IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Claim-838392655-09242021.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Author: Test, Last Saved By: Test, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Jun 5 19:17:20 2015, Last Saved Time/Date: Fri Sep 24 10:05:02 2021, Security: 0
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\44466.4649013889[1].dat
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\44466.4649013889[2].dat
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\44466.4649013889[3].dat
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Fiosa.der
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Fiosa1.der
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Fiosa2.der
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\VBE\MSForms.exd
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Fiosa.der
malicious
C:\Windows\SysWOW64\regsvr32.exe
-silent ..\Fiosa.der
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Fiosa1.der
malicious
C:\Windows\SysWOW64\regsvr32.exe
-silent ..\Fiosa1.der
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\SysWOW64\schtasks.exe
'C:\Windows\system32\schtasks.exe' /Create /RU 'NT AUTHORITY\SYSTEM' /tn pmdfegez /tr 'regsvr32.exe -s \'C:\Users\user\Fiosa.der\'' /SC ONCE /Z /ST 11:12 /ET 11:24
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\Fiosa.der'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\Fiosa.der'
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Fiosa2.der
malicious
C:\Windows\SysWOW64\regsvr32.exe
-silent ..\Fiosa2.der
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\System32\reg.exe
C:\Windows\system32\reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths' /f /t REG_DWORD /v 'C:\ProgramData\Microsoft\Yiiocubi' /d '0'
malicious
C:\Windows\System32\reg.exe
C:\Windows\system32\reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths' /f /t REG_DWORD /v 'C:\Users\user\AppData\Roaming\Microsoft\Nqsaq' /d '0'
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\Fiosa.der'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\Fiosa.der'
malicious
There are 8 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://www.%s.comPA
unknown
clean
http://111.90.148.104/44466.4649013889.dat
111.90.148.104
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://190.14.37.173/44466.4649013889.dat
190.14.37.173
clean
http://servername/isapibackend.dll
unknown
clean
http://51.89.115.111/44466.4649013889.dat
51.89.115.111
clean

IPs

IP
Domain
Country
Malicious
190.14.37.173
unknown
Panama
clean
51.89.115.111
unknown
France
clean
111.90.148.104
unknown
Malaysia
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
`6&
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2FA85
2FA85
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FE50DCD5-4669-4509-BE98-F6D09C4AA61B}\2.0
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FE50DCD5-4669-4509-BE98-F6D09C4AA61B}\2.0\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FE50DCD5-4669-4509-BE98-F6D09C4AA61B}\2.0\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FE50DCD5-4669-4509-BE98-F6D09C4AA61B}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{FE50DCD5-4669-4509-BE98-F6D09C4AA61B}\2.0
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{FE50DCD5-4669-4509-BE98-F6D09C4AA61B}\2.0\FLAGS
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{FE50DCD5-4669-4509-BE98-F6D09C4AA61B}\2.0\0\win32
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{FE50DCD5-4669-4509-BE98-F6D09C4AA61B}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
>'&
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\4F72B
4F72B
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\4FB11
4FB11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_CURRENT_USER\Software\Microsoft\Iijjdbclvgvtma
884436a0
clean
HKEY_CURRENT_USER\Software\Microsoft\Iijjdbclvgvtma
bddbe6ee
clean
HKEY_CURRENT_USER\Software\Microsoft\Iijjdbclvgvtma
bf9ac692
clean
HKEY_CURRENT_USER\Software\Microsoft\Iijjdbclvgvtma
726a1f7
clean
HKEY_CURRENT_USER\Software\Microsoft\Iijjdbclvgvtma
7a2eee7d
clean
HKEY_CURRENT_USER\Software\Microsoft\Iijjdbclvgvtma
c2928918
clean
HKEY_CURRENT_USER\Software\Microsoft\Iijjdbclvgvtma
567818b
clean
HKEY_CURRENT_USER\Software\Microsoft\Iijjdbclvgvtma
f70d5956
clean
HKEY_CURRENT_USER\Software\Microsoft\Iijjdbclvgvtma
884436a0
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Agsiyibws
84a07c7
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Agsiyibws
3dd5d789
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Agsiyibws
3f94f7f5
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Agsiyibws
87289090
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Agsiyibws
fa20df1a
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Agsiyibws
429cb87f
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Agsiyibws
8569b0ec
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Agsiyibws
77036831
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Agsiyibws
84a07c7
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
C:\ProgramData\Microsoft\Yiiocubi
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
C:\Users\user\AppData\Roaming\Microsoft\Nqsaq
clean
There are 205 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
7FFFFFD0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
30000
unkown image
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
460000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
2D4000
heap private
page read and write
clean
710000
unkown image
page readonly
clean
695000
heap default
page read and write
clean
7EFB0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
176000
heap private
page read and write
clean
4D0000
unkown image
page readonly
clean
3C0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
290000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
450000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
10001000
unkown image
page execute read
clean
1002A000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
24C0000
unkown image
page readonly
clean
5B0000
unkown image
page readonly
clean
A6000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
E0000
unkown image
page readonly
clean
10116000
unkown image
page readonly
clean
10000000
unkown image
page readonly
clean
DC000
unkown
page read and write
clean
1C10000
unkown image
page readonly
clean
3F3000
unkown
page read and write
clean
930000
unkown image
page readonly
clean
1001F000
unkown image
page readonly
clean
69D000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
80000
unkown image
page execute and read and write
clean
25B000
unkown
page read and write
clean
1CA0000
unkown image
page readonly
clean
1FE0000
unkown image
page readonly
clean
6A0000
unkown image
page readonly
clean
4D0000
heap private
page read and write
clean
297000
heap default
page read and write
clean
240000
heap private
page read and write
clean
24EF000
unkown
page read and write
clean
1C6000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
4D6000
heap private
page read and write
clean
1A0000
unkown
page execute and read and write
clean
2905000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
660000
unkown image
page readonly
clean
10000000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
3F2000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
417000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
340000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
4B0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
10000
unkown image
page read and write
clean
68F000
heap default
page read and write
clean
4A7000
heap default
page read and write
clean
50000
unkown image
page readonly
clean
246000
heap private
page read and write
clean
1FED000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
10077000
unkown image
page execute and read and write
clean
1002A000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
132F000
heap private
page read and write
clean
2740000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
285F000
heap private
page read and write
clean
1001F000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
10075000
unkown image
page read and write
clean
7CF000
heap default
page read and write
clean
10075000
unkown image
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
180000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
21BC000
unkown
page read and write
clean
205B000
heap private
page read and write
clean
2800000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
2840000
unkown
page read and write
clean
1B7000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
33E000
unkown
page read and write
clean
270000
unkown
page read and write
clean
150000
heap default
page read and write
clean
3AE000
heap default
page read and write
clean
CA000
unkown
page read and write
clean
657000
heap default
page read and write
clean
30000
unkown image
page readonly
clean
2E7000
heap default
page read and write
clean
26F0000
heap private
page read and write
clean
670000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
75E000
unkown
page read and write
clean
6A7000
heap default
page read and write
clean
50000
unkown image
page readonly
clean
84D000
unkown
page read and write
clean
580000
unkown image
page readonly
clean
2EE000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
20A0000
unkown image
page readonly
clean
2F0000
heap default
page read and write
clean
2270000
heap private
page read and write
clean
41F000
unkown
page read and write
clean
13F1000
unkown
page read and write
clean
299F000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
D0000
unkown
page execute and read and write
clean
C80000
heap private
page read and write
clean
300000
heap private
page read and write
clean
240000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
27C000
unkown
page read and write
clean
350000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2900000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
416000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
650000
unkown image
page readonly
clean
830000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
657000
heap default
page read and write
clean
80000
unkown image
page execute and read and write
clean
230000
unkown
page read and write
clean
12B0000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
287E000
unkown
page read and write
clean
3C3000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2120000
heap private
page read and write
clean
2025000
heap private
page read and write
clean
10018000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
2352000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
10000000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
2A6000
heap private
page read and write
clean
154F000
unkown
page read and write
clean
377000
heap default
page read and write
clean
20000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
860000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
170000
unkown
page read and write
clean
450000
unkown image
page readonly
clean
3E4000
heap private
page read and write
clean
316000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
780000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
224000
heap default
page read and write
clean
1EE000
heap default
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7FE000
unkown
page read and write
clean
2651000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
10077000
unkown image
page execute and read and write
clean
24C000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
3C0000
unkown
page read and write
clean
190000
unkown
page execute and read and write
clean
7EFC2000
unkown image
page readonly
clean
C0000
unkown image
page readonly
clean
6A0000
heap default
page read and write
clean
2F7000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
180000
heap private
page read and write
clean
60000
unkown image
page readonly
clean
700000
unkown image
page readonly
clean
10000000
unkown image
page readonly
clean
160000
unkown image
page read and write
clean
570000
heap private
page read and write
clean
6A8000
unkown
page read and write
clean
2841000
unkown
page read and write
clean
2610000
heap private
page read and write
clean
30000
unkown image
page read and write
clean
180000
heap private
page read and write
clean
9D000
heap default
page read and write
clean
170000
unkown
page read and write
clean
2943000
heap private
page read and write
clean
4B0000
unkown image
page readonly
clean
710000
unkown image
page readonly
clean
2A6000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
132F000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
284F000
heap private
page read and write
clean
2BD000
unkown
page read and write
clean
1EE000
heap default
page read and write
clean
700000
unkown image
page readonly
clean
23B000
unkown
page read and write
clean
3F4000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
184000
heap private
page read and write
clean
2E0000
heap default
page read and write
clean
13F0000
unkown
page read and write
clean
410000
heap default
page read and write
clean
1001F000
unkown image
page readonly
clean
7C9000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
2174000
heap private
page read and write
clean
CE0000
heap private
page read and write
clean
270000
heap private
page read and write
clean
120000
unkown
page execute and read and write
clean
F0000
heap default
page read and write
clean
25EF000
unkown
page read and write
clean
1EC000
unkown
page read and write
clean
3F5000
unkown
page read and write
clean
1CA0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
80000
unkown image
page execute and read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
3C4000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
130000
unkown image
page read and write
clean
717000
heap default
page read and write
clean
2923000
heap private
page read and write
clean
220000
unkown image
page read and write
clean
1E3000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
1220000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
36B000
unkown
page read and write
clean
31E000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
27D0000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
2E3000
heap default
page read and write
clean
170000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
1243000
heap private
page read and write
clean
180000
heap private
page read and write
clean
170000
unkown image
page read and write
clean
100000
unkown
page read and write
clean
10021000
unkown image
page execute read
clean
190000
unkown
page read and write
clean
C2D000
unkown
page read and write
clean
39F000
unkown
page read and write
clean
8B0000
unkown image
page readonly
clean
580000
unkown image
page readonly
clean
2160000
unkown image
page readonly
clean
730000
unkown image
page readonly
clean
27EE000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
C10000
unkown
page read and write
clean
29CF000
heap private
page read and write
clean
700000
unkown image
page readonly
clean
10001000
unkown image
page execute read
clean
570000
heap private
page read and write
clean
3E0000
unkown
page read and write
clean
3E0000
heap default
page read and write
clean
202B000
heap private
page read and write
clean
260000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
D0000
unkown image
page readonly
clean
1FC0000
heap private
page read and write
clean
2C6000
unkown
page read and write
clean
1CE000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
1A4000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
446000
heap private
page read and write
clean
50000
unkown image
page readonly
clean
250000
unkown
page read and write
clean
170000
heap private
page read and write
clean
420000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
80000
unkown image
page execute and read and write
clean
26D000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
1FD0000
unkown
page read and write
clean
20C000
unkown
page read and write
clean
10000000
unkown image
page readonly
clean
250000
unkown
page execute and read and write
clean
7EFD0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
11C000
unkown
page read and write
clean
76A000
heap default
page read and write
clean
7EFD0000
unkown image
page readonly
clean
710000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
2EC000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
D3D000
unkown
page read and write
clean
20A000
heap default
page read and write
clean
7EFC0000
unkown image
page readonly
clean
190000
heap default
page read and write
clean
21D000
unkown
page read and write
clean
4AF000
unkown
page read and write
clean
10000000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
2950000
heap private
page read and write
clean
500000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
1F94000
heap private
page read and write
clean
2E6000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
530000
heap default
page read and write
clean
20000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
1E40000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
184000
heap private
page read and write
clean
60000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
3E6000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
830000
unkown image
page readonly
clean
DAC000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
310000
heap private
page read and write
clean
60000
unkown image
page readonly
clean
190000
unkown
page read and write
clean
33C000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
510000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
350000
unkown image
page readonly
clean
840000
unkown
page read and write
clean
370000
heap default
page read and write
clean
390000
unkown
page read and write
clean
1001D000
unkown image
page read and write
clean
7EFE0000
unkown image
page readonly
clean
F0000
unkown
page read and write
clean
11A000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
10077000
unkown image
page execute and read and write
clean
7EFB2000
unkown image
page readonly
clean
310000
heap private
page read and write
clean
570000
unkown image
page readonly
clean
2D20000
unkown image
page readonly
clean
290000
heap default
page read and write
clean
240000
heap private
page read and write
clean
660000
unkown image
page readonly
clean
B0000
unkown
page execute and read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
197000
heap default
page read and write
clean
1B0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2CDF000
unkown
page read and write
clean
A30000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
296000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
B0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
6A6000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
21B0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
4F0000
heap private
page read and write
clean
710000
heap default
page read and write
clean
20000
unkown image
page readonly
clean
21C000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
8D0000
heap private
page read and write
clean
30000
unkown image
page readonly
clean
90000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
26CE000
unkown
page read and write
clean
10001000
unkown image
page execute read
clean
20000
unkown image
page read and write
clean
69F000
unkown
page read and write
clean
3F8000
unkown
page read and write
clean
910000
unkown image
page readonly
clean
12B000
unkown
page read and write
clean
74F000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
790000
heap default
page read and write
clean
7EFC0000
unkown image
page readonly
clean
1002A000
unkown image
page readonly
clean
2925000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
4A0000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
1FA000
unkown
page read and write
clean
1D0000
unkown
page execute and read and write
clean
20000
unkown image
page readonly
clean
10021000
unkown image
page execute read
clean
7EFE0000
unkown image
page readonly
clean
213C000
unkown
page read and write
clean
7B4000
heap default
page read and write
clean
10075000
unkown image
page read and write
clean
200000
heap default
page read and write
clean
7EFD0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
17C000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
674000
heap default
page read and write
clean
10000000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
150000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
E0000
unkown image
page read and write
clean
1B7000
heap default
page read and write
clean
7EFB0000
unkown image
page readonly
clean
E30000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
5A0000
unkown image
page readonly
clean
170000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
C0000
unkown image
page read and write
clean
170000
unkown
page read and write
clean
1A0000
heap private
page read and write
clean
40000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
440000
heap private
page read and write
clean
640000
unkown image
page readonly
clean
2170000
heap private
page read and write
clean
194E000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
3EC000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7EFC0000
unkown image
page readonly
clean
2920000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
94E000
unkown
page read and write
clean
2070000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
160000
unkown image
page read and write
clean
1FFB000
heap private
page read and write
clean
2020000
heap private
page read and write
clean
5D0000
unkown image
page readonly
clean
263F000
unkown
page read and write
clean
32E000
heap default
page read and write
clean
350000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
247D000
unkown
page read and write
clean
2460000
unkown
page read and write
clean
6A0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
60000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
2330000
heap private
page read and write
clean
674000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
5F0000
unkown image
page readonly
clean
343000
heap default
page read and write
clean
10000000
unkown image
page readonly
clean
30000
unkown image
page read and write
clean
170000
unkown image
page read and write
clean
2E9E000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
2AE000
unkown
page read and write
clean
2CE000
heap default
page read and write
clean
80000
unkown
page read and write
clean
190000
unkown image
page readonly
clean
4E0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
1F0000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
1F0000
unkown image
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
10018000
unkown image
page readonly
clean
574000
heap private
page read and write
clean
890000
unkown image
page readonly
clean
C80000
heap private
page read and write
clean
7EFDF000
unkown
page read and write
clean
689000
heap default
page read and write
clean
510000
unkown image
page readonly
clean
1001F000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
278F000
unkown
page read and write
clean
2070000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7E6000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
4F0000
heap default
page read and write
clean
2B0000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
20D0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
67F000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2FE000
unkown
page read and write
clean
44A000
heap default
page read and write
clean
10000000
unkown image
page readonly
clean
27DE000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
30000
unkown image
page read and write
clean
430000
heap default
page read and write
clean
27BF000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
314000
heap default
page read and write
clean
4D0000
unkown image
page readonly
clean
240000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
2F7000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
4C4000
heap default
page read and write
clean
650000
heap default
page read and write
clean
263E000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
1CA0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
56F000
unkown
page read and write
clean
2B6C000
unkown
page read and write
clean
6A2000
heap default
page read and write
clean
1002A000
unkown image
page readonly
clean
3D0000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
6C4000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
3B0000
unkown
page read and write
clean
292000
heap private
page read and write
clean
580000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
426000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
630000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
203000
heap default
page read and write
clean
140000
unkown
page read and write
clean
2730000
heap private
page read and write
clean
BC000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
1B0000
heap default
page read and write
clean
2F0F000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
2D0000
heap private
page read and write
clean
60000
unkown image
page readonly
clean
2803000
heap private
page read and write
clean
70000
unkown image
page read and write
clean
1001D000
unkown image
page read and write
clean
1D0000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
D20000
unkown
page read and write
clean
10116000
unkown image
page readonly
clean
180000
heap private
page read and write
clean
50000
unkown image
page readonly
clean
154E000
unkown
page read and write
clean
2370000
unkown image
page readonly
clean
1F90000
heap private
page read and write
clean
27DE000
unkown
page read and write
clean
426000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
87D000
unkown
page read and write
clean
62F000
unkown
page read and write
clean
130000
unkown
page execute and read and write
clean
5D0000
unkown image
page readonly
clean
1A0000
unkown
page read and write
clean
2070000
unkown image
page readonly
clean
1001D000
unkown image
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
8C000
unkown
page read and write
clean
180000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
2560000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
274000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
D10000
unkown image
page readonly
clean
830000
unkown
page read and write
clean
2550000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
3C0000
heap private
page read and write
clean
4A6000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
3E4000
unkown
page read and write
clean
698000
unkown
page read and write
clean
2FF000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
720000
unkown image
page readonly
clean
1FB2000
heap private
page read and write
clean
7A0000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
800000
unkown
page execute and read and write
clean
BC000
unkown
page read and write
clean
2040000
unkown image
page readonly
clean
47E000
unkown
page read and write
clean
FC000
unkown
page read and write
clean
5E0000
unkown image
page readonly
clean
207000
heap default
page read and write
clean
150000
unkown
page read and write
clean
1C0000
unkown
page execute and read and write
clean
C0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
574000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
E0000
unkown
page read and write
clean
27BE000
unkown
page read and write
clean
E0000
unkown image
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
CD0000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
10018000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
27E5000
heap private
page read and write
clean
22EC000
unkown
page read and write
clean
2561000
unkown
page read and write
clean
734000
heap default
page read and write
clean
690000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
692000
unkown
page read and write
clean
2561000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
3CA000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
470000
unkown image
page readonly
clean
20CF000
unkown
page read and write
clean
30000
unkown image
page read and write
clean
7EFD0000
unkown image
page readonly
clean
4D0000
unkown image
page readonly
clean
2192000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
386000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
4F0000
heap private
page read and write
clean
10018000
unkown image
page readonly
clean
4F4000
heap private
page read and write
clean
E70000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
10077000
unkown image
page execute and read and write
clean
1CE0000
unkown image
page readonly
clean
2334000
heap private
page read and write
clean
3F0000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
5E0000
unkown image
page readonly
clean
10116000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
B0000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
297F000
unkown
page read and write
clean
1D6000
unkown
page read and write
clean
344000
heap private
page read and write
clean
16C000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
70000
unkown image
page read and write
clean
1FF0000
heap private
page read and write
clean
3DD000
unkown
page read and write
clean
18FC000
unkown
page read and write
clean
E20000
unkown image
page readonly
clean
1E0000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
15EF000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
190000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
27E0000
heap private
page read and write
clean
260000
unkown
page read and write
clean
26E000
unkown
page read and write
clean
1A4E000
unkown
page read and write
clean
44F000
heap default
page read and write
clean
3F0000
unkown
page read and write
clean
C70000
unkown image
page readonly
clean
3AF000
unkown
page read and write
clean
800000
heap private
page read and write
clean
2650000
unkown
page read and write
clean
23F000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
3E0000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
10000
unkown image
page read and write
clean
574000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
1FC5000
heap private
page read and write
clean
30000
unkown image
page readonly
clean
10021000
unkown image
page execute read
clean
190000
unkown
page read and write
clean
1FF5000
heap private
page read and write
clean
D2E000
unkown
page read and write
clean
316000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
1F0000
unkown
page read and write
clean
2EA000
heap default
page read and write
clean
D30000
heap private
page read and write
clean
10001000
unkown image
page execute read
clean
10116000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
1B0000
heap default
page read and write
clean
EC000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
1ADF000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
67000
heap default
page read and write
clean
AD000
unkown
page read and write
clean
34A000
heap default
page read and write
clean
2F0000
heap default
page read and write
clean
180000
unkown
page execute and read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
26DC000
unkown
page read and write
clean
297F000
heap private
page read and write
clean
3E7000
heap default
page read and write
clean
2A0000
heap private
page read and write
clean
2670000
heap private
page read and write
clean
2D1E000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
23A000
heap default
page read and write
clean
B0000
unkown
page read and write
clean
10021000
unkown image
page execute read
clean
350000
heap default
page read and write
clean
570000
heap private
page read and write
clean
504000
heap private
page read and write
clean
2B0000
unkown
page execute and read and write
clean
43F000
unkown
page read and write
clean
3C6000
unkown
page read and write
clean
90F000
unkown
page read and write
clean
10075000
unkown image
page read and write
clean
259E000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
74A000
heap default
page read and write
clean
650000
heap default
page read and write
clean
FC000
unkown
page read and write
clean
2A0000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
7EFB2000
unkown image
page readonly
clean
797000
heap default
page read and write
clean
1225000
heap private
page read and write
clean
1EC000
unkown
page read and write
clean
5E0000
unkown image
page readonly
clean
406000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
129F000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
1EA000
heap default
page read and write
clean
20000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
470000
unkown
page read and write
clean
20000
unkown image
page read and write
clean
7EFB0000
unkown image
page readonly
clean
176000
heap private
page read and write
clean
90000
unkown
page read and write
clean
1B0000
unkown
page read and write
clean
210000
heap private
page read and write
clean
2CBE000
unkown
page read and write
clean
184000
heap private
page read and write
clean
434000
heap default
page read and write
clean
29CF000
heap private
page read and write
clean
950000
unkown image
page readonly
clean
690000
unkown image
page readonly
clean
750000
unkown image
page readonly
clean
6A2000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
1001D000
unkown image
page read and write
clean
There are 818 hidden memdumps, click here to show them.