IOCReport

loading gif

Files

File Path
Type
Category
Malicious
SOL2021-03-14-NETC-NI-21-049-CEVA INV.xlsx
CDFV2 Encrypted
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\nano[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Local\Temp\tmp2720.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\run.dat
ISO-8859 text, with no line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\gmSlQSien.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\Desktop\~$SOL2021-03-14-NETC-NI-21-049-CEVA INV.xlsx
data
dropped
malicious
C:\Users\Public\vbc.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\27A56AD2.png
PNG image data, 1268 x 540, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\29AF82FC.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 220x220, segment length 16, baseline, precision 8, 550x310, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\365FCBB7.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 191x263, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\4132FFE5.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5394A5DD.png
PNG image data, 199 x 126, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5A7818AB.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 333x151, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5DF1CC3E.png
PNG image data, 199 x 126, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\69EC2A79.png
PNG image data, 1686 x 725, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\98FE530E.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 333x151, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\9EE93CA2.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\A4A722F1.png
PNG image data, 110 x 167, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\AB377A3A.png
PNG image data, 566 x 429, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\B9A26101.png
PNG image data, 1268 x 540, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\BC2E50F3.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 220x220, segment length 16, baseline, precision 8, 550x310, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\D2E7424C.png
PNG image data, 110 x 167, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\D3B54A74.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\D6B60ECD.jpeg
[TIFF image data, big-endian, direntries=4], baseline, precision 8, 396x275, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\DAA062B0.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 191x263, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\E3296E6A.png
PNG image data, 1686 x 725, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\EA55EE58.jpeg
[TIFF image data, big-endian, direntries=4], baseline, precision 8, 396x275, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\EB61327.png
PNG image data, 566 x 429, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\Excel8.0\MSForms.exd
data
dropped
clean
There are 20 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
malicious
C:\Users\Public\vbc.exe
'C:\Users\Public\vbc.exe'
malicious
C:\Windows\SysWOW64\schtasks.exe
'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\gmSlQSien' /XML 'C:\Users\user\AppData\Local\Temp\tmp2720.tmp'
malicious
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
clean
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
'C:\Program Files (x86)\SMTP Service\smtpsvc.exe'
clean

URLs

Name
IP
Malicious
nassiru1155.ddns.net
malicious
http://covid19vaccinations.hopto.org/nano.exe
13.235.115.155
malicious
79.134.225.30
malicious
http://www.%s.comPA
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
https://stackpath.bootstrapcdn.com/bootstrap/4.5.0/css/bootstrap.min.css
unknown
clean

Domains

Name
IP
Malicious
covid19vaccinations.hopto.org
13.235.115.155
malicious
nassiru1155.ddns.net
unknown
malicious

IPs

IP
Domain
Country
Malicious
13.235.115.155
covid19vaccinations.hopto.org
United States
malicious
79.134.225.30
unknown
Switzerland
malicious

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
$v3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F1F63
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
FontCachePath
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
q14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F6DFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F7C8F
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 21
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F6DFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F6DFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F6DFF
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
EquationEditorFilesIntl_1033
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
SavedLegacySettings
clean
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
SMTP Service
clean
There are 193 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
840000
unkown
page read and write
malicious
36A1000
unkown
page read and write
malicious
26A1000
unkown
page read and write
malicious
37E6000
unkown
page read and write
malicious
402000
unkown
page execute and read and write
malicious
7EF50000
unkown
page execute and read and write
clean
397E000
unkown
page read and write
clean
2FB000
unkown
page execute and read and write
clean
3A1F000
unkown
page read and write
clean
500000
unkown
page read and write
clean
3ABE000
unkown
page read and write
clean
506000
unkown
page read and write
clean
1286000
unkown image
page readonly
clean
3A3E000
unkown
page read and write
clean
4E0000
unkown
page write copy
clean
3B1E000
unkown
page read and write
clean
60E000
unkown
page read and write
clean
790000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
63FF000
unkown
page read and write
clean
20000
heap private
page read and write
clean
5B0000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
B60000
unkown
page read and write
clean
3ABE000
unkown
page read and write
clean
2CA000
unkown
page execute and read and write
clean
2130000
unkown
page readonly
clean
38BE000
unkown
page read and write
clean
21B0000
unkown
page read and write
clean
39FE000
unkown
page read and write
clean
13A000
unkown
page execute and read and write
clean
7A0000
unkown
page read and write
clean
542E000
unkown
page read and write
clean
505000
unkown
page read and write
clean
730000
unkown
page readonly
clean
9A0000
unkown
page read and write
clean
1F0000
heap private
page read and write
clean
7A0000
unkown
page read and write
clean
60000
unkown
page readonly
clean
5F8000
unkown
page read and write
clean
23B000
unkown
page execute and read and write
clean
120000
unkown
page read and write
clean
9D0000
unkown
page readonly
clean
39DF000
unkown
page read and write
clean
4951000
unkown
page read and write
clean
3A7E000
unkown
page read and write
clean
B61000
unkown
page read and write
clean
39FE000
unkown
page read and write
clean
58F000
unkown
page read and write
clean
3B0000
unkown
page read and write
clean
500000
unkown
page read and write
clean
3D6000
heap private
page read and write
clean
29FC000
unkown
page read and write
clean
3A3E000
unkown
page read and write
clean
790000
unkown
page read and write
clean
A9CD000
stack
page read and write
clean
387E000
unkown
page read and write
clean
492F000
unkown
page read and write
clean
200000
unkown image
page readonly
clean
5B5000
heap default
page read and write
clean
38BE000
unkown
page read and write
clean
500000
unkown
page read and write
clean
715000
unkown
page read and write
clean
3A7E000
unkown
page read and write
clean
650000
unkown
page readonly
clean
4AE7000
heap private
page execute and read and write
clean
790000
unkown
page read and write
clean
214F000
unkown
page read and write
clean
1114000
heap private
page read and write
clean
6F0000
unkown
page read and write
clean
715000
unkown
page read and write
clean
232000
unkown
page read and write
clean
1286000
unkown image
page readonly
clean
20A000
unkown
page read and write
clean
416000
unkown
page read and write | page guard
clean
B70000
unkown
page read and write
clean
1E0000
heap private
page read and write
clean
3A9E000
unkown
page read and write
clean
684000
heap default
page read and write
clean
5A3E000
unkown
page read and write
clean
500000
unkown
page read and write
clean
2C2000
unkown
page execute and read and write
clean
391E000
unkown
page read and write
clean
46A0000
unkown
page read and write
clean
5F0000
unkown
page read and write
clean
2A0000
unkown
page readonly
clean
495D000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2D2000
unkown
page read and write
clean
5AF000
heap default
page read and write
clean
397E000
unkown
page read and write
clean
480000
unkown
page read and write
clean
39BE000
unkown
page read and write
clean
300000
unkown
page readonly
clean
6210000
heap private
page read and write
clean
3E0000
unkown
page readonly
clean
4E80000
unkown
page read and write
clean
37C1000
unkown
page read and write
clean
290000
unkown
page read and write
clean
2D7000
unkown
page execute and read and write
clean
2C7000
unkown
page read and write
clean
39FE000
unkown
page read and write
clean
5F5E000
unkown
page read and write
clean
300000
unkown
page read and write
clean
160000
heap private
page read and write
clean
393E000
unkown
page read and write
clean
506000
unkown
page read and write
clean
3A5E000
unkown
page read and write
clean
500000
unkown
page read and write
clean
340000
unkown
page execute and read and write
clean
4DD0000
heap private
page read and write
clean
5AFD000
unkown
page read and write
clean
420000
unkown
page read and write
clean
395E000
unkown
page read and write
clean
354000
heap private
page read and write
clean
3ADE000
unkown
page read and write
clean
39DF000
unkown
page read and write
clean
11D0000
unkown image
page readonly
clean
9A0000
unkown
page read and write
clean
590000
unkown
page readonly
clean
39BE000
unkown
page read and write
clean
202000
unkown image
page execute read
clean
C7F000
stack
page read and write
clean
38DE000
unkown
page read and write
clean
781000
unkown
page read and write
clean
790000
unkown
page read and write
clean
370000
heap default
page read and write
clean
4E7E000
unkown
page read and write | page guard
clean
4D0000
unkown
page read and write
clean
9A0000
unkown
page read and write
clean
3ABE000
unkown
page read and write
clean
1160000
unkown
page read and write
clean
300000
unkown
page read and write
clean
6E2000
unkown
page execute and read and write
clean
3A9E000
unkown
page read and write
clean
781000
unkown
page read and write
clean
5C1E000
stack
page read and write
clean
496E000
unkown
page read and write
clean
640000
unkown
page readonly
clean
3421000
unkown
page read and write
clean
1B6000
unkown
page execute and read and write
clean
860000
heap private
page execute and read and write
clean
393E000
unkown
page read and write
clean
3A9E000
unkown
page read and write
clean
9A0000
unkown
page read and write
clean
2B0000
unkown
page readonly
clean
387E000
unkown
page read and write
clean
3A0000
unkown
page read and write
clean
D30000
unkown
page readonly
clean
4CE000
unkown
page read and write
clean
39BE000
unkown
page read and write
clean
597E000
unkown
page read and write
clean
F0000
unkown
page readonly
clean
500000
unkown
page read and write
clean
4E5E000
unkown
page read and write
clean
208000
unkown image
page readonly
clean
2198000
unkown
page read and write
clean
667000
heap default
page read and write
clean
3A9E000
unkown
page read and write
clean
5A9D000
unkown
page read and write
clean
3ABE000
unkown
page read and write
clean
80000
unkown
page readonly
clean
3A1F000
unkown
page read and write
clean
6D0000
unkown
page execute and read and write
clean
3819000
unkown
page read and write
clean
500000
unkown
page read and write
clean
500000
unkown
page read and write
clean
1CC000
unkown
page execute and read and write
clean
399E000
unkown
page read and write
clean
4E7F000
unkown
page read and write
clean
590000
unkown
page read and write
clean
4919000
unkown
page read and write
clean
1C0000
unkown
page read and write
clean
3B1E000
unkown
page read and write
clean
3A3E000
unkown
page read and write
clean
610000
unkown
page readonly
clean
555F000
unkown
page read and write
clean
4F0000
heap default
page read and write
clean
850000
unkown
page read and write
clean
4926000
unkown
page read and write
clean
2F7000
unkown
page execute and read and write
clean
B70000
unkown
page execute and read and write
clean
4A97000
unkown
page read and write
clean
22AD000
unkown
page read and write
clean
26E1000
unkown
page read and write
clean
214E000
unkown
page read and write | page guard
clean
39DE000
unkown
page read and write
clean
4F7000
heap default
page read and write
clean
4D8F000
unkown
page read and write
clean
550000
heap default
page read and write
clean
7EFDF000
unkown
page read and write
clean
3ABE000
unkown
page read and write
clean
391E000
unkown
page read and write
clean
780000
unkown
page read and write
clean
3A7E000
unkown
page read and write
clean
790000
unkown
page read and write
clean
11D2000
unkown image
page execute read
clean
391E000
unkown
page read and write
clean
B98000
heap private
page read and write
clean
5540000
unkown
page readonly
clean
38BE000
unkown
page read and write
clean
540000
unkown
page readonly
clean
3A7E000
unkown
page read and write
clean
3A5E000
unkown
page read and write
clean
B70000
unkown
page read and write
clean
385F000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
150000
heap default
page read and write
clean
1BA000
unkown
page execute and read and write
clean
4A45000
heap private
page read and write
clean
395E000
unkown
page read and write
clean
514000
heap default
page read and write
clean
9A0000
unkown
page read and write
clean
2F1000
unkown
page read and write
clean
50A0000
unkown
page read and write
clean
790000
unkown
page read and write
clean
9A7000
unkown
page read and write
clean
62BF000
unkown
page read and write
clean
1E0000
unkown
page readonly
clean
7EF60000
unkown
page execute and read and write
clean
22A000
unkown
page execute and read and write
clean
395E000
unkown
page read and write
clean
20000
unkown
page read and write
clean
3ADE000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
422000
unkown
page execute and read and write
clean
540000
unkown
page read and write
clean
9B0000
unkown
page read and write
clean
500000
unkown
page read and write
clean
590000
unkown
page read and write
clean
7E0000
unkown
page read and write
clean
4FDC000
unkown
page read and write
clean
2B2000
unkown
page execute and read and write
clean
3A3E000
unkown
page read and write
clean
3A9E000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
3B0000
unkown
page readonly
clean
4AE0000
heap private
page execute and read and write
clean
AE5E000
stack
page read and write
clean
395E000
unkown
page read and write
clean
200000
unkown image
page readonly
clean
7F0000
unkown
page readonly
clean
1CA000
stack
page read and write
clean
4957000
unkown
page read and write
clean
417000
stack
page read and write
clean
8A0000
unkown
page read and write
clean
542000
unkown
page read and write
clean
389E000
unkown
page read and write
clean
488D000
stack
page read and write
clean
A5DF000
unkown
page read and write
clean
3AFE000
unkown
page read and write
clean
39BE000
unkown
page read and write
clean
2150000
unkown
page readonly
clean
63B000
unkown
page readonly
clean
2814000
unkown
page read and write
clean
1100000
unkown
page read and write
clean
39DE000
unkown
page read and write
clean
9A0000
unkown
page read and write
clean
607E000
unkown
page read and write
clean
500000
unkown
page read and write
clean
840000
unkown
page read and write
clean
2F0000
unkown
page readonly
clean
393E000
unkown
page read and write
clean
500000
unkown
page read and write
clean
3B1E000
unkown
page read and write
clean
237000
unkown
page execute and read and write
clean
7EFDF000
unkown
page read and write
clean
650000
unkown
page read and write
clean
3ADE000
unkown
page read and write
clean
180000
unkown
page read and write
clean
212000
unkown
page read and write
clean
11D0000
unkown image
page readonly
clean
504000
unkown
page read and write
clean
389E000
unkown
page read and write
clean
3AFE000
unkown
page read and write
clean
2DD000
heap default
page read and write
clean
39FE000
unkown
page read and write
clean
39FE000
unkown
page read and write
clean
430000
unkown
page read and write
clean
770000
unkown
page execute and read and write
clean
56C000
heap default
page read and write
clean
840000
unkown
page read and write
clean
478D000
unkown
page read and write
clean
7A0000
unkown
page readonly
clean
790000
unkown
page read and write
clean
20000
unkown
page read and write
clean
7EF50000
unkown
page execute and read and write
clean
3A5E000
unkown
page read and write
clean
45B000
unkown
page readonly
clean
61C000
unkown
page readonly
clean
500000
unkown
page read and write
clean
500000
unkown
page read and write
clean
38FE000
unkown
page read and write
clean
222000
unkown
page execute and read and write
clean
285A000
unkown
page read and write
clean
506000
unkown
page read and write
clean
C80000
unkown
page read and write
clean
B80000
unkown
page read and write
clean
2421000
unkown
page read and write
clean
4A8C000
unkown
page read and write
clean
3B1E000
unkown
page read and write
clean
790000
unkown
page read and write
clean
7A8000
unkown
page read and write
clean
2EA000
unkown
page execute and read and write
clean
62BE000
unkown
page read and write | page guard
clean
3AFE000
unkown
page read and write
clean
5AE0000
unkown
page read and write
clean
1DE7000
unkown
page readonly
clean
3ABE000
unkown
page read and write
clean
1E80000
heap private
page execute and read and write
clean
24F0000
unkown
page readonly
clean
500000
unkown
page read and write
clean
1DD0000
unkown
page read and write
clean
3A9E000
unkown
page read and write
clean
506000
unkown
page read and write
clean
46AE000
stack
page read and write
clean
437000
unkown
page readonly
clean
660000
unkown
page readonly
clean
3B1E000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
3A7E000
unkown
page read and write
clean
1FFE000
unkown
page read and write
clean
3B1000
unkown
page read and write
clean
4A40000
heap private
page read and write
clean
5C70000
heap private
page read and write
clean
48C8000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
790000
unkown
page read and write
clean
387F000
unkown
page read and write
clean
4A50000
unkown
page read and write
clean
22E5000
heap private
page execute and read and write
clean
3B0000
unkown
page read and write
clean
790000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
3ABE000
unkown
page read and write
clean
9A6000
unkown
page read and write
clean
5F2000
unkown
page read and write
clean
590000
unkown
page read and write
clean
B70000
unkown
page read and write
clean
38DE000
unkown
page read and write
clean
542000
unkown
page read and write
clean
10C0000
unkown
page read and write
clean
387E000
unkown
page read and write
clean
389E000
unkown
page read and write
clean
448000
unkown
page read and write
clean
3A1E000
unkown
page read and write
clean
3AFE000
unkown
page read and write
clean
9B0000
unkown
page read and write
clean
500000
unkown
page readonly
clean
420000
unkown
page readonly
clean
2C0000
unkown
page read and write
clean
3B1E000
unkown
page read and write
clean
21A000
unkown
page execute and read and write
clean
3ADE000
unkown
page read and write
clean
500000
unkown
page read and write
clean
38DE000
unkown
page read and write
clean
11D0000
unkown image
page readonly
clean
2E2000
unkown
page execute and read and write
clean
4ECF000
unkown
page read and write
clean
67F000
unkown
page read and write
clean
6E3000
unkown
page read and write
clean
3B3E000
unkown
page read and write
clean
A71C000
unkown
page read and write
clean
5B0000
unkown
page execute and read and write
clean
538000
heap default
page read and write
clean
24EF000
unkown
page read and write
clean
7D0000
unkown
page readonly
clean
320000
unkown
page readonly
clean
7F0000
heap private
page read and write
clean
553E000
stack
page read and write
clean
FE0000
unkown
page readonly
clean
4890000
unkown
page read and write
clean
59A000
heap default
page read and write
clean
2BA000
unkown
page execute and read and write
clean
2E0000
unkown
page execute and read and write
clean
3F0000
unkown
page read and write
clean
5F0000
unkown
page read and write
clean
210000
unkown
page readonly
clean
7EFDF000
unkown
page read and write
clean
208000
unkown image
page readonly
clean
19A000
unkown
page execute and read and write
clean
3ABE000
unkown
page read and write
clean
6EA000
unkown
page read and write
clean
840000
unkown
page read and write
clean
A61C000
unkown
page read and write
clean
4916000
unkown
page read and write
clean
140000
unkown
page readonly
clean
4A1E000
unkown
page read and write
clean
239E000
unkown
page read and write
clean
385F000
unkown
page read and write
clean
D0000
unkown
page readonly
clean
5DDE000
unkown
page read and write
clean
500000
heap private
page execute and read and write
clean
390000
unkown
page readonly
clean
1150000
unkown
page read and write
clean
4C5E000
stack
page read and write
clean
790000
unkown
page read and write
clean
60AE000
unkown
page read and write
clean
10E0000
unkown
page read and write
clean
310000
unkown
page readonly
clean
393E000
unkown
page read and write
clean
6A8000
heap default
page read and write
clean
9A0000
unkown
page read and write
clean
72B0000
unkown
page read and write
clean
372000
heap private
page read and write
clean
38FE000
unkown
page read and write
clean
3A1E000
unkown
page read and write
clean
1132000
heap private
page read and write
clean
568E000
unkown
page read and write
clean
48F4000
unkown
page read and write
clean
5EEE000
stack
page read and write
clean
BC000
unkown
page read and write
clean
590E000
unkown
page read and write
clean
11D2000
unkown image
page execute read
clean
3B3E000
unkown
page read and write
clean
506000
unkown
page read and write
clean
300000
unkown
page read and write
clean
5C0000
unkown
page read and write
clean
506000
unkown
page read and write
clean
506000
unkown
page read and write
clean
29F6000
unkown
page read and write
clean
500000
unkown
page read and write
clean
3ABE000
unkown
page read and write
clean
574000
heap default
page read and write
clean
5C7000
unkown
page read and write
clean
9A8000
unkown
page read and write
clean
617000
unkown
page readonly
clean
350000
unkown
page readonly
clean
7E0000
unkown
page read and write
clean
9A5000
unkown
page read and write
clean
3A0000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
500000
unkown
page read and write
clean
5D9E000
stack
page read and write
clean
2A0000
heap default
page read and write
clean
B10000
unkown
page readonly
clean
716000
unkown
page read and write
clean
B65000
unkown
page read and write
clean
2190000
unkown
page read and write
clean
217000
unkown
page execute and read and write
clean
500000
unkown
page read and write
clean
4FE0000
unkown
page readonly
clean
200000
unkown image
page readonly
clean
3ADE000
unkown
page read and write
clean
60B0000
unkown
page write copy
clean
400000
unkown
page execute and read and write
clean
5290000
unkown
page read and write
clean
5F0000
unkown
page read and write
clean
38DE000
unkown
page read and write
clean
3ADE000
unkown
page read and write
clean
330000
unkown
page read and write
clean
4A6D000
unkown
page read and write
clean
500000
unkown
page read and write
clean
3AFE000
unkown
page read and write
clean
3ADE000
unkown
page read and write
clean
21A0000
unkown
page read and write
clean
21FC000
unkown
page read and write
clean
3A9F000
unkown
page read and write
clean
710000
unkown
page read and write
clean
2F1000
unkown
page read and write
clean
2EB000
heap default
page read and write
clean
9A8000
unkown
page read and write
clean
2C6000
unkown
page read and write | page guard
clean
780000
unkown
page read and write
clean
3B1E000
unkown
page read and write
clean
4D8E000
unkown
page read and write | page guard
clean
598000
unkown
page read and write
clean
B70000
unkown
page read and write
clean
11AC000
unkown
page read and write
clean
3A5E000
unkown
page read and write
clean
9A0000
unkown
page read and write
clean
1100000
unkown
page read and write
clean
660000
heap default
page read and write
clean
6C9000
heap private
page read and write
clean
399E000
unkown
page read and write
clean
1AC000
unkown
page execute and read and write
clean
1A0000
unkown
page read and write
clean
39DE000
unkown
page read and write
clean
2E6000
heap default
page read and write
clean
1100000
unkown
page read and write
clean
3A1E000
unkown
page read and write
clean
170000
unkown
page read and write
clean
1E4000
heap private
page read and write
clean
3ADE000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
4F0000
unkown
page execute and read and write
clean
4F0000
unkown
page execute and read and write
clean
23DE000
unkown
page read and write
clean
599E000
unkown
page read and write
clean
AFF000
unkown
page read and write
clean
140000
unkown
page read and write
clean
1110000
heap private
page read and write
clean
1DE0000
unkown
page readonly
clean
790000
unkown
page read and write
clean
132000
unkown
page execute and read and write
clean
D10000
unkown
page readonly
clean
385E000
unkown
page read and write
clean
970000
unkown
page readonly
clean
50C000
unkown
page read and write
clean
39FE000
unkown
page read and write
clean
C2F000
unkown
page read and write
clean
505000
unkown
page read and write
clean
3A5E000
unkown
page read and write
clean
4CE000
unkown
page read and write
clean
500000
unkown
page read and write
clean
9A0000
unkown
page read and write
clean
7B0000
heap private
page execute and read and write
clean
2D0000
heap private
page read and write
clean
6C0000
heap private
page read and write
clean
760000
unkown
page readonly
clean
10C0000
unkown
page readonly
clean
540000
unkown
page read and write
clean
3ADE000
unkown
page read and write
clean
2A7000
heap default
page read and write
clean
72F000
unkown
page read and write
clean
150000
unkown
page read and write
clean
3A3E000
unkown
page read and write
clean
1E0B000
unkown
page readonly
clean
5290000
unkown
page read and write
clean
38FE000
unkown
page read and write
clean
537E000
unkown
page read and write
clean
5A5000
unkown
page read and write
clean
5290000
unkown
page readonly
clean
3B1E000
unkown
page read and write
clean
1C2000
unkown
page execute and read and write
clean
5ADE000
unkown
page read and write
clean
300000
unkown
page read and write
clean
3B5000
unkown
page read and write
clean
430000
unkown
page readonly
clean
385F000
unkown
page read and write
clean
3B0000
unkown
page read and write
clean
5C0000
unkown
page read and write
clean
3A3E000
unkown
page read and write
clean
3AFE000
unkown
page read and write
clean
1D90000
unkown
page readonly
clean
A89F000
stack
page read and write
clean
142000
unkown
page execute and read and write
clean
500000
unkown
page read and write
clean
63FE000
unkown
page read and write | page guard
clean
500000
unkown
page read and write
clean
3ADE000
unkown
page read and write
clean
3A1E000
unkown
page read and write
clean
3A9F000
unkown
page read and write
clean
10D0000
unkown
page read and write
clean
225D000
unkown
page read and write
clean
3A3E000
unkown
page read and write
clean
B50000
unkown
page readonly
clean
43C000
unkown
page readonly
clean
22E0000
heap private
page execute and read and write
clean
543E000
unkown
page read and write
clean
397E000
unkown
page read and write
clean
790000
unkown
page read and write
clean
3A3E000
unkown
page read and write
clean
790000
unkown
page read and write
clean
557000
heap default
page read and write
clean
3AFE000
unkown
page read and write
clean
507000
unkown
page read and write
clean
3D0000
heap private
page read and write
clean
500000
unkown
page read and write
clean
38BE000
unkown
page read and write
clean
2DB000
unkown
page execute and read and write
clean
3D6000
unkown
page read and write
clean
500000
unkown
page read and write
clean
1A2000
unkown
page execute and read and write
clean
790000
unkown
page read and write
clean
510000
heap default
page read and write
clean
202000
unkown image
page execute read
clean
8BD000
unkown
page read and write
clean
AA000
unkown
page read and write
clean
3A1E000
unkown
page read and write
clean
3A5E000
unkown
page read and write
clean
3A5E000
unkown
page read and write
clean
1DEC000
unkown
page readonly
clean
4C60000
unkown
page read and write
clean
600000
unkown
page read and write
clean
790000
unkown
page read and write
clean
500000
unkown
page read and write
clean
5290000
unkown
page read and write
clean
9A0000
unkown
page read and write
clean
3B0000
unkown
page read and write
clean
7E0000
unkown
page read and write
clean
500000
unkown
page read and write
clean
3C0000
unkown
page execute and read and write
clean
39DE000
unkown
page read and write
clean
16D000
unkown
page read and write
clean
5090000
unkown
page read and write
clean
500000
unkown
page read and write
clean
500000
unkown
page read and write
clean
250000
heap private
page execute and read and write
clean
2302000
heap private
page execute and read and write
clean
397E000
unkown
page read and write
clean
29FA000
unkown
page read and write
clean
3A7E000
unkown
page read and write
clean
391E000
unkown
page read and write
clean
4C5F000
unkown
page read and write
clean
496C000
unkown
page read and write
clean
389E000
unkown
page read and write
clean
5F0000
unkown
page read and write
clean
310000
unkown
page read and write
clean
38FE000
unkown
page read and write
clean
ABAC000
stack
page read and write
clean
399E000
unkown
page read and write
clean
399E000
unkown
page read and write
clean
5B5000
unkown
page read and write
clean
5F1000
unkown
page read and write
clean
500000
unkown
page read and write
clean
350000
heap private
page read and write
clean
500000
unkown
page read and write
clean
47FE000
unkown
page read and write
clean
2C0000
unkown
page read and write
clean
493D000
unkown
page read and write
clean
602D000
stack
page read and write
clean
3A1E000
unkown
page read and write
clean
27C1000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
4D10000
unkown
page read and write
clean
3ABE000
unkown
page read and write
clean
5F0000
unkown
page readonly
clean
3AFE000
unkown
page read and write
clean
507000
unkown
page read and write
clean
4B04000
heap private
page execute and read and write
clean
2190000
unkown
page read and write
clean
1CA000
unkown
page execute and read and write
clean
192000
unkown
page execute and read and write
clean
34E000
unkown
page read and write
clean
1C6000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
3A9E000
unkown
page read and write
clean
B90000
heap private
page read and write
clean
360000
heap private
page read and write
clean
D00000
heap private
page read and write
clean
3A7E000
unkown
page read and write
clean
3A7E000
unkown
page read and write
clean
4ACE000
unkown
page read and write
clean
75C000
unkown
page read and write
clean
3B0000
unkown
page read and write
clean
440000
unkown
page read and write
clean
26F9000
unkown
page read and write
clean
There are 629 hidden memdumps, click here to show them.