IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Compensation-2100058996-09272021.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Author: Test, Last Saved By: Test, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Jun 5 19:17:20 2015, Last Saved Time/Date: Mon Sep 27 10:38:52 2021, Security: 0
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\44467.4314974537[1].dat
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Drezd.red
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\VBE\MSForms.exd
data
dropped
clean
C:\Users\user\AppData\Local\Temp\VBE\RefEdit.exd
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Drezd.red
malicious
C:\Windows\SysWOW64\regsvr32.exe
-silent ..\Drezd.red
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Drezd1.red
malicious
C:\Windows\SysWOW64\schtasks.exe
'C:\Windows\system32\schtasks.exe' /Create /RU 'NT AUTHORITY\SYSTEM' /tn uwqvoal /tr 'regsvr32.exe -s \'C:\Users\user\Drezd.red\'' /SC ONCE /Z /ST 10:25 /ET 10:37
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Drezd2.red
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\System32\reg.exe
C:\Windows\system32\reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths' /f /t REG_DWORD /v 'C:\ProgramData\Microsoft\Imqocbuplg' /d '0'
malicious
C:\Windows\System32\reg.exe
C:\Windows\system32\reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths' /f /t REG_DWORD /v 'C:\Users\user\AppData\Roaming\Microsoft\Iaoaukbfna' /d '0'
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\Drezd.red'
malicious
There are 4 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://www.%s.comPA
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://190.14.37.178/44467.4314974537.dat
190.14.37.178
clean
http://servername/isapibackend.dll
unknown
clean

IPs

IP
Domain
Country
Malicious
185.183.96.67
unknown
Netherlands
clean
190.14.37.178
unknown
Panama
clean
185.250.148.213
unknown
Russian Federation
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
=<-
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2E408
2E408
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{764C8E42-17A3-4079-9422-2B955F5D82BB}\2.0
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{764C8E42-17A3-4079-9422-2B955F5D82BB}\2.0\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{764C8E42-17A3-4079-9422-2B955F5D82BB}\2.0\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{764C8E42-17A3-4079-9422-2B955F5D82BB}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{764C8E42-17A3-4079-9422-2B955F5D82BB}\2.0
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{764C8E42-17A3-4079-9422-2B955F5D82BB}\2.0\FLAGS
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{764C8E42-17A3-4079-9422-2B955F5D82BB}\2.0\0\win32
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{764C8E42-17A3-4079-9422-2B955F5D82BB}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5F1EA10C-54A9-4557-8E84-AC7E59FFF990}\1.2
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5F1EA10C-54A9-4557-8E84-AC7E59FFF990}\1.2\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5F1EA10C-54A9-4557-8E84-AC7E59FFF990}\1.2\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5F1EA10C-54A9-4557-8E84-AC7E59FFF990}\1.2\HELPDIR
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00024518-0000-0000-C000-000000000046}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
hg-
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\57407
57407
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\57658
57658
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_CURRENT_USER\Software\Microsoft\Lrekauiesw
50b30089
clean
HKEY_CURRENT_USER\Software\Microsoft\Lrekauiesw
652cd0c7
clean
HKEY_CURRENT_USER\Software\Microsoft\Lrekauiesw
676df0bb
clean
HKEY_CURRENT_USER\Software\Microsoft\Lrekauiesw
dfd197de
clean
HKEY_CURRENT_USER\Software\Microsoft\Lrekauiesw
a2d9d854
clean
HKEY_CURRENT_USER\Software\Microsoft\Lrekauiesw
1a65bf31
clean
HKEY_CURRENT_USER\Software\Microsoft\Lrekauiesw
dd90b7a2
clean
HKEY_CURRENT_USER\Software\Microsoft\Lrekauiesw
2ffa6f7f
clean
HKEY_CURRENT_USER\Software\Microsoft\Lrekauiesw
50b30089
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Iexanqetkbici
83b6d542
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Iexanqetkbici
b629050c
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Iexanqetkbici
b4682570
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Iexanqetkbici
cd44215
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Iexanqetkbici
71dc0d9f
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Iexanqetkbici
c9606afa
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Iexanqetkbici
e956269
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Iexanqetkbici
fcffbab4
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Iexanqetkbici
83b6d542
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
C:\ProgramData\Microsoft\Imqocbuplg
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
C:\Users\user\AppData\Roaming\Microsoft\Iaoaukbfna
clean
There are 212 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
E0000
unkown image
page execute and read and write
malicious
10001000
unkown image
page execute and read and write
malicious
C0000
unkown image
page execute and read and write
malicious
210000
unkown
page read and write
malicious
10001000
unkown image
page execute and read and write
malicious
890000
unkown
page read and write
malicious
920000
unkown image
page readonly
clean
950000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
6B0000
unkown
page read and write
clean
346000
unkown
page read and write
clean
6C4000
unkown
page read and write
clean
21E2000
heap private
page read and write
clean
274000
heap default
page read and write
clean
2020000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
820000
unkown image
page readonly
clean
2A7000
heap default
page read and write
clean
780000
unkown image
page readonly
clean
30000
unkown image
page read and write
clean
3B0000
unkown image
page readonly
clean
151C000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
4A0000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
991000
unkown
page execute and read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
26E0000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
A1E000
unkown
page read and write
clean
1D20000
unkown image
page readonly
clean
12C000
unkown
page read and write
clean
F0000
heap default
page read and write
clean
524000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
BF0000
unkown image
page readonly
clean
120000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
1A9F000
unkown
page read and write
clean
29C000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
16C000
unkown
page read and write
clean
8C000
unkown
page read and write
clean
2C7000
heap default
page read and write
clean
6F0000
unkown image
page readonly
clean
F0000
unkown
page read and write
clean
6C8000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2B0000
heap default
page read and write
clean
12E000
heap default
page read and write
clean
550000
heap private
page read and write
clean
10000000
unkown image
page readonly
clean
264000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
306000
heap default
page read and write
clean
D0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
300000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
530000
unkown
page read and write
clean
2F3000
heap default
page read and write
clean
20000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
26DC000
unkown
page read and write
clean
2B7000
heap default
page read and write
clean
E0000
unkown image
page read and write
clean
4B0000
heap default
page read and write
clean
2FD000
heap default
page read and write
clean
213F000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
1E30000
unkown image
page readonly
clean
2A0000
heap private
page read and write
clean
8C000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
410000
unkown
page read and write
clean
18C3000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
26CF000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
DEF000
unkown
page read and write
clean
670000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
6FE000
unkown
page read and write
clean
1D6000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
80000
unkown
page read and write
clean
F20000
unkown image
page readonly
clean
1530000
heap private
page read and write
clean
284F000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
90000
unkown
page read and write
clean
25AF000
unkown
page read and write
clean
2C05000
heap private
page read and write
clean
2205000
heap private
page read and write
clean
6AD000
unkown
page read and write
clean
8C6000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
143000
heap default
page read and write
clean
F0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2C0000
heap default
page read and write
clean
262E000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
310000
heap default
page read and write
clean
20000
unkown image
page readonly
clean
4C0000
heap default
page read and write
clean
446000
unkown
page read and write
clean
30000
unkown image
page read and write
clean
560000
unkown image
page readonly
clean
240000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
257000
heap default
page read and write
clean
196000
unkown
page read and write
clean
590000
heap private
page read and write
clean
320000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
2EE000
heap default
page read and write
clean
20000
unkown image
page read and write
clean
7EFDF000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
26CB000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
640000
heap default
page read and write
clean
2C00000
heap private
page read and write
clean
50F000
heap default
page read and write
clean
2150000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
1360000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
950000
unkown
page execute and read and write
clean
7AD000
unkown
page read and write
clean
2A4000
heap private
page read and write
clean
C40000
unkown
page read and write
clean
20C0000
heap private
page read and write
clean
C0000
heap private
page read and write
clean
97000
heap default
page read and write
clean
7EFC0000
unkown image
page readonly
clean
4D0000
heap default
page read and write
clean
490000
heap private
page read and write
clean
804000
heap default
page read and write
clean
18E000
unkown
page read and write
clean
330000
unkown image
page readonly
clean
15AF000
heap private
page read and write
clean
131E000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
B40000
heap private
page read and write
clean
740000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
61E000
unkown
page read and write
clean
8E2000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
160000
unkown
page read and write
clean
500000
unkown
page read and write
clean
790000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
1FD0000
unkown image
page readonly
clean
DB000
unkown
page read and write
clean
D40000
unkown image
page readonly
clean
C00000
unkown
page read and write
clean
694000
heap default
page read and write
clean
164000
unkown
page read and write
clean
18A0000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
195F000
unkown
page read and write
clean
187C000
unkown
page read and write
clean
2F3000
heap default
page read and write
clean
780000
heap private
page read and write
clean
10052000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
6C0000
unkown image
page readonly
clean
540000
unkown image
page readonly
clean
6C8000
unkown
page read and write
clean
37E000
heap default
page read and write
clean
20000
unkown image
page readonly
clean
10000000
unkown image
page readonly
clean
310000
unkown
page read and write
clean
174000
unkown
page read and write
clean
7E0000
heap default
page read and write
clean
4D6000
unkown
page read and write
clean
8E1000
unkown
page execute and read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
120000
unkown
page read and write
clean
173000
unkown
page read and write
clean
4D0000
unkown image
page read and write
clean
7EFE0000
unkown image
page readonly
clean
15AF000
heap private
page read and write
clean
554000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
3A0000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
324000
heap private
page read and write
clean
1F95000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
A60000
unkown image
page readonly
clean
910000
unkown image
page readonly
clean
100000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
786000
heap private
page read and write
clean
A0000
unkown image
page readonly
clean
4A0000
unkown
page read and write
clean
2EE000
heap default
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2010000
unkown image
page readonly
clean
6B5000
unkown
page read and write
clean
630000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
E0000
unkown image
page readonly
clean
520000
heap private
page read and write
clean
4F4000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
393000
heap default
page read and write
clean
90000
unkown image
page read and write
clean
40000
unkown image
page readonly
clean
770000
unkown
page read and write
clean
6B3000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
10044000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
556000
heap private
page read and write
clean
CE000
heap default
page read and write
clean
1FCB000
heap private
page read and write
clean
180000
unkown
page read and write
clean
4D4000
heap default
page read and write
clean
9C0000
unkown image
page readonly
clean
2DCC000
unkown
page read and write
clean
6BD000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
3C0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
8C4000
heap private
page read and write
clean
C70000
heap private
page read and write
clean
1EE000
unkown
page read and write
clean
E0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
4A0000
unkown
page read and write
clean
246000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
213F000
heap private
page read and write
clean
39A000
heap default
page read and write
clean
13FE000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
A60000
unkown image
page readonly
clean
1C0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
191F000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
2130000
unkown image
page readonly
clean
78D000
unkown
page read and write
clean
7E7000
heap default
page read and write
clean
7C0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
4C0000
unkown
page read and write
clean
494000
heap private
page read and write
clean
790000
unkown image
page readonly
clean
270000
unkown image
page read and write
clean
70000
unkown image
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
4B0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
51B000
unkown
page read and write
clean
208F000
unkown
page read and write
clean
EA000
heap default
page read and write
clean
20000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
542000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
6B5000
unkown
page read and write
clean
690000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
1450000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
1320000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
4B0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
2C2000
heap default
page read and write
clean
100000
unkown image
page read and write
clean
30000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
304000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
3AD000
unkown
page read and write
clean
2A0000
heap private
page read and write
clean
280000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
19BF000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
694000
heap private
page read and write
clean
1C80000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
2B0000
heap default
page read and write
clean
70000
unkown image
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
4A0000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
780000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
1CD0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
20C000
unkown
page read and write
clean
210000
unkown
page read and write
clean
3D6000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
90000
heap default
page read and write
clean
14A000
heap default
page read and write
clean
1DC000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
940000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
4D6000
unkown
page read and write
clean
2B7000
heap default
page read and write
clean
175000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
1A0000
unkown
page read and write
clean
7B0000
unkown image
page readonly
clean
12A0000
heap private
page read and write
clean
5DB000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
80000
unkown
page read and write
clean
A0000
unkown image
page readonly
clean
550000
heap private
page read and write
clean
340000
heap default
page read and write
clean
8A0000
unkown
page execute and read and write
clean
40000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
2670000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
4A4000
heap private
page read and write
clean
14C000
unkown
page read and write
clean
985000
unkown
page execute and read and write
clean
10052000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
1E0000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
EC000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
1E4000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
4B7000
heap default
page read and write
clean
21C0000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2A7C000
unkown
page read and write
clean
530000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
A50000
unkown image
page readonly
clean
530000
unkown image
page readonly
clean
2C7B000
unkown
page read and write
clean
30000
unkown image
page read and write
clean
347000
heap default
page read and write
clean
1F90000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
4D7000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
4EF000
heap default
page read and write
clean
50A000
heap default
page read and write
clean
149E000
unkown
page read and write
clean
830000
unkown image
page readonly
clean
5D0000
unkown image
page readonly
clean
4A0000
unkown
page read and write
clean
28B000
unkown
page read and write
clean
128C000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
4F4000
heap default
page read and write
clean
566000
unkown
page read and write
clean
190000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
266E000
unkown
page read and write
clean
213F000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
90000
unkown
page read and write
clean
596000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
4E6000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
2A0000
heap default
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2C2E000
unkown
page read and write
clean
930000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
10000000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
540000
unkown image
page readonly
clean
126F000
unkown
page read and write
clean
1B3E000
unkown
page read and write
clean
DF0000
heap private
page read and write
clean
47F000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
DC000
unkown
page read and write
clean
8D5000
unkown
page execute and read and write
clean
6E0000
unkown image
page readonly
clean
10000000
unkown image
page readonly
clean
167000
heap default
page read and write
clean
8C0000
heap private
page read and write
clean
2A0000
heap default
page read and write
clean
E0000
unkown image
page read and write
clean
11C000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
5B0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
90000
unkown image
page readonly
clean
3D6000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2A0000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
860000
heap private
page read and write
clean
2125000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
730000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
6A0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
536000
unkown
page read and write
clean
6C2000
unkown
page read and write
clean
223B000
heap private
page read and write
clean
268E000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
90000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
2DE000
heap default
page read and write
clean
390000
unkown
page read and write
clean
2D6000
unkown
page read and write
clean
6BF000
unkown
page read and write
clean
444000
heap private
page read and write
clean
40000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
1361000
unkown
page read and write
clean
790000
unkown image
page readonly
clean
250000
heap default
page read and write
clean
502000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
10042000
unkown image
page readonly
clean
940000
heap private
page read and write
clean
F7000
heap default
page read and write
clean
2D2F000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
121F000
unkown
page read and write
clean
C5D000
unkown
page read and write
clean
786000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
1ED000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
260000
heap private
page read and write
clean
2BF000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
20000
unkown image
page read and write
clean
26BF000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
10000000
unkown image
page readonly
clean
2E00000
unkown image
page readonly
clean
15AF000
heap private
page read and write
clean
560000
unkown image
page readonly
clean
6B8000
unkown
page read and write
clean
CA000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
2FA000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2F8F000
unkown
page read and write
clean
440000
heap private
page read and write
clean
6AE000
unkown
page read and write
clean
6C6000
unkown
page read and write
clean
30B000
heap default
page read and write
clean
2200000
heap private
page read and write
clean
268D000
unkown
page read and write
clean
AB0000
unkown image
page readonly
clean
E3000
heap default
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2A7000
heap default
page read and write
clean
2200000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
178000
unkown
page read and write
clean
4E9000
heap default
page read and write
clean
263E000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
2B0000
heap default
page read and write
clean
212B000
heap private
page read and write
clean
18A5000
heap private
page read and write
clean
C1D000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
77F000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
60F000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
3A0000
unkown
page read and write
clean
8D0000
unkown image
page readonly
clean
10042000
unkown image
page readonly
clean
12B000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
289000
heap default
page read and write
clean
1370000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
540000
unkown image
page readonly
clean
2C23000
heap private
page read and write
clean
80000
unkown
page read and write
clean
790000
unkown image
page readonly
clean
8BE000
unkown
page read and write
clean
2123000
heap private
page read and write
clean
677000
heap default
page read and write
clean
EE0000
heap private
page read and write
clean
60000
unkown image
page readonly
clean
2C7F000
heap private
page read and write
clean
3B0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
7EFB2000
unkown image
page readonly
clean
85E000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
24000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
2671000
unkown
page read and write
clean
2FA000
heap default
page read and write
clean
E30000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
28F000
heap default
page read and write
clean
20000
heap private
page read and write
clean
8C0000
heap private
page read and write
clean
2DE000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
8E0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
790000
unkown image
page readonly
clean
10044000
unkown image
page readonly
clean
20F0000
heap private
page read and write
clean
F0000
unkown image
page read and write
clean
6CA000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
21C4000
heap private
page read and write
clean
40000
unkown image
page readonly
clean
70000
unkown image
page read and write
clean
20F5000
heap private
page read and write
clean
4F0000
heap private
page read and write
clean
80000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
172000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
600000
unkown image
page readonly
clean
2B00000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
A70000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
There are 591 hidden memdumps, click here to show them.