IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Compensation-2308017-09272021.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Author: Test, Last Saved By: Test, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Jun 5 19:17:20 2015, Last Saved Time/Date: Mon Sep 27 10:38:52 2021, Security: 0
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\44466.7516903935[1].dat
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\44466.7516903935[2].dat
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\44466.7516903935[3].dat
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Drezd.red
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Drezd1.red
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Drezd2.red
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\VBE\MSForms.exd
data
dropped
clean
C:\Users\user\AppData\Local\Temp\VBE\RefEdit.exd
data
dropped
clean
C:\Windows\System32\wbem\Performance\WmiApRpl_new.h
ASCII text, with CRLF line terminators
dropped
clean
C:\Windows\System32\wbem\Performance\WmiApRpl_new.ini
Little-endian UTF-16 Unicode text, with CRLF, CR line terminators
dropped
clean
C:\Windows\system32\wbem\Performance\WmiApRpl.hec (copy)
ASCII text, with CRLF line terminators
dropped
clean
There are 2 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Drezd.red
malicious
C:\Windows\SysWOW64\regsvr32.exe
-silent ..\Drezd.red
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Drezd1.red
malicious
C:\Windows\SysWOW64\schtasks.exe
'C:\Windows\system32\schtasks.exe' /Create /RU 'NT AUTHORITY\SYSTEM' /tn icvxxob /tr 'regsvr32.exe -s \'C:\Users\user\Drezd.red\'' /SC ONCE /Z /ST 18:04 /ET 18:16
malicious
C:\Windows\SysWOW64\regsvr32.exe
-silent ..\Drezd1.red
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Drezd2.red
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\SysWOW64\regsvr32.exe
-silent ..\Drezd2.red
malicious
C:\Windows\System32\reg.exe
C:\Windows\system32\reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths' /f /t REG_DWORD /v 'C:\ProgramData\Microsoft\Tououa' /d '0'
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\System32\reg.exe
C:\Windows\system32\reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths' /f /t REG_DWORD /v 'C:\Users\user\AppData\Roaming\Microsoft\Gnydpduzkfqu' /d '0'
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\System32\wbem\WMIADAP.exe
wmiadap.exe /F /T /R
clean
There are 9 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://www.%s.comPA
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://185.250.148.213/44466.7516903935.dat
185.250.148.213
clean
http://servername/isapibackend.dll
unknown
clean
http://185.183.96.67/44466.7516903935.dat
185.183.96.67
clean
http://190.14.37.178/44466.7516903935.dat
190.14.37.178
clean

IPs

IP
Domain
Country
Malicious
185.183.96.67
unknown
Netherlands
clean
190.14.37.178
unknown
Panama
clean
185.250.148.213
unknown
Russian Federation
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
1%-
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2F5B4
2F5B4
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{674E5CEC-03BC-46F9-9B6B-9ED841B1AF4B}\2.0
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{674E5CEC-03BC-46F9-9B6B-9ED841B1AF4B}\2.0\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{674E5CEC-03BC-46F9-9B6B-9ED841B1AF4B}\2.0\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{674E5CEC-03BC-46F9-9B6B-9ED841B1AF4B}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{674E5CEC-03BC-46F9-9B6B-9ED841B1AF4B}\2.0
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{674E5CEC-03BC-46F9-9B6B-9ED841B1AF4B}\2.0\FLAGS
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{674E5CEC-03BC-46F9-9B6B-9ED841B1AF4B}\2.0\0\win32
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{674E5CEC-03BC-46F9-9B6B-9ED841B1AF4B}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{2A06D78C-5748-41E1-A3FB-41F960B30EDE}\1.2
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{2A06D78C-5748-41E1-A3FB-41F960B30EDE}\1.2\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{2A06D78C-5748-41E1-A3FB-41F960B30EDE}\1.2\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{2A06D78C-5748-41E1-A3FB-41F960B30EDE}\1.2\HELPDIR
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00024518-0000-0000-C000-000000000046}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
1-
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\3A2A5
3A2A5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\3A525
3A525
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_CURRENT_USER\Software\Microsoft\Kzhleibyf
9438916a
clean
HKEY_CURRENT_USER\Software\Microsoft\Kzhleibyf
a1a74124
clean
HKEY_CURRENT_USER\Software\Microsoft\Kzhleibyf
a3e66158
clean
HKEY_CURRENT_USER\Software\Microsoft\Kzhleibyf
1b5a063d
clean
HKEY_CURRENT_USER\Software\Microsoft\Kzhleibyf
665249b7
clean
HKEY_CURRENT_USER\Software\Microsoft\Kzhleibyf
deee2ed2
clean
HKEY_CURRENT_USER\Software\Microsoft\Kzhleibyf
191b2641
clean
HKEY_CURRENT_USER\Software\Microsoft\Kzhleibyf
eb71fe9c
clean
HKEY_CURRENT_USER\Software\Microsoft\Kzhleibyf
9438916a
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Seciucquxdfey
71ed1234
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Seciucquxdfey
4472c27a
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Seciucquxdfey
4633e206
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Seciucquxdfey
fe8f8563
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Seciucquxdfey
8387cae9
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Seciucquxdfey
3b3bad8c
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Seciucquxdfey
fccea51f
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Seciucquxdfey
ea47dc2
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Seciucquxdfey
71ed1234
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
C:\ProgramData\Microsoft\Tououa
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
C:\Users\user\AppData\Roaming\Microsoft\Gnydpduzkfqu
clean
There are 212 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
20000
unkown image
page readonly
clean
6F0000
unkown image
page readonly
clean
208D000
unkown
page read and write
clean
80000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
600000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
6F0000
unkown image
page readonly
clean
90000
unkown image
page read and write
clean
7EFC2000
unkown image
page readonly
clean
BB0000
unkown
page read and write
clean
2A8E000
unkown
page read and write
clean
17C000
unkown
page read and write
clean
1F80000
unkown
page read and write
clean
2730000
unkown
page read and write
clean
2BEF000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
130E000
unkown
page read and write
clean
180000
unkown
page read and write
clean
2A1000
unkown
page execute and read and write
clean
10052000
unkown image
page readonly
clean
540000
heap private
page read and write
clean
160000
unkown image
page read and write
clean
1C80000
unkown image
page readonly
clean
790000
unkown image
page readonly
clean
269C000
unkown
page read and write
clean
80000
unkown
page read and write
clean
250000
heap private
page read and write
clean
670000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
26C0000
unkown
page read and write
clean
240000
unkown
page read and write
clean
C0000
unkown image
page readonly
clean
500000
heap private
page read and write
clean
177000
heap default
page read and write
clean
173C000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
790000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
1C80000
unkown image
page readonly
clean
2520000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
2821000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
30000
unkown image
page read and write
clean
690000
unkown image
page readonly
clean
170000
unkown
page read and write
clean
6D0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
19EF000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
255000
unkown
page execute and read and write
clean
1C0000
heap default
page read and write
clean
11AE000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
A7000
heap default
page read and write
clean
C00000
unkown
page read and write
clean
640000
heap private
page read and write
clean
360000
heap default
page read and write
clean
15C000
unkown
page read and write
clean
10042000
unkown image
page readonly
clean
10001000
unkown image
page execute and read and write
clean
7EFB0000
unkown image
page readonly
clean
A0000
heap default
page read and write
clean
1CA000
unkown
page read and write
clean
259F000
heap private
page read and write
clean
7A0000
unkown image
page readonly
clean
170000
heap default
page read and write
clean
2170000
unkown image
page readonly
clean
600000
unkown image
page readonly
clean
1D0000
unkown
page execute and read and write
clean
50000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
10000000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
2C6E000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
920000
unkown image
page readonly
clean
3B0000
unkown
page read and write
clean
930000
unkown image
page readonly
clean
340000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
7EFB2000
unkown image
page readonly
clean
2770000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
25E000
unkown
page read and write
clean
780000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
2E0000
heap private
page read and write
clean
2D1F000
heap private
page read and write
clean
7EFDF000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
380000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
1EC000
unkown
page read and write
clean
4E6000
unkown
page read and write
clean
70000
unkown image
page read and write
clean
1BA000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
DC000
unkown
page read and write
clean
2B0000
heap default
page read and write
clean
30000
unkown image
page readonly
clean
190000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
40F000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
251F000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
2B50000
heap private
page read and write
clean
490000
heap private
page read and write
clean
B9D000
unkown
page read and write
clean
2560000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
D0000
heap default
page read and write
clean
2D4000
heap default
page read and write
clean
690000
unkown image
page readonly
clean
10042000
unkown image
page readonly
clean
3B0000
unkown image
page readonly
clean
295C000
unkown
page read and write
clean
CD0000
heap private
page read and write
clean
45D000
unkown
page read and write
clean
322000
heap default
page read and write
clean
1EC000
unkown
page read and write
clean
24F0000
unkown image
page readonly
clean
794000
heap private
page read and write
clean
40000
unkown image
page readonly
clean
170000
heap private
page read and write
clean
10044000
unkown image
page readonly
clean
211000
unkown
page execute and read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
684000
heap private
page read and write
clean
20000
unkown image
page readonly
clean
15CF000
unkown
page read and write
clean
590000
heap default
page read and write
clean
1D00000
unkown image
page readonly
clean
470000
unkown image
page readonly
clean
DE000
heap default
page read and write
clean
3E6000
unkown
page read and write
clean
626000
heap private
page read and write
clean
860000
unkown image
page readonly
clean
120000
unkown
page read and write
clean
1AE000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
470000
heap private
page read and write
clean
260000
heap default
page read and write
clean
4B0000
unkown
page read and write
clean
17F5000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
2731000
unkown
page read and write
clean
261E000
unkown
page read and write
clean
C0000
unkown image
page readonly
clean
123000
heap default
page read and write
clean
64F000
heap default
page read and write
clean
286F000
unkown
page read and write
clean
600000
heap private
page read and write
clean
364000
heap private
page read and write
clean
610000
heap default
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
2CA000
heap default
page read and write
clean
3B3000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
410000
heap private
page read and write
clean
281F000
heap private
page read and write
clean
22E000
heap default
page read and write
clean
1E0000
unkown image
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
3FE000
unkown
page read and write
clean
B8F000
unkown
page read and write
clean
5E2000
unkown
page read and write
clean
11C000
unkown
page read and write
clean
3A6000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
80000
unkown image
page execute and read and write
clean
264000
heap default
page read and write
clean
2CAE000
unkown
page read and write
clean
2B7000
heap default
page read and write
clean
42B000
heap private
page read and write
clean
36E000
unkown
page read and write
clean
3A4000
heap default
page read and write
clean
50000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
6DE000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
3A0000
heap private
page read and write
clean
279F000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
26BE000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
510000
unkown
page read and write
clean
550000
unkown image
page readonly
clean
674000
heap private
page read and write
clean
25AF000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
10042000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
5C6000
heap private
page read and write
clean
3A6000
unkown
page read and write
clean
550000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7D0000
heap private
page read and write
clean
634000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
25EE000
unkown
page read and write
clean
134F000
unkown
page read and write
clean
7C0000
unkown image
page readonly
clean
1E0000
heap default
page read and write
clean
616000
heap private
page read and write
clean
720000
heap private
page read and write
clean
5E0000
unkown
page execute and read and write
clean
247000
heap default
page read and write
clean
60000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
552000
heap default
page read and write
clean
2570000
unkown image
page readonly
clean
27EF000
heap private
page read and write
clean
520000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
160000
unkown
page read and write
clean
45F000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
23C000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
B0000
unkown
page read and write
clean
370000
unkown
page read and write
clean
80000
unkown image
page execute and read and write
clean
1FF0000
unkown image
page readonly
clean
F40000
unkown image
page readonly
clean
26B000
unkown
page read and write
clean
5E8000
unkown
page read and write
clean
C30000
heap private
page read and write
clean
26C1000
unkown
page read and write
clean
E0000
unkown image
page read and write
clean
560000
heap private
page read and write
clean
62F000
heap private
page read and write
clean
621000
unkown
page execute and read and write
clean
60000
unkown image
page readonly
clean
810000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
7EFC0000
unkown image
page readonly
clean
17F0000
heap private
page read and write
clean
21D000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
3F2000
heap default
page read and write
clean
2CA5000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
6F0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
7EFC0000
unkown image
page readonly
clean
285E000
unkown
page read and write
clean
170000
unkown image
page read and write
clean
2EF000
heap default
page read and write
clean
2D3E000
unkown
page read and write
clean
70000
unkown image
page read and write
clean
2710000
heap private
page read and write
clean
597000
heap default
page read and write
clean
680000
unkown image
page readonly
clean
1CD000
unkown
page read and write
clean
880000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
1ADE000
unkown
page read and write
clean
FC000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
EE0000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
340000
heap default
page read and write
clean
10000000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
73F000
unkown
page read and write
clean
380000
heap default
page read and write
clean
7EFDF000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
7EFC2000
unkown image
page readonly
clean
1F0000
unkown image
page read and write
clean
7EFD0000
unkown image
page readonly
clean
281F000
heap private
page read and write
clean
151C000
unkown
page read and write
clean
2820000
heap private
page read and write
clean
30000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
2CB0000
unkown image
page readonly
clean
23A000
heap default
page read and write
clean
80000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2052000
heap private
page read and write
clean
20000
unkown image
page readonly
clean
10052000
unkown image
page readonly
clean
360000
heap private
page read and write
clean
30000
unkown image
page readonly
clean
230000
heap private
page read and write
clean
2034000
heap private
page read and write
clean
620000
heap private
page read and write
clean
C10000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
670000
heap private
page read and write
clean
10001000
unkown image
page execute and read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
630000
unkown
page read and write
clean
30000
unkown image
page read and write
clean
4E0000
unkown
page read and write
clean
220000
heap default
page read and write
clean
270000
heap default
page read and write
clean
50000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
1880000
heap private
page read and write
clean
270000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
153000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
5B0000
heap private
page read and write
clean
2070000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
90000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
12CC000
unkown
page read and write
clean
2C6C000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
DBF000
unkown
page read and write
clean
2821000
unkown
page read and write
clean
69C000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
620000
unkown image
page readonly
clean
710000
unkown image
page readonly
clean
116000
unkown
page read and write
clean
261000
unkown
page execute and read and write
clean
2B70000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
5B4000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
152000
unkown
page read and write
clean
30000
unkown image
page read and write
clean
7EFB0000
unkown image
page readonly
clean
546000
heap private
page read and write
clean
3C0000
heap default
page read and write
clean
284000
heap default
page read and write
clean
3BA000
heap default
page read and write
clean
3A4000
heap private
page read and write
clean
10000000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
2F0000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
770000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
150000
unkown
page read and write
clean
516000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
10044000
unkown image
page readonly
clean
5E0000
unkown image
page readonly
clean
6C0000
heap private
page read and write
clean
25F0000
heap private
page read and write
clean
A30000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
C91000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
25AF000
heap private
page read and write
clean
62F000
heap private
page read and write
clean
50000
unkown image
page readonly
clean
5D3000
unkown
page read and write
clean
360000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
198F000
unkown
page read and write
clean
1EC0000
unkown image
page readonly
clean
243000
heap default
page read and write
clean
7EFB0000
unkown image
page readonly
clean
BEF000
unkown
page read and write
clean
330000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
2F0000
unkown
page read and write
clean
DBF000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
610000
heap private
page read and write
clean
41E000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
272000
heap private
page read and write
clean
63B000
heap private
page read and write
clean
4E7000
heap default
page read and write
clean
205000
unkown
page execute and read and write
clean
546000
unkown
page read and write
clean
C8F000
unkown
page read and write
clean
10000000
unkown image
page readonly
clean
D7000
heap default
page read and write
clean
506000
unkown
page read and write
clean
130000
unkown image
page read and write
clean
10E000
heap default
page read and write
clean
E0000
unkown image
page execute and read and write
clean
4C4000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
250000
heap private
page read and write
clean
10052000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
90000
unkown image
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
1C0000
unkown
page read and write
clean
820000
unkown image
page readonly
clean
90000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
9A0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
8A0000
unkown image
page readonly
clean
186F000
heap private
page read and write
clean
760000
unkown image
page readonly
clean
259F000
heap private
page read and write
clean
680000
heap private
page read and write
clean
40000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
D0000
unkown image
page read and write
clean
267000
heap default
page read and write
clean
7EFDF000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
10A0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
2B93000
heap private
page read and write
clean
2180000
unkown image
page readonly
clean
1D0000
unkown
page read and write
clean
1C2F000
unkown
page read and write
clean
10044000
unkown image
page readonly
clean
496000
heap private
page read and write
clean
281F000
heap private
page read and write
clean
B40000
heap private
page read and write
clean
10000000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
20000
unkown image
page read and write
clean
13C000
unkown
page read and write
clean
62F000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
4B4000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
94000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
1A4000
heap private
page read and write
clean
16FE000
unkown
page read and write
clean
1DB0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
DA000
unkown
page read and write
clean
460000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
200000
heap default
page read and write
clean
20000
unkown image
page readonly
clean
E0000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
2775000
heap private
page read and write
clean
2A3C000
unkown
page read and write
clean
662000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
1BC000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
277000
heap default
page read and write
clean
3F5000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
3BF000
heap default
page read and write
clean
E0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
5DF000
unkown
page read and write
clean
BC000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
160000
unkown image
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
26E0000
heap private
page read and write
clean
271F000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
5D5000
heap default
page read and write
clean
400000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
CEE000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
281F000
heap private
page read and write
clean
850000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
270000
unkown image
page readonly
clean
2B75000
heap private
page read and write
clean
20CE000
unkown
page read and write
clean
497000
heap default
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
170000
unkown
page read and write
clean
605000
heap private
page read and write
clean
7EFDF000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
BC000
unkown
page read and write
clean
3D0000
unkown image
page readonly
clean
AC000
unkown
page read and write
clean
4B0000
heap private
page read and write
clean
10000000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
2E0000
unkown
page read and write
clean
2C3000
heap default
page read and write
clean
C2D000
unkown
page read and write
clean
D7F000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
900000
unkown image
page readonly
clean
DD000
unkown
page read and write
clean
C90000
unkown
page read and write
clean
530000
unkown image
page readonly
clean
B0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
370000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
D00000
heap private
page read and write
clean
780000
unkown image
page readonly
clean
90000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
496000
unkown
page read and write
clean
10000000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
14C000
unkown
page read and write
clean
1F9D000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
2144000
heap private
page read and write
clean
254000
heap private
page read and write
clean
1CF0000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
615000
unkown
page execute and read and write
clean
600000
unkown image
page readonly
clean
3B0000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
4D4000
heap private
page read and write
clean
760000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
2C2B000
unkown
page read and write
clean
1813000
heap private
page read and write
clean
2030000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
387000
heap default
page read and write
clean
2CA0000
heap private
page read and write
clean
51A000
heap default
page read and write
clean
7EFB0000
unkown image
page readonly
clean
B0000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
440000
unkown
page read and write
clean
30000
unkown image
page read and write
clean
10044000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
2D4000
heap default
page read and write
clean
450000
unkown image
page readonly
clean
260000
unkown
page execute and read and write
clean
27B000
unkown
page read and write
clean
1C2000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
270000
heap private
page read and write
clean
67C000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
11E0000
heap private
page read and write
clean
25FF000
unkown
page read and write
clean
24EE000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
4B0000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
150000
unkown
page read and write
clean
566000
heap private
page read and write
clean
10D000
unkown
page read and write
clean
D0000
unkown
page read and write
clean
10042000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
2140000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
147000
heap default
page read and write
clean
7EFB0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
150000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
2D6000
unkown
page read and write
clean
27A000
heap default
page read and write
clean
10A0000
unkown image
page readonly
clean
5F0000
unkown image
page readonly
clean
570000
unkown image
page readonly
clean
504000
heap default
page read and write
clean
1380000
heap private
page read and write
clean
154000
unkown
page read and write
clean
213F000
unkown
page read and write
clean
617000
heap default
page read and write
clean
20000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
1FBE000
unkown
page read and write
clean
275F000
unkown
page read and write
clean
10000000
unkown image
page readonly
clean
160000
unkown image
page read and write
clean
1A0000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
2AF0000
heap private
page read and write
clean
60000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
27F000
heap default
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
280000
unkown
page read and write
clean
286F000
unkown
page read and write
clean
316000
unkown
page read and write
clean
A0D000
unkown
page read and write
clean
10000000
unkown image
page readonly
clean
290000
heap private
page read and write
clean
649000
heap default
page read and write
clean
24A000
heap default
page read and write
clean
20000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
180000
unkown
page read and write
clean
272E000
unkown
page read and write
clean
21E000
heap default
page read and write
clean
60000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
9F0000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
1F7000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
2861000
unkown
page read and write
clean
B4F000
unkown
page read and write
clean
440000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
5D0000
unkown image
page readonly
clean
39E000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2100000
unkown image
page readonly
clean
614000
heap private
page read and write
clean
E0000
unkown image
page execute and read and write
clean
2A0000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
480000
unkown image
page readonly
clean
820000
unkown image
page readonly
clean
5DB000
unkown
page read and write
clean
3F0000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
530000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
100000
heap default
page read and write
clean
B80000
unkown
page read and write
clean
5E0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
1E7000
heap default
page read and write
clean
80000
unkown
page read and write
clean
158000
unkown
page read and write
clean
27A0000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
160000
heap private
page read and write
clean
BD000
unkown
page read and write
clean
2B0000
heap default
page read and write
clean
7EFDF000
unkown
page read and write
clean
10001000
unkown image
page execute and read and write
clean
220000
unkown
page execute and read and write
clean
326000
unkown
page read and write
clean
646000
heap private
page read and write
clean
1A0000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
800000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
270000
unkown
page read and write
clean
20000
unkown image
page read and write
clean
2162000
heap private
page read and write
clean
155000
unkown
page read and write
clean
2FE000
unkown
page read and write
clean
51F000
heap default
page read and write
clean
480000
unkown image
page readonly
clean
2350000
heap private
page read and write
clean
504000
heap private
page read and write
clean
233000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
2820000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
5E6000
unkown
page read and write
clean
6C6000
heap private
page read and write
clean
2530000
heap private
page read and write
clean
5D0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
12A000
heap default
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
C0000
unkown image
page readonly
clean
236000
heap private
page read and write
clean
4C0000
heap private
page read and write
clean
29D000
unkown
page read and write
clean
2EA000
heap default
page read and write
clean
1B5E000
unkown
page read and write
clean
490000
heap default
page read and write
clean
10052000
unkown image
page readonly
clean
2355000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
295000
unkown
page execute and read and write
clean
2AE000
heap default
page read and write
clean
F0000
unkown
page read and write
clean
890000
unkown image
page readonly
clean
3B9000
heap default
page read and write
clean
20000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
367000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
20B0000
unkown image
page readonly
clean
5C0000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
4D0000
unkown
page read and write
clean
2793000
heap private
page read and write
clean
810000
unkown image
page readonly
clean
610000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
2852000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
2B7000
heap default
page read and write
clean
760000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
D10000
unkown image
page readonly
clean
2000000
unkown
page read and write
clean
750000
unkown image
page readonly
clean
810000
unkown image
page readonly
clean
770000
unkown image
page readonly
clean
3A0000
unkown image
page readonly
clean
2CC3000
heap private
page read and write
clean
580000
unkown image
page readonly
clean
4B4000
heap default
page read and write
clean
20000
unkown image
page readonly
clean
1F0000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
2B2000
heap default
page read and write
clean
144000
unkown
page read and write
clean
291E000
unkown
page read and write
clean
4D0000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
240000
heap default
page read and write
clean
5DD000
heap default
page read and write
clean
4B4000
heap private
page read and write
clean
238B000
heap private
page read and write
clean
26B000
unkown
page read and write
clean
201D000
unkown
page read and write
clean
10001000
unkown image
page execute and read and write
clean
4E0000
heap default
page read and write
clean
There are 794 hidden memdumps, click here to show them.