Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\Lista produkt#U00f3w.exe
|
'C:\Users\user\Desktop\Lista produkt#U00f3w.exe'
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
|
unknown
|
||
http://www.windows.com/pctv.
|
unknown
|
||
http://investor.msn.com
|
unknown
|
||
http://www.msnbc.com/news/ticker.txt
|
unknown
|
||
http://www.icra.org/vocabulary/.
|
unknown
|
||
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
|
unknown
|
||
http://www.hotmail.com/oe
|
unknown
|
||
http://investor.msn.com/
|
unknown
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
1D70000
|
unkown
|
page execute and read and write
|
||
3225000
|
unkown
|
page readonly
|
||
401000
|
unkown image
|
page execute read
|
||
2B30000
|
unkown
|
page readonly
|
||
31D2000
|
unkown
|
page readonly
|
||
3126000
|
unkown
|
page readonly
|
||
7EFDF000
|
unkown
|
page read and write
|
||
1CE0000
|
unkown
|
page read and write
|
||
4C0000
|
heap default
|
page read and write
|
||
3102000
|
unkown
|
page readonly
|
||
3400000
|
unkown
|
page readonly
|
||
3186000
|
unkown
|
page readonly
|
||
2D0000
|
unkown
|
page readonly
|
||
3B4000
|
heap private
|
page read and write
|
||
4E4000
|
heap default
|
page read and write
|
||
8E0000
|
unkown
|
page readonly
|
||
400000
|
unkown image
|
page readonly
|
||
2B50000
|
unkown
|
page readonly
|
||
3094000
|
unkown
|
page readonly
|
||
3192000
|
unkown
|
page readonly
|
||
26F0000
|
heap private
|
page read and write
|
||
414000
|
unkown image
|
page readonly
|
||
30B4000
|
unkown
|
page readonly
|
||
412000
|
unkown image
|
page read and write
|
||
30B2000
|
unkown
|
page readonly
|
||
3209000
|
unkown
|
page readonly
|
||
2290000
|
unkown
|
page readonly
|
||
3F0000
|
unkown
|
page read and write
|
||
31B6000
|
unkown
|
page readonly
|
||
26F4000
|
heap private
|
page read and write
|
||
3156000
|
unkown
|
page readonly
|
||
31D9000
|
unkown
|
page readonly
|
||
1E58000
|
heap private
|
page read and write
|
||
3092000
|
unkown
|
page readonly
|
||
2712000
|
heap private
|
page read and write
|
||
401000
|
unkown image
|
page execute read
|
||
31B9000
|
unkown
|
page readonly
|
||
3132000
|
unkown
|
page readonly
|
||
30D2000
|
unkown
|
page readonly
|
||
3162000
|
unkown
|
page readonly
|
||
3B0000
|
heap private
|
page read and write
|
||
33C2000
|
unkown
|
page readonly
|
||
2730000
|
unkown
|
page read and write
|
||
250000
|
heap default
|
page read and write
|
||
2ED8000
|
unkown
|
page readonly
|
||
3420000
|
unkown
|
page readonly
|
||
3440000
|
unkown
|
page readonly
|
||
8A000
|
unkown
|
page read and write
|
||
30D4000
|
unkown
|
page readonly
|
||
3239000
|
unkown
|
page readonly
|
||
1B0000
|
unkown
|
page readonly
|
||
3647000
|
unkown
|
page readonly
|
||
1E90000
|
unkown
|
page read and write
|
||
1E3A000
|
heap private
|
page read and write
|
||
1E30000
|
heap private
|
page read and write
|
||
240000
|
unkown
|
page readonly
|
||
414000
|
unkown image
|
page readonly
|
||
3B8000
|
heap private
|
page read and write
|
||
3232000
|
unkown
|
page readonly
|
||
740000
|
unkown
|
page readonly
|
||
400000
|
unkown image
|
page readonly
|
||
1DE0000
|
heap private
|
page read and write
|
||
2FD2000
|
unkown
|
page readonly
|
||
3175000
|
unkown
|
page readonly
|
||
4C7000
|
heap default
|
page read and write
|
||
3460000
|
unkown
|
page readonly
|
||
420000
|
unkown
|
page read and write
|
||
3BB000
|
heap private
|
page read and write
|
||
1E80000
|
heap private
|
page read and write
|
||
18D000
|
unkown
|
page read and write
|
||
31A5000
|
unkown
|
page readonly
|
||
5C0000
|
unkown
|
page readonly
|
||
400000
|
unkown image
|
page readonly
|
||
4A0000
|
unkown
|
page write copy
|
||
3255000
|
unkown
|
page readonly
|
||
20000
|
heap private
|
page read and write
|
||
2ED2000
|
unkown
|
page readonly
|
||
230000
|
unkown
|
page execute read
|
||
3115000
|
unkown
|
page readonly
|
||
31BD000
|
unkown
|
page readonly
|
||
3145000
|
unkown
|
page readonly
|
||
3202000
|
unkown
|
page readonly
|
||
31F5000
|
unkown
|
page readonly
|
There are 73 hidden memdumps, click here to show them.