IOCReport

loading gif

Files

File Path
Type
Category
Malicious
INVOICE = 212888585 .xlsx
Microsoft Excel 2007+
initial sample
malicious
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\tmp3811.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\ALP.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\run.dat
Non-ISO extended-ASCII text, with no line terminators
dropped
malicious
C:\Users\user\Desktop\~$INVOICE = 212888585 .xlsx
data
dropped
malicious
C:\Users\user\AppData\Local\Temp\tmp277F.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\catalog.dat
data
dropped
clean
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\storage.dat
data
dropped
clean
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\task.dat
ASCII text, with no line terminators
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
malicious
C:\Users\user\AppData\Roaming\ALP.exe
C:\Users\user\AppData\Roaming\ALP.exe
malicious
C:\Users\user\AppData\Roaming\ALP.exe
C:\Users\user\AppData\Roaming\ALP.exe
malicious
C:\Windows\SysWOW64\schtasks.exe
'schtasks.exe' /create /f /tn 'SMTP Service' /xml 'C:\Users\user\AppData\Local\Temp\tmp3811.tmp'
malicious
C:\Windows\SysWOW64\schtasks.exe
'schtasks.exe' /create /f /tn 'SMTP Service Task' /xml 'C:\Users\user\AppData\Local\Temp\tmp277F.tmp'
malicious
C:\Users\user\AppData\Roaming\ALP.exe
C:\Users\user\AppData\Roaming\ALP.exe 0
malicious
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
'C:\Program Files (x86)\SMTP Service\smtpsvc.exe' 0
malicious
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
'C:\Program Files (x86)\SMTP Service\smtpsvc.exe'
malicious
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
malicious
C:\Users\user\AppData\Roaming\ALP.exe
C:\Users\user\AppData\Roaming\ALP.exe
malicious
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
malicious
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
malicious
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
clean
C:\Windows\System32\taskeng.exe
taskeng.exe {6D7D75E4-8EFD-44BB-96AC-FEA7E6E0852F} S-1-5-21-966771315-3019405637-367336477-1006:user-PC\user:Interactive:[1]
clean
There are 5 hidden processes, click here to show them.

URLs

Name
IP
Malicious
godisgood1.hopto.org
malicious
malicious
http://136.144.41.96/HHK.exe
136.144.41.96
malicious
http://www.%s.comPA
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://google.com
unknown
clean

Domains

Name
IP
Malicious
godisgood1.hopto.org
103.147.184.84
malicious

IPs

IP
Domain
Country
Malicious
103.147.184.84
godisgood1.hopto.org
unknown
malicious
136.144.41.96
unknown
Netherlands
malicious

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
$m'
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
30C7F
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
dq'
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
371F5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
372B0
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EquationEditorFilesIntl_1033
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
EquationEditorFilesIntl_1033
clean
C:\Users\user\AppData\Roaming\ALP.exe
SMTP Service
clean
C:\Windows\System32\taskeng.exe
data
clean
There are 51 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
32D9000
unkown
page read and write
malicious
2231000
unkown
page read and write
malicious
3549000
unkown
page read and write
malicious
22D1000
unkown
page read and write
malicious
223D000
unkown
page read and write
malicious
2541000
unkown
page read and write
malicious
6C0000
unkown image
page read and write
malicious
3289000
unkown
page read and write
malicious
402000
unkown
page execute and read and write
malicious
3209000
unkown
page read and write
malicious
3239000
unkown
page read and write
malicious
249D000
unkown
page read and write
malicious
22BD000
unkown
page read and write
malicious
3479000
unkown
page read and write
malicious
402000
unkown
page execute and read and write
malicious
3469000
unkown
page read and write
malicious
402000
unkown
page execute and read and write
malicious
402000
unkown
page execute and read and write
malicious
32A9000
unkown
page read and write
malicious
22DD000
unkown
page read and write
malicious
2431000
unkown
page read and write
malicious
4C0000
unkown
page read and write
clean
514000
heap default
page read and write
clean
7EFC0000
unkown image
page readonly
clean
4730000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
3E0000
unkown
page read and write
clean
633B000
unkown
page read and write
clean
757000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
633B000
unkown
page read and write
clean
BE0000
unkown image
page readonly
clean
632C000
unkown
page read and write
clean
1FEC000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
4BAF000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
43A4000
heap private
page read and write
clean
50A0000
unkown image
page read and write
clean
899000
heap private
page read and write
clean
4CE000
unkown
page read and write
clean
5D0000
unkown image
page readonly
clean
9A6000
unkown image
page readonly
clean
7B0000
heap private
page read and write
clean
480000
unkown
page read and write
clean
555E000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
997000
heap private
page read and write
clean
22D0000
unkown
page read and write
clean
610000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
8F0000
unkown
page read and write
clean
150000
unkown
page read and write
clean
771D000
unkown
page read and write
clean
652D000
unkown
page read and write
clean
6301000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
BE0000
unkown image
page readonly
clean
790000
unkown
page read and write
clean
3E6000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
2201000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
4D0000
heap default
page read and write
clean
4B70000
unkown
page read and write
clean
3431000
unkown
page read and write
clean
6E0000
heap private
page read and write
clean
507E000
unkown
page read and write
clean
4F30000
unkown
page read and write
clean
460000
unkown
page read and write
clean
4D7000
heap default
page read and write
clean
4872000
heap private
page read and write
clean
912000
unkown image
page execute read
clean
10000
unkown image
page read and write
clean
6E0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
2A0000
heap private
page read and write
clean
530000
heap default
page read and write
clean
BE0000
unkown image
page readonly
clean
53B0000
unkown
page read and write
clean
4F70000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
910000
unkown image
page readonly
clean
2995000
heap private
page read and write
clean
860000
heap default
page read and write
clean
240000
unkown
page read and write
clean
2DB000
unkown
page execute and read and write
clean
50000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
7EFC0000
unkown image
page readonly
clean
5A1000
unkown
page read and write
clean
470000
unkown
page read and write
clean
6301000
unkown
page read and write
clean
5000000
heap private
page execute and read and write
clean
496E000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
4E20000
heap private
page read and write
clean
3E0000
unkown
page read and write
clean
7C0000
unkown
page read and write
clean
28D000
unkown
page execute and read and write
clean
4E3C000
unkown
page read and write
clean
4B7000
unkown
page read and write
clean
790000
unkown
page read and write
clean
57D000
unkown
page read and write
clean
22CF000
unkown
page read and write
clean
9D0000
unkown
page read and write
clean
27D000
unkown
page execute and read and write
clean
3D0000
unkown
page read and write
clean
22B8000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
B44000
heap private
page read and write
clean
481F000
unkown
page read and write
clean
350000
unkown
page read and write
clean
450000
unkown
page read and write
clean
2AFF000
unkown
page read and write
clean
910000
unkown image
page readonly
clean
4C0000
unkown
page read and write
clean
6200000
unkown
page read and write
clean
780000
unkown
page read and write
clean
163000
unkown
page execute and read and write
clean
4D0000
heap default
page read and write
clean
510000
heap default
page read and write
clean
6F8D000
unkown
page read and write
clean
6321000
unkown
page read and write
clean
633B000
unkown
page read and write
clean
450000
unkown
page read and write
clean
C76000
unkown image
page readonly
clean
AC5E000
unkown
page read and write
clean
834000
unkown
page read and write
clean
492E000
unkown
page read and write
clean
500000
unkown
page read and write
clean
7B6000
heap default
page read and write
clean
502C000
unkown
page read and write
clean
5F0000
unkown image
page readonly
clean
66AC000
unkown
page read and write
clean
290000
unkown image
page readonly
clean
22B0000
unkown
page read and write
clean
A0000
unkown
page read and write
clean
4440000
unkown
page read and write
clean
4860000
unkown image
page read and write
clean
270000
unkown
page read and write
clean
364A000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
A1C000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
480000
unkown
page read and write
clean
705000
heap private
page read and write
clean
6C0000
unkown
page read and write
clean
56CD000
unkown
page read and write
clean
AE9F000
unkown
page read and write
clean
3541000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
22C0000
unkown
page read and write
clean
1A6000
unkown
page read and write
clean
4854000
heap private
page read and write
clean
780000
unkown
page read and write
clean
C80000
unkown image
page readonly
clean
4E0000
unkown
page read and write
clean
7EF40000
unkown
page execute and read and write
clean
570000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
A700000
unkown
page read and write
clean
9D0000
unkown
page read and write
clean
180000
unkown
page read and write
clean
2A6000
unkown
page read and write
clean
480000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
517000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
2A0000
unkown
page read and write
clean
583E000
unkown
page read and write
clean
7C4000
heap default
page read and write
clean
32D1000
unkown
page read and write
clean
8A0000
unkown image
page read and write
clean
900000
unkown
page read and write
clean
484F000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
990000
heap private
page read and write
clean
400000
unkown
page read and write
clean
BE0000
unkown image
page readonly
clean
21B0000
unkown image
page read and write
clean
3923000
unkown
page read and write
clean
1CD000
unkown
page execute and read and write
clean
422000
unkown
page execute and read and write
clean
20AE000
unkown
page read and write
clean
227F000
unkown
page read and write
clean
320000
unkown
page read and write
clean
790000
unkown
page read and write
clean
4E0E000
unkown
page read and write
clean
4B0000
unkown
page read and write
clean
147000
unkown
page execute and read and write
clean
68AC000
unkown
page read and write
clean
6333000
unkown
page read and write
clean
BE2000
unkown image
page execute read
clean
16D000
unkown
page execute and read and write
clean
5D0000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
E00000
unkown image
page readonly
clean
470000
unkown
page read and write
clean
8D0000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
B40000
heap private
page read and write
clean
632C000
unkown
page read and write
clean
20000
unkown
page read and write
clean
290000
heap private
page execute and read and write
clean
5C0000
unkown image
page readonly
clean
330000
heap private
page read and write
clean
12A000
unkown
page read and write
clean
22B0000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
13A000
unkown
page read and write
clean
37E3000
unkown
page read and write
clean
61AC000
unkown
page read and write
clean
610000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
830000
unkown
page read and write
clean
240000
unkown
page read and write
clean
760000
heap private
page read and write
clean
280000
unkown image
page read and write
clean
B94000
heap private
page read and write
clean
5F0000
unkown image
page read and write
clean
7EFD0000
unkown image
page readonly
clean
2A0000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
2A0000
unkown
page read and write
clean
460000
unkown
page read and write
clean
27D000
unkown
page execute and read and write
clean
750000
unkown image
page readonly
clean
780000
unkown
page read and write
clean
496C000
unkown
page read and write
clean
610000
unkown
page read and write
clean
9A000
unkown
page read and write
clean
B60000
heap private
page read and write
clean
8B5000
heap default
page read and write
clean
355000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
2281000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
297000
unkown
page execute and read and write
clean
38E2000
unkown
page read and write
clean
450000
unkown
page read and write
clean
6329000
unkown
page read and write
clean
3521000
unkown
page read and write
clean
1B0000
heap private
page read and write
clean
267000
unkown
page read and write
clean
4AAC000
unkown
page read and write
clean
6331000
unkown
page read and write
clean
1F10000
heap private
page read and write
clean
250000
unkown
page execute and read and write
clean
F0000
unkown image
page read and write
clean
245F000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
3CC3000
unkown
page read and write
clean
400000
unkown
page execute and read and write
clean
16D000
unkown
page execute and read and write
clean
480000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
35D9000
unkown
page read and write
clean
378000
unkown
page read and write
clean
5B2000
unkown
page read and write
clean
22C0000
unkown
page read and write
clean
B40000
unkown image
page readonly
clean
568D000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
450000
unkown
page read and write
clean
3551000
unkown
page read and write
clean
4E8C000
unkown
page read and write
clean
1E8000
unkown
page read and write
clean
7EFA9000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
110000
unkown
page read and write
clean
163000
unkown
page execute and read and write
clean
7EFC2000
unkown image
page readonly
clean
6331000
unkown
page read and write
clean
616000
unkown
page read and write
clean
3A0000
heap default
page read and write
clean
7EFC0000
unkown image
page readonly
clean
4E0000
unkown
page read and write
clean
498F000
unkown
page read and write
clean
610000
unkown
page read and write
clean
1E7000
unkown
page execute and read and write
clean
3F0000
unkown
page read and write
clean
310000
unkown
page read and write
clean
B80000
unkown image
page read and write
clean
520F000
unkown
page read and write
clean
5EAE000
unkown
page read and write
clean
203000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
3982000
unkown
page read and write
clean
C76000
unkown image
page readonly
clean
633C000
unkown
page read and write
clean
900000
unkown
page read and write
clean
470000
unkown
page read and write
clean
547E000
unkown
page read and write
clean
491C000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
489C000
unkown
page read and write
clean
2B2000
unkown
page read and write
clean
22B5000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
3C0000
heap private
page execute and read and write
clean
488000
unkown
page read and write
clean
E10000
unkown image
page readonly
clean
6325000
unkown
page read and write
clean
1C0000
heap private
page execute and read and write
clean
560000
unkown
page read and write
clean
5B0000
heap default
page read and write
clean
22B0000
unkown
page read and write
clean
60AC000
unkown
page read and write
clean
770000
unkown image
page readonly
clean
BE0000
unkown image
page readonly
clean
4A2F000
unkown
page read and write
clean
4DDF000
unkown
page read and write
clean
780000
unkown image
page read and write
clean
670000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
4D80000
heap private
page execute and read and write
clean
782000
unkown
page read and write
clean
9D0000
unkown
page read and write
clean
38A3000
unkown
page read and write
clean
18A000
unkown
page execute and read and write
clean
21D0000
unkown image
page read and write
clean
880000
unkown image
page read and write
clean
4F7000
heap default
page read and write
clean
390000
unkown
page read and write
clean
AE5E000
unkown
page read and write
clean
357000
heap default
page read and write
clean
4B0000
unkown
page read and write
clean
22B0000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
470000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
502E000
unkown
page read and write | page guard
clean
300000
unkown
page read and write
clean
780000
unkown
page read and write
clean
75DD000
unkown
page read and write
clean
486000
unkown
page read and write
clean
164000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
51EE000
unkown
page read and write
clean
15B000
unkown
page execute and read and write
clean
4C00000
heap private
page execute and read and write
clean
6375000
unkown
page read and write
clean
B23F000
unkown
page read and write
clean
3F0000
unkown
page execute and read and write
clean
790000
unkown image
page read and write
clean
1C4000
unkown
page read and write
clean
422000
unkown
page execute and read and write
clean
310000
unkown
page execute and read and write
clean
3E0000
unkown
page read and write
clean
36AA000
unkown
page read and write
clean
22BC000
unkown
page read and write
clean
430000
unkown
page execute and read and write
clean
AF1E000
unkown
page read and write | page guard
clean
22BC000
unkown
page read and write
clean
4C4E000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
3C0000
unkown
page read and write
clean
4E6E000
unkown
page read and write
clean
2220000
heap private
page execute and read and write
clean
35C9000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
182000
unkown
page read and write
clean
810000
unkown
page read and write
clean
4EF1000
unkown
page read and write
clean
227E000
unkown
page read and write | page guard
clean
4EF0000
heap private
page read and write
clean
630000
heap private
page read and write
clean
350000
unkown
page read and write
clean
910000
unkown image
page readonly
clean
3E0000
unkown
page read and write
clean
420000
unkown
page read and write
clean
2C0000
unkown
page read and write
clean
2461000
unkown
page read and write
clean
7B8000
heap private
page read and write
clean
230000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
124000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
610000
unkown
page read and write
clean
2172000
heap private
page read and write
clean
BE2000
unkown image
page execute read
clean
BE0000
unkown image
page readonly
clean
6325000
unkown
page read and write
clean
550000
unkown
page read and write
clean
163000
unkown
page execute and read and write
clean
7EFC2000
unkown image
page readonly
clean
780000
unkown
page read and write
clean
480000
unkown
page read and write
clean
22B0000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
9D7000
unkown
page read and write
clean
BE2000
unkown image
page execute read
clean
632C000
unkown
page read and write
clean
227000
unkown
page read and write
clean
2C7000
unkown
page read and write
clean
95C000
unkown
page read and write
clean
730000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
55C000
heap default
page read and write
clean
3E8000
unkown
page read and write
clean
3C0000
unkown
page read and write
clean
211B000
heap private
page read and write
clean
22B6000
unkown
page read and write
clean
633C000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
530E000
unkown
page read and write
clean
A20000
unkown
page read and write
clean
1FCE000
unkown
page read and write
clean
240000
unkown
page read and write
clean
3843000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
4B20000
heap private
page read and write
clean
618000
unkown
page read and write
clean
5E1D000
unkown
page read and write
clean
50BE000
unkown
page read and write
clean
260000
unkown
page read and write
clean
4435000
heap private
page read and write
clean
17D000
unkown
page execute and read and write
clean
8F2000
heap private
page read and write
clean
2154000
heap private
page read and write
clean
910000
unkown image
page readonly
clean
202C000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
484E000
unkown
page read and write
clean
2DB000
unkown
page execute and read and write
clean
150000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
460000
unkown image
page readonly
clean
4AF000
unkown
page read and write
clean
260000
unkown
page read and write
clean
2A0000
unkown image
page readonly
clean
320000
unkown
page read and write
clean
297E000
unkown
page read and write
clean
140000
unkown image
page read and write
clean
3D0000
unkown
page read and write
clean
22B0000
unkown
page read and write
clean
260000
unkown
page read and write
clean
80E000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
5880000
unkown image
page readonly
clean
440000
unkown image
page read and write
clean
7EF40000
unkown
page execute and read and write
clean
8F0000
unkown
page read and write
clean
559E000
unkown
page read and write
clean
4E00000
heap private
page read and write
clean
7A0000
unkown image
page readonly
clean
4AE000
unkown
page read and write
clean
5D8000
unkown
page read and write
clean
738000
heap private
page read and write
clean
29B000
unkown
page execute and read and write
clean
2B7000
unkown
page execute and read and write
clean
556F000
unkown
page read and write
clean
250000
unkown
page execute and read and write
clean
750000
heap default
page read and write
clean
453D000
unkown
page read and write
clean
2000000
heap private
page read and write
clean
157000
unkown
page execute and read and write
clean
22B8000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
3201000
unkown
page read and write
clean
53C000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
B1E000
unkown
page read and write
clean
280000
unkown
page read and write
clean
9A6000
unkown image
page readonly
clean
633B000
unkown
page read and write
clean
310000
unkown
page read and write
clean
513D000
unkown
page read and write
clean
36E8000
unkown
page read and write
clean
2B6000
unkown
page read and write
clean
2500000
heap private
page execute and read and write
clean
502F000
unkown
page read and write
clean
632C000
unkown
page read and write
clean
49B0000
heap private
page read and write
clean
7C0000
unkown
page read and write
clean
C76000
unkown image
page readonly
clean
86D000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
28A000
unkown
page execute and read and write
clean
20000
unkown
page read and write
clean
470000
unkown
page read and write
clean
4DE1000
unkown
page read and write
clean
380000
unkown image
page read and write
clean
518D000
unkown
page read and write
clean
BE2000
unkown image
page execute read
clean
10000
unkown image
page read and write
clean
480000
unkown
page read and write
clean
7C0000
unkown image
page read and write
clean
7EFB0000
unkown image
page readonly
clean
240000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
330000
unkown
page read and write
clean
CD0000
unkown image
page readonly
clean
310000
unkown
page execute and read and write
clean
42B000
unkown
page read and write
clean
C76000
unkown image
page readonly
clean
450000
unkown
page read and write
clean
380000
unkown
page read and write
clean
670000
unkown
page read and write
clean
16D000
unkown
page execute and read and write
clean
170000
heap private
page execute and read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
680000
heap private
page execute and read and write
clean
474000
unkown
page read and write
clean
27C000
unkown
page read and write
clean
670000
unkown
page read and write
clean
8D4000
heap private
page read and write
clean
300000
unkown
page read and write
clean
3F0000
unkown
page read and write
clean
AF0000
heap private
page read and write
clean
6322000
unkown
page read and write
clean
266000
unkown
page read and write
clean
480000
unkown
page read and write
clean
38C2000
unkown
page read and write
clean
7EF40000
unkown
page execute and read and write
clean
240000
unkown image
page readonly
clean
4C0000
heap private
page read and write
clean
A50000
heap private
page read and write
clean
6329000
unkown
page read and write
clean
21FF000
unkown
page read and write
clean
900000
unkown
page read and write
clean
4F5000
heap private
page read and write
clean
212E000
unkown
page read and write
clean
520E000
unkown
page read and write
clean
7C8000
unkown
page read and write
clean
3B0000
unkown
page read and write
clean
AD8F000
unkown
page read and write
clean
6C0000
unkown image
page readonly
clean
575000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
400000
unkown
page read and write
clean
22B0000
unkown
page read and write
clean
280000
unkown
page read and write
clean
3D43000
unkown
page read and write
clean
250000
heap default
page read and write
clean
2E0000
unkown
page execute and read and write
clean
655000
heap private
page read and write
clean
2A0000
unkown
page read and write
clean
187000
unkown
page execute and read and write
clean
380000
unkown
page read and write
clean
20000
unkown
page read and write
clean
6323000
unkown
page read and write
clean
912000
unkown image
page execute read
clean
4280000
unkown image
page readonly
clean
460000
unkown
page read and write
clean
6350000
unkown
page read and write
clean
460000
unkown
page read and write
clean
22D0000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
720000
unkown
page execute and read and write
clean
2F0000
heap default
page read and write
clean
9A6000
unkown image
page readonly
clean
4280000
unkown
page read and write
clean
36EA000
unkown
page read and write
clean
4E31000
unkown
page read and write
clean
910000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
4F4000
heap default
page read and write
clean
9A6000
unkown image
page readonly
clean
4B0000
unkown
page read and write
clean
4C9C000
unkown
page read and write
clean
22B0000
unkown
page read and write
clean
620000
unkown
page read and write
clean
BE0000
unkown image
page readonly
clean
740000
heap private
page execute and read and write
clean
518E000
unkown
page read and write
clean
B1BF000
unkown
page read and write
clean
49B4000
heap private
page read and write
clean
3F23000
unkown
page read and write
clean
456000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
4670000
unkown image
page readonly
clean
525E000
unkown
page read and write
clean
24C0000
heap private
page read and write
clean
150000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
6342000
unkown
page read and write
clean
5110000
heap private
page read and write
clean
245E000
unkown
page read and write | page guard
clean
1BD000
unkown
page execute and read and write
clean
574D000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
90000
unkown image
page readonly
clean
21BF000
unkown
page read and write
clean
3508000
unkown
page read and write
clean
C76000
unkown image
page readonly
clean
769000
heap private
page read and write
clean
270000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
BE0000
unkown image
page readonly
clean
3803000
unkown
page read and write
clean
480000
unkown
page read and write
clean
22F0000
heap private
page read and write
clean
422000
unkown
page execute and read and write
clean
3D0000
unkown
page read and write
clean
1C7000
unkown
page execute and read and write
clean
7EF40000
unkown
page execute and read and write
clean
6E7000
heap private
page read and write
clean
490000
unkown image
page read and write
clean
4F90000
unkown
page read and write
clean
2D0000
heap private
page execute and read and write
clean
780000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
4CD0000
heap private
page execute and read and write
clean
400000
unkown
page execute and read and write
clean
3C0000
unkown
page read and write
clean
7C0000
unkown
page read and write
clean
A831000
unkown
page read and write
clean
D0000
unkown image
page read and write
clean
6301000
unkown
page read and write
clean
B10F000
unkown
page read and write
clean
6329000
unkown
page read and write
clean
475000
unkown
page read and write
clean
B30000
unkown image
page readonly
clean
590000
unkown image
page readonly
clean
6E0000
unkown image
page readonly
clean
435E000
unkown
page read and write
clean
22B0000
unkown
page read and write
clean
4F0000
unkown
page read and write
clean
1B0000
unkown
page read and write
clean
900000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
494F000
unkown
page read and write
clean
2924000
unkown
page read and write
clean
4E2000
unkown
page read and write
clean
7EF40000
unkown
page execute and read and write
clean
7EFC2000
unkown image
page readonly
clean
4B0000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
340000
heap default
page read and write
clean
B34E000
unkown
page read and write
clean
489E000
unkown
page read and write
clean
1F7E000
unkown
page read and write
clean
1F8000
heap default
page read and write
clean
480000
unkown
page read and write
clean
900000
unkown
page read and write
clean
BE2000
unkown image
page execute read
clean
1F5000
unkown
page read and write
clean
6357000
unkown
page read and write
clean
22B0000
unkown
page read and write
clean
457E000
unkown
page read and write
clean
787E000
unkown
page read and write
clean
485000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
22B0000
unkown
page read and write
clean
458D000
unkown
page read and write
clean
4F4C000
unkown
page read and write
clean
510000
unkown
page read and write
clean
1FF0000
heap private
page execute and read and write
clean
50000
unkown image
page readonly
clean
790000
unkown image
page readonly
clean
164000
unkown
page read and write
clean
1AA000
unkown
page read and write
clean
186000
unkown
page execute and read and write
clean
320000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
51DF000
unkown
page read and write
clean
450000
unkown
page read and write
clean
6D0000
heap private
page read and write
clean
61C0000
heap private
page read and write
clean
14A000
unkown
page execute and read and write
clean
1DD000
unkown
page execute and read and write
clean
BE0000
unkown image
page readonly
clean
610000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
ABFE000
unkown
page read and write
clean
21C0000
unkown
page read and write
clean
550000
unkown image
page readonly
clean
250000
unkown
page read and write
clean
BE0000
unkown image
page readonly
clean
AF1F000
unkown
page read and write
clean
39A3000
unkown
page read and write
clean
820000
heap default
page read and write
clean
3488000
unkown
page read and write
clean
4430000
unkown
page read and write
clean
230D000
unkown
page read and write
clean
287000
unkown
page execute and read and write
clean
632C000
unkown
page read and write
clean
9A6000
unkown image
page readonly
clean
49D2000
heap private
page read and write
clean
39C3000
unkown
page read and write
clean
470000
unkown
page read and write
clean
350000
unkown
page read and write
clean
34E1000
unkown
page read and write
clean
21FE000
unkown
page read and write | page guard
clean
20E0000
heap private
page execute and read and write
clean
B30000
heap private
page read and write
clean
368A000
unkown
page read and write
clean
51C000
heap default
page read and write
clean
450000
unkown
page read and write
clean
BE0000
unkown image
page readonly
clean
287000
unkown
page execute and read and write
clean
5F0E000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
47E000
unkown
page read and write
clean
486000
unkown
page read and write
clean
53AE000
unkown
page read and write
clean
28A000
unkown
page execute and read and write
clean
7EFD0000
unkown image
page readonly
clean
6328000
unkown
page read and write
clean
620000
unkown
page read and write
clean
BE0000
unkown image
page readonly
clean
610000
unkown
page read and write
clean
480000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
250000
unkown image
page readonly
clean
802000
unkown
page read and write
clean
2290000
unkown
page read and write
clean
36CA000
unkown
page read and write
clean
912000
unkown image
page execute read
clean
4C7000
unkown
page read and write
clean
200000
heap private
page execute and read and write
clean
790000
heap default
page read and write
clean
ABE000
unkown
page read and write
clean
4CAE000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
4B0000
unkown
page read and write
clean
844000
heap default
page read and write
clean
912000
unkown image
page execute read
clean
22B0000
unkown
page read and write
clean
3C8000
unkown
page read and write
clean
743C000
unkown
page read and write
clean
4D0000
unkown image
page readonly
clean
3963000
unkown
page read and write
clean
516E000
unkown
page read and write
clean
450000
unkown
page read and write
clean
2120000
unkown image
page read and write
clean
A0000
unkown image
page readonly
clean
720000
unkown
page read and write
clean
1C2000
unkown
page read and write
clean
222F000
unkown
page read and write
clean
2F0000
heap private
page execute and read and write
clean
8C0000
heap private
page execute and read and write
clean
10000
unkown image
page read and write
clean
163000
unkown
page execute and read and write
clean
1F0E000
unkown
page read and write
clean
285000
unkown
page read and write
clean
1B0000
unkown
page read and write
clean
458000
unkown
page read and write
clean
4360000
unkown image
page readonly
clean
5170000
unkown
page read and write
clean
BE0000
unkown image
page readonly
clean
4D7000
heap private
page read and write
clean
16D000
unkown
page execute and read and write
clean
4DE0000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
43C2000
heap private
page read and write
clean
7A7000
heap default
page read and write
clean
910000
unkown image
page readonly
clean
370000
unkown
page read and write
clean
ACFE000
unkown
page read and write
clean
3F0000
unkown
page read and write
clean
2480000
unkown
page read and write
clean
6300000
unkown
page read and write
clean
1D0000
heap default
page read and write
clean
3231000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
20E0000
heap private
page read and write
clean
4F80000
unkown
page read and write
clean
4452000
heap private
page read and write
clean
242E000
unkown
page read and write
clean
210000
heap default
page read and write
clean
297000
unkown
page execute and read and write
clean
3943000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
A20000
unkown
page read and write
clean
440000
unkown image
page readonly
clean
6AED000
unkown
page read and write
clean
5120000
unkown
page read and write
clean
450000
unkown
page read and write
clean
292000
unkown
page read and write
clean
3823000
unkown
page read and write
clean
7772000
unkown
page read and write
clean
22B0000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
A70000
heap private
page read and write
clean
1EA000
unkown
page execute and read and write
clean
4EB000
unkown
page read and write
clean
570000
unkown
page read and write
clean
610000
unkown
page read and write
clean
4D2000
heap default
page read and write
clean
BE2000
unkown image
page execute read
clean
1F50000
unkown
page read and write
clean
B47E000
unkown
page read and write
clean
1ECE000
unkown
page read and write
clean
3528000
unkown
page read and write
clean
50C000
unkown
page read and write
clean
820000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
AE9E000
unkown
page read and write | page guard
clean
1CA000
unkown
page execute and read and write
clean
7EFB2000
unkown image
page readonly
clean
5F0000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
22A000
unkown
page read and write
clean
510000
heap default
page read and write
clean
350000
unkown image
page readonly
clean
6C5000
unkown
page read and write
clean
840000
unkown image
page readonly
clean
22B0000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
AFEE000
unkown
page read and write
clean
263000
unkown
page execute and read and write
clean
570000
unkown image
page readonly
clean
7CC000
unkown
page read and write
clean
550000
heap default
page read and write
clean
22B0000
unkown
page read and write
clean
4D0000
heap private
page read and write
clean
41E000
unkown
page read and write
clean
445E000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
720000
unkown
page read and write
clean
810000
unkown
page read and write
clean
310000
unkown
page read and write
clean
9F0000
heap private
page execute and read and write
clean
123000
unkown
page execute and read and write
clean
3C0000
unkown
page read and write
clean
385000
heap default
page read and write
clean
73F000
unkown
page read and write
clean
4810000
unkown
page read and write
clean
427C000
unkown
page read and write
clean
5FF0000
heap private
page read and write
clean
22B6000
unkown
page read and write
clean
17D000
unkown
page execute and read and write
clean
780000
unkown
page read and write
clean
9A6000
unkown image
page readonly
clean
7C0000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
280000
unkown
page read and write
clean
1B4000
heap private
page read and write
clean
237000
unkown
page execute and read and write
clean
22B0000
unkown
page read and write
clean
4F8F000
unkown
page read and write
clean
672000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
51C000
heap default
page read and write
clean
670000
unkown
page read and write
clean
380000
unkown
page read and write
clean
4D7000
heap default
page read and write
clean
2A0000
unkown
page read and write
clean
9D0000
unkown
page read and write
clean
20E4000
heap private
page read and write
clean
4E10000
unkown image
page read and write
clean
28B0000
unkown
page read and write
clean
1C70000
unkown image
page readonly
clean
480000
unkown
page read and write
clean
19B000
unkown
page execute and read and write
clean
22A0000
unkown
page read and write
clean
774000
heap default
page read and write
clean
610000
unkown
page read and write
clean
5DDD000
unkown
page read and write
clean
264000
unkown
page read and write
clean
1F9E000
unkown
page read and write
clean
4D90000
unkown
page read and write
clean
22B0000
unkown
page read and write
clean
7C0000
unkown
page read and write
clean
560E000
unkown
page read and write
clean
3C8000
unkown
page read and write
clean
529E000
unkown
page read and write
clean
3599000
unkown
page read and write
clean
470000
unkown image
page read and write
clean
49FF000
unkown
page read and write
clean
73C000
heap private
page read and write
clean
AB0000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
6322000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
2714000
unkown
page read and write
clean
20000
unkown
page read and write
clean
4BAE000
unkown
page read and write
clean
4D8F000
unkown
page read and write
clean
330000
unkown
page read and write
clean
523E000
unkown
page read and write
clean
9B000
unkown
page read and write
clean
400000
unkown
page execute and read and write
clean
192000
unkown
page read and write
clean
9B0000
unkown image
page readonly
clean
5C0000
unkown
page read and write
clean
1C3000
unkown
page execute and read and write
clean
366A000
unkown
page read and write
clean
3CB1000
unkown
page read and write
clean
192000
unkown
page read and write
clean
5AB000
heap default
page read and write
clean
483F000
unkown
page read and write
clean
20E000
unkown
page read and write
clean
4C40000
unkown image
page read and write
clean
7EFC2000
unkown image
page readonly
clean
780000
unkown
page read and write
clean
510D000
unkown
page read and write
clean
864000
heap private
page read and write
clean
4F4000
heap default
page read and write
clean
510000
heap default
page read and write
clean
71DB000
unkown
page read and write
clean
5CDC000
unkown
page read and write
clean
3B0000
unkown image
page read and write
clean
22B5000
unkown
page read and write
clean
534000
heap default
page read and write
clean
3461000
unkown
page read and write
clean
164000
unkown
page read and write
clean
24BE000
unkown
page read and write
clean
520E000
unkown
page read and write | page guard
clean
5030000
unkown
page read and write
clean
410000
unkown image
page readonly
clean
23B000
unkown
page execute and read and write
clean
632C000
unkown
page read and write
clean
860000
unkown image
page readonly
clean
472000
unkown
page read and write
clean
79C000
heap default
page read and write
clean
ADEF000
unkown
page read and write
clean
5C3000
heap default
page read and write
clean
912000
unkown image
page execute read
clean
7EFB2000
unkown image
page readonly
clean
BE2000
unkown image
page execute read
clean
3579000
unkown
page read and write
clean
720000
unkown image
page readonly
clean
59AF000
unkown
page read and write
clean
670000
unkown image
page readonly
clean
860000
heap private
page read and write
clean
730000
unkown
page read and write
clean
38C3000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
3FF000
unkown
page read and write
clean
5A0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
531E000
unkown
page read and write
clean
910000
unkown image
page readonly
clean
4F4D000
unkown
page read and write
clean
47B000
unkown
page read and write
clean
2F7000
heap default
page read and write
clean
2100000
heap private
page execute and read and write
clean
60000
unkown image
page readonly
clean
422000
unkown
page execute and read and write
clean
7EFB0000
unkown image
page readonly
clean
5EE000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
3531000
unkown
page read and write
clean
22B0000
unkown
page read and write
clean
223E000
unkown
page read and write
clean
4A5E000
unkown
page read and write
clean
43A0000
heap private
page read and write
clean
9D0000
unkown
page read and write
clean
439E000
unkown
page read and write
clean
22AC000
unkown
page read and write
clean
5C4000
unkown
page read and write
clean
242E000
unkown
page read and write | page guard
clean
B05E000
unkown
page read and write
clean
A7E1000
unkown
page read and write
clean
3902000
unkown
page read and write
clean
3511000
unkown
page read and write
clean
912000
unkown image
page execute read
clean
ADE000
unkown
page read and write
clean
543F000
unkown
page read and write
clean
BE2000
unkown image
page execute read
clean
480000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
B62000
heap private
page read and write
clean
3A0000
heap private
page execute and read and write
clean
3E0000
unkown
page read and write
clean
280000
unkown
page read and write
clean
2D7000
unkown
page execute and read and write
clean
4B0000
unkown
page read and write
clean
280000
unkown image
page readonly
clean
2990000
heap private
page read and write
clean
536E000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
3459000
unkown
page read and write
clean
2260000
unkown
page read and write
clean
AF9F000
unkown
page read and write
clean
780000
unkown
page read and write
clean
390000
unkown
page read and write
clean
2758000
unkown
page read and write
clean
4E4000
unkown
page read and write
clean
550C000
unkown
page read and write
clean
22B0000
unkown
page read and write
clean
274000
unkown
page read and write
clean
21BE000
unkown
page read and write | page guard
clean
4E30000
unkown
page read and write
clean
A6E000
unkown
page read and write
clean
197000
unkown
page execute and read and write
clean
2548000
unkown
page read and write
clean
C76000
unkown image
page readonly
clean
7E0000
heap default
page read and write
clean
A4E000
unkown
page read and write
clean
7EFA9000
unkown
page read and write
clean
820000
unkown image
page read and write
clean
20000
unkown
page read and write
clean
280000
unkown
page read and write
clean
456000
unkown
page read and write
clean
400000
unkown
page execute and read and write
clean
8B0000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
22CE000
unkown
page read and write | page guard
clean
3D0000
unkown
page read and write
clean
23DE000
unkown
page read and write
clean
9B0000
unkown image
page readonly
clean
A0000
unkown image
page readonly
clean
561E000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
AC3F000
unkown
page read and write
clean
52C0000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
637A000
unkown
page read and write
clean
220000
unkown
page read and write
clean
4E0000
unkown image
page read and write
clean
2482000
unkown
page read and write
clean
310000
unkown
page read and write
clean
520000
heap default
page read and write
clean
6332000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
4B0000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
55C000
heap default
page read and write
clean
556E000
unkown
page read and write | page guard
clean
480000
unkown
page read and write
clean
424000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
476000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
280000
unkown
page read and write
clean
19B000
unkown
page execute and read and write
clean
460000
unkown
page read and write
clean
8F7000
unkown
page read and write
clean
8F0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
4B0000
unkown image
page readonly
clean
541E000
unkown
page read and write
clean
221E000
unkown
page read and write
clean
20FC000
unkown
page read and write
clean
242F000
unkown
page read and write
clean
78F000
unkown
page read and write
clean
2922000
unkown
page read and write
clean
443E000
unkown
page read and write
clean
4B0000
unkown
page read and write
clean
6344000
unkown
page read and write
clean
7C6000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
57B000
heap default
page read and write
clean
ADEE000
unkown
page read and write | page guard
clean
450000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
6DD9000
unkown
page read and write
clean
790000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
480000
unkown
page read and write
clean
20000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
3853000
unkown
page read and write
clean
130000
unkown
page read and write
clean
29A000
unkown
page execute and read and write
clean
C76000
unkown image
page readonly
clean
22B0000
unkown
page read and write
clean
3D63000
unkown
page read and write
clean
2A8000
unkown
page read and write
clean
670000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
610000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
480000
unkown image
page read and write
clean
5CC000
heap default
page read and write
clean
420000
unkown
page read and write
clean
450000
heap default
page read and write
clean
587C000
unkown
page read and write
clean
8FC000
unkown
page read and write
clean
340000
unkown
page read and write
clean
C76000
unkown image
page readonly
clean
36F7000
unkown
page read and write
clean
900000
unkown image
page readonly
clean
670000
unkown
page read and write
clean
60F0000
heap private
page read and write
clean
22A1000
unkown
page read and write
clean
29CB000
heap private
page read and write
clean
4430000
heap private
page read and write
clean
8F0000
unkown
page read and write
clean
4C4E000
unkown
page read and write
clean
20000
heap private
page read and write
clean
A20000
unkown
page read and write
clean
8F0000
unkown
page read and write
clean
BE0000
unkown image
page readonly
clean
170000
unkown
page read and write
clean
27D000
unkown
page execute and read and write
clean
480000
unkown
page read and write
clean
20000
unkown
page read and write
clean
350000
unkown
page read and write
clean
BE2000
unkown image
page execute read
clean
7EFDF000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
210000
unkown
page execute and read and write
clean
225F000
unkown
page read and write
clean
34D1000
unkown
page read and write
clean
BDE000
unkown
page read and write
clean
26D8000
unkown
page read and write
clean
4850000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
790000
unkown
page read and write
clean
1D0000
unkown
page read and write
clean
466E000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
32A1000
unkown
page read and write
clean
632C000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
6AF0000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
470000
unkown
page read and write
clean
22B0000
unkown
page read and write
clean
2946000
unkown
page read and write
clean
12D000
unkown
page execute and read and write
clean
3E0000
unkown
page read and write
clean
13D000
unkown
page execute and read and write
clean
60000
unkown image
page readonly
clean
3E6000
unkown
page read and write
clean
7C6000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
460000
unkown
page read and write
clean
4EE0000
heap private
page read and write
clean
BE2000
unkown image
page execute read
clean
368000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
3A5000
unkown
page read and write
clean
AEEF000
unkown
page read and write
clean
910000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
8A000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
8A0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
4C2000
unkown
page read and write
clean
21D0000
heap private
page execute and read and write
clean
310000
unkown
page read and write
clean
664E000
unkown
page read and write
clean
B7E000
unkown
page read and write
clean
360000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
479000
heap private
page read and write
clean
510000
unkown
page read and write
clean
170000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
5C5000
unkown
page read and write
clean
48E000
heap default
page read and write
clean
6D0000
unkown image
page readonly
clean
1F0000
heap default
page read and write
clean
422000
unkown
page read and write
clean
3863000
unkown
page read and write
clean
806000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
616000
unkown
page read and write
clean
18A000
unkown
page execute and read and write
clean
459F000
unkown
page read and write
clean
633C000
unkown
page read and write
clean
218E000
unkown
page read and write
clean
330000
heap private
page read and write
clean
53DE000
unkown
page read and write
clean
912000
unkown image
page execute read
clean
BE0000
unkown image
page readonly
clean
26D000
unkown
page execute and read and write
clean
4EBE000
unkown
page read and write
clean
320000
unkown
page read and write
clean
450000
unkown
page read and write
clean
78E000
unkown
page read and write
clean
70BE000
unkown
page read and write
clean
4F6E000
unkown
page read and write
clean
3F6000
unkown
page read and write
clean
20D0000
unkown image
page readonly
clean
910000
unkown image
page readonly
clean
213C000
unkown
page read and write
clean
C76000
unkown image
page readonly
clean
470000
heap private
page read and write
clean
7E1000
heap default
page read and write
clean
2260000
heap private
page execute and read and write
clean
827000
heap default
page read and write
clean
8B0000
unkown image
page read and write
clean
7EFE0000
unkown image
page readonly
clean
2A0000
unkown
page read and write
clean
4F8E000
unkown
page read and write | page guard
clean
9B5000
heap private
page read and write
clean
164000
unkown
page read and write
clean
4F7E000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
2310000
unkown
page read and write
clean
780000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
610000
unkown
page read and write
clean
5020000
heap private
page execute and read and write
clean
633B000
unkown
page read and write
clean
222E000
unkown
page read and write | page guard
clean
2810000
unkown image
page readonly
clean
380000
unkown
page read and write
clean
850000
unkown image
page readonly
clean
509E000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7A0000
heap default
page read and write
clean
3883000
unkown
page read and write
clean
BE2000
unkown image
page execute read
clean
910000
unkown image
page readonly
clean
380000
unkown
page read and write
clean
3992000
unkown
page read and write
clean
35F9000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
AC3E000
unkown
page read and write | page guard
clean
7EFB0000
unkown image
page readonly
clean
273000
unkown
page execute and read and write
clean
38A2000
unkown
page read and write
clean
4F4E000
unkown
page read and write
clean
A0000
unkown image
page readonly
clean
732E000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
7C0000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
2210000
unkown
page read and write
clean
2BB000
unkown
page execute and read and write
clean
2A6000
unkown
page read and write
clean
7EF40000
unkown
page execute and read and write
clean
460000
unkown
page read and write
clean
544F000
unkown
page read and write
clean
5FDE000
unkown
page read and write
clean
7B8E000
unkown
page read and write
clean
C76000
unkown image
page readonly
clean
260000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
1FF0000
unkown
page read and write
clean
197000
unkown
page execute and read and write
clean
7EFD0000
unkown image
page readonly
clean
435E000
unkown
page read and write
clean
570000
unkown
page read and write
clean
7C0000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
9A6000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
EA000
unkown
page read and write
clean
900000
unkown
page read and write
clean
4A6F000
unkown
page read and write
clean
2A9000
heap private
page read and write
clean
3A0000
unkown
page read and write
clean
3F0000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
4CB000
unkown
page read and write
clean
2150000
heap private
page read and write
clean
2B0000
unkown
page read and write
clean
245000
unkown
page read and write
clean
6BD000
unkown
page read and write
clean
8C0000
unkown image
page read and write
clean
637000
heap private
page read and write
clean
460000
unkown
page read and write
clean
9B0000
unkown image
page readonly
clean
4B6E000
unkown
page read and write
clean
340000
unkown
page read and write
clean
2752000
unkown
page read and write
clean
4EF0000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7C0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
1DB0000
unkown image
page readonly
clean
2D7000
unkown
page execute and read and write
clean
678000
unkown
page read and write
clean
796000
unkown
page read and write
clean
370000
unkown
page read and write
clean
314000
heap default
page read and write
clean
850000
unkown image
page read and write
clean
369A000
unkown
page read and write
clean
282000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
890000
heap private
page read and write
clean
912000
unkown image
page execute read
clean
510000
unkown
page read and write
clean
BE0000
unkown image
page readonly
clean
457000
heap default
page read and write
clean
7EFB0000
unkown image
page readonly
clean
4F9D000
unkown
page read and write
clean
C76000
unkown image
page readonly
clean
4C4000
unkown
page read and write
clean
5CA000
heap default
page read and write
clean
480000
unkown
page read and write
clean
4F0000
heap default
page read and write
clean
50000
unkown image
page readonly
clean
A50000
unkown image
page read and write
clean
882000
heap private
page read and write
clean
7EF40000
unkown
page execute and read and write
clean
632C000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
BE2000
unkown image
page execute read
clean
ADF000
unkown
page read and write
clean
460000
unkown
page read and write
clean
470000
unkown
page read and write
clean
4CC000
unkown
page read and write
clean
910000
unkown image
page readonly
clean
182000
unkown
page read and write
clean
487000
unkown
page read and write
clean
330000
heap default
page read and write
clean
3E0000
unkown
page read and write
clean
51CE000
unkown
page read and write
clean
34F1000
unkown
page read and write
clean
840000
unkown image
page read and write
clean
450000
unkown
page read and write
clean
308000
unkown
page read and write
clean
B90000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
6324000
unkown
page read and write
clean
42E000
unkown
page read and write
clean
580000
heap private
page read and write
clean
C76000
unkown image
page readonly
clean
33D000
heap default
page read and write
clean
35B9000
unkown
page read and write
clean
9D0000
unkown
page read and write
clean
2300000
unkown image
page read and write
clean
BE0000
unkown image
page readonly
clean
BB2000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
610000
unkown image
page readonly
clean
533E000
unkown
page read and write
clean
870000
unkown image
page readonly
clean
9A6000
unkown image
page readonly
clean
465000
unkown
page read and write
clean
B80000
unkown
page read and write
clean
450000
unkown
page read and write
clean
8F0000
unkown
page read and write
clean
20E0000
heap private
page read and write
clean
7EC000
heap default
page read and write
clean
8B0000
unkown
page read and write
clean
570000
unkown
page read and write
clean
89E000
unkown
page read and write
clean
8F0000
unkown
page read and write
clean
270000
unkown
page read and write
clean
2190000
unkown image
page read and write
clean
22E0000
unkown
page execute and read and write
clean
910000
unkown image
page readonly
clean
3281000
unkown
page read and write
clean
59A000
unkown
page read and write
clean
340000
heap default
page read and write
clean
9D0000
unkown
page read and write
clean
280C000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
795000
unkown
page read and write
clean
73E000
unkown
page read and write | page guard
clean
BE0000
unkown image
page readonly
clean
7EF40000
unkown
page execute and read and write
clean
There are 1353 hidden memdumps, click here to show them.