IOC Report

loading gif

Files

File Path
Type
Category
Malicious
o4c8AUtX1g.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\plcd-player.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Config.Msi\440bbf.rbs
data
modified
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, 61157 bytes, 1 file
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
dropped
clean
C:\Users\user\AppData\Local\Temp\MSI76CC.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Local\Temp\MSI79F9.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Local\Temp\shi7515.tmp
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools 3.4.0.2\install\0CE0CF4\AWSSDK.SimpleDB.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools 3.4.0.2\install\0CE0CF4\CrashRpt License.txt
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools 3.4.0.2\install\0CE0CF4\Delimon.Win32.IO.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools 3.4.0.2\install\0CE0CF4\ICSharpCode.SharpZipLib.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools 3.4.0.2\install\0CE0CF4\License.txt
Non-ISO extended-ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools 3.4.0.2\install\0CE0CF4\Microsoft.Azure.KeyVault.Core.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools 3.4.0.2\install\0CE0CF4\SslCertBinding.Net.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools 3.4.0.2\install\0CE0CF4\System.Threading.Tasks.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
modified
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools 3.4.0.2\install\0CE0CF4\Templates\currencysystem4.js
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools 3.4.0.2\install\0CE0CF4\Templates\currencysystem5.js
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools 3.4.0.2\install\0CE0CF4\Templates\currencysystem5.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools 3.4.0.2\install\0CE0CF4\Templates\ecb-eurofxref-daily.xml
XML 1.0 document, ASCII text
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools 3.4.0.2\install\0CE0CF4\adv.msi
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Last Printed: Fri Dec 11 11:47:44 2009, Create Time/Date: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Sep 18 15:06:51 2020, Security: 0, Code page: 1252, Revision Number: {D9FF1A35-78F9-49F0-A6A0-DB3A11387835}, Number of Words: 8, Subject: JDesktop Tools, Author: JDesktop Integration Components (JDIC) Project, Name of Creating Application: Advanced Installer 18.7 build 0a7fdead, Template: ;1033, Title: Installation Database, Keywords: Installer, MSI, Database, Number of Pages: 200
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools 3.4.0.2\install\0CE0CF4\help.chm
MS Windows HtmlHelp Data
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools 3.4.0.2\install\0CE0CF4\icuio58.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools 3.4.0.2\install\0CE0CF4\lcms-5.0.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools 3.4.0.2\install\0CE0CF4\libeay32.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools 3.4.0.2\install\0CE0CF4\ml
PDF document, version 1.5
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools 3.4.0.2\install\0CE0CF4\plcd-player.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools 3.4.0.2\install\0CE0CF4\ssleay32.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools 3.4.0.2\install\decoder.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\AWSSDK.SimpleDB.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\CrashRpt License.txt
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\Delimon.Win32.IO.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\ICSharpCode.SharpZipLib.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\License.txt
Non-ISO extended-ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\Microsoft.Azure.KeyVault.Core.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\SslCertBinding.Net.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\System.Threading.Tasks.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\Templates\currencysystem4.js
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\Templates\currencysystem5.js
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\Templates\currencysystem5.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\Templates\ecb-eurofxref-daily.xml
XML 1.0 document, ASCII text
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\help.chm
MS Windows HtmlHelp Data
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\icuio58.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\lcms-5.0.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\libeay32.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\ml
PDF document, version 1.5
dropped
clean
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\ssleay32.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Windows\Installer\440bbd.msi
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Last Printed: Fri Dec 11 11:47:44 2009, Create Time/Date: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Sep 18 15:06:51 2020, Security: 0, Code page: 1252, Revision Number: {D9FF1A35-78F9-49F0-A6A0-DB3A11387835}, Number of Words: 8, Subject: JDesktop Tools, Author: JDesktop Integration Components (JDIC) Project, Name of Creating Application: Advanced Installer 18.7 build 0a7fdead, Template: ;1033, Title: Installation Database, Keywords: Installer, MSI, Database, Number of Pages: 200
dropped
clean
C:\Windows\Installer\MSI11D7.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Windows\Installer\MSI1488.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Windows\Installer\MSI15F0.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Windows\Installer\MSI16EB.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Windows\Installer\MSI1815.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Windows\Installer\MSI193F.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Windows\Installer\MSI3F85.tmp
data
dropped
clean
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log
UTF-8 Unicode (with BOM) text, with CRLF line terminators
dropped
clean
There are 46 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\o4c8AUtX1g.exe
'C:\Users\user\Desktop\o4c8AUtX1g.exe'
malicious
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\plcd-player.exe
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\plcd-player.exe
malicious
C:\Windows\System32\msiexec.exe
C:\Windows\system32\msiexec.exe /V
clean
C:\Windows\SysWOW64\msiexec.exe
C:\Windows\syswow64\MsiExec.exe -Embedding D90C408BAA115D1625882500CC5A128E C
clean
C:\Windows\SysWOW64\msiexec.exe
'C:\Windows\system32\msiexec.exe' /i 'C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools 3.4.0.2\install\0CE0CF4\adv.msi' AI_SETUPEXEPATH=C:\Users\user\Desktop\o4c8AUtX1g.exe SETUPEXEDIR=C:\Users\user\Desktop\ EXE_CMD_LINE='/exenoupdates /forcecleanup /wintime 1635154532 ' AI_EUIMSI=''
clean
C:\Windows\SysWOW64\msiexec.exe
C:\Windows\syswow64\MsiExec.exe -Embedding 97E0B76AE09D0E82CE071E7BABCE98E1
clean

URLs

Name
IP
Malicious
http://crl.sectigo.com/SectigoPublicCodeSigningCAEVR36.crl0
unknown
clean
http://html4/loose.dtd
unknown
clean
http://www.openssl.org/support/faq.html....................rbwb.rndC:HOMERANDFILEPRNG
unknown
clean
http://ocsp.startssl.com/sub/class2/code/ca0
unknown
clean
http://crl.startssl.com/sfsca.crl0C
unknown
clean
https://sectigo.com/CPS0
unknown
clean
http://apache.org/xml/UnknownNSUCS4UCS-4UCS_4UTF-32ISO-10646-UCS-4UCS-4
unknown
clean
http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0
unknown
clean
http://ocsp.sectigo.com0
unknown
clean
http://www.openssl.org/V
unknown
clean
http://www.unicode.org/copyright.html
unknown
clean
https://currencysystem.com/gfx/pub/script-icon-16x16.gif
unknown
clean
https://www.nuget.org/packages/Azure.Security.KeyVault.Keys
unknown
clean
http://www.gesmes.org/xml/2002-08-01
unknown
clean
http://crt.sectigo.com/SectigoPublicCodeSigningCAEVR36.crt0#
unknown
clean
http://ocsp.startssl.com/ca00
unknown
clean
http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#
unknown
clean
http://.css
unknown
clean
https://aka.ms/azsdkvalueprop.
unknown
clean
http://crl.startssl.com/crtc2-crl.crl0
unknown
clean
http://ocsp.sectigo.com0)
unknown
clean
http://www.ecb.int/vocabulary/2002-08-01/eurofxref
unknown
clean
http://icu-project.org
unknown
clean
http://www.MyBusinessCatalog.com
unknown
clean
http://www.openssl.org/support/faq.html
unknown
clean
http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
unknown
clean
https://www.nuget.org/packages/Azure.Security.KeyVault.Certificates
unknown
clean
https://currencysystem.com/gfx/pub/script-button-88x31.gif
unknown
clean
http://aia.startssl.com/certs/sub.class2.code.ca.crt0#
unknown
clean
https://currencysystem.com/gfx/pub/script-icon-16x16.png
unknown
clean
https://www.nuget.org/packages/Azure.Security.KeyVault.Secrets
unknown
clean
https://www.thawte.com/cps0/
unknown
clean
http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
unknown
clean
https://www.thawte.com/repository0W
unknown
clean
http://mybusinesscatalog.com0
unknown
clean
https://sectigo.com/CPS0D
unknown
clean
http://aia.startssl.com/certs/ca.crt02
unknown
clean
http://apache.org/xml/messages/XML4CErrors#FIXEDEBCDIC-CP-USIBM037IBM1047IBM-1047IBM1140IBM01140CCSI
unknown
clean
http://www.startssl.com/policy.pdf0
unknown
clean
https://www.advancedinstaller.com
unknown
clean
https://secure.comodo.com/CPS0L
unknown
clean
http://www.startssl.com/0
unknown
clean
https://currencysystem.com/gfx/pub/script-button-88x31.png
unknown
clean
http://.jpg
unknown
clean
http://apache.org/xml/messages/XMLValidityWINDOWS-1252XERCES-XMLCHhttp://apache.org/xml/messages/XML
unknown
clean
https://currencysystem.com
unknown
clean
There are 36 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
get.updates.avast.cn
unknown
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Owner
clean
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
SessionHash
clean
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Sequence
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Config.Msi\
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\440bbf.rbs
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\440bbf.rbsLow
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-3853321935-2125563209-4053062332-1002\Components\B6B1AB5FB65704B45ABC8A2AE197AD6E
159325A4F2A056D43AE1BB220DECC04F
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-3853321935-2125563209-4053062332-1002\Components\25B5D3CF1652336458BCF6B8A8682F9F
159325A4F2A056D43AE1BB220DECC04F
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-3853321935-2125563209-4053062332-1002\Components\537D28C8793086441BC6D31BF7A70760
159325A4F2A056D43AE1BB220DECC04F
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-3853321935-2125563209-4053062332-1002\Components\40A865B0C963BF34894E4C731A75900E
159325A4F2A056D43AE1BB220DECC04F
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-3853321935-2125563209-4053062332-1002\Components\7134500D701E9C54DB28707B49957706
159325A4F2A056D43AE1BB220DECC04F
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-3853321935-2125563209-4053062332-1002\Components\3F855EC47D030174A80335FFC70A9AF7
159325A4F2A056D43AE1BB220DECC04F
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-3853321935-2125563209-4053062332-1002\Components\190B693A04848D44DA7D96EB58838687
159325A4F2A056D43AE1BB220DECC04F
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-3853321935-2125563209-4053062332-1002\Components\7B6FCD98048077942AFC50FC7D19D105
159325A4F2A056D43AE1BB220DECC04F
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-3853321935-2125563209-4053062332-1002\Components\0F739F1630978C44F8C9F005FFDD6292
159325A4F2A056D43AE1BB220DECC04F
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-3853321935-2125563209-4053062332-1002\Components\D56023AD4EAB9874E8DC2179D4889E82
159325A4F2A056D43AE1BB220DECC04F
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-3853321935-2125563209-4053062332-1002\Components\DA66C642B153B1B4B82A44D62501F968
159325A4F2A056D43AE1BB220DECC04F
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-3853321935-2125563209-4053062332-1002\Components\ACE6C7E24428B7E46BDEB75CB23FB730
159325A4F2A056D43AE1BB220DECC04F
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-3853321935-2125563209-4053062332-1002\Components\6540FADD1E14D4041826B1A437DBF2AB
159325A4F2A056D43AE1BB220DECC04F
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-3853321935-2125563209-4053062332-1002\Components\876DCC939950A7C428E54E307B42FC7A
159325A4F2A056D43AE1BB220DECC04F
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-3853321935-2125563209-4053062332-1002\Components\4CC97D2637A61F54AAFB083B3FDFC425
159325A4F2A056D43AE1BB220DECC04F
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-3853321935-2125563209-4053062332-1002\Components\3E270501E619D75458D5D9BBCEF6E402
159325A4F2A056D43AE1BB220DECC04F
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-3853321935-2125563209-4053062332-1002\Components\DE30B1393AF1E8248AD3524F20C3A62A
159325A4F2A056D43AE1BB220DECC04F
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Users\user\AppData\Roaming\JDesktop Integration Components (JDIC) Project\JDesktop Tools\Templates\
clean
HKEY_CURRENT_USER\Software\JDesktop Integration Components (JDIC) Project\JDesktop Tools
Version
clean
HKEY_CURRENT_USER\Software\JDesktop Integration Components (JDIC) Project\JDesktop Tools
Path
clean
HKEY_CURRENT_USER\Software\Caphyon\Advanced Installer\LZMA\{4A523951-0A2F-4D65-A31E-BB22D0CE0CF4}\3.4.0.2
AI_ExePath
clean
There are 18 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
3E68000
heap private
page read and write
malicious
3E68000
heap private
page read and write
malicious
3949000
heap private
page read and write
malicious
3E68000
heap private
page read and write
malicious
3E68000
heap private
page read and write
malicious
3E68000
heap private
page read and write
malicious
3E68000
heap private
page read and write
malicious
3E68000
heap private
page read and write
malicious
3E68000
heap private
page read and write
malicious
3E68000
heap private
page read and write
malicious
20824D91000
unkown
page read and write
clean
7DF5BBE20000
unkown image
page readonly
clean
183F1060000
unkown image
page readonly
clean
2F87000
unkown
page read and write
clean
7FF5DB841000
unkown image
page readonly
clean
7DF525390000
unkown image
page readonly
clean
7DF525390000
unkown image
page readonly
clean
20824D7F000
unkown
page read and write
clean
3BEA000
unkown
page read and write
clean
4480000
unkown
page read and write
clean
5240000
unkown
page read and write
clean
1250000
unkown
page read and write
clean
20824DA2000
unkown
page read and write
clean
124E000
unkown
page read and write
clean
D3D000
unkown image
page readonly
clean
20824D91000
unkown
page read and write
clean
7FF510101000
unkown image
page readonly
clean
7DF5F0B02000
unkown image
page readonly
clean
1266000
unkown
page read and write
clean
1250000
unkown
page read and write
clean
1250000
unkown
page read and write
clean
10BF2400000
unkown
page read and write
clean
5501000
unkown
page read and write
clean
124B000
unkown
page read and write
clean
33C0000
heap private
page read and write
clean
4840000
unkown
page read and write
clean
7FF5684FE000
unkown image
page readonly
clean
121E000
unkown
page read and write
clean
FF7A2000
unkown image
page readonly
clean
11D3000
heap default
page read and write
clean
69EED78000
stack
page read and write
clean
7FF510264000
unkown image
page readonly
clean
6DA87000
unkown image
page write copy
clean
20824D91000
unkown
page read and write
clean
7DF5253A2000
unkown image
page readonly
clean
20824DB5000
unkown
page read and write
clean
3158000
unkown
page read and write
clean
16921202000
unkown
page read and write
clean
20824D7E000
unkown
page read and write
clean
10BF2980000
unkown image
page readonly
clean
DE0000
unkown image
page readonly
clean
183F0ED0000
unkown image
page read and write
clean
AB877F000
stack
page read and write
clean
7FF556C71000
unkown image
page readonly
clean
5400000
unkown
page read and write
clean
1240000
unkown
page read and write
clean
7FF5DB546000
unkown image
page readonly
clean
1142000
unkown
page read and write
clean
20825202000
unkown
page read and write
clean
325547E000
stack
page read and write
clean
10BF2402000
unkown
page read and write
clean
20824483000
unkown
page read and write
clean
1375000
heap default
page read and write
clean
7FF5DB9AF000
unkown image
page readonly
clean
19A0000
unkown image
page readonly
clean
7DF57D620000
unkown image
page readonly
clean
12E0000
heap default
page read and write
clean
5947000
unkown
page read and write
clean
16920890000
unkown image
page readonly
clean
1336000
unkown
page read and write
clean
20824470000
unkown
page read and write
clean
20824D91000
unkown
page read and write
clean
7FF5A6D74000
unkown image
page readonly
clean
2082445C000
unkown
page read and write
clean
7FF5DB730000
unkown image
page readonly
clean
20824459000
unkown
page read and write
clean
7FF50FA77000
unkown image
page readonly
clean
16920A50000
unkown
page read and write
clean
7FF5DB7C1000
unkown image
page readonly
clean
20824D91000
unkown
page read and write
clean
3E6B000
heap private
page read and write
clean
1341000
heap default
page read and write
clean
20824D94000
unkown
page read and write
clean
472F000
stack
page read and write
clean
20824D93000
unkown
page read and write
clean
AB7F8B000
unkown
page read and write
clean
7FF556CDD000
unkown image
page readonly
clean
5501000
unkown
page read and write
clean
12D4000
heap default
page read and write
clean
7FF5A6D81000
unkown image
page readonly
clean
1220000
unkown
page read and write
clean
3B31000
unkown
page read and write
clean
11D9000
unkown
page read and write
clean
183F1106000
unkown
page read and write
clean
7DF5BBE10000
unkown image
page readonly
clean
7FF510220000
unkown image
page readonly
clean
127C000
unkown
page read and write
clean
69EEF7F000
stack
page read and write
clean
7FF5565ED000
unkown image
page readonly
clean
32556FE000
stack
page read and write
clean
7DF5F0AF2000
unkown image
page readonly
clean
10BF243C000
unkown
page read and write
clean
20824D95000
unkown
page read and write
clean
2081503C000
unkown
page read and write
clean
A74000
unkown image
page execute and read and write
clean
CB7000
unkown image
page readonly
clean
3BF1000
unkown
page read and write
clean
F10000
unkown image
page readonly
clean
10BF2513000
unkown
page read and write
clean
20824DB9000
unkown
page read and write
clean
7FF510312000
unkown image
page readonly
clean
7FF5DB9C4000
unkown image
page readonly
clean
121D000
unkown
page read and write
clean
208244D3000
unkown
page read and write
clean
3B29000
unkown
page read and write
clean
69EE67E000
stack
page read and write
clean
48BE000
stack
page read and write
clean
1250000
unkown
page read and write
clean
5341000
unkown
page read and write
clean
898635E000
stack
page read and write
clean
20824A80000
unkown image
page read and write
clean
69EE8FE000
stack
page read and write
clean
132B000
unkown
page read and write
clean
7FF5DB8D3000
unkown image
page readonly
clean
7DF57D630000
unkown image
page readonly
clean
390B000
stack
page read and write
clean
7FF568519000
unkown image
page readonly
clean
137A000
unkown
page read and write
clean
20824D91000
unkown
page read and write
clean
20815053000
unkown
page read and write
clean
7FF51027F000
unkown image
page readonly
clean
7FF5DB9F6000
unkown image
page readonly
clean
20824D88000
unkown
page read and write
clean
1335000
unkown
page read and write
clean
7FF5A6B8B000
unkown image
page readonly
clean
2FBC000
unkown
page read and write
clean
AB827E000
stack
page read and write
clean
20824DA6000
unkown
page read and write
clean
7DF5BBE10000
unkown image
page readonly
clean
3090000
unkown
page read and write
clean
169E000
stack
page read and write
clean
7DF57D620000
unkown image
page readonly
clean
31D0000
unkown
page read and write
clean
7DF5BBE12000
unkown image
page readonly
clean
7F6E0000
unkown image
page readonly
clean
7FF51026A000
unkown image
page readonly
clean
2F56000
heap private
page read and write
clean
3B5A000
unkown
page read and write
clean
89862DB000
unkown
page read and write
clean
20824D81000
unkown
page read and write
clean
20815802000
unkown
page read and write
clean
1236000
unkown
page read and write
clean
7DF56BF10000
unkown image
page readonly
clean
325557C000
stack
page read and write
clean
D50000
unkown image
page readonly
clean
3B37000
unkown
page read and write
clean
7FF5DB823000
unkown image
page readonly
clean
20824D7B000
unkown
page read and write
clean
1250000
unkown image
page read and write
clean
69EEBF8000
stack
page read and write
clean
7DF56BF02000
unkown image
page readonly
clean
20825202000
unkown
page read and write
clean
20815049000
unkown
page read and write
clean
1250000
unkown
page read and write
clean
1351000
unkown
page read and write
clean
1250000
unkown
page read and write
clean
2082449E000
unkown
page read and write
clean
147D000
unkown image
page readonly
clean
113E000
stack
page read and write
clean
7FF5DBA71000
unkown image
page readonly
clean
11D9000
unkown
page read and write
clean
7FF5DB94F000
unkown image
page readonly
clean
16920A00000
unkown
page read and write
clean
A5C000
unkown
page read and write
clean
7FF5DB780000
unkown image
page readonly
clean
C6B000
unkown image
page readonly
clean
7FF556DD4000
unkown image
page readonly
clean
20824D95000
unkown
page read and write
clean
20824DA2000
unkown
page read and write
clean
1208000
unkown
page read and write
clean
7FF51021E000
unkown image
page readonly
clean
3E90000
unkown
page read and write
clean
3B42000
unkown
page read and write
clean
20825202000
unkown
page read and write
clean
325567B000
stack
page read and write
clean
2082526A000
unkown
page read and write
clean
2F50000
heap private
page read and write
clean
20824D8F000
unkown
page read and write
clean
7FF556DA7000
unkown image
page readonly
clean
20824D91000
unkown
page read and write
clean
7FF556E09000
unkown image
page readonly
clean
20824D85000
unkown
page read and write
clean
137A000
unkown
page read and write
clean
20824D87000
unkown
page read and write
clean
317D000
stack
page read and write
clean
6D621000
unkown image
page execute read
clean
20824A70000
unkown
page read and write
clean
16920A2A000
unkown
page read and write
clean
20825202000
unkown
page read and write
clean
20824516000
unkown
page read and write
clean
20824DB5000
unkown
page read and write
clean
3B3D000
unkown
page read and write
clean
20824DB5000
unkown
page read and write
clean
20815000000
unkown
page read and write
clean
1250000
unkown
page read and write
clean
7FF5A6B33000
unkown image
page readonly
clean
7FF5DB94B000
unkown image
page readonly
clean
7FF5A6865000
unkown image
page readonly
clean
11F8000
unkown
page read and write
clean
3B6B000
unkown
page read and write
clean
3B50000
unkown
page read and write
clean
208241E0000
unkown image
page read and write
clean
4500000
unkown
page read and write
clean
1218000
unkown
page read and write
clean
7DF525392000
unkown image
page readonly
clean
20824DB7000
unkown
page read and write
clean
127C000
unkown image
page readonly
clean
7DF4B9CD0000
unkown image
page readonly
clean
7FF5A6C9B000
unkown image
page readonly
clean
1146000
unkown
page read and write
clean
1279000
unkown
page read and write
clean
FF7A0000
unkown image
page readonly
clean
7F6D2000
unkown image
page readonly
clean
20825220000
unkown
page read and write
clean
7FF50FF97000
unkown image
page readonly
clean
3B4A000
unkown
page read and write
clean
42EE000
stack
page read and write
clean
2F9E000
stack
page read and write
clean
7DF5BBE20000
unkown image
page readonly
clean
C6B000
unkown image
page readonly
clean
7FF556DDA000
unkown image
page readonly
clean
3BC5000
unkown
page read and write
clean
183F1000000
unkown
page read and write
clean
7FF556CF4000
unkown image
page readonly
clean
183F110D000
unkown
page read and write
clean
3EA0000
stack
page read and write
clean
20824D7C000
unkown
page read and write
clean
1242000
unkown
page read and write
clean
20814F80000
unkown
page read and write
clean
7FF5DB888000
unkown image
page readonly
clean
12FE000
heap default
page read and write
clean
7FF5DB1DD000
unkown image
page readonly
clean
2082443C000
unkown
page read and write
clean
1207000
unkown
page read and write
clean
1272000
unkown
page read and write
clean
7FF5A6B8E000
unkown image
page readonly
clean
DA8000
unkown image
page read and write
clean
AB84FA000
stack
page read and write
clean
1364000
unkown
page read and write
clean
DA7000
unkown image
page write copy
clean
6DDF0000
unkown image
page readonly
clean
20824D99000
unkown
page read and write
clean
7FF556C8B000
unkown image
page readonly
clean
7FF556D95000
unkown image
page readonly
clean
5501000
unkown
page read and write
clean
10BF2429000
unkown
page read and write
clean
3A10000
unkown
page read and write
clean
4400000
unkown
page read and write
clean
20824DC6000
unkown
page read and write
clean
7FF5A6CC7000
unkown image
page readonly
clean
7FF556E7A000
unkown image
page readonly
clean
20825203000
unkown
page read and write
clean
1B20000
unkown image
page readonly
clean
7FF5A6D09000
unkown image
page readonly
clean
16920890000
unkown image
page readonly
clean
20824DB2000
unkown
page read and write
clean
7FF5684CC000
unkown image
page readonly
clean
AB857F000
stack
page read and write
clean
7FF556DE4000
unkown image
page readonly
clean
20824D2B000
unkown
page read and write
clean
124B000
unkown
page read and write
clean
7DF5253A0000
unkown image
page readonly
clean
208244C2000
unkown
page read and write
clean
20824230000
unkown image
page readonly
clean
7FF5DB9E8000
unkown image
page readonly
clean
12DB000
heap default
page read and write
clean
20824D91000
unkown
page read and write
clean
3C10000
unkown
page read and write
clean
11BB000
heap default
page read and write
clean
11D3000
unkown
page read and write
clean
3A0F000
stack
page read and write
clean
10BF22A0000
unkown image
page readonly
clean
10BF2450000
unkown
page read and write
clean
2082444A000
unkown
page read and write
clean
5300000
unkown
page read and write
clean
7DF5253B0000
unkown image
page readonly
clean
7FF5A6C90000
unkown image
page readonly
clean
3B20000
unkown
page read and write
clean
7FF556E06000
unkown image
page readonly
clean
20824600000
unkown image
page readonly
clean
183F11E0000
unkown image
page readonly
clean
7FF51030A000
unkown image
page readonly
clean
7F6F0000
unkown image
page readonly
clean
3041000
unkown
page read and write
clean
10BF2508000
unkown
page read and write
clean
131A000
unkown
page read and write
clean
1251000
unkown
page read and write
clean
7DF5F0AF2000
unkown image
page readonly
clean
11DC000
unkown
page read and write
clean
7DF5BBE00000
unkown image
page readonly
clean
7FF5DB7B6000
unkown image
page readonly
clean
16920A4A000
unkown
page read and write
clean
16920A55000
unkown
page read and write
clean
7DF5F0AF0000
unkown image
page readonly
clean
1240000
unkown
page read and write
clean
7FF5DB883000
unkown image
page readonly
clean
2D5F3BA000
unkown
page read and write
clean
138A000
unkown
page read and write
clean
7DF57D630000
unkown image
page readonly
clean
1250000
unkown
page read and write
clean
20815002000
unkown
page read and write
clean
7FF5684A5000
unkown image
page readonly
clean
1264000
unkown
page read and write
clean
1278000
unkown
page read and write
clean
11B8000
unkown
page read and write
clean
5241000
unkown
page read and write
clean
2081504E000
unkown
page read and write
clean
20824D82000
unkown
page read and write
clean
1250000
unkown
page read and write
clean
1372000
unkown
page read and write
clean
53C1000
unkown
page read and write
clean
CB7000
unkown image
page readonly
clean
7FF510274000
unkown image
page readonly
clean
3BCA000
unkown
page read and write
clean
121A000
unkown
page read and write
clean
7FF5DB8E4000
unkown image
page readonly
clean
32558F7000
stack
page read and write
clean
7FF5DB95F000
unkown image
page readonly
clean
10BF2455000
unkown
page read and write
clean
147A000
unkown image
page write copy
clean
8986B7F000
stack
page read and write
clean
20824D00000
unkown
page read and write
clean
16920A87000
unkown
page read and write
clean
11D9000
unkown
page read and write
clean
3B10000
unkown
page read and write
clean
2D5F8FD000
stack
page read and write
clean
183F1030000
unkown
page read and write
clean
20815029000
unkown
page read and write
clean
3B20000
unkown
page read and write
clean
7FF5A6CD4000
unkown image
page readonly
clean
1205000
unkown
page read and write
clean
7FF5DB980000
unkown image
page readonly
clean
7FF5DB4F2000
unkown image
page readonly
clean
16920C00000
unkown image
page readonly
clean
2D5F87F000
stack
page read and write
clean
1327000
unkown
page read and write
clean
20824DC6000
unkown
page read and write
clean
DB0000
heap default
page read and write
clean
7FF5A6C95000
unkown image
page readonly
clean
131C000
heap default
page read and write
clean
10BF2290000
heap private
page read and write
clean
10BF2800000
unkown image
page readonly
clean
7DF56BF10000
unkown image
page readonly
clean
16920B13000
unkown
page read and write
clean
7FF556D8E000
unkown image
page readonly
clean
7DF47B4E0000
unkown image
page readonly
clean
A60000
unkown image
page readonly
clean
20824980000
unkown image
page readonly
clean
7DF469DD0000
unkown image
page readonly
clean
7FF5A6D0D000
unkown image
page readonly
clean
CE0000
unkown image
page readonly
clean
7FF5100E1000
unkown image
page readonly
clean
7DF5253B0000
unkown image
page readonly
clean
12B6000
heap default
page read and write
clean
7DF56BF12000
unkown image
page readonly
clean
20824456000
unkown
page read and write
clean
5501000
unkown
page read and write
clean
7DF5BBE00000
unkown image
page readonly
clean
89863DE000
stack
page read and write
clean
1322000
heap default
page read and write
clean
10BF2280000
unkown image
page read and write
clean
476E000
stack
page read and write
clean
20824D91000
unkown
page read and write
clean
477E000
stack
page read and write
clean
7FF5DB45E000
unkown image
page readonly
clean
20825202000
unkown
page read and write
clean
183F1110000
unkown
page read and write
clean
20824DA2000
unkown
page read and write
clean
69EF07F000
stack
page read and write
clean
11EF000
unkown
page read and write
clean
183F1110000
unkown
page read and write
clean
20824453000
unkown
page read and write
clean
1190000
heap default
page read and write
clean
7FF5DB9D4000
unkown image
page readonly
clean
3B25000
unkown
page read and write
clean
1381000
unkown
page read and write
clean
2081504A000
unkown
page read and write
clean
20824450000
unkown
page read and write
clean
FF7C0000
unkown image
page readonly
clean
DA7000
unkown image
page write copy
clean
20825202000
unkown
page read and write
clean
1256000
unkown
page read and write
clean
20824D8F000
unkown
page read and write
clean
1226000
unkown
page read and write
clean
7FF51016D000
unkown image
page readonly
clean
7F6D0000
unkown image
page readonly
clean
3B4B000
unkown
page read and write
clean
F70000
heap default
page read and write
clean
7FF556DEF000
unkown image
page readonly
clean
4401000
unkown
page read and write
clean
11CF000
unkown
page read and write
clean
20824D7B000
unkown
page read and write
clean
20824429000
unkown
page read and write
clean
20814E30000
unkown image
page readonly
clean
7FF5DB2D7000
unkown image
page readonly
clean
F60000
unkown
page read and write
clean
1242000
unkown
page read and write
clean
1250000
unkown
page read and write
clean
20814F60000
unkown image
page readonly
clean
11E2000
unkown
page read and write
clean
7DF5BBE02000
unkown image
page readonly
clean
169209C0000
unkown image
page readonly
clean
20824D77000
unkown
page read and write
clean
8986977000
stack
page read and write
clean
208244E4000
unkown
page read and write
clean
20824D8F000
unkown
page read and write
clean
325515C000
unkown
page read and write
clean
20824D8F000
unkown
page read and write
clean
10BF22C0000
unkown image
page readonly
clean
11DD000
unkown
page read and write
clean
4481000
unkown
page read and write
clean
183F13E0000
unkown image
page readonly
clean
208244D0000
unkown
page read and write
clean
20824D91000
unkown
page read and write
clean
7FF510257000
unkown image
page readonly
clean
1250000
unkown
page read and write
clean
1250000
unkown
page read and write
clean
179E000
stack
page read and write
clean
3B33000
unkown
page read and write
clean
6D620000
unkown image
page readonly
clean
30E0000
unkown
page read and write
clean
208244EC000
unkown
page read and write
clean
1207000
unkown
page read and write
clean
2FBC000
unkown
page read and write
clean
20824DA2000
unkown
page read and write
clean
A00000
unkown image
page readonly
clean
1262000
unkown
page read and write
clean
32551DE000
stack
page read and write
clean
20824449000
unkown
page read and write
clean
7F5D0000
unkown image
page readonly
clean
16920880000
heap private
page read and write
clean
D87000
unkown image
page write copy
clean
10BF2600000
unkown image
page readonly
clean
3B5A000
unkown
page read and write
clean
10BF244D000
unkown
page read and write
clean
183F1070000
unkown image
page readonly
clean
1240000
unkown
page read and write
clean
20824D8F000
unkown
page read and write
clean
7DF5BBE02000
unkown image
page readonly
clean
7FF5DB97A000
unkown image
page readonly
clean
7FF5DB2D3000
unkown image
page readonly
clean
10BF247D000
unkown
page read and write
clean
7FF5DB985000
unkown image
page readonly
clean
CE0000
unkown image
page readonly
clean
3158000
unkown
page read and write
clean
7FF556C8E000
unkown image
page readonly
clean
9F0000
unkown image
page read and write
clean
183F1120000
unkown
page read and write
clean
7DF525392000
unkown image
page readonly
clean
20824D8B000
unkown
page read and write
clean
20824D73000
unkown
page read and write
clean
7FF510288000
unkown image
page readonly
clean
44C0000
unkown
page read and write
clean
20815200000
unkown image
page readonly
clean
3FF0000
heap private
page read and write
clean
7FF556950000
unkown image
page readonly
clean
7FF568250000
unkown image
page readonly
clean
7FF568592000
unkown image
page readonly
clean
7FF556965000
unkown image
page readonly
clean
10BF22A0000
unkown image
page readonly
clean
183F10EB000
heap default
page read and write
clean
1250000
unkown
page read and write
clean
7FF5A6A07000
unkown image
page readonly
clean
FF7B0000
unkown image
page readonly
clean
1210000
unkown
page read and write
clean
1260000
heap private
page read and write
clean
1415000
unkown image
page readonly
clean
3B34000
unkown
page read and write
clean
DBB000
unkown image
page readonly
clean
20824D9A000
unkown
page read and write
clean
20824D89000
unkown
page read and write
clean
20824800000
unkown image
page readonly
clean
3B3E000
unkown
page read and write
clean
31D0000
unkown
page read and write
clean
20814E20000
heap private
page read and write
clean
7FF556D9B000
unkown image
page readonly
clean
CDA000
unkown image
page readonly
clean
1225000
unkown
page read and write
clean
20824DA2000
unkown
page read and write
clean
124C000
unkown
page read and write
clean
7FF51024C000
unkown image
page readonly
clean
121D000
unkown
page read and write
clean
183F0EF0000
unkown image
page readonly
clean
1327000
unkown
page read and write
clean
358E000
stack
page read and write
clean
7FF5A6856000
unkown image
page readonly
clean
7FF556BE1000
unkown image
page readonly
clean
10BF246F000
unkown
page read and write
clean
3A6E000
stack
page read and write
clean
1379000
heap default
page read and write
clean
3091000
unkown
page read and write
clean
183F0F10000
unkown image
page readonly
clean
CC7000
unkown image
page readonly
clean
20824D89000
unkown
page read and write
clean
7FF5DB282000
unkown image
page readonly
clean
20824200000
unkown image
page readonly
clean
7FF510225000
unkown image
page readonly
clean
20815080000
unkown
page read and write
clean
7FF556DBF000
unkown image
page readonly
clean
A70000
unkown image
page readonly
clean
7FF5DBA64000
unkown image
page readonly
clean
3040000
unkown
page read and write
clean
208244A5000
unkown
page read and write
clean
7FF567DF3000
unkown image
page readonly
clean
DF0000
unkown image
page readonly
clean
183F1110000
unkown
page read and write
clean
7FF5DB9EE000
unkown image
page readonly
clean
463D000
stack
page read and write
clean
6DA83000
unkown image
page read and write
clean
16920B02000
unkown
page read and write
clean
7FF568508000
unkown image
page readonly
clean
7FF5DB540000
unkown image
page readonly
clean
16920A13000
unkown
page read and write
clean
2F41000
unkown
page read and write
clean
20814E60000
unkown image
page readonly
clean
3158000
unkown
page read and write
clean
20824D91000
unkown
page read and write
clean
3A1E000
stack
page read and write
clean
11DD000
unkown
page read and write
clean
7DF56BF20000
unkown image
page readonly
clean
7FF568591000
unkown image
page readonly
clean
20824DA2000
unkown
page read and write
clean
16920E00000
unkown image
page readonly
clean
1250000
unkown
page read and write
clean
7DF57D610000
unkown image
page readonly
clean
D3C000
unkown
page read and write
clean
453F000
stack
page read and write
clean
7FF5DB9AC000
unkown image
page readonly
clean
1251000
unkown
page read and write
clean
7F6D0000
unkown image
page readonly
clean
7FF5A6BFC000
unkown image
page readonly
clean
1251000
unkown
page read and write
clean
138B000
unkown
page read and write
clean
C6A000
unkown image
page execute and read and write
clean
20824330000
unkown image
page readonly
clean
69EEAFE000
stack
page read and write
clean
16920B00000
unkown
page read and write
clean
69EE37C000
unkown
page read and write
clean
16920F80000
unkown image
page readonly
clean
5440000
unkown
page read and write
clean
7DF5F0B00000
unkown image
page readonly
clean
32557FE000
stack
page read and write
clean
11E7000
unkown
page read and write
clean
3247000
unkown
page read and write
clean
6DDF0000
unkown image
page readonly
clean
20815052000
unkown
page read and write
clean
11E8000
unkown
page read and write
clean
121A000
unkown
page read and write
clean
126C000
unkown
page read and write
clean
7FF5DB595000
unkown image
page readonly
clean
7FF556C33000
unkown image
page readonly
clean
5501000
unkown
page read and write
clean
7F6D2000
unkown image
page readonly
clean
20824457000
unkown
page read and write
clean
117E000
stack
page read and write
clean
11D9000
unkown
page read and write
clean
69EEC7F000
stack
page read and write
clean
7FF5A6CBC000
unkown image
page readonly
clean
3BDB000
unkown
page read and write
clean
5A36000
unkown
page read and write
clean
7FF5DB9B7000
unkown image
page readonly
clean
D40000
unkown image
page readonly
clean
7FF5100C3000
unkown image
page readonly
clean
1240000
unkown
page read and write
clean
6D620000
unkown image
page readonly
clean
20824D98000
unkown
page read and write
clean
3BB9000
unkown
page read and write
clean
2082445D000
unkown
page read and write
clean
1280000
unkown image
page read and write
clean
1250000
unkown
page read and write
clean
169209E0000
unkown
page read and write
clean
1290000
unkown image
page readonly
clean
20824A70000
unkown
page read and write
clean
2FD0000
unkown
page read and write
clean
FF6A0000
unkown image
page readonly
clean
20824D8C000
unkown
page read and write
clean
3D73000
unkown
page read and write
clean
7FF5684EA000
unkown image
page readonly
clean
35CE000
stack
page read and write
clean
7FF5A6BDD000
unkown image
page readonly
clean
7FF556E0D000
unkown image
page readonly
clean
CC0000
unkown image
page read and write
clean
20824D91000
unkown
page read and write
clean
7FF510071000
unkown image
page readonly
clean
5640000
unkown
page read and write
clean
10BF2413000
unkown
page read and write
clean
32559FE000
stack
page read and write
clean
3BEE000
unkown
page read and write
clean
20825202000
unkown
page read and write
clean
7FF5A6BF4000
unkown image
page readonly
clean
1354000
unkown
page read and write
clean
FF7A2000
unkown image
page readonly
clean
7FF5684F4000
unkown image
page readonly
clean
7FF510173000
unkown image
page readonly
clean
7F6E0000
unkown image
page readonly
clean
169208B0000
unkown image
page readonly
clean
1251000
unkown
page read and write
clean
20824D99000
unkown
page read and write
clean
1320000
heap default
page read and write
clean
7FF5A6D82000
unkown image
page readonly
clean
20825202000
unkown
page read and write
clean
7FF5DB775000
unkown image
page readonly
clean
7FF5684CF000
unkown image
page readonly
clean
7DF56BF02000
unkown image
page readonly
clean
20824D1E000
unkown
page read and write
clean
5480000
unkown
page read and write
clean
3B3F000
unkown
page read and write
clean
7FF5A6CBF000
unkown image
page readonly
clean
3F7E000
stack
page read and write
clean
20824D8D000
unkown
page read and write
clean
7DF4EE9C0000
unkown image
page readonly
clean
129A000
heap default
page read and write
clean
7FF51029D000
unkown image
page readonly
clean
69EE9F7000
stack
page read and write
clean
5441000
unkown
page read and write
clean
20824451000
unkown
page read and write
clean
20824D91000
unkown
page read and write
clean
125A000
unkown
page read and write
clean
20824508000
unkown
page read and write
clean
1415000
unkown image
page readonly
clean
3B64000
unkown
page read and write
clean
7FF5DB87E000
unkown image
page readonly
clean
7FF5684D8000
unkown image
page readonly
clean
7FF556DC7000
unkown image
page readonly
clean
7FF51020A000
unkown image
page readonly
clean
1476000
unkown image
page read and write
clean
1270000
unkown image
page read and write
clean
20824D91000
unkown
page read and write
clean
F0C000
unkown
page read and write
clean
F75000
heap default
page read and write
clean
1251000
unkown
page read and write
clean
127E000
unkown
page read and write
clean
7FF56850E000
unkown image
page readonly
clean
1250000
unkown
page read and write
clean
10BF248A000
unkown
page read and write
clean
1351000
unkown
page read and write
clean
7FF510296000
unkown image
page readonly
clean
1291000
unkown image
page execute read
clean
20825202000
unkown
page read and write
clean
3B4B000
unkown
page read and write
clean
2082444B000
unkown
page read and write
clean
898687F000
stack
page read and write
clean
10BF2500000
unkown
page read and write
clean
20824D89000
unkown
page read and write
clean
7DF5F0B00000
unkown image
page readonly
clean
1240000
unkown
page read and write
clean
31BD000
stack
page read and write
clean
20824D7B000
unkown
page read and write
clean
1250000
unkown
page read and write
clean
7FF5DB861000
unkown image
page readonly
clean
20824D8F000
unkown
page read and write
clean
7FF510304000
unkown image
page readonly
clean
1290000
unkown image
page readonly
clean
7FF5A6C8A000
unkown image
page readonly
clean
3B4A000
unkown
page read and write
clean
183F10F6000
heap default
page read and write
clean
CC7000
unkown image
page readonly
clean
7FF5DB9DF000
unkown image
page readonly
clean
7FF568584000
unkown image
page readonly
clean
7FF556CFC000
unkown image
page readonly
clean
7FF5DB997000
unkown image
page readonly
clean
121E000
unkown
page read and write
clean
7DF5F0B10000
unkown image
page readonly
clean
FF7B2000
unkown image
page readonly
clean
380D000
stack
page read and write
clean
20824370000
unkown image
page readonly
clean
443F000
stack
page read and write
clean
30E0000
unkown
page read and write
clean
7FF556956000
unkown image
page readonly
clean
7FF5DB97E000
unkown image
page readonly
clean
4840000
unkown
page read and write
clean
35D0000
heap private
page read and write
clean
20824D9D000
unkown
page read and write
clean
31C0000
heap private
page read and write
clean
1354000
unkown
page read and write
clean
7FF556DFE000
unkown image
page readonly
clean
69EE877000
stack
page read and write
clean
20824D8F000
unkown
page read and write
clean
A71000
unkown image
page execute and read and write
clean
7FF5DB7B4000
unkown image
page readonly
clean
1200000
unkown image
page readonly
clean
20814E50000
unkown image
page readonly
clean
20824D91000
unkown
page read and write
clean
7FF5684E4000
unkown image
page readonly
clean
7FF556D90000
unkown image
page readonly
clean
1349000
heap default
page read and write
clean
6DA9B000
unkown image
page readonly
clean
A71000
unkown image
page execute and write copy
clean
3B27000
unkown
page read and write
clean
20824DB9000
unkown
page read and write
clean
183F1020000
heap private
page read and write
clean
473A000
stack
page read and write
clean
20824D79000
unkown
page read and write
clean
3B4D000
unkown
page read and write
clean
183F111F000
unkown
page read and write
clean
8986A7F000
stack
page read and write
clean
20824DB2000
unkown
page read and write
clean
2D5F67F000
stack
page read and write
clean
20824D83000
unkown
page read and write
clean
7FF510311000
unkown image
page readonly
clean
7FF5DB82A000
unkown image
page readonly
clean
7FF5A6850000
unkown image
page readonly
clean
20824D77000
unkown
page read and write
clean
1363000
unkown
page read and write
clean
7DF5253A2000
unkown image
page readonly
clean
3B63000
unkown
page read and write
clean
7DF57D610000
unkown image
page readonly
clean
20824400000
unkown
page read and write
clean
20824D77000
unkown
page read and write
clean
1250000
unkown
page read and write
clean
20824D8F000
unkown
page read and write
clean
7FF5A6AE1000
unkown image
page readonly
clean
7FF51022B000
unkown image
page readonly
clean
D87000
unkown image
page write copy
clean
183F110D000
unkown
page read and write
clean
7DF5253A0000
unkown image
page readonly
clean
20824DC3000
unkown
page read and write
clean
3B61000
unkown
page read and write
clean
1363000
unkown
page read and write
clean
183F10F1000
unkown
page read and write
clean
A70000
unkown image
page readonly
clean
11FF000
unkown
page read and write
clean
5501000
unkown
page read and write
clean
7FF5A6B71000
unkown image
page readonly
clean
10BF2C02000
unkown
page read and write
clean
7FF510237000
unkown image
page readonly
clean
1279000
unkown
page read and write
clean
127F000
unkown image
page readonly
clean
1373000
heap default
page read and write
clean
FF7C0000
unkown image
page readonly
clean
1230000
unkown image
page readonly
clean
7FF5A6CA7000
unkown image
page readonly
clean
7FF5DBA72000
unkown image
page readonly
clean
2FF0000
heap private
page read and write
clean
FF7B2000
unkown image
page readonly
clean
147D000
unkown image
page readonly
clean
7FF5DB920000
unkown image
page readonly
clean
2D5F7FA000
stack
page read and write
clean
7FF56858A000
unkown image
page readonly
clean
F12000
unkown
page read and write
clean
120B000
unkown
page read and write
clean
1250000
unkown
page read and write
clean
7FF50FDE6000
unkown image
page readonly
clean
19F0000
unkown image
page readonly
clean
20824D92000
unkown
page read and write
clean
7FF556C51000
unkown image
page readonly
clean
FF7B0000
unkown image
page readonly
clean
124E000
unkown
page read and write
clean
16920870000
unkown image
page read and write
clean
5A26000
unkown
page read and write
clean
7FF5DB1D7000
unkown image
page readonly
clean
7FF50FFD0000
unkown image
page readonly
clean
20815108000
unkown
page read and write
clean
7FF5684AB000
unkown image
page readonly
clean
7FF50FDE0000
unkown image
page readonly
clean
20824200000
unkown image
page readonly
clean
7FF5565E7000
unkown image
page readonly
clean
20824D91000
unkown
page read and write
clean
7DF57D612000
unkown image
page readonly
clean
6DA80000
unkown image
page write copy
clean
7F6F0000
unkown image
page readonly
clean
7FF5DB87B000
unkown image
page readonly
clean
7FF556E82000
unkown image
page readonly
clean
1321000
unkown
page read and write
clean
20824D72000
unkown
page read and write
clean
31D4000
unkown
page read and write
clean
89867FB000
stack
page read and write
clean
7FF5DB9F9000
unkown image
page readonly
clean
20824D95000
unkown
page read and write
clean
208244CA000
unkown
page read and write
clean
1250000
unkown
page read and write
clean
7FF5A6C7A000
unkown image
page readonly
clean
20815070000
unkown
page read and write
clean
20824A70000
unkown
page read and write
clean
3FBD000
stack
page read and write
clean
5501000
unkown
page read and write
clean
31D0000
unkown
page read and write
clean
131F000
unkown
page read and write
clean
5957000
unkown
page read and write
clean
4A5F000
stack
page read and write
clean
20824D91000
unkown
page read and write
clean
7FF5A6CE4000
unkown image
page readonly
clean
3A70000
heap private
page read and write
clean
7FF5DB96A000
unkown image
page readonly
clean
2D5F6FF000
stack
page read and write
clean
1250000
unkown
page read and write
clean
1250000
unkown
page read and write
clean
7FF51021A000
unkown image
page readonly
clean
7FF5DB6F7000
unkown image
page readonly
clean
20824D7D000
unkown
page read and write
clean
7FF5684A0000
unkown image
page readonly
clean
7DF56BF00000
unkown image
page readonly
clean
A00000
unkown image
page readonly
clean
10FA000
unkown
page read and write
clean
342C000
stack
page read and write
clean
7FF556D7A000
unkown image
page readonly
clean
49BE000
stack
page read and write
clean
6DA9A000
unkown image
page read and write
clean
20814E80000
heap default
page read and write
clean
1222000
unkown
page read and write
clean
3BE9000
unkown
page read and write
clean
5230000
heap private
page read and write
clean
7FF556CE3000
unkown image
page readonly
clean
7FF5DB4E2000
unkown image
page readonly
clean
7FF5DB933000
unkown image
page readonly
clean
20815100000
unkown
page read and write
clean
DAA000
unkown image
page write copy
clean
20825202000
unkown
page read and write
clean
1250000
unkown
page read and write
clean
127D000
unkown image
page read and write
clean
3BDB000
unkown
page read and write
clean
3BCA000
unkown
page read and write
clean
183F1025000
heap private
page read and write
clean
16920A4D000
unkown
page read and write
clean
20825263000
unkown
page read and write
clean
20824D98000
unkown
page read and write
clean
5501000
unkown
page read and write
clean
2FBC000
unkown
page read and write
clean
1284000
unkown
page read and write
clean
1207000
unkown
page read and write
clean
20824D98000
unkown
page read and write
clean
2F40000
unkown
page read and write
clean
3B11000
unkown
page read and write
clean
20824D94000
unkown
page read and write
clean
AB82FE000
stack
page read and write
clean
3BED000
unkown
page read and write
clean
3BE9000
unkown
page read and write
clean
3B2E000
unkown
page read and write
clean
1476000
unkown image
page write copy
clean
20815113000
unkown
page read and write
clean
54C0000
unkown
page read and write
clean
1351000
unkown
page read and write
clean
10BF23F0000
unkown
page read and write
clean
137D000
heap default
page read and write
clean
20824D8B000
unkown
page read and write
clean
183F0EF0000
unkown image
page readonly
clean
1240000
unkown
page read and write
clean
208244BA000
unkown
page read and write
clean
7FF50FDF5000
unkown image
page readonly
clean
20824220000
unkown image
page readonly
clean
1241000
unkown
page read and write
clean
7FF5A6B51000
unkown image
page readonly
clean
10BF244A000
unkown
page read and write
clean
7FF51024F000
unkown image
page readonly
clean
2082444C000
unkown
page read and write
clean
7FF5DB746000
unkown image
page readonly
clean
20824413000
unkown
page read and write
clean
1348000
unkown
page read and write
clean
59CA000
unkown
page read and write
clean
D97000
unkown image
page write copy
clean
487F000
stack
page read and write
clean
1200000
unkown
page read and write
clean
1336000
unkown
page read and write
clean
2F63000
unkown
page read and write
clean
20824D9A000
unkown
page read and write
clean
7FF5A6D7A000
unkown image
page readonly
clean
20824D77000
unkown
page read and write
clean
7F6E2000
unkown image
page readonly
clean
7FF51011E000
unkown image
page readonly
clean
1351000
unkown
page read and write
clean
3B22000
unkown
page read and write
clean
7DF56BF00000
unkown image
page readonly
clean
53C0000
unkown
page read and write
clean
20815102000
unkown
page read and write
clean
7FF5A6CDA000
unkown image
page readonly
clean
CDA000
unkown image
page readonly
clean
3B51000
unkown
page read and write
clean
3B1F000
unkown
page read and write
clean
69EE3FE000
stack
page read and write
clean
432E000
stack
page read and write
clean
7FF5A6CF8000
unkown image
page readonly
clean
19E0000
unkown image
page readonly
clean
10BF23D0000
unkown image
page readonly
clean
4540000
unkown
page read and write
clean
2081508B000
unkown
page read and write
clean
7DF423260000
unkown image
page readonly
clean
7F6E2000
unkown image
page readonly
clean
20824D7B000
unkown
page read and write
clean
7FF5DB4EE000
unkown image
page readonly
clean
2F64000
unkown
page read and write
clean
7FF556E74000
unkown image
page readonly
clean
3BC4000
unkown
page read and write
clean
2D5F779000
stack
page read and write
clean
7FF556B40000
unkown image
page readonly
clean
5BBE000
unkown
page read and write
clean
1227000
unkown
page read and write
clean
494F000
stack
page read and write
clean
1271000
unkown image
page execute read
clean
7FF5A6BE3000
unkown image
page readonly
clean
2082448C000
unkown
page read and write
clean
7FF51020C000
unkown image
page readonly
clean
5501000
unkown
page read and write
clean
169208C0000
unkown image
page readonly
clean
20815013000
unkown
page read and write
clean
7FF5DB8CD000
unkown image
page readonly
clean
134E000
heap default
page read and write
clean
1388000
heap default
page read and write
clean
20824D91000
unkown
page read and write
clean
7FF5DBA6A000
unkown image
page readonly
clean
20824D7E000
unkown
page read and write
clean
1250000
unkown
page read and write
clean
7FF556DBC000
unkown image
page readonly
clean
54C1000
unkown
page read and write
clean
10BF22D0000
unkown image
page readonly
clean
7FF5DB8EC000
unkown image
page readonly
clean
20824D8C000
unkown
page read and write
clean
5340000
unkown
page read and write
clean
3A10000
unkown
page read and write
clean
7DF5F0AF0000
unkown image
page readonly
clean
183F10E0000
heap default
page read and write
clean
20824513000
unkown
page read and write
clean
7DF57D612000
unkown image
page readonly
clean
1250000
unkown
page read and write
clean
183F1560000
unkown image
page readonly
clean
124B000
unkown
page read and write
clean
1250000
unkown
page read and write
clean
7FF510184000
unkown image
page readonly
clean
20824D8F000
unkown
page read and write
clean
7FF51028E000
unkown image
page readonly
clean
137E000
unkown
page read and write
clean
7FF5DB98B000
unkown image
page readonly
clean
20824250000
heap default
page read and write
clean
7FF51018C000
unkown image
page readonly
clean
7FF50FA7D000
unkown image
page readonly
clean
20824DA2000
unkown
page read and write
clean
2082444E000
unkown
page read and write
clean
20824350000
unkown
page read and write
clean
4580000
unkown
page read and write
clean
1250000
unkown
page read and write
clean
89866FB000
stack
page read and write
clean
DB9000
unkown image
page read and write
clean
A70000
unkown image
page readonly
clean
2082444F000
unkown
page read and write
clean
7DF5F0B10000
unkown image
page readonly
clean
7FF556E81000
unkown image
page readonly
clean
125A000
unkown
page read and write
clean
7FF5A6A40000
unkown image
page readonly
clean
20825203000
unkown
page read and write
clean
183F110D000
unkown
page read and write
clean
7FF5A6D06000
unkown image
page readonly
clean
4501000
unkown
page read and write
clean
16920A3C000
unkown
page read and write
clean
3BEF000
unkown
page read and write
clean
6D995000
unkown image
page readonly
clean
208241F0000
heap private
page read and write
clean
20824D87000
unkown
page read and write
clean
16920A7A000
unkown
page read and write
clean
7FF5DB73B000
unkown image
page readonly
clean
11EE000
unkown
page read and write
clean
20824DA3000
unkown
page read and write
clean
F0E000
unkown
page read and write
clean
3BA9000
unkown
page read and write
clean
6FA20000
unkown image
page readonly
clean
7FF5A6CFE000
unkown image
page readonly
clean
169208E0000
heap default
page read and write
clean
1240000
unkown
page read and write
clean
39C8000
heap private
page read and write
clean
AB8677000
stack
page read and write
clean
69EEE7C000
stack
page read and write
clean
5501000
unkown
page read and write
clean
4380000
unkown
page read and write
clean
20824454000
unkown
page read and write
clean
2F41000
unkown
page read and write
clean
20824D5E000
unkown
page read and write
clean
4840000
unkown
page read and write
clean
3B26000
unkown
page read and write
clean
10BF22F0000
heap default
page read and write
clean
DBB000
unkown image
page readonly
clean
7FF51011B000
unkown image
page readonly
clean
1334000
heap default
page read and write
clean
6DA96000
unkown image
page read and write
clean
20815057000
unkown
page read and write
clean
138B000
unkown
page read and write
clean
11FA000
unkown
page read and write
clean
7FF556B07000
unkown image
page readonly
clean
5380000
unkown
page read and write
clean
20814E10000
unkown image
page read and write
clean
20824DA2000
unkown
page read and write
clean
7FF56851D000
unkown image
page readonly
clean
127A000
unkown
page read and write
clean
7FF5DB9CA000
unkown image
page readonly
clean
7FF5A6CEF000
unkown image
page readonly
clean
3B4D000
unkown
page read and write
clean
7DF56BF20000
unkown image
page readonly
clean
7DF5F0B02000
unkown image
page readonly
clean
20824D84000
unkown
page read and write
clean
7FF5DB555000
unkown image
page readonly
clean
1290000
heap default
page read and write
clean
20824D9D000
unkown
page read and write
clean
D3D000
unkown image
page readonly
clean
7FF556DF8000
unkown image
page readonly
clean
1250000
unkown
page read and write
clean
1250000
unkown
page read and write
clean
7FF5DB922000
unkown image
page readonly
clean
7FF5DB96C000
unkown image
page readonly
clean
7FF5DB954000
unkown image
page readonly
clean
1222000
unkown
page read and write
clean
A7F000
unkown image
page execute and write copy
clean
1275000
unkown
page read and write
clean
183F1107000
unkown
page read and write
clean
7FF510299000
unkown image
page readonly
clean
138B000
unkown
page read and write
clean
20825200000
unkown
page read and write
clean
3041000
unkown
page read and write
clean
30FE000
stack
page read and write
clean
7DF56BF12000
unkown image
page readonly
clean
7FF5A6C8E000
unkown image
page readonly
clean
20814E30000
unkown image
page readonly
clean
7FF5DB7D1000
unkown image
page readonly
clean
1860000
unkown image
page readonly
clean
5969000
unkown
page read and write
clean
208244FB000
unkown
page read and write
clean
20824502000
unkown
page read and write
clean
1291000
unkown image
page execute read
clean
352B000
stack
page read and write
clean
20824D93000
unkown
page read and write
clean
10BF2502000
unkown
page read and write
clean
1290000
unkown image
page readonly
clean
7FF556D8A000
unkown image
page readonly
clean
124E000
unkown
page read and write
clean
20824C02000
unkown
page read and write
clean
D97000
unkown image
page write copy
clean
5501000
unkown
page read and write
clean
7FF5A63AE000
unkown image
page readonly
clean
138E000
unkown
page read and write
clean
20815580000
unkown image
page readonly
clean
52C0000
unkown
page read and write
clean
59CC000
unkown
page read and write
clean
7DF57D622000
unkown image
page readonly
clean
2FA0000
unkown
page read and write
clean
7FF556D7C000
unkown image
page readonly
clean
3B50000
unkown
page read and write
clean
AB887F000
stack
page read and write
clean
20815400000
unkown image
page readonly
clean
A76000
unkown image
page execute and read and write
clean
20824D84000
unkown
page read and write
clean
1251000
unkown
page read and write
clean
7DF57D622000
unkown image
page readonly
clean
1264000
unkown
page read and write
clean
11E1000
unkown
page read and write
clean
1251000
unkown
page read and write
clean
7FF567DF7000
unkown image
page readonly
clean
1660000
unkown image
page readonly
clean
2FB0000
unkown image
page readonly
clean
17A0000
unkown image
page readonly
clean
7FF5DB597000
unkown image
page readonly
clean
FF7A0000
unkown image
page readonly
clean
2082521D000
unkown
page read and write
clean
208243A0000
unkown image
page write copy
clean
16920B08000
unkown
page read and write
clean
7FF5A6C7C000
unkown image
page readonly
clean
4581000
unkown
page read and write
clean
20824D9A000
unkown
page read and write
clean
12C8000
heap default
page read and write
clean
16920A70000
unkown
page read and write
clean
7DF5BBE12000
unkown image
page readonly
clean
124E000
unkown
page read and write
clean
3BF1000
unkown
page read and write
clean
336E000
stack
page read and write
clean
52C1000
unkown
page read and write
clean
3BDC000
unkown
page read and write
clean
There are 1061 hidden memdumps, click here to show them.