IOC Report

loading gif

Files

File Path
Type
Category
Malicious
xls.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Author: Test, Last Saved By: Test, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Jun 5 19:17:20 2015, Last Saved Time/Date: Mon Sep 27 10:38:52 2021, Security: 0
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\44467.7495993056[1].dat
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Drezd.red
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\VBE\MSForms.exd
data
dropped
clean
C:\Users\user\AppData\Local\Temp\VBE\RefEdit.exd
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Drezd.red
malicious
C:\Windows\SysWOW64\regsvr32.exe
-silent ..\Drezd.red
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Drezd1.red
malicious
C:\Windows\SysWOW64\schtasks.exe
'C:\Windows\system32\schtasks.exe' /Create /RU 'NT AUTHORITY\SYSTEM' /tn mywmprn /tr 'regsvr32.exe -s \'C:\Users\user\Drezd.red\'' /SC ONCE /Z /ST 18:03 /ET 18:15
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Drezd2.red
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\System32\reg.exe
C:\Windows\system32\reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths' /f /t REG_DWORD /v 'C:\ProgramData\Microsoft\Ofsugluhreiu' /d '0'
malicious
C:\Windows\System32\reg.exe
C:\Windows\system32\reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths' /f /t REG_DWORD /v 'C:\Users\user\AppData\Roaming\Microsoft\Csbfke' /d '0'
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\Drezd.red'
malicious
There are 4 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://www.%s.comPA
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://190.14.37.178/44467.7495993056.dat
190.14.37.178
clean
http://servername/isapibackend.dll
unknown
clean

IPs

IP
Domain
Country
Malicious
185.183.96.67
unknown
Netherlands
clean
190.14.37.178
unknown
Panama
clean
185.250.148.213
unknown
Russian Federation
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
v+%
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2F122
2F122
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A3A00B7C-0085-4B8F-9AE1-815F36820617}\2.0
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A3A00B7C-0085-4B8F-9AE1-815F36820617}\2.0\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A3A00B7C-0085-4B8F-9AE1-815F36820617}\2.0\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A3A00B7C-0085-4B8F-9AE1-815F36820617}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{A3A00B7C-0085-4B8F-9AE1-815F36820617}\2.0
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{A3A00B7C-0085-4B8F-9AE1-815F36820617}\2.0\FLAGS
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{A3A00B7C-0085-4B8F-9AE1-815F36820617}\2.0\0\win32
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{A3A00B7C-0085-4B8F-9AE1-815F36820617}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6E800BD8-2A59-4ACF-B91C-96EB0C98E944}\1.2
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6E800BD8-2A59-4ACF-B91C-96EB0C98E944}\1.2\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6E800BD8-2A59-4ACF-B91C-96EB0C98E944}\1.2\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6E800BD8-2A59-4ACF-B91C-96EB0C98E944}\1.2\HELPDIR
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00024518-0000-0000-C000-000000000046}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
q:%
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\4CD6D
4CD6D
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\4CFEC
4CFEC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_CURRENT_USER\Software\Microsoft\Zfkuzoqvfipoxh
d440693b
clean
HKEY_CURRENT_USER\Software\Microsoft\Zfkuzoqvfipoxh
e1dfb975
clean
HKEY_CURRENT_USER\Software\Microsoft\Zfkuzoqvfipoxh
e39e9909
clean
HKEY_CURRENT_USER\Software\Microsoft\Zfkuzoqvfipoxh
5b22fe6c
clean
HKEY_CURRENT_USER\Software\Microsoft\Zfkuzoqvfipoxh
262ab1e6
clean
HKEY_CURRENT_USER\Software\Microsoft\Zfkuzoqvfipoxh
9e96d683
clean
HKEY_CURRENT_USER\Software\Microsoft\Zfkuzoqvfipoxh
5963de10
clean
HKEY_CURRENT_USER\Software\Microsoft\Zfkuzoqvfipoxh
ab0906cd
clean
HKEY_CURRENT_USER\Software\Microsoft\Zfkuzoqvfipoxh
d440693b
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Zncgiuvfjlk
612b4477
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Zncgiuvfjlk
54b49439
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Zncgiuvfjlk
56f5b445
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Zncgiuvfjlk
ee49d320
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Zncgiuvfjlk
93419caa
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Zncgiuvfjlk
2bfdfbcf
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Zncgiuvfjlk
ec08f35c
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Zncgiuvfjlk
1e622b81
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Zncgiuvfjlk
612b4477
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
C:\ProgramData\Microsoft\Ofsugluhreiu
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
C:\Users\user\AppData\Roaming\Microsoft\Csbfke
clean
There are 212 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
10001000
unkown image
page execute and read and write
malicious
300000
unkown
page read and write
malicious
3B0000
unkown
page read and write
malicious
10001000
unkown image
page execute and read and write
malicious
C0000
unkown image
page execute and read and write
malicious
80000
unkown image
page execute and read and write
malicious
846000
heap private
page read and write
clean
1C80000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
1AAF000
unkown
page read and write
clean
B0000
unkown
page read and write
clean
350000
heap private
page read and write
clean
50000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
570000
unkown image
page readonly
clean
164000
heap private
page read and write
clean
30000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
B84000
unkown
page read and write
clean
70000
unkown image
page read and write
clean
30000
unkown image
page read and write
clean
290000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
1D0000
heap default
page read and write
clean
20D0000
heap private
page read and write
clean
21A5000
heap private
page read and write
clean
B88000
unkown
page read and write
clean
3B0000
heap private
page read and write
clean
1D20000
unkown image
page readonly
clean
160000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
396000
unkown
page read and write
clean
B2F000
unkown
page read and write
clean
4C4000
unkown
page read and write
clean
BD0000
heap private
page read and write
clean
1450000
heap private
page read and write
clean
100000
unkown
page read and write
clean
600000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
560000
unkown image
page readonly
clean
34F000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
4B7000
heap default
page read and write
clean
296000
unkown
page read and write
clean
14CF000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
27CF000
unkown
page read and write
clean
3F0000
unkown
page read and write
clean
3D4000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
10044000
unkown image
page readonly
clean
9E0000
unkown image
page readonly
clean
6E0000
unkown image
page readonly
clean
780000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
2C0000
heap default
page read and write
clean
212B000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
29B000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
21D000
unkown
page read and write
clean
210000
unkown
page read and write
clean
340000
heap private
page read and write
clean
B77000
heap default
page read and write
clean
840000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
20000
unkown image
page read and write
clean
BC000
unkown
page read and write
clean
14D0000
unkown
page read and write
clean
B79000
unkown
page read and write
clean
4C3000
unkown
page read and write
clean
14E000
heap default
page read and write
clean
277E000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
6F0000
unkown image
page readonly
clean
BC000
unkown
page read and write
clean
19BF000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
17A000
heap default
page read and write
clean
7C0000
unkown image
page readonly
clean
9E0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
260000
unkown
page read and write
clean
450000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
6B0000
heap private
page read and write
clean
30000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
B0000
unkown image
page readonly
clean
1AE000
heap default
page read and write
clean
53A000
heap default
page read and write
clean
2150000
unkown image
page readonly
clean
10042000
unkown image
page readonly
clean
B75000
unkown
page read and write
clean
2DE5000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
454000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
890000
unkown
page read and write
clean
116E000
unkown
page read and write
clean
27B0000
heap private
page read and write
clean
190000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7B0000
heap private
page read and write
clean
1000000
unkown
page read and write
clean
522000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
264000
heap private
page read and write
clean
C30000
unkown image
page readonly
clean
790000
unkown image
page readonly
clean
560000
unkown image
page readonly
clean
C0000
unkown image
page readonly
clean
FC000
unkown
page read and write
clean
12AE000
unkown
page read and write
clean
AA0000
unkown image
page readonly
clean
4D7000
heap default
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
1C0000
unkown
page read and write
clean
3D7000
heap default
page read and write
clean
1E0000
unkown
page read and write
clean
770000
unkown image
page readonly
clean
624000
heap default
page read and write
clean
17C000
unkown
page read and write
clean
1D10000
unkown image
page readonly
clean
10052000
unkown image
page readonly
clean
180000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
F0000
unkown image
page read and write
clean
7EFC0000
unkown image
page readonly
clean
163000
heap default
page read and write
clean
2030000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
282000
heap private
page read and write
clean
290000
heap private
page read and write
clean
ADD000
unkown
page read and write
clean
2D6000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
30000
unkown image
page read and write
clean
1D5000
unkown
page execute and read and write
clean
572000
heap default
page read and write
clean
D20000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
50000
unkown image
page readonly
clean
650000
unkown image
page readonly
clean
49A000
heap default
page read and write
clean
20000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
2781000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
770000
unkown image
page readonly
clean
250000
heap default
page read and write
clean
2ED0000
unkown image
page readonly
clean
B8A000
unkown
page read and write
clean
A2E000
unkown
page read and write
clean
8D0000
heap default
page read and write
clean
BD0000
heap private
page read and write
clean
426000
unkown
page read and write
clean
10042000
unkown image
page readonly
clean
127000
heap default
page read and write
clean
189F000
heap private
page read and write
clean
B30000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
8AD000
unkown
page read and write
clean
496000
unkown
page read and write
clean
790000
unkown image
page readonly
clean
493000
heap default
page read and write
clean
240000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
F0000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
672000
heap default
page read and write
clean
E0000
unkown image
page read and write
clean
7EFB2000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
70000
unkown image
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
240000
unkown image
page read and write
clean
B7D000
unkown
page read and write
clean
2780000
unkown
page read and write
clean
2420000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
1B6000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
213D000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
780000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
48F000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
5E4000
heap private
page read and write
clean
850000
unkown image
page readonly
clean
170000
heap default
page read and write
clean
2102000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
180000
heap private
page read and write
clean
14CF000
heap private
page read and write
clean
4D0000
unkown image
page readonly
clean
16A000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
160000
unkown image
page read and write
clean
8B0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
259F000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
3E0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
82F000
unkown
page read and write
clean
2D0000
heap private
page read and write
clean
110000
unkown
page read and write
clean
780000
unkown image
page readonly
clean
2220000
unkown image
page readonly
clean
2A0000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
450000
heap private
page read and write
clean
870000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
350000
unkown
page read and write
clean
2781000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
340000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
330000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2E5F000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
440000
heap default
page read and write
clean
14D1000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
780000
unkown image
page readonly
clean
21A0000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2DAF000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
840000
heap private
page read and write
clean
354000
heap private
page read and write
clean
4C8000
unkown
page read and write
clean
10044000
unkown image
page readonly
clean
101D000
unkown
page read and write
clean
9D0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
27BE000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
1843000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
386000
unkown
page read and write
clean
460000
unkown
page read and write
clean
26AE000
unkown
page read and write
clean
509000
heap default
page read and write
clean
33B000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
B7A000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
600000
unkown image
page readonly
clean
194C000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
7EFE0000
unkown image
page readonly
clean
3D0000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
5E0000
unkown image
page readonly
clean
607000
heap default
page read and write
clean
5E4000
heap private
page read and write
clean
274000
heap default
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
F0000
unkown
page read and write
clean
2700000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
3E0000
heap default
page read and write
clean
2D0E000
unkown
page read and write
clean
B7F000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
4B4000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
AC000
unkown
page read and write
clean
271F000
unkown
page read and write
clean
100000
unkown image
page read and write
clean
60000
unkown image
page readonly
clean
20E000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
40000
unkown image
page readonly
clean
53F000
heap default
page read and write
clean
B54000
heap default
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
20F0000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
5F0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
4C5000
unkown
page read and write
clean
447000
heap default
page read and write
clean
360000
unkown
page read and write
clean
80000
unkown
page read and write
clean
2D6000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
27B2000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
1BB000
unkown
page read and write
clean
20000
unkown image
page read and write
clean
496000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
4D0000
heap default
page read and write
clean
2A6000
unkown
page read and write
clean
700000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
6F0000
unkown image
page readonly
clean
120F000
unkown
page read and write
clean
450000
heap private
page read and write
clean
16F0000
heap private
page read and write
clean
170000
unkown
page read and write
clean
50F000
heap default
page read and write
clean
4C2000
unkown
page read and write
clean
12D000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
2E03000
heap private
page read and write
clean
850000
unkown image
page readonly
clean
100000
unkown image
page read and write
clean
460000
unkown image
page readonly
clean
540000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
E0000
unkown image
page read and write
clean
500000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
34F000
heap private
page read and write
clean
1A0000
unkown
page execute and read and write
clean
150000
unkown
page read and write
clean
10C000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
F00000
heap private
page read and write
clean
7C0000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
2C9E000
unkown
page read and write
clean
20E0000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
130000
unkown image
page read and write
clean
340000
unkown image
page readonly
clean
27C1000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
1D1000
unkown
page execute and read and write
clean
4C0000
unkown image
page readonly
clean
90000
unkown
page read and write
clean
1C5000
unkown
page execute and read and write
clean
454000
heap private
page read and write
clean
29B000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
574000
heap private
page read and write
clean
20000
unkown image
page readonly
clean
257000
heap default
page read and write
clean
E0000
unkown image
page read and write
clean
D80000
heap private
page read and write
clean
63F000
heap default
page read and write
clean
507000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
4F4000
heap private
page read and write
clean
20E4000
heap private
page read and write
clean
B2F000
unkown
page read and write
clean
15E000
heap default
page read and write
clean
570000
heap private
page read and write
clean
2F3000
heap default
page read and write
clean
9D0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
2CE000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
210B000
heap private
page read and write
clean
2C50000
heap private
page read and write
clean
40E000
heap default
page read and write
clean
184000
heap private
page read and write
clean
294000
heap private
page read and write
clean
117000
heap default
page read and write
clean
3D0000
heap private
page read and write
clean
25D0000
heap private
page read and write
clean
20000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
7EFC0000
unkown image
page readonly
clean
270000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
14CF000
heap private
page read and write
clean
173000
heap default
page read and write
clean
30000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
190000
unkown
page execute and read and write
clean
D0000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7B6000
heap private
page read and write
clean
27AE000
unkown
page read and write
clean
A7F000
unkown
page read and write
clean
D0000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
500000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
20D5000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
1825000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
5F0000
unkown image
page readonly
clean
524000
heap default
page read and write
clean
4BC000
unkown
page read and write
clean
2F0000
heap default
page read and write
clean
10052000
unkown image
page readonly
clean
2220000
unkown image
page readonly
clean
10000000
unkown image
page readonly
clean
660000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
2F7000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
243D000
unkown
page read and write
clean
34F000
heap private
page read and write
clean
346000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
3EF000
unkown
page read and write
clean
F90000
heap private
page read and write
clean
FD0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
BC000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
23A000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
1F0000
heap private
page read and write
clean
1220000
heap private
page read and write
clean
1E1000
unkown
page execute and read and write
clean
7EFE0000
unkown image
page readonly
clean
380000
heap private
page read and write
clean
1DE0000
unkown image
page readonly
clean
460000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
344000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
177000
heap default
page read and write
clean
22A000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
110000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
536000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2BAC000
unkown
page read and write
clean
47E000
heap default
page read and write
clean
6B4000
heap private
page read and write
clean
9EE000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
23C000
unkown
page read and write
clean
C0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
20BE000
unkown
page read and write
clean
11BE000
unkown
page read and write
clean
AC0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
1820000
heap private
page read and write
clean
205C000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
2DE000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
486000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
4F0000
heap private
page read and write
clean
1F80000
unkown image
page readonly
clean
2E5F000
heap private
page read and write
clean
291E000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
1D7000
heap default
page read and write
clean
3FE000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
2A7000
heap default
page read and write
clean
2120000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
950000
unkown image
page readonly
clean
EBC000
unkown
page read and write
clean
223000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
338000
heap default
page read and write
clean
2FA000
heap default
page read and write
clean
C10000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
21DB000
heap private
page read and write
clean
5E0000
heap private
page read and write
clean
2C3A000
unkown
page read and write
clean
2ECE000
unkown
page read and write
clean
25C000
unkown
page read and write
clean
E5E000
unkown
page read and write
clean
B37000
heap default
page read and write
clean
7EFDF000
unkown
page read and write
clean
576000
unkown
page read and write
clean
D0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
5D0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
160000
unkown
page read and write
clean
34F000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
639000
heap default
page read and write
clean
10000000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
600000
heap default
page read and write
clean
6F0000
unkown image
page readonly
clean
1B8F000
unkown
page read and write
clean
19F000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
10000000
unkown image
page readonly
clean
32D000
heap default
page read and write
clean
5E0000
heap private
page read and write
clean
2A0000
unkown
page read and write
clean
336000
heap default
page read and write
clean
AD0000
heap private
page read and write
clean
B81000
unkown
page read and write
clean
6C0000
unkown image
page readonly
clean
10000000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
2DE0000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
12B000
unkown
page read and write
clean
260000
heap private
page read and write
clean
386000
heap private
page read and write
clean
19BC000
unkown
page read and write
clean
23C000
unkown
page read and write
clean
20F5000
heap private
page read and write
clean
7EFDF000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
120000
heap default
page read and write
clean
4F4000
heap default
page read and write
clean
370000
unkown
page read and write
clean
10000000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
14B000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
There are 585 hidden memdumps, click here to show them.