IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Compensation-1730406737-09272021.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Author: Test, Last Saved By: Test, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Jun 5 19:17:20 2015, Last Saved Time/Date: Mon Sep 27 10:38:52 2021, Security: 0
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\44466.7022844907[1].dat
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\44466.7022844907[2].dat
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\44466.7022844907[3].dat
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Drezd.red
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Drezd1.red
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Drezd2.red
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\VBE\MSForms.exd
data
dropped
clean
C:\Users\user\AppData\Local\Temp\VBE\RefEdit.exd
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Drezd.red
malicious
C:\Windows\SysWOW64\regsvr32.exe
-silent ..\Drezd.red
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Drezd1.red
malicious
C:\Windows\SysWOW64\schtasks.exe
'C:\Windows\system32\schtasks.exe' /Create /RU 'NT AUTHORITY\SYSTEM' /tn fpdnnxq /tr 'regsvr32.exe -s \'C:\Users\user\Drezd.red\'' /SC ONCE /Z /ST 16:53 /ET 17:05
malicious
C:\Windows\SysWOW64\regsvr32.exe
-silent ..\Drezd1.red
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Drezd2.red
malicious
C:\Windows\SysWOW64\regsvr32.exe
-silent ..\Drezd2.red
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\System32\reg.exe
C:\Windows\system32\reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths' /f /t REG_DWORD /v 'C:\ProgramData\Microsoft\Djryxcyvgoe' /d '0'
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\System32\reg.exe
C:\Windows\system32\reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths' /f /t REG_DWORD /v 'C:\Users\user\AppData\Roaming\Microsoft\Benqxuam' /d '0'
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\Drezd.red'
malicious
There are 8 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://www.%s.comPA
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://190.14.37.178/44466.7022844907.dat
190.14.37.178
clean
http://185.250.148.213/44466.7022844907.dat
185.250.148.213
clean
http://185.183.96.67/44466.7022844907.dat
185.183.96.67
clean
http://servername/isapibackend.dll
unknown
clean

IPs

IP
Domain
Country
Malicious
185.183.96.67
unknown
Netherlands
clean
190.14.37.178
unknown
Panama
clean
185.250.148.213
unknown
Russian Federation
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
',-
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2D49D
2D49D
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{79353955-DA68-4297-870E-CA8D594B50DB}\2.0
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{79353955-DA68-4297-870E-CA8D594B50DB}\2.0\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{79353955-DA68-4297-870E-CA8D594B50DB}\2.0\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{79353955-DA68-4297-870E-CA8D594B50DB}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{79353955-DA68-4297-870E-CA8D594B50DB}\2.0
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{79353955-DA68-4297-870E-CA8D594B50DB}\2.0\FLAGS
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{79353955-DA68-4297-870E-CA8D594B50DB}\2.0\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{79353955-DA68-4297-870E-CA8D594B50DB}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CC904D23-768E-4B8B-AA7E-0E789305E902}\1.2
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CC904D23-768E-4B8B-AA7E-0E789305E902}\1.2\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CC904D23-768E-4B8B-AA7E-0E789305E902}\1.2\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CC904D23-768E-4B8B-AA7E-0E789305E902}\1.2\HELPDIR
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00024518-0000-0000-C000-000000000046}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
}7-
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\38056
38056
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\382E6
382E6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_CURRENT_USER\Software\Microsoft\Jhveyicyauzw
7f3945b5
clean
HKEY_CURRENT_USER\Software\Microsoft\Jhveyicyauzw
4aa695fb
clean
HKEY_CURRENT_USER\Software\Microsoft\Jhveyicyauzw
48e7b587
clean
HKEY_CURRENT_USER\Software\Microsoft\Jhveyicyauzw
f05bd2e2
clean
HKEY_CURRENT_USER\Software\Microsoft\Jhveyicyauzw
8d539d68
clean
HKEY_CURRENT_USER\Software\Microsoft\Jhveyicyauzw
35effa0d
clean
HKEY_CURRENT_USER\Software\Microsoft\Jhveyicyauzw
f21af29e
clean
HKEY_CURRENT_USER\Software\Microsoft\Jhveyicyauzw
702a43
clean
HKEY_CURRENT_USER\Software\Microsoft\Jhveyicyauzw
7f3945b5
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Bbutlvs
f6f33628
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Bbutlvs
c36ce666
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Bbutlvs
c12dc61a
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Bbutlvs
7991a17f
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Bbutlvs
499eef5
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Bbutlvs
bc258990
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Bbutlvs
7bd08103
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Bbutlvs
89ba59de
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Bbutlvs
f6f33628
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
C:\ProgramData\Microsoft\Djryxcyvgoe
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
C:\Users\user\AppData\Roaming\Microsoft\Benqxuam
clean
There are 212 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
32E000
unkown
page read and write
clean
E0000
unkown image
page read and write
clean
30000
unkown image
page readonly
clean
100000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
F0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
20E0000
unkown image
page readonly
clean
39A000
heap default
page read and write
clean
20000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
35C000
unkown
page read and write
clean
590000
unkown image
page readonly
clean
9E0000
unkown image
page readonly
clean
10000000
unkown image
page readonly
clean
2BBF000
heap private
page read and write
clean
20000
unkown image
page readonly
clean
2DF3000
heap private
page read and write
clean
C00000
heap private
page read and write
clean
5F0000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
9FF000
unkown
page read and write
clean
247000
heap default
page read and write
clean
570000
unkown
page read and write
clean
80000
unkown image
page execute and read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
27FF000
heap private
page read and write
clean
50000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
6A4000
heap default
page read and write
clean
60000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
4B4000
heap default
page read and write
clean
281C000
unkown
page read and write
clean
470000
unkown
page read and write
clean
5EF000
unkown
page read and write
clean
5F4000
heap private
page read and write
clean
2E7000
heap default
page read and write
clean
10001000
unkown image
page execute and read and write
clean
290000
heap default
page read and write
clean
18DE000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
13E000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
200000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
A5F000
unkown
page read and write
clean
E0000
unkown image
page read and write
clean
1BC0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
209B000
heap private
page read and write
clean
20000
unkown image
page readonly
clean
127C000
unkown
page read and write
clean
1F4000
heap private
page read and write
clean
226C000
unkown
page read and write
clean
1790000
heap private
page read and write
clean
10001000
unkown image
page execute and read and write
clean
10042000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
190000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
186000
unkown
page read and write
clean
12BF000
unkown
page read and write
clean
5C0000
heap private
page read and write
clean
E0000
heap default
page read and write
clean
13EE000
unkown
page read and write
clean
2C0000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
510000
heap private
page read and write
clean
37A000
heap default
page read and write
clean
30000
unkown image
page readonly
clean
290000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
5F0000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
530000
heap private
page read and write
clean
950000
unkown image
page readonly
clean
630000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
3D2000
heap default
page read and write
clean
1F6000
unkown
page read and write
clean
393000
heap default
page read and write
clean
516000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
B0000
unkown
page read and write
clean
330000
heap private
page read and write
clean
2C03000
heap private
page read and write
clean
2CE000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
F0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
C10000
heap private
page read and write
clean
1BB000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
270000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7C0000
unkown
page read and write
clean
4D8000
unkown
page read and write
clean
27CD000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
BA0000
unkown
page execute and read and write
clean
7EFB0000
unkown image
page readonly
clean
990000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
160000
unkown
page read and write
clean
80000
unkown image
page execute and read and write
clean
7EFC0000
unkown image
page readonly
clean
280F000
unkown
page read and write
clean
5E0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
A0000
unkown image
page readonly
clean
80000
unkown image
page execute and read and write
clean
10052000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
604000
heap default
page read and write
clean
F0000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
22B0000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
D80000
unkown image
page readonly
clean
FB000
unkown
page read and write
clean
123F000
heap private
page read and write
clean
22DF000
heap private
page read and write
clean
2D8F000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
490000
heap default
page read and write
clean
3F6000
heap private
page read and write
clean
3C3000
heap default
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
279000
heap default
page read and write
clean
264000
heap default
page read and write
clean
104000
heap private
page read and write
clean
20000
unkown image
page readonly
clean
4A6000
unkown
page read and write
clean
D90000
unkown image
page readonly
clean
416000
unkown
page read and write
clean
190000
unkown
page read and write
clean
3B0000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
200000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
272000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
10042000
unkown image
page readonly
clean
64E000
unkown
page read and write
clean
24B000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
300000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
260000
unkown image
page read and write
clean
8B0000
heap private
page read and write
clean
4E2000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
164F000
unkown
page read and write
clean
4D5000
heap default
page read and write
clean
20000
unkown image
page readonly
clean
384000
heap default
page read and write
clean
1FC0000
unkown image
page readonly
clean
480000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
620000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
4DF000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
27B0000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
77E000
unkown
page read and write
clean
2125000
heap private
page read and write
clean
600000
unkown
page read and write
clean
8F0000
unkown image
page readonly
clean
5E0000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
340000
unkown
page execute and read and write
clean
C0000
unkown image
page read and write
clean
7EFB2000
unkown image
page readonly
clean
10000000
unkown image
page readonly
clean
350000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2B40000
heap private
page read and write
clean
1B0000
unkown
page read and write
clean
2075000
heap private
page read and write
clean
100000
heap private
page read and write
clean
7EFDF000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
580000
heap private
page read and write
clean
2CE000
unkown
page read and write
clean
670000
unkown image
page readonly
clean
C2F000
unkown
page read and write
clean
B0000
unkown
page read and write
clean
600000
unkown image
page readonly
clean
BE1000
unkown
page execute and read and write
clean
7EFDF000
unkown
page read and write
clean
A0000
unkown image
page readonly
clean
10000000
unkown image
page readonly
clean
22DF000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
27CE000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
30000
unkown image
page read and write
clean
1A0000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
90000
unkown
page read and write
clean
1C0000
unkown
page read and write
clean
280B000
unkown
page read and write
clean
2C0000
unkown
page read and write
clean
1491000
unkown
page read and write
clean
160000
heap default
page read and write
clean
60000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
276F000
unkown
page read and write
clean
8E0000
unkown image
page readonly
clean
497000
heap default
page read and write
clean
4F4000
heap private
page read and write
clean
23A2000
heap private
page read and write
clean
327000
heap default
page read and write
clean
7EFD0000
unkown image
page readonly
clean
330000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
D0000
unkown
page read and write
clean
524000
heap default
page read and write
clean
50000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
2AC0000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2060000
heap private
page read and write
clean
3B0000
heap private
page read and write
clean
790000
unkown image
page readonly
clean
142F000
unkown
page read and write
clean
2D2F000
unkown
page read and write
clean
2190000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
10001000
unkown image
page execute and read and write
clean
7EFD0000
unkown image
page readonly
clean
17B3000
heap private
page read and write
clean
2200000
unkown image
page readonly
clean
760000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
1D2000
heap default
page read and write
clean
30000
unkown image
page read and write
clean
4C0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
10044000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
B0000
unkown image
page readonly
clean
2260000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
10000
unkown image
page read and write
clean
4E0000
unkown
page read and write
clean
2E4F000
heap private
page read and write
clean
30000
unkown image
page readonly
clean
16BE000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
580000
unkown image
page readonly
clean
4E6000
unkown
page read and write
clean
860000
unkown image
page readonly
clean
460000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
D80000
unkown
page execute and read and write
clean
30000
unkown image
page readonly
clean
4E8000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
3BE000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
25C000
unkown
page read and write
clean
8A0000
unkown image
page readonly
clean
2380000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
10052000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
136E000
unkown
page read and write
clean
336000
heap private
page read and write
clean
BD5000
unkown
page execute and read and write
clean
1F0000
heap private
page read and write
clean
18A000
unkown
page read and write
clean
8CD000
unkown
page read and write
clean
420000
unkown
page read and write
clean
199000
heap default
page read and write
clean
4D2000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
680000
heap default
page read and write
clean
5AF000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
F0000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
1A9F000
unkown
page read and write
clean
2190000
unkown image
page readonly
clean
2871000
unkown
page execute and read and write
clean
1C0000
unkown
page read and write
clean
2A7C000
unkown
page read and write
clean
294000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
270000
unkown
page read and write
clean
280000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
150000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
2D0000
heap private
page read and write
clean
8FE000
unkown
page read and write
clean
687000
heap default
page read and write
clean
7EFC0000
unkown image
page readonly
clean
4DD000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
9A000
unkown
page read and write
clean
590000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
320000
heap default
page read and write
clean
2780000
heap private
page read and write
clean
5A6000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
20000
unkown image
page read and write
clean
69F000
heap default
page read and write
clean
8E0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
840000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
590000
unkown image
page readonly
clean
476000
unkown
page read and write
clean
5A6000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
39A000
heap default
page read and write
clean
27B0000
unkown
page read and write
clean
780000
unkown image
page readonly
clean
377000
heap default
page read and write
clean
25CF000
unkown
page read and write
clean
30000
unkown image
page read and write
clean
239E000
unkown
page read and write
clean
167000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
DC1000
unkown
page execute and read and write
clean
69A000
heap default
page read and write
clean
20000
unkown image
page readonly
clean
26C000
unkown
page read and write
clean
190000
unkown
page read and write
clean
37E000
heap default
page read and write
clean
50000
unkown image
page readonly
clean
18B000
unkown
page read and write
clean
890000
heap private
page read and write
clean
970000
heap private
page read and write
clean
50000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
123F000
heap private
page read and write
clean
1CC0000
unkown image
page readonly
clean
400000
unkown image
page readonly
clean
D7F000
unkown
page read and write
clean
136000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
370000
heap default
page read and write
clean
7EFB0000
unkown image
page readonly
clean
15B0000
heap private
page read and write
clean
10000000
unkown image
page readonly
clean
E0000
unkown
page read and write
clean
2120000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
44E000
unkown
page read and write
clean
190000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
23B0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
440000
heap default
page read and write
clean
23F000
heap default
page read and write
clean
584000
heap private
page read and write
clean
B0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
790000
unkown image
page readonly
clean
297000
heap default
page read and write
clean
440000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
347000
heap default
page read and write
clean
1D20000
unkown image
page readonly
clean
3F0000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
2B45000
heap private
page read and write
clean
500000
heap default
page read and write
clean
13C000
unkown
page read and write
clean
23C0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
375000
unkown
page execute and read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
EC000
unkown
page read and write
clean
440000
unkown
page read and write
clean
C50000
unkown image
page readonly
clean
23A000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
340000
unkown image
page readonly
clean
784000
heap private
page read and write
clean
50000
unkown image
page readonly
clean
5F0000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
1795000
heap private
page read and write
clean
15FF000
unkown
page read and write
clean
D20000
heap private
page read and write
clean
23A0000
heap private
page read and write
clean
2E0000
heap default
page read and write
clean
4D0000
unkown
page read and write
clean
180F000
heap private
page read and write
clean
347000
heap default
page read and write
clean
3AE000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
10000000
unkown image
page readonly
clean
400000
heap private
page read and write
clean
131E000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
365000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
27B1000
unkown
page read and write
clean
10042000
unkown image
page readonly
clean
E0000
unkown image
page read and write
clean
3F0000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
27FF000
heap private
page read and write
clean
2C5F000
heap private
page read and write
clean
8B0000
unkown
page read and write
clean
2384000
heap private
page read and write
clean
30000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
2671000
unkown
page read and write
clean
20F0000
unkown image
page readonly
clean
226000
unkown
page read and write
clean
DC000
unkown
page read and write
clean
35E000
heap default
page read and write
clean
240000
heap default
page read and write
clean
330000
heap private
page read and write
clean
710000
unkown image
page readonly
clean
61D000
unkown
page read and write
clean
1EC000
unkown
page read and write
clean
1B4F000
unkown
page read and write
clean
255E000
unkown
page read and write
clean
22DF000
heap private
page read and write
clean
200000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
206000
heap private
page read and write
clean
10000000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
307000
heap default
page read and write
clean
7DD000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
393000
heap default
page read and write
clean
476000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
30000
unkown image
page read and write
clean
7EFD0000
unkown image
page readonly
clean
11C0000
heap private
page read and write
clean
148E000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
60000
unkown image
page readonly
clean
10001000
unkown image
page execute and read and write
clean
7EFE0000
unkown image
page readonly
clean
1D20000
unkown image
page readonly
clean
19F000
heap default
page read and write
clean
27B000
unkown
page read and write
clean
4E0000
heap private
page read and write
clean
E00000
unkown image
page readonly
clean
23E0000
unkown image
page readonly
clean
340000
heap default
page read and write
clean
1A6000
heap private
page read and write
clean
2B2000
heap private
page read and write
clean
29CC000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
39A000
heap default
page read and write
clean
536000
heap private
page read and write
clean
2DD0000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
364000
unkown
page read and write
clean
4F0000
heap private
page read and write
clean
A7F000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
F0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
26E0000
heap private
page read and write
clean
23A4000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
DC000
unkown
page read and write
clean
1490000
unkown
page read and write
clean
289F000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
92F000
heap private
page read and write
clean
210000
heap default
page read and write
clean
626000
heap private
page read and write
clean
10044000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
196000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
354000
unkown
page read and write
clean
A5E000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
B0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
560000
heap private
page read and write
clean
460000
unkown image
page readonly
clean
760000
unkown image
page readonly
clean
330000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
367000
heap default
page read and write
clean
20AB000
heap private
page read and write
clean
2865000
unkown
page execute and read and write
clean
507000
heap default
page read and write
clean
E0000
heap default
page read and write
clean
5C4000
heap private
page read and write
clean
450000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
250000
unkown image
page readonly
clean
3E0000
heap default
page read and write
clean
7EFB0000
unkown image
page readonly
clean
25D0000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
294E000
unkown
page read and write
clean
E0000
unkown image
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
31E000
heap default
page read and write
clean
2ADE000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
756000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
27D000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
6B0000
unkown image
page readonly
clean
15C000
unkown
page read and write
clean
FD000
unkown
page read and write
clean
2830000
unkown
page execute and read and write
clean
340000
heap default
page read and write
clean
120000
heap default
page read and write
clean
10042000
unkown image
page readonly
clean
590000
unkown image
page readonly
clean
5F4000
heap private
page read and write
clean
820000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
2BE0000
heap private
page read and write
clean
340000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
3CA000
heap default
page read and write
clean
10000000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
7F0000
unkown image
page readonly
clean
720000
heap private
page read and write
clean
2F0000
unkown image
page read and write
clean
50000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
22C5000
heap private
page read and write
clean
4F0000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
370000
heap private
page read and write
clean
260000
unkown image
page read and write
clean
333000
heap default
page read and write
clean
710000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
516000
heap private
page read and write
clean
20000
unkown image
page readonly
clean
10044000
unkown image
page readonly
clean
E0000
unkown image
page read and write
clean
200000
heap private
page read and write
clean
34E000
unkown
page read and write
clean
950000
heap private
page read and write
clean
2070000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
6D2000
heap default
page read and write
clean
D0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
33F000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
37E000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
368000
unkown
page read and write
clean
215B000
heap private
page read and write
clean
10052000
unkown image
page readonly
clean
27CE000
unkown
page read and write
clean
2C1C000
unkown
page read and write
clean
1FC000
unkown
page read and write
clean
564000
heap private
page read and write
clean
31E000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
363000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
1EDD000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
170000
unkown image
page read and write
clean
7EFC0000
unkown image
page readonly
clean
184000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
100000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
8A000
unkown
page read and write
clean
24DF000
unkown
page read and write
clean
10000000
unkown image
page readonly
clean
1EC0000
unkown
page read and write
clean
362000
unkown
page read and write
clean
5E7000
heap default
page read and write
clean
340000
heap default
page read and write
clean
22AC000
unkown
page read and write
clean
176C000
unkown
page read and write
clean
10000000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
940000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
684000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
5A0000
heap private
page read and write
clean
660000
heap default
page read and write
clean
2D90000
unkown image
page readonly
clean
360000
heap default
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
500000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
D90000
unkown image
page readonly
clean
20000
unkown image
page read and write
clean
8F0000
unkown image
page readonly
clean
273C000
unkown
page read and write
clean
2C4000
heap private
page read and write
clean
130000
unkown image
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
292F000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
23C2000
heap private
page read and write
clean
690000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
540000
unkown image
page readonly
clean
357000
heap default
page read and write
clean
292000
heap default
page read and write
clean
60000
unkown image
page readonly
clean
85D000
unkown
page read and write
clean
21D000
unkown
page read and write
clean
6E0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
600000
unkown image
page readonly
clean
D40000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
2DD5000
heap private
page read and write
clean
1BC000
unkown
page read and write
clean
7A2000
heap private
page read and write
clean
A80000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
2CCA000
unkown
page read and write
clean
790000
unkown image
page readonly
clean
780000
unkown image
page readonly
clean
6A0000
unkown image
page readonly
clean
140000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
92F000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
25D1000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
39F000
heap default
page read and write
clean
2BE5000
heap private
page read and write
clean
600000
unkown image
page readonly
clean
E0000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
520000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
2EBE000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
22C3000
heap private
page read and write
clean
30000
unkown image
page read and write
clean
667000
heap default
page read and write
clean
50000
unkown image
page readonly
clean
2630000
heap private
page read and write
clean
2320000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
960000
unkown image
page readonly
clean
1D0000
unkown
page read and write
clean
27F000
heap default
page read and write
clean
170000
unkown image
page read and write
clean
CEC000
unkown
page read and write
clean
870000
unkown image
page readonly
clean
24F0000
heap private
page read and write
clean
800000
unkown image
page readonly
clean
2C30000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
373000
heap default
page read and write
clean
DB5000
unkown
page execute and read and write
clean
381000
unkown
page execute and read and write
clean
750000
heap private
page read and write
clean
790000
unkown
page read and write
clean
7E0000
unkown image
page readonly
clean
200000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
5F4000
heap private
page read and write
clean
780000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
20D000
unkown
page read and write
clean
470000
unkown image
page readonly
clean
400000
unkown image
page readonly
clean
2B63000
heap private
page read and write
clean
1FC000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
400000
unkown image
page readonly
clean
D80000
heap private
page read and write
clean
1C0000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
2ACE000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
730000
unkown image
page readonly
clean
224000
heap default
page read and write
clean
7EFD0000
unkown image
page readonly
clean
724000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
780000
unkown
page read and write
clean
10052000
unkown image
page readonly
clean
334000
heap private
page read and write
clean
20000
unkown image
page readonly
clean
90000
unkown
page read and write
clean
2065000
heap private
page read and write
clean
80000
unkown image
page execute and read and write
clean
7EFB0000
unkown image
page readonly
clean
123F000
heap private
page read and write
clean
7AD000
unkown
page read and write
clean
1EC000
unkown
page read and write
clean
150000
unkown
page read and write
clean
720000
unkown image
page readonly
clean
33E000
heap default
page read and write
clean
10044000
unkown image
page readonly
clean
456000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
200000
heap default
page read and write
clean
2CC000
unkown
page read and write
clean
2670000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7EFC0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
780000
heap private
page read and write
clean
680000
unkown image
page readonly
clean
25EE000
unkown
page read and write
clean
580000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
33A000
heap default
page read and write
clean
7EFC0000
unkown image
page readonly
clean
207000
heap default
page read and write
clean
126E000
unkown
page read and write
clean
4C0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
There are 796 hidden memdumps, click here to show them.