IOCReport

loading gif

Files

File Path
Type
Category
Malicious
Documents_111651917_375818984.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1251, Last Saved By: 5, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Mon May 3 14:24:59 2021, Security: 0
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\vegas[1].dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
downloaded
malicious
C:\Users\user\bsdnbsej.dbw
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
modified
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\vegas[1].dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
downloaded
malicious
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, 58596 bytes, 1 file
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\2[1].json
Non-ISO extended-ASCII text, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\2[1].json
Non-ISO extended-ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\fOhFGX570RDgmgTtbgZ5[1]
data
downloaded
clean
C:\Users\user\AppData\Local\Temp\ECA40000
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Thu Jun 27 17:12:41 2019, mtime=Mon May 3 22:13:16 2021, atime=Mon May 3 22:13:16 2021, length=8192, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Documents_111651917_375818984.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Sep 30 06:35:51 2020, mtime=Mon May 3 22:13:16 2021, atime=Mon May 3 22:13:16 2021, length=127488, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
Little-endian UTF-16 Unicode text, with CR line terminators
dropped
clean
C:\Users\user\Desktop\CDA40000
Applesoft BASIC program data, first line number 16
dropped
clean
C:\Users\user\AppData\Local\Temp\06CE0000
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\VPKC7C2S.txt
ASCII text
downloaded
clean
C:\Users\user\Desktop\C6CE0000
Applesoft BASIC program data, first line number 16
dropped
clean
There are 8 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32 ..\bsdnbsej.dbw,PluginInit
malicious
C:\Windows\SysWOW64\cmd.exe
C:\Windows\System32\cmd.exe
malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\bsdnbsej.dbw,PluginInit
malicious

URLs

Name
IP
Malicious
http://fedir.comsign.co.il/crl/ComSignSecuredCA.crl0
unknown
clean
http://www.certplus.com/CRL/class3.crl0
unknown
clean
http://www.e-me.lv/repository0
unknown
clean
http://www.acabogacia.org/doc0
unknown
clean
http://crl.chambersign.org/chambersroot.crl0
unknown
clean
http://ocsp.suscerte.gob.ve0
unknown
clean
http://www.postsignum.cz/crl/psrootqca2.crl02
unknown
clean
http://crl.dhimyotis.com/certignarootca.crl0
unknown
clean
http://sertifikati.ca.posta.rs/crl/PostaCARoot.crl0
unknown
clean
https://18.222.240.99/qOh
unknown
clean
http://www.chambersign.org1
unknown
clean
http://www.pkioverheid.nl/policies/root-policy0
unknown
clean
http://repository.swisssign.com/0
unknown
clean
http://www.suscerte.gob.ve/lcr0#
unknown
clean
http://ca2.mtin.es/mtin/crl/MTINAutoridadRaiz0
unknown
clean
http://crl.ssc.lt/root-c/cacrl.crl0
unknown
clean
http://postsignum.ttc.cz/crl/psrootqca2.crl0
unknown
clean
http://www.trustcenter.de/crl/v2/tc_class_3_ca_II.crl
unknown
clean
http://ca.disig.sk/ca/crl/ca_disig.crl0
unknown
clean
http://crl1.comsign.co.il/crl/comsignglobalrootca.crl0
unknown
clean
http://www.certplus.com/CRL/class3P.crl0
unknown
clean
http://www.suscerte.gob.ve/dpc0
unknown
clean
http://www.certeurope.fr/reference/root2.crl0
unknown
clean
http://www.certplus.com/CRL/class2.crl0
unknown
clean
http://www.disig.sk/ca/crl/ca_disig.crl0
unknown
clean
http://eca.hinet.net/repository/Certs/IssuedToThisCA.p7b05
unknown
clean
http://www.defence.gov.au/pki0
unknown
clean
http://www.sk.ee/cps/0
unknown
clean
http://www.globaltrust.info0=
unknown
clean
http://www.anf.es
unknown
clean
http://www.pki.admin.ch/cps/CPS_2_16_756_1_17_3_1_0.pdf09
unknown
clean
http://pki.registradores.org/normativa/index.htm0
unknown
clean
http://policy.camerfirma.com0
unknown
clean
http://www.ssc.lt/cps03
unknown
clean
http://ocsp.pki.gva.es0
unknown
clean
http://www.anf.es/es/address-direccion.html
unknown
clean
https://www.anf.es/address/)1(0&
unknown
clean
http://acraiz.icpbrasil.gov.br/DPCacraiz.pdf0?
unknown
clean
https://18.222.240.99/hOg
unknown
clean
http://ca.mtin.es/mtin/ocsp0
unknown
clean
http://crl.ssc.lt/root-b/cacrl.crl0
unknown
clean
http://web.ncdc.gov.sa/crl/nrcacomb1.crl0
unknown
clean
http://www.certicamara.com/dpc/0Z
unknown
clean
http://www.uce.gub.uy/informacion-tecnica/politicas/cp_acrn.pdf0G
unknown
clean
http://crl.pki.wellsfargo.com/wsprca.crl0
unknown
clean
https://18.222.240.99/update/infoy
unknown
clean
https://wwww.certigna.fr/autorites/0m
unknown
clean
http://www.dnie.es/dpc0
unknown
clean
http://www.ica.co.il/repository/cps/PersonalID_Practice_Statement.pdf0
unknown
clean
http://ca.mtin.es/mtin/DPCyPoliticas0
unknown
clean
https://www.anf.es/AC/ANFServerCA.crl0
unknown
clean
http://www.globaltrust.info0
unknown
clean
http://certificates.starfieldtech.com/repository/1604
unknown
clean
http://acedicom.edicomgroup.com/doc0
unknown
clean
http://www.certplus.com/CRL/class3TS.crl0
unknown
clean
https://crl.anf.es/AC/ANFServerCA.crl0
unknown
clean
http://www.certeurope.fr/reference/pc-root2.pdf0
unknown
clean
http://ac.economia.gob.mx/last.crl0G
unknown
clean
https://www.catcert.net/verarrel
unknown
clean
http://www.disig.sk/ca0f
unknown
clean
http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1.crt0
unknown
clean
http://www.e-szigno.hu/RootCA.crl
unknown
clean
http://www.sk.ee/juur/crl/0
unknown
clean
http://crl.chambersign.org/chambersignroot.crl0
unknown
clean
http://crl.xrampsecurity.com/XGCA.crl0
unknown
clean
http://certs.oati.net/repository/OATICA2.crl0
unknown
clean
http://crl.oces.trust2408.com/oces.crl0
unknown
clean
http://www.quovadis.bm0
unknown
clean
https://eca.hinet.net/repository0
unknown
clean
http://crl.ssc.lt/root-a/cacrl.crl0
unknown
clean
http://certs.oaticerts.com/repository/OATICA2.crl
unknown
clean
http://www.trustdst.com/certificates/policy/ACES-index.html0
unknown
clean
http://certs.oati.net/repository/OATICA2.crt0
unknown
clean
http://www.accv.es00
unknown
clean
http://www.pkioverheid.nl/policies/root-policy-G20
unknown
clean
https://www.netlock.net/docs
unknown
clean
http://www.pki.admin.ch/policy/CPS_2_16_756_1_17_3_21_1.pdf0
unknown
clean
https://18.222.240.99/
unknown
clean
http://www.e-trust.be/CPS/QNcerts
unknown
clean
http://ocsp.ncdc.gov.sa0
unknown
clean
http://html4/loose.dtd
unknown
clean
http://fedir.comsign.co.il/crl/ComSignCA.crl0
unknown
clean
http://trustcenter-crl.certificat2.com/Keynectis/KEYNECTIS_ROOT_CA.crl0
unknown
clean
http://web.ncdc.gov.sa/crl/nrcaparta1.crl
unknown
clean
http://www.datev.de/zertifikat-policy-int0
unknown
clean
http://fedir.comsign.co.il/crl/comsignglobalrootca.crl0;
unknown
clean
https://repository.luxtrust.lu0
unknown
clean
http://cps.chambersign.org/cps/chambersroot.html0
unknown
clean
http://www.acabogacia.org0
unknown
clean
http://ocsp.eca.hinet.net/OCSP/ocspG2sha20
unknown
clean
http://www.firmaprofesional.com/cps0
unknown
clean
http://www.uce.gub.uy/acrn/acrn.crl0
unknown
clean
http://.css
unknown
clean
http://crl.securetrust.com/SGCA.crl0
unknown
clean
http://fedir.comsign.co.il/cacert/ComSignAdvancedSecurityCA.crt0
unknown
clean
https://18.222.240.99/versal
unknown
clean
http://www.agesic.gub.uy/acrn/acrn.crl0)
unknown
clean
https://18.222.240.99/gO~
unknown
clean
http://crl.securetrust.com/STCA.crl0
unknown
clean
http://www.rcsc.lt/repository0
unknown
clean
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://investor.msn.com/
unknown
clean
There are 98 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
otusmail.com
104.21.64.132
clean
cdn.digicertcdn.com
104.18.10.39
clean

IPs

IP
Domain
Country
Malicious
18.222.240.99
unknown
United States
malicious
104.21.64.132
otusmail.com
United States
clean
54.163.9.216
unknown
United States
clean
172.67.151.10
otusmail.com
United States
clean

Registry

Path
Value
Malicious
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
d.1
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
e.1
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastBootTime
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ReviewToken
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
4A238
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
VBAFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
MSForms
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
MSComctlLib
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
1
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
UpdateComplete
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
4AA95
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
4AB7F
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
4AC3B
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
4AD35
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
4AE10
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
)c1
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
FileFormatBallotBoxAppIDBootedOnce
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
en-US
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
en-US
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
EXCELFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
RoamingConfigurableSettings
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
RoamingLastSyncTime
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
RoamingLastWriteTime
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
CacheReady
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastRequest
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
CacheReady
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastUpdate
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
NextUpdate
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastBootTime
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
r37
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EBE5F
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
FontCachePath
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC4B6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC533
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC5BF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC69A
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC716
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
2?7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\system32\qagentrt.dll,-10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-843
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-844
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\wuaueng.dll,-400
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
FDBBF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
FDD26
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SavedLegacySettings
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
There are 157 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
7FF5B8497000
unkown
page readonly
clean
22329E30000
heap private
page read and write
clean
94788FF000
unkown
page read and write
clean
67330000
unkown image
page readonly
clean
7FF5E527E000
unkown
page readonly
clean
7FF5B87C7000
unkown
page readonly
clean
D30000
unkown
page readonly
clean
245AADE0000
unkown
page readonly
clean
2CCD000
unkown
page readonly
clean
24BDBFA000
unkown
page read and write
clean
3107000
unkown
page read and write
clean
24BD5FC000
unkown
page read and write
clean
4FC9000
unkown
page read and write
clean
2BB7000
unkown
page readonly
clean
5A0000
heap default
page read and write
clean
24BDEFE000
unkown
page read and write
clean
1BC000
unkown
page read and write
clean
7FF535250000
unkown
page readonly
clean
4C0F000
unkown
page read and write
clean
2BE6000
unkown
page readonly
clean
5171000
unkown
page read and write
clean
2C31000
unkown
page readonly
clean
5B4A000
unkown
page readonly
clean
2FF3000
unkown
page readonly
clean
19573A50000
heap default
page read and write
clean
2F23000
unkown
page readonly
clean
2BBD000
unkown
page readonly
clean
2A63000
unkown
page readonly
clean
5C5000
unkown
page read and write
clean
245AADD5000
heap private
page read and write
clean
19578FB0000
unkown
page read and write
clean
2A58000
unkown
page readonly
clean
7FF5352A4000
unkown
page readonly
clean
6A0000
unkown
page readonly
clean
4A2E000
unkown
page read and write
clean
4C10000
unkown
page readonly
clean
5C5000
unkown
page read and write
clean
639000
heap default
page read and write
clean
2BCA000
unkown
page readonly
clean
19579210000
unkown
page read and write
clean
19573B30000
unkown
page readonly
clean
2BEB000
unkown
page readonly
clean
4D0000
heap default
page read and write
clean
2B4F000
unkown
page readonly
clean
480000
unkown
page readonly
clean
5170000
unkown
page read and write
clean
7FF5352BE000
unkown
page readonly
clean
D90000
unkown
page readonly
clean
117E000
unkown
page read and write
clean
2EDF000
unkown
page readonly
clean
2BB5000
unkown
page readonly
clean
845787E000
unkown
page read and write
clean
4FBA000
unkown
page read and write
clean
30AA000
unkown
page read and write
clean
58F000
unkown
page read and write
clean
2B7D000
unkown
page readonly
clean
7FF57A8F2000
unkown
page readonly
clean
2A69000
unkown
page readonly
clean
22329E35000
heap private
page read and write
clean
2E0F000
unkown
page readonly
clean
310A000
unkown
page read and write
clean
2BBF000
unkown
page readonly
clean
310A000
unkown
page read and write
clean
EB0000
unkown
page readonly
clean
195790D4000
unkown
page read and write
clean
2C63000
unkown
page readonly
clean
2CC3000
unkown
page readonly
clean
10B0000
unkown
page readonly
clean
6BDE000
unkown
page read and write
clean
7FF57A969000
unkown
page readonly
clean
5FF4000
unkown
page readonly
clean
674B9000
unkown image
page readonly
clean
3105000
unkown
page read and write
clean
7FF5E5258000
unkown
page readonly
clean
2F60000
unkown
page read and write
clean
42B0000
unkown
page read and write
clean
19579190000
unkown
page read and write
clean
6D30000
unkown
page read and write
clean
7FF5352CD000
unkown
page readonly
clean
67345000
unkown image
page readonly
clean
C00000
heap private
page read and write
clean
19574C00000
unkown
page readonly
clean
EA0000
heap private
page read and write
clean
7FF5352AF000
unkown
page readonly
clean
23AAD8E0000
unkown
page readonly
clean
460000
unkown
page read and write
clean
22329C59000
unkown
page read and write
clean
24BDFFF000
unkown
page read and write
clean
19573C6E000
unkown
page read and write
clean
6D1F000
unkown
page read and write
clean
790000
unkown
page readonly
clean
308A000
heap default
page read and write
clean
7FF5B87AE000
unkown
page readonly
clean
7FF5B8826000
unkown
page readonly
clean
7FF5B879C000
unkown
page readonly
clean
22329C58000
unkown
page read and write
clean
5021000
unkown
page read and write
clean
19579210000
unkown
page readonly
clean
8BD000
unkown
page read and write
clean
2F2B000
unkown
page readonly
clean
30F8000
unkown
page read and write
clean
7FF5B87B0000
unkown
page readonly
clean
947000
unkown
page read and write
clean
2F20000
unkown
page execute and read and write
clean
4A40000
heap private
page read and write
clean
960000
unkown
page readonly
clean
7FF57A9D4000
unkown
page readonly
clean
7FF5B8804000
unkown
page readonly
clean
512E000
unkown
page read and write
clean
19573B50000
unkown
page read and write
clean
67343000
unkown image
page read and write
clean
7FF5B8049000
unkown
page readonly
clean
19573CAC000
unkown
page read and write
clean
7FF5B83C5000
unkown
page readonly
clean
E50000
unkown
page readonly
clean
E70000
unkown
page read and write
clean
7FF5B852F000
unkown
page readonly
clean
7FF5E5304000
unkown
page readonly
clean
195794BD000
unkown
page read and write
clean
2A7F000
unkown
page readonly
clean
67331000
unkown image
page execute read
clean
2B9B000
unkown
page readonly
clean
3035000
unkown
page read and write
clean
8457AFF000
unkown
page read and write
clean
4B8F000
unkown
page read and write
clean
22329D30000
unkown
page read and write
clean
6F9000
unkown
page read and write
clean
1957940C000
unkown
page read and write
clean
1957949C000
unkown
page read and write
clean
7FF5B88A2000
unkown
page readonly
clean
51A4000
unkown
page read and write
clean
7FF5E528E000
unkown
page readonly
clean
2B59000
unkown
page readonly
clean
23AAD6FC000
heap default
page read and write
clean
2F1C000
unkown
page readonly
clean
245AABD0000
unkown
page read and write
clean
7D0000
unkown
page readonly
clean
B70000
unkown
page execute and read and write
clean
7FF5B8601000
unkown
page readonly
clean
7FF5E5222000
unkown
page readonly
clean
19574C40000
unkown
page readonly
clean
19579453000
unkown
page read and write
clean
7FF5B87B5000
unkown
page readonly
clean
2F4F000
unkown
page readonly
clean
5021000
unkown
page read and write
clean
2FC5000
unkown
page readonly
clean
19574518000
unkown
page read and write
clean
4FC8000
unkown
page read and write
clean
24BE1FF000
unkown
page read and write
clean
7FF5B8588000
unkown
page readonly
clean
2BC3000
unkown
page readonly
clean
19574C20000
unkown
page readonly
clean
28E6000
unkown
page readonly
clean
2B63000
unkown
page readonly
clean
84578FF000
unkown
page read and write
clean
2BEB000
unkown
page readonly
clean
310A000
unkown
page read and write
clean
35C000
unkown
page read and write
clean
2BA0000
unkown
page readonly
clean
7FF5B878F000
unkown
page readonly
clean
7FF5B8489000
unkown
page readonly
clean
3107000
unkown
page read and write
clean
7FF5E5225000
unkown
page readonly
clean
4FC6000
unkown
page readonly
clean
67320000
unkown image
page readonly
clean
19579270000
unkown
page readonly
clean
67358000
unkown image
page execute read
clean
300C000
unkown
page read and write
clean
2873000
unkown
page readonly
clean
7FF5B876F000
unkown
page readonly
clean
22329C58000
unkown
page read and write
clean
7FF5B8312000
unkown
page readonly
clean
22329C4A000
unkown
page read and write
clean
30BE000
unkown
page read and write
clean
48B0000
unkown
page readonly
clean
67353000
unkown image
page read and write
clean
19574500000
unkown
page read and write
clean
7FF5B859B000
unkown
page readonly
clean
2CC5000
unkown
page readonly
clean
7FF535255000
unkown
page readonly
clean
2A90000
unkown
page readonly
clean
2C44000
unkown
page readonly
clean
7FF5B87F8000
unkown
page readonly
clean
49AD000
unkown
page read and write
clean
19574402000
unkown
page read and write
clean
2FDC000
unkown
page readonly
clean
22329C5B000
unkown
page read and write
clean
19574C30000
unkown
page readonly
clean
23AAD640000
unkown
page read and write
clean
19573D02000
unkown
page read and write
clean
195794DD000
unkown
page read and write
clean
6734C000
unkown image
page readonly
clean
2F60000
unkown
page read and write
clean
19574C50000
unkown
page readonly
clean
19579184000
unkown
page read and write
clean
30F8000
unkown
page read and write
clean
2C44000
unkown
page readonly
clean
3010000
heap default
page read and write
clean
19579210000
unkown
page read and write
clean
4A0000
unkown
page readonly
clean
933000
unkown
page read and write
clean
2BBF000
unkown
page readonly
clean
6A9B000
unkown
page read and write
clean
24BE0FF000
unkown
page read and write
clean
2F80000
heap private
page read and write
clean
5711000
unkown
page readonly
clean
7FF5B879A000
unkown
page readonly
clean
7FF5B877B000
unkown
page readonly
clean
2F7B000
unkown
page readonly
clean
23AAD680000
unkown
page readonly
clean
2DF3000
unkown
page readonly
clean
3083000
heap default
page read and write
clean
19574513000
unkown
page read and write
clean
6BE0000
unkown
page read and write
clean
7FF5351D1000
unkown
page readonly
clean
6BE0000
unkown
page read and write
clean
4C0000
unkown
page execute and read and write
clean
19573D13000
unkown
page read and write
clean
22329C20000
unkown
page readonly
clean
860000
heap default
page read and write
clean
7FF535341000
unkown
page readonly
clean
22329B30000
unkown
page readonly
clean
30AA000
unkown
page read and write
clean
19574BF0000
unkown
page readonly
clean
19579200000
unkown
page read and write
clean
2B5D000
unkown
page readonly
clean
195790B8000
unkown
page read and write
clean
4F70000
unkown
page read and write
clean
30E1000
unkown
page read and write
clean
6842C7E000
unkown
page read and write
clean
7FF5B881E000
unkown
page readonly
clean
94787FE000
unkown
page read and write
clean
4C30000
unkown
page readonly
clean
55F000
unkown
page read and write
clean
7A0000
unkown
page readonly
clean
9FC000
unkown
page read and write
clean
7FF5B8784000
unkown
page readonly
clean
2A7F000
unkown
page readonly
clean
4A30000
unkown
page readonly
clean
7FF57A93A000
unkown
page readonly
clean
937000
heap default
page read and write
clean
7FF5B87DF000
unkown
page readonly
clean
7FF5E522B000
unkown
page readonly
clean
2BA9000
unkown
page readonly
clean
19574601000
unkown
page read and write
clean
195791A8000
unkown
page read and write
clean
7FF53529A000
unkown
page readonly
clean
490000
unkown
page readonly
clean
7FF5B87AA000
unkown
page readonly
clean
5AA000
heap default
page read and write
clean
E60000
unkown
page execute and read and write
clean
4F71000
unkown
page read and write
clean
19574A30000
unkown
page read and write
clean
58B000
unkown
page read and write
clean
2FE2000
unkown
page readonly
clean
4FA1000
unkown
page read and write
clean
30BE000
unkown
page read and write
clean
674A8000
unkown image
page read and write
clean
7FF5B8750000
unkown
page readonly
clean
7FF5B87BB000
unkown
page readonly
clean
30E2000
unkown
page read and write
clean
7FF5B8773000
unkown
page readonly
clean
19573C73000
unkown
page read and write
clean
639000
unkown
page read and write
clean
900000
unkown
page execute and read and write
clean
7FF5B8818000
unkown
page readonly
clean
4B0000
unkown
page readonly
clean
24BDCFE000
unkown
page read and write
clean
7FF5B88A1000
unkown
page readonly
clean
67330000
unkown image
page readonly
clean
7FF5B8763000
unkown
page readonly
clean
19573C91000
unkown
page read and write
clean
2F72000
unkown
page readonly
clean
2F60000
unkown
page read and write
clean
7FF5B880F000
unkown
page readonly
clean
2C58000
unkown
page readonly
clean
2F76000
unkown
page readonly
clean
7FF5B8056000
unkown
page readonly
clean
2C0E000
unkown
page readonly
clean
7FF57A8FB000
unkown
page readonly
clean
2C63000
unkown
page readonly
clean
35D000
unkown
page read and write
clean
4C20000
heap private
page read and write
clean
7FF5B849A000
unkown
page readonly
clean
2BB5000
unkown
page readonly
clean
7FF5352C9000
unkown
page readonly
clean
6842BFE000
unkown
page read and write
clean
67355000
unkown image
page readonly
clean
7FF5B8406000
unkown
page readonly
clean
195790E0000
unkown
page read and write
clean
7FF5B871C000
unkown
page readonly
clean
7FF5B85F1000
unkown
page readonly
clean
195790BE000
unkown
page read and write
clean
7FF5B858F000
unkown
page readonly
clean
2A79000
unkown
page readonly
clean
673AE000
unkown image
page read and write
clean
2B8C000
unkown
page readonly
clean
19573C29000
unkown
page read and write
clean
19574C10000
unkown
page readonly
clean
245AADD0000
heap private
page read and write
clean
59EB000
unkown
page readonly
clean
30E9000
unkown
page read and write
clean
2DE8000
unkown
page readonly
clean
7FF57A8F5000
unkown
page readonly
clean
7FF5E5220000
unkown
page readonly
clean
19574415000
unkown
page read and write
clean
19578FA0000
unkown
page read and write
clean
195791C0000
unkown
page read and write
clean
4F71000
unkown
page read and write
clean
2B6A000
unkown
page readonly
clean
900000
unkown
page read and write
clean
2BE2000
unkown
page readonly
clean
5040000
unkown
page readonly
clean
19574A00000
unkown
page readonly
clean
301A000
heap default
page read and write
clean
19573BE0000
unkown
page read and write
clean
4FA2000
unkown
page read and write
clean
6560000
unkown
page readonly
clean
7FF5E5264000
unkown
page readonly
clean
2F5A000
unkown
page readonly
clean
7FF5B8829000
unkown
page readonly
clean
2C52000
unkown
page readonly
clean
19574900000
unkown
page read and write
clean
7FF53533A000
unkown
page readonly
clean
2883000
unkown
page readonly
clean
19573C13000
unkown
page read and write
clean
6BE0000
unkown
page read and write
clean
19579250000
unkown
page readonly
clean
2C39000
unkown
page readonly
clean
2C4C000
unkown
page readonly
clean
4FB6000
unkown
page read and write
clean
2F53000
unkown
page readonly
clean
22329C45000
unkown
page read and write
clean
2B48000
unkown
page readonly
clean
7FF57A8F0000
unkown
page readonly
clean
195790F0000
unkown
page read and write
clean
5C4000
unkown
page read and write
clean
2BCA000
unkown
page readonly
clean
19573BC1000
unkown
page read and write
clean
195790B0000
unkown
page read and write
clean
E30000
unkown
page readonly
clean
B6F000
unkown
page read and write
clean
19579320000
unkown
page readonly
clean
195743C0000
unkown
page read and write
clean
19573C75000
unkown
page read and write
clean
51BB000
unkown
page read and write
clean
7FF5B877F000
unkown
page readonly
clean
11D0000
unkown
page execute and read and write
clean
2C31000
unkown
page readonly
clean
33C0000
unkown
page readonly
clean
3107000
unkown
page read and write
clean
2F5F000
unkown
page readonly
clean
19573CFC000
unkown
page read and write
clean
7FF57A958000
unkown
page readonly
clean
84579FF000
unkown
page read and write
clean
2FCD000
unkown
page read and write
clean
4FA4000
unkown
page read and write
clean
6370000
unkown
page readonly
clean
2B85000
unkown
page readonly
clean
DA0000
unkown
page readonly
clean
2F4D000
unkown
page readonly
clean
6373000
unkown
page readonly
clean
7FF5352B8000
unkown
page readonly
clean
D70000
unkown
page read and write
clean
4EB0000
unkown
page readonly
clean
195791E0000
unkown
page read and write
clean
2C35000
unkown
page readonly
clean
7FF5B865A000
unkown
page readonly
clean
67320000
unkown image
page readonly
clean
7FF5B86FD000
unkown
page readonly
clean
2BE6000
unkown
page readonly
clean
19573C53000
unkown
page read and write
clean
930000
unkown
page readonly
clean
7FF5E5274000
unkown
page readonly
clean
7FF5B85A1000
unkown
page readonly
clean
B29000
unkown
page read and write
clean
7FF5B85E4000
unkown
page readonly
clean
195790B1000
unkown
page read and write
clean
19573CA3000
unkown
page read and write
clean
2BA0000
unkown
page readonly
clean
51E0000
unkown
page readonly
clean
5022000
unkown
page read and write
clean
94783FC000
unkown
page read and write
clean
4FA4000
unkown
page read and write
clean
7FF57A94E000
unkown
page readonly
clean
2FD4000
unkown
page readonly
clean
673AF000
unkown image
page execute and read and write
clean
195739F0000
heap private
page read and write
clean
7FF5B86F6000
unkown
page readonly
clean
308A000
unkown
page read and write
clean
195743D0000
unkown
page read and write
clean
19574502000
unkown
page read and write
clean
674B8000
unkown image
page read and write
clean
7FF5B889A000
unkown
page readonly
clean
845759C000
unkown
page read and write
clean
E35000
heap default
page read and write
clean
7FF5B85AD000
unkown
page readonly
clean
4FFD000
unkown
page read and write
clean
2B93000
unkown
page readonly
clean
7FF5B87DC000
unkown
page readonly
clean
19573A60000
unkown
page readonly
clean
23AAD570000
unkown
page readonly
clean
2F47000
unkown
page readonly
clean
7C5000
heap default
page read and write
clean
23AAD8D5000
heap private
page read and write
clean
E30000
heap default
page read and write
clean
51E000
unkown
page read and write
clean
24BDDFB000
unkown
page read and write
clean
517F000
unkown
page read and write
clean
E40000
unkown
page readonly
clean
245AAC10000
unkown
page readonly
clean
1FB000
unkown
page read and write
clean
850000
unkown
page readonly
clean
195791F0000
unkown
page read and write
clean
7FF5E5312000
unkown
page readonly
clean
245AAAD8000
heap default
page read and write
clean
19573BE3000
unkown
page read and write
clean
30E2000
unkown
page read and write
clean
2A90000
unkown
page readonly
clean
2BA9000
unkown
page readonly
clean
11C0000
unkown
page readonly
clean
2BC3000
unkown
page readonly
clean
19573C8C000
unkown
page read and write
clean
1957947E000
unkown
page read and write
clean
245AAAD0000
heap default
page read and write
clean
3107000
unkown
page read and write
clean
358000
unkown
page read and write
clean
24BDF7F000
unkown
page read and write
clean
7FF5B87F4000
unkown
page readonly
clean
7FF5B87E7000
unkown
page readonly
clean
7FF5B8642000
unkown
page readonly
clean
B2D000
unkown
page read and write
clean
8BD000
heap default
page read and write
clean
19579481000
unkown
page read and write
clean
19579200000
unkown
page read and write
clean
195794EE000
unkown
page read and write
clean
24BDAFA000
unkown
page read and write
clean
6739E000
unkown image
page read and write
clean
22329E40000
unkown
page readonly
clean
22329AD0000
unkown
page readonly
clean
19579260000
unkown
page readonly
clean
19573C78000
unkown
page read and write
clean
2B93000
unkown
page readonly
clean
195791D0000
unkown
page read and write
clean
7FF57A934000
unkown
page readonly
clean
947877F000
unkown
page read and write
clean
7FF5B865F000
unkown
page readonly
clean
19579460000
unkown
page read and write
clean
89B000
unkown
page read and write
clean
19579180000
unkown
page readonly
clean
2FC1000
unkown
page readonly
clean
4FB6000
unkown
page read and write
clean
4FA4000
unkown
page read and write
clean
2C63000
unkown
page readonly
clean
2F30000
unkown
page readonly
clean
6842B7F000
unkown
page read and write
clean
7FF5B80B1000
unkown
page readonly
clean
3035000
unkown
page read and write
clean
7FF5B855A000
unkown
page readonly
clean
7FF535294000
unkown
page readonly
clean
19573C9C000
unkown
page read and write
clean
23AAD510000
unkown
page readonly
clean
2BE2000
unkown
page readonly
clean
7FF53527C000
unkown
page readonly
clean
19573BF0000
unkown
page read and write
clean
7FF5E529D000
unkown
page readonly
clean
7FF5B85E6000
unkown
page readonly
clean
245AABF0000
unkown
page read and write
clean
19579400000
unkown
page read and write
clean
24BE17E000
unkown
page read and write
clean
6FB000
unkown
page read and write
clean
7FF5B85AF000
unkown
page readonly
clean
195790E0000
unkown
page read and write
clean
2F60000
unkown
page read and write
clean
4FB6000
unkown
page read and write
clean
2C35000
unkown
page readonly
clean
3110000
unkown
page readonly
clean
2F1F000
unkown
page read and write
clean
7FF57A944000
unkown
page readonly
clean
59E000
unkown
page read and write
clean
7FF57A95E000
unkown
page readonly
clean
19579210000
unkown
page read and write
clean
4ACE000
unkown
page read and write
clean
7FF535252000
unkown
page readonly
clean
2BCF000
unkown
page readonly
clean
245AA9F0000
unkown
page readonly
clean
7FF5E524C000
unkown
page readonly
clean
19573B60000
unkown
page read and write
clean
4FA4000
unkown
page read and write
clean
30E5000
unkown
page read and write
clean
19579180000
unkown
page read and write
clean
62F1000
unkown
page readonly
clean
195790B0000
unkown
page read and write
clean
19574190000
unkown
page readonly
clean
1957943C000
unkown
page read and write
clean
5B66000
unkown
page readonly
clean
7FF5E5299000
unkown
page readonly
clean
2B59000
unkown
page readonly
clean
868000
heap default
page read and write
clean
2B8C000
unkown
page readonly
clean
6012000
unkown
page readonly
clean
23AAD6D0000
heap default
page read and write
clean
7FF5B873C000
unkown
page readonly
clean
19573C3D000
unkown
page read and write
clean
2C4C000
unkown
page readonly
clean
2EDE000
unkown
page read and write
clean
23AAD660000
unkown
page read and write
clean
19579449000
unkown
page read and write
clean
245AAFE0000
unkown
page readonly
clean
2F30000
unkown
page readonly
clean
7FF5B80D0000
unkown
page readonly
clean
28A9000
unkown
page readonly
clean
6D20000
unkown
page readonly
clean
DD0000
unkown
page read and write
clean
19574400000
unkown
page read and write
clean
2B7D000
unkown
page readonly
clean
2B5D000
unkown
page readonly
clean
19573E00000
unkown
page readonly
clean
2C13000
unkown
page readonly
clean
944000
heap default
page read and write
clean
310A000
unkown
page read and write
clean
11BE000
unkown
page read and write
clean
3036000
unkown
page read and write
clean
2B9B000
unkown
page readonly
clean
6733C000
unkown image
page readonly
clean
4A8F000
unkown
page read and write
clean
7FF5B7FFC000
unkown
page readonly
clean
7FF5B856B000
unkown
page readonly
clean
2B63000
unkown
page readonly
clean
6ADD000
unkown
page read and write
clean
7FF57A9E2000
unkown
page readonly
clean
7FF5B8671000
unkown
page readonly
clean
57E1000
unkown
page readonly
clean
2BBD000
unkown
page readonly
clean
4FA6000
unkown
page read and write
clean
570B000
unkown
page readonly
clean
2F45000
unkown
page readonly
clean
947867F000
unkown
page read and write
clean
504E000
unkown
page read and write
clean
DD0000
heap private
page read and write
clean
49EE000
unkown
page read and write
clean
2F39000
unkown
page readonly
clean
4B4E000
unkown
page read and write
clean
2873000
unkown
page readonly
clean
2DF9000
unkown
page readonly
clean
1957942C000
unkown
page read and write
clean
7FF5B8576000
unkown
page readonly
clean
2F70000
unkown
page readonly
clean
30E4000
unkown
page read and write
clean
7FF5B83C7000
unkown
page readonly
clean
6739F000
unkown image
page execute and read and write
clean
E20000
unkown
page readonly
clean
19573C25000
unkown
page read and write
clean
24BD9F7000
unkown
page read and write
clean
23AAD6DB000
heap default
page read and write
clean
7FF5B8655000
unkown
page readonly
clean
7FF5E5288000
unkown
page readonly
clean
C3B000
unkown
page read and write
clean
947887F000
unkown
page read and write
clean
2B6A000
unkown
page readonly
clean
7FF57A9E1000
unkown
page readonly
clean
5D59000
unkown
page readonly
clean
E70000
unkown
page read and write
clean
195790D1000
unkown
page read and write
clean
7FF5B8012000
unkown
page readonly
clean
7FF535334000
unkown
page readonly
clean
699E000
unkown
page read and write
clean
24BE2FE000
unkown
page read and write
clean
3105000
unkown
page read and write
clean
1220000
unkown
page readonly
clean
19574F90000
unkown
page read and write
clean
195792F0000
unkown
page readonly
clean
7FF57A96D000
unkown
page readonly
clean
7FF535342000
unkown
page readonly
clean
19578F90000
unkown
page read and write
clean
2F88000
heap private
page read and write
clean
7FF57A928000
unkown
page readonly
clean
5070000
unkown
page readonly
clean
24BDE7E000
unkown
page read and write
clean
3072000
heap default
page read and write
clean
7FF5E526A000
unkown
page readonly
clean
7C0000
heap default
page read and write
clean
19579210000
unkown
page read and write
clean
4B0A000
unkown
page read and write
clean
19579194000
unkown
page readonly
clean
2BCF000
unkown
page readonly
clean
2FE8000
unkown
page readonly
clean
2A3C000
unkown
page readonly
clean
4FA1000
unkown
page read and write
clean
516E000
unkown
page read and write
clean
22329C30000
heap default
page read and write
clean
2F15000
unkown
page readonly
clean
19573C00000
unkown
page read and write
clean
67348000
unkown image
page execute read
clean
7FF5E530A000
unkown
page readonly
clean
19579413000
unkown
page read and write
clean
7FF5B80FE000
unkown
page readonly
clean
2C52000
unkown
page readonly
clean
7FF534F15000
unkown
page readonly
clean
7FF57A91C000
unkown
page readonly
clean
2BB7000
unkown
page readonly
clean
7FF57A9DA000
unkown
page readonly
clean
7FF535288000
unkown
page readonly
clean
2EF3000
unkown
page readonly
clean
195794CD000
unkown
page read and write
clean
740000
unkown
page read and write
clean
3107000
unkown
page read and write
clean
4BCE000
unkown
page read and write
clean
674A9000
unkown image
page readonly
clean
C10000
unkown
page readonly
clean
19579500000
unkown
page read and write
clean
19573C56000
unkown
page read and write
clean
19573B40000
unkown
page readonly
clean
8457A7F000
unkown
page read and write
clean
24BE5FE000
unkown
page read and write
clean
4AC0000
unkown
page readonly
clean
19574B10000
unkown
page read and write
clean
2B85000
unkown
page readonly
clean
68427FA000
unkown
page read and write
clean
195791AA000
unkown
page write copy
clean
920000
heap private
page read and write
clean
2CCB000
unkown
page readonly
clean
6C1E000
unkown
page read and write
clean
2BD1000
unkown
page readonly
clean
23AAD8D0000
heap private
page read and write
clean
22329C3B000
heap default
page read and write
clean
47D0000
unkown
page readonly
clean
7FF5B8441000
unkown
page readonly
clean
E70000
unkown
page execute and read and write
clean
639000
unkown
page read and write
clean
19573C8A000
unkown
page read and write
clean
504E000
unkown
page read and write
clean
195790F4000
unkown
page read and write
clean
590A000
unkown
page readonly
clean
7FF5B8894000
unkown
page readonly
clean
2C63000
unkown
page readonly
clean
4F7F000
unkown
page read and write
clean
B70000
unkown
page readonly
clean
67321000
unkown image
page execute read
clean
7FF5E5311000
unkown
page readonly
clean
30FF000
unkown
page read and write
clean
3105000
unkown
page read and write
clean
24BE3FB000
unkown
page read and write
clean
CA0000
unkown
page readonly
clean
4FBA000
unkown
page read and write
clean
7FF5B8494000
unkown
page readonly
clean
2C58000
unkown
page readonly
clean
19579220000
unkown
page read and write
clean
1957941E000
unkown
page read and write
clean
7FF53525B000
unkown
page readonly
clean
287E000
unkown
page readonly
clean
3107000
unkown
page read and write
clean
195790D0000
unkown
page read and write
clean
2BD1000
unkown
page readonly
clean
22329C00000
unkown
page read and write
clean
There are 645 hidden memdumps, click here to show them.