IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Compensation_Reject-958463727-09292021.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Author: Test, Last Saved By: Test, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Jun 5 19:17:20 2015, Last Saved Time/Date: Wed Sep 29 09:13:10 2021, Security: 0
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\44469.4662202546[1].dat
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Drezd.red
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\VBE\MSForms.exd
data
dropped
clean
C:\Users\user\AppData\Local\Temp\VBE\RefEdit.exd
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Drezd.red
malicious
C:\Windows\SysWOW64\regsvr32.exe
-silent ..\Drezd.red
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Drezd1.red
malicious
C:\Windows\SysWOW64\schtasks.exe
'C:\Windows\system32\schtasks.exe' /Create /RU 'NT AUTHORITY\SYSTEM' /tn hhxoksfm /tr 'regsvr32.exe -s \'C:\Users\user\Drezd.red\'' /SC ONCE /Z /ST 11:16 /ET 11:28
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Drezd2.red
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\System32\reg.exe
C:\Windows\system32\reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths' /f /t REG_DWORD /v 'C:\ProgramData\Microsoft\Yenslqus' /d '0'
malicious
C:\Windows\System32\reg.exe
C:\Windows\system32\reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths' /f /t REG_DWORD /v 'C:\Users\user\AppData\Roaming\Microsoft\Gruwmuaixpvu' /d '0'
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\Drezd.red'
malicious
C:\Windows\System32\taskeng.exe
taskeng.exe {0A2617DB-2F69-45ED-A602-BD27C244EA7E} S-1-5-18:NT AUTHORITY\System:Service:
clean
There are 5 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://188.165.62.15/44469.4662202546.dat
188.165.62.15
clean
http://www.%s.comPA
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://servername/isapibackend.dll
unknown
clean

IPs

IP
Domain
Country
Malicious
188.165.62.15
unknown
France
clean
45.84.0.123
unknown
Russian Federation
clean
45.138.172.22
unknown
Germany
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
`-
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2E408
2E408
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{95664EDB-0C22-44E7-8FE6-BF4928A3BEDE}\2.0
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{95664EDB-0C22-44E7-8FE6-BF4928A3BEDE}\2.0\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{95664EDB-0C22-44E7-8FE6-BF4928A3BEDE}\2.0\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{95664EDB-0C22-44E7-8FE6-BF4928A3BEDE}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{95664EDB-0C22-44E7-8FE6-BF4928A3BEDE}\2.0
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{95664EDB-0C22-44E7-8FE6-BF4928A3BEDE}\2.0\FLAGS
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{95664EDB-0C22-44E7-8FE6-BF4928A3BEDE}\2.0\0\win32
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{95664EDB-0C22-44E7-8FE6-BF4928A3BEDE}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C01B6712-8D6F-49D0-B7CC-AEFEC841F6DD}\1.2
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C01B6712-8D6F-49D0-B7CC-AEFEC841F6DD}\1.2\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C01B6712-8D6F-49D0-B7CC-AEFEC841F6DD}\1.2\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C01B6712-8D6F-49D0-B7CC-AEFEC841F6DD}\1.2\HELPDIR
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00024518-0000-0000-C000-000000000046}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
%k-
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\62693
62693
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\629AF
629AF
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common
QMSessionCount
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\General
LastAutoSavePurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Ujjvkzyi
c4341091
clean
HKEY_CURRENT_USER\Software\Microsoft\Ujjvkzyi
f1abc0df
clean
HKEY_CURRENT_USER\Software\Microsoft\Ujjvkzyi
f3eae0a3
clean
HKEY_CURRENT_USER\Software\Microsoft\Ujjvkzyi
4b5687c6
clean
HKEY_CURRENT_USER\Software\Microsoft\Ujjvkzyi
365ec84c
clean
HKEY_CURRENT_USER\Software\Microsoft\Ujjvkzyi
8ee2af29
clean
HKEY_CURRENT_USER\Software\Microsoft\Ujjvkzyi
4917a7ba
clean
HKEY_CURRENT_USER\Software\Microsoft\Ujjvkzyi
bb7d7f67
clean
HKEY_CURRENT_USER\Software\Microsoft\Ujjvkzyi
c4341091
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\Handshake\{0A2617DB-2F69-45ED-A602-BD27C244EA7E}
data
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Mramsciwgwru
1c1ac9f8
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Mramsciwgwru
298519b6
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Mramsciwgwru
2bc439ca
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Mramsciwgwru
93785eaf
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Mramsciwgwru
ee701125
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Mramsciwgwru
56cc7640
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Mramsciwgwru
91397ed3
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Mramsciwgwru
6353a60e
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Mramsciwgwru
1c1ac9f8
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
C:\ProgramData\Microsoft\Yenslqus
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
C:\Users\user\AppData\Roaming\Microsoft\Gruwmuaixpvu
clean
There are 217 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
3C0000
unkown image
page execute and read and write
malicious
370000
unkown image
page execute and read and write
malicious
230000
unkown
page execute and read and write
malicious
4C0000
unkown
page execute and read and write
malicious
6E0000
unkown image
page readonly
clean
6E0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
550000
unkown image
page readonly
clean
BF0000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
486000
unkown
page read and write
clean
332000
unkown
page read and write
clean
2D70000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
240000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
CCF000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
70291000
unkown image
page execute and read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
554000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
160000
unkown image
page read and write
clean
7EFD0000
unkown image
page readonly
clean
440000
heap private
page read and write
clean
BD000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2F0000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
150000
unkown image
page readonly
clean
2D0000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
BF4000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2DD000
unkown
page read and write
clean
25A0000
unkown
page read and write
clean
1440000
unkown
page read and write
clean
190000
heap private
page read and write
clean
324000
unkown
page read and write
clean
290000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2623000
heap private
page read and write
clean
570000
unkown
page read and write
clean
6F0000
unkown image
page readonly
clean
2600000
heap private
page read and write
clean
1B0000
unkown image
page read and write
clean
460000
unkown image
page readonly
clean
56F000
heap default
page read and write
clean
70571000
unkown image
page execute read
clean
28A000
heap default
page read and write
clean
5A4000
heap private
page read and write
clean
950000
heap private
page read and write
clean
A40000
unkown image
page readonly
clean
9FF000
unkown
page read and write
clean
2605000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
6DF000
heap private
page read and write
clean
5F6000
heap private
page read and write
clean
20F0000
heap private
page read and write
clean
9AD000
unkown
page read and write
clean
70635000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
740000
unkown image
page readonly
clean
1340000
heap private
page read and write
clean
3C0000
heap default
page read and write
clean
1AB000
unkown
page read and write
clean
1B0000
heap private
page read and write
clean
300000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
940000
unkown image
page readonly
clean
147000
heap default
page read and write
clean
7028F000
unkown image
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
160000
unkown image
page readonly
clean
11B000
unkown
page read and write
clean
15C000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
701E0000
unkown image
page readonly
clean
1E6000
unkown
page read and write
clean
226000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
80000
unkown
page read and write
clean
B10000
unkown image
page readonly
clean
867000
heap default
page read and write
clean
52C000
unkown
page read and write
clean
2C6000
unkown
page read and write
clean
683000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
430000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
700000
heap default
page read and write
clean
530000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
31E000
heap default
page read and write
clean
330000
heap default
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
2EBE000
unkown
page read and write
clean
480000
heap private
page read and write
clean
660000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7F0000
unkown image
page readonly
clean
5F0000
heap private
page read and write
clean
6C0000
heap default
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
59B000
unkown
page read and write
clean
297E000
unkown
page read and write
clean
D3E000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
286E000
unkown
page read and write
clean
990000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7E0000
unkown image
page readonly
clean
142D000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
366000
unkown
page read and write
clean
1B0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
5B0000
unkown image
page readonly
clean
2045000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
F0000
unkown
page read and write
clean
197F000
unkown
page read and write
clean
4A0000
unkown image
page readonly
clean
98B000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
2E0000
unkown image
page readonly
clean
327000
heap default
page read and write
clean
30000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
BDF000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
670000
unkown image
page readonly
clean
2E7000
heap default
page read and write
clean
132F000
unkown
page read and write
clean
947000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
19A000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7058F000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
1A0000
heap private
page read and write
clean
560000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
14DE000
unkown
page read and write
clean
70591000
unkown image
page execute read
clean
F30000
unkown image
page readonly
clean
E6D000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7EFE0000
unkown image
page readonly
clean
4D0000
unkown image
page read and write
clean
7EFC0000
unkown image
page readonly
clean
390000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
283000
heap default
page read and write
clean
2660000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
10C000
unkown
page read and write
clean
DCC000
unkown
page read and write
clean
E0000
unkown image
page read and write
clean
70588000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
FD000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
C30000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
3DD000
unkown
page read and write
clean
25EC000
unkown
page read and write
clean
4D2000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
80000
unkown
page read and write
clean
6C0000
heap default
page read and write
clean
267F000
heap private
page read and write
clean
630000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
35E000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
334000
unkown
page read and write
clean
3AD000
heap default
page read and write
clean
1D90000
unkown image
page readonly
clean
98F000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
32C000
unkown
page read and write
clean
3D9000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
1FD0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
530000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
30000
unkown image
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
30000
unkown image
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
780000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
230000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
620000
unkown image
page readonly
clean
D7C000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
20000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
3B6000
heap default
page read and write
clean
2C0000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
A0000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
3BC000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
135C000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
564000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
AF0000
unkown image
page readonly
clean
590000
unkown image
page readonly
clean
DA0000
heap private
page read and write
clean
2F4000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
550000
heap private
page read and write
clean
701E0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
330000
unkown
page read and write
clean
3B0000
heap private
page read and write
clean
303000
heap default
page read and write
clean
216B000
heap private
page read and write
clean
696000
heap private
page read and write
clean
7058D000
unkown image
page read and write
clean
800000
unkown image
page readonly
clean
6FF000
heap default
page read and write
clean
60000
unkown image
page readonly
clean
A7000
heap default
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
1B4000
heap private
page read and write
clean
259E000
unkown
page read and write
clean
1F80000
unkown image
page readonly
clean
964000
heap default
page read and write
clean
6A0000
unkown image
page read and write
clean
50000
unkown image
page readonly
clean
998000
unkown
page read and write
clean
7A0000
unkown image
page readonly
clean
26B0000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
C70000
heap private
page read and write
clean
30000
unkown image
page readonly
clean
207B000
heap private
page read and write
clean
5D6000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
537000
heap default
page read and write
clean
281E000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
3C0000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
466000
unkown
page read and write
clean
2D4000
heap private
page read and write
clean
985000
heap default
page read and write
clean
DC000
unkown
page read and write
clean
192F000
unkown
page read and write
clean
2130000
heap private
page read and write
clean
20000
unkown image
page read and write
clean
701FD000
unkown image
page read and write
clean
7EFB2000
unkown image
page readonly
clean
EF0000
heap private
page read and write
clean
1C0000
unkown
page execute and read and write
clean
7EFC0000
unkown image
page readonly
clean
560000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
701F8000
unkown image
page readonly
clean
98D000
heap default
page read and write
clean
30000
unkown image
page readonly
clean
444000
heap private
page read and write
clean
2D6F000
unkown
page read and write
clean
220000
heap private
page read and write
clean
3B4000
heap private
page read and write
clean
560000
unkown image
page readonly
clean
2B0000
unkown
page execute and read and write
clean
C54000
heap private
page read and write
clean
3C0000
unkown image
page readonly
clean
3A0000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
38A000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
4B0000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
2E0000
heap default
page read and write
clean
7EFD0000
unkown image
page readonly
clean
160000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
3C4000
heap default
page read and write
clean
6FA000
heap default
page read and write
clean
370000
unkown image
page read and write
clean
13C000
unkown
page read and write
clean
5A6000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
355000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
143F000
unkown
page read and write
clean
5D0000
heap private
page read and write
clean
4C6000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
490000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
200000
heap default
page read and write
clean
6C7000
heap default
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
4C6000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
279F000
heap private
page read and write
clean
580000
unkown image
page readonly
clean
8F0000
unkown image
page readonly
clean
C12000
heap private
page read and write
clean
560000
unkown image
page readonly
clean
5EF000
unkown
page read and write
clean
100000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
30000
unkown image
page read and write
clean
AE0000
unkown image
page readonly
clean
336000
unkown
page read and write
clean
26E000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
F3000
heap default
page read and write
clean
20D000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
12CE000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
70000
heap default
page read and write
clean
7EFD0000
unkown image
page readonly
clean
960000
unkown image
page readonly
clean
338000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
860000
heap default
page read and write
clean
73F000
unkown
page read and write
clean
53C000
unkown
page read and write
clean
70570000
unkown image
page readonly
clean
80000
unkown
page read and write
clean
14F0000
heap private
page read and write
clean
2F6F000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
F6F000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
70000
unkown image
page read and write
clean
5F3000
heap private
page read and write
clean
300000
unkown
page read and write
clean
800000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
36E000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
770000
unkown image
page readonly
clean
484000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
293F000
unkown
page read and write
clean
80000
unkown
page read and write
clean
3E0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
6F0000
unkown image
page readonly
clean
19FE000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
1CB0000
unkown image
page readonly
clean
7061F000
unkown image
page read and write
clean
70201000
unkown image
page execute read
clean
7EFB2000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
410000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
3E6000
unkown
page read and write
clean
940000
heap default
page read and write
clean
160F000
unkown
page read and write
clean
140000
unkown
page read and write
clean
664000
heap private
page read and write
clean
60000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
242E000
unkown
page read and write
clean
380000
heap private
page read and write
clean
5A0000
unkown
page read and write
clean
1A4000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
510000
unkown image
page readonly
clean
28D000
unkown
page read and write
clean
13EE000
unkown
page read and write
clean
60000
unkown image
page read and write
clean
670000
unkown image
page readonly
clean
193000
heap default
page read and write
clean
70621000
unkown image
page execute and read and write
clean
5A0000
heap private
page read and write
clean
20F5000
heap private
page read and write
clean
F70000
unkown
page read and write
clean
ADD000
unkown
page read and write
clean
550000
heap private
page read and write
clean
7EFDF000
unkown
page read and write
clean
F0000
unkown image
page read and write
clean
490000
unkown
page read and write
clean
DE0000
unkown image
page readonly
clean
1B6000
unkown
page read and write
clean
75D000
unkown
page read and write
clean
554000
heap private
page read and write
clean
E10000
unkown image
page readonly
clean
21B0000
unkown image
page readonly
clean
BD0000
unkown image
page readonly
clean
70570000
unkown image
page readonly
clean
23E000
heap default
page read and write
clean
490000
heap default
page read and write
clean
77000
heap default
page read and write
clean
3A7000
heap default
page read and write
clean
2B7000
heap default
page read and write
clean
590000
unkown image
page readonly
clean
237000
heap default
page read and write
clean
2F0000
heap private
page read and write
clean
992000
unkown
page read and write
clean
340000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
4B4000
heap private
page read and write
clean
C0000
unkown image
page readonly
clean
21E000
unkown
page read and write
clean
690000
heap private
page read and write
clean
143E000
unkown
page read and write
clean
170000
unkown
page read and write
clean
6E4000
heap default
page read and write
clean
720000
unkown image
page readonly
clean
336000
unkown
page read and write
clean
AC0000
unkown
page read and write
clean
140000
heap default
page read and write
clean
26CA000
unkown
page read and write
clean
61D000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2040000
heap private
page read and write
clean
470000
unkown
page read and write
clean
210000
heap private
page read and write
clean
60000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
377000
heap default
page read and write
clean
2EE000
heap default
page read and write
clean
990000
unkown image
page readonly
clean
554000
heap private
page read and write
clean
2C4C000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
24DF000
unkown
page read and write
clean
370000
heap default
page read and write
clean
1E0000
unkown image
page read and write
clean
207000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
64F000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
705DD000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
710000
unkown image
page readonly
clean
450000
unkown
page read and write
clean
DAF000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
B1F000
unkown
page read and write
clean
996000
unkown
page read and write
clean
3DF000
heap default
page read and write
clean
900000
unkown image
page readonly
clean
7024D000
unkown image
page readonly
clean
11D0000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
383000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
800000
unkown image
page readonly
clean
7C0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
20C0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
7F0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
701E1000
unkown image
page execute read
clean
569000
heap default
page read and write
clean
343000
heap default
page read and write
clean
DE000
heap default
page read and write
clean
212B000
heap private
page read and write
clean
70000
unkown image
page read and write
clean
17E000
heap default
page read and write
clean
7EFB0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
216000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
B00000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
2D6000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
AE000
heap default
page read and write
clean
3C6000
unkown
page read and write
clean
665000
heap private
page read and write
clean
702A5000
unkown image
page readonly
clean
4A6000
unkown
page read and write
clean
470000
unkown
page read and write
clean
900000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
540000
unkown image
page readonly
clean
23B000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
28C000
unkown
page read and write
clean
20000
unkown image
page read and write
clean
20000
unkown image
page readonly
clean
1C80000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
291E000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
1CD000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
884000
heap default
page read and write
clean
7EFC0000
unkown image
page readonly
clean
C50000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2510000
heap private
page read and write
clean
FA000
heap default
page read and write
clean
351000
heap default
page read and write
clean
490000
unkown
page read and write
clean
660000
heap private
page read and write
clean
20000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
180000
unkown
page read and write
clean
2720000
heap private
page read and write
clean
2135000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
360000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
740000
unkown
page read and write
clean
100000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
384000
heap private
page read and write
clean
70000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
983000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
4B0000
heap private
page read and write
clean
333000
unkown
page read and write
clean
1D0000
unkown
page read and write
clean
358000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
68E000
unkown
page read and write
clean
335000
unkown
page read and write
clean
30A000
heap default
page read and write
clean
90000
unkown
page read and write
clean
3B0000
unkown
page read and write
clean
C8B000
heap private
page read and write
clean
30000
unkown image
page readonly
clean
2660000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
183E000
unkown
page read and write
clean
2170000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
2B0000
heap default
page read and write
clean
701FF000
unkown image
page readonly
clean
337000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
600000
unkown
page read and write
clean
2D0000
heap private
page read and write
clean
240000
heap default
page read and write
clean
7EFDF000
unkown
page read and write
clean
A90000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
4B4000
heap private
page read and write
clean
30000
unkown image
page readonly
clean
There are 620 hidden memdumps, click here to show them.