IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Rebate-690835286-10052021.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Author: Test, Last Saved By: Test, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Jun 5 19:17:20 2015, Last Saved Time/Date: Tue Oct 5 09:11:15 2021, Security: 0
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\44474.9279916667[1].dat
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Celod.wac2
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\VBE\MSForms.exd
data
dropped
clean
C:\Users\user\AppData\Local\Temp\VBE\RefEdit.exd
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Celod.wac
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Celod.wac1
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Celod.wac2
malicious
C:\Windows\SysWOW64\regsvr32.exe
-silent ..\Celod.wac2
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\SysWOW64\schtasks.exe
'C:\Windows\system32\schtasks.exe' /Create /RU 'NT AUTHORITY\SYSTEM' /tn tcrzbkfctd /tr 'regsvr32.exe -s \'C:\Users\user\Celod.wac2\'' /SC ONCE /Z /ST 22:20 /ET 22:32
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\Celod.wac2'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\Celod.wac2'
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\System32\reg.exe
C:\Windows\system32\reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths' /f /t REG_DWORD /v 'C:\ProgramData\Microsoft\Jjyjdgvcvuvi' /d '0'
malicious
C:\Windows\System32\reg.exe
C:\Windows\system32\reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths' /f /t REG_DWORD /v 'C:\Users\user\AppData\Roaming\Microsoft\Uwwyocree' /d '0'
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\Celod.wac2'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\Celod.wac2'
malicious
There are 4 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://101.99.90.118/44474.9279916667.dat
101.99.90.118
malicious
http://www.%s.comPA
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://servername/isapibackend.dll
unknown
clean

IPs

IP
Domain
Country
Malicious
185.123.53.199
unknown
unknown
clean
101.99.90.118
unknown
Malaysia
clean
194.36.191.21
unknown
Netherlands
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
8m$
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2D855
2D855
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0EB29A2E-C6DB-422E-B4AC-7193DE747964}\2.0
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0EB29A2E-C6DB-422E-B4AC-7193DE747964}\2.0\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0EB29A2E-C6DB-422E-B4AC-7193DE747964}\2.0\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0EB29A2E-C6DB-422E-B4AC-7193DE747964}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{0EB29A2E-C6DB-422E-B4AC-7193DE747964}\2.0
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{0EB29A2E-C6DB-422E-B4AC-7193DE747964}\2.0\FLAGS
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{0EB29A2E-C6DB-422E-B4AC-7193DE747964}\2.0\0\win32
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{0EB29A2E-C6DB-422E-B4AC-7193DE747964}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6B19CBD2-89D6-4CB1-BD29-3E5F5AA7E1E4}\1.2
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6B19CBD2-89D6-4CB1-BD29-3E5F5AA7E1E4}\1.2\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6B19CBD2-89D6-4CB1-BD29-3E5F5AA7E1E4}\1.2\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6B19CBD2-89D6-4CB1-BD29-3E5F5AA7E1E4}\1.2\HELPDIR
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00024518-0000-0000-C000-000000000046}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
!x$
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\4F40F
4F40F
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\4F66F
4F66F
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_CURRENT_USER\Software\Microsoft\Imklvydwgebgy
f69f8db
clean
HKEY_CURRENT_USER\Software\Microsoft\Imklvydwgebgy
3af62895
clean
HKEY_CURRENT_USER\Software\Microsoft\Imklvydwgebgy
38b708e9
clean
HKEY_CURRENT_USER\Software\Microsoft\Imklvydwgebgy
800b6f8c
clean
HKEY_CURRENT_USER\Software\Microsoft\Imklvydwgebgy
fd032006
clean
HKEY_CURRENT_USER\Software\Microsoft\Imklvydwgebgy
45bf4763
clean
HKEY_CURRENT_USER\Software\Microsoft\Imklvydwgebgy
824a4ff0
clean
HKEY_CURRENT_USER\Software\Microsoft\Imklvydwgebgy
7020972d
clean
HKEY_CURRENT_USER\Software\Microsoft\Imklvydwgebgy
f69f8db
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Mgjaeuelud
b85dcf60
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Mgjaeuelud
8dc21f2e
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Mgjaeuelud
8f833f52
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Mgjaeuelud
373f5837
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Mgjaeuelud
4a3717bd
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Mgjaeuelud
f28b70d8
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Mgjaeuelud
357e784b
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Mgjaeuelud
c714a096
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Mgjaeuelud
b85dcf60
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
C:\ProgramData\Microsoft\Jjyjdgvcvuvi
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
C:\Users\user\AppData\Roaming\Microsoft\Uwwyocree
clean
There are 212 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
80000
unkown image
page execute and read and write
malicious
E0000
unkown image
page execute and read and write
malicious
4C0000
unkown
page execute and read and write
malicious
1A0000
unkown
page execute and read and write
malicious
F70000
unkown image
page readonly
clean
300000
heap default
page read and write
clean
50000
unkown image
page readonly
clean
200000
heap private
page read and write
clean
9EF000
stack
page read and write
clean
2C6000
unkown
page read and write
clean
5B4000
heap private
page read and write
clean
890000
unkown image
page readonly
clean
B0000
unkown image
page readonly
clean
1290000
heap private
page read and write
clean
977000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
440000
heap default
page read and write
clean
436000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
197000
heap default
page read and write
clean
2B4000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
1460000
heap private
page read and write
clean
8D1000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
8F0000
unkown image
page readonly
clean
667000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
DA0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
EDE000
stack
page read and write
clean
6CC08000
unkown image
page execute and read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
D0000
unkown
page execute and read and write
clean
320000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
28CF000
stack
page read and write
clean
6CB18000
unkown image
page readonly
clean
360000
heap default
page read and write
clean
2110000
heap private
page read and write
clean
3B0000
unkown image
page readonly
clean
6CC06000
unkown image
page read and write
clean
4C0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
13CC000
stack
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
6CB01000
unkown image
page execute read
clean
620000
heap private
page read and write
clean
B10000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7B0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
240000
heap default
page read and write
clean
C5E000
stack
page read and write
clean
5C0000
heap private
page read and write
clean
D40000
heap private
page read and write
clean
D45000
heap private
page read and write
clean
50000
unkown image
page readonly
clean
22D000
unkown
page read and write
clean
304000
heap private
page read and write
clean
510000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
80000
unkown
page read and write
clean
2AD000
unkown
page read and write
clean
390000
heap private
page read and write
clean
390000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
50000
unkown image
page readonly
clean
404000
heap private
page read and write
clean
169E000
stack
page read and write
clean
2D40000
unkown image
page readonly
clean
6CB42000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
140000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
1E3000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
33F000
stack
page read and write
clean
890000
unkown
page read and write
clean
7F0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
8CD000
unkown
page read and write
clean
59A000
heap default
page read and write
clean
17C000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
380000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
324000
heap private
page read and write
clean
1B6000
unkown
page read and write
clean
CA000
unkown
page read and write
clean
B0000
unkown
page execute and read and write
clean
6CB1D000
unkown image
page read and write
clean
660000
heap default
page read and write
clean
300000
heap private
page read and write
clean
640000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
560000
heap default
page read and write
clean
350000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
8CF000
heap default
page read and write
clean
21CB000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
584000
heap default
page read and write
clean
186000
unkown
page read and write
clean
1DD000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
12B3000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
170000
unkown
page read and write
clean
3C6000
unkown
page read and write
clean
59E000
stack
page read and write
clean
BF0000
unkown image
page readonly
clean
145F000
stack
page read and write
clean
570000
unkown
page read and write
clean
243E000
stack
page read and write
clean
7F0000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
7EFB0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
850000
heap private
page read and write
clean
30000
unkown image
page read and write
clean
7EFD0000
unkown image
page readonly
clean
CA0000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
CBD000
unkown
page read and write
clean
2E7E000
stack
page read and write
clean
3AA000
heap default
page read and write
clean
24000
heap private
page read and write
clean
556000
unkown
page read and write
clean
387000
heap default
page read and write
clean
30000
unkown image
page readonly
clean
870000
unkown image
page readonly
clean
DBF000
heap private
page read and write
clean
206000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
17C000
unkown
page read and write
clean
3B9000
heap default
page read and write
clean
990000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
69F000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
14E0000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
150000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
8C9000
unkown
page read and write
clean
174000
heap private
page read and write
clean
690000
unkown image
page readonly
clean
11EC000
stack
page read and write
clean
248A000
stack
page read and write
clean
C10000
heap private
page read and write
clean
530000
unkown image
page readonly
clean
510000
heap private
page read and write
clean
3AE000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
E0000
unkown image
page read and write
clean
20000
unkown image
page read and write
clean
646000
heap private
page read and write
clean
570000
heap private
page read and write
clean
980000
unkown image
page readonly
clean
690000
unkown image
page readonly
clean
7F0000
unkown image
page readonly
clean
6CB1D000
unkown image
page read and write
clean
F0000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
3BF000
heap default
page read and write
clean
7EFD0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
6CB00000
unkown image
page readonly
clean
384000
heap private
page read and write
clean
106000
unkown
page read and write
clean
254000
heap private
page read and write
clean
B8E000
stack
page read and write
clean
2540000
heap private
page read and write
clean
564000
heap private
page read and write
clean
266000
unkown
page read and write
clean
2B0000
heap default
page read and write
clean
190000
heap default
page read and write
clean
660000
unkown image
page readonly
clean
574000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
880000
heap default
page read and write
clean
130000
unkown image
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
520000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
6CB00000
unkown image
page readonly
clean
410000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
220000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
346000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
A5C000
stack
page read and write
clean
7A0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
CEE000
stack
page read and write
clean
15A000
heap default
page read and write
clean
600000
unkown image
page readonly
clean
6F0000
unkown image
page readonly
clean
486000
unkown
page read and write
clean
29A000
heap default
page read and write
clean
620000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
BD000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
446000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
4C6000
unkown
page read and write
clean
3A3000
heap default
page read and write
clean
247000
heap default
page read and write
clean
20000
unkown image
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
12C000
unkown
page read and write
clean
3D4000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
270000
unkown
page read and write
clean
1CE000
heap default
page read and write
clean
720000
unkown image
page readonly
clean
137E000
stack
page read and write
clean
AEF000
stack
page read and write
clean
7EFE0000
unkown image
page readonly
clean
417000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
230000
unkown
page read and write
clean
3D8000
unkown
page read and write
clean
2115000
heap private
page read and write
clean
7E0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
6CB21000
unkown image
page execute read
clean
270000
unkown image
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
190000
heap private
page read and write
clean
1EA000
heap default
page read and write
clean
214B000
heap private
page read and write
clean
20000
unkown image
page readonly
clean
DC000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
264E000
stack
page read and write
clean
7EFC0000
unkown image
page readonly
clean
6CB00000
unkown image
page readonly
clean
356000
heap private
page read and write
clean
8CA000
heap default
page read and write
clean
196000
heap private
page read and write
clean
2EE000
heap default
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
F30000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
2760000
unkown
page read and write
clean
510000
unkown image
page readonly
clean
180000
unkown
page execute and read and write
clean
130F000
heap private
page read and write
clean
3D5000
unkown
page read and write
clean
377000
heap default
page read and write
clean
6CB21000
unkown image
page execute read
clean
D30000
unkown image
page readonly
clean
26F000
stack
page read and write
clean
A70000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
394000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
E0C000
stack
page read and write
clean
C0000
unkown image
page readonly
clean
2E0000
heap default
page read and write
clean
2B0000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
8C5000
unkown
page read and write
clean
253F000
stack
page read and write
clean
60000
unkown image
page readonly
clean
29D000
unkown
page read and write
clean
BC000
unkown
page read and write
clean
1CB0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
C0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
288F000
stack
page read and write
clean
20000
unkown image
page readonly
clean
3C7000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
1D40000
unkown image
page readonly
clean
293000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
1295000
heap private
page read and write
clean
490000
unkown
page read and write
clean
A30000
unkown image
page readonly
clean
650000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
14DF000
heap private
page read and write
clean
AA0000
heap private
page read and write
clean
90000
unkown image
page read and write
clean
160000
unkown image
page read and write
clean
33D000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
400000
unkown
page read and write
clean
6CC08000
unkown image
page execute and read and write
clean
3D3000
unkown
page read and write
clean
34D000
heap default
page read and write
clean
320000
unkown image
page read and write
clean
10000
unkown image
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
1D0000
unkown
page read and write
clean
6CB1F000
unkown image
page readonly
clean
2B0000
unkown image
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
7EFC0000
unkown image
page readonly
clean
2100000
heap private
page read and write
clean
994000
heap default
page read and write
clean
9EF000
stack
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
970000
heap default
page read and write
clean
E40000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
1AF000
stack
page read and write
clean
1D50000
unkown image
page readonly
clean
3CA000
heap default
page read and write
clean
307000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
30000
unkown image
page read and write
clean
20000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
5C4000
heap private
page read and write
clean
40000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
B0000
unkown
page read and write
clean
FC000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
370000
heap default
page read and write
clean
3E0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
170000
heap private
page read and write
clean
160000
unkown
page execute and read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
710000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
153000
heap default
page read and write
clean
7EFB0000
unkown image
page readonly
clean
180000
unkown
page read and write
clean
480000
unkown image
page readonly
clean
2E0000
unkown
page read and write
clean
410000
heap default
page read and write
clean
800000
unkown image
page readonly
clean
39F000
stack
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
290000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
590000
unkown image
page readonly
clean
D0000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
684000
heap default
page read and write
clean
630000
unkown image
page readonly
clean
25BF000
heap private
page read and write
clean
90000
unkown
page read and write
clean
450000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
174E000
stack
page read and write
clean
27E000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
24DE000
stack
page read and write
clean
8C7000
heap default
page read and write
clean
7EFC0000
unkown image
page readonly
clean
1D0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
6CB1F000
unkown image
page readonly
clean
3C4000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
231D000
unkown
page read and write
clean
59F000
heap default
page read and write
clean
567000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
6F0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
107000
heap default
page read and write
clean
887000
heap default
page read and write
clean
1DC000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
6CC06000
unkown image
page read and write
clean
870000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
143E000
stack
page read and write
clean
420000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
2AB000
unkown
page read and write
clean
2D3F000
stack
page read and write
clean
380000
heap private
page read and write
clean
830000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
13E000
heap default
page read and write
clean
226000
heap private
page read and write
clean
6CB42000
unkown image
page readonly
clean
C60000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
150000
unkown
page read and write
clean
90000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
6CB00000
unkown image
page readonly
clean
3CC000
unkown
page read and write
clean
8AD000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
2180000
unkown image
page readonly
clean
560000
heap private
page read and write
clean
770000
heap private
page read and write
clean
38E000
heap default
page read and write
clean
3C3000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
100000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
699000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
3D2000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
F0000
unkown image
page readonly
clean
2B7000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
5B0000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
1F10000
unkown image
page readonly
clean
6D512000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
6CB18000
unkown image
page readonly
clean
580000
unkown image
page readonly
clean
357000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
6CB01000
unkown image
page execute read
clean
7EFC2000
unkown image
page readonly
clean
AC000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
1E0000
unkown
page read and write
clean
1ACE000
stack
page read and write
clean
88D000
unkown
page read and write
clean
8A4000
heap default
page read and write
clean
2190000
heap private
page read and write
clean
400000
heap private
page read and write
clean
6A0000
unkown image
page readonly
clean
C0000
unkown image
page readonly
clean
280000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
220000
heap private
page read and write
clean
40000
unkown image
page readonly
clean
A20000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
E0000
unkown image
page read and write
clean
7EFE0000
unkown image
page readonly
clean
BB0000
heap private
page read and write
clean
6A0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
C1F000
stack
page read and write
clean
20000
heap private
page read and write
clean
14B000
unkown
page read and write
clean
44E000
heap default
page read and write
clean
21F000
stack
page read and write
clean
8DA000
unkown
page read and write
clean
8D8000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
15F0000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
180000
unkown
page read and write
clean
1FB0000
unkown image
page readonly
clean
BCC000
stack
page read and write
clean
7EFDF000
unkown
page read and write
clean
2105000
heap private
page read and write
clean
2320000
unkown image
page readonly
clean
D63000
heap private
page read and write
clean
5A6000
unkown
page read and write
clean
7B0000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
150F000
stack
page read and write
clean
25C0000
heap private
page read and write
clean
6D512000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
F1F000
stack
page read and write
clean
260000
unkown image
page read and write
clean
7EFB0000
unkown image
page readonly
clean
350000
heap default
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2760000
unkown
page read and write
clean
8D4000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
514000
heap private
page read and write
clean
213B000
heap private
page read and write
clean
60000
unkown image
page readonly
clean
2A0000
unkown image
page readonly
clean
330000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
25D000
unkown
page read and write
clean
B90000
heap private
page read and write
clean
20000
unkown image
page readonly
clean
342000
heap private
page read and write
clean
340000
unkown
page read and write
clean
2650000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2195000
heap private
page read and write
clean
250000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7C0000
unkown image
page readonly
clean
1A8F000
stack
page read and write
clean
20000
unkown image
page readonly
clean
13FF000
stack
page read and write
clean
3A4000
heap default
page read and write
clean
2620000
unkown image
page readonly
clean
E0000
unkown image
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7D0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
272000
heap private
page read and write
clean
22B000
unkown
page read and write
clean
624000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
2050000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
F0000
unkown
page read and write
clean
C00000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
F0000
unkown
page read and write
clean
670000
unkown image
page readonly
clean
250000
heap private
page read and write
clean
1FD000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
376000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
100000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
30000
unkown image
page read and write
clean
2300000
unkown
page read and write
clean
There are 578 hidden memdumps, click here to show them.