IOC Report

loading gif

Files

File Path
Type
Category
Malicious
#Qbot downloader.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Author: Test, Last Saved By: Test, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Jun 5 19:17:20 2015, Last Saved Time/Date: Mon Sep 27 10:38:52 2021, Security: 0
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\44466.8890891204[1].dat
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\44466.8890891204[2].dat
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Drezd.red
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Drezd1.red
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\VBE\MSForms.exd
data
dropped
clean
C:\Users\user\AppData\Local\Temp\VBE\RefEdit.exd
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Drezd.red
malicious
C:\Windows\SysWOW64\regsvr32.exe
-silent ..\Drezd.red
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Drezd1.red
malicious
C:\Windows\SysWOW64\schtasks.exe
'C:\Windows\system32\schtasks.exe' /Create /RU 'NT AUTHORITY\SYSTEM' /tn vevmwwj /tr 'regsvr32.exe -s \'C:\Users\user\Drezd.red\'' /SC ONCE /Z /ST 21:23 /ET 21:35
malicious
C:\Windows\SysWOW64\regsvr32.exe
-silent ..\Drezd1.red
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Drezd2.red
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\System32\reg.exe
C:\Windows\system32\reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths' /f /t REG_DWORD /v 'C:\ProgramData\Microsoft\Krngnamoimcp' /d '0'
malicious
C:\Windows\System32\reg.exe
C:\Windows\system32\reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths' /f /t REG_DWORD /v 'C:\Users\user\AppData\Roaming\Microsoft\Waizacawzvcu' /d '0'
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\Drezd.red'
malicious
There are 6 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://www.%s.comPA
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://185.183.96.67/44466.8890891204.dat
185.183.96.67
clean
http://190.14.37.178/44466.8890891204.dat
190.14.37.178
clean
http://servername/isapibackend.dll
unknown
clean

IPs

IP
Domain
Country
Malicious
185.183.96.67
unknown
Netherlands
clean
190.14.37.178
unknown
Panama
clean
185.250.148.213
unknown
Russian Federation
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
9|%
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2D3B3
2D3B3
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8A697CDF-B101-4FF3-9D9F-82FCCD82AABE}\2.0
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8A697CDF-B101-4FF3-9D9F-82FCCD82AABE}\2.0\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8A697CDF-B101-4FF3-9D9F-82FCCD82AABE}\2.0\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8A697CDF-B101-4FF3-9D9F-82FCCD82AABE}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{8A697CDF-B101-4FF3-9D9F-82FCCD82AABE}\2.0
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{8A697CDF-B101-4FF3-9D9F-82FCCD82AABE}\2.0\FLAGS
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{8A697CDF-B101-4FF3-9D9F-82FCCD82AABE}\2.0\0\win32
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{8A697CDF-B101-4FF3-9D9F-82FCCD82AABE}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0EE786B9-C102-4775-8FD9-C5CB86B313A1}\1.2
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0EE786B9-C102-4775-8FD9-C5CB86B313A1}\1.2\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0EE786B9-C102-4775-8FD9-C5CB86B313A1}\1.2\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0EE786B9-C102-4775-8FD9-C5CB86B313A1}\1.2\HELPDIR
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00024518-0000-0000-C000-000000000046}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
s&%
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\44F77
44F77
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\451D8
451D8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_CURRENT_USER\Software\Microsoft\Aknouuyuwy
2cbbc103
clean
HKEY_CURRENT_USER\Software\Microsoft\Aknouuyuwy
1924114d
clean
HKEY_CURRENT_USER\Software\Microsoft\Aknouuyuwy
1b653131
clean
HKEY_CURRENT_USER\Software\Microsoft\Aknouuyuwy
a3d95654
clean
HKEY_CURRENT_USER\Software\Microsoft\Aknouuyuwy
ded119de
clean
HKEY_CURRENT_USER\Software\Microsoft\Aknouuyuwy
666d7ebb
clean
HKEY_CURRENT_USER\Software\Microsoft\Aknouuyuwy
a1987628
clean
HKEY_CURRENT_USER\Software\Microsoft\Aknouuyuwy
53f2aef5
clean
HKEY_CURRENT_USER\Software\Microsoft\Aknouuyuwy
2cbbc103
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Bjuybfbrscu
aeb92bad
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Bjuybfbrscu
9b26fbe3
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Bjuybfbrscu
9967db9f
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Bjuybfbrscu
21dbbcfa
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Bjuybfbrscu
5cd3f370
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Bjuybfbrscu
e46f9415
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Bjuybfbrscu
239a9c86
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Bjuybfbrscu
d1f0445b
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Bjuybfbrscu
aeb92bad
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
C:\ProgramData\Microsoft\Krngnamoimcp
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
C:\Users\user\AppData\Roaming\Microsoft\Waizacawzvcu
clean
There are 212 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
80000
unkown image
page execute and read and write
malicious
10001000
unkown image
page execute and read and write
malicious
10001000
unkown image
page execute and read and write
malicious
270000
unkown
page read and write
malicious
190000
unkown
page read and write
malicious
80000
unkown image
page execute and read and write
malicious
80000
unkown image
page execute and read and write
malicious
440000
unkown
page read and write
malicious
10001000
unkown image
page execute and read and write
malicious
2860000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
BFE000
unkown
page read and write
clean
17AE000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
390000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
1E6000
unkown
page read and write
clean
2E50000
heap private
page read and write
clean
470000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
394000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
6F0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
367000
heap default
page read and write
clean
E9F000
heap private
page read and write
clean
E0000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
1EA0000
unkown image
page readonly
clean
7F0000
unkown image
page readonly
clean
510000
unkown
page read and write
clean
3FD000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
2A2000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
60000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
220000
heap default
page read and write
clean
3D4000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
464000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
924000
heap private
page read and write
clean
C0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
2E0000
heap default
page read and write
clean
4F0000
unkown
page read and write
clean
26EA000
unkown
page read and write
clean
356000
unkown
page read and write
clean
70000
unkown image
page read and write
clean
7EFC0000
unkown image
page readonly
clean
220000
heap default
page read and write
clean
487000
heap default
page read and write
clean
45D000
unkown
page read and write
clean
27A000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
32D000
heap default
page read and write
clean
7EFDF000
unkown
page read and write
clean
164F000
heap private
page read and write
clean
325000
heap default
page read and write
clean
2700000
heap private
page read and write
clean
496000
unkown
page read and write
clean
130E000
unkown
page read and write
clean
FD000
unkown
page read and write
clean
950000
unkown image
page readonly
clean
5F0000
unkown image
page readonly
clean
B0F000
unkown
page read and write
clean
BB000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2274000
heap private
page read and write
clean
30000
unkown image
page read and write
clean
4F2000
heap default
page read and write
clean
10042000
unkown image
page readonly
clean
264F000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
240000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
18AF000
unkown
page read and write
clean
4D1000
unkown
page execute and read and write
clean
7EFC0000
unkown image
page readonly
clean
460000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
10000
unkown image
page read and write
clean
100000
unkown image
page read and write
clean
25FF000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
1DB000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
190000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
510000
unkown image
page readonly
clean
217B000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
29E0000
heap private
page read and write
clean
190000
heap default
page read and write
clean
40000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
F0000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
514000
heap private
page read and write
clean
3E0000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
B0000
unkown image
page readonly
clean
7BA000
heap default
page read and write
clean
1F0000
heap default
page read and write
clean
10000000
unkown image
page readonly
clean
2A3000
unkown
page read and write
clean
13BF000
unkown
page read and write
clean
2AD000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
2C6C000
unkown
page read and write
clean
780000
heap default
page read and write
clean
370000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
50000
unkown image
page readonly
clean
10052000
unkown image
page readonly
clean
664000
heap private
page read and write
clean
510000
heap private
page read and write
clean
40000
unkown image
page readonly
clean
100000
unkown image
page read and write
clean
20000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
800000
unkown image
page readonly
clean
15F3000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
2E4000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
7EFC0000
unkown image
page readonly
clean
55E000
unkown
page read and write
clean
DF0000
heap private
page read and write
clean
20000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
447000
heap default
page read and write
clean
6B4000
heap private
page read and write
clean
32B000
unkown
page read and write
clean
6D0000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
140000
heap private
page read and write
clean
1B4000
heap private
page read and write
clean
546000
unkown
page read and write
clean
360000
heap default
page read and write
clean
10042000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
280F000
unkown
page read and write
clean
297000
heap default
page read and write
clean
2A4000
unkown
page read and write
clean
7BF000
heap default
page read and write
clean
4A4000
heap default
page read and write
clean
6E0000
unkown image
page readonly
clean
600000
unkown image
page readonly
clean
940000
heap private
page read and write
clean
220E000
unkown
page read and write
clean
2B8000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
790000
unkown image
page readonly
clean
180000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
570000
unkown image
page readonly
clean
150000
unkown
page read and write
clean
5CF000
heap default
page read and write
clean
1A0000
heap default
page read and write
clean
10052000
unkown image
page readonly
clean
2CDE000
unkown
page read and write
clean
25E000
heap default
page read and write
clean
F0000
unkown
page read and write
clean
EAF000
unkown
page read and write
clean
24A000
heap default
page read and write
clean
1E3000
heap default
page read and write
clean
605000
unkown
page execute and read and write
clean
74E000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
C60000
unkown
page read and write
clean
42C000
unkown
page read and write
clean
410000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
22D000
unkown
page read and write
clean
C0000
unkown image
page read and write
clean
940000
unkown image
page readonly
clean
3F0000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
16FE000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
370000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
277000
heap default
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
910000
unkown image
page readonly
clean
156E000
unkown
page read and write
clean
1D40000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
10044000
unkown image
page readonly
clean
26FF000
unkown
page read and write
clean
426000
unkown
page read and write
clean
150000
unkown
page read and write
clean
2E1F000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
2B70000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
2DC3000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
3D0000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
15A000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
840000
unkown image
page readonly
clean
FD000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
B0000
unkown
page read and write
clean
2C0000
heap default
page read and write
clean
60000
unkown image
page readonly
clean
26D000
unkown
page read and write
clean
2C4E000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
19C000
unkown
page read and write
clean
12B0000
heap private
page read and write
clean
590000
heap default
page read and write
clean
510000
heap private
page read and write
clean
336000
unkown
page read and write
clean
597000
heap default
page read and write
clean
7EFB0000
unkown image
page readonly
clean
1B0000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
22B0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
11C0000
heap private
page read and write
clean
A0000
unkown image
page readonly
clean
E7E000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
5E0000
heap private
page read and write
clean
410000
heap private
page read and write
clean
370000
unkown image
page read and write
clean
FE0000
unkown image
page readonly
clean
10052000
unkown image
page readonly
clean
2C7000
heap default
page read and write
clean
7B0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
228B000
heap private
page read and write
clean
240000
heap default
page read and write
clean
10042000
unkown image
page readonly
clean
2D6F000
unkown
page read and write
clean
304000
heap default
page read and write
clean
6C0000
unkown image
page readonly
clean
850000
unkown image
page readonly
clean
90000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
2741000
unkown
page read and write
clean
20000
unkown image
page read and write
clean
6F0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
AE0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
283000
heap default
page read and write
clean
243000
heap default
page read and write
clean
170000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
390000
heap default
page read and write
clean
13D000
unkown
page read and write
clean
600000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
540000
unkown image
page readonly
clean
110000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
11D1000
unkown
page read and write
clean
5E0000
unkown image
page readonly
clean
2110000
unkown
page execute and read and write
clean
2B0000
heap default
page read and write
clean
450000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
200000
unkown image
page readonly
clean
7A0000
unkown image
page readonly
clean
2B6000
heap default
page read and write
clean
20000
unkown image
page read and write
clean
787000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
3C0000
heap default
page read and write
clean
50000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
920000
heap private
page read and write
clean
2DFE000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
2740000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
21DB000
heap private
page read and write
clean
27C1000
unkown
page read and write
clean
27CE000
unkown
page read and write
clean
940000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
611000
unkown
page execute and read and write
clean
273000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
1EC000
unkown
page read and write
clean
2E0000
heap default
page read and write
clean
140F000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
5E6000
heap private
page read and write
clean
2870000
heap private
page read and write
clean
38C000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
197000
heap default
page read and write
clean
E6F000
heap private
page read and write
clean
22E000
heap default
page read and write
clean
1D10000
unkown image
page readonly
clean
10000000
unkown image
page readonly
clean
2250000
heap private
page read and write
clean
20000
heap private
page read and write
clean
870000
unkown image
page readonly
clean
1C0000
unkown
page read and write
clean
237000
heap default
page read and write
clean
410000
unkown
page read and write
clean
5B4000
heap default
page read and write
clean
21A0000
unkown image
page readonly
clean
2A8000
unkown
page read and write
clean
430000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
460000
unkown image
page readonly
clean
1D0000
unkown
page read and write
clean
160000
unkown image
page read and write
clean
39E000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
1DC000
unkown
page read and write
clean
322000
heap default
page read and write
clean
B0000
unkown
page read and write
clean
28A000
heap default
page read and write
clean
100000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
10044000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
364000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
320000
unkown
page read and write
clean
150000
heap default
page read and write
clean
5CE000
unkown
page read and write
clean
1BB000
unkown
page read and write
clean
414000
heap private
page read and write
clean
40000
unkown image
page readonly
clean
2780000
heap private
page read and write
clean
6D6000
heap private
page read and write
clean
2F0000
unkown image
page readonly
clean
2A80000
heap private
page read and write
clean
2BF000
unkown
page read and write
clean
2A5000
unkown
page read and write
clean
1ED000
unkown
page read and write
clean
28DF000
heap private
page read and write
clean
2255000
heap private
page read and write
clean
294000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
146F000
unkown
page read and write
clean
2140000
heap private
page read and write
clean
2DA0000
heap private
page read and write
clean
7EFDF000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
2C6000
unkown
page read and write
clean
2DA5000
heap private
page read and write
clean
1F7000
heap default
page read and write
clean
198C000
unkown
page read and write
clean
338000
unkown
page read and write
clean
440000
unkown
page read and write
clean
2270000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
C7D000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
28DF000
heap private
page read and write
clean
2801000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
E6F000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
2D4000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
E0000
unkown image
page read and write
clean
21A0000
heap private
page read and write
clean
E0000
unkown image
page read and write
clean
4BF000
heap default
page read and write
clean
261F000
unkown
page read and write
clean
5E2000
heap default
page read and write
clean
50000
unkown image
page readonly
clean
5CF000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
144000
heap private
page read and write
clean
60000
unkown image
page readonly
clean
500000
heap private
page read and write
clean
1BC000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
26BE000
unkown
page read and write
clean
780000
unkown image
page readonly
clean
660000
heap private
page read and write
clean
946000
heap private
page read and write
clean
AC000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
130000
unkown image
page read and write
clean
520000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
293000
heap default
page read and write
clean
160000
unkown image
page read and write
clean
700000
unkown image
page readonly
clean
360000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2E0000
heap default
page read and write
clean
2E9000
heap default
page read and write
clean
1EA000
heap default
page read and write
clean
1ADE000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
5F0000
unkown image
page readonly
clean
556000
unkown
page read and write
clean
480000
heap private
page read and write
clean
670000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
5D0000
unkown
page execute and read and write
clean
920000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
1B0000
heap private
page read and write
clean
470000
heap private
page read and write
clean
A00000
unkown image
page readonly
clean
D80000
heap private
page read and write
clean
3B0000
heap private
page read and write
clean
F0000
unkown
page read and write
clean
2B0000
heap private
page read and write
clean
7B0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
420000
unkown
page read and write
clean
11CE000
unkown
page read and write
clean
1E10000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
2B4000
heap private
page read and write
clean
27C1000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
5F0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
B0000
unkown
page read and write
clean
590000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
18F0000
heap private
page read and write
clean
900000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
BD0000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
2E55000
heap private
page read and write
clean
D0000
unkown image
page readonly
clean
4BA000
heap default
page read and write
clean
360000
unkown image
page readonly
clean
10000000
unkown image
page readonly
clean
4C5000
unkown
page execute and read and write
clean
98E000
unkown
page read and write
clean
247000
heap default
page read and write
clean
30000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
29CC000
unkown
page read and write
clean
566000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
170000
unkown image
page read and write
clean
960000
unkown image
page readonly
clean
E9F000
heap private
page read and write
clean
E20000
heap private
page read and write
clean
100000
unkown
page read and write
clean
332000
unkown
page read and write
clean
27C0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
323000
unkown
page read and write
clean
1F0000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
20C000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
270000
heap default
page read and write
clean
18E000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
29AC000
unkown
page read and write
clean
6E0000
unkown image
page readonly
clean
7B0000
unkown image
page readonly
clean
266000
heap private
page read and write
clean
620000
unkown image
page readonly
clean
7A4000
heap default
page read and write
clean
1CE000
heap default
page read and write
clean
2145000
unkown
page execute and read and write
clean
526000
unkown
page read and write
clean
404000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
FA0000
heap private
page read and write
clean
19C000
unkown
page read and write
clean
210000
unkown
page read and write
clean
29C000
unkown
page read and write
clean
2090000
unkown image
page readonly
clean
6BF000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
770000
unkown image
page readonly
clean
1FC000
unkown
page read and write
clean
16C000
unkown
page read and write
clean
10000000
unkown image
page readonly
clean
290000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
27F2000
unkown
page read and write
clean
D20000
unkown image
page readonly
clean
C0000
unkown image
page readonly
clean
E9F000
heap private
page read and write
clean
3A6000
unkown
page read and write
clean
10044000
unkown image
page readonly
clean
3E0000
unkown
page read and write
clean
157000
heap default
page read and write
clean
160000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
560000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
1190000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
454000
heap private
page read and write
clean
117C000
unkown
page read and write
clean
420000
unkown image
page readonly
clean
8C000
unkown
page read and write
clean
197F000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
2151000
unkown
page execute and read and write
clean
10000
unkown image
page read and write
clean
20000
unkown image
page readonly
clean
30000
unkown image
page read and write
clean
29A000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
1AC000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
3E4000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
F0000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
780000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
6D2000
heap private
page read and write
clean
264000
heap private
page read and write
clean
10000000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
140000
unkown
page read and write
clean
490000
unkown
page execute and read and write
clean
8DF000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
5C9000
heap default
page read and write
clean
7F2000
heap default
page read and write
clean
20000
unkown image
page readonly
clean
26E000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
456000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
260000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
14A000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2E73000
heap private
page read and write
clean
30000
unkown image
page readonly
clean
2A7E000
unkown
page read and write
clean
506000
heap private
page read and write
clean
3A6000
unkown
page read and write
clean
2145000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
27E000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
2BEE000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
480000
heap default
page read and write
clean
880000
unkown image
page readonly
clean
10000000
unkown image
page readonly
clean
2ED0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
11D0000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
690000
unkown image
page readonly
clean
C3D000
unkown
page read and write
clean
2D0000
unkown
page read and write
clean
15D5000
heap private
page read and write
clean
21A5000
heap private
page read and write
clean
6B0000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
230000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
6F6000
heap private
page read and write
clean
520000
unkown
page read and write
clean
E0000
unkown image
page read and write
clean
1F0000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
E0000
unkown image
page read and write
clean
660000
heap private
page read and write
clean
942000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
9C0000
heap private
page read and write
clean
125F000
unkown
page read and write
clean
560000
unkown image
page readonly
clean
15D0000
heap private
page read and write
clean
1D90000
unkown image
page readonly
clean
2E0000
heap private
page read and write
clean
2EF000
heap default
page read and write
clean
2ECF000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
19FF000
unkown
page read and write
clean
1AC000
unkown
page read and write
clean
227000
heap default
page read and write
clean
556000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
C20000
unkown
page read and write
clean
EB000
unkown
page read and write
clean
170000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
446000
unkown
page read and write
clean
7A0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
780000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
E6F000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
32F000
unkown
page read and write
clean
2B7000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
260000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
930000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
2C0000
unkown
page read and write
clean
8CF000
unkown
page read and write
clean
27FE000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
2C0000
heap default
page read and write
clean
2E7000
heap default
page read and write
clean
E9F000
heap private
page read and write
clean
6A0000
unkown image
page readonly
clean
6F0000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
400000
heap private
page read and write
clean
91E000
unkown
page read and write
clean
600000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
440000
heap default
page read and write
clean
620000
unkown image
page readonly
clean
2292000
heap private
page read and write
clean
50000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
There are 702 hidden memdumps, click here to show them.