IOC Report

loading gif

Files

File Path
Type
Category
Malicious
(QUOTATION)B-RUS-20061REV2.xlsx
CDFV2 Encrypted
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\rundll32[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
downloaded
malicious
C:\Users\user\Desktop\~$(QUOTATION)B-RUS-20061REV2.xlsx
data
dropped
malicious
C:\Users\Public\vbc.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\45827960.png
PNG image data, 484 x 544, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5E5C69E1.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 220x220, segment length 16, baseline, precision 8, 686x220, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\90D5CCBD.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 191x263, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\9F672CAC.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 220x220, segment length 16, baseline, precision 8, 686x220, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\CC400E1B.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\E1602797.png
PNG image data, 484 x 544, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F3DA066E.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 191x263, frames 3
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
malicious
C:\Users\Public\vbc.exe
'C:\Users\Public\vbc.exe'
malicious
C:\Users\Public\vbc.exe
C:\Users\Public\vbc.exe
malicious
C:\Windows\explorer.exe
C:\Windows\Explorer.EXE
malicious
C:\Windows\SysWOW64\msiexec.exe
C:\Windows\SysWOW64\msiexec.exe
malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
clean
C:\Windows\SysWOW64\autofmt.exe
C:\Windows\SysWOW64\autofmt.exe
clean
C:\Windows\SysWOW64\cmd.exe
/c del 'C:\Users\Public\vbc.exe'
clean

URLs

Name
IP
Malicious
http://180.214.239.85/service/rundll32.exe
180.214.239.85
malicious
www.odysseysailingsantorini.com/cmsr/
malicious
http://www.paradisgrp.com/cmsr/?rP=nVytjV1HNt3hMhEp&yPWTYF2P=ujlsVlrzpoa18ID3lc18bZaAxLX0DfE0xdRLh6j3jOxuPYwZm7ST3/5Fs9u0Ms1f4kekUA==
128.65.195.232
malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://java.sun.com
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://wellformedweb.org/CommentAPI/
unknown
clean
http://www.piriform.com/ccleanerhttp://www.piriform.com/ccleanerv
unknown
clean
http://investor.msn.com/
unknown
clean
http://www.iis.fhg.de/audioPA
unknown
clean
http://www.piriform.com/ccleaner
unknown
clean
http://computername/printers/printername/.printer
unknown
clean
http://www.uvoyus.com/cmsr/?yPWTYF2P=Z163eHxziih9zoATqlvcvJ58YKpwfcrh+Tl2ZMFzPk6a2h2CebNQOI6FcYtN0fOfP8d5cg==&rP=nVytjV1HNt3hMhEp
34.102.136.180
clean
http://www.%s.comPA
unknown
clean
http://www.autoitscript.com/autoit3
unknown
clean
https://support.mozilla.org
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://treyresearch.net
unknown
clean
http://servername/isapibackend.dll
unknown
clean
There are 13 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
www.paradisgrp.com
128.65.195.232
malicious
www.uvoyus.com
unknown
malicious
uvoyus.com
34.102.136.180
clean

IPs

IP
Domain
Country
Malicious
128.65.195.232
www.paradisgrp.com
Switzerland
malicious
180.214.239.85
unknown
Viet Nam
malicious
34.102.136.180
uvoyus.com
United States
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
kc#
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2DAC5
2DAC5
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
zh#
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\32240
32240
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\33B1D
33B1D
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 21
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\32240
32240
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
EquationEditorFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus
FontCachePath
clean
There are 31 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
251B000
unkown
page read and write
malicious
24B1000
unkown
page read and write
malicious
90000
unkown image
page execute and read and write
malicious
8065000
unkown image
page execute and read and write
malicious
250000
unkown image
page execute and read and write
malicious
400000
unkown
page execute and read and write
malicious
8065000
unkown image
page execute and read and write
malicious
280000
unkown
page read and write
malicious
1F0000
unkown image
page execute and read and write
malicious
300000
unkown image
page execute and read and write
malicious
34B9000
unkown
page read and write
malicious
7EFE0000
unkown image
page readonly
clean
4D80000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
45BF000
unkown
page read and write
clean
6513000
unkown
page read and write
clean
6861000
unkown
page read and write
clean
2A30000
unkown
page read and write
clean
8374000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
306000
heap default
page read and write
clean
5090000
unkown
page read and write
clean
1D7000
unkown
page read and write
clean
1D7000
unkown
page read and write
clean
D6E000
unkown
page read and write
clean
3C90000
unkown image
page read and write
clean
32A000
unkown
page read and write
clean
39E000
unkown
page read and write
clean
7B4B000
unkown
page read and write
clean
3140000
heap private
page read and write
clean
74B4000
heap private
page read and write
clean
456F000
unkown
page read and write
clean
2AA0000
unkown
page read and write
clean
62F000
unkown
page read and write
clean
8FAE000
unkown
page read and write
clean
2933000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
24C000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
30F0000
unkown image
page readonly
clean
F20000
unkown
page read and write
clean
2CC7000
unkown image
page readonly
clean
74D3000
heap private
page read and write
clean
9774000
unkown
page read and write
clean
2170000
unkown image
page readonly
clean
249000
heap default
page read and write
clean
5A0000
heap default
page read and write
clean
170000
unkown
page read and write
clean
836E000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
B90000
unkown
page execute and read and write
clean
4D20000
unkown
page execute and read and write
clean
2110000
unkown image
page read and write
clean
3CC0000
unkown image
page readonly
clean
31D000
heap default
page read and write
clean
2A50000
unkown
page read and write
clean
4D70000
unkown image
page readonly
clean
7A6000
heap private
page read and write
clean
679C000
unkown
page read and write
clean
36F000
unkown
page read and write
clean
BE0000
unkown image
page readonly
clean
CA7000
unkown
page execute and read and write
clean
29F0000
unkown
page read and write
clean
F50000
unkown
page read and write
clean
25C3000
unkown
page read and write
clean
449C000
unkown
page read and write
clean
43C0000
heap private
page read and write
clean
2AA0000
unkown
page read and write
clean
564000
heap private
page read and write
clean
2A00000
unkown
page read and write
clean
2130000
unkown image
page read and write
clean
4593000
unkown
page read and write
clean
4FAD000
unkown
page read and write
clean
382E000
unkown
page read and write
clean
17D000
unkown
page execute and read and write
clean
1E0000
unkown
page read and write
clean
460F000
unkown
page read and write
clean
6D40000
unkown
page read and write
clean
2971000
unkown
page execute and read and write
clean
5033000
unkown
page read and write
clean
694B000
unkown
page read and write
clean
36F000
unkown
page read and write
clean
8392000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
1000000
unkown image
page readonly
clean
6E50000
heap private
page read and write
clean
1FD0000
unkown image
page readonly
clean
1000000
unkown image
page readonly
clean
34E000
unkown
page read and write
clean
4D50000
unkown image
page readonly
clean
3278000
unkown
page read and write
clean
255000
heap default
page read and write
clean
4300000
unkown
page read and write
clean
D10000
unkown
page read and write
clean
20B6000
unkown
page read and write
clean
55F000
unkown
page read and write
clean
74B0000
heap private
page read and write
clean
A00000
unkown
page read and write
clean
7839000
unkown
page read and write
clean
6C72000
unkown
page read and write
clean
7B4000
heap default
page read and write
clean
230000
unkown
page read and write
clean
30E000
unkown
page read and write
clean
2520000
unkown
page read and write
clean
C50000
unkown
page read and write
clean
3DF8000
unkown
page read and write
clean
45CF000
unkown
page read and write
clean
799000
unkown
page read and write
clean
34E000
unkown
page read and write
clean
2A10000
unkown
page read and write
clean
2100000
unkown image
page readonly
clean
DA9000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
6914000
unkown
page read and write
clean
6E50000
heap private
page read and write
clean
1002000
unkown image
page execute read
clean
36F000
unkown
page read and write
clean
69E0000
unkown
page read and write
clean
B27000
unkown
page execute and read and write
clean
67E2000
unkown
page read and write
clean
800000
unkown image
page readonly
clean
6BBE000
unkown
page read and write
clean
4AF0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
230000
unkown
page read and write
clean
2A10000
unkown
page read and write
clean
1B50000
unkown
page read and write
clean
65B0000
unkown
page read and write
clean
4575000
unkown
page read and write
clean
3D40000
unkown
page read and write
clean
729A000
unkown
page read and write
clean
4F90000
unkown
page read and write
clean
2520000
unkown
page read and write
clean
B30000
unkown
page execute and read and write
clean
7CA000
heap default
page read and write
clean
2CC7000
unkown image
page readonly
clean
7839000
unkown
page read and write
clean
C50000
unkown
page read and write
clean
43C0000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
73BB000
unkown
page read and write
clean
20B6000
unkown
page read and write
clean
263C000
unkown
page read and write
clean
43A0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
32A9000
heap private
page read and write
clean
2A00000
unkown
page read and write
clean
6436000
unkown
page read and write
clean
7D20000
heap private
page read and write
clean
5360000
unkown image
page read and write
clean
32A5000
heap private
page read and write
clean
5B0000
unkown image
page readonly
clean
6717000
unkown
page read and write
clean
1E0000
unkown
page read and write
clean
32A0000
heap private
page read and write
clean
4AF0000
unkown image
page readonly
clean
19D000
unkown
page read and write
clean
3CA0000
unkown
page read and write
clean
65FF000
unkown
page read and write
clean
2C7000
heap default
page read and write
clean
250000
unkown
page read and write
clean
57E000
unkown
page read and write
clean
4FFD000
unkown
page read and write
clean
2667000
unkown
page read and write
clean
7BD0000
heap private
page read and write
clean
230000
heap default
page read and write
clean
97F2000
unkown
page read and write
clean
65F5000
unkown
page read and write
clean
5072000
unkown
page read and write
clean
33F000
unkown image
page execute and read and write
clean
9E0000
unkown
page read and write
clean
65E2000
unkown
page read and write
clean
D80000
unkown
page read and write
clean
20B6000
unkown
page read and write
clean
729A000
unkown
page read and write
clean
4450000
unkown
page read and write
clean
32A9000
heap private
page read and write
clean
213B000
unkown image
page read and write
clean
4BEE000
unkown
page read and write
clean
2A20000
unkown
page read and write
clean
6D2000
unkown image
page execute and read and write
clean
173000
unkown
page execute and read and write
clean
DA0000
unkown
page read and write
clean
2AA0000
unkown
page read and write
clean
5330000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2BFF000
unkown image
page read and write
clean
230000
unkown
page read and write
clean
8DC0000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
7B40000
unkown
page read and write
clean
8DDE000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
1470000
unkown image
page readonly
clean
2959000
unkown
page read and write
clean
D00000
unkown
page read and write
clean
1B83000
heap private
page read and write
clean
73B9000
unkown
page read and write
clean
4575000
unkown
page read and write
clean
7B4B000
unkown
page read and write
clean
E4000
heap private
page read and write
clean
2A10000
unkown
page read and write
clean
6DE4000
unkown
page read and write
clean
6340000
unkown
page read and write
clean
24F0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
4650000
unkown image
page readonly
clean
8FAE000
unkown
page read and write
clean
4DB1000
unkown image
page read and write
clean
609E000
unkown
page read and write
clean
301E000
unkown
page read and write
clean
5390000
heap private
page read and write
clean
30000
unkown image
page readonly
clean
30A8000
unkown
page read and write
clean
4150000
unkown image
page readonly
clean
66DB000
unkown
page read and write
clean
6A53000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
2750000
unkown
page read and write
clean
C50000
unkown
page read and write
clean
4593000
unkown
page read and write
clean
58A000
unkown
page read and write
clean
B20000
unkown
page execute and read and write
clean
2540000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
610E000
unkown
page read and write
clean
7F4E000
unkown
page read and write
clean
6E27000
unkown
page read and write
clean
31FF000
unkown
page read and write
clean
2646000
unkown
page read and write
clean
6620000
unkown
page read and write
clean
7FF0000
unkown image
page execute and read and write
clean
6492000
unkown
page read and write
clean
74B0000
heap private
page read and write
clean
24F0000
unkown image
page readonly
clean
220000
heap private
page read and write
clean
890000
unkown
page read and write
clean
B24000
unkown
page execute and read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
834B000
unkown
page read and write
clean
997000
unkown
page read and write
clean
C50000
unkown
page read and write
clean
652B000
unkown
page read and write
clean
2C7000
heap default
page read and write
clean
2570000
unkown
page read and write
clean
6C72000
unkown
page read and write
clean
2A00000
unkown
page read and write
clean
6C77000
unkown
page read and write
clean
630000
unkown
page read and write
clean
70D000
unkown
page read and write
clean
4300000
unkown
page read and write
clean
72CA000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
36F000
unkown
page read and write
clean
4450000
unkown
page read and write
clean
237000
heap default
page read and write
clean
77BE000
unkown
page read and write
clean
3D40000
unkown
page read and write
clean
2110000
unkown image
page read and write
clean
6758000
unkown
page read and write
clean
61C0000
unkown
page read and write
clean
1000000
unkown image
page readonly
clean
240000
heap private
page read and write
clean
5B0000
unkown image
page readonly
clean
F0000
unkown image
page read and write
clean
9B0000
unkown
page read and write
clean
4D60000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
12E0000
unkown image
page readonly
clean
9A95000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
230000
unkown
page read and write
clean
3CA0000
unkown
page read and write
clean
9A95000
heap private
page read and write
clean
1FD0000
unkown image
page readonly
clean
2120000
unkown image
page read and write
clean
330000
unkown
page read and write
clean
4650000
unkown image
page readonly
clean
6A5B000
unkown
page read and write
clean
59F000
unkown
page read and write
clean
69E9000
unkown
page read and write
clean
21BF000
unkown
page read and write
clean
30C0000
unkown
page read and write
clean
237000
heap default
page read and write
clean
32AE000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
212B000
unkown image
page read and write
clean
C30000
unkown
page read and write
clean
32A0000
heap private
page read and write
clean
A50000
unkown
page execute and read and write
clean
3145000
heap private
page read and write
clean
2646000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
4F4000
unkown
page read and write
clean
30EF000
unkown image
page read and write
clean
21BF000
unkown
page read and write
clean
3270000
unkown
page read and write
clean
C9D000
unkown
page read and write
clean
4FFC000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
8355000
unkown
page read and write
clean
44E7000
unkown
page read and write
clean
31FF000
unkown
page read and write
clean
211B000
unkown image
page read and write
clean
30E0000
unkown image
page readonly
clean
32A5000
heap private
page read and write
clean
454000
heap default
page read and write
clean
D70000
unkown image
page read and write
clean
750000
unkown image
page readonly
clean
CA0000
unkown
page read and write
clean
45A1000
unkown
page read and write
clean
44E7000
unkown
page read and write
clean
6202000
unkown
page read and write
clean
45A1000
unkown
page read and write
clean
610A000
unkown
page read and write
clean
4DC0000
unkown
page read and write
clean
636F000
unkown
page read and write
clean
32A9000
heap private
page read and write
clean
6D48000
unkown
page read and write
clean
E6F000
unkown
page read and write
clean
810000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
6E60000
unkown
page read and write
clean
3D90000
unkown
page read and write
clean
29E0000
unkown
page read and write
clean
29F0000
unkown
page execute and read and write
clean
2120000
unkown image
page read and write
clean
330000
unkown
page read and write
clean
5056000
unkown
page read and write
clean
7B50000
heap private
page read and write
clean
1B83000
heap private
page read and write
clean
3D50000
unkown
page read and write
clean
197000
unkown
page execute and read and write
clean
D0000
unkown image
page readonly
clean
5410000
heap private
page read and write
clean
80A2000
unkown image
page execute and read and write
clean
65FB000
unkown
page read and write
clean
603B000
unkown
page read and write
clean
6567000
unkown
page read and write
clean
B10000
heap private
page read and write
clean
74BB000
unkown
page read and write
clean
589000
unkown
page read and write
clean
29B000
heap default
page read and write
clean
9AB3000
heap private
page read and write
clean
25C3000
unkown
page read and write
clean
4D70000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
570000
heap default
page read and write
clean
7D20000
heap private
page read and write
clean
A00000
unkown
page read and write
clean
457A000
unkown
page read and write
clean
608F000
unkown
page read and write
clean
650A000
unkown
page read and write
clean
CA0000
unkown
page read and write
clean
45BF000
unkown
page read and write
clean
110000
unkown
page read and write
clean
23D000
heap default
page read and write
clean
642F000
unkown
page read and write
clean
6375000
unkown
page read and write
clean
C42000
unkown
page read and write
clean
80A2000
unkown image
page execute and read and write
clean
30D0000
unkown image
page readonly
clean
1B83000
heap private
page read and write
clean
36B000
unkown
page read and write
clean
2110000
unkown image
page read and write
clean
6C72000
unkown
page read and write
clean
2700000
unkown
page execute and read and write
clean
2A60000
unkown
page read and write
clean
74D3000
unkown
page read and write
clean
2AE0000
unkown image
page readonly
clean
2661000
unkown
page read and write
clean
1CC000
unkown
page read and write
clean
249000
heap default
page read and write
clean
3CC0000
unkown image
page readonly
clean
7BD0000
heap private
page read and write
clean
57E000
unkown
page read and write
clean
4D80000
unkown image
page readonly
clean
6556000
unkown
page read and write
clean
2A70000
unkown
page read and write
clean
E0000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
34B1000
unkown
page read and write
clean
2977000
unkown
page execute and read and write
clean
62E5000
unkown
page read and write
clean
230000
unkown
page read and write
clean
BA0000
unkown
page execute and read and write
clean
6E0A000
unkown
page read and write
clean
79BB000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
E4000
heap private
page read and write
clean
2110000
unkown image
page read and write
clean
73BB000
unkown
page read and write
clean
4DB1000
unkown image
page read and write
clean
7EFB0000
unkown image
page readonly
clean
263C000
unkown
page read and write
clean
8DC0000
unkown
page read and write
clean
3D40000
unkown
page read and write
clean
645F000
unkown
page read and write
clean
69C8000
unkown
page read and write
clean
4C70000
heap private
page read and write
clean
110000
unkown
page read and write
clean
D70000
unkown
page read and write
clean
30F0000
unkown image
page readonly
clean
1C0000
heap default
page read and write
clean
698E000
unkown
page read and write
clean
74C1000
unkown
page read and write
clean
5390000
heap private
page read and write
clean
4160000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
7B50000
heap private
page read and write
clean
530000
heap default
page read and write
clean
30000
unkown image
page read and write
clean
27E0000
unkown
page read and write
clean
7D20000
heap private
page read and write
clean
F20000
unkown
page read and write
clean
45BF000
unkown
page read and write
clean
230000
unkown
page read and write
clean
420000
unkown
page execute and read and write
clean
1D7000
unkown
page read and write
clean
96F3000
unkown
page read and write
clean
3D50000
unkown
page read and write
clean
1CE000
unkown
page read and write
clean
843B000
unkown
page read and write
clean
6021000
unkown
page read and write
clean
2959000
unkown
page read and write
clean
4FFC000
unkown
page read and write
clean
1002000
unkown image
page execute read
clean
2130000
unkown image
page read and write
clean
2AB0000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
4E4000
heap default
page read and write
clean
81AE000
unkown
page read and write
clean
2A90000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
8400000
unkown
page read and write
clean
9774000
unkown
page read and write
clean
6527000
unkown
page read and write
clean
70A000
unkown
page read and write
clean
80A2000
unkown image
page execute and read and write
clean
30F0000
unkown image
page readonly
clean
83D8000
unkown
page read and write
clean
980000
unkown
page read and write
clean
230000
heap default
page read and write
clean
7FF0000
unkown image
page execute and read and write
clean
3D50000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
16C000
unkown
page read and write
clean
1FD0000
unkown image
page readonly
clean
9B0000
unkown
page execute and read and write
clean
2A40000
unkown
page read and write
clean
3DF8000
unkown
page read and write
clean
79F0000
heap private
page read and write
clean
5270000
unkown
page execute read
clean
BB0000
unkown
page execute and read and write
clean
192000
unkown
page read and write
clean
4593000
unkown
page read and write
clean
7839000
unkown
page read and write
clean
73B9000
unkown
page read and write
clean
71F0000
unkown
page read and write
clean
63D4000
unkown
page read and write
clean
4160000
unkown
page read and write
clean
4450000
unkown
page read and write
clean
4308000
unkown
page read and write
clean
6347000
unkown
page read and write
clean
29B000
heap default
page read and write
clean
73B9000
unkown
page read and write
clean
3CC0000
unkown image
page readonly
clean
694E000
unkown
page read and write
clean
2500000
unkown image
page readonly
clean
60A3000
unkown
page read and write
clean
647C000
unkown
page read and write
clean
36B000
unkown
page read and write
clean
83D8000
unkown
page read and write
clean
2A06000
unkown image
page read and write
clean
2C7000
heap default
page read and write
clean
1BE0000
unkown image
page readonly
clean
4D30000
unkown image
page readonly
clean
6D48000
unkown
page read and write
clean
8400000
unkown
page read and write
clean
43C0000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
4D80000
unkown image
page readonly
clean
9830000
unkown
page read and write
clean
6A28000
unkown
page read and write
clean
4150000
unkown image
page readonly
clean
2550000
unkown
page read and write
clean
7149000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
3130000
unkown image
page readonly
clean
4D70000
unkown image
page readonly
clean
1000000
unkown image
page readonly
clean
2750000
unkown
page read and write
clean
B10000
unkown
page execute and read and write
clean
5E40000
unkown
page read and write
clean
220000
unkown image
page readonly
clean
5B0000
unkown image
page readonly
clean
5C0000
unkown image
page read and write
clean
2AB0000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
6170000
unkown
page read and write
clean
8720000
unkown
page read and write
clean
C30000
unkown
page read and write
clean
6B49000
unkown
page read and write
clean
3D4B000
unkown
page read and write
clean
633A000
unkown
page read and write
clean
3CC0000
unkown image
page readonly
clean
C40000
unkown
page read and write
clean
CC0000
heap private
page execute and read and write
clean
18D000
unkown
page execute and read and write
clean
9A90000
heap private
page read and write
clean
309E000
unkown
page read and write
clean
23D000
heap default
page read and write
clean
32A0000
heap private
page read and write
clean
5C0000
unkown image
page readonly
clean
1AB000
unkown
page execute and read and write
clean
47C000
heap default
page read and write
clean
44E7000
unkown
page read and write
clean
2750000
unkown
page read and write
clean
1B83000
heap private
page read and write
clean
2AE0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7CFE000
unkown
page read and write
clean
D20000
unkown
page read and write
clean
6C77000
unkown
page read and write
clean
744D000
unkown
page read and write
clean
4B00000
unkown image
page readonly
clean
263C000
unkown
page read and write
clean
3278000
unkown
page read and write
clean
3CA0000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
2A90000
unkown
page read and write
clean
6A0D000
unkown
page read and write
clean
3D4B000
unkown
page read and write
clean
D70000
unkown
page read and write
clean
2980000
unkown
page execute and read and write
clean
6C70000
unkown
page read and write
clean
E4000
heap private
page read and write
clean
E4000
heap private
page read and write
clean
230000
unkown
page read and write
clean
79F000
unkown
page read and write
clean
45CB000
unkown
page read and write
clean
6516000
unkown
page read and write
clean
4160000
unkown
page read and write
clean
4AC0000
unkown
page read and write
clean
9830000
unkown
page read and write
clean
8DC0000
unkown
page read and write
clean
E00000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
6182000
unkown
page read and write
clean
74D3000
heap private
page read and write
clean
30D0000
unkown image
page readonly
clean
2A90000
unkown
page read and write
clean
2120000
unkown image
page read and write
clean
430000
unkown image
page readonly
clean
4DC0000
unkown
page read and write
clean
9F0000
unkown
page read and write
clean
D70000
unkown image
page readonly
clean
2A60000
unkown
page read and write
clean
9C0000
unkown
page read and write
clean
4C70000
heap private
page read and write
clean
1BE0000
unkown image
page readonly
clean
6A60000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
DB0000
unkown
page read and write
clean
4DB1000
unkown image
page read and write
clean
3270000
unkown
page read and write
clean
45CB000
unkown
page read and write
clean
140000
unkown image
page readonly
clean
255000
heap default
page read and write
clean
2F50000
unkown
page read and write
clean
66CC000
unkown
page read and write
clean
5C0000
unkown image
page readonly
clean
5250000
unkown
page read and write
clean
6998000
unkown
page read and write
clean
2FD000
heap default
page read and write
clean
237000
heap default
page read and write
clean
4308000
unkown
page read and write
clean
556F000
unkown
page read and write
clean
2C0000
heap default
page read and write
clean
24F0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
2670000
unkown
page read and write
clean
BCE000
unkown
page read and write
clean
29E0000
unkown
page read and write
clean
29D0000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
5C0000
unkown image
page readonly
clean
4150000
unkown image
page readonly
clean
30C0000
unkown
page read and write
clean
27E0000
unkown
page execute and read and write
clean
4D80000
unkown image
page readonly
clean
65A4000
unkown
page read and write
clean
782F000
unkown
page read and write
clean
2933000
unkown
page read and write
clean
6964000
unkown
page read and write
clean
655A000
unkown
page read and write
clean
C40000
unkown
page read and write
clean
45B4000
unkown
page read and write
clean
3D90000
unkown
page read and write
clean
9AB3000
heap private
page read and write
clean
10AA000
unkown image
page readonly
clean
2C7000
heap default
page read and write
clean
2960000
unkown
page execute and read and write
clean
7EFB2000
unkown image
page readonly
clean
69E9000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7E1E000
unkown
page read and write
clean
29E0000
unkown
page read and write
clean
4B00000
unkown image
page readonly
clean
7BD0000
heap private
page read and write
clean
5056000
unkown
page read and write
clean
62EA000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
540000
unkown image
page readonly
clean
4C7A000
heap private
page read and write
clean
4200000
unkown image
page readonly
clean
8720000
unkown
page read and write
clean
430000
unkown image
page readonly
clean
6C77000
unkown
page read and write
clean
74B6000
unkown
page read and write
clean
B50000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
32A0000
heap private
page read and write
clean
10AA000
unkown image
page readonly
clean
2A40000
unkown
page read and write
clean
4308000
unkown
page read and write
clean
7EE9000
unkown
page read and write
clean
A00000
unkown
page read and write
clean
5042000
unkown
page read and write
clean
A30000
unkown
page execute and read and write
clean
2646000
unkown
page read and write
clean
47A000
heap default
page read and write
clean
96F3000
unkown
page read and write
clean
2760000
heap private
page read and write
clean
2AB0000
unkown
page read and write
clean
74B0000
heap private
page read and write
clean
212B000
unkown image
page read and write
clean
28E0000
unkown
page read and write
clean
6E20000
unkown
page read and write
clean
371000
unkown
page read and write
clean
664A000
unkown
page read and write
clean
71FE000
unkown
page read and write
clean
2A90000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2550000
unkown
page read and write
clean
636D000
unkown
page read and write
clean
54D0000
heap private
page read and write
clean
4B00000
unkown image
page readonly
clean
F0000
unkown image
page read and write
clean
71F0000
unkown
page read and write
clean
2520000
unkown
page read and write
clean
1CE000
unkown
page read and write
clean
50F000
unkown
page read and write
clean
5E0000
unkown
page read and write
clean
DC0000
heap private
page execute and read and write
clean
6E71000
unkown
page read and write
clean
C30000
unkown
page read and write
clean
19A000
unkown
page execute and read and write
clean
2A50000
unkown
page read and write
clean
5410000
heap private
page read and write
clean
6A12000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
4E60000
unkown
page read and write
clean
4575000
unkown
page read and write
clean
27E0000
unkown
page read and write
clean
9B0000
unkown
page read and write
clean
A00000
unkown
page read and write
clean
6551000
unkown
page read and write
clean
43B0000
unkown image
page readonly
clean
7149000
unkown
page read and write
clean
80FE000
unkown
page read and write
clean
243000
heap default
page read and write
clean
447A000
unkown
page read and write
clean
160000
unkown
page read and write
clean
24F0000
unkown image
page readonly
clean
2AE0000
unkown image
page readonly
clean
27F4000
unkown
page execute and read and write
clean
E0000
heap private
page read and write
clean
5D0000
unkown
page read and write
clean
4DC0000
unkown
page read and write
clean
5086000
unkown
page read and write
clean
2650000
unkown
page read and write
clean
212B000
unkown image
page read and write
clean
D00000
unkown
page read and write
clean
843B000
unkown
page read and write
clean
2A10000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
1A0000
unkown
page read and write
clean
4308000
unkown
page read and write
clean
211B000
unkown image
page read and write
clean
341000
unkown image
page execute and read and write
clean
D13000
unkown
page read and write
clean
8320000
unkown
page read and write
clean
5D0000
unkown
page read and write
clean
4D30000
unkown image
page readonly
clean
5390000
heap private
page read and write
clean
7FF0000
unkown image
page execute and read and write
clean
940000
unkown
page execute and read and write
clean
6C70000
unkown
page read and write
clean
2959000
unkown
page read and write
clean
F0000
unkown image
page read and write
clean
F30000
unkown
page read and write
clean
F10000
unkown
page read and write
clean
530000
unkown
page read and write
clean
79BB000
unkown
page read and write
clean
31D000
heap default
page read and write
clean
9D0000
unkown
page read and write
clean
6C70000
unkown
page read and write
clean
6D40000
unkown
page read and write
clean
6A49000
unkown
page read and write
clean
2740000
unkown image
page readonly
clean
2974000
unkown
page execute and read and write
clean
30A8000
unkown
page read and write
clean
5B0000
unkown image
page readonly
clean
7B40000
unkown
page read and write
clean
1F0000
unkown
page execute and read and write
clean
4AAD000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
D2F000
unkown
page read and write
clean
2540000
unkown
page read and write
clean
4B9D000
unkown
page read and write
clean
2760000
heap private
page read and write
clean
71F7000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
4DD0000
heap private
page read and write
clean
7EFDF000
unkown
page read and write
clean
211B000
unkown image
page read and write
clean
834B000
unkown
page read and write
clean
4200000
unkown image
page readonly
clean
CB0000
unkown
page execute and read and write
clean
6373000
unkown
page read and write
clean
58E000
unkown
page read and write
clean
4E5E000
unkown
page read and write
clean
50AD000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
6BBE000
unkown
page read and write
clean
71F7000
unkown
page read and write
clean
7CFE000
unkown
page read and write
clean
744D000
unkown
page read and write
clean
3DF8000
unkown
page read and write
clean
1002000
unkown image
page execute read
clean
457A000
unkown
page read and write
clean
2A60000
unkown
page read and write
clean
D0000
unkown image
page readonly
clean
2A0000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
21BF000
unkown
page read and write
clean
2540000
unkown
page read and write
clean
8BBE000
unkown
page read and write
clean
630000
unkown
page read and write
clean
1E0000
unkown
page read and write
clean
456F000
unkown
page read and write
clean
4DC0000
unkown
page read and write
clean
1A2000
unkown
page read and write
clean
5360000
unkown image
page read and write
clean
81AE000
unkown
page read and write
clean
460B000
unkown
page read and write
clean
6A4B000
unkown
page read and write
clean
4FF8000
unkown
page read and write
clean
71F0000
unkown
page read and write
clean
230000
heap default
page read and write
clean
2A30000
unkown
page read and write
clean
2A70000
unkown
page read and write
clean
3130000
unkown image
page readonly
clean
69E9000
unkown
page read and write
clean
4DD0000
heap private
page read and write
clean
5E0000
unkown
page read and write
clean
330000
unkown image
page execute and read and write
clean
457A000
unkown
page read and write
clean
61D2000
unkown
page read and write
clean
A41000
unkown image
page execute and read and write
clean
D0000
unkown image
page readonly
clean
8355000
unkown
page read and write
clean
69D3000
unkown
page read and write
clean
330000
heap private
page read and write
clean
79BB000
unkown
page read and write
clean
B3F000
unkown
page read and write
clean
213B000
unkown image
page read and write
clean
7EFC0000
unkown image
page readonly
clean
25C3000
unkown
page read and write
clean
C50000
unkown
page read and write
clean
3130000
unkown image
page readonly
clean
23D000
heap default
page read and write
clean
2740000
unkown image
page readonly
clean
5072000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
27E0000
unkown
page read and write
clean
45A1000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
4AAD000
unkown
page read and write
clean
A00000
unkown image
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
554000
heap default
page read and write
clean
2533000
unkown
page read and write
clean
31D000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2A40000
unkown
page read and write
clean
43A0000
unkown image
page readonly
clean
616E000
unkown
page read and write
clean
243000
heap default
page read and write
clean
97F2000
unkown
page read and write
clean
728E000
unkown
page read and write
clean
5017000
unkown
page read and write
clean
5C0000
unkown
page read and write
clean
7EE9000
unkown
page read and write
clean
805F000
unkown
page read and write
clean
32D000
unkown
page read and write
clean
2EC1000
unkown
page read and write
clean
2533000
unkown
page read and write
clean
580000
unkown
page read and write
clean
7B40000
unkown
page read and write
clean
2933000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
449C000
unkown
page read and write
clean
140000
unkown image
page readonly
clean
26D0000
unkown
page read and write
clean
B8E000
unkown
page read and write
clean
29B000
heap default
page read and write
clean
340000
heap default
page read and write
clean
6BBE000
unkown
page read and write
clean
4D50000
unkown image
page readonly
clean
537000
heap default
page read and write
clean
4AF0000
unkown image
page readonly
clean
994000
unkown
page read and write
clean
10AA000
unkown image
page readonly
clean
1D7000
unkown
page read and write
clean
65A1000
unkown
page read and write
clean
7E1E000
unkown
page read and write
clean
7A0000
heap private
page read and write
clean
6602000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
E0000
heap private
page read and write
clean
8248000
unkown
page read and write
clean
6D48000
unkown
page read and write
clean
2740000
unkown image
page readonly
clean
70E000
unkown
page read and write
clean
659E000
unkown
page read and write
clean
447A000
unkown
page read and write
clean
26F0000
unkown
page execute and read and write
clean
620000
unkown image
page execute and read and write
clean
2A30000
unkown
page read and write
clean
8FAE000
unkown
page read and write
clean
6E35000
unkown
page read and write
clean
74D3000
heap private
page read and write
clean
8374000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
230000
unkown
page read and write
clean
7E1E000
unkown
page read and write
clean
744D000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
CA0000
unkown
page read and write
clean
6575000
unkown
page read and write
clean
2933000
unkown
page read and write
clean
6E50000
heap private
page read and write
clean
7DD000
heap default
page read and write
clean
8320000
unkown
page read and write
clean
5360000
unkown image
page read and write
clean
742C000
unkown
page read and write
clean
750000
unkown image
page readonly
clean
4B9D000
unkown
page read and write
clean
4AC0000
unkown
page read and write
clean
628E000
unkown
page read and write
clean
71F0000
unkown
page read and write
clean
5270000
unkown
page execute read
clean
D80000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
69DB000
unkown
page read and write
clean
CA4000
unkown
page execute and read and write
clean
36B000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
419000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
456F000
unkown
page read and write
clean
97F2000
unkown
page read and write
clean
9A0000
unkown
page read and write
clean
9A95000
heap private
page read and write
clean
74B0000
heap private
page read and write
clean
1B65000
heap private
page read and write
clean
8320000
unkown
page read and write
clean
58F000
unkown
page read and write
clean
5360000
unkown image
page read and write
clean
6BC5000
unkown
page read and write
clean
782F000
unkown
page read and write
clean
44E7000
unkown
page read and write
clean
A00000
unkown
page read and write
clean
782F000
unkown
page read and write
clean
457A000
unkown
page read and write
clean
2646000
unkown
page read and write
clean
5042000
unkown
page read and write
clean
2533000
unkown
page read and write
clean
2550000
unkown
page read and write
clean
8392000
unkown
page read and write
clean
45B4000
unkown
page read and write
clean
D10000
unkown
page execute and read and write
clean
5F2E000
unkown
page read and write
clean
C30000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
1B50000
unkown
page read and write
clean
F0000
unkown image
page read and write
clean
4E60000
unkown
page read and write
clean
4FF8000
unkown
page read and write
clean
2533000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2A80000
unkown
page read and write
clean
83D8000
unkown
page read and write
clean
7B4B000
unkown
page read and write
clean
348000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7CFE000
unkown
page read and write
clean
8374000
unkown
page read and write
clean
30B000
heap default
page read and write
clean
652E000
unkown
page read and write
clean
A3F000
unkown image
page execute and read and write
clean
590000
unkown
page read and write
clean
470000
heap default
page read and write
clean
49FE000
unkown
page read and write
clean
2FE000
unkown
page read and write
clean
2A20000
unkown
page read and write
clean
29D0000
unkown
page read and write
clean
4B9D000
unkown
page read and write
clean
6943000
unkown
page read and write
clean
9B0000
unkown
page read and write
clean
3270000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
584000
heap default
page read and write
clean
627A000
unkown
page read and write
clean
6311000
unkown
page read and write
clean
93F000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
5056000
unkown
page read and write
clean
31FF000
unkown
page read and write
clean
1000000
unkown image
page readonly
clean
25C3000
unkown
page read and write
clean
5086000
unkown
page read and write
clean
6708000
unkown
page read and write
clean
29A1000
unkown
page read and write
clean
797000
heap default
page read and write
clean
7EFC0000
unkown image
page readonly
clean
2100000
unkown image
page readonly
clean
622B000
unkown
page read and write
clean
1BE0000
unkown image
page readonly
clean
F9C000
unkown
page read and write
clean
77BE000
unkown
page read and write
clean
1CE000
unkown
page read and write
clean
6521000
unkown
page read and write
clean
680000
unkown image
page readonly
clean
2A60000
unkown
page read and write
clean
60F1000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
750000
unkown image
page readonly
clean
3C0000
unkown
page read and write
clean
8392000
unkown
page read and write
clean
4B00000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
2A70000
unkown
page read and write
clean
6318000
unkown
page read and write
clean
3145000
heap private
page read and write
clean
4AAD000
unkown
page read and write
clean
9AA000
unkown
page read and write
clean
2120000
unkown image
page read and write
clean
6A1D000
unkown
page read and write
clean
6C70000
unkown
page read and write
clean
6497000
unkown
page read and write
clean
54DB000
heap private
page read and write
clean
2959000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
790000
heap default
page read and write
clean
659C000
unkown
page read and write
clean
729A000
unkown
page read and write
clean
630000
unkown
page read and write
clean
5086000
unkown
page read and write
clean
8248000
unkown
page read and write
clean
9873000
unkown
page read and write
clean
3D90000
unkown
page read and write
clean
630000
unkown
page read and write
clean
2A30000
unkown
page read and write
clean
6EDF000
unkown
page read and write
clean
2870000
unkown
page execute and read and write
clean
2750000
unkown
page read and write
clean
3E50000
unkown image
page readonly
clean
36B000
unkown
page read and write
clean
9D0000
unkown
page read and write
clean
30D0000
unkown image
page readonly
clean
29C7000
unkown
page read and write
clean
65AE000
unkown
page read and write
clean
6D40000
unkown
page read and write
clean
4FD4000
unkown
page read and write
clean
6AFC000
unkown
page read and write
clean
5033000
unkown
page read and write
clean
D90000
unkown
page read and write
clean
2100000
unkown image
page readonly
clean
4C7A000
heap private
page read and write
clean
249000
heap default
page read and write
clean
650E000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
630A000
unkown
page read and write
clean
A30000
unkown image
page execute and read and write
clean
1002000
unkown image
page execute read
clean
32AE000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
580000
heap default
page read and write
clean
7B9000
heap default
page read and write
clean
74D3000
heap private
page read and write
clean
73BB000
unkown
page read and write
clean
460B000
unkown
page read and write
clean
6C72000
unkown
page read and write
clean
3E50000
unkown image
page readonly
clean
656E000
unkown
page read and write
clean
1D6000
unkown
page read and write
clean
43B0000
unkown image
page readonly
clean
5019000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
589000
heap default
page read and write
clean
F0E000
unkown
page read and write
clean
BD0000
heap private
page read and write
clean
2970000
unkown
page read and write
clean
6690000
unkown
page read and write
clean
45A1000
unkown
page read and write
clean
655D000
unkown
page read and write
clean
7B50000
heap private
page read and write
clean
67CE000
unkown
page read and write
clean
2A80000
unkown
page read and write
clean
20DA000
unkown
page read and write
clean
5270000
unkown
page execute read
clean
7EFB2000
unkown image
page readonly
clean
6962000
unkown
page read and write
clean
2AE0000
unkown image
page readonly
clean
69E0000
unkown
page read and write
clean
3D4B000
unkown
page read and write
clean
640000
heap private
page execute and read and write
clean
FA0000
unkown
page execute and read and write
clean
2CC7000
unkown image
page readonly
clean
30C0000
unkown
page read and write
clean
4E5E000
unkown
page read and write
clean
30A8000
unkown
page read and write
clean
79BB000
unkown
page read and write
clean
180000
unkown
page read and write
clean
4300000
unkown
page read and write
clean
1A5000
unkown
page execute and read and write
clean
D0000
unkown image
page readonly
clean
2860000
unkown
page execute and read and write
clean
3C90000
unkown image
page read and write
clean
7B40000
unkown
page read and write
clean
220000
unkown image
page readonly
clean
2560000
unkown
page read and write
clean
DB000
unkown
page read and write
clean
69A6000
unkown
page read and write
clean
6529000
unkown
page read and write
clean
A20000
unkown
page execute and read and write
clean
CB0000
unkown
page read and write
clean
2800000
unkown
page execute and read and write
clean
2A50000
unkown
page read and write
clean
4200000
unkown image
page readonly
clean
2F50000
unkown
page read and write
clean
20DA000
unkown
page read and write
clean
6D40000
unkown
page read and write
clean
1E0000
unkown
page read and write
clean
45B4000
unkown
page read and write
clean
5270000
unkown
page execute read
clean
2AB0000
unkown
page read and write
clean
6A07000
unkown
page read and write
clean
30F0000
unkown image
page readonly
clean
6659000
unkown
page read and write
clean
1FD0000
unkown image
page readonly
clean
174000
unkown
page read and write
clean
237000
heap default
page read and write
clean
81AE000
unkown
page read and write
clean
74B4000
heap private
page read and write
clean
63AD000
unkown
page read and write
clean
1B65000
heap private
page read and write
clean
9E0000
unkown
page read and write
clean
449C000
unkown
page read and write
clean
27E0000
unkown
page read and write
clean
4D40000
unkown image
page readonly
clean
6C77000
unkown
page read and write
clean
7EE9000
unkown
page read and write
clean
9873000
unkown
page read and write
clean
2A50000
unkown
page read and write
clean
4B9D000
unkown
page read and write
clean
2EC1000
unkown
page read and write
clean
2500000
unkown image
page readonly
clean
7B4B000
unkown
page read and write
clean
4200000
unkown image
page readonly
clean
7E4E000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
6424000
unkown
page read and write
clean
D0B000
unkown
page read and write
clean
3130000
unkown image
page readonly
clean
4D50000
unkown image
page readonly
clean
8400000
unkown
page read and write
clean
74D7000
unkown
page read and write
clean
590000
unkown
page read and write
clean
F40000
unkown
page read and write
clean
140000
unkown image
page readonly
clean
744D000
unkown
page read and write
clean
647E000
unkown
page read and write
clean
69E0000
unkown
page read and write
clean
532E000
unkown
page read and write
clean
212B000
unkown image
page read and write
clean
6D36000
unkown
page read and write
clean
6220000
unkown
page read and write
clean
4C70000
heap private
page read and write
clean
20B6000
unkown
page read and write
clean
7EE9000
unkown
page read and write
clean
12DF000
unkown
page read and write
clean
280000
unkown
page execute and read and write
clean
7149000
unkown
page read and write
clean
45CB000
unkown
page read and write
clean
4575000
unkown
page read and write
clean
D20000
unkown
page read and write
clean
5B0000
unkown image
page readonly
clean
DB0000
unkown
page read and write
clean
834B000
unkown
page read and write
clean
6490000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
110000
unkown
page read and write
clean
3298000
unkown
page read and write
clean
301E000
unkown
page read and write
clean
400000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
782F000
unkown
page read and write
clean
E0000
heap private
page read and write
clean
630C000
unkown
page read and write
clean
4D40000
unkown image
page readonly
clean
213B000
unkown image
page read and write
clean
8400000
unkown
page read and write
clean
5034000
unkown
page read and write
clean
460B000
unkown
page read and write
clean
FC0000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
1A7000
unkown
page execute and read and write
clean
2A20000
unkown
page read and write
clean
C50000
unkown
page read and write
clean
4D30000
unkown image
page readonly
clean
79F0000
heap private
page read and write
clean
96F3000
unkown
page read and write
clean
44B0000
unkown image
page read and write
clean
4AF0000
unkown image
page readonly
clean
4300000
unkown
page read and write
clean
230000
unkown
page read and write
clean
30E0000
unkown image
page readonly
clean
2AA0000
unkown
page read and write
clean
61BE000
unkown
page read and write
clean
29E0000
unkown
page read and write
clean
140000
unkown image
page readonly
clean
81AE000
unkown
page read and write
clean
69A4000
unkown
page read and write
clean
5409000
unkown
page read and write
clean
4D60000
unkown image
page readonly
clean
73B9000
unkown
page read and write
clean
A41000
unkown image
page execute and read and write
clean
211B000
unkown image
page read and write
clean
4DB1000
unkown image
page read and write
clean
1B60000
heap private
page read and write
clean
2740000
unkown image
page readonly
clean
4160000
unkown
page read and write
clean
69E9000
unkown
page read and write
clean
45CB000
unkown
page read and write
clean
29F0000
unkown
page read and write
clean
27F0000
unkown
page execute and read and write
clean
532E000
unkown
page read and write
clean
34E000
unkown
page read and write
clean
20DA000
unkown
page read and write
clean
28E0000
unkown
page read and write
clean
2540000
unkown
page read and write
clean
301E000
unkown
page read and write
clean
556F000
unkown
page read and write
clean
9A0000
unkown
page read and write
clean
6020000
unkown
page read and write
clean
8355000
unkown
page read and write
clean
3D90000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7CFE000
unkown
page read and write
clean
7D20000
heap private
page read and write
clean
230000
unkown
page read and write
clean
45CF000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
4D40000
unkown image
page readonly
clean
5390000
heap private
page read and write
clean
4E5E000
unkown
page read and write
clean
3298000
unkown
page read and write
clean
3298000
unkown
page read and write
clean
CA0000
unkown
page read and write
clean
65E9000
unkown
page read and write
clean
3145000
heap private
page read and write
clean
29D0000
unkown
page read and write
clean
2EC1000
unkown
page read and write
clean
2CC7000
unkown image
page readonly
clean
8720000
unkown
page read and write
clean
4A50000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
9730000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
2760000
heap private
page read and write
clean
4650000
unkown image
page readonly
clean
20000
unkown
page read and write
clean
79F0000
heap private
page read and write
clean
30D0000
unkown image
page readonly
clean
1CE000
unkown
page read and write
clean
249000
heap default
page read and write
clean
4AC0000
unkown
page read and write
clean
1460000
unkown image
page readonly
clean
1B60000
heap private
page read and write
clean
8248000
unkown
page read and write
clean
4AAD000
unkown
page read and write
clean
8392000
unkown
page read and write
clean
20DA000
unkown
page read and write
clean
6788000
unkown
page read and write
clean
110000
unkown
page read and write
clean
728E000
unkown
page read and write
clean
FCC000
heap private
page read and write
clean
532E000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
4650000
unkown image
page readonly
clean
3C90000
unkown image
page read and write
clean
7EFD0000
unkown image
page readonly
clean
3278000
unkown
page read and write
clean
29D0000
unkown
page read and write
clean
32A9000
heap private
page read and write
clean
5410000
heap private
page read and write
clean
3140000
heap private
page read and write
clean
589000
unkown
page read and write
clean
301E000
unkown
page read and write
clean
4D40000
unkown image
page readonly
clean
309E000
unkown
page read and write
clean
255000
heap default
page read and write
clean
7B0000
unkown image
page readonly
clean
3DD000
unkown
page read and write
clean
68BB000
unkown
page read and write
clean
5072000
unkown
page read and write
clean
69E0000
unkown
page read and write
clean
4D60000
unkown image
page readonly
clean
B0F000
unkown
page read and write
clean
449C000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7EFB0000
unkown image
page readonly
clean
4E60000
unkown
page read and write
clean
3D50000
unkown
page read and write
clean
B0E000
unkown
page read and write | page guard
clean
65DF000
unkown
page read and write
clean
371000
unkown
page read and write
clean
2A20000
unkown
page read and write
clean
230000
unkown
page read and write
clean
8374000
unkown
page read and write
clean
9830000
unkown
page read and write
clean
447A000
unkown
page read and write
clean
27F7000
unkown
page execute and read and write
clean
243000
heap default
page read and write
clean
B2E000
unkown
page read and write
clean
32AE000
heap private
page read and write
clean
6985000
unkown
page read and write
clean
2550000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
991000
unkown
page read and write
clean
29E0000
unkown
page execute and read and write
clean
6BBE000
unkown
page read and write
clean
6315000
unkown
page read and write
clean
5FDE000
unkown
page read and write
clean
56A000
heap default
page read and write
clean
309E000
unkown
page read and write
clean
729A000
unkown
page read and write
clean
63A6000
unkown
page read and write
clean
4D70000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
8248000
unkown
page read and write
clean
309E000
unkown
page read and write
clean
6A51000
unkown
page read and write
clean
850E000
unkown
page read and write
clean
556F000
unkown
page read and write
clean
8320000
unkown
page read and write
clean
29B000
heap default
page read and write
clean
220000
unkown image
page readonly
clean
6B85000
unkown
page read and write
clean
805E000
unkown
page read and write | page guard
clean
7EFB0000
unkown image
page readonly
clean
2500000
unkown image
page readonly
clean
2A40000
unkown
page read and write
clean
65B7000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
2880000
unkown
page execute and read and write
clean
9AB3000
heap private
page read and write
clean
60DE000
unkown
page read and write
clean
83D8000
unkown
page read and write
clean
243000
heap default
page read and write
clean
4DD0000
heap private
page read and write
clean
3270000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
62C9000
unkown
page read and write
clean
4DD0000
heap private
page read and write
clean
7B50000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
30E0000
unkown image
page readonly
clean
4D20000
unkown
page execute and read and write
clean
1E0000
unkown
page read and write
clean
29F0000
unkown
page read and write
clean
32A5000
heap private
page read and write
clean
3E50000
unkown image
page readonly
clean
9A90000
heap private
page read and write
clean
2100000
unkown image
page readonly
clean
3278000
unkown
page read and write
clean
4D20000
unkown
page execute and read and write
clean
4593000
unkown
page read and write
clean
65B5000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
9A90000
heap private
page read and write
clean
D90000
unkown
page read and write
clean
1B65000
heap private
page read and write
clean
CB0000
unkown
page read and write
clean
456F000
unkown
page read and write
clean
4D60000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
65E7000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
3298000
unkown
page read and write
clean
6570000
unkown
page read and write
clean
5017000
unkown
page read and write
clean
DA0000
unkown
page read and write
clean
2F20000
unkown
page read and write
clean
74B4000
heap private
page read and write
clean
54D4000
heap private
page read and write
clean
F10000
heap private
page read and write
clean
8DDE000
unkown
page read and write
clean
263C000
unkown
page read and write
clean
6A15000
unkown
page read and write
clean
2A80000
unkown
page read and write
clean
4AC0000
unkown
page read and write
clean
2A00000
unkown
page read and write
clean
4A72000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
9774000
unkown
page read and write
clean
71F7000
unkown
page read and write
clean
65BC000
unkown
page read and write
clean
8A0000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
3D40000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
6A60000
heap private
page read and write
clean
3E50000
unkown image
page readonly
clean
10AA000
unkown image
page readonly
clean
4D30000
unkown image
page readonly
clean
45CF000
unkown
page read and write
clean
230000
heap default
page read and write
clean
6990000
unkown
page read and write
clean
79E000
unkown
page read and write
clean
930000
unkown image
page readonly
clean
213B000
unkown image
page read and write
clean
6598000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
9730000
unkown
page read and write
clean
63A0000
unkown
page read and write
clean
437000
heap default
page read and write
clean
6321000
unkown
page read and write
clean
1B65000
heap private
page read and write
clean
4A54000
heap private
page read and write
clean
31FF000
unkown
page read and write
clean
358000
unkown
page read and write
clean
C40000
unkown
page read and write
clean
6D48000
unkown
page read and write
clean
7BD0000
heap private
page read and write
clean
460B000
unkown
page read and write
clean
45B4000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
496000
heap default
page read and write
clean
32A5000
heap private
page read and write
clean
32AE000
heap private
page read and write
clean
3DF8000
unkown
page read and write
clean
43C0000
heap private
page read and write
clean
7839000
unkown
page read and write
clean
6745000
unkown
page read and write
clean
43B0000
unkown image
page readonly
clean
3D4B000
unkown
page read and write
clean
447A000
unkown
page read and write
clean
C50000
unkown
page read and write
clean
63D0000
unkown
page read and write
clean
71F7000
unkown
page read and write
clean
1B50000
unkown
page read and write
clean
4150000
unkown image
page readonly
clean
3C90000
unkown image
page read and write
clean
45CF000
unkown
page read and write
clean
4C7A000
heap private
page read and write
clean
623F000
unkown
page read and write
clean
43A0000
unkown image
page readonly
clean
5042000
unkown
page read and write
clean
30C0000
unkown
page read and write
clean
30A8000
unkown
page read and write
clean
4C70000
heap private
page read and write
clean
2EC1000
unkown
page read and write
clean
2F20000
unkown
page read and write
clean
6489000
unkown
page read and write
clean
45BF000
unkown
page read and write
clean
9730000
unkown
page read and write
clean
CA1000
unkown
page execute and read and write
clean
750000
unkown image
page readonly
clean
2130000
unkown image
page read and write
clean
330000
unkown
page read and write
clean
3CA0000
unkown
page read and write
clean
6955000
unkown
page read and write
clean
8BBE000
unkown
page read and write
clean
53B1000
unkown
page read and write
clean
532E000
unkown
page read and write
clean
371000
unkown
page read and write
clean
2A70000
unkown
page read and write
clean
4C7A000
heap private
page read and write
clean
4E60000
unkown
page read and write
clean
53B0000
unkown
page read and write
clean
4D20000
unkown
page execute and read and write
clean
1B60000
heap private
page read and write
clean
43A0000
unkown image
page readonly
clean
2A80000
unkown
page read and write
clean
410000
heap private
page read and write
clean
8DDE000
unkown
page read and write
clean
29F0000
unkown
page read and write
clean
255000
heap default
page read and write
clean
5B0000
unkown
page read and write
clean
6A0A000
unkown
page read and write
clean
31D000
heap default
page read and write
clean
3145000
heap private
page read and write
clean
8BBE000
unkown
page read and write
clean
77BE000
unkown
page read and write
clean
7149000
unkown
page read and write
clean
6E50000
heap private
page read and write
clean
843B000
unkown
page read and write
clean
9B0000
unkown
page read and write
clean
69E7000
unkown
page read and write
clean
79F0000
heap private
page read and write
clean
FD000
unkown
page read and write
clean
6A60000
heap private
page read and write
clean
5410000
heap private
page read and write
clean
30000
unkown image
page readonly
clean
D20000
unkown
page execute and read and write
clean
20000
unkown
page read and write
clean
371000
unkown
page read and write
clean
556F000
unkown
page read and write
clean
46F000
unkown
page read and write
clean
4450000
unkown
page read and write
clean
1000000
unkown image
page readonly
clean
C90000
unkown
page execute and read and write
clean
F10000
unkown
page read and write
clean
3140000
heap private
page read and write
clean
6344000
unkown
page read and write
clean
2520000
unkown
page read and write
clean
6A60000
heap private
page read and write
clean
220000
unkown image
page readonly
clean
643C000
unkown
page read and write
clean
180000
unkown
page read and write
clean
34E000
unkown
page read and write
clean
43B0000
unkown image
page readonly
clean
63AA000
unkown
page read and write
clean
58F000
unkown
page read and write
clean
74E2000
unkown
page read and write
clean
2664000
unkown
page read and write
clean
2C7000
heap default
page read and write
clean
60000
unkown image
page readonly
clean
6596000
unkown
page read and write
clean
6077000
unkown
page read and write
clean
5C0000
unkown image
page readonly
clean
728E000
unkown
page read and write
clean
8355000
unkown
page read and write
clean
23D000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7E1E000
unkown
page read and write
clean
79F000
unkown
page read and write
clean
A30000
unkown image
page execute and read and write
clean
4D50000
unkown image
page readonly
clean
73BB000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
3140000
heap private
page read and write
clean
6829000
unkown
page read and write
clean
1BE0000
unkown image
page readonly
clean
4E5E000
unkown
page read and write
clean
21BF000
unkown
page read and write
clean
2760000
heap private
page read and write
clean
54D8000
heap private
page read and write
clean
430000
unkown image
page readonly
clean
1B60000
heap private
page read and write
clean
2130000
unkown image
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2500000
unkown image
page readonly
clean
6A66000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
330000
unkown
page read and write
clean
430000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
834B000
unkown
page read and write
clean
30E0000
unkown image
page readonly
clean
1B50000
unkown
page read and write
clean
62CC000
unkown
page read and write
clean
430000
heap default
page read and write
clean
6BEA000
unkown
page read and write
clean
669E000
unkown
page read and write
clean
74B4000
heap private
page read and write
clean
74F000
unkown
page read and write
clean
A3F000
unkown image
page execute and read and write
clean
560000
heap private
page read and write
clean
728E000
unkown
page read and write
clean
9873000
unkown
page read and write
clean
There are 1493 hidden memdumps, click here to show them.