IOC Report

loading gif

Files

File Path
Type
Category
Malicious
CompensationClaim-1033191014-09282021.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Author: Test, Last Saved By: Test, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Jun 5 19:17:20 2015, Last Saved Time/Date: Tue Sep 28 08:54:40 2021, Security: 0
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\44467.9218096065[1].dat
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Drezd.red
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\VBE\MSForms.exd
data
dropped
clean
C:\Users\user\AppData\Local\Temp\VBE\RefEdit.exd
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Drezd.red
malicious
C:\Windows\SysWOW64\regsvr32.exe
-silent ..\Drezd.red
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Drezd1.red
malicious
C:\Windows\SysWOW64\schtasks.exe
'C:\Windows\system32\schtasks.exe' /Create /RU 'NT AUTHORITY\SYSTEM' /tn pajjxwey /tr 'regsvr32.exe -s \'C:\Users\user\Drezd.red\'' /SC ONCE /Z /ST 22:10 /ET 22:22
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Drezd2.red
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\System32\reg.exe
C:\Windows\system32\reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths' /f /t REG_DWORD /v 'C:\ProgramData\Microsoft\Ciwuywu' /d '0'
malicious
C:\Windows\System32\reg.exe
C:\Windows\system32\reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths' /f /t REG_DWORD /v 'C:\Users\user\AppData\Roaming\Microsoft\Uvelq' /d '0'
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\Drezd.red'
malicious
There are 4 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://www.%s.comPA
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://190.14.37.187/44467.9218096065.dat
190.14.37.187
clean
http://servername/isapibackend.dll
unknown
clean

IPs

IP
Domain
Country
Malicious
185.141.27.213
unknown
Netherlands
clean
190.14.37.187
unknown
Panama
clean
94.140.112.126
unknown
Latvia
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
f.
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2EDE7
2EDE7
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{54B3FCCA-9061-4E1B-B225-C5E2A2C452F2}\2.0
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{54B3FCCA-9061-4E1B-B225-C5E2A2C452F2}\2.0\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{54B3FCCA-9061-4E1B-B225-C5E2A2C452F2}\2.0\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{54B3FCCA-9061-4E1B-B225-C5E2A2C452F2}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{54B3FCCA-9061-4E1B-B225-C5E2A2C452F2}\2.0
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{54B3FCCA-9061-4E1B-B225-C5E2A2C452F2}\2.0\FLAGS
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{54B3FCCA-9061-4E1B-B225-C5E2A2C452F2}\2.0\0\win32
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{54B3FCCA-9061-4E1B-B225-C5E2A2C452F2}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{70BBF6E4-1A10-451C-9C91-5AA010820DF0}\1.2
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{70BBF6E4-1A10-451C-9C91-5AA010820DF0}\1.2\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{70BBF6E4-1A10-451C-9C91-5AA010820DF0}\1.2\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{70BBF6E4-1A10-451C-9C91-5AA010820DF0}\1.2\HELPDIR
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00024518-0000-0000-C000-000000000046}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
*s.
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\4C4E5
4C4E5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\4C6D8
4C6D8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_CURRENT_USER\Software\Microsoft\Gythyoiasr
37a8230d
clean
HKEY_CURRENT_USER\Software\Microsoft\Gythyoiasr
237f343
clean
HKEY_CURRENT_USER\Software\Microsoft\Gythyoiasr
76d33f
clean
HKEY_CURRENT_USER\Software\Microsoft\Gythyoiasr
b8cab45a
clean
HKEY_CURRENT_USER\Software\Microsoft\Gythyoiasr
c5c2fbd0
clean
HKEY_CURRENT_USER\Software\Microsoft\Gythyoiasr
7d7e9cb5
clean
HKEY_CURRENT_USER\Software\Microsoft\Gythyoiasr
ba8b9426
clean
HKEY_CURRENT_USER\Software\Microsoft\Gythyoiasr
48e14cfb
clean
HKEY_CURRENT_USER\Software\Microsoft\Gythyoiasr
37a8230d
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Usikewpzhwk
7e3e9e64
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Usikewpzhwk
4ba14e2a
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Usikewpzhwk
49e06e56
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Usikewpzhwk
f15c0933
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Usikewpzhwk
8c5446b9
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Usikewpzhwk
34e821dc
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Usikewpzhwk
f31d294f
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Usikewpzhwk
177f192
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Usikewpzhwk
7e3e9e64
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
C:\ProgramData\Microsoft\Ciwuywu
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
C:\Users\user\AppData\Roaming\Microsoft\Uvelq
clean
There are 212 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
10001000
unkown image
page execute and read and write
malicious
3D0000
unkown
page read and write
malicious
10001000
unkown image
page execute and read and write
malicious
80000
unkown image
page execute and read and write
malicious
C0000
unkown image
page execute and read and write
malicious
2A0000
unkown
page read and write
malicious
260000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
10000000
unkown image
page readonly
clean
21FB000
heap private
page read and write
clean
770000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
25B000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
480000
unkown
page read and write
clean
43E000
heap default
page read and write
clean
9A0000
unkown image
page readonly
clean
5F0000
unkown image
page readonly
clean
2CBE000
unkown
page read and write
clean
350000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
296000
unkown
page read and write
clean
3AB000
heap default
page read and write
clean
26B0000
heap private
page read and write
clean
7EFDF000
unkown
page read and write
clean
189C000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
28FE000
unkown
page read and write
clean
7EC000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
872000
unkown
page read and write
clean
780000
unkown image
page readonly
clean
170000
unkown image
page read and write
clean
770000
heap private
page read and write
clean
700000
unkown image
page readonly
clean
244D000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
7A0000
unkown image
page readonly
clean
2492000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
2A0000
heap private
page read and write
clean
138F000
heap private
page read and write
clean
7EFDF000
unkown
page read and write
clean
8CF6000
unkown
page execute and read and write
clean
245F000
unkown
page read and write
clean
360000
heap default
page read and write
clean
64F000
unkown
page read and write
clean
24B0000
unkown image
page readonly
clean
1C0000
heap default
page read and write
clean
1E7000
heap default
page read and write
clean
21E000
heap default
page read and write
clean
20000
unkown image
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2F7F000
unkown
page read and write
clean
580000
unkown image
page readonly
clean
806000
heap private
page read and write
clean
400000
heap default
page read and write
clean
7EFC0000
unkown image
page readonly
clean
1E7000
heap default
page read and write
clean
600000
heap private
page read and write
clean
BD000
unkown
page read and write
clean
1BD000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
206B000
heap private
page read and write
clean
2F0000
heap private
page read and write
clean
1D4000
heap private
page read and write
clean
2325000
heap private
page read and write
clean
5B0000
unkown image
page readonly
clean
1B7F000
unkown
page read and write
clean
26ED000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
5BB000
unkown
page read and write
clean
34A000
heap default
page read and write
clean
536000
heap private
page read and write
clean
7653000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
140000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2010000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7A2000
heap private
page read and write
clean
3F4000
heap private
page read and write
clean
25FE000
unkown
page read and write
clean
4E0000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
190000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
7EFB0000
unkown image
page readonly
clean
A0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
210000
heap private
page read and write
clean
20000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
30A000
heap default
page read and write
clean
150000
unkown image
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
1CD0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
4F0000
unkown
page read and write
clean
10000000
unkown image
page readonly
clean
7B0000
unkown image
page readonly
clean
430000
unkown image
page readonly
clean
387000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
E50000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
1D10000
unkown image
page readonly
clean
14F000
unkown
page read and write
clean
6A4000
heap default
page read and write
clean
40000
unkown image
page readonly
clean
2035000
heap private
page read and write
clean
374000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
E0000
unkown image
page read and write
clean
1E0000
heap default
page read and write
clean
7EFD0000
unkown image
page readonly
clean
614000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
73E000
unkown
page read and write
clean
8D0000
heap private
page read and write
clean
16C000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
4B0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
840000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
550000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
3B0000
unkown
page read and write
clean
750000
unkown image
page read and write
clean
2343000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
4B6000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
A0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
6C0000
unkown image
page readonly
clean
214000
heap private
page read and write
clean
80000
unkown
page read and write
clean
12C000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
364000
unkown
page read and write
clean
13C000
unkown
page read and write
clean
21C0000
heap private
page read and write
clean
1FD0000
unkown image
page readonly
clean
1350000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
380000
heap default
page read and write
clean
7EFB0000
unkown image
page readonly
clean
4E4000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
21C5000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
19AF000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
160000
unkown
page read and write
clean
2E6000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
5F0000
unkown image
page readonly
clean
204000
heap default
page read and write
clean
19FE000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
610000
heap private
page read and write
clean
7EFDF000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2474000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
2F7000
heap default
page read and write
clean
710000
unkown image
page readonly
clean
7586000
unkown
page execute and read and write
clean
24C000
unkown
page read and write
clean
C5F000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
407000
heap default
page read and write
clean
3F0000
heap private
page read and write
clean
4E0000
unkown image
page readonly
clean
80000
unkown
page read and write
clean
E0000
unkown image
page read and write
clean
10000
unkown image
page read and write
clean
2A3000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
60A000
heap default
page read and write
clean
5F0000
unkown image
page readonly
clean
770000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
257000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
1345000
unkown
page execute and read and write
clean
827000
heap default
page read and write
clean
350000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
E0000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
6ED000
unkown
page read and write
clean
4F0000
unkown
page read and write
clean
1E0000
heap default
page read and write
clean
86B000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
8A0000
unkown image
page readonly
clean
F0000
unkown
page read and write
clean
A0000
heap private
page read and write
clean
1D10000
unkown image
page readonly
clean
70000
unkown image
page read and write
clean
330000
heap default
page read and write
clean
AB0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
F0000
unkown
page read and write
clean
329000
heap default
page read and write
clean
50000
unkown image
page readonly
clean
219000
heap default
page read and write
clean
990000
unkown image
page readonly
clean
A00000
unkown image
page readonly
clean
550000
unkown image
page read and write
clean
760000
unkown image
page readonly
clean
5D4000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
F20000
unkown image
page readonly
clean
32F000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
4E6000
unkown
page read and write
clean
3BE000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
23A000
heap default
page read and write
clean
182E000
unkown
page read and write
clean
5F4000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
A4000
heap private
page read and write
clean
2F7000
heap default
page read and write
clean
40000
unkown image
page readonly
clean
780000
unkown image
page readonly
clean
820000
heap default
page read and write
clean
7EFC0000
unkown image
page readonly
clean
680000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
453000
heap default
page read and write
clean
426000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
D0000
unkown image
page readonly
clean
20B0000
unkown image
page readonly
clean
E00000
unkown image
page readonly
clean
2430000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
8E0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
536000
unkown
page read and write
clean
C60000
heap private
page read and write
clean
36C000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
138F000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
77CE000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
540000
unkown image
page readonly
clean
22D000
unkown
page read and write
clean
5C0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
770000
unkown image
page readonly
clean
1DC000
unkown
page read and write
clean
D40000
heap private
page read and write
clean
20000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
AA0000
unkown image
page readonly
clean
86D000
heap default
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
D80000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
60000
unkown image
page readonly
clean
B70000
heap private
page read and write
clean
5C0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
2AA000
heap default
page read and write
clean
76C000
unkown
page read and write
clean
246000
unkown
page read and write
clean
386000
unkown
page read and write
clean
367000
heap default
page read and write
clean
86F000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
2F0000
heap default
page read and write
clean
90000
unkown
page read and write
clean
362000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
25AF000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
902E000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
850000
unkown image
page readonly
clean
670000
heap default
page read and write
clean
4D0000
unkown image
page readonly
clean
2CC0000
unkown image
page readonly
clean
2030000
heap private
page read and write
clean
194000
heap private
page read and write
clean
40000
unkown image
page readonly
clean
32E000
heap default
page read and write
clean
1310000
heap private
page read and write
clean
20000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
2470000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
60F000
heap default
page read and write
clean
C40000
unkown image
page readonly
clean
367000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
170000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
232000
heap default
page read and write
clean
1D0000
heap private
page read and write
clean
100000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
780000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
283E000
unkown
page read and write
clean
5B0000
heap private
page read and write
clean
60000
unkown image
page readonly
clean
E0000
unkown image
page read and write
clean
777C000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
A60000
unkown image
page readonly
clean
740000
unkown image
page readonly
clean
266000
unkown
page read and write
clean
5B0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
2F4000
heap private
page read and write
clean
8D6000
heap private
page read and write
clean
254000
heap private
page read and write
clean
C0000
unkown image
page read and write
clean
CEE000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
144000
heap private
page read and write
clean
16277000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
810000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7B8C000
unkown
page read and write
clean
2A80000
unkown
page execute and read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
687000
heap default
page read and write
clean
140000
heap private
page read and write
clean
290E000
unkown
page read and write
clean
215B000
heap private
page read and write
clean
2EE000
heap default
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
DC0000
heap private
page read and write
clean
378000
unkown
page read and write
clean
74D000
unkown
page read and write
clean
EA0000
heap private
page read and write
clean
5D0000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
2040000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
20000
unkown image
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
76AF000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
4EE000
unkown
page read and write
clean
E0000
unkown image
page read and write
clean
6D0000
unkown
page read and write
clean
2320000
heap private
page read and write
clean
2B0000
heap default
page read and write
clean
A60000
unkown
page read and write
clean
28E000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
368000
heap default
page read and write
clean
190000
unkown
page read and write
clean
B0000
unkown
page read and write
clean
210000
unkown
page read and write
clean
26B0000
heap private
page read and write
clean
150000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
3A6000
heap default
page read and write
clean
30000
unkown image
page readonly
clean
620000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
29CE000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
70000
unkown image
page read and write
clean
800000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
25B000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
239F000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
3E6000
unkown
page read and write
clean
39D000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
1390000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
D0000
heap default
page read and write
clean
30000
unkown image
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
303000
heap default
page read and write
clean
F0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
1ADF000
unkown
page read and write
clean
2670000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
45A000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
20D000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
2AB5000
unkown
page execute and read and write
clean
784000
heap private
page read and write
clean
2F0000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2125000
heap private
page read and write
clean
1F0000
heap private
page read and write
clean
10000000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
10000000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
79D000
unkown
page read and write
clean
316000
unkown
page read and write
clean
9E0000
unkown image
page readonly
clean
256F000
unkown
page read and write
clean
12DF000
unkown
page read and write
clean
2F0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
1B0000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
1310000
unkown
page execute and read and write
clean
375000
unkown
page read and write
clean
E0000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
526000
unkown
page read and write
clean
4F0000
unkown
page read and write
clean
890000
heap private
page read and write
clean
1FC000
unkown
page read and write
clean
337000
heap default
page read and write
clean
730000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
233000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
230000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
865000
heap default
page read and write
clean
373000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
A70000
unkown image
page readonly
clean
6CF000
unkown
page read and write
clean
30000
unkown image
page read and write
clean
420000
heap default
page read and write
clean
343000
heap default
page read and write
clean
1DB000
unkown
page read and write
clean
296000
unkown
page read and write
clean
16277000
unkown image
page readonly
clean
21F000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
40000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
314000
heap default
page read and write
clean
5D7000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7E0000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
920000
unkown image
page readonly
clean
7630000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
26F0000
unkown
page read and write
clean
526000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
250000
heap default
page read and write
clean
4E0000
heap private
page read and write
clean
13C000
unkown
page read and write
clean
26EF000
heap private
page read and write
clean
1A0000
unkown image
page readonly
clean
144000
heap private
page read and write
clean
780000
heap private
page read and write
clean
1A0000
unkown
page read and write
clean
D20000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
730000
unkown
page read and write
clean
606000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
642000
heap default
page read and write
clean
266B000
unkown
page read and write
clean
DAE000
unkown
page read and write
clean
876000
unkown
page read and write
clean
372000
unkown
page read and write
clean
7FF000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7B4E000
unkown
page read and write
clean
19A000
unkown
page read and write
clean
2120000
heap private
page read and write
clean
863000
unkown
page read and write
clean
75EF000
unkown
page read and write
clean
910000
unkown image
page readonly
clean
1FA0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
2B7000
heap default
page read and write
clean
3F0000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
250000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
4E4000
heap private
page read and write
clean
E5E000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
8A0000
unkown image
page readonly
clean
530000
heap private
page read and write
clean
2E0000
unkown
page read and write
clean
878000
unkown
page read and write
clean
1D0000
unkown
page read and write
clean
2E1F000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
844000
heap default
page read and write
clean
9C000
unkown
page read and write
clean
26EF000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
780000
unkown image
page readonly
clean
5D0000
heap default
page read and write
clean
526000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
240000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
500000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7EFC2000
unkown image
page readonly
clean
36E000
heap default
page read and write
clean
7635000
heap private
page read and write
clean
2A70000
heap private
page read and write
clean
There are 572 hidden memdumps, click here to show them.