and write
clean
2744000
unkown
page readonly
clean
29D5000
unkown
page read and write
clean
2A26000
unkown
page read and write
clean
37E000
heap default
page read and write
clean
2A26000
unkown
page read and write
clean
2F51000
unkown
page read and write
clean
27B2000
unkown
page readonly
clean
386000
heap default
page read and write
clean
E0000
unkown
page read and write
clean
30B000
heap default
page read and write
clean
27B5000
unkown
page readonly
clean
37A000
unkown
page read and write
clean
2119000
heap private
page read and write
clean
2FC3000
unkown
page read and write
clean
21EF000
heap private
page read and write
clean
140000
unkown
page execute and read and write
clean
2829000
unkown
page readonly
clean
2D45000
heap private
page read and write
clean
29F3000
unkown
page read and write
clean
2F51000
unkown
page read and write
clean
398000
unkown
page read and write
clean
314C000
unkown
page read and write
clean
3A2000
unkown
page read and write
clean
26D2000
unkown
page readonly
clean
14D000
unkown
page read and write
clean
B9F000
unkown
page read and write
clean
7FEF4618000
unkown image
page readonly
clean
367000
unkown
page read and write
clean
2F51000
unkown
page read and write
clean
2FC3000
unkown
page read and write
clean
2895000
unkown
page readonly
clean
2200000
heap private
page read and write
clean
3A2000
unkown
page read and write
clean
2F87000
unkown
page read and write
clean
374000
unkown
page read and write
clean
2785000
unkown
page readonly
clean
2F87000
unkown
page read and write
clean
2AB0000
unkown
page readonly
clean
2FCB000
unkown
page read and write
clean
1D87000
unkown
page readonly
clean
29DC000
unkown
page read and write
clean
29CF000
unkown
page read and write
clean
29CA000
unkown
page read and write
clean
2989000
unkown
page readonly
clean
317000
heap default
page read and write
clean
2865000
unkown
page readonly
clean
34F000
unkown
page read and write
clean
2C60000
heap private
page read and write
clean
37E000
unkown
page read and write
clean
384000
unkown
page read and write
clean
29D5000
unkown
page read and write
clean
37E000
unkown
page read and write
clean
2160000
unkown
page write copy
clean
2704000
unkown
page readonly
clean
2804000
unkown
page readonly
clean
2895000
unkown
page readonly
clean
2ABB000
unkown
page read and write
clean
37E000
unkown
page read and write
clean
27D2000
unkown
page readonly
clean
29D5000
unkown
page read and write
clean
3A2000
unkown
page read and write
clean
37B000
unkown
page read and write
clean
37A000
unkown
page read and write
clean
100000
unkown
page readonly
clean
306000
unkown
page read and write
clean
7FEF46C5000
unkown image
page readonly
clean
29A5000
unkown
page readonly
clean
367000
unkown
page read and write
clean
2892000
unkown
page readonly
clean
2C9B000
heap private
page read and write
clean
29EC000
unkown
page read and write
clean
37B000
unkown
page read and write
clean
2A26000
unkown
page read and write
clean
29C1000
unkown
page read and write
clean
2909000
unkown
page readonly
clean
7FEF4619000
unkown image
page write copy
clean
710000
unkown
page readonly
clean
2980000
unkown
page read and write
clean
2FCB000
unkown
page read and write
clean
29DA000
unkown
page read and write
clean
35B000
unkown
page read and write
clean
2794000
unkown
page readonly
clean
20E0000
heap private
page read and write
clean
2100000
unkown
page read and write
clean
2850000
heap private
page read and write
clean
29EC000
unkown
page read and write
clean
120000
unkown
page read and write
clean
60000
unkown
page readonly
clean
37A000
unkown
page read and write
clean
374000
unkown
page read and write
clean
37B000
unkown
page read and write
clean
374000
unkown
page read and write
clean
29E2000
unkown
page read and write
clean
29C2000
unkown
page read and write
clean
2209000
heap private
page read and write
clean
2F88000
unkown
page read and write
clean
29E2000
unkown
page read and write
clean
2CE0000
unkown
page readonly
clean
500000
heap private
page read and write
clean
37B000
unkown
page read and write
clean
2792000
unkown
page readonly
clean
306000
unkown
page read and write
clean
31DC000
unkown
page read and write
clean
28C5000
unkown
page readonly
clean
2FCB000
unkown
page read and write
clean
230000
unkown
page execute and read and write
clean
2A26000
unkown
page read and write
clean
27E5000
unkown
page readonly
clean
29CA000
unkown
page read and write
clean
7FEF4611000
unkown image
page execute read
clean
7FEF4610000
unkown image
page readonly
clean
150000
unkown
page read and write
clean
D0000
unkown
page read and write
clean
29E2000
unkown
page read and write
clean
2A26000
unkown
page read and write
clean
2B60000
unkown
page readonly
clean
2FCB000
unkown
page read and write
clean
35B000
unkown
page read and write
clean
37E000
unkown
page read and write
clean
2B20000
unkown
page readonly
clean
29D3000
heap private
page read and write
clean
2129000
heap private
page read and write
clean
2A26000
unkown
page read and write
clean
2FC3000
unkown
page read and write
clean
7FEF4691000
unkown image
page execute read
clean
2A26000
unkown
page read and write
clean
28B6000
unkown
page readonly
clean
29D5000
unkown
page read and write
clean
3A7000
unkown
page read and write
clean
2B12000
unkown
page readonly
clean
3B0000
unkown
page read and write
clean
530000
unkown
page readonly
clean
2E6000
unkown
page read and write
clean
1EE0000
heap private
page read and write
clean
37A000
unkown
page read and write
clean
274000
heap private
page read and write
clean
580000
heap private
page read and write
clean
2640000
unkown
page write copy
clean
367000
unkown
page read and write
clean
37E000
unkown
page read and write
clean
359000
unkown
page read and write
clean
37A000
unkown
page read and write
clean
100000
heap private
page read and write
clean
29D5000
unkown
page read and write
clean
29E2000
unkown
page read and write
clean
2FCB000
unkown
page read and write
clean
2A26000
unkown
page read and write
clean
2FA0000
unkown
page read and write
clean
584000
heap private
page read and write
clean
270000
heap private
page read and write
clean
2F87000
unkown
page read and write
clean
305000
unkown
page read and write
clean
60000
unkown
page readonly
clean
2F51000
unkown
page read and write
clean
359000
unkown
page read and write
clean
311E000
unkown
page read and write
clean
397000
unkown
page read and write
clean
2A26000
unkown
page read and write
clean
386000
unkown
page read and write
clean
37A000
unkown
page read and write
clean
20000
unkown
page readonly
clean
2988000
unkown
page read and write
clean
2A26000
unkown
page read and write
clean
2642000
unkown
page readonly
clean
2932000
unkown
page readonly
clean
29DA000
unkown
page read and write
clean
35B000
unkown
page read and write
clean
29D5000
unkown
page read and write
clean
374000
unkown
page read and write
clean
332000
unkown
page read and write
clean
2EE000
heap default
page read and write
clean
2FC3000
unkown
page read and write
clean
150000
unkown
page read and write
clean
2A26000
unkown
page read and write
clean
37E000
heap default
page read and write
clean
351000
unkown
page read and write
clean
2906000
unkown
page readonly
clean
DB000
unkown
page read and write
clean
306000
unkown
page read and write
clean
2925000
unkown
page readonly
clean
2872000
unkown
page readonly
clean
2959000
unkown
page readonly
clean
2886000
unkown
page readonly
clean
37E000
unkown
page read and write
clean
2AB3000
heap private
page read and write
clean
37E000
unkown
page read and write
clean
650000
heap private
page read and write
clean
2955000
unkown
page readonly
clean
29DA000
unkown
page read and write
clean
2975000
unkown
page readonly
clean
104000
heap private
page read and write
clean
34F000
unkown
page read and write
clean
37E000
unkown
page read and write
clean
28D2000
unkown
page readonly
clean
2A37000
unkown
page read and write
clean
37A000
unkown
page read and write
clean
2F59000
unkown
page read and write
clean
2F51000
unkown
page read and write
clean
373000
unkown
page read and write
clean
29E2000
unkown
page read and write
clean
2902000
unkown
page readonly
clean
58E000
unkown
page read and write
clean
21B0000
heap private
page read and write
clean
2C55000
heap private
page read and write
clean
2F51000
unkown
page read and write
clean
359000
unkown
page read and write
clean
28F5000
unkown
page readonly
clean
281C000
unkown
page read and write
clean
2826000
unkown
page readonly
clean
6F0000
unkown
page readonly
clean
34F000
unkown
page read and write
clean
1CB0000
unkown
page readonly
clean
2B90000
unkown
page readonly
clean
29EC000
unkown
page read and write
clean
306000
unkown
page read and write
clean
374000
unkown
page read and write
clean
2FCB000
unkown
page read and write
clean
2B70000
unkown
page readonly
clean
2722000
unkown
page readonly
clean
560000
heap private
page read and write
clean
29C1000
unkown
page read and write
clean
2DB000
heap default
page read and write
clean
32AC000
unkown
page read and write
clean
1BA0000
unkown
page readonly
clean
2FC3000
unkown
page read and write
clean
37A000
unkown
page read and write
clean
2125000
heap private
page read and write
clean
2A26000
unkown
page read and write
clean
29F4000
unkown
page read and write
clean
20000
unkown
page readonly
clean
34F000
unkown
page read and write
clean
29C2000
unkown
page read and write
clean
311000
heap default
page read and write
clean
351000
unkown
page read and write
clean
29D5000
unkown
page read and write
clean
347000
heap default
page read and write
clean
1E5000
heap private
page read and write
clean
3AF000
unkown
page read and write
clean
34F000
unkown
page read and write
clean
2FC3000
unkown
page read and write
clean
440000
unkown
page write copy
clean
2A70000
unkown
page readonly
clean
29D5000
unkown
page read and write
clean
29C9000
unkown
page read and write
clean
2FC1000
unkown
page read and write
clean
29E2000
unkown
page read and write
clean
37A000
unkown
page read and write
clean
374000
unkown
page read and write
clean
28D6000
unkown
page readonly
clean
22A0000
unkown
page readonly
clean
37A000
unkown
page read and write
clean
29C1000
unkown
page read and write
clean
2FCB000
unkown
page read and write
clean
397000
unkown
page read and write
clean
110000
heap private
page read and write
clean
34F000
unkown
page read and write
clean
29E2000
unkown
page read and write
clean
There are 668 hidden memdumps, click here to show them.