IOC Report

loading gif

Files

File Path
Type
Category
Malicious
OBL PN210700369.doc
Rich Text Format data, unknown version
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\obinnazx[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Roaming\obinnamaxdw2962.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{889F468E-8515-4A9A-AC98-AE12DF1E51F6}.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{A9A4A70D-764F-4C80-824C-4FCC7297AA70}.tmp
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\OBL PN210700369.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Mon Aug 30 20:08:56 2021, mtime=Mon Aug 30 20:08:56 2021, atime=Mon Sep 27 21:20:18 2021, length=15364, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
dropped
clean
C:\Users\user\Desktop\~$L PN210700369.doc
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
malicious
C:\Users\user\AppData\Roaming\obinnamaxdw2962.exe
C:\Users\user\AppData\Roaming\obinnamaxdw2962.exe
malicious
C:\Users\user\AppData\Roaming\obinnamaxdw2962.exe
C:\Users\user\AppData\Roaming\obinnamaxdw2962.exe
malicious
C:\Windows\explorer.exe
C:\Windows\Explorer.EXE
malicious
C:\Windows\SysWOW64\cmmon32.exe
C:\Windows\SysWOW64\cmmon32.exe
malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
'C:\Program Files\Microsoft Office\Office14\WINWORD.EXE' /Automation -Embedding
clean
C:\Windows\SysWOW64\cmd.exe
/c del 'C:\Users\user\AppData\Roaming\obinnamaxdw2962.exe'
clean

URLs

Name
IP
Malicious
http://lg-tv.tk/obinnazx.exe
185.239.243.112
malicious
www.vaughnmethod.com/ed9s/
malicious
http://www.islamic-coins.com/ed9s/?tXNH2v=aXG8CVn8ddSLaR&ydudnHn=k2ojovXzPk6QP2E57heACoDYW6OrA9sZh3WmhaFm9atosFE1d0WL15gHEPMcVErHBLYJUA==
2.57.140.50
malicious
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.msn.com/de-de/?ocid=iehp#
unknown
clean
http://wellformedweb.org/CommentAPI/
unknown
clean
http://www.rspb.org.uk/wildlife/birdguide/name/
unknown
clean
https://contextual.media.net/medianet.php?cid=8CUT39MWR&crid=715624197&size=306x271&https=1
unknown
clean
http://www.iis.fhg.de/audioPA
unknown
clean
https://contextual.media.net/medianet.php?cid=8CUT39MWR&crid=715624197&size=306x271&https=1LMEM
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://treyresearch.net
unknown
clean
https://contextual.media.net/checksync.php?&vsSync=1&cs=1&hb=1&cv=37&ndec=1&cid=8HBSKZM1Y&prvid=77%2
unknown
clean
https://contextual.media.net/medianet.php?cid=8CUT39MWR&crid=715624197&size=306x271&https=1b
unknown
clean
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://java.sun.com
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://www.piriform.com/ccleanerhttp://www.piriform.com/ccleanerv
unknown
clean
http://investor.msn.com/
unknown
clean
http://www.msn.com/?ocid=iehp
unknown
clean
http://www.msn.com/de-de/?ocid=iehp
unknown
clean
http://www.piriform.com/ccleaner
unknown
clean
http://computername/printers/printername/.printer
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.autoitscript.com/autoit3
unknown
clean
http://www.msn.com/?ocid=iehped2
unknown
clean
https://contextual.media.net/medianet.php?cid=8CUT39MWR&crid=715624197&size=306x271&https=1J
unknown
clean
https://support.mozilla.org
unknown
clean
http://www.piriform.com/ccleanerv
unknown
clean
http://servername/isapibackend.dll
unknown
clean
There are 24 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
lg-tv.tk
185.239.243.112
malicious
www.islamic-coins.com
2.57.140.50
malicious

IPs

IP
Domain
Country
Malicious
2.57.140.50
www.islamic-coins.com
France
malicious
185.239.243.112
lg-tv.tk
Moldova Republic of
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
l!)
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
##)
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
g$)
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\2F2A8
2F2A8
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Arial Unicode MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Batang
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@BatangChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DFKai-SB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Dotum
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DotumChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@FangSong
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gulim
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GulimChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gungsuh
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GungsuhChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@KaiTi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Malgun Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft JhengHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft YaHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Mincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PGothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PMincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS UI Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@NSimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Agency FB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aharoni
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Algerian
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Andalus
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Angsana New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
AngsanaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aparajita
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arabic Typesetting
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Black
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Narrow
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Rounded MT Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Unicode MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Baskerville Old Face
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Batang
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BatangChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bauhaus 93
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bell MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB Demi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bernard MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Blackadder ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Black
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Poster Compressed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Book Antiqua
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookman Old Style
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookshelf Symbol 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bradley Hand ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Britannic Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Broadway
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Browallia New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BrowalliaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Brush Script MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Californian FB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calisto MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria Math
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Candara
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Castellar
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Centaur
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Schoolbook
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Chiller
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Colonna MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Comic Sans MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Consolas
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Constantia
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cooper Black
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Corbel
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cordia New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
CordiaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Courier New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Curlz MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DaunPenh
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
David
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DFKai-SB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DilleniaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DokChampa
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Dotum
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DotumChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ebrima
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Edwardian Script ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Elephant
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Engravers MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Bold ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Demi ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Light ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Medium ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Estrangelo Edessa
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
EucrosiaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Euphemia
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FangSong
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Felix Titling
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Footlight MT Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Forte
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Book
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi Cond
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Heavy
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium Cond
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FrankRuehl
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FreesiaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Freestyle Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
French Script MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gabriola
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Garamond
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gautami
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Georgia
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gigi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Ext Condensed Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gisha
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gloucester MT Extra Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Old Style
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Stout
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gulim
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GulimChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gungsuh
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GungsuhChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Haettenschweiler
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harlow Solid Italic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harrington
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
High Tower Text
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Impact
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Imprint MT Shadow
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Informal Roman
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
IrisUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Iskoola Pota
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
JasmineUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Jokerman
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Juice ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KaiTi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kalinga
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kartika
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Khmer UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KodchiangUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kokila
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kristen ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kunstler Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lao UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Latha
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Leelawadee
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Levenim MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
LilyUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Bright
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Calligraphy
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Console
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Fax
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Handwriting
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Typewriter
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Unicode
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Magneto
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Maiandra GD
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Malgun Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mangal
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Marlett
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Matura MT Script Capitals
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Himalaya
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft JhengHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft New Tai Lue
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft PhagsPa
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Sans Serif
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Tai Le
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Uighur
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft YaHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Yi Baiti
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam Fixed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mistral
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Modern No. 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mongolian Baiti
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Monotype Corsiva
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MoolBoran
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Mincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Outlook
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PGothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PMincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Sans Serif
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Specialty
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS UI Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MT Extra
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MV Boli
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Narkisim
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Engraved
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Solid
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
NSimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Nyala
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
OCR A Extended
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Old English Text MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Onyx
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palace Script MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palatino Linotype
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Papyrus
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Parchment
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua Titling MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Plantagenet Cherokee
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Playbill
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Poor Richard
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Pristina
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Raavi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rage Italic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ravie
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Extra Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rod
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sakkal Majalla
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Script MT Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Print
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Semibold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Symbol
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shonar Bangla
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Showcard Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shruti
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic Fixed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Snap ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Stencil
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sylfaen
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Symbol
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tahoma
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tempus Sans ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Times New Roman
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Traditional Arabic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Trebuchet MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tunga
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed Extra Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Utsaah
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vani
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Verdana
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vijaya
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Viner Hand ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vivaldi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vladimir Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vrinda
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Webdings
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wide Latin
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\36519
36519
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
WORDFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\36519
36519
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Data
Settings
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Options
ZoomApp
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTF
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTA
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
EquationEditorFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus
FontCachePath
clean
There are 314 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
400000
unkown
page execute and read and write
malicious
21D1000
unkown
page read and write
malicious
2F0000
unkown image
page execute and read and write
malicious
31D1000
unkown
page read and write
malicious
F0000
unkown image
page execute and read and write
malicious
240000
unkown image
page execute and read and write
malicious
9A6D000
unkown image
page execute and read and write
malicious
80000
unkown image
page execute and read and write
malicious
9A6D000
unkown image
page execute and read and write
malicious
2233000
unkown
page read and write
malicious
380000
unkown
page read and write
malicious
9480000
heap private
page read and write
clean
6A8B000
unkown
page read and write
clean
26D000
unkown
page read and write
clean
216F000
unkown
page read and write
clean
1E0000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
29B000
heap default
page read and write
clean
2AA0000
unkown
page read and write
clean
44E7000
unkown
page read and write
clean
4650000
unkown image
page readonly
clean
66E3000
unkown
page read and write
clean
7D20000
heap private
page read and write
clean
449C000
unkown
page read and write
clean
377000
heap default
page read and write
clean
20000
unkown image
page readonly
clean
1B60000
heap private
page read and write
clean
4AC0000
unkown
page read and write
clean
8412000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
45CB000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
9864000
unkown
page read and write
clean
D0000
unkown image
page readonly
clean
3FC000
unkown
page read and write
clean
4B0000
unkown
page read and write
clean
110000
unkown
page read and write
clean
91A0000
unkown
page read and write
clean
4D20000
unkown
page execute and read and write
clean
B11000
unkown
page read and write
clean
45D6000
unkown
page read and write
clean
2A00000
unkown
page read and write
clean
2A00000
unkown
page read and write
clean
43C0000
heap private
page read and write
clean
5D0000
unkown
page read and write
clean
29D0000
unkown
page read and write
clean
4D20000
unkown
page execute and read and write
clean
301E000
unkown
page read and write
clean
1C7000
heap default
page read and write
clean
27E0000
unkown
page read and write
clean
6A0000
unkown image
page execute and read and write
clean
A90000
unkown image
page execute read
clean
73CE000
unkown
page read and write
clean
91A0000
unkown
page read and write
clean
430000
unkown image
page readonly
clean
6B32000
unkown
page read and write
clean
7E1E000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
5E0000
unkown
page read and write
clean
2180000
unkown
page read and write
clean
6A17000
unkown
page read and write
clean
6D40000
unkown
page read and write
clean
A90000
unkown image
page execute read
clean
2A10000
unkown
page read and write
clean
6860000
unkown
page read and write
clean
2D7000
unkown
page read and write
clean
662F000
unkown
page read and write
clean
430000
unkown image
page readonly
clean
20C000
unkown
page read and write
clean
1B60000
heap private
page read and write
clean
728E000
unkown
page read and write
clean
81AE000
unkown
page read and write
clean
29B000
heap default
page read and write
clean
4AF0000
unkown image
page readonly
clean
657D000
unkown
page read and write
clean
744D000
unkown
page read and write
clean
4200000
unkown image
page readonly
clean
5DF000
unkown
page read and write
clean
6247000
unkown
page read and write
clean
45CF000
unkown
page read and write
clean
1FD000
heap default
page read and write
clean
46F000
unkown
page read and write
clean
2500000
unkown image
page readonly
clean
6928000
unkown
page read and write
clean
4593000
unkown
page read and write
clean
2AB0000
unkown
page read and write
clean
4200000
unkown image
page readonly
clean
1CE000
unkown
page read and write
clean
330000
unkown
page read and write
clean
2AE0000
unkown image
page readonly
clean
9963000
unkown
page read and write
clean
E1E000
unkown
page read and write
clean
2AB0000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
1FF0000
heap private
page read and write
clean
211F000
unkown image
page read and write
clean
6AE4000
unkown
page read and write
clean
6B1E000
unkown
page read and write
clean
65A4000
unkown
page read and write
clean
32A0000
heap private
page read and write
clean
45BE000
unkown
page read and write
clean
653F000
unkown
page read and write
clean
782F000
unkown
page read and write
clean
3D90000
unkown
page read and write
clean
32A9000
heap private
page read and write
clean
654000
heap default
page read and write
clean
AAA000
unkown image
page readonly
clean
749A000
unkown
page read and write
clean
4C60000
unkown
page read and write
clean
4230000
unkown
page read and write
clean
255000
heap default
page read and write
clean
46B0000
unkown image
page readonly
clean
3D50000
unkown
page read and write
clean
67F0000
unkown
page read and write
clean
3D4B000
unkown
page read and write
clean
4513000
unkown
page read and write
clean
2040000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
6BA0000
unkown
page read and write
clean
677E000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
29D0000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7EFD0000
unkown image
page readonly
clean
263C000
unkown
page read and write
clean
3270000
unkown
page read and write
clean
371000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
29E0000
unkown
page read and write
clean
43C0000
heap private
page read and write
clean
23D000
heap default
page read and write
clean
220000
unkown image
page readonly
clean
2646000
unkown
page read and write
clean
2170000
unkown
page read and write
clean
31FF000
unkown
page read and write
clean
729A000
unkown
page read and write
clean
2A00000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
828E000
unkown
page read and write
clean
4AAC000
unkown
page read and write
clean
6499000
unkown
page read and write
clean
456F000
unkown
page read and write
clean
21B000
unkown
page execute and read and write
clean
1B65000
heap private
page read and write
clean
73B9000
unkown
page read and write
clean
660C000
unkown
page read and write
clean
20000
unkown
page read and write
clean
1B65000
heap private
page read and write
clean
110000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
60000
unkown image
page readonly
clean
AAA000
unkown image
page readonly
clean
9E2000
unkown image
page execute read
clean
45CB000
unkown
page read and write
clean
217000
unkown
page execute and read and write
clean
45A1000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
9480000
heap private
page read and write
clean
4593000
unkown
page read and write
clean
213F000
unkown image
page read and write
clean
6829000
unkown
page read and write
clean
C1F000
unkown
page read and write
clean
D00000
unkown image
page execute and read and write
clean
4C60000
unkown
page read and write
clean
4650000
unkown image
page readonly
clean
61F1000
unkown
page read and write
clean
86E000
unkown
page read and write
clean
6A12000
unkown
page read and write
clean
1140000
unkown image
page readonly
clean
4280000
unkown
page read and write
clean
275A000
unkown
page read and write
clean
2550000
unkown
page read and write
clean
5390000
heap private
page read and write
clean
9AAA000
unkown image
page execute and read and write
clean
6771000
unkown
page read and write
clean
1B50000
unkown
page read and write
clean
360000
unkown
page execute and read and write
clean
2210000
unkown
page execute and read and write
clean
83E8000
unkown
page read and write
clean
1D7000
unkown
page read and write
clean
301E000
unkown
page read and write
clean
2EC1000
unkown
page read and write
clean
4150000
unkown image
page readonly
clean
B00000
unkown
page read and write
clean
8720000
unkown
page read and write
clean
2A50000
unkown
page read and write
clean
2A70000
unkown
page read and write
clean
36F000
unkown
page read and write
clean
2110000
unkown image
page read and write
clean
212F000
unkown image
page read and write
clean
6BED000
unkown
page read and write
clean
64DC000
unkown
page read and write
clean
2560000
unkown image
page readonly
clean
42C0000
unkown
page read and write
clean
B20000
unkown
page read and write
clean
25C3000
unkown
page read and write
clean
D44000
unkown
page execute and read and write
clean
2533000
unkown
page read and write
clean
43B0000
unkown image
page readonly
clean
94A3000
heap private
page read and write
clean
1FE000
unkown
page read and write
clean
68D8000
unkown
page read and write
clean
5C8D000
unkown
page read and write
clean
729A000
unkown
page read and write
clean
2AA0000
unkown
page read and write
clean
2110000
unkown image
page read and write
clean
75FC000
unkown
page read and write
clean
45CF000
unkown
page read and write
clean
607F000
unkown
page read and write
clean
638E000
unkown
page read and write
clean
32A0000
heap private
page read and write
clean
7EFDF000
unkown
page read and write
clean
3165000
heap private
page read and write
clean
FC0000
unkown image
page readonly
clean
B17000
unkown
page read and write
clean
97A3000
unkown
page read and write
clean
2100000
unkown image
page readonly
clean
7AA000
unkown image
page execute and read and write
clean
890000
heap default
page read and write
clean
6D95000
unkown
page read and write
clean
3D50000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
2500000
unkown image
page readonly
clean
9864000
unkown
page read and write
clean
42A0000
unkown
page read and write
clean
4D70000
unkown image
page readonly
clean
4C7A000
heap private
page read and write
clean
1BE0000
unkown image
page readonly
clean
4290000
unkown
page read and write
clean
2760000
heap private
page read and write
clean
4D50000
unkown image
page readonly
clean
24F0000
unkown image
page readonly
clean
3C90000
unkown image
page read and write
clean
3E50000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
E0000
heap private
page read and write
clean
2C7000
heap default
page read and write
clean
8319000
unkown
page read and write
clean
A3F000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
1EE0000
unkown
page read and write
clean
66FE000
unkown
page read and write
clean
7E1E000
unkown
page read and write
clean
63F0000
unkown
page read and write
clean
5E1E000
unkown
page read and write
clean
30D0000
unkown image
page readonly
clean
6FF0000
unkown
page read and write
clean
440000
unkown
page read and write
clean
3D4B000
unkown
page read and write
clean
1FE0000
unkown
page read and write
clean
6FDA000
unkown
page read and write
clean
834B000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
1FD0000
unkown image
page readonly
clean
8720000
unkown
page read and write
clean
3E50000
unkown image
page readonly
clean
4D60000
unkown image
page readonly
clean
3CC0000
unkown image
page readonly
clean
F0000
unkown image
page read and write
clean
292F000
unkown
page read and write
clean
30D0000
unkown image
page readonly
clean
2A30000
unkown
page read and write
clean
2A50000
unkown
page read and write
clean
6C2B000
unkown
page read and write
clean
69B2000
unkown
page read and write
clean
67F000
unkown
page read and write
clean
309E000
unkown
page read and write
clean
A20000
unkown
page read and write
clean
67B7000
unkown
page read and write
clean
3278000
unkown
page read and write
clean
4AF0000
unkown image
page readonly
clean
4B9D000
unkown
page read and write
clean
5390000
heap private
page read and write
clean
4DB1000
unkown image
page read and write
clean
301E000
unkown
page read and write
clean
2394000
unkown
page execute and read and write
clean
1EC0000
unkown
page read and write
clean
67AF000
unkown
page read and write
clean
394000
heap default
page read and write
clean
2520000
unkown
page read and write
clean
26A000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
30F0000
unkown image
page readonly
clean
5270000
unkown
page execute read
clean
3C90000
unkown image
page read and write
clean
1F30000
unkown
page read and write
clean
292F000
unkown
page read and write
clean
4E34000
unkown
page read and write
clean
45D6000
unkown
page read and write
clean
6662000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
640F000
unkown
page read and write
clean
2AE0000
unkown image
page readonly
clean
2A90000
unkown
page read and write
clean
74B4000
heap private
page read and write
clean
BC7000
unkown
page execute and read and write
clean
2110000
unkown
page execute and read and write
clean
4D50000
unkown image
page readonly
clean
E4000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
C7F000
unkown
page read and write
clean
68E7000
unkown
page read and write
clean
2750000
unkown
page read and write
clean
370000
heap default
page read and write
clean
7EFD0000
unkown image
page readonly
clean
4E0D000
unkown
page read and write
clean
6BE5000
unkown
page read and write
clean
447A000
unkown
page read and write
clean
4D60000
unkown image
page readonly
clean
1EE0000
unkown
page read and write
clean
834B000
unkown
page read and write
clean
7CFE000
unkown
page read and write
clean
2030000
unkown
page read and write
clean
6726000
unkown
page read and write
clean
74B0000
heap private
page read and write
clean
66DE000
unkown
page read and write
clean
4C70000
heap private
page read and write
clean
8BCE000
unkown
page read and write
clean
99A0000
unkown image
page execute and read and write
clean
4E9000
heap private
page read and write
clean
4D40000
unkown image
page readonly
clean
309E000
unkown
page read and write
clean
98E3000
unkown
page read and write
clean
2740000
unkown image
page readonly
clean
919E000
unkown
page read and write
clean
3BA000
heap default
page read and write
clean
20A000
unkown
page execute and read and write
clean
2410000
unkown
page execute and read and write
clean
7EFD0000
unkown image
page readonly
clean
2904000
unkown image
page execute and read and write
clean
10000
unkown image
page read and write
clean
2990000
unkown
page read and write
clean
6DBA000
unkown
page read and write
clean
9AAA000
unkown image
page execute and read and write
clean
6740000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
4D80000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
243000
heap default
page read and write
clean
4220000
unkown
page read and write
clean
556F000
unkown
page read and write
clean
7B4B000
unkown
page read and write
clean
560000
heap private
page execute and read and write
clean
6BA3000
unkown
page read and write
clean
43A0000
unkown image
page readonly
clean
6570000
unkown
page read and write
clean
430000
unkown image
page readonly
clean
1FE0000
unkown
page read and write
clean
9864000
unkown
page read and write
clean
26C0000
unkown image
page read and write
clean
29F0000
unkown
page read and write
clean
1B83000
heap private
page read and write
clean
2060000
unkown
page read and write
clean
6510000
unkown
page read and write
clean
6766000
unkown
page read and write
clean
220000
unkown image
page readonly
clean
6C23000
unkown
page read and write
clean
31D000
heap default
page read and write
clean
1EE0000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
C50000
unkown
page execute and read and write
clean
7EFDF000
unkown
page read and write
clean
4ED2000
unkown
page read and write
clean
32A0000
heap private
page read and write
clean
1FD0000
unkown image
page readonly
clean
8412000
unkown
page read and write
clean
45CF000
unkown
page read and write
clean
2C7000
heap default
page read and write
clean
79C9000
unkown
page read and write
clean
4E58000
unkown
page read and write
clean
34E000
unkown
page read and write
clean
230000
heap default
page read and write
clean
2540000
unkown
page read and write
clean
270000
heap private
page read and write
clean
550000
unkown
page read and write
clean
686E000
unkown
page read and write
clean
30E0000
unkown image
page readonly
clean
9963000
unkown
page read and write
clean
2A40000
unkown
page read and write
clean
74D3000
heap private
page read and write
clean
672D000
unkown
page read and write
clean
6D55000
unkown
page read and write
clean
6B55000
unkown
page read and write
clean
676C000
unkown
page read and write
clean
20B6000
unkown
page read and write
clean
73BB000
unkown
page read and write
clean
430000
unkown
page read and write
clean
4593000
unkown
page read and write
clean
3DF8000
unkown
page read and write
clean
5270000
unkown
page execute read
clean
7EFD0000
unkown image
page readonly
clean
B4000
unkown
page read and write
clean
556F000
unkown
page read and write
clean
4EB6000
unkown
page read and write
clean
8459000
unkown
page read and write
clean
4160000
unkown
page read and write
clean
7E1E000
unkown
page read and write
clean
728E000
unkown
page read and write
clean
5C0000
unkown image
page readonly
clean
2BCF000
unkown
page read and write
clean
20DA000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
7686000
unkown
page read and write
clean
2C7000
heap default
page read and write
clean
5A0000
unkown
page read and write
clean
828E000
unkown
page read and write
clean
4D70000
unkown image
page readonly
clean
4AC0000
unkown
page read and write
clean
140000
unkown image
page readonly
clean
30000
unkown image
page read and write
clean
31D000
heap default
page read and write
clean
68AB000
unkown
page read and write
clean
A9C000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
2533000
unkown
page read and write
clean
32A9000
heap private
page read and write
clean
2955000
unkown
page read and write
clean
8319000
unkown
page read and write
clean
2397000
unkown
page execute and read and write
clean
2990000
unkown
page read and write
clean
32A5000
heap private
page read and write
clean
7BD0000
heap private
page read and write
clean
371000
unkown
page read and write
clean
2CA000
unkown
page read and write
clean
80E6000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
44E7000
unkown
page read and write
clean
9485000
heap private
page read and write
clean
7B50000
heap private
page read and write
clean
2426000
unkown image
page read and write
clean
330000
unkown
page read and write
clean
350000
unkown
page read and write
clean
41F000
unkown
page read and write
clean
4D60000
unkown image
page readonly
clean
1FA0000
heap private
page read and write
clean
6C57000
unkown
page read and write
clean
667000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
45A1000
unkown
page read and write
clean
2550000
unkown
page read and write
clean
4C60000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
460B000
unkown
page read and write
clean
4B9D000
unkown
page read and write
clean
30C0000
unkown
page read and write
clean
408000
heap default
page read and write
clean
2200000
unkown
page execute and read and write
clean
4575000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
2400000
unkown
page execute and read and write
clean
610000
heap private
page read and write
clean
4D30000
unkown image
page readonly
clean
74B4000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7B0000
unkown image
page readonly
clean
2170000
unkown
page read and write
clean
74B0000
heap private
page read and write
clean
1EE0000
unkown
page read and write
clean
AC0000
unkown
page execute and read and write
clean
6D48000
unkown
page read and write
clean
2A90000
unkown
page read and write
clean
6C50000
unkown
page read and write
clean
3DF8000
unkown
page read and write
clean
2A60000
unkown
page read and write
clean
1FE0000
unkown
page read and write
clean
43A0000
unkown image
page readonly
clean
99A000
unkown
page read and write
clean
2740000
unkown image
page readonly
clean
6E50000
heap private
page read and write
clean
2760000
heap private
page read and write
clean
8BCE000
unkown
page read and write
clean
4E5E000
unkown
page read and write
clean
43B0000
unkown image
page readonly
clean
6785000
unkown
page read and write
clean
6FF7000
unkown
page read and write
clean
620B000
unkown
page read and write
clean
27E0000
unkown
page read and write
clean
2750000
unkown
page read and write
clean
D30000
unkown
page execute and read and write
clean
36B000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
4D80000
unkown image
page readonly
clean
80DF000
unkown
page read and write
clean
36B000
unkown
page read and write
clean
1B50000
unkown
page read and write
clean
7691000
unkown
page read and write
clean
330000
heap private
page read and write
clean
74D3000
heap private
page read and write
clean
18A000
unkown
page read and write
clean
2120000
unkown
page execute and read and write
clean
460000
unkown image
page readonly
clean
456F000
unkown
page read and write
clean
64E1000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
5410000
heap private
page read and write
clean
4AAC000
unkown
page read and write
clean
2646000
unkown
page read and write
clean
D0000
unkown image
page readonly
clean
3298000
unkown
page read and write
clean
9E2000
unkown image
page execute read
clean
237000
heap default
page read and write
clean
6BE2000
unkown
page read and write
clean
30C0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
4513000
unkown
page read and write
clean
2A70000
unkown
page read and write
clean
7CFE000
unkown
page read and write
clean
A0000
unkown
page read and write
clean
21BF000
unkown
page read and write
clean
D10000
unkown image
page readonly
clean
29D0000
unkown
page read and write
clean
4ED2000
unkown
page read and write
clean
45B4000
unkown
page read and write
clean
6768000
unkown
page read and write
clean
750000
unkown image
page readonly
clean
3160000
heap private
page read and write
clean
2AB0000
unkown
page read and write
clean
97E000
unkown
page read and write
clean
1CE000
unkown
page read and write
clean
BDE000
unkown
page read and write
clean
C9E000
unkown
page read and write
clean
2A80000
unkown
page read and write
clean
6C57000
unkown
page read and write
clean
834B000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
9485000
heap private
page read and write
clean
4C67000
unkown
page read and write
clean
99A0000
unkown image
page execute and read and write
clean
A9C000
unkown image
page readonly
clean
5B0000
unkown image
page readonly
clean
2760000
heap private
page read and write
clean
9920000
unkown
page read and write
clean
A83000
unkown image
page execute read
clean
2A60000
unkown
page read and write
clean
29E0000
unkown
page read and write
clean
220000
unkown image
page readonly
clean
6BAB000
unkown
page read and write
clean
35F000
unkown
page read and write
clean
1FD0000
unkown image
page readonly
clean
4160000
unkown
page read and write
clean
9920000
unkown
page read and write
clean
2280000
unkown
page execute and read and write
clean
F0000
unkown
page read and write
clean
97A3000
unkown
page read and write
clean
45CF000
unkown
page read and write
clean
44E7000
unkown
page read and write
clean
2A70000
unkown
page read and write
clean
79F0000
heap private
page read and write
clean
20B6000
unkown
page read and write
clean
B3000
unkown
page execute and read and write
clean
301E000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
3CA0000
unkown
page read and write
clean
6C57000
unkown
page read and write
clean
3270000
unkown
page read and write
clean
213F000
unkown image
page read and write
clean
3E0000
heap default
page read and write
clean
3CA0000
unkown
page read and write
clean
4513000
unkown
page read and write
clean
32A5000
heap private
page read and write
clean
4C67000
unkown
page read and write
clean
263C000
unkown
page read and write
clean
4D70000
unkown image
page readonly
clean
2646000
unkown
page read and write
clean
3CC0000
unkown image
page readonly
clean
371000
unkown
page read and write
clean
4ABF000
unkown
page read and write
clean
89E000
unkown
page read and write
clean
6667000
unkown
page read and write
clean
190000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
3298000
unkown
page read and write
clean
23D000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
E0000
heap private
page read and write
clean
67C5000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7D20000
heap private
page read and write
clean
447A000
unkown
page read and write
clean
6340000
unkown
page read and write
clean
83E8000
unkown
page read and write
clean
1B83000
heap private
page read and write
clean
32A5000
heap private
page read and write
clean
5000000
heap private
page read and write
clean
919E000
unkown
page read and write
clean
2A00000
unkown
page read and write
clean
25C3000
unkown
page read and write
clean
2A80000
unkown
page read and write
clean
447A000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
45BE000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
1B50000
unkown
page read and write
clean
F0000
unkown image
page read and write
clean
263C000
unkown
page read and write
clean
41D0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
BC0000
unkown
page execute and read and write
clean
110000
unkown
page read and write
clean
4D40000
unkown image
page readonly
clean
6745000
unkown
page read and write
clean
4150000
unkown image
page readonly
clean
2990000
unkown
page read and write
clean
4900000
unkown
page read and write
clean
3160000
heap private
page read and write
clean
4593000
unkown
page read and write
clean
4300000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
4575000
unkown
page read and write
clean
29E0000
unkown
page read and write
clean
1EC0000
unkown
page read and write
clean
5C0000
unkown image
page readonly
clean
249000
heap default
page read and write
clean
40000
unkown image
page readonly
clean
BC4000
unkown
page execute and read and write
clean
3D50000
unkown
page read and write
clean
140000
unkown image
page readonly
clean
20DA000
unkown
page read and write
clean
30F0000
unkown image
page readonly
clean
4AF0000
unkown image
page readonly
clean
F0000
unkown
page read and write
clean
1B65000
heap private
page read and write
clean
7B40000
unkown
page read and write
clean
2AE0000
unkown image
page readonly
clean
94A3000
heap private
page read and write
clean
6B60000
unkown
page read and write
clean
5410000
heap private
page read and write
clean
42B0000
unkown
page read and write
clean
32AE000
heap private
page read and write
clean
3D40000
unkown
page read and write
clean
8374000
unkown
page read and write
clean
2100000
unkown image
page readonly
clean
91BE000
unkown
page read and write
clean
7BD0000
heap private
page read and write
clean
2500000
unkown image
page readonly
clean
91BE000
unkown
page read and write
clean
FBE000
unkown
page read and write
clean
67B9000
unkown
page read and write
clean
620000
unkown image
page readonly
clean
2CC7000
unkown image
page readonly
clean
190000
unkown
page execute and read and write
clean
2740000
unkown image
page readonly
clean
4EA2000
unkown
page read and write
clean
67D2000
unkown
page read and write
clean
6A31000
unkown
page read and write
clean
4AF0000
unkown image
page readonly
clean
532E000
unkown
page read and write
clean
63D2000
unkown
page read and write
clean
2550000
unkown
page read and write
clean
2CC7000
unkown image
page readonly
clean
243000
heap default
page read and write
clean
4300000
unkown
page read and write
clean
4D50000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
4B00000
unkown image
page readonly
clean
36F000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
4EE6000
unkown
page read and write
clean
1EE0000
unkown
page read and write
clean
4E5C000
unkown
page read and write
clean
BD000
unkown
page execute and read and write
clean
41D0000
unkown
page read and write
clean
4E5D000
unkown
page read and write
clean
4B9D000
unkown
page read and write
clean
34E000
unkown
page read and write
clean
45B4000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
F0000
unkown
page read and write
clean
6A19000
unkown
page read and write
clean
6C50000
unkown
page read and write
clean
1B60000
heap private
page read and write
clean
729A000
unkown
page read and write
clean
5C0000
unkown image
page readonly
clean
899000
unkown
page read and write
clean
6BDA000
unkown
page read and write
clean
9920000
unkown
page read and write
clean
650A000
unkown
page read and write
clean
2955000
unkown
page read and write
clean
76A3000
unkown
page read and write
clean
7B50000
heap private
page read and write
clean
30000
unkown image
page readonly
clean
9E0000
unkown image
page readonly
clean
2BE000
unkown
page read and write
clean
4FCE000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
94A3000
heap private
page read and write
clean
20B6000
unkown
page read and write
clean
4DD0000
heap private
page read and write
clean
4E5C000
unkown
page read and write
clean
62C1000
unkown
page read and write
clean
3DF8000
unkown
page read and write
clean
550000
unkown
page read and write
clean
9DE000
unkown
page read and write
clean
768B000
unkown
page read and write
clean
4790000
unkown image
page read and write
clean
4C60000
unkown
page read and write
clean
2130000
unkown image
page read and write
clean
4DC0000
unkown
page read and write
clean
335E000
unkown
page read and write
clean
6C50000
unkown
page read and write
clean
667000
heap default
page read and write
clean
5EEE000
unkown
page read and write
clean
4D70000
unkown image
page readonly
clean
1B50000
unkown
page read and write
clean
2560000
unkown image
page readonly
clean
6B1B000
unkown
page read and write
clean
30C0000
unkown
page read and write
clean
30E0000
unkown image
page readonly
clean
532E000
unkown
page read and write
clean
C0000
unkown
page read and write
clean
6B34000
unkown
page read and write
clean
657A000
unkown
page read and write
clean
54E000
unkown
page read and write
clean
3165000
heap private
page read and write
clean
30A8000
unkown
page read and write
clean
4AE000
unkown
page read and write
clean
45BE000
unkown
page read and write
clean
7B4B000
unkown
page read and write
clean
838E000
unkown
page read and write
clean
6514000
unkown
page read and write
clean
625F000
unkown
page read and write
clean
26CE000
unkown image
page read and write
clean
9E0000
unkown image
page readonly
clean
9E0000
unkown image
page readonly
clean
2100000
unkown image
page readonly
clean
460B000
unkown
page read and write
clean
BD0000
unkown
page execute and read and write
clean
9963000
unkown
page read and write
clean
D0000
heap default
page read and write
clean
62DE000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
237000
heap default
page read and write
clean
20B6000
unkown
page read and write
clean
537000
unkown
page read and write
clean
A9C000
unkown image
page readonly
clean
449C000
unkown
page read and write
clean
213F000
unkown image
page read and write
clean
2380000
unkown
page execute and read and write
clean
4E0000
heap private
page read and write
clean
4F20000
heap private
page execute and read and write
clean
7B40000
unkown
page read and write
clean
207000
unkown
page execute and read and write
clean
662000
heap default
page read and write
clean
696C000
unkown
page read and write
clean
6660000
unkown
page read and write
clean
2120000
unkown image
page read and write
clean
10000
unkown image
page read and write
clean
230000
heap default
page read and write
clean
6A0F000
unkown
page read and write
clean
8320000
unkown
page read and write
clean
C0000
unkown
page read and write
clean
10D000
unkown
page read and write
clean
30A8000
unkown
page read and write
clean
6915000
unkown
page read and write
clean
6737000
unkown
page read and write
clean
3D4B000
unkown
page read and write
clean
2190000
heap private
page execute and read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
6A19000
unkown
page read and write
clean
2A30000
unkown
page read and write
clean
620000
heap default
page read and write
clean
525E000
unkown
page read and write
clean
1C0000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
4D40000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
2391000
unkown
page execute and read and write
clean
2500000
unkown image
page readonly
clean
4650000
unkown image
page readonly
clean
2A30000
unkown
page read and write
clean
80DF000
unkown
page read and write
clean
BFF000
unkown
page read and write
clean
4D50000
unkown image
page readonly
clean
79C9000
unkown
page read and write
clean
7839000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
3298000
unkown
page read and write
clean
653D000
unkown
page read and write
clean
43C0000
heap private
page read and write
clean
3B0000
heap default
page read and write
clean
2540000
unkown
page read and write
clean
532E000
unkown
page read and write
clean
1FE0000
unkown
page read and write
clean
8412000
unkown
page read and write
clean
63A2000
unkown
page read and write
clean
6CCC000
unkown
page read and write
clean
6780000
unkown
page read and write
clean
3E50000
unkown image
page readonly
clean
9820000
unkown
page read and write
clean
32A9000
heap private
page read and write
clean
6B76000
unkown
page read and write
clean
1EE0000
unkown
page read and write
clean
4B00000
unkown image
page readonly
clean
A83000
unkown image
page execute read
clean
3270000
unkown
page read and write
clean
21BF000
unkown
page read and write
clean
6C19000
unkown
page read and write
clean
45A1000
unkown
page read and write
clean
2540000
unkown
page read and write
clean
6D48000
unkown
page read and write
clean
2170000
unkown
page read and write
clean
4D30000
unkown image
page readonly
clean
5360000
unkown image
page read and write
clean
6BDD000
unkown
page read and write
clean
676E000
unkown
page read and write
clean
B80000
unkown
page read and write
clean
292F000
unkown
page read and write
clean
1FD0000
unkown image
page readonly
clean
32AE000
heap private
page read and write
clean
32A9000
heap private
page read and write
clean
2120000
unkown image
page read and write
clean
4D80000
unkown image
page readonly
clean
255000
heap default
page read and write
clean
5410000
heap private
page read and write
clean
F0000
unkown image
page read and write
clean
67CB000
unkown
page read and write
clean
5F0000
unkown
page read and write
clean
4220000
unkown
page read and write
clean
6659000
unkown
page read and write
clean
4300000
unkown
page read and write
clean
3278000
unkown
page read and write
clean
76A7000
unkown
page read and write
clean
C40000
unkown
page execute and read and write
clean
2750000
unkown
page read and write
clean
4EA2000
unkown
page read and write
clean
1F2E000
unkown
page read and write
clean
4200000
unkown image
page readonly
clean
E4000
heap private
page read and write
clean
6D48000
unkown
page read and write
clean
213F000
unkown image
page read and write
clean
2A90000
unkown
page read and write
clean
4513000
unkown
page read and write
clean
421C000
unkown
page read and write
clean
6A17000
unkown
page read and write
clean
6C1B000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
371000
unkown
page read and write
clean
3278000
unkown
page read and write
clean
460B000
unkown
page read and write
clean
5E0000
unkown image
page readonly
clean
948000
unkown
page read and write
clean
4AF2000
heap private
page read and write
clean
6352000
unkown
page read and write
clean
3298000
unkown
page read and write
clean
31FF000
unkown
page read and write
clean
1E0000
unkown
page read and write
clean
23D000
heap default
page read and write
clean
30F0000
unkown image
page readonly
clean
3D40000
unkown
page read and write
clean
4DC0000
unkown
page read and write
clean
80E6000
unkown
page read and write
clean
1B83000
heap private
page read and write
clean
42D0000
unkown
page read and write
clean
6543000
unkown
page read and write
clean
89F000
unkown
page read and write
clean
1FE0000
unkown
page read and write
clean
64B5000
unkown
page read and write
clean
4E5E000
unkown
page read and write
clean
2A10000
unkown
page read and write
clean
237000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
30C0000
unkown
page read and write
clean
E0000
heap private
page read and write
clean
2F6000
unkown
page read and write
clean
782F000
unkown
page read and write
clean
7CFE000
unkown
page read and write
clean
7839000
unkown
page read and write
clean
6A12000
unkown
page read and write
clean
9E0000
unkown image
page readonly
clean
5B0000
unkown image
page readonly
clean
23D000
heap default
page read and write
clean
672A000
unkown
page read and write
clean
4AC0000
unkown
page read and write
clean
6FB4000
unkown
page read and write
clean
32A0000
heap private
page read and write
clean
6BBE000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
1BE0000
unkown image
page readonly
clean
2030000
unkown
page read and write
clean
DB0000
unkown
page execute and read and write
clean
9485000
heap private
page read and write
clean
422E000
unkown
page read and write
clean
3160000
heap private
page read and write
clean
F0000
unkown
page read and write
clean
3160000
heap private
page read and write
clean
20000
unkown
page read and write
clean
E4000
heap private
page read and write
clean
4B9D000
unkown
page read and write
clean
98A2000
unkown
page read and write
clean
6BF8000
unkown
page read and write
clean
2EC1000
unkown
page read and write
clean
4150000
unkown image
page readonly
clean
4280000
unkown
page read and write
clean
43A0000
unkown image
page readonly
clean
6A17000
unkown
page read and write
clean
1F30000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
66C000
unkown
page read and write
clean
4EA2000
unkown
page read and write
clean
211F000
unkown image
page read and write
clean
31D000
heap default
page read and write
clean
6B25000
unkown
page read and write
clean
6998000
unkown
page read and write
clean
42B0000
unkown
page execute and read and write
clean
1E0000
unkown
page read and write
clean
29D0000
unkown
page read and write
clean
2044000
unkown
page read and write
clean
1BE0000
unkown image
page readonly
clean
62AE000
unkown
page read and write
clean
6B13000
unkown
page read and write
clean
2A20000
unkown
page read and write
clean
2533000
unkown
page read and write
clean
6BD7000
unkown
page read and write
clean
43B0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
626E000
unkown
page read and write
clean
5008000
heap private
page read and write
clean
36B000
unkown
page read and write
clean
2A90000
unkown
page read and write
clean
2130000
unkown image
page read and write
clean
7EFB2000
unkown image
page readonly
clean
9820000
unkown
page read and write
clean
1EE0000
unkown
page read and write
clean
E4000
heap private
page read and write
clean
318000
unkown
page read and write
clean
1D7000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
2177000
unkown
page read and write
clean
5B0000
unkown image
page readonly
clean
BB0000
unkown
page execute and read and write
clean
514C000
heap private
page read and write
clean
80E6000
unkown
page read and write
clean
4E93000
unkown
page read and write
clean
32AE000
heap private
page read and write
clean
4575000
unkown
page read and write
clean
230000
heap default
page read and write
clean
24F0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
91A0000
unkown
page read and write
clean
91BE000
unkown
page read and write
clean
2A40000
unkown
page read and write
clean
255000
heap default
page read and write
clean
30E0000
unkown image
page readonly
clean
782F000
unkown
page read and write
clean
AD0000
unkown
page execute and read and write
clean
DC0000
unkown
page execute and read and write
clean
2040000
unkown
page read and write
clean
202000
unkown
page read and write
clean
4C7A000
heap private
page read and write
clean
309E000
unkown
page read and write
clean
2CC7000
unkown image
page readonly
clean
4E77000
unkown
page read and write
clean
30F0000
unkown image
page readonly
clean
2990000
unkown
page read and write
clean
211F000
unkown image
page read and write
clean
64DA000
unkown
page read and write
clean
5C0000
unkown image
page readonly
clean
5C70000
unkown
page read and write
clean
509C000
unkown
page read and write
clean
6787000
unkown
page read and write
clean
447A000
unkown
page read and write
clean
220000
unkown image
page readonly
clean
2A40000
unkown
page read and write
clean
6390000
unkown
page read and write
clean
666000
unkown
page read and write
clean
98A2000
unkown
page read and write
clean
80DF000
unkown
page read and write
clean
97A3000
unkown
page read and write
clean
309E000
unkown
page read and write
clean
2A80000
unkown
page read and write
clean
C30000
unkown
page execute and read and write
clean
1F9E000
unkown
page read and write
clean
673E000
unkown
page read and write
clean
6D19000
unkown
page read and write
clean
750000
unkown image
page readonly
clean
140000
unkown
page read and write
clean
4160000
unkown
page read and write
clean
4AAC000
unkown
page read and write
clean
457A000
unkown
page read and write
clean
8BCE000
unkown
page read and write
clean
212F000
unkown image
page read and write
clean
2A50000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
4450000
unkown
page read and write
clean
6721000
unkown
page read and write
clean
430000
unkown image
page readonly
clean
2533000
unkown
page read and write
clean
540000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
4E79000
unkown
page read and write
clean
65E000
heap default
page read and write
clean
4C70000
heap private
page read and write
clean
2290000
unkown
page execute and read and write
clean
255000
heap default
page read and write
clean
6B5E000
unkown
page read and write
clean
A90000
unkown image
page execute read
clean
4450000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
206000
heap default
page read and write
clean
99D000
unkown
page read and write
clean
2A20000
unkown
page read and write
clean
18C000
unkown
page read and write
clean
79C9000
unkown
page read and write
clean
3D90000
unkown
page read and write
clean
48FF000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
D00000
unkown image
page execute and read and write
clean
7EFC2000
unkown image
page readonly
clean
A90000
unkown image
page execute read
clean
4200000
unkown image
page readonly
clean
97E0000
unkown
page read and write
clean
73B9000
unkown
page read and write
clean
32A5000
heap private
page read and write
clean
43DD000
unkown
page read and write
clean
30D0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
29E0000
unkown
page read and write
clean
2520000
unkown
page read and write
clean
4D40000
unkown image
page readonly
clean
9760000
unkown
page read and write
clean
2550000
unkown
page read and write
clean
3278000
unkown
page read and write
clean
D0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
3D40000
unkown
page read and write
clean
427C000
unkown
page read and write
clean
263C000
unkown
page read and write
clean
3165000
heap private
page read and write
clean
2A50000
unkown
page read and write
clean
D41000
unkown
page execute and read and write
clean
4D20000
unkown
page execute and read and write
clean
10000
unkown image
page read and write
clean
30000
unkown image
page execute and read and write
clean
249000
heap default
page read and write
clean
66DA000
unkown
page read and write
clean
2046000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
97E0000
unkown
page read and write
clean
7BD0000
heap private
page read and write
clean
4308000
unkown
page read and write
clean
1B60000
heap private
page read and write
clean
500000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
9760000
unkown
page read and write
clean
63FB000
unkown
page read and write
clean
630000
heap default
page read and write
clean
34E000
unkown
page read and write
clean
6998000
unkown
page read and write
clean
1ED0000
unkown
page read and write
clean
4160000
unkown
page read and write
clean
69F9000
unkown
page read and write
clean
AE0000
unkown
page execute and read and write
clean
66F1000
unkown
page read and write
clean
607E000
unkown
page read and write | page guard
clean
4E93000
unkown
page read and write
clean
6A60000
heap private
page read and write
clean
457A000
unkown
page read and write
clean
7839000
unkown
page read and write
clean
2560000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
4230000
unkown
page read and write
clean
9E2000
unkown image
page execute read
clean
330000
unkown
page read and write
clean
7A0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
2AAF000
unkown
page read and write
clean
2220000
unkown
page execute and read and write
clean
9E2000
unkown image
page execute read
clean
2750000
unkown
page read and write
clean
292F000
unkown
page read and write
clean
7B40000
unkown
page read and write
clean
4EB6000
unkown
page read and write
clean
637000
heap default
page read and write
clean
40000
unkown image
page readonly
clean
CD000
unkown
page execute and read and write
clean
6958000
unkown
page read and write
clean
618E000
unkown
page read and write
clean
6B68000
unkown
page read and write
clean
29F0000
unkown
page read and write
clean
3CA0000
unkown
page read and write
clean
D50000
unkown
page execute and read and write
clean
10000
unkown image
page read and write
clean
98A2000
unkown
page read and write
clean
120000
unkown
page execute and read and write
clean
64F1000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
CFE000
unkown
page read and write
clean
5360000
unkown image
page read and write
clean
4D20000
unkown
page execute and read and write
clean
200000
unkown
page execute and read and write
clean
9480000
heap private
page read and write
clean
70AF000
unkown
page read and write
clean
30D0000
unkown image
page readonly
clean
2A70000
unkown
page read and write
clean
3D50000
unkown
page read and write
clean
2955000
unkown
page read and write
clean
4C70000
heap private
page read and write
clean
5140000
heap private
page read and write
clean
8B4000
heap default
page read and write
clean
24F0000
unkown image
page readonly
clean
97E0000
unkown
page read and write
clean
2110000
unkown image
page read and write
clean
65D000
unkown
page read and write
clean
556F000
unkown
page read and write
clean
2AA0000
unkown
page read and write
clean
3C90000
unkown image
page read and write
clean
5390000
heap private
page read and write
clean
A83000
unkown image
page execute read
clean
6576000
unkown
page read and write
clean
5041000
unkown
page read and write
clean
4575000
unkown
page read and write
clean
2A60000
unkown
page read and write
clean
2760000
heap private
page read and write
clean
22A0000
unkown
page execute and read and write
clean
633E000
unkown
page read and write
clean
354000
unkown
page read and write
clean
5C0000
unkown
page read and write
clean
7041000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
6BBE000
unkown
page read and write
clean
4E58000
unkown
page read and write
clean
6517000
unkown
page read and write
clean
4E5E000
unkown
page read and write
clean
4290000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
45B4000
unkown
page read and write
clean
494000
heap private
page read and write
clean
490000
heap private
page read and write
clean
744D000
unkown
page read and write
clean
1260000
unkown image
page readonly
clean
249000
heap default
page read and write
clean
31D000
heap default
page read and write
clean
43B0000
unkown image
page readonly
clean
2120000
unkown image
page read and write
clean
42A0000
unkown
page read and write
clean
A83000
unkown image
page execute read
clean
D47000
unkown
page execute and read and write
clean
4DD0000
heap private
page read and write
clean
2A10000
unkown
page read and write
clean
8355000
unkown
page read and write
clean
1D7000
unkown
page read and write
clean
4E77000
unkown
page read and write
clean
4DD0000
heap private
page read and write
clean
243000
heap default
page read and write
clean
230000
heap default
page read and write
clean
2520000
unkown
page read and write
clean
449C000
unkown
page read and write
clean
A9C000
unkown image
page readonly
clean
6BB7000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
534000
unkown
page read and write
clean
249000
heap default
page read and write
clean
36F000
unkown
page read and write
clean
AAA000
unkown image
page readonly
clean
32AE000
heap private
page read and write
clean
6998000
unkown
page read and write
clean
4DF0000
unkown
page read and write
clean
330000
unkown
page read and write
clean
3270000
unkown
page read and write
clean
45A1000
unkown
page read and write
clean
45CB000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
4EB6000
unkown
page read and write
clean
30A8000
unkown
page read and write
clean
2EC1000
unkown
page read and write
clean
6A60000
heap private
page read and write
clean
3D90000
unkown
page read and write
clean
73BB000
unkown
page read and write
clean
AAA000
unkown image
page readonly
clean
689C000
unkown
page read and write
clean
9E0000
unkown image
page readonly
clean
750000
unkown image
page readonly
clean
27F0000
unkown image
page execute and read and write
clean
2955000
unkown
page read and write
clean
A40000
unkown
page execute and read and write
clean
327F000
unkown
page read and write
clean
4D30000
unkown image
page readonly
clean
2A40000
unkown
page read and write
clean
828E000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
31FF000
unkown
page read and write
clean
66F7000
unkown
page read and write
clean
65FF000
unkown
page read and write
clean
64E8000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
4B00000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
67B2000
unkown
page read and write
clean
3BD000
heap default
page read and write
clean
20DA000
unkown
page read and write
clean
1F40000
unkown
page read and write
clean
81AE000
unkown
page read and write
clean
4AAC000
unkown
page read and write
clean
3165000
heap private
page read and write
clean
37E000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
74D3000
heap private
page read and write
clean
61F0000
unkown
page read and write
clean
1D7000
unkown
page read and write
clean
212F000
unkown image
page read and write
clean
8320000
unkown
page read and write
clean
4ED2000
unkown
page read and write
clean
125F000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
3DF8000
unkown
page read and write
clean
4AC0000
unkown
page read and write
clean
1CE000
unkown
page read and write
clean
2C7000
heap default
page read and write
clean
66FB000
unkown
page read and write
clean
7005000
unkown
page read and write
clean
8459000
unkown
page read and write
clean
3CC0000
unkown image
page readonly
clean
25C3000
unkown
page read and write
clean
2100000
unkown image
page readonly
clean
2060000
unkown
page read and write
clean
66C000
unkown
page read and write
clean
65B000
unkown
page read and write
clean
29F0000
unkown
page read and write
clean
6A19000
unkown
page read and write
clean
6545000
unkown
page read and write
clean
36F000
unkown
page read and write
clean
5004000
heap private
page read and write
clean
4EE6000
unkown
page read and write
clean
64E5000
unkown
page read and write
clean
9820000
unkown
page read and write
clean
5260000
unkown
page read and write
clean
2214000
unkown
page execute and read and write
clean
8374000
unkown
page read and write
clean
750000
unkown image
page readonly
clean
3E50000
unkown image
page readonly
clean
6A0F000
unkown
page read and write
clean
6F06000
unkown
page read and write
clean
681A000
unkown
page read and write
clean
261F000
unkown image
page read and write
clean
7EFB2000
unkown image
page readonly
clean
66F9000
unkown
page read and write
clean
9760000
unkown
page read and write
clean
4450000
unkown
page read and write
clean
897000
heap default
page read and write
clean
21BF000
unkown
page read and write
clean
4D30000
unkown image
page readonly
clean
24F0000
unkown image
page readonly
clean
4308000
unkown
page read and write
clean
8319000
unkown
page read and write
clean
2EC1000
unkown
page read and write
clean
8374000
unkown
page read and write
clean
74B4000
heap private
page read and write
clean
74B0000
heap private
page read and write
clean
30A8000
unkown
page read and write
clean
2130000
unkown image
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
34E000
unkown
page read and write
clean
98E3000
unkown
page read and write
clean
98E3000
unkown
page read and write
clean
1B83000
heap private
page read and write
clean
664C000
unkown
page read and write
clean
30E0000
unkown image
page readonly
clean
2AE0000
unkown image
page readonly
clean
64BA000
unkown
page read and write
clean
F0000
unkown image
page read and write
clean
26D9000
unkown image
page read and write
clean
E0000
heap private
page read and write
clean
1CE000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
67CF000
unkown
page read and write
clean
2B1000
unkown
page read and write
clean
45D6000
unkown
page read and write
clean
6D40000
unkown
page read and write
clean
3CA0000
unkown
page read and write
clean
73BB000
unkown
page read and write
clean
2130000
unkown image
page read and write
clean
30000
unkown image
page readonly
clean
210000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
4AD4000
heap private
page read and write
clean
65B000
unkown
page read and write
clean
6B98000
unkown
page read and write
clean
4C7A000
heap private
page read and write
clean
31FF000
unkown
page read and write
clean
2217000
unkown
page execute and read and write
clean
7B4B000
unkown
page read and write
clean
2C0000
unkown
page read and write
clean
A10000
unkown
page read and write
clean
21BF000
unkown
page read and write
clean
81AE000
unkown
page read and write
clean
8C0000
unkown
page read and write
clean
5270000
unkown
page execute read
clean
7B50000
heap private
page read and write
clean
4E60000
unkown
page read and write
clean
6C21000
unkown
page read and write
clean
7D20000
heap private
page read and write
clean
4AD0000
heap private
page read and write
clean
4450000
unkown
page read and write
clean
2520000
unkown
page read and write
clean
457A000
unkown
page read and write
clean
27E0000
unkown
page read and write
clean
5040000
unkown
page read and write
clean
8355000
unkown
page read and write
clean
45D6000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
3CC0000
unkown image
page readonly
clean
3D40000
unkown
page read and write
clean
4B00000
unkown image
page readonly
clean
730000
unkown image
page readonly
clean
520000
unkown
page read and write
clean
2540000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
666000
unkown
page read and write
clean
2A80000
unkown
page read and write
clean
2110000
unkown image
page read and write
clean
4650000
unkown image
page readonly
clean
45CB000
unkown
page read and write
clean
4EE6000
unkown
page read and write
clean
66E6000
unkown
page read and write
clean
6E50000
heap private
page read and write
clean
2050000
unkown
page read and write
clean
600000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
2A20000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
73B9000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
6C36000
unkown
page read and write
clean
2A60000
unkown
page read and write
clean
456F000
unkown
page read and write
clean
45B4000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
8720000
unkown
page read and write
clean
45BE000
unkown
page read and write
clean
6B74000
unkown
page read and write
clean
243000
heap default
page read and write
clean
457A000
unkown
page read and write
clean
2646000
unkown
page read and write
clean
13C000
unkown
page read and write
clean
4308000
unkown
page read and write
clean
211F000
unkown image
page read and write
clean
2120000
unkown image
page read and write
clean
2740000
unkown image
page readonly
clean
29B000
heap default
page read and write
clean
8320000
unkown
page read and write
clean
4E60000
unkown
page read and write
clean
23A0000
unkown
page execute and read and write
clean
29B000
heap default
page read and write
clean
4308000
unkown
page read and write
clean
500000
unkown image
page read and write
clean
7EFE0000
unkown image
page readonly
clean
2030000
unkown image
page read and write
clean
4DC0000
unkown
page read and write
clean
56F000
unkown
page read and write
clean
44E7000
unkown
page read and write
clean
728E000
unkown
page read and write
clean
79F0000
heap private
page read and write
clean
237000
heap default
page read and write
clean
79F0000
heap private
page read and write
clean
678C000
unkown
page read and write
clean
2180000
unkown
page read and write
clean
4D60000
unkown image
page readonly
clean
460B000
unkown
page read and write
clean
1B65000
heap private
page read and write
clean
43C0000
heap private
page read and write
clean
9E0000
unkown image
page readonly
clean
27E0000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7030000
unkown
page read and write
clean
5B0000
unkown image
page readonly
clean
208000
heap default
page read and write
clean
1EE0000
unkown
page read and write
clean
3D90000
unkown
page read and write
clean
4DB1000
unkown image
page read and write
clean
456F000
unkown
page read and write
clean
2AB0000
unkown
page read and write
clean
2054000
unkown
page read and write
clean
1ED0000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
644A000
unkown
page read and write
clean
25C3000
unkown
page read and write
clean
6606000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
5360000
unkown image
page read and write
clean
531000
unkown
page read and write
clean
4150000
unkown image
page readonly
clean
2A10000
unkown
page read and write
clean
D0000
unkown image
page readonly
clean
65F4000
unkown
page read and write
clean
1BE0000
unkown image
page readonly
clean
9EF000
unkown
page read and write
clean
4C70000
heap private
page read and write
clean
140000
unkown image
page readonly
clean
744D000
unkown
page read and write
clean
4E60000
unkown
page read and write
clean
1E0000
unkown
page read and write
clean
6774000
unkown
page read and write
clean
4C67000
unkown
page read and write
clean
220000
unkown
page execute and read and write
clean
212F000
unkown image
page read and write
clean
140000
unkown image
page readonly
clean
65A0000
unkown
page read and write
clean
4DB1000
unkown image
page read and write
clean
449C000
unkown
page read and write
clean
2CC7000
unkown image
page readonly
clean
6A12000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
2AA0000
unkown
page read and write
clean
2B0F000
unkown image
page read and write
clean
4C0000
unkown image
page readonly
clean
2A30000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
699E000
unkown
page read and write
clean
6A60000
heap private
page read and write
clean
4C7A000
heap private
page read and write
clean
6A0F000
unkown
page read and write
clean
8459000
unkown
page read and write
clean
F7F000
unkown
page read and write
clean
43A0000
unkown image
page readonly
clean
4D80000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
36B000
unkown
page read and write
clean
664E000
unkown
page read and write
clean
3D4B000
unkown
page read and write
clean
6D40000
unkown
page read and write
clean
110000
unkown
page read and write
clean
2A20000
unkown
page read and write
clean
4300000
unkown
page read and write
clean
645E000
unkown
page read and write
clean
3C90000
unkown image
page read and write
clean
29F0000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
4E94000
unkown
page read and write
clean
4C67000
unkown
page read and write
clean
26E6000
unkown image
page read and write
clean
7EFB0000
unkown image
page readonly
clean
81BF000
unkown
page read and write
clean
B14000
unkown
page read and write
clean
2560000
unkown image
page readonly
clean
6273000
unkown
page read and write
clean
919E000
unkown
page read and write
clean
6E50000
heap private
page read and write
clean
20DA000
unkown
page read and write
clean
83E8000
unkown
page read and write
clean
6BBE000
unkown
page read and write
clean
8355000
unkown
page read and write
clean
There are 1442 hidden memdumps, click here to show them.