IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Document_748968552-10062021.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Author: Test, Last Saved By: Test, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Jun 5 19:17:20 2015, Last Saved Time/Date: Wed Oct 6 08:51:31 2021, Security: 0
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\44475.7050777778[1].dat
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\44475.7050777778[2].dat
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\44475.7050777778[3].dat
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Celod.wac
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Celod.wac1
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Celod.wac2
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\VBE\MSForms.exd
data
dropped
clean
C:\Users\user\AppData\Local\Temp\VBE\RefEdit.exd
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Celod.wac
malicious
C:\Windows\SysWOW64\regsvr32.exe
-silent ..\Celod.wac
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Celod.wac1
malicious
C:\Windows\SysWOW64\regsvr32.exe
-silent ..\Celod.wac1
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\SysWOW64\schtasks.exe
'C:\Windows\system32\schtasks.exe' /Create /RU 'NT AUTHORITY\SYSTEM' /tn kzlufjnad /tr 'regsvr32.exe -s \'C:\Users\user\Celod.wac\'' /SC ONCE /Z /ST 16:57 /ET 17:09
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\Celod.wac'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\Celod.wac'
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Celod.wac2
malicious
C:\Windows\SysWOW64\regsvr32.exe
-silent ..\Celod.wac2
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
C:\Windows\System32\reg.exe
C:\Windows\system32\reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths' /f /t REG_DWORD /v 'C:\ProgramData\Microsoft\Fmjlcuic' /d '0'
malicious
C:\Windows\System32\reg.exe
C:\Windows\system32\reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths' /f /t REG_DWORD /v 'C:\Users\user\AppData\Roaming\Microsoft\Adbwawqor' /d '0'
malicious
C:\Windows\System32\regsvr32.exe
regsvr32.exe -s 'C:\Users\user\Celod.wac'
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s 'C:\Users\user\Celod.wac'
malicious
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
malicious
There are 8 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://188.165.62.50/44475.7050777778.dat
188.165.62.50
clean
http://190.14.37.107/44475.7050777778.dat
190.14.37.107
clean
http://www.%s.comPA
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://94.140.114.111/44475.7050777778.dat
94.140.114.111
clean
http://servername/isapibackend.dll
unknown
clean

IPs

IP
Domain
Country
Malicious
94.140.114.111
unknown
Latvia
clean
190.14.37.107
unknown
Panama
clean
188.165.62.50
unknown
France
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
ar*
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2D9DB
2D9DB
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B1FBDDBF-6DF4-4984-82DD-F1F5F37504FD}\2.0
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B1FBDDBF-6DF4-4984-82DD-F1F5F37504FD}\2.0\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B1FBDDBF-6DF4-4984-82DD-F1F5F37504FD}\2.0\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B1FBDDBF-6DF4-4984-82DD-F1F5F37504FD}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{B1FBDDBF-6DF4-4984-82DD-F1F5F37504FD}\2.0
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{B1FBDDBF-6DF4-4984-82DD-F1F5F37504FD}\2.0\FLAGS
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{B1FBDDBF-6DF4-4984-82DD-F1F5F37504FD}\2.0\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B1FBDDBF-6DF4-4984-82DD-F1F5F37504FD}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{058417E8-46D6-4917-B9B2-7724337897AC}\1.2
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{058417E8-46D6-4917-B9B2-7724337897AC}\1.2\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{058417E8-46D6-4917-B9B2-7724337897AC}\1.2\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{058417E8-46D6-4917-B9B2-7724337897AC}\1.2\HELPDIR
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00024518-0000-0000-C000-000000000046}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
:}*
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\4BFB6
4BFB6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\4C1E8
4C1E8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_CURRENT_USER\Software\Microsoft\Yannsjuihwcxo
acf91558
clean
HKEY_CURRENT_USER\Software\Microsoft\Yannsjuihwcxo
9966c516
clean
HKEY_CURRENT_USER\Software\Microsoft\Yannsjuihwcxo
9b27e56a
clean
HKEY_CURRENT_USER\Software\Microsoft\Yannsjuihwcxo
239b820f
clean
HKEY_CURRENT_USER\Software\Microsoft\Yannsjuihwcxo
5e93cd85
clean
HKEY_CURRENT_USER\Software\Microsoft\Yannsjuihwcxo
e62faae0
clean
HKEY_CURRENT_USER\Software\Microsoft\Yannsjuihwcxo
21daa273
clean
HKEY_CURRENT_USER\Software\Microsoft\Yannsjuihwcxo
d3b07aae
clean
HKEY_CURRENT_USER\Software\Microsoft\Yannsjuihwcxo
acf91558
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Rmytnevajantu
764839bd
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Rmytnevajantu
43d7e9f3
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Rmytnevajantu
4196c98f
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Rmytnevajantu
f92aaeea
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Rmytnevajantu
8422e160
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Rmytnevajantu
3c9e8605
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Rmytnevajantu
fb6b8e96
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Rmytnevajantu
901564b
clean
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Rmytnevajantu
764839bd
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
C:\ProgramData\Microsoft\Fmjlcuic
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
C:\Users\user\AppData\Roaming\Microsoft\Adbwawqor
clean
There are 212 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
1E0000
unkown
page execute and read and write
malicious
1A0000
unkown
page execute and read and write
malicious
100000
unkown image
page execute and read and write
malicious
80000
unkown image
page execute and read and write
malicious
80000
unkown image
page execute and read and write
malicious
770000
unkown
page execute and read and write
malicious
1C0000
unkown
page execute and read and write
malicious
D0000
unkown image
page execute and read and write
malicious
326000
heap private
page read and write
clean
2BA000
heap default
page read and write
clean
7EFD0000
unkown image
page readonly
clean
354000
unkown
page read and write
clean
7E0000
unkown image
page readonly
clean
139E000
unkown
page read and write
clean
550000
unkown image
page readonly
clean
584000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2070000
unkown image
page readonly
clean
90000
unkown
page read and write
clean
272E000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
29FF000
heap private
page read and write
clean
25F000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
6DE7F000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
20000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
3F0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
20000
unkown image
page read and write
clean
10000
unkown image
page read and write
clean
570000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
C0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
550000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
20000
unkown image
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
410000
heap private
page read and write
clean
20000
unkown image
page readonly
clean
6DCCD000
unkown image
page read and write
clean
7EFB0000
unkown image
page readonly
clean
4A0000
unkown image
page readonly
clean
55F000
unkown
page read and write
clean
140000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
5AD000
unkown
page read and write
clean
30000
unkown image
page read and write
clean
8C0000
unkown image
page readonly
clean
130000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
2E0000
heap default
page read and write
clean
3FD000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
9B0000
unkown image
page readonly
clean
C70000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
2730000
unkown
page read and write
clean
596000
unkown
page read and write
clean
100000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
E0000
unkown image
page read and write
clean
63D000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
254C000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
190000
heap default
page read and write
clean
3D4000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
E4000
heap private
page read and write
clean
28D000
unkown
page read and write
clean
21C000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
50D000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
7F0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
6DB73000
unkown image
page readonly
clean
64E000
unkown
page read and write
clean
23B2000
heap private
page read and write
clean
710000
unkown image
page readonly
clean
362000
heap private
page read and write
clean
40000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
6DCCF000
unkown image
page readonly
clean
6E010000
unkown image
page readonly
clean
6E1BB000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
960000
unkown image
page readonly
clean
6DDB9000
unkown image
page read and write
clean
7EFDF000
unkown
page read and write
clean
550000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
F0000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
6DCC8000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
760000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
5F7000
heap default
page read and write
clean
212F000
unkown
page read and write
clean
8B0000
heap private
page read and write
clean
6DB00000
unkown image
page readonly
clean
21D0000
heap private
page read and write
clean
13FF000
heap private
page read and write
clean
1B4000
heap private
page read and write
clean
506000
unkown
page read and write
clean
2070000
unkown image
page readonly
clean
3F0000
heap private
page read and write
clean
50000
unkown image
page readonly
clean
23E000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
1BA000
heap default
page read and write
clean
5D0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
6E02D000
unkown image
page read and write
clean
377000
heap default
page read and write
clean
554000
heap private
page read and write
clean
1C0000
unkown
page read and write
clean
12A000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
23D0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
271E000
unkown
page read and write
clean
289000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
494000
heap private
page read and write
clean
1A8E000
unkown
page read and write
clean
360000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
21B000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
210000
heap private
page read and write
clean
60000
unkown image
page readonly
clean
414000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
430000
heap default
page read and write
clean
780000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
3D0000
heap private
page read and write
clean
880000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
362000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
684000
heap private
page read and write
clean
292F000
unkown
page read and write
clean
6E083000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
281F000
unkown
page read and write
clean
CD000
unkown
page read and write
clean
5B6000
unkown
page read and write
clean
450000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
98E000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
277F000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
680000
unkown image
page readonly
clean
6E11B000
unkown image
page execute and read and write
clean
7EFDF000
unkown
page read and write
clean
6DE5B000
unkown image
page readonly
clean
566000
unkown
page read and write
clean
51C000
unkown
page read and write
clean
6E031000
unkown image
page execute read
clean
6DE60000
unkown image
page readonly
clean
207000
heap default
page read and write
clean
250000
heap default
page read and write
clean
130000
unkown image
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
18BF000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
280000
unkown
page read and write
clean
344000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
3B6000
heap default
page read and write
clean
284000
heap default
page read and write
clean
50000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
18C000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
2D50000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7E0000
unkown image
page readonly
clean
6F0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
270000
unkown
page read and write
clean
269F000
unkown
page read and write
clean
28F000
heap default
page read and write
clean
4D0000
unkown
page read and write
clean
28BF000
heap private
page read and write
clean
5AF000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
6BD000
unkown
page read and write
clean
1380000
heap private
page read and write
clean
1A4000
heap private
page read and write
clean
369000
heap default
page read and write
clean
60000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
330000
heap default
page read and write
clean
5E0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
550000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
2570000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
5A8000
unkown
page read and write
clean
AFF000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
2D7000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
1A0000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
620000
unkown
page read and write
clean
336000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
11B000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
31C000
unkown
page read and write
clean
6DE7D000
unkown image
page read and write
clean
D60000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
7EFC2000
unkown image
page readonly
clean
31E000
heap default
page read and write
clean
20CE000
unkown
page read and write
clean
1CC000
unkown
page read and write
clean
29C000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
1E5000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
554000
heap private
page read and write
clean
5B2000
unkown
page read and write
clean
27BE000
unkown
page read and write
clean
2770000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
437000
heap default
page read and write
clean
416000
unkown
page read and write
clean
2845000
heap private
page read and write
clean
29DF000
heap private
page read and write
clean
17B000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
7D0000
unkown image
page readonly
clean
530000
unkown
page read and write
clean
620000
unkown image
page readonly
clean
2983000
heap private
page read and write
clean
2C0000
unkown image
page readonly
clean
527000
heap default
page read and write
clean
30000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7CE000
unkown
page read and write
clean
4E0000
heap default
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
27D0000
heap private
page read and write
clean
6DED3000
unkown image
page readonly
clean
256E000
unkown
page read and write
clean
20E000
heap default
page read and write
clean
BDD000
unkown
page read and write
clean
2DF000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
3F0000
heap default
page read and write
clean
D20000
heap private
page read and write
clean
7EFDF000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
CEF000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
25EF000
heap private
page read and write
clean
614000
heap default
page read and write
clean
22A000
heap default
page read and write
clean
880000
unkown
page read and write
clean
7ED000
unkown
page read and write
clean
28E0000
unkown
page read and write
clean
5F6000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
1D0000
heap default
page read and write
clean
2E0000
heap private
page read and write
clean
6DB1D000
unkown image
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
92F000
unkown
page read and write
clean
1B0000
heap private
page read and write
clean
97E000
unkown
page read and write
clean
6E0000
unkown image
page readonly
clean
257000
heap default
page read and write
clean
21D5000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
620000
unkown image
page readonly
clean
21F0000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
3A0000
heap default
page read and write
clean
7C0000
unkown image
page readonly
clean
420000
unkown
page read and write
clean
2070000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
18D000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
20D000
unkown
page read and write
clean
240000
unkown image
page read and write
clean
2F0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
396000
unkown
page read and write
clean
251F000
unkown
page read and write
clean
4E7000
heap default
page read and write
clean
4C0000
heap private
page read and write
clean
2965000
heap private
page read and write
clean
2D0000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
1F0000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
6E00B000
unkown image
page readonly
clean
20C000
unkown
page read and write
clean
E0000
unkown image
page read and write
clean
6DCAB000
unkown image
page readonly
clean
2C7E000
unkown
page read and write
clean
170000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
364000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
29F000
unkown
page read and write
clean
249E000
unkown
page read and write
clean
580000
unkown image
page readonly
clean
5A2000
unkown
page read and write
clean
6E011000
unkown image
page execute read
clean
7EFC2000
unkown image
page readonly
clean
4F0000
unkown
page read and write
clean
25EF000
heap private
page read and write
clean
272F000
unkown
page read and write
clean
90000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7EFE0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
BC0000
unkown
page read and write
clean
6DE78000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
2E0000
heap private
page read and write
clean
100000
heap default
page read and write
clean
E0000
unkown image
page read and write
clean
190000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
170000
unkown
page read and write
clean
AB000
unkown
page read and write
clean
544000
heap default
page read and write
clean
6DF6B000
unkown image
page execute and read and write
clean
6DCD1000
unkown image
page execute read
clean
7E0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
2230000
unkown image
page readonly
clean
6DB00000
unkown image
page readonly
clean
567000
heap default
page read and write
clean
3BB000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7E0000
unkown image
page readonly
clean
36F000
heap default
page read and write
clean
580000
unkown image
page readonly
clean
6DF69000
unkown image
page read and write
clean
576000
heap private
page read and write
clean
21BF000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
3F7000
heap default
page read and write
clean
3E0000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
5E0000
unkown image
page readonly
clean
610000
heap private
page read and write
clean
167000
heap default
page read and write
clean
786000
heap private
page read and write
clean
6E02F000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
2B3000
heap default
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
3E0000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
560000
unkown
page read and write
clean
520000
heap default
page read and write
clean
414000
heap default
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
660000
unkown image
page readonly
clean
80000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
C00000
heap private
page read and write
clean
60000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
4C4000
heap private
page read and write
clean
490000
heap private
page read and write
clean
2D0000
heap default
page read and write
clean
223000
heap default
page read and write
clean
1D70000
unkown image
page readonly
clean
2120000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7A0000
unkown image
page readonly
clean
1B6000
heap private
page read and write
clean
244000
heap private
page read and write
clean
320000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
280000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
D80000
heap private
page read and write
clean
20000
unkown image
page readonly
clean
6DB01000
unkown image
page execute read
clean
357000
heap default
page read and write
clean
1D80000
unkown image
page readonly
clean
22D0000
heap private
page read and write
clean
540000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
7E0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
337000
heap default
page read and write
clean
566000
heap private
page read and write
clean
5F0000
heap private
page read and write
clean
820000
unkown image
page readonly
clean
504000
heap default
page read and write
clean
6DE60000
unkown image
page readonly
clean
2570000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2630000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
6DCB1000
unkown image
page execute read
clean
180000
unkown
page read and write
clean
260000
heap default
page read and write
clean
160000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
D70000
heap private
page read and write
clean
2840000
heap private
page read and write
clean
483000
heap default
page read and write
clean
1C70000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
570000
unkown image
page readonly
clean
6DC09000
unkown image
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
1D0000
unkown
page execute and read and write
clean
7EFD0000
unkown image
page readonly
clean
326000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
368000
unkown
page read and write
clean
1E6000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
810000
unkown image
page readonly
clean
140000
heap private
page read and write
clean
18FF000
unkown
page read and write
clean
2B6000
unkown
page read and write
clean
D3F000
unkown
page read and write
clean
306000
unkown
page read and write
clean
1F00000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
51F000
heap default
page read and write
clean
7EFD0000
unkown image
page readonly
clean
1273000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
51A000
heap default
page read and write
clean
50000
unkown image
page readonly
clean
12CF000
heap private
page read and write
clean
3D0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
2125000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
291E000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
333000
heap default
page read and write
clean
1EC000
unkown
page read and write
clean
340000
heap private
page read and write
clean
2980000
heap private
page read and write
clean
6DE81000
unkown image
page execute read
clean
630000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
267000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
274000
heap default
page read and write
clean
3E0000
unkown
page read and write
clean
3AD000
heap default
page read and write
clean
560000
unkown image
page readonly
clean
C0000
unkown image
page read and write
clean
18D000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
6DB1F000
unkown image
page readonly
clean
43D000
unkown
page read and write
clean
6DC0B000
unkown image
page execute and read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
970000
unkown image
page readonly
clean
EC000
unkown
page read and write
clean
35C000
unkown
page read and write
clean
970000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
6DDBB000
unkown image
page execute and read and write
clean
49C000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
28E0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
33A000
heap default
page read and write
clean
70000
unkown image
page read and write
clean
440000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
360000
unkown
page read and write
clean
5F0000
heap default
page read and write
clean
7EFC0000
unkown image
page readonly
clean
A1F000
unkown
page read and write
clean
BA000
unkown
page read and write
clean
26DE000
unkown
page read and write
clean
2840000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
630000
unkown image
page readonly
clean
2BD000
unkown
page read and write
clean
26AE000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
240000
heap default
page read and write
clean
25A000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
29E000
heap default
page read and write
clean
184C000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
354000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
140E000
unkown
page read and write
clean
297E000
unkown
page read and write
clean
264F000
heap private
page read and write
clean
6E010000
unkown image
page readonly
clean
24FE000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
1BD000
unkown
page read and write
clean
240000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
19E000
heap default
page read and write
clean
30000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
700000
unkown image
page readonly
clean
416000
unkown
page read and write
clean
220B000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2F4000
heap default
page read and write
clean
680000
heap private
page read and write
clean
6DCB0000
unkown image
page readonly
clean
6DCB0000
unkown image
page readonly
clean
42A000
heap default
page read and write
clean
30000
unkown image
page readonly
clean
1F70000
unkown image
page readonly
clean
D0000
unkown image
page readonly
clean
29FF000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
2593000
heap private
page read and write
clean
C90000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7E0000
unkown image
page readonly
clean
48A000
heap default
page read and write
clean
30000
unkown image
page read and write
clean
2810000
unkown
page read and write
clean
365000
unkown
page read and write
clean
24BE000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
1BB000
unkown
page read and write
clean
55A000
heap default
page read and write
clean
30000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
200000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
160000
unkown
page read and write
clean
360000
heap default
page read and write
clean
1A0000
heap private
page read and write
clean
6DD23000
unkown image
page readonly
clean
15AE000
unkown
page read and write
clean
940000
unkown image
page readonly
clean
460000
unkown image
page readonly
clean
2A7E000
unkown
page read and write
clean
300000
unkown
page read and write
clean
2230000
heap private
page read and write
clean
690000
heap private
page read and write
clean
4F0000
heap private
page read and write
clean
446000
heap private
page read and write
clean
100000
unkown image
page read and write
clean
7EFDF000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
20000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
46E000
heap default
page read and write
clean
50000
unkown image
page readonly
clean
7D0000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
660000
unkown image
page readonly
clean
500000
unkown image
page readonly
clean
1AD000
unkown
page read and write
clean
2960000
heap private
page read and write
clean
690000
unkown image
page readonly
clean
440000
heap private
page read and write
clean
170000
unkown image
page read and write
clean
6DE61000
unkown image
page execute read
clean
20000
unkown image
page readonly
clean
BB000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
1D70000
unkown image
page readonly
clean
2575000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
150F000
unkown
page read and write
clean
1F7000
heap default
page read and write
clean
7B0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
370000
heap default
page read and write
clean
140000
unkown image
page read and write
clean
55F000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
260000
heap default
page read and write
clean
E0000
unkown
page execute and read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
30000
unkown image
page read and write
clean
6DB21000
unkown image
page execute read
clean
320000
heap private
page read and write
clean
260000
heap private
page read and write
clean
6E028000
unkown image
page readonly
clean
E0000
unkown image
page read and write
clean
42F000
heap default
page read and write
clean
6E119000
unkown image
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
1250000
heap private
page read and write
clean
6F0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
363000
unkown
page read and write
clean
144000
heap private
page read and write
clean
1F0000
unkown
page read and write
clean
6D0000
unkown image
page readonly
clean
2390000
heap private
page read and write
clean
1E0000
heap private
page read and write
clean
E0000
heap private
page read and write
clean
D0000
unkown image
page readonly
clean
55A000
unkown
page read and write
clean
2270000
unkown image
page readonly
clean
696000
heap private
page read and write
clean
60000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
5B8000
unkown
page read and write
clean
2863000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
5B0000
unkown image
page readonly
clean
30000
unkown image
page read and write
clean
3B0000
heap default
page read and write
clean
E20000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
190000
unkown
page read and write
clean
570000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
430000
unkown image
page readonly
clean
6A0000
unkown
page read and write
clean
5A5000
heap default
page read and write
clean
210000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
80000
unkown
page read and write
clean
3B0000
heap default
page read and write
clean
2620000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
110000
unkown
page read and write
clean
1400000
unkown
page read and write
clean
27D0000
unkown
page read and write
clean
1B0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
23C000
unkown
page read and write
clean
ED000
unkown
page read and write
clean
160000
unkown
page execute and read and write
clean
20000
unkown image
page readonly
clean
14EC000
unkown
page read and write
clean
2E7000
heap default
page read and write
clean
2252000
heap private
page read and write
clean
40000
unkown image
page readonly
clean
1E0000
unkown
page read and write
clean
269F000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
1B0000
heap private
page read and write
clean
60000
unkown image
page readonly
clean
25C000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
1CC000
unkown
page read and write
clean
22E000
heap default
page read and write
clean
6DB18000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
6F0000
unkown image
page readonly
clean
B0000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
560000
heap private
page read and write
clean
262000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
281F000
unkown
page read and write
clean
2234000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
DC0000
unkown image
page readonly
clean
F0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
1255000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
160000
unkown
page execute and read and write
clean
2070000
unkown image
page readonly
clean
1D7000
heap default
page read and write
clean
7EFC0000
unkown image
page readonly
clean
1250000
unkown
page read and write
clean
E60000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
1CD000
unkown
page read and write
clean
14CE000
unkown
page read and write
clean
D0000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
190000
unkown
page read and write
clean
B0000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
1D50000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
F0000
unkown
page read and write
clean
300000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
E0000
unkown image
page read and write
clean
364000
unkown
page read and write
clean
136000
unkown
page read and write
clean
2050000
unkown image
page readonly
clean
7F0000
unkown image
page readonly
clean
267000
heap default
page read and write
clean
544000
heap private
page read and write
clean
11AC000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
25D0000
heap private
page read and write
clean
6E0000
unkown image
page readonly
clean
1C6000
unkown
page read and write
clean
260000
unkown image
page read and write
clean
215B000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
90000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
2394000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
1B3000
heap default
page read and write
clean
560000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
26000
heap private
page read and write
clean
There are 806 hidden memdumps, click here to show them.