IOC Report

loading gif

Files

File Path
Type
Category
Malicious
PRMS_558161433.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Last Saved By: Gretta, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Jun 5 19:17:20 2015, Last Saved Time/Date: Tue Oct 12 08:41:12 2021, Security: 0
initial sample
malicious
C:\Users\user\AppData\Local\Temp\VBE\MSForms.exd
data
dropped
clean
C:\Users\user\AppData\Local\Temp\VBE\RefEdit.exd
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\SysWOW64\regsvr32.exe
regsvr32 -silent ..\Celod.wac
malicious
C:\Windows\SysWOW64\regsvr32.exe
regsvr32 -silent ..\Celod.wac1
malicious
C:\Windows\SysWOW64\regsvr32.exe
regsvr32 -silent ..\Celod.wac2
malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Celod.wac
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Celod.wac1
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -silent ..\Celod.wac2
malicious

URLs

Name
IP
Malicious
http://185.123.53.220/44483.3585885417.dat
185.123.53.220
clean
http://185.244.150.172/44483.3585885417.dat
185.244.150.172
clean
http://101.99.90.219/44483.3585885417.dat
101.99.90.219
clean
http://185.123.53.220/44483.3537556712.dat
185.123.53.220
clean
http://185.244.150.172/44483.3537556712.dat
185.244.150.172
clean
http://101.99.90.219/44483.3537556712.dat
101.99.90.219
clean
http://servername/isapibackend.dll
unknown
clean

IPs

IP
Domain
Country
Malicious
185.244.150.172
unknown
Netherlands
clean
185.123.53.220
unknown
unknown
clean
101.99.90.219
unknown
Malaysia
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems
yz0
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems
zz0
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\IOAV
LastBootTime
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109110000000000000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ExdCache\Excel8.0
MSForms
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ExdCache\Excel8.0
MSComctlLib
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\DocumentRecovery\4B65D
4B65D
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{41C10AE5-3E2F-4C66-B6CE-9C37A885FF56}\2.0
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{41C10AE5-3E2F-4C66-B6CE-9C37A885FF56}\2.0\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{41C10AE5-3E2F-4C66-B6CE-9C37A885FF56}\2.0\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{41C10AE5-3E2F-4C66-B6CE-9C37A885FF56}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_Classes\TypeLib\{41C10AE5-3E2F-4C66-B6CE-9C37A885FF56}\2.0
NULL
clean
HKEY_CURRENT_USER_Classes\TypeLib\{41C10AE5-3E2F-4C66-B6CE-9C37A885FF56}\2.0\FLAGS
NULL
clean
HKEY_CURRENT_USER_Classes\TypeLib\{41C10AE5-3E2F-4C66-B6CE-9C37A885FF56}\2.0\0\win32
NULL
clean
HKEY_CURRENT_USER_Classes\TypeLib\{41C10AE5-3E2F-4C66-B6CE-9C37A885FF56}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C98A7E2F-9B55-4B3F-B555-FA4DB81DE045}\1.2
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C98A7E2F-9B55-4B3F-B555-FA4DB81DE045}\1.2\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C98A7E2F-9B55-4B3F-B555-FA4DB81DE045}\1.2\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C98A7E2F-9B55-4B3F-B555-FA4DB81DE045}\1.2\HELPDIR
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00024518-0000-0000-C000-000000000046}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems
&k0
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109E60090400000000000F01FEC\Usage
VBAFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\DocumentRecovery\5A205
5A205
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\DocumentRecovery\5A939
5A939
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109110000000000000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
en-US
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
en-US
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109110000000000000000F01FEC\Usage
EXCELFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming
RoamingConfigurableSettings
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming
RoamingLastSyncTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming
RoamingLastWriteTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\IOAV
LastBootTime
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_Classes\WOW6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_Classes\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
w,&
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2ED6B
2ED6B
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{E5074220-7568-41A0-BC0B-1B511ECE9DC2}\2.0
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{E5074220-7568-41A0-BC0B-1B511ECE9DC2}\2.0\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{E5074220-7568-41A0-BC0B-1B511ECE9DC2}\2.0\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{E5074220-7568-41A0-BC0B-1B511ECE9DC2}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{E5074220-7568-41A0-BC0B-1B511ECE9DC2}\2.0
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{E5074220-7568-41A0-BC0B-1B511ECE9DC2}\2.0\FLAGS
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{E5074220-7568-41A0-BC0B-1B511ECE9DC2}\2.0\0\win32
NULL
clean
HKEY_CURRENT_USER_CLASSES\TypeLib\{E5074220-7568-41A0-BC0B-1B511ECE9DC2}\2.0\HELPDIR
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C8ABFB10-3EE6-4D2A-AAE0-26E7110D6FE2}\1.2
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C8ABFB10-3EE6-4D2A-AAE0-26E7110D6FE2}\1.2\FLAGS
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C8ABFB10-3EE6-4D2A-AAE0-26E7110D6FE2}\1.2\0\win32
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C8ABFB10-3EE6-4D2A-AAE0-26E7110D6FE2}\1.2\HELPDIR
NULL
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00024518-0000-0000-C000-000000000046}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
{:&
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\363A3
363A3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\37436
37436
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER_CLASSES\Wow6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
There are 357 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
7FF572745000
unkown image
page readonly
clean
2A70FC40000
unkown image
page readonly
clean
7FF5727B9000
unkown image
page readonly
clean
2A70FD60000
unkown
page read and write
clean
7F1F0000
unkown image
page readonly
clean
2A70FD60000
unkown
page read and write
clean
7FF523801000
unkown image
page readonly
clean
7EFF2000
unkown image
page readonly
clean
7F300000
unkown image
page readonly
clean
2F93000
unkown image
page readonly
clean
2B98000
unkown image
page readonly
clean
31D0000
unkown image
page readonly
clean
1000000
unkown image
page read and write
clean
1EAF4000000
unkown image
page readonly
clean
2A70FCFA000
unkown
page read and write
clean
2F93000
unkown image
page readonly
clean
7FF572831000
unkown image
page readonly
clean
7FF57273A000
unkown image
page readonly
clean
DBA1DFE000
stack
page read and write
clean
7DF5878C0000
unkown image
page readonly
clean
2F65000
unkown image
page readonly
clean
2A70FD0B000
unkown
page read and write
clean
2A70FE80000
unkown
page read and write
clean
7F020000
unkown image
page readonly
clean
2EE7000
unkown image
page readonly
clean
F10000
heap default
page read and write
clean
2EEF000
unkown image
page readonly
clean
C6C000
unkown
page read and write
clean
2A70FCF4000
unkown
page read and write
clean
2A70FD68000
unkown
page read and write
clean
7FF572581000
unkown image
page readonly
clean
2A7106D2000
unkown
page read and write
clean
C68000
unkown
page read and write
clean
7F032000
unkown image
page readonly
clean
2A70FC70000
unkown image
page readonly
clean
BF0000
unkown image
page readonly
clean
7FF523764000
unkown image
page readonly
clean
7DF5878B2000
unkown image
page readonly
clean
7FF5237F4000
unkown image
page readonly
clean
2DB000
unkown
page read and write
clean
2EBC000
unkown image
page readonly
clean
2F82000
unkown image
page readonly
clean
2A70FD84000
unkown
page read and write
clean
7FF5726F3000
unkown image
page readonly
clean
2EFA000
unkown image
page readonly
clean
2EEF000
unkown image
page readonly
clean
2A70FCE3000
unkown
page read and write
clean
2EE7000
unkown image
page readonly
clean
2B98000
unkown image
page readonly
clean
360000
unkown image
page readonly
clean
2F88000
unkown image
page readonly
clean
2A70FFF0000
heap private
page read and write
clean
2A70FCD1000
unkown
page read and write
clean
EC0000
heap private
page read and write
clean
7F010000
unkown image
page readonly
clean
1EAF40E6000
heap default
page read and write
clean
2A70FD66000
unkown
page read and write
clean
1150000
heap private
page read and write
clean
2A70FCF7000
unkown
page read and write
clean
2E93000
unkown image
page readonly
clean
2ED0000
unkown image
page readonly
clean
2F61000
unkown image
page readonly
clean
2F61000
unkown image
page readonly
clean
36E0000
unkown image
page readonly
clean
7F2F2000
unkown image
page readonly
clean
DBA1C7B000
stack
page read and write
clean
7DF5878D0000
unkown image
page readonly
clean
7FF523715000
unkown image
page readonly
clean
7FF57208E000
unkown image
page readonly
clean
7F310000
unkown image
page readonly
clean
2B98000
unkown image
page readonly
clean
7FF5237FA000
unkown image
page readonly
clean
7FF52375A000
unkown image
page readonly
clean
2DC0000
unkown image
page readonly
clean
7DF538882000
unkown image
page readonly
clean
7EEF0000
unkown image
page readonly
clean
7FF572540000
unkown image
page readonly
clean
2A70FFC0000
unkown
page read and write
clean
7FF52378D000
unkown image
page readonly
clean
7FF57276C000
unkown image
page readonly
clean
2EFF000
unkown image
page readonly
clean
2F82000
unkown image
page readonly
clean
2A710380000
unkown image
page readonly
clean
7EFF2000
unkown image
page readonly
clean
7F040000
unkown image
page readonly
clean
7FF572777000
unkown image
page readonly
clean
2A70FFF5000
heap private
page read and write
clean
853937E000
stack
page read and write
clean
36B0000
unkown image
page readonly
clean
2E89000
unkown image
page readonly
clean
7FF52377E000
unkown image
page readonly
clean
2A70FD66000
unkown
page read and write
clean
7DF5388A0000
unkown image
page readonly
clean
2DAB000
unkown image
page readonly
clean
7F040000
unkown image
page readonly
clean
7FF572046000
unkown image
page readonly
clean
2A70FCD5000
unkown
page read and write
clean
2EC3000
unkown image
page readonly
clean
2A70FD66000
unkown
page read and write
clean
E50000
unkown
page read and write
clean
2F16000
unkown image
page readonly
clean
2A70FD87000
unkown
page read and write
clean
E00000
unkown image
page readonly
clean
2F93000
unkown image
page readonly
clean
7FF572703000
unkown image
page readonly
clean
2A70FC98000
heap default
page read and write
clean
2F01000
unkown image
page readonly
clean
DBA1CFB000
stack
page read and write
clean
55A000
unkown
page read and write
clean
2EF3000
unkown image
page readonly
clean
7FF57271F000
unkown image
page readonly
clean
2A70FFC0000
unkown
page read and write
clean
7DF5878B2000
unkown image
page readonly
clean
2A70FFC0000
unkown
page read and write
clean
2A70FCBC000
unkown
page read and write
clean
7DF5878C2000
unkown image
page readonly
clean
7EF20000
unkown image
page readonly
clean
2EB5000
unkown image
page readonly
clean
D70000
unkown image
page readonly
clean
7DF538880000
unkown image
page readonly
clean
2A7106D1000
unkown
page read and write
clean
DBA1E7F000
stack
page read and write
clean
BF0000
unkown image
page readonly
clean
2EFA000
unkown image
page readonly
clean
853907C000
unkown
page read and write
clean
7FF57273E000
unkown image
page readonly
clean
2ECC000
unkown image
page readonly
clean
7FF572794000
unkown image
page readonly
clean
1EAF3FC0000
unkown image
page readonly
clean
7DF436750000
unkown image
page readonly
clean
7DF5878D0000
unkown image
page readonly
clean
7F010000
unkown image
page readonly
clean
E70000
unkown image
page readonly
clean
7FF572832000
unkown image
page readonly
clean
2F65000
unkown image
page readonly
clean
343A000
heap default
page read and write
clean
7F032000
unkown image
page readonly
clean
7FF572740000
unkown image
page readonly
clean
2A70FD86000
unkown
page read and write
clean
2A70FC30000
unkown image
page readonly
clean
7FF572591000
unkown image
page readonly
clean
DBA1D7D000
stack
page read and write
clean
7DF5878C2000
unkown image
page readonly
clean
1EAF4020000
unkown
page read and write
clean
7D0000
heap default
page read and write
clean
7FF572714000
unkown image
page readonly
clean
7F030000
unkown image
page readonly
clean
BEB000
unkown
page read and write
clean
2F1B000
unkown image
page readonly
clean
36D0000
heap private
page read and write
clean
7FF52373C000
unkown image
page readonly
clean
7FF563676000
unkown image
page readonly
clean
2EB5000
unkown image
page readonly
clean
2ECC000
unkown image
page readonly
clean
2A70FD2E000
unkown
page read and write
clean
BAC000
unkown
page read and write
clean
2F12000
unkown image
page readonly
clean
3550000
unkown image
page readonly
clean
DBA1B7E000
stack
page read and write
clean
2E8D000
unkown image
page readonly
clean
7FF57274B000
unkown image
page readonly
clean
2F16000
unkown image
page readonly
clean
2EE5000
unkown image
page readonly
clean
7DF538890000
unkown image
page readonly
clean
2EE5000
unkown image
page readonly
clean
2A70FD68000
unkown
page read and write
clean
7FF57282A000
unkown image
page readonly
clean
2A70FD86000
unkown
page read and write
clean
2A70FD68000
unkown
page read and write
clean
2A70FD60000
unkown
page read and write
clean
7FF572784000
unkown image
page readonly
clean
B40000
unkown image
page read and write
clean
1EAF3FD0000
unkown image
page readonly
clean
2ED9000
unkown image
page readonly
clean
7FF57209D000
unkown image
page readonly
clean
2F61000
unkown image
page readonly
clean
2EED000
unkown image
page readonly
clean
2A70FD0B000
unkown
page read and write
clean
7F002000
unkown image
page readonly
clean
7FF5725D0000
unkown image
page readonly
clean
2A70FC20000
unkown image
page read and write
clean
10AB000
unkown
page read and write
clean
2ED9000
unkown image
page readonly
clean
29C000
unkown
page read and write
clean
85390FF000
stack
page read and write
clean
1110000
unkown
page read and write
clean
2EF3000
unkown image
page readonly
clean
340000
unkown
page read and write
clean
2A70FD66000
unkown
page read and write
clean
2F82000
unkown image
page readonly
clean
2E9C000
unkown image
page readonly
clean
EB0000
heap private
page read and write
clean
2DC0000
unkown image
page readonly
clean
2A70FCD1000
unkown
page read and write
clean
2A710200000
unkown image
page readonly
clean
2F01000
unkown image
page readonly
clean
7DF485780000
unkown image
page readonly
clean
7FF572042000
unkown image
page readonly
clean
E35000
unkown
page read and write
clean
2E8D000
unkown image
page readonly
clean
7FF57272A000
unkown image
page readonly
clean
2ED0000
unkown image
page readonly
clean
2F01000
unkown image
page readonly
clean
7FF5726C1000
unkown image
page readonly
clean
2A70FCF4000
unkown
page read and write
clean
2A70FD2E000
unkown
page read and write
clean
7FF563676000
unkown image
page readonly
clean
240000
unkown image
page readonly
clean
7FF523778000
unkown image
page readonly
clean
2EE7000
unkown image
page readonly
clean
33D0000
unkown image
page readonly
clean
240000
unkown image
page readonly
clean
2A70FD1F000
unkown
page read and write
clean
DBA1AFE000
stack
page read and write
clean
62A000
heap default
page read and write
clean
2A70FD60000
unkown
page read and write
clean
7FF523754000
unkown image
page readonly
clean
2E0000
unkown image
page readonly
clean
7FF523789000
unkown image
page readonly
clean
7FF572574000
unkown image
page readonly
clean
2A70FD1F000
unkown
page read and write
clean
7FF5723D1000
unkown image
page readonly
clean
2F16000
unkown image
page readonly
clean
7F002000
unkown image
page readonly
clean
7DF538892000
unkown image
page readonly
clean
2EFF000
unkown image
page readonly
clean
2EED000
unkown image
page readonly
clean
7F022000
unkown image
page readonly
clean
2A70FCE5000
unkown
page read and write
clean
2F88000
unkown image
page readonly
clean
2A70FD68000
unkown
page read and write
clean
7FF57278A000
unkown image
page readonly
clean
2E9C000
unkown image
page readonly
clean
2EC3000
unkown image
page readonly
clean
2F74000
unkown image
page readonly
clean
2ED9000
unkown image
page readonly
clean
2A70FCC2000
unkown
page read and write
clean
7DF5878B0000
unkown image
page readonly
clean
2F65000
unkown image
page readonly
clean
2F74000
unkown image
page readonly
clean
2EE5000
unkown image
page readonly
clean
2F1B000
unkown image
page readonly
clean
853917E000
stack
page read and write
clean
2EFA000
unkown image
page readonly
clean
1EAF4445000
heap private
page read and write
clean
2F93000
unkown image
page readonly
clean
2F93000
unkown image
page readonly
clean
230000
unkown image
page read and write
clean
7FF571FA3000
unkown image
page readonly
clean
7F2F2000
unkown image
page readonly
clean
7FF52371B000
unkown image
page readonly
clean
7FF52376E000
unkown image
page readonly
clean
2A70FD66000
unkown
page read and write
clean
853927F000
stack
page read and write
clean
7FF5727AE000
unkown image
page readonly
clean
7DF538882000
unkown image
page readonly
clean
106C000
unkown
page read and write
clean
2E93000
unkown image
page readonly
clean
1EAF3FD0000
unkown image
page readonly
clean
7F2F0000
unkown image
page readonly
clean
3360000
heap default
page read and write
clean
2A70FD68000
unkown
page read and write
clean
7F020000
unkown image
page readonly
clean
2A70FCE5000
unkown
page read and write
clean
2A70FCD5000
unkown
page read and write
clean
7FF572757000
unkown image
page readonly
clean
7F302000
unkown image
page readonly
clean
2F74000
unkown image
page readonly
clean
DBA1A7A000
unkown
page read and write
clean
7DF538890000
unkown image
page readonly
clean
2EFF000
unkown image
page readonly
clean
7FF57270F000
unkown image
page readonly
clean
7FF5725EF000
unkown image
page readonly
clean
2DAB000
unkown image
page readonly
clean
2E8D000
unkown image
page readonly
clean
7FF5727B6000
unkown image
page readonly
clean
10B0000
unkown image
page readonly
clean
2E9C000
unkown image
page readonly
clean
1010000
unkown image
page readonly
clean
7FF523710000
unkown image
page readonly
clean
9F0000
unkown image
page readonly
clean
2F93000
unkown image
page readonly
clean
2E89000
unkown image
page readonly
clean
2ED0000
unkown image
page readonly
clean
7FF5727A8000
unkown image
page readonly
clean
7DF538880000
unkown image
page readonly
clean
7FF5723FA000
unkown image
page readonly
clean
101A000
heap default
page read and write
clean
2A70FC90000
heap default
page read and write
clean
9E0000
heap private
page read and write
clean
7F000000
unkown image
page readonly
clean
2EB5000
unkown image
page readonly
clean
7FF572576000
unkown image
page readonly
clean
2EBC000
unkown image
page readonly
clean
7F022000
unkown image
page readonly
clean
2EED000
unkown image
page readonly
clean
7F2F0000
unkown image
page readonly
clean
1EAF40C0000
heap default
page read and write
clean
7FF523712000
unkown image
page readonly
clean
2F88000
unkown image
page readonly
clean
2A70FD60000
unkown
page read and write
clean
7F300000
unkown image
page readonly
clean
2DAB000
unkown image
page readonly
clean
2A710000000
unkown image
page readonly
clean
1EAF4290000
unkown image
page readonly
clean
7DF538892000
unkown image
page readonly
clean
2A70FD1F000
unkown
page read and write
clean
2DC0000
unkown image
page readonly
clean
2A70FD2F000
unkown
page read and write
clean
7DF5878B0000
unkown image
page readonly
clean
1EAF3FF0000
unkown image
page readonly
clean
3340000
heap private
page read and write
clean
1EAF4440000
heap private
page read and write
clean
10C0000
unkown image
page readonly
clean
7EFF0000
unkown image
page readonly
clean
2A7106D1000
unkown
page read and write
clean
2A70FCFC000
unkown
page read and write
clean
2F12000
unkown image
page readonly
clean
1130000
unkown image
page readonly
clean
3530000
unkown image
page readonly
clean
2E89000
unkown image
page readonly
clean
2F1B000
unkown image
page readonly
clean
1EAF40ED000
heap default
page read and write
clean
85392FF000
stack
page read and write
clean
2A70FFD0000
unkown image
page read and write
clean
2EF3000
unkown image
page readonly
clean
7FF57276F000
unkown image
page readonly
clean
E39000
unkown
page read and write
clean
620000
heap default
page read and write
clean
1EAF40CB000
heap default
page read and write
clean
1EAF4410000
unkown image
page readonly
clean
2EBC000
unkown image
page readonly
clean
7F030000
unkown image
page readonly
clean
7FF572824000
unkown image
page readonly
clean
1EAF4450000
unkown image
page readonly
clean
7FF5727C2000
unkown image
page readonly
clean
2A70FCE3000
unkown
page read and write
clean
2A70FC60000
unkown image
page readonly
clean
7FF57272C000
unkown image
page readonly
clean
2A70FE60000
unkown
page read and write
clean
2F0000
unkown image
page readonly
clean
7FF5727D3000
unkown image
page readonly
clean
B50000
unkown image
page readonly
clean
2A70FC40000
unkown image
page readonly
clean
7DF5878C0000
unkown image
page readonly
clean
7F310000
unkown image
page readonly
clean
2E93000
unkown image
page readonly
clean
7FF57279F000
unkown image
page readonly
clean
1EAF3FB0000
unkown image
page read and write
clean
7EFF0000
unkown image
page readonly
clean
7FF523802000
unkown image
page readonly
clean
2A7106D0000
unkown
page read and write
clean
DBA1BFE000
stack
page read and write
clean
2A70FD0B000
unkown
page read and write
clean
7FF5722A2000
unkown image
page readonly
clean
B50000
unkown image
page readonly
clean
7DF5388A0000
unkown image
page readonly
clean
7F000000
unkown image
page readonly
clean
7FF5726C4000
unkown image
page readonly
clean
7FF523748000
unkown image
page readonly
clean
1010000
unkown image
page readonly
clean
2F12000
unkown image
page readonly
clean
2EC3000
unkown image
page readonly
clean
7F302000
unkown image
page readonly
clean
2ECC000
unkown image
page readonly
clean
3430000
heap default
page read and write
clean
1010000
heap default
page read and write
clean
7FF57270B000
unkown image
page readonly
clean
2EEF000
unkown image
page readonly
clean
1EAF4040000
unkown
page read and write
clean
There are 360 hidden memdumps, click here to show them.