IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Purchase order_122.doc
Rich Text Format data, unknown version
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\catzx[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Local\Temp\tmp566B.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\run.dat
data
dropped
malicious
C:\Users\user\AppData\Roaming\catzjt7863.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Roaming\eWoGxZG.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{2D531D94-C583-4137-BC9C-F35D458886D0}.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{9294EB41-BC98-4811-8155-5BA310CE0BF9}.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{B46515BE-EB2B-43E1-A77A-ECFC555EC443}.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Temp\tmp1E64.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\tmp249A.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\catalog.dat
data
dropped
clean
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\task.dat
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Purchase order_122.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Mon Aug 30 20:08:57 2021, mtime=Mon Aug 30 20:08:57 2021, atime=Tue Oct 26 20:31:28 2021, length=444924, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
dropped
clean
C:\Users\user\Desktop\~$rchase order_122.doc
data
dropped
clean
There are 8 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
malicious
C:\Users\user\AppData\Roaming\catzjt7863.exe
C:\Users\user\AppData\Roaming\catzjt7863.exe
malicious
C:\Windows\SysWOW64\schtasks.exe
'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\eWoGxZG' /XML 'C:\Users\user\AppData\Local\Temp\tmp566B.tmp'
malicious
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
malicious
C:\Windows\SysWOW64\schtasks.exe
'schtasks.exe' /create /f /tn 'SMTP Service' /xml 'C:\Users\user\AppData\Local\Temp\tmp249A.tmp'
malicious
C:\Windows\SysWOW64\schtasks.exe
'schtasks.exe' /create /f /tn 'SMTP Service Task' /xml 'C:\Users\user\AppData\Local\Temp\tmp1E64.tmp'
malicious
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe 0
malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
'C:\Program Files\Microsoft Office\Office14\WINWORD.EXE' /Automation -Embedding
clean
C:\Windows\System32\taskeng.exe
taskeng.exe {AC07D2CB-425B-43FA-983F-3B14071F638D} S-1-5-21-966771315-3019405637-367336477-1006:user-PC\user:Interactive:[1]
clean
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
'C:\Program Files (x86)\SMTP Service\smtpsvc.exe' 0
clean
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
'C:\Program Files (x86)\SMTP Service\smtpsvc.exe'
clean
There are 1 hidden processes, click here to show them.

URLs

Name
IP
Malicious
drrkingsleym001.ddns.net
malicious
http://binatonezx.tk/catzx.exe
2.56.59.211
malicious
http://www.%s.comPA
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://www.collada.org/2005/11/COLLADASchema9Done
unknown
clean

Domains

Name
IP
Malicious
binatonezx.tk
2.56.59.211
malicious
drrkingsleym001.ddns.net
103.133.109.121
malicious

IPs

IP
Domain
Country
Malicious
103.133.109.121
drrkingsleym001.ddns.net
Viet Nam
malicious
2.56.59.211
binatonezx.tk
Netherlands
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
k ,
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
b',
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
t$,
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\31A35
31A35
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Arial Unicode MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Batang
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@BatangChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DFKai-SB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Dotum
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DotumChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@FangSong
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gulim
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GulimChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gungsuh
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GungsuhChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@KaiTi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Malgun Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft JhengHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft YaHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Mincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PGothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PMincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS UI Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@NSimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Agency FB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aharoni
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Algerian
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Andalus
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Angsana New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
AngsanaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aparajita
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arabic Typesetting
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Black
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Narrow
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Rounded MT Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Unicode MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Baskerville Old Face
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Batang
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BatangChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bauhaus 93
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bell MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB Demi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bernard MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Blackadder ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Black
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Poster Compressed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Book Antiqua
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookman Old Style
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookshelf Symbol 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bradley Hand ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Britannic Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Broadway
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Browallia New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BrowalliaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Brush Script MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Californian FB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calisto MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria Math
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Candara
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Castellar
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Centaur
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Schoolbook
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Chiller
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Colonna MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Comic Sans MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Consolas
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Constantia
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cooper Black
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Corbel
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cordia New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
CordiaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Courier New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Curlz MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DaunPenh
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
David
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DFKai-SB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DilleniaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DokChampa
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Dotum
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DotumChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ebrima
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Edwardian Script ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Elephant
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Engravers MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Bold ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Demi ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Light ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Medium ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Estrangelo Edessa
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
EucrosiaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Euphemia
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FangSong
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Felix Titling
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Footlight MT Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Forte
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Book
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi Cond
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Heavy
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium Cond
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FrankRuehl
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FreesiaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Freestyle Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
French Script MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gabriola
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Garamond
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gautami
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Georgia
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gigi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Ext Condensed Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gisha
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gloucester MT Extra Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Old Style
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Stout
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gulim
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GulimChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gungsuh
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GungsuhChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Haettenschweiler
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harlow Solid Italic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harrington
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
High Tower Text
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Impact
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Imprint MT Shadow
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Informal Roman
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
IrisUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Iskoola Pota
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
JasmineUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Jokerman
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Juice ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KaiTi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kalinga
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kartika
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Khmer UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KodchiangUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kokila
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kristen ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kunstler Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lao UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Latha
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Leelawadee
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Levenim MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
LilyUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Bright
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Calligraphy
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Console
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Fax
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Handwriting
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Typewriter
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Unicode
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Magneto
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Maiandra GD
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Malgun Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mangal
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Marlett
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Matura MT Script Capitals
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Himalaya
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft JhengHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft New Tai Lue
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft PhagsPa
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Sans Serif
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Tai Le
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Uighur
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft YaHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Yi Baiti
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam Fixed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mistral
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Modern No. 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mongolian Baiti
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Monotype Corsiva
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MoolBoran
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Mincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Outlook
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PGothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PMincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Sans Serif
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Specialty
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS UI Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MT Extra
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MV Boli
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Narkisim
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Engraved
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Solid
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
NSimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Nyala
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
OCR A Extended
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Old English Text MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Onyx
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palace Script MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palatino Linotype
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Papyrus
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Parchment
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua Titling MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Plantagenet Cherokee
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Playbill
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Poor Richard
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Pristina
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Raavi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rage Italic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ravie
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Extra Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rod
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sakkal Majalla
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Script MT Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Print
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Semibold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Symbol
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shonar Bangla
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Showcard Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shruti
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic Fixed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Snap ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Stencil
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sylfaen
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Symbol
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tahoma
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tempus Sans ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Times New Roman
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Traditional Arabic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Trebuchet MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tunga
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed Extra Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Utsaah
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vani
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Verdana
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vijaya
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Viner Hand ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vivaldi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vladimir Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vrinda
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Webdings
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wide Latin
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\390BB
390BB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
WORDFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\390BB
390BB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Data
Settings
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Options
ZoomApp
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTF
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTA
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
EquationEditorFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus
FontCachePath
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
SMTP Service
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\Handshake\{AC07D2CB-425B-43FA-983F-3B14071F638D}
data
clean
There are 316 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
402000
unkown
page execute and read and write
malicious
402000
unkown
page execute and read and write
malicious
34FB000
unkown
page read and write
malicious
2451000
unkown
page read and write
malicious
24A6000
unkown
page read and write
malicious
402000
unkown
page execute and read and write
malicious
560000
unkown image
page read and write
malicious
402000
unkown
page execute and read and write
malicious
3676000
unkown
page read and write
malicious
402000
unkown
page execute and read and write
malicious
374F000
unkown
page read and write
malicious
63DA000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
3867000
unkown
page read and write
clean
36F1000
unkown
page read and write
clean
5C0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
2120000
unkown
page read and write
clean
390000
heap private
page read and write
clean
3656000
unkown
page read and write
clean
3770000
unkown
page read and write
clean
226C000
stack
page read and write
clean
1D2000
unkown
page execute and read and write
clean
67F0000
unkown
page read and write
clean
2130000
heap private
page execute and read and write
clean
930000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
38D0000
unkown
page read and write
clean
3830000
unkown
page read and write
clean
37D0000
unkown
page read and write
clean
578000
unkown
page read and write
clean
3967000
unkown
page read and write
clean
209000
unkown
page read and write
clean
3451000
unkown
page read and write
clean
63AB000
unkown
page read and write
clean
3970000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
19A000
unkown
page execute and read and write
clean
2611000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
90000
unkown image
page readonly
clean
DFE000
stack
page read and write | page guard
clean
180000
unkown
page read and write
clean
1082000
unkown image
page execute read
clean
714000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
3887000
unkown
page read and write
clean
474000
heap default
page read and write
clean
5E0000
unkown
page read and write
clean
3790000
unkown
page read and write
clean
5DF4000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
5F87000
unkown
page read and write
clean
790000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
5FCB000
unkown
page read and write
clean
5C4A000
unkown
page read and write
clean
1082000
unkown image
page execute read
clean
60AB000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
4A03000
unkown
page read and write
clean
59F1000
unkown
page read and write
clean
23AF000
stack
page read and write
clean
3EC000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7EFC0000
unkown image
page readonly
clean
6BF000
stack
page read and write
clean
3E0000
unkown
page read and write
clean
495E000
stack
page read and write
clean
310000
unkown image
page readonly
clean
3850000
unkown
page read and write
clean
37B0000
unkown
page read and write
clean
950000
unkown image
page read and write
clean
3B7000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
1088000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
9C0000
unkown image
page readonly
clean
6423000
unkown
page read and write
clean
2140000
heap private
page execute and read and write
clean
474E000
stack
page read and write
clean
5B8E000
unkown
page read and write
clean
5EF7000
unkown
page read and write
clean
5AAE000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
46D9000
unkown
page read and write
clean
D0000
unkown image
page read and write
clean
3E0000
unkown
page read and write
clean
200B000
heap private
page read and write
clean
530000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
3810000
unkown
page read and write
clean
5D76000
unkown
page read and write
clean
1CF0000
unkown image
page readonly
clean
4850000
unkown
page read and write
clean
4A12000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
78BE000
stack
page read and write
clean
3950000
unkown
page read and write
clean
5048000
unkown
page read and write
clean
7DAE000
stack
page read and write
clean
4A12000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7C6E000
stack
page read and write
clean
57F000
stack
page read and write
clean
1F2000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
160000
unkown image
page read and write
clean
16D000
heap default
page read and write
clean
5D3D000
unkown
page read and write
clean
6115000
unkown
page read and write
clean
2889000
unkown
page read and write
clean
3770000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
3D4000
heap default
page read and write
clean
47A7000
heap private
page execute and read and write
clean
7EFB0000
unkown image
page readonly
clean
20FD000
stack
page read and write
clean
312000
unkown
page read and write
clean
1E2000
unkown
page read and write
clean
766000
heap default
page read and write
clean
3E6000
unkown
page read and write
clean
530000
unkown
page read and write
clean
3B0000
heap default
page read and write
clean
70E000
stack
page read and write
clean
3E0000
unkown
page read and write
clean
5F0000
unkown image
page readonly
clean
6421000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
458D000
stack
page read and write
clean
23C4000
heap private
page read and write
clean
6029000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
490000
unkown
page read and write
clean
504E000
unkown
page read and write
clean
2E8000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
37A000
unkown
page execute and read and write
clean
1D2000
unkown
page execute and read and write
clean
52AD000
unkown
page read and write
clean
37F0000
unkown
page read and write
clean
1CF000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
61F9000
unkown
page read and write
clean
3927000
unkown
page read and write
clean
55CE000
stack
page read and write
clean
6D0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
200000
unkown
page read and write
clean
1DF000
unkown
page read and write
clean
5BF0000
unkown
page read and write
clean
2935000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
370000
unkown
page read and write
clean
3930000
unkown
page read and write
clean
400000
unkown
page execute and read and write
clean
5390000
unkown
page read and write
clean
2110000
unkown
page read and write
clean
3990000
unkown
page read and write
clean
4F0000
unkown
page execute and read and write
clean
7EFC0000
unkown image
page readonly
clean
5D10000
unkown
page read and write
clean
6F0000
heap private
page execute and read and write
clean
4A60000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
3830000
unkown
page read and write
clean
2881000
unkown
page read and write
clean
6368000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
1E0000
heap private
page read and write
clean
5F0000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
1CB000
unkown
page read and write
clean
3E4000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
270A000
unkown
page read and write
clean
5F8C000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
522F000
stack
page read and write
clean
7EFD0000
unkown image
page readonly
clean
440000
heap private
page execute and read and write
clean
7EFD0000
unkown image
page readonly
clean
20A000
unkown
page execute and read and write
clean
7EFC2000
unkown image
page readonly
clean
5FCF000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
5F21000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7D4000
heap default
page read and write
clean
5E60000
unkown
page read and write
clean
6AAD000
stack
page read and write
clean
914000
heap private
page read and write
clean
3E0000
unkown
page read and write
clean
530000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
580000
unkown
page read and write
clean
560000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7EFB0000
unkown image
page readonly
clean
3E0000
unkown
page read and write
clean
A0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
207000
unkown
page read and write | page guard
clean
90000
unkown image
page readonly
clean
560000
unkown
page execute and read and write
clean
5E0000
unkown
page read and write
clean
38F7000
unkown
page read and write
clean
4C20000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
7A6E000
stack
page read and write
clean
3E0000
unkown
page read and write
clean
6334000
unkown
page read and write
clean
1D7000
unkown
page execute and read and write
clean
7EFC0000
unkown image
page readonly
clean
2A0000
heap default
page read and write
clean
38D0000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
A0000
unkown image
page readonly
clean
63D7000
unkown
page read and write
clean
5D43000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
527E000
stack
page read and write
clean
3770000
unkown
page read and write
clean
63E5000
unkown
page read and write
clean
5D7A000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
32F000
stack
page read and write
clean
ABF000
stack
page read and write
clean
7EFD0000
unkown image
page readonly
clean
2491000
unkown
page read and write
clean
5EF9000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
7A9000
heap default
page read and write
clean
5EE6000
unkown
page read and write
clean
1B0000
unkown
page read and write
clean
3790000
unkown
page read and write
clean
4B0000
unkown
page read and write
clean
67B4000
unkown
page read and write
clean
140000
unkown image
page readonly
clean
440000
heap private
page read and write
clean
5CB5000
unkown
page read and write
clean
3B0000
unkown image
page read and write
clean
4C0000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
6595000
unkown
page read and write
clean
5F45000
unkown
page read and write
clean
A0000
unkown image
page readonly
clean
3A7000
unkown
page execute and read and write
clean
820000
unkown image
page readonly
clean
5B3000
heap default
page read and write
clean
7EFC0000
unkown image
page readonly
clean
6C9A000
unkown
page read and write
clean
60E7000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
530000
unkown
page read and write
clean
2110000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
65BA000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
830000
unkown image
page readonly
clean
3E0000
unkown
page read and write
clean
3890000
unkown
page read and write
clean
870000
unkown image
page readonly
clean
6BCE000
unkown
page read and write
clean
CAF000
stack
page read and write
clean
1A0000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
3950000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
3D6000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
4830000
heap private
page read and write
clean
530000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
2110000
unkown
page read and write
clean
49CC000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
3E0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
3870000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
3787000
unkown
page read and write
clean
63A0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
48E000
stack
page read and write
clean
4460000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
1E0000
unkown image
page readonly
clean
372000
unkown
page execute and read and write
clean
38D0000
unkown
page read and write
clean
4E0000
unkown
page read and write
clean
306000
unkown
page read and write
clean
1DA000
unkown
page execute and read and write
clean
4A56000
unkown
page read and write
clean
20000
unkown
page read and write
clean
5EFE000
stack
page read and write
clean
7EFD0000
unkown image
page readonly
clean
478E000
stack
page read and write
clean
9BC000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
4720000
unkown
page read and write
clean
63A3000
unkown
page read and write
clean
3F0000
unkown
page read and write
clean
631E000
unkown
page read and write
clean
3947000
unkown
page read and write
clean
A40000
unkown image
page readonly
clean
3750000
unkown
page read and write
clean
2A7000
heap default
page read and write
clean
6805000
unkown
page read and write
clean
3910000
unkown
page read and write
clean
710000
unkown
page read and write
clean
63B7000
unkown
page read and write
clean
4670000
unkown image
page read and write
clean
5E4E000
unkown
page read and write
clean
47E0000
unkown
page read and write
clean
396000
unkown
page read and write
clean
5F6E000
unkown
page read and write
clean
F0000
unkown image
page read and write
clean
502D000
stack
page read and write
clean
7EFB2000
unkown image
page readonly
clean
3930000
unkown
page read and write
clean
6419000
unkown
page read and write
clean
63DD000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
360000
unkown
page read and write
clean
4B0000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
5F2A000
unkown
page read and write
clean
3E5000
unkown
page read and write
clean
6E91000
unkown
page read and write
clean
340000
unkown
page execute and read and write
clean
500000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
3E7000
unkown
page read and write
clean
1CA000
unkown
page execute and read and write
clean
59F0000
unkown
page read and write
clean
1C2000
unkown
page execute and read and write
clean
5B90000
unkown
page read and write
clean
37C7000
unkown
page read and write
clean
5BFB000
unkown
page read and write
clean
3850000
unkown
page read and write
clean
4B0000
heap default
page read and write
clean
350000
heap private
page read and write
clean
620000
unkown image
page readonly
clean
1B2000
unkown
page read and write
clean
644000
heap default
page read and write
clean
457000
heap default
page read and write
clean
7EF50000
unkown
page execute and read and write
clean
90000
unkown image
page readonly
clean
31B000
unkown
page execute and read and write
clean
7EFB0000
unkown image
page readonly
clean
4960000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
450000
heap default
page read and write
clean
510000
heap private
page read and write
clean
962000
unkown image
page execute read
clean
4DF000
stack
page read and write
clean
7EFE0000
unkown image
page readonly
clean
4A0000
unkown image
page readonly
clean
6360000
unkown
page read and write
clean
350000
unkown image
page readonly
clean
61B2000
unkown
page read and write
clean
3E6000
unkown
page read and write
clean
38F0000
unkown
page read and write
clean
5EE3000
unkown
page read and write
clean
3611000
unkown
page read and write
clean
641B000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
760000
heap default
page read and write
clean
4A0000
unkown
page read and write
clean
490000
unkown
page read and write
clean
480000
unkown
page read and write
clean
471C000
stack
page read and write
clean
3730000
unkown
page read and write
clean
137000
heap default
page read and write
clean
400000
unkown
page execute and read and write
clean
1A0000
heap default
page read and write
clean
90000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
202000
unkown
page execute and read and write
clean
50000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
466E000
stack
page read and write
clean
3730000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
8F0000
unkown
page read and write
clean
20000
unkown image
page read and write
clean
5480000
heap private
page read and write
clean
3910000
unkown
page read and write
clean
C9F000
stack
page read and write
clean
6B0000
unkown image
page readonly
clean
497D000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
5390000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
3E0000
unkown
page read and write
clean
5E06000
unkown
page read and write
clean
23E2000
heap private
page read and write
clean
440000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
6519000
unkown
page read and write
clean
6780000
unkown
page read and write
clean
DB000
unkown
page read and write
clean
37B0000
unkown
page read and write
clean
541E000
stack
page read and write
clean
271E000
unkown
page read and write
clean
370000
unkown
page read and write
clean
4D3E000
stack
page read and write
clean
90000
unkown image
page readonly
clean
317000
unkown
page execute and read and write
clean
A0000
unkown image
page readonly
clean
737000
heap default
page read and write
clean
21C000
unkown
page read and write
clean
5CBA000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
27B0000
unkown
page read and write
clean
354000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
4A0000
heap private
page execute and read and write
clean
5EDE000
unkown
page read and write
clean
5DA0000
unkown
page read and write
clean
3767000
unkown
page read and write
clean
581F000
stack
page read and write
clean
7EFDF000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
27B4000
unkown
page read and write
clean
400000
unkown
page execute and read and write
clean
836000
unkown
page read and write
clean
3930000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
360000
unkown
page read and write
clean
1080000
unkown image
page readonly
clean
420000
unkown
page read and write
clean
2E6000
unkown
page read and write
clean
960000
unkown image
page readonly
clean
2BA000
unkown
page execute and read and write
clean
5E0C000
unkown
page read and write
clean
3970000
unkown
page read and write
clean
3750000
unkown
page read and write
clean
3770000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
5AC1000
unkown
page read and write
clean
618000
unkown
page read and write
clean
630000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
739000
heap default
page read and write
clean
457000
unkown
page execute and read and write
clean
5031000
unkown
page read and write
clean
4EED000
stack
page read and write
clean
6158000
unkown
page read and write
clean
2EA000
unkown
page read and write
clean
1A0000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
600000
unkown image
page readonly
clean
5F2D000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
F60000
unkown image
page readonly
clean
5F00000
unkown
page read and write
clean
570000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
2330000
heap private
page read and write
clean
3790000
unkown
page read and write
clean
3730000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
D54000
heap private
page read and write
clean
6332000
unkown
page read and write
clean
338000
unkown
page read and write
clean
932000
heap private
page read and write
clean
616C000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
4E4F000
stack
page read and write
clean
220000
heap private
page read and write
clean
60000
unkown image
page readonly
clean
990000
unkown
page read and write
clean
90000
unkown image
page readonly
clean
730000
heap default
page read and write
clean
62E4000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
3A0000
unkown
page read and write
clean
530000
unkown
page read and write
clean
29000
heap private
page read and write
clean
A40000
unkown image
page readonly
clean
601A000
unkown
page read and write
clean
600000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
3E0000
unkown
page read and write
clean
DD000
unkown
page read and write
clean
6128000
unkown
page read and write
clean
3747000
unkown
page read and write
clean
2524000
heap private
page read and write
clean
3807000
unkown
page read and write
clean
442000
unkown
page execute and read and write
clean
3770000
unkown
page read and write
clean
79F000
heap default
page read and write
clean
3DE000
stack
page read and write
clean
3E0000
unkown
page read and write
clean
22F0000
unkown
page read and write
clean
4D0000
unkown image
page readonly
clean
6C0000
unkown
page read and write
clean
38B0000
unkown
page read and write
clean
210000
unkown
page read and write
clean
2A6F000
stack
page read and write
clean
2631000
unkown
page read and write
clean
49C8000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
4A12000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
4A0000
unkown
page execute and read and write
clean
37A7000
unkown
page read and write
clean
60D8000
unkown
page read and write
clean
140000
unkown
page read and write
clean
4A42000
unkown
page read and write
clean
4E4E000
stack
page read and write | page guard
clean
A0000
unkown image
page readonly
clean
287F000
unkown
page read and write
clean
1AA000
unkown
page execute and read and write
clean
2899000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
3E0000
unkown
page read and write
clean
A0000
unkown image
page readonly
clean
631B000
unkown
page read and write
clean
3810000
unkown
page read and write
clean
49E7000
unkown
page read and write
clean
192000
unkown
page execute and read and write
clean
7EFC0000
unkown image
page readonly
clean
392000
unkown
page execute and read and write
clean
370000
unkown
page read and write
clean
962000
unkown image
page execute read
clean
3830000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
4CED000
stack
page read and write
clean
440000
unkown
page read and write
clean
19A000
unkown
page execute and read and write
clean
720000
unkown image
page readonly
clean
9F0000
unkown image
page readonly
clean
609C000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
DDE000
stack
page read and write
clean
1B7000
unkown
page execute and read and write
clean
697C000
stack
page read and write
clean
170000
heap private
page execute and read and write
clean
50000
unkown image
page readonly
clean
530000
unkown
page read and write
clean
CAE000
stack
page read and write | page guard
clean
7EFB2000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
910000
heap private
page read and write
clean
2130000
unkown
page read and write
clean
49CD000
unkown
page read and write
clean
530000
unkown
page read and write
clean
7C0000
unkown image
page readonly
clean
4480000
unkown image
page read and write
clean
7EFC0000
unkown image
page readonly
clean
23C0000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
3E0000
unkown
page read and write
clean
4F2E000
stack
page read and write
clean
7EFC2000
unkown image
page readonly
clean
12B000
unkown
page read and write
clean
5E0000
unkown image
page readonly
clean
480000
unkown image
page readonly
clean
47C4000
heap private
page execute and read and write
clean
5E67000
unkown
page read and write
clean
296B000
heap private
page read and write
clean
20000
unkown image
page read and write
clean
5DFF000
unkown
page read and write
clean
246E000
stack
page read and write
clean
37F0000
unkown
page read and write
clean
150000
unkown image
page readonly
clean
6A0000
unkown image
page readonly
clean
4A26000
unkown
page read and write
clean
370000
unkown image
page readonly
clean
67DA000
unkown
page read and write
clean
3631000
unkown
page read and write
clean
422000
unkown
page execute and read and write
clean
2100000
unkown
page execute and read and write
clean
5CE2000
unkown
page read and write
clean
A0000
unkown image
page readonly
clean
4C2000
heap private
page execute and read and write
clean
341000
heap default
page read and write
clean
37D0000
unkown
page read and write
clean
3E7000
unkown
page read and write
clean
F3D000
stack
page read and write
clean
EFF000
stack
page read and write
clean
5FB2000
unkown
page read and write
clean
8A000
unkown
page read and write
clean
5B3E000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
2482000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
3890000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
760000
unkown image
page readonly
clean
3730000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
651D000
stack
page read and write
clean
5E62000
unkown
page read and write
clean
3727000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
710000
unkown
page execute and read and write
clean
50000
unkown image
page readonly
clean
6C0000
unkown
page read and write
clean
7F5E000
stack
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
3910000
unkown
page read and write
clean
4A5000
heap private
page execute and read and write
clean
3BE000
stack
page read and write
clean
530000
unkown
page read and write
clean
3F0000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
1FA000
unkown
page execute and read and write
clean
5F40000
unkown
page read and write
clean
2460000
heap private
page read and write
clean
3987000
unkown
page read and write
clean
635E000
unkown
page read and write
clean
3947000
unkown
page read and write
clean
1A2000
unkown
page execute and read and write
clean
3790000
unkown
page read and write
clean
A48000
unkown image
page readonly
clean
570000
unkown
page read and write
clean
530000
unkown image
page readonly
clean
20000
unkown image
page read and write
clean
538000
unkown
page read and write
clean
59A0000
unkown image
page readonly
clean
2631000
unkown
page read and write
clean
38C7000
unkown
page read and write
clean
38F0000
unkown
page read and write
clean
2E7000
heap default
page read and write
clean
7EFC0000
unkown image
page readonly
clean
26C000
unkown
page read and write
clean
3890000
unkown
page read and write
clean
3810000
unkown
page read and write
clean
3E5000
unkown
page read and write
clean
540000
heap private
page read and write
clean
9A0000
unkown
page read and write
clean
36F1000
unkown
page read and write
clean
38B0000
unkown
page read and write
clean
7E8000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
3E0000
unkown
page read and write
clean
2110000
unkown
page read and write
clean
37B0000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
530000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
3E0000
unkown
page read and write
clean
1088000
unkown image
page readonly
clean
64CC000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
6E86000
unkown
page read and write
clean
5D2000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
270000
heap private
page read and write
clean
3E0000
unkown
page read and write
clean
3827000
unkown
page read and write
clean
5D0000
unkown
page read and write
clean
2DE000
heap default
page read and write
clean
160000
heap private
page read and write
clean
422000
unkown
page execute and read and write
clean
1BA000
unkown
page execute and read and write
clean
7F8000
unkown
page read and write
clean
5CDA000
unkown
page read and write
clean
3910000
unkown
page read and write
clean
4AEF000
stack
page read and write
clean
5D0A000
unkown
page read and write
clean
32F000
heap default
page read and write
clean
4B4E000
stack
page read and write
clean
10000
unkown image
page read and write
clean
5FD2000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
490000
unkown
page read and write
clean
27B000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
2E6000
unkown
page read and write | page guard
clean
EFE000
stack
page read and write | page guard
clean
5C99000
unkown
page read and write
clean
5E4C000
unkown
page read and write
clean
5F0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EF40000
unkown
page execute and read and write
clean
7EFB0000
unkown image
page readonly
clean
4A42000
unkown
page read and write
clean
7F6000
unkown
page read and write
clean
2060000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
6F0000
heap default
page read and write
clean
90000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
B80000
heap private
page read and write
clean
5F80000
unkown
page read and write
clean
45E000
stack
page read and write
clean
6436000
unkown
page read and write
clean
90000
unkown image
page readonly
clean
375000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
832000
unkown
page read and write
clean
1ED000
heap private
page read and write
clean
860000
unkown image
page readonly
clean
39A000
unkown
page execute and read and write
clean
2D7000
heap default
page read and write
clean
5E2F000
unkown
page read and write
clean
6555000
unkown
page read and write
clean
3A0000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
9E0000
unkown image
page readonly
clean
B0E000
stack
page read and write
clean
1A9000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
4CAE000
stack
page read and write
clean
50000
unkown image
page readonly
clean
5A5F000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
3E0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
D50000
heap private
page read and write
clean
1BC0000
unkown image
page readonly
clean
180000
unkown
page read and write
clean
3830000
unkown
page read and write
clean
67F7000
unkown
page read and write
clean
4AFD000
unkown
page read and write
clean
1F6000
unkown
page execute and read and write
clean
7EFC0000
unkown image
page readonly
clean
6231000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
A0000
unkown image
page readonly
clean
4A26000
unkown
page read and write
clean
350000
unkown image
page readonly
clean
7FF000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
494E000
stack
page read and write
clean
5B52000
unkown
page read and write
clean
49E9000
unkown
page read and write
clean
222000
unkown
page execute and read and write
clean
422000
unkown
page execute and read and write
clean
3750000
unkown
page read and write
clean
372F000
unkown
page read and write
clean
620000
heap default
page read and write
clean
400000
unkown
page execute and read and write
clean
537000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
6706000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
13B000
unkown
page read and write
clean
64E000
stack
page read and write
clean
371000
unkown
page read and write
clean
1D0000
unkown
page read and write
clean
2110000
unkown
page read and write
clean
5BA2000
unkown
page read and write
clean
572000
unkown
page read and write
clean
98E000
stack
page read and write
clean
628B000
unkown
page read and write
clean
4CFE000
stack
page read and write
clean
4CAE000
stack
page read and write
clean
63E2000
unkown
page read and write
clean
5EFB000
unkown
page read and write
clean
606E000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
A0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
3E0000
unkown
page read and write
clean
4F2E000
stack
page read and write
clean
3928000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
3E0000
unkown
page read and write
clean
1E6000
heap private
page read and write
clean
9BC000
unkown image
page readonly
clean
5CE5000
unkown
page read and write
clean
767000
heap default
page read and write
clean
4A2000
unkown
page read and write
clean
599D000
stack
page read and write
clean
5F68000
unkown
page read and write
clean
34DB000
unkown
page read and write
clean
960000
unkown image
page readonly
clean
38F0000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
38B0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
514C000
stack
page read and write
clean
30000
unkown image
page readonly
clean
330000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
36F0000
unkown
page read and write
clean
3930000
unkown
page read and write
clean
90000
unkown image
page readonly
clean
4B0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
3E6000
unkown
page read and write
clean
4590000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
4AE0000
unkown
page read and write
clean
5A6E000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
2F4000
heap default
page read and write
clean
A50000
unkown image
page readonly
clean
CA0000
unkown
page read and write
clean
5D14000
unkown
page read and write
clean
38B0000
unkown
page read and write
clean
248E000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
5F66000
unkown
page read and write
clean
3E6000
unkown
page read and write
clean
68AF000
unkown
page read and write
clean
5F71000
unkown
page read and write
clean
DFF000
stack
page read and write
clean
37B0000
unkown
page read and write
clean
4A42000
unkown
page read and write
clean
90000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
6EA7000
unkown
page read and write
clean
3750000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
3F0000
unkown image
page readonly
clean
53FF000
stack
page read and write
clean
470000
unkown image
page readonly
clean
90000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
4469000
unkown
page read and write
clean
4A03000
unkown
page read and write
clean
490000
unkown
page read and write
clean
75C000
stack
page read and write
clean
3E0000
unkown
page read and write
clean
1A6000
unkown
page read and write
clean
3930000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
430000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
A0000
unkown image
page readonly
clean
3810000
unkown
page read and write
clean
A0000
unkown image
page readonly
clean
1E00000
unkown image
page readonly
clean
480000
unkown
page read and write
clean
1D0000
unkown
page read and write
clean
2D0000
heap default
page read and write
clean
61ED000
stack
page read and write
clean
538D000
stack
page read and write
clean
7EFB0000
unkown image
page readonly
clean
4E6E000
stack
page read and write
clean
3897000
unkown
page read and write
clean
370000
unkown
page read and write
clean
5F37000
unkown
page read and write
clean
690000
heap private
page read and write
clean
4A26000
unkown
page read and write
clean
3710000
unkown
page read and write
clean
530000
unkown
page read and write
clean
5BE000
stack
page read and write
clean
1EB000
unkown
page execute and read and write
clean
6376000
unkown
page read and write
clean
280000
heap private
page execute and read and write
clean
2BF000
stack
page read and write
clean
3710000
unkown
page read and write
clean
3E6000
unkown
page read and write
clean
2542000
heap private
page read and write
clean
A48000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
3710000
unkown
page read and write
clean
7EF50000
unkown
page execute and read and write
clean
3710000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
6C0000
unkown
page read and write
clean
549E000
stack
page read and write
clean
1C0000
heap private
page read and write
clean
6030000
heap private
page read and write
clean
22A000
unkown
page execute and read and write
clean
7EFB0000
unkown image
page readonly
clean
380000
unkown
page execute and read and write
clean
3847000
unkown
page read and write
clean
44A000
unkown
page execute and read and write
clean
230000
heap default
page read and write
clean
3E0000
unkown
page read and write
clean
6C5000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
2684000
unkown
page read and write
clean
37F0000
unkown
page read and write
clean
3870000
unkown
page read and write
clean
560D000
stack
page read and write
clean
5F3E000
unkown
page read and write
clean
530000
unkown
page read and write
clean
3967000
unkown
page read and write
clean
164000
heap private
page read and write
clean
4470000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
360000
unkown
page read and write
clean
20000
heap private
page read and write
clean
3E6000
unkown
page read and write
clean
3730000
unkown
page read and write
clean
F0000
unkown image
page read and write
clean
5FAF000
unkown
page read and write
clean
992000
unkown
page read and write
clean
779000
heap default
page read and write
clean
5C5E000
unkown
page read and write
clean
370000
unkown
page read and write
clean
31A000
heap default
page read and write
clean
5CF1000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
754000
heap default
page read and write
clean
49CC000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
5BD2000
unkown
page read and write
clean
22E000
stack
page read and write
clean
4800000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
4470000
unkown image
page readonly
clean
490000
unkown
page read and write
clean
5A1000
heap default
page read and write
clean
3710000
unkown
page read and write
clean
2930000
heap private
page read and write
clean
470000
unkown
page execute and read and write
clean
2D0000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
1080000
unkown image
page readonly
clean
6C9000
unkown
page read and write
clean
619E000
unkown
page read and write
clean
780000
unkown image
page readonly
clean
4820000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
460000
heap private
page read and write
clean
5D7D000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
482000
unkown
page read and write
clean
535000
unkown
page read and write
clean
5F26000
unkown
page read and write
clean
130000
heap default
page read and write
clean
320000
unkown
page read and write
clean
30E000
stack
page read and write
clean
7EFB2000
unkown image
page readonly
clean
3850000
unkown
page read and write
clean
3A0000
unkown image
page readonly
clean
490000
unkown
page read and write
clean
6325000
unkown
page read and write
clean
27B2000
unkown
page read and write
clean
36F1000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
37D0000
unkown
page read and write
clean
3AB000
unkown
page execute and read and write
clean
7EFDF000
unkown
page read and write
clean
398000
heap private
page read and write
clean
1C2000
unkown
page execute and read and write
clean
1080000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
20000
unkown image
page read and write
clean
A0000
unkown image
page readonly
clean
5F7E000
unkown
page read and write
clean
1AC000
unkown
page execute and read and write
clean
3850000
unkown
page read and write
clean
5B40000
unkown
page read and write
clean
490000
unkown
page execute and read and write
clean
3D0000
unkown
page execute and read and write
clean
6F7000
heap default
page read and write
clean
5C0F000
unkown
page read and write
clean
9B0000
unkown image
page readonly
clean
49C8000
unkown
page read and write
clean
3810000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
5AE3000
unkown
page read and write
clean
440000
unkown image
page readonly
clean
2E0000
heap default
page read and write
clean
4A56000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
A42000
unkown image
page execute read
clean
63F8000
unkown
page read and write
clean
38E7000
unkown
page read and write
clean
100000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7EFD0000
unkown image
page readonly
clean
5F85000
unkown
page read and write
clean
4810000
unkown
page read and write
clean
4840000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
3E6000
unkown
page read and write
clean
4B32000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
90000
unkown image
page readonly
clean
6EA3000
unkown
page read and write
clean
535000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
5FBA000
unkown
page read and write
clean
3C0000
heap default
page read and write
clean
1DB000
unkown
page read and write
clean
46D0000
unkown
page read and write
clean
3890000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
530000
unkown
page read and write
clean
5EDA000
unkown
page read and write
clean
940000
unkown
page read and write
clean
3631000
unkown
page read and write
clean
483C000
heap private
page read and write
clean
7EFDF000
unkown
page read and write
clean
550000
unkown image
page readonly
clean
4FCD000
stack
page read and write
clean
490000
unkown
page read and write
clean
2520000
heap private
page read and write
clean
580000
unkown
page read and write
clean
3FA000
heap default
page read and write
clean
642B000
unkown
page read and write
clean
5A0B000
unkown
page read and write
clean
FFE000
stack
page read and write
clean
3870000
unkown
page read and write
clean
4C10000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
A40000
unkown image
page readonly
clean
38D0000
unkown
page read and write
clean
3830000
unkown
page read and write
clean
3907000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
627000
heap default
page read and write
clean
4C0000
heap private
page execute and read and write
clean
7EFE0000
unkown image
page readonly
clean
7D0000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
5A47000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
4A04000
unkown
page read and write
clean
590000
heap default
page read and write
clean
5ADE000
unkown
page read and write
clean
37F0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
495000
unkown
page read and write
clean
2D0000
heap default
page read and write
clean
932000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
580000
unkown image
page read and write
clean
3870000
unkown
page read and write
clean
140000
unkown image
page readonly
clean
535000
unkown
page read and write
clean
22FE000
stack
page read and write
clean
38F0000
unkown
page read and write
clean
36A000
unkown
page execute and read and write
clean
40000
unkown image
page readonly
clean
370000
unkown
page read and write
clean
370000
unkown
page read and write
clean
5CDC000
unkown
page read and write
clean
4A56000
unkown
page read and write
clean
49E7000
unkown
page read and write
clean
5CE8000
unkown
page read and write
clean
36F1000
unkown
page read and write
clean
31F000
heap default
page read and write
clean
3E0000
unkown
page read and write
clean
530000
unkown
page read and write
clean
150000
unkown image
page read and write
clean
2B0000
unkown
page read and write
clean
22EF000
stack
page read and write
clean
20000
unkown image
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
21AF000
stack
page read and write
clean
6B1000
unkown
page read and write
clean
530000
unkown
page read and write
clean
5A73000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
920000
unkown
page execute and read and write
clean
4630000
unkown image
page readonly
clean
242F000
stack
page read and write
clean
1DB000
unkown
page execute and read and write
clean
E0000
unkown image
page readonly
clean
A10000
heap private
page execute and read and write
clean
6355000
unkown
page read and write
clean
A42000
unkown image
page execute read
clean
7EFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
37B0000
unkown
page read and write
clean
430000
unkown
page execute and read and write
clean
580000
unkown
page read and write
clean
6E8B000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
17B000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
160000
heap private
page read and write
clean
45B000
unkown
page execute and read and write
clean
140000
unkown
page read and write
clean
B80000
unkown image
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7E7000
unkown
page read and write
clean
6830000
unkown
page read and write
clean
90000
unkown image
page readonly
clean
130000
unkown image
page read and write
clean
50000
unkown image
page readonly
clean
E0000
unkown
page read and write
clean
55D0000
unkown image
page readonly
clean
537000
unkown
page read and write
clean
36D0000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
3950000
unkown
page read and write
clean
5DA4000
unkown
page read and write
clean
A0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
AC000
unkown
page read and write
clean
1FD4000
heap private
page read and write
clean
330000
unkown
page read and write
clean
5EF1000
unkown
page read and write
clean
538000
unkown
page read and write
clean
5EFE000
unkown
page read and write
clean
6398000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
830000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
560000
unkown
page read and write
clean
213F000
unkown
page read and write
clean
BB000
unkown
page read and write
clean
6DFC000
unkown
page read and write
clean
350000
unkown image
page readonly
clean
6D0000
heap private
page read and write
clean
5E59000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
960000
unkown image
page readonly
clean
4450000
unkown
page read and write
clean
2464000
heap private
page read and write
clean
20000
unkown image
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
206000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
3E0000
unkown
page read and write
clean
63ED000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
D72000
heap private
page read and write
clean
253F000
stack
page read and write
clean
3F8000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
5FB7000
unkown
page read and write
clean
192000
unkown
page execute and read and write
clean
30000
unkown image
page readonly
clean
38D0000
unkown
page read and write
clean
49A4000
unkown
page read and write
clean
205F000
stack
page read and write
clean
5D3F000
unkown
page read and write
clean
37E7000
unkown
page read and write
clean
5FC5000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
13F000
unkown
page read and write
clean
1A2000
unkown
page execute and read and write
clean
60000
unkown image
page readonly
clean
496000
unkown
page read and write
clean
350000
unkown
page read and write
clean
6313000
unkown
page read and write
clean
580000
unkown
page read and write
clean
6374000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
37D1000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
3810000
unkown
page read and write
clean
304000
heap default
page read and write
clean
5F6C000
unkown
page read and write
clean
536000
unkown
page read and write
clean
5D46000
unkown
page read and write
clean
198000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
2897000
unkown
page read and write
clean
47A0000
heap private
page execute and read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
4BCE000
stack
page read and write
clean
A0000
unkown image
page readonly
clean
5030000
unkown
page read and write
clean
590000
heap private
page execute and read and write
clean
839000
unkown
page read and write
clean
1FD0000
heap private
page read and write
clean
6E0000
unkown image
page readonly
clean
4D0000
heap default
page read and write
clean
990000
unkown
page read and write
clean
2050000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
38A7000
unkown
page read and write
clean
47FD000
unkown
page read and write
clean
3890000
unkown
page read and write
clean
4A2000
unkown
page execute and read and write
clean
3F0000
unkown
page read and write
clean
320000
heap private
page read and write
clean
581E000
stack
page read and write | page guard
clean
AB0000
unkown image
page read and write
clean
550000
unkown image
page read and write
clean
400000
unkown
page execute and read and write
clean
2B2000
unkown
page execute and read and write
clean
4A0000
unkown
page read and write
clean
3850000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
5F74000
unkown
page read and write
clean
3950000
unkown
page read and write
clean
1E7000
unkown
page execute and read and write
clean
7EFC2000
unkown image
page readonly
clean
3950000
unkown
page read and write
clean
362000
unkown
page execute and read and write
clean
50000
unkown image
page readonly
clean
176000
heap default
page read and write
clean
50000
unkown image
page readonly
clean
37D0000
unkown
page read and write
clean
3F0000
unkown
page read and write
clean
2110000
unkown
page read and write
clean
3750000
unkown
page read and write
clean
50BD000
stack
page read and write
clean
4480000
unkown
page read and write
clean
7C0F000
stack
page read and write
clean
5390000
unkown
page read and write
clean
66AE000
stack
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
360000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
26BA000
unkown
page read and write
clean
5FF0000
unkown
page read and write
clean
400000
unkown
page execute and read and write
clean
3491000
unkown
page read and write
clean
400000
unkown
page execute and read and write
clean
784000
heap default
page read and write
clean
1A7000
unkown
page read and write | page guard
clean
1CA000
unkown
page execute and read and write
clean
9B0000
unkown
page read and write
clean
9A0000
unkown image
page readonly
clean
38B0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
6841000
unkown
page read and write
clean
6060000
unkown
page read and write
clean
710000
unkown
page read and write
clean
5D70000
unkown
page read and write
clean
5D17000
unkown
page read and write
clean
AC0000
unkown
page read and write
clean
550000
unkown image
page read and write
clean
1DC000
unkown
page execute and read and write
clean
4E90000
heap private
page read and write
clean
There are 1276 hidden memdumps, click here to show them.