IOCReport

loading gif

Files

File Path
Type
Category
Malicious
PO4018308875.doc
Rich Text Format data, unknown version
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\princedanx[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Local\Temp\princedan859323.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Roaming\princedan859323.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{9B09F78D-537D-406E-B057-1B1541B1D39D}.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{C67C7B4A-7023-4170-93C2-146687425423}.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{F7C72BCE-A594-453E-9048-97C10E531855}.tmp
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\PO4018308875.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:15 2020, mtime=Wed Aug 26 14:08:15 2020, atime=Thu Jul 22 20:14:33 2021, length=50939, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
dropped
clean
C:\Users\user\Desktop\~$4018308875.doc
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
malicious
C:\Users\user\AppData\Roaming\princedan859323.exe
C:\Users\user\AppData\Roaming\princedan859323.exe
malicious
C:\Users\user\AppData\Local\Temp\princedan859323.exe
C:\Users\user\AppData\Local\Temp\princedan859323.exe vgyjnbhui
malicious
C:\Users\user\AppData\Local\Temp\princedan859323.exe
C:\Users\user\AppData\Local\Temp\princedan859323.exe vgyjnbhui
malicious
C:\Users\user\AppData\Local\Temp\princedan859323.exe
C:\Users\user\AppData\Local\Temp\princedan859323.exe vgyjnbhui
malicious
C:\Users\user\AppData\Local\Temp\princedan859323.exe
C:\Users\user\AppData\Local\Temp\princedan859323.exe vgyjnbhui
malicious
C:\Users\user\AppData\Local\Temp\princedan859323.exe
C:\Users\user\AppData\Local\Temp\princedan859323.exe vgyjnbhui
malicious
C:\Users\user\AppData\Local\Temp\princedan859323.exe
C:\Users\user\AppData\Local\Temp\princedan859323.exe vgyjnbhui
malicious
C:\Users\user\AppData\Local\Temp\princedan859323.exe
C:\Users\user\AppData\Local\Temp\princedan859323.exe vgyjnbhui
malicious
C:\Users\user\AppData\Local\Temp\princedan859323.exe
C:\Users\user\AppData\Local\Temp\princedan859323.exe vgyjnbhui
malicious
C:\Users\user\AppData\Local\Temp\princedan859323.exe
C:\Users\user\AppData\Local\Temp\princedan859323.exe vgyjnbhui
malicious
C:\Users\user\AppData\Local\Temp\princedan859323.exe
C:\Users\user\AppData\Local\Temp\princedan859323.exe vgyjnbhui
malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
'C:\Program Files\Microsoft Office\Office14\WINWORD.EXE' /Automation -Embedding
clean
There are 3 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://topv.xyz/princedanx.exe
185.239.243.112
malicious
www.containerflippers.com/np0c/
malicious
http://go.microso
unknown
clean
http://www.opera.com0
unknown
clean

Domains

Name
IP
Malicious
topv.xyz
185.239.243.112
malicious

IPs

IP
Domain
Country
Malicious
185.239.243.112
topv.xyz
Moldova Republic of
malicious

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
,i7
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
tj7
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
,k7
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
ECC16
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@Arial Unicode MS
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@Batang
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@BatangChe
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@DFKai-SB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@Dotum
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@DotumChe
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@FangSong
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@Gulim
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@GulimChe
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@Gungsuh
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@GungsuhChe
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@KaiTi
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@Malgun Gothic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@Meiryo
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@Meiryo UI
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@Microsoft JhengHei
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@Microsoft YaHei
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@MingLiU
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@MingLiU_HKSCS
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@MingLiU_HKSCS-ExtB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@MingLiU-ExtB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@MS Gothic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@MS Mincho
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@MS PGothic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@MS PMincho
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@MS UI Gothic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@NSimSun
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@PMingLiU
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@PMingLiU-ExtB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@SimHei
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@SimSun
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@SimSun-ExtB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Agency FB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Aharoni
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Algerian
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Andalus
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Angsana New
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
AngsanaUPC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Aparajita
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Arabic Typesetting
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Arial
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Arial Black
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Arial Narrow
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Arial Rounded MT Bold
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Arial Unicode MS
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Baskerville Old Face
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Batang
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
BatangChe
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Bauhaus 93
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Bell MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Berlin Sans FB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Berlin Sans FB Demi
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Bernard MT Condensed
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Blackadder ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Bodoni MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Bodoni MT Black
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Bodoni MT Condensed
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Bodoni MT Poster Compressed
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Book Antiqua
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Bookman Old Style
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Bookshelf Symbol 7
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Bradley Hand ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Britannic Bold
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Broadway
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Browallia New
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
BrowalliaUPC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Brush Script MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Calibri
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Calibri Light
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Californian FB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Calisto MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Cambria
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Cambria Math
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Candara
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Castellar
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Centaur
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Century
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Century Gothic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Century Schoolbook
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Chiller
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Colonna MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Comic Sans MS
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Consolas
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Constantia
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Cooper Black
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Copperplate Gothic Bold
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Copperplate Gothic Light
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Corbel
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Cordia New
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
CordiaUPC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Courier New
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Curlz MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
DaunPenh
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
David
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
DFKai-SB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
DilleniaUPC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
DokChampa
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Dotum
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
DotumChe
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Ebrima
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Edwardian Script ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Elephant
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Engravers MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Eras Bold ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Eras Demi ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Eras Light ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Eras Medium ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Estrangelo Edessa
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
EucrosiaUPC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Euphemia
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
FangSong
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Felix Titling
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Footlight MT Light
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Forte
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Franklin Gothic Book
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Franklin Gothic Demi
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Franklin Gothic Demi Cond
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Franklin Gothic Heavy
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Franklin Gothic Medium
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Franklin Gothic Medium Cond
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
FrankRuehl
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
FreesiaUPC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Freestyle Script
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
French Script MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gabriola
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Garamond
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gautami
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Georgia
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gigi
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gill Sans MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gill Sans MT Condensed
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gill Sans MT Ext Condensed Bold
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gill Sans Ultra Bold
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gill Sans Ultra Bold Condensed
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gisha
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gloucester MT Extra Condensed
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Goudy Old Style
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Goudy Stout
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gulim
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
GulimChe
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gungsuh
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
GungsuhChe
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Haettenschweiler
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Harlow Solid Italic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Harrington
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
High Tower Text
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Impact
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Imprint MT Shadow
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Informal Roman
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
IrisUPC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Iskoola Pota
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
JasmineUPC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Jokerman
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Juice ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
KaiTi
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Kalinga
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Kartika
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Khmer UI
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
KodchiangUPC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Kokila
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Kristen ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Kunstler Script
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Lao UI
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Latha
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Leelawadee
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Levenim MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
LilyUPC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Lucida Bright
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Lucida Calligraphy
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Lucida Console
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Lucida Fax
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Lucida Handwriting
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Lucida Sans
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Lucida Sans Typewriter
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Lucida Sans Unicode
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Magneto
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Maiandra GD
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Malgun Gothic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Mangal
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Marlett
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Matura MT Script Capitals
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Meiryo
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Meiryo UI
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Microsoft Himalaya
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Microsoft JhengHei
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Microsoft New Tai Lue
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Microsoft PhagsPa
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Microsoft Sans Serif
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Microsoft Tai Le
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Microsoft Uighur
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Microsoft YaHei
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Microsoft Yi Baiti
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MingLiU
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MingLiU_HKSCS
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MingLiU_HKSCS-ExtB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MingLiU-ExtB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Miriam
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Miriam Fixed
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Mistral
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Modern No. 20
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Mongolian Baiti
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Monotype Corsiva
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MoolBoran
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MS Gothic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MS Mincho
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MS Outlook
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MS PGothic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MS PMincho
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MS Reference Sans Serif
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MS Reference Specialty
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MS UI Gothic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MT Extra
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MV Boli
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Narkisim
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Niagara Engraved
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Niagara Solid
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NSimSun
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Nyala
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
OCR A Extended
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Old English Text MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Onyx
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Palace Script MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Palatino Linotype
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Papyrus
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Parchment
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Perpetua
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Perpetua Titling MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Plantagenet Cherokee
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Playbill
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
PMingLiU
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
PMingLiU-ExtB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Poor Richard
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Pristina
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Raavi
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Rage Italic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Ravie
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Rockwell
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Rockwell Condensed
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Rockwell Extra Bold
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Rod
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Sakkal Majalla
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Script MT Bold
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Segoe Print
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Segoe Script
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Segoe UI
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Segoe UI Light
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Segoe UI Semibold
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Segoe UI Symbol
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Shonar Bangla
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Showcard Gothic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Shruti
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SimHei
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Simplified Arabic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Simplified Arabic Fixed
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SimSun
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SimSun-ExtB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Snap ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Stencil
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Sylfaen
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Symbol
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Tahoma
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Tempus Sans ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Times New Roman
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Traditional Arabic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Trebuchet MS
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Tunga
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Tw Cen MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Tw Cen MT Condensed
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Tw Cen MT Condensed Extra Bold
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Utsaah
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Vani
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Verdana
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Vijaya
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Viner Hand ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Vivaldi
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Vladimir Script
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Vrinda
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Webdings
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Wide Latin
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Wingdings
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Wingdings 2
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Wingdings 3
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
F3B3C
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
WORDFiles
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
F3B3C
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Settings
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
ZoomApp
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MTTF
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MTTA
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
EquationEditorFilesIntl_1033
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
SavedLegacySettings
clean
C:\Users\user\AppData\Roaming\princedan859323.exe
FontCachePath
clean
There are 314 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
3399000
unkown
page read and write
malicious
3520000
unkown
page read and write
malicious
3562000
unkown
page read and write
malicious
58E2000
unkown
page readonly
clean
6060000
unkown image
page readonly
clean
4960000
unkown
page read and write
clean
73DA000
unkown
page read and write
clean
46C000
unkown image
page readonly
clean
6330000
unkown
page read and write
clean
750000
unkown
page read and write
clean
6F0000
unkown
page read and write
clean
6730000
unkown
page read and write
clean
5220000
unkown
page read and write
clean
5C40000
unkown
page read and write
clean
297000
unkown
page execute and read and write
clean
67A0000
unkown
page read and write
clean
6060000
unkown image
page readonly
clean
5874000
unkown
page readonly
clean
2130000
unkown
page read and write
clean
620000
unkown
page read and write
clean
26D000
unkown
page execute and read and write
clean
4EA0000
heap private
page read and write
clean
5B2000
unkown
page read and write
clean
6425000
unkown
page read and write
clean
6C0C000
unkown
page read and write
clean
5BA000
unkown
page read and write
clean
6AE0000
unkown
page read and write
clean
663E000
unkown
page read and write
clean
4300000
unkown
page read and write
clean
168000
unkown
page read and write
clean
6637000
unkown
page read and write
clean
50A0000
unkown
page read and write
clean
46C000
unkown image
page readonly
clean
46C000
unkown image
page readonly
clean
654C000
unkown
page read and write
clean
8F0000
unkown image
page readonly
clean
6639000
unkown
page read and write
clean
6B25000
unkown
page read and write
clean
3E0000
unkown image
page readonly
clean
66A6000
unkown
page read and write
clean
6868000
unkown
page read and write
clean
6A74000
unkown
page read and write
clean
8D0000
unkown
page read and write
clean
3F8000
unkown
page read and write
clean
8E0000
unkown
page read and write
clean
61EE000
unkown
page read and write
clean
300000
unkown
page readonly
clean
690000
unkown
page read and write
clean
46C000
unkown image
page readonly
clean
3E0000
unkown image
page readonly
clean
7BE000
unkown
page read and write
clean
46F0000
unkown
page read and write
clean
4860000
unkown
page read and write
clean
6060000
unkown image
page readonly
clean
3E2000
unkown image
page execute read
clean
5F10000
unkown
page write copy
clean
760000
unkown
page read and write
clean
29B000
unkown
page execute and read and write
clean
4290000
unkown
page read and write
clean
690000
unkown
page read and write
clean
3299000
unkown
page read and write
clean
46C000
unkown image
page readonly
clean
8CA000
unkown
page read and write
clean
2170000
unkown
page read and write
clean
4EC5000
unkown
page read and write
clean
48F0000
unkown
page read and write
clean
701000
unkown
page read and write
clean
620000
unkown
page read and write
clean
3E2000
unkown image
page execute read
clean
6428000
unkown
page read and write
clean
5C20000
unkown
page readonly
clean
6421000
unkown
page read and write
clean
6A9E000
unkown
page read and write
clean
3E0000
unkown image
page readonly
clean
231A000
unkown
page read and write
clean
58B2000
unkown
page readonly
clean
50BD000
unkown
page read and write
clean
310000
unkown
page read and write
clean
638A000
unkown
page read and write
clean
5925000
unkown
page readonly
clean
66BE000
unkown
page read and write
clean
3E2000
unkown image
page execute read
clean
46C000
unkown image
page readonly
clean
4710000
unkown
page read and write
clean
52D4000
heap private
page read and write
clean
3E0000
unkown image
page readonly
clean
3E0000
unkown image
page readonly
clean
3E0000
unkown image
page readonly
clean
58B4000
unkown
page readonly
clean
641C000
unkown
page read and write
clean
69A000
unkown
page read and write
clean
B20000
unkown
page readonly
clean
46C000
unkown image
page readonly
clean
5996000
unkown
page readonly
clean
690000
unkown
page read and write
clean
5999000
unkown
page readonly
clean
8F0000
unkown image
page readonly
clean
5230000
unkown
page read and write
clean
831E000
unkown
page read and write
clean
4890000
unkown
page read and write
clean
46C000
unkown image
page readonly
clean
8F2000
unkown image
page execute read
clean
370000
heap default
page read and write
clean
4720000
unkown
page read and write
clean
3E0000
unkown image
page readonly
clean
2170000
unkown
page read and write
clean
8C0000
unkown
page read and write
clean
770000
heap private
page read and write
clean
6E0000
unkown
page execute and read and write
clean
6060000
unkown image
page readonly
clean
3E0000
unkown image
page readonly
clean
504E000
unkown
page read and write
clean
658C000
unkown
page read and write
clean
2291000
unkown
page read and write
clean
5A05000
unkown
page readonly
clean
66AE000
unkown
page read and write
clean
4319000
unkown
page read and write
clean
2365000
unkown
page read and write
clean
620000
unkown
page read and write
clean
610000
unkown
page read and write
clean
8B0000
unkown
page read and write
clean
8C0000
unkown
page read and write
clean
690000
unkown
page read and write
clean
690000
unkown
page read and write
clean
6060000
unkown image
page readonly
clean
6534000
unkown
page read and write
clean
264000
unkown
page read and write
clean
2333000
unkown
page read and write
clean
490000
unkown
page readonly
clean
6060000
unkown image
page readonly
clean
20C0000
unkown
page readonly
clean
70C000
unkown
page read and write
clean
8A0000
unkown
page read and write
clean
67DC000
unkown
page read and write
clean
6B76000
unkown
page read and write
clean
2140000
unkown
page read and write
clean
2130000
unkown
page read and write
clean
6AB6000
unkown
page read and write
clean
8A0000
unkown
page read and write
clean
75C6000
unkown
page read and write
clean
3E2000
unkown image
page execute read
clean
6B17000
unkown
page read and write
clean
661A000
unkown
page read and write
clean
3E0000
unkown image
page readonly
clean
871E000
unkown
page read and write
clean
5166000
unkown
page read and write
clean
4900000
unkown
page read and write
clean
3E2000
unkown image
page execute read
clean
5050000
unkown
page read and write
clean
46C000
unkown image
page readonly
clean
46C000
unkown image
page readonly
clean
6AD8000
unkown
page read and write
clean
4AD0000
unkown
page readonly
clean
6818000
unkown
page read and write
clean
48E0000
unkown
page read and write
clean
6AEB000
unkown
page read and write
clean
6FEF000
unkown
page read and write
clean
52B0000
unkown
page read and write
clean
67AE000
unkown
page read and write
clean
613000
unkown
page read and write
clean
3E0000
unkown image
page readonly
clean
690000
unkown
page read and write
clean
6AE3000
unkown
page read and write
clean
700000
unkown
page read and write
clean
5330000
unkown
page readonly
clean
286000
unkown
page execute and read and write
clean
680000
unkown
page execute and read and write
clean
8A0000
unkown
page read and write
clean
8A0000
unkown
page read and write
clean
4310000
unkown
page read and write
clean
750000
unkown
page read and write
clean
6B1D000
unkown
page read and write
clean
66EF000
unkown
page read and write
clean
2150000
unkown
page read and write
clean
6B61000
unkown
page read and write
clean
5BE0000
unkown
page readonly
clean
5CB0000
unkown
page read and write
clean
680000
unkown
page read and write
clean
8A0000
unkown
page read and write
clean
6292000
unkown
page read and write
clean
66A8000
unkown
page read and write
clean
8A0000
unkown
page read and write
clean
2C0000
heap private
page read and write
clean
5E90000
unkown
page read and write
clean
4720000
unkown
page read and write
clean
66F7000
unkown
page read and write
clean
670B000
unkown
page read and write
clean
35B9000
unkown
page read and write
clean
2130000
unkown
page read and write
clean
6454000
unkown
page read and write
clean
4300000
unkown
page read and write
clean
534000
heap default
page read and write
clean
3E2000
unkown image
page execute read
clean
8A0000
unkown
page read and write
clean
760000
unkown
page read and write
clean
760000
unkown
page read and write
clean
680000
unkown
page read and write
clean
6B63000
unkown
page read and write
clean
6AA8000
unkown
page read and write
clean
75E3000
unkown
page read and write
clean
3E2000
unkown image
page execute read
clean
68DE000
unkown
page read and write
clean
2150000
unkown
page read and write
clean
4ACE000
unkown
page read and write
clean
8D0000
unkown
page read and write
clean
5A12000
unkown
page readonly
clean
8D0000
unkown
page read and write
clean
5955000
unkown
page readonly
clean
69CB000
unkown
page read and write
clean
3E0000
unkown image
page readonly
clean
6827000
unkown
page read and write
clean
6666000
unkown
page read and write
clean
5BA2000
unkown
page readonly
clean
750000
unkown
page read and write
clean
6E0000
unkown
page read and write
clean
5DA000
unkown
page read and write
clean
5C40000
unkown
page read and write
clean
656F000
unkown
page read and write
clean
66C7000
unkown
page read and write
clean
4740000
unkown
page read and write
clean
3E0000
unkown image
page readonly
clean
5240000
unkown
page read and write
clean
4E90000
unkown
page read and write
clean
8D0000
unkown
page read and write
clean
4710000
unkown
page read and write
clean
550000
heap default
page read and write
clean
5AD000
unkown
page read and write
clean
5210000
unkown
page read and write
clean
510D000
unkown
page read and write
clean
6F0000
unkown
page read and write
clean
66AC000
unkown
page read and write
clean
4ED0000
heap private
page read and write
clean
59E2000
unkown
page readonly
clean
46C000
unkown image
page readonly
clean
62D0000
unkown
page read and write
clean
310000
unkown
page read and write
clean
3E0000
unkown image
page readonly
clean
766000
unkown
page read and write
clean
6131000
unkown
page read and write
clean
66C5000
unkown
page read and write
clean
3E0000
unkown image
page readonly
clean
6312000
unkown
page read and write
clean
234C000
unkown
page read and write
clean
8A0000
unkown
page read and write
clean
61AE000
unkown
page read and write
clean
2140000
unkown
page read and write
clean
4970000
unkown
page read and write
clean
8B0000
unkown
page read and write
clean
71A000
heap private
page read and write
clean
750000
unkown
page read and write
clean
4310000
unkown
page read and write
clean
8E0000
unkown
page read and write
clean
810E000
unkown
page read and write
clean
46C000
unkown image
page readonly
clean
67EB000
unkown
page read and write
clean
6705000
unkown
page read and write
clean
6187000
unkown
page read and write
clean
66C0000
unkown
page read and write
clean
66CC000
unkown
page read and write
clean
760000
unkown
page read and write
clean
6B6B000
unkown
page read and write
clean
46C000
unkown image
page readonly
clean
8C0000
unkown
page read and write
clean
6898000
unkown
page read and write
clean
4EC0000
unkown
page read and write
clean
5166000
unkown
page read and write
clean
3E2000
unkown image
page execute read
clean
5152000
unkown
page read and write
clean
663B000
unkown
page read and write
clean
217E000
unkown
page read and write
clean
5892000
unkown
page readonly
clean
64BD000
unkown
page read and write
clean
5E0E000
unkown
page read and write
clean
661E000
unkown
page read and write
clean
68F2000
unkown
page read and write
clean
6C59000
unkown
page read and write
clean
55D000
heap default
page read and write
clean
6483000
unkown
page read and write
clean
760000
unkown
page read and write
clean
4850000
unkown
page read and write
clean
4890000
unkown
page read and write
clean
630000
unkown
page read and write
clean
620000
unkown
page read and write
clean
5182000
unkown
page read and write
clean
46C000
unkown image
page readonly
clean
228F000
unkown
page read and write
clean
4900000
unkown
page read and write
clean
699000
unkown
page read and write
clean
666D000
unkown
page read and write
clean
8E0000
unkown
page read and write
clean
23AF000
unkown
page read and write
clean
6060000
unkown image
page readonly
clean
484F000
unkown
page read and write
clean
738000
heap private
page read and write
clean
63FA000
unkown
page read and write
clean
627E000
unkown
page read and write
clean
4EAC000
heap private
page read and write
clean
3E2000
unkown image
page execute read
clean
6939000
unkown
page read and write
clean
4E0000
unkown
page read and write
clean
6431000
unkown
page read and write
clean
690000
unkown
page read and write
clean
6F37000
unkown
page read and write
clean
4729000
unkown
page read and write
clean
6A5E000
unkown
page read and write
clean
690000
unkown
page read and write
clean
680000
unkown
page read and write
clean
5936000
unkown
page readonly
clean
634F000
unkown
page read and write
clean
5310000
unkown
page readonly
clean
6F30000
unkown
page read and write
clean
680000
unkown
page read and write
clean
610000
unkown
page read and write
clean
5E90000
unkown
page read and write
clean
5250000
unkown
page read and write
clean
5166000
unkown
page read and write
clean
760000
unkown
page read and write
clean
5912000
unkown
page readonly
clean
617000
unkown
page read and write
clean
5060000
heap private
page execute and read and write
clean
46C000
unkown image
page readonly
clean
282000
unkown
page read and write
clean
3E0000
unkown image
page readonly
clean
619F000
unkown
page read and write
clean
667E000
unkown
page read and write
clean
3E0000
unkown image
page readonly
clean
46C000
unkown image
page readonly
clean
180000
unkown
page readonly
clean
3E0000
unkown image
page readonly
clean
64B6000
unkown
page read and write
clean
3E2000
unkown image
page execute read
clean
49B2000
heap private
page read and write
clean
730E000
unkown
page read and write
clean
4740000
unkown
page read and write
clean
666A000
unkown
page read and write
clean
5152000
unkown
page read and write
clean
4DB0000
unkown
page read and write
clean
2160000
unkown
page read and write
clean
760000
unkown
page read and write
clean
6F45000
unkown
page read and write
clean
66F9000
unkown
page read and write
clean
2396000
unkown
page read and write
clean
5152000
unkown
page read and write
clean
8B0000
unkown
page read and write
clean
6677000
unkown
page read and write
clean
23E1000
unkown
page read and write
clean
23F3000
unkown
page read and write
clean
760000
unkown
page read and write
clean
51A0000
unkown
page read and write
clean
3E2000
unkown image
page execute read
clean
6712000
unkown
page read and write
clean
6457000
unkown
page read and write
clean
292000
unkown
page read and write
clean
6B1A000
unkown
page read and write
clean
6546000
unkown
page read and write
clean
4880000
unkown
page read and write
clean
6E0000
unkown
page read and write
clean
6661000
unkown
page read and write
clean
5906000
unkown
page readonly
clean
6060000
unkown image
page readonly
clean
6450000
unkown
page read and write
clean
8AF000
unkown
page read and write
clean
52D8000
heap private
page read and write
clean
8C0000
unkown
page read and write
clean
65A2000
unkown
page read and write
clean
4990000
heap private
page read and write
clean
4850000
unkown
page read and write
clean
8B0000
unkown
page read and write
clean
3E0000
unkown image
page readonly
clean
2F0000
unkown
page read and write
clean
5196000
unkown
page read and write
clean
56B8000
unkown
page readonly
clean
6F0000
unkown
page read and write
clean
59B2000
unkown
page readonly
clean
6F0000
unkown
page read and write
clean
760000
unkown
page read and write
clean
6130000
unkown
page read and write
clean
52C0000
unkown
page read and write
clean
85CE000
unkown
page read and write | page guard
clean
5000000
unkown
page read and write
clean
51A0000
unkown
page read and write
clean
8B0000
unkown
page read and write
clean
2180000
unkown
page read and write
clean
5108000
unkown
page read and write
clean
4730000
unkown
page read and write
clean
3E0000
unkown image
page readonly
clean
3E0000
unkown image
page readonly
clean
644A000
unkown
page read and write
clean
68AC000
unkown
page read and write
clean
270000
unkown
page read and write
clean
59D5000
unkown
page readonly
clean
250000
unkown
page read and write
clean
5D20000
unkown
page read and write
clean
690000
unkown
page read and write
clean
27D000
unkown
page execute and read and write
clean
67C000
unkown
page read and write
clean
23C8000
unkown
page read and write
clean
8D0000
unkown
page read and write
clean
6AF7000
unkown
page read and write
clean
760000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
3E2000
unkown image
page execute read
clean
8C0000
unkown
page read and write
clean
4FFE000
unkown
page read and write
clean
760000
unkown
page read and write
clean
621E000
unkown
page read and write
clean
4730000
unkown
page read and write
clean
9A0000
unkown
page readonly
clean
6F0000
unkown
page read and write
clean
2180000
unkown
page read and write
clean
35DA000
unkown
page read and write
clean
5020000
unkown
page read and write
clean
6680000
unkown
page read and write
clean
66B4000
unkown
page read and write
clean
4994000
heap private
page read and write
clean
48DE000
unkown
page read and write
clean
6060000
unkown image
page readonly
clean
6F0000
unkown
page read and write
clean
66F2000
unkown
page read and write
clean
5196000
unkown
page read and write
clean
614B000
unkown
page read and write
clean
2160000
unkown
page read and write
clean
6A95000
unkown
page read and write
clean
3E2000
unkown image
page execute read
clean
55A000
heap default
page read and write
clean
64E4000
unkown
page read and write
clean
5260000
unkown
page execute and read and write
clean
647F000
unkown
page read and write
clean
59E9000
unkown
page readonly
clean
65A0000
unkown
page read and write
clean
510C000
unkown
page read and write
clean
750000
unkown
page read and write
clean
65A7000
unkown
page read and write
clean
641A000
unkown
page read and write
clean
255A000
unkown
page read and write
clean
4980000
unkown
page read and write
clean
63D9000
unkown
page read and write
clean
8F0000
unkown image
page readonly
clean
6B22000
unkown
page read and write
clean
52DB000
heap private
page read and write
clean
3E0000
unkown image
page readonly
clean
48E0000
unkown
page read and write
clean
610000
unkown
page read and write
clean
6A72000
unkown
page read and write
clean
6626000
unkown
page read and write
clean
5182000
unkown
page read and write
clean
5872000
unkown
page readonly
clean
6CFA000
unkown
page read and write
clean
46C000
unkown image
page readonly
clean
3E2000
unkown image
page execute read
clean
3E0000
unkown image
page readonly
clean
8A2000
unkown
page read and write
clean
3E0000
unkown image
page readonly
clean
750000
unkown
page execute and read and write
clean
3E0000
unkown image
page readonly
clean
2E0000
unkown
page execute and read and write
clean
97C000
unkown image
page readonly
clean
5196000
unkown
page read and write
clean
6B2D000
unkown
page read and write
clean
5942000
unkown
page readonly
clean
20000
unkown
page read and write
clean
28A000
unkown
page execute and read and write
clean
6DE000
unkown
page read and write
clean
64B0000
unkown
page read and write
clean
5972000
unkown
page readonly
clean
2160000
unkown
page read and write
clean
6855000
unkown
page read and write
clean
750000
unkown
page read and write
clean
4880000
unkown
page read and write
clean
6F1A000
unkown
page read and write
clean
5030000
unkown
page read and write
clean
630000
unkown
page read and write
clean
46F0000
unkown
page read and write
clean
633B000
unkown
page read and write
clean
6599000
unkown
page read and write
clean
760000
unkown
page read and write
clean
2300000
unkown
page read and write
clean
4885000
unkown
page read and write
clean
6050000
unkown
page read and write
clean
4EF0000
unkown
page read and write
clean
647D000
unkown
page read and write
clean
658E000
unkown
page read and write
clean
6623000
unkown
page read and write
clean
75CB000
unkown
page read and write
clean
263000
unkown
page execute and read and write
clean
6E0000
unkown
page read and write
clean
6B38000
unkown
page read and write
clean
249000
unkown
page read and write
clean
46C000
unkown image
page readonly
clean
6C95000
unkown
page read and write
clean
4950000
unkown
page read and write
clean
5182000
unkown
page read and write
clean
51A0000
unkown
page read and write
clean
5143000
unkown
page read and write
clean
66B1000
unkown
page read and write
clean
3E0000
unkown image
page readonly
clean
6CD5000
unkown
page read and write
clean
4420000
unkown
page readonly
clean
8F2000
unkown image
page execute read
clean
8E0000
unkown
page read and write
clean
616000
unkown
page read and write
clean
5FD0000
unkown
page read and write
clean
56B2000
unkown
page readonly
clean
3E0000
unkown image
page readonly
clean
5A35000
unkown
page readonly
clean
766000
unkown
page read and write
clean
6060000
unkown image
page readonly
clean
4700000
unkown
page read and write
clean
3E0000
unkown image
page readonly
clean
6A24000
unkown
page read and write
clean
6769000
unkown
page read and write
clean
6A53000
unkown
page read and write
clean
3E0000
unkown image
page readonly
clean
62CE000
unkown
page read and write
clean
6F81000
unkown
page read and write
clean
6280000
unkown
page read and write
clean
5127000
unkown
page read and write
clean
5E90000
unkown
page read and write
clean
5144000
unkown
page read and write
clean
3E0000
unkown image
page readonly
clean
60BE000
unkown
page read and write
clean
3E2000
unkown image
page execute read
clean
75E7000
unkown
page read and write
clean
75D1000
unkown
page read and write
clean
59B9000
unkown
page readonly
clean
4EE0000
unkown
page read and write
clean
6A5B000
unkown
page read and write
clean
61B3000
unkown
page read and write
clean
3E2000
unkown image
page execute read
clean
5108000
unkown
page read and write
clean
441E000
unkown
page read and write
clean
315000
unkown
page read and write
clean
6F70000
unkown
page read and write
clean
4F0000
unkown
page write copy
clean
8C0000
unkown
page read and write
clean
5143000
unkown
page read and write
clean
2150000
unkown
page read and write
clean
63F5000
unkown
page read and write
clean
639E000
unkown
page read and write
clean
620000
unkown
page read and write
clean
237E000
unkown
page read and write
clean
494C000
unkown
page read and write
clean
6201000
unkown
page read and write
clean
5894000
unkown
page readonly
clean
310000
unkown
page read and write
clean
5129000
unkown
page read and write
clean
6B59000
unkown
page read and write
clean
52D0000
heap private
page read and write
clean
680000
unkown
page read and write
clean
5966000
unkown
page readonly
clean
68C000
unkown
page read and write
clean
700000
unkown
page read and write
clean
8A5000
unkown
page read and write
clean
6685000
unkown
page read and write
clean
6EF4000
unkown
page read and write
clean
6485000
unkown
page read and write
clean
753C000
unkown
page read and write
clean
675A000
unkown
page read and write
clean
3E2000
unkown image
page execute read
clean
621A000
unkown
page read and write
clean
680000
unkown
page read and write
clean
6AA0000
unkown
page read and write
clean
750000
unkown
page read and write
clean
710000
heap private
page read and write
clean
46C000
unkown image
page readonly
clean
2130000
unkown
page read and write
clean
700000
unkown
page read and write
clean
4A0000
heap private
page execute and read and write
clean
97C000
unkown image
page readonly
clean
4700000
unkown
page read and write
clean
665F000
unkown
page read and write
clean
510000
heap default
page read and write
clean
85CF000
unkown
page read and write
clean
3291000
unkown
page read and write
clean
5127000
unkown
page read and write
clean
510C000
unkown
page read and write
clean
760000
unkown
page read and write
clean
50E4000
unkown
page read and write
clean
6A65000
unkown
page read and write
clean
58F5000
unkown
page readonly
clean
3E2000
unkown image
page execute read
clean
5985000
unkown
page readonly
clean
6AB4000
unkown
page read and write
clean
517000
heap default
page read and write
clean
8B0000
unkown
page read and write
clean
46C000
unkown image
page readonly
clean
4870000
unkown
page read and write
clean
636000
unkown
page read and write
clean
670F000
unkown
page read and write
clean
762000
unkown
page read and write
clean
653F000
unkown
page read and write
clean
610000
unkown
page read and write
clean
64E0000
unkown
page read and write
clean
599D000
unkown
page readonly
clean
3E2000
unkown image
page execute read
clean
629000
unkown
page read and write
clean
3E0000
unkown image
page readonly
clean
6B5B000
unkown
page read and write
clean
320000
heap private
page execute and read and write
clean
62E2000
unkown
page read and write
clean
6971000
unkown
page read and write
clean
760000
unkown
page read and write
clean
5C00000
unkown
page readonly
clean
3E2000
unkown image
page execute read
clean
5A19000
unkown
page readonly
clean
7C0000
unkown
page readonly
clean
617000
unkown
page read and write
clean
6E46000
unkown
page read and write
clean
57B2000
unkown
page readonly
clean
5040000
unkown
page read and write
clean
4EB0000
unkown
page read and write
clean
6631000
unkown
page read and write
clean
64BA000
unkown
page read and write
clean
There are 603 hidden memdumps, click here to show them.