IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Purchase order.doc
Rich Text Format data, unknown version
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\villarzx[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{79E0ADDF-4BCA-42D2-95DC-650BFEE60233}.tmp
Composite Document File V2 Document, Cannot read section info
dropped
malicious
C:\Users\user\AppData\Roaming\villar8681.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{3AC3AA43-F534-4DDB-AF6A-E52603844969}.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{CE200956-F676-4F00-A1C2-2784A0C388FF}.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{E7122D4A-0A99-4D1B-A260-A7FE10FBEC45}.tmp
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Purchase order.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Mon Aug 30 20:08:58 2021, mtime=Mon Aug 30 20:08:58 2021, atime=Wed Oct 27 22:38:18 2021, length=532611, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
dropped
clean
C:\Users\user\Desktop\~$rchase order.doc
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
malicious
C:\Users\user\AppData\Roaming\villar8681.exe
C:\Users\user\AppData\Roaming\villar8681.exe
malicious
C:\Users\user\AppData\Roaming\villar8681.exe
C:\Users\user\AppData\Roaming\villar8681.exe
malicious
C:\Windows\explorer.exe
C:\Windows\Explorer.EXE
malicious
C:\Windows\SysWOW64\raserver.exe
C:\Windows\SysWOW64\raserver.exe
malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
'C:\Program Files\Microsoft Office\Office14\WINWORD.EXE' /Automation -Embedding
clean
C:\Windows\SysWOW64\cmd.exe
/c del 'C:\Users\user\AppData\Roaming\villar8681.exe'
clean

URLs

Name
IP
Malicious
www.filecrev.com/jy0b/
malicious
http://www.filecrev.com/jy0b/?06384Dqp=TyGDJhL/cA+57wfufaZRyMMrQk8uPd2d6NfY81Rsj46bZhOJLXgZ522BupBE7+BqQsP88Q==&ct=Xhh4nL38YNvpj
202.165.66.108
malicious
http://www.charlotte-s-creations.com/jy0b/?06384Dqp=AerW1ym2Fscv67+RpL/0se6tZB+gK2Llczeyi+qylm7PPSapsOoYwZFX50tzMVhi1EMssA==&ct=Xhh4nL38YNvpj
54.156.84.168
malicious
http://binatonezx.tk/villarzx.exe
2.56.59.211
malicious
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://wellformedweb.org/CommentAPI/
unknown
clean
https://contextual.media.net/medianet.php?cid=8CUT39MWR&crid=715624197&size=306x271&https=1
unknown
clean
http://www.iis.fhg.de/audioPA
unknown
clean
https://contextual.media.net/medianet.php?cid=8CUT39MWR&crid=715624197&size=306x271&https=1LMEM
unknown
clean
http://www.mozilla.com0
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
https://www.charlotte-s-creations.com/jy0b/?06384Dqp=AerW1ym2Fscv67
unknown
clean
http://treyresearch.net
unknown
clean
https://contextual.media.net/checksync.php?&vsSync=1&cs=1&hb=1&cv=37&ndec=1&cid=8HBSKZM1Y&prvid=77%2
unknown
clean
http://www.collada.org/2005/11/COLLADASchema9Done
unknown
clean
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://java.sun.com
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://www.piriform.com/ccleanerhttp://www.piriform.com/ccleanerv
unknown
clean
http://investor.msn.com/
unknown
clean
http://www.msn.com/?ocid=iehp
unknown
clean
http://www.msn.com/de-de/?ocid=iehp
unknown
clean
http://www.piriform.com/ccleaner
unknown
clean
http://computername/printers/printername/.printer
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.autoitscript.com/autoit3
unknown
clean
https://support.mozilla.org
unknown
clean
http://servername/isapibackend.dll
unknown
clean
There are 22 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
binatonezx.tk
2.56.59.211
malicious
www.filecrev.com
202.165.66.108
malicious
www.charlotte-s-creations.com
unknown
malicious
www.tapehitsscriptsparty.com
unknown
malicious
caddy-2-4-3-a154c717787f8b4f.elb.us-east-1.amazonaws.com
54.156.84.168
clean

IPs

IP
Domain
Country
Malicious
2.56.59.211
binatonezx.tk
Netherlands
malicious
202.165.66.108
www.filecrev.com
Australia
malicious
54.156.84.168
caddy-2-4-3-a154c717787f8b4f.elb.us-east-1.amazonaws.com
United States
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
>-
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
x?-
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
)b-
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\2F1AF
2F1AF
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Arial Unicode MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Batang
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@BatangChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DFKai-SB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Dotum
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DotumChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@FangSong
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gulim
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GulimChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gungsuh
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GungsuhChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@KaiTi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Malgun Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft JhengHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft YaHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Mincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PGothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PMincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS UI Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@NSimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Agency FB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aharoni
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Algerian
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Andalus
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Angsana New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
AngsanaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aparajita
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arabic Typesetting
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Black
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Narrow
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Rounded MT Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Unicode MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Baskerville Old Face
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Batang
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BatangChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bauhaus 93
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bell MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB Demi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bernard MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Blackadder ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Black
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Poster Compressed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Book Antiqua
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookman Old Style
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookshelf Symbol 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bradley Hand ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Britannic Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Broadway
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Browallia New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BrowalliaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Brush Script MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Californian FB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calisto MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria Math
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Candara
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Castellar
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Centaur
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Schoolbook
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Chiller
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Colonna MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Comic Sans MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Consolas
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Constantia
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cooper Black
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Corbel
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cordia New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
CordiaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Courier New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Curlz MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DaunPenh
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
David
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DFKai-SB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DilleniaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DokChampa
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Dotum
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DotumChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ebrima
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Edwardian Script ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Elephant
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Engravers MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Bold ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Demi ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Light ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Medium ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Estrangelo Edessa
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
EucrosiaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Euphemia
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FangSong
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Felix Titling
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Footlight MT Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Forte
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Book
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi Cond
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Heavy
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium Cond
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FrankRuehl
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FreesiaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Freestyle Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
French Script MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gabriola
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Garamond
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gautami
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Georgia
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gigi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Ext Condensed Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gisha
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gloucester MT Extra Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Old Style
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Stout
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gulim
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GulimChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gungsuh
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GungsuhChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Haettenschweiler
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harlow Solid Italic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harrington
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
High Tower Text
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Impact
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Imprint MT Shadow
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Informal Roman
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
IrisUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Iskoola Pota
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
JasmineUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Jokerman
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Juice ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KaiTi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kalinga
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kartika
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Khmer UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KodchiangUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kokila
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kristen ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kunstler Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lao UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Latha
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Leelawadee
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Levenim MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
LilyUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Bright
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Calligraphy
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Console
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Fax
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Handwriting
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Typewriter
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Unicode
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Magneto
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Maiandra GD
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Malgun Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mangal
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Marlett
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Matura MT Script Capitals
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Himalaya
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft JhengHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft New Tai Lue
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft PhagsPa
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Sans Serif
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Tai Le
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Uighur
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft YaHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Yi Baiti
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam Fixed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mistral
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Modern No. 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mongolian Baiti
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Monotype Corsiva
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MoolBoran
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Mincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Outlook
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PGothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PMincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Sans Serif
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Specialty
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS UI Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MT Extra
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MV Boli
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Narkisim
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Engraved
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Solid
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
NSimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Nyala
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
OCR A Extended
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Old English Text MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Onyx
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palace Script MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palatino Linotype
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Papyrus
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Parchment
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua Titling MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Plantagenet Cherokee
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Playbill
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Poor Richard
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Pristina
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Raavi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rage Italic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ravie
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Extra Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rod
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sakkal Majalla
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Script MT Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Print
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Semibold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Symbol
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shonar Bangla
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Showcard Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shruti
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic Fixed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Snap ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Stencil
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sylfaen
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Symbol
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tahoma
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tempus Sans ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Times New Roman
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Traditional Arabic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Trebuchet MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tunga
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed Extra Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Utsaah
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vani
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Verdana
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vijaya
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Viner Hand ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vivaldi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vladimir Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vrinda
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Webdings
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wide Latin
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\38C86
38C86
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
WORDFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\38C86
38C86
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Data
Settings
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Options
ZoomApp
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTF
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTA
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
EquationEditorFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus
FontCachePath
clean
There are 314 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
80000
unkown image
page execute and read and write
malicious
24D1000
unkown
page read and write
malicious
80000
unkown image
page execute and read and write
malicious
90FF000
unkown image
page execute and read and write
malicious
5D0000
unkown image
page execute and read and write
malicious
400000
unkown
page execute and read and write
malicious
1A0000
unkown image
page execute and read and write
malicious
90FF000
unkown image
page execute and read and write
malicious
34D9000
unkown
page read and write
malicious
400000
unkown
page execute and read and write
malicious
2F0000
unkown
page read and write
malicious
400000
unkown
page execute and read and write
malicious
7FFFFFB0000
unkown image
page readonly
clean
27A0000
unkown image
page readonly
clean
4308000
unkown
page read and write
clean
2500000
unkown image
page readonly
clean
6BA0000
unkown
page read and write
clean
430000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
8420000
unkown
page read and write
clean
2F20000
unkown
page read and write
clean
7125000
unkown
page read and write
clean
74B4000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
556F000
unkown
page read and write
clean
6C37000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
3CA0000
unkown
page read and write
clean
67B3000
unkown
page read and write
clean
30A8000
unkown
page read and write
clean
32A0000
heap private
page read and write
clean
6B34000
unkown
page read and write
clean
59A000
heap default
page read and write
clean
4D40000
unkown image
page readonly
clean
20D1000
unkown
page read and write
clean
709E000
unkown
page read and write
clean
E4000
heap private
page read and write
clean
6D40000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
6C3E000
unkown
page read and write
clean
370000
unkown
page read and write
clean
8BB8000
unkown
page read and write
clean
560E000
stack
page read and write
clean
2740000
unkown image
page readonly
clean
3270000
unkown
page read and write
clean
69D9000
unkown
page read and write
clean
1040000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
4D80000
unkown image
page readonly
clean
1B65000
heap private
page read and write
clean
F0000
unkown image
page read and write
clean
2A80000
unkown
page read and write
clean
7122000
unkown
page read and write
clean
E0000
heap private
page read and write
clean
237000
heap default
page read and write
clean
2A40000
unkown
page read and write
clean
4D20000
unkown
page execute and read and write
clean
54E2000
unkown
page read and write
clean
371000
unkown
page read and write
clean
6CB8000
unkown
page read and write
clean
2A50000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7D0000
unkown
page read and write
clean
2A30000
unkown
page read and write
clean
4593000
unkown
page read and write
clean
2A50000
unkown
page read and write
clean
1040000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
7C1000
unkown
page read and write
clean
9840000
unkown
page read and write
clean
7530000
unkown
page read and write
clean
4C7A000
heap private
page read and write
clean
31D000
heap default
page read and write
clean
2760000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
9983000
unkown
page read and write
clean
5E2E000
stack
page read and write
clean
7EFD0000
unkown image
page readonly
clean
350000
unkown
page read and write
clean
29B000
unkown
page execute and read and write
clean
70B4000
unkown
page read and write
clean
30F0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
2AD0000
unkown
page read and write
clean
744D000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
460B000
unkown
page read and write
clean
7BD0000
heap private
page read and write
clean
7D0000
unkown
page read and write
clean
4300000
unkown
page read and write
clean
43A0000
unkown image
page readonly
clean
ED0000
unkown
page read and write
clean
6DDC000
unkown
page read and write
clean
6C23000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
36B000
unkown
page read and write
clean
7CFE000
unkown
page read and write
clean
6CBE000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7B50000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
32AE000
heap private
page read and write
clean
45BF000
unkown
page read and write
clean
5C0000
unkown image
page readonly
clean
2500000
unkown image
page readonly
clean
2C7000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
2EC1000
unkown
page read and write
clean
6EAC000
unkown
page read and write
clean
1FD0000
unkown image
page readonly
clean
75EF000
unkown
page read and write
clean
449C000
unkown
page read and write
clean
532E000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
8320000
unkown
page read and write
clean
28A000
unkown
page execute and read and write
clean
7EFC0000
unkown image
page readonly
clean
54B2000
unkown
page read and write
clean
32D000
unkown
page read and write
clean
6B6F000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
6B99000
unkown
page read and write
clean
5C0000
unkown image
page readonly
clean
C50000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
960000
unkown
page execute and read and write
clean
7C7000
unkown
page read and write
clean
541D000
unkown
page read and write
clean
2A10000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
4AC0000
unkown
page read and write
clean
4C70000
heap private
page read and write
clean
7065000
unkown
page read and write
clean
190000
unkown
page read and write
clean
1D0000
unkown
page read and write
clean
9803000
unkown
page read and write
clean
43A0000
unkown image
page readonly
clean
3DF8000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
E0000
heap private
page read and write
clean
36F000
unkown
page read and write
clean
6F4000
heap private
page read and write
clean
45CB000
unkown
page read and write
clean
9903000
unkown
page read and write
clean
45CF000
unkown
page read and write
clean
45A1000
unkown
page read and write
clean
1040000
unkown image
page readonly
clean
2A20000
unkown
page read and write
clean
370000
unkown
page read and write
clean
58A0000
unkown
page read and write
clean
3278000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
4BB0000
heap private
page read and write
clean
2A40000
unkown
page read and write
clean
729A000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
8448000
unkown
page read and write
clean
212B000
unkown image
page read and write
clean
209E000
stack
page read and write
clean
310000
heap private
page read and write
clean
54A4000
unkown
page read and write
clean
43B0000
heap private
page read and write
clean
45B4000
unkown
page read and write
clean
31D000
heap default
page read and write
clean
263C000
unkown
page read and write
clean
430000
unkown image
page readonly
clean
6E0000
unkown
page read and write
clean
1FD0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
6A4A000
unkown
page read and write
clean
4B9D000
unkown
page read and write
clean
733A000
unkown
page read and write
clean
71D8000
unkown
page read and write
clean
266F000
unkown image
page read and write
clean
2E0000
unkown
page read and write
clean
728E000
unkown
page read and write
clean
1B65000
heap private
page read and write
clean
32A0000
heap private
page read and write
clean
263C000
unkown
page read and write
clean
800000
unkown image
page readonly
clean
2267000
unkown
page execute and read and write
clean
9783000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
6B8C000
unkown
page read and write
clean
5B5F000
stack
page read and write
clean
1F5D000
unkown
page read and write
clean
6C1A000
unkown
page read and write
clean
69F5000
unkown
page read and write
clean
237000
heap default
page read and write
clean
4450000
unkown
page read and write
clean
2740000
unkown image
page readonly
clean
DEC000
stack
page read and write
clean
7EFB2000
unkown image
page readonly
clean
4D70000
unkown image
page readonly
clean
4B9D000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7259000
unkown
page read and write
clean
3298000
unkown
page read and write
clean
474000
heap default
page read and write
clean
8438000
unkown
page read and write
clean
640000
unkown image
page readonly
clean
57ED000
unkown
page read and write
clean
220000
unkown image
page readonly
clean
2550000
unkown
page read and write
clean
2C7000
heap default
page read and write
clean
380000
heap default
page read and write
clean
712000
heap private
page read and write
clean
21BF000
unkown
page read and write
clean
30F0000
unkown image
page readonly
clean
6E50000
heap private
page read and write
clean
2F10000
unkown
page read and write
clean
2AB0000
unkown
page read and write
clean
520000
unkown
page read and write
clean
729A000
unkown
page read and write
clean
449C000
unkown
page read and write
clean
54F6000
unkown
page read and write
clean
1FD0000
unkown image
page readonly
clean
913C000
unkown image
page execute and read and write
clean
7B40000
unkown
page read and write
clean
5B0000
unkown image
page readonly
clean
4AC0000
unkown
page read and write
clean
846B000
unkown
page read and write
clean
31D000
heap default
page read and write
clean
4D20000
unkown
page execute and read and write
clean
400000
unkown
page execute and read and write
clean
74B0000
heap private
page read and write
clean
630000
heap private
page read and write
clean
6D0F000
unkown
page read and write
clean
2500000
unkown image
page readonly
clean
4D60000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
301E000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
20000
unkown image
page read and write
clean
8720000
unkown
page read and write
clean
6CCC000
unkown
page read and write
clean
2A40000
unkown
page read and write
clean
4AAC000
unkown
page read and write
clean
2A00000
unkown
page read and write
clean
243000
heap default
page read and write
clean
10C4000
unkown image
page readonly
clean
300000
unkown image
page readonly
clean
1042000
unkown image
page execute read
clean
1040000
unkown image
page readonly
clean
36B000
unkown
page read and write
clean
34E000
unkown
page read and write
clean
532E000
unkown
page read and write
clean
44E7000
unkown
page read and write
clean
83A8000
unkown
page read and write
clean
6E50000
heap private
page read and write
clean
470000
heap default
page read and write
clean
30A8000
unkown
page read and write
clean
243000
heap default
page read and write
clean
6A59000
unkown
page read and write
clean
3D50000
unkown
page read and write
clean
457A000
unkown
page read and write
clean
90C0000
unkown image
page execute and read and write
clean
6F71000
unkown
page read and write
clean
6D48000
unkown
page read and write
clean
23D0000
unkown
page execute and read and write
clean
50000
unkown image
page readonly
clean
6CB0000
unkown
page read and write
clean
4D30000
unkown image
page readonly
clean
7C0000
unkown image
page readonly
clean
10C4000
unkown image
page readonly
clean
7295000
unkown
page read and write
clean
2AD0000
unkown
page read and write
clean
371000
unkown
page read and write
clean
24A000
heap default
page read and write
clean
59EF000
stack
page read and write
clean
211B000
unkown image
page read and write
clean
6D05000
unkown
page read and write
clean
530000
unkown
page read and write
clean
7B0000
unkown
page read and write
clean
70EB000
unkown
page read and write
clean
4DD0000
heap private
page read and write
clean
7159000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
6A83000
unkown
page read and write
clean
8355000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
4D60000
unkown image
page readonly
clean
77AE000
unkown
page read and write
clean
6E68000
unkown
page read and write
clean
1040000
unkown image
page readonly
clean
73B9000
unkown
page read and write
clean
2CC7000
unkown image
page readonly
clean
43B0000
heap private
page read and write
clean
7D20000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
59F000
unkown
page read and write
clean
6C6D000
unkown
page read and write
clean
43B0000
heap private
page read and write
clean
579E000
stack
page read and write
clean
69FA000
unkown
page read and write
clean
2A10000
unkown
page read and write
clean
6F39000
unkown
page read and write
clean
20DA000
unkown
page read and write
clean
2A20000
unkown
page read and write
clean
207D000
unkown
page read and write
clean
6CC0000
unkown
page read and write
clean
6CC7000
unkown
page read and write
clean
679F000
unkown
page read and write
clean
22E0000
unkown
page execute and read and write
clean
AC0000
unkown
page execute and read and write
clean
4B00000
unkown image
page readonly
clean
2D0000
unkown
page execute and read and write
clean
711D000
unkown
page read and write
clean
9940000
unkown
page read and write
clean
2980000
unkown
page read and write
clean
480000
heap default
page read and write
clean
2A80000
unkown
page read and write
clean
B7C000
stack
page read and write
clean
7176000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
8430000
unkown
page read and write
clean
2A70000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
F0000
unkown image
page read and write
clean
7EFE0000
unkown image
page readonly
clean
91DE000
unkown
page read and write
clean
6ABA000
unkown
page read and write
clean
A80000
unkown image
page readonly
clean
3C90000
unkown image
page read and write
clean
23D000
heap default
page read and write
clean
7EFB0000
unkown image
page readonly
clean
24F0000
unkown image
page readonly
clean
456F000
unkown
page read and write
clean
6731000
unkown
page read and write
clean
636000
heap private
page read and write
clean
7053000
unkown
page read and write
clean
DA0000
unkown
page read and write
clean
70E0000
unkown
page read and write
clean
32A5000
heap private
page read and write
clean
594000
unkown
page read and write
clean
8355000
unkown
page read and write
clean
712D000
unkown
page read and write
clean
45BF000
unkown
page read and write
clean
72D5000
unkown
page read and write
clean
220000
unkown image
page readonly
clean
74D3000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
1BE0000
unkown image
page readonly
clean
744D000
unkown
page read and write
clean
546C000
unkown
page read and write
clean
699F000
unkown
page read and write
clean
2110000
unkown image
page read and write
clean
1CE000
unkown
page read and write
clean
4D50000
unkown image
page readonly
clean
202D000
stack
page read and write
clean
9940000
unkown
page read and write
clean
7F0E000
unkown
page read and write
clean
6801000
unkown
page read and write
clean
447A000
unkown
page read and write
clean
6A52000
unkown
page read and write
clean
3E50000
unkown image
page readonly
clean
957000
unkown
page execute and read and write
clean
4650000
unkown image
page readonly
clean
2FC000
unkown
page read and write
clean
556E000
stack
page read and write
clean
4150000
unkown image
page readonly
clean
2130000
unkown image
page read and write
clean
1250000
unkown image
page readonly
clean
8420000
unkown
page read and write
clean
45CB000
unkown
page read and write
clean
4150000
unkown image
page readonly
clean
3D90000
unkown
page read and write
clean
4B9D000
unkown
page read and write
clean
8430000
unkown
page read and write
clean
430000
unkown
page execute and read and write
clean
6A57000
unkown
page read and write
clean
7B4B000
unkown
page read and write
clean
3D90000
unkown
page read and write
clean
5487000
unkown
page read and write
clean
688000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
6BA7000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
30E0000
unkown image
page readonly
clean
9840000
unkown
page read and write
clean
1E0000
unkown
page read and write
clean
D0000
unkown image
page readonly
clean
54E2000
unkown
page read and write
clean
5410000
heap private
page read and write
clean
8720000
unkown
page read and write
clean
31FF000
unkown
page read and write
clean
24F0000
unkown image
page readonly
clean
30C0000
unkown
page read and write
clean
79F0000
heap private
page read and write
clean
6AB6000
unkown
page read and write
clean
4150000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
6C6A000
unkown
page read and write
clean
36B000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2AC0000
unkown
page read and write
clean
1040000
unkown image
page readonly
clean
2A90000
unkown
page read and write
clean
4BB0000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
681E000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
834B000
unkown
page read and write
clean
230000
heap default
page read and write
clean
5C0000
unkown image
page readonly
clean
5360000
unkown image
page read and write
clean
54E2000
unkown
page read and write
clean
4DB1000
unkown image
page read and write
clean
77AE000
unkown
page read and write
clean
7B50000
heap private
page read and write
clean
4D20000
unkown
page execute and read and write
clean
4150000
unkown image
page readonly
clean
211B000
unkown image
page read and write
clean
7E0000
unkown
page read and write
clean
2A00000
unkown
page read and write
clean
45CB000
unkown
page read and write
clean
43A0000
unkown image
page readonly
clean
2750000
unkown
page read and write
clean
674B000
unkown
page read and write
clean
32AE000
heap private
page read and write
clean
94C3000
heap private
page read and write
clean
750000
unkown image
page readonly
clean
1D0000
unkown
page read and write
clean
F0000
unkown image
page read and write
clean
456F000
unkown
page read and write
clean
2460000
unkown
page execute and read and write
clean
5468000
unkown
page read and write
clean
10D0000
unkown image
page readonly
clean
8374000
unkown
page read and write
clean
4440000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
264000
unkown
page read and write
clean
7839000
unkown
page read and write
clean
3298000
unkown
page read and write
clean
30E0000
unkown image
page readonly
clean
2AC0000
unkown
page read and write
clean
7839000
unkown
page read and write
clean
4AC0000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
D2F000
stack
page read and write
clean
40000
unkown image
page readonly
clean
94A0000
heap private
page read and write
clean
67EE000
unkown
page read and write
clean
8444000
unkown
page read and write
clean
4430000
unkown image
page readonly
clean
6EDE000
unkown
page read and write
clean
7150000
unkown
page read and write
clean
7CFE000
unkown
page read and write
clean
32AE000
heap private
page read and write
clean
4430000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
4575000
unkown
page read and write
clean
590000
heap default
page read and write
clean
6CAE000
unkown
page read and write
clean
47F000
unkown
page read and write
clean
6CB8000
unkown
page read and write
clean
4D40000
unkown image
page readonly
clean
7B40000
unkown
page read and write
clean
301E000
unkown
page read and write
clean
4DD0000
heap private
page read and write
clean
45CF000
unkown
page read and write
clean
1CE000
unkown
page read and write
clean
110000
unkown
page read and write
clean
6B0000
unkown
page read and write
clean
3C90000
unkown image
page read and write
clean
20D4000
unkown
page read and write
clean
6C80000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
1F20000
unkown
page execute and read and write
clean
4513000
unkown
page read and write
clean
4E20000
unkown
page read and write
clean
1D60000
unkown image
page readonly
clean
4DB1000
unkown image
page read and write
clean
6AB0000
unkown
page read and write
clean
43B0000
heap private
page read and write
clean
2740000
unkown image
page readonly
clean
2760000
unkown image
page readonly
clean
2AB0000
unkown
page read and write
clean
3E0000
heap private
page read and write
clean
6C7E000
unkown
page read and write
clean
2550000
unkown
page read and write
clean
7150000
unkown
page read and write
clean
3CA0000
unkown
page read and write
clean
7F0000
heap private
page read and write
clean
21E000
stack
page read and write
clean
7EFB2000
unkown image
page readonly
clean
370000
heap private
page read and write
clean
60000
unkown image
page readonly
clean
8374000
unkown
page read and write
clean
1260000
unkown image
page readonly
clean
2A70000
unkown
page read and write
clean
E0000
heap private
page read and write
clean
371000
unkown
page read and write
clean
3270000
unkown
page read and write
clean
733A000
unkown
page read and write
clean
1042000
unkown image
page execute read
clean
7EFC0000
unkown image
page readonly
clean
2A10000
unkown
page read and write
clean
5390000
heap private
page read and write
clean
6AE5000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
940000
unkown
page execute and read and write
clean
50A000
unkown
page read and write
clean
6C77000
unkown
page read and write
clean
7F9000
heap private
page read and write
clean
AD7000
unkown
page execute and read and write
clean
7072000
unkown
page read and write
clean
751A000
unkown
page read and write
clean
45BF000
unkown
page read and write
clean
30000
unkown image
page read and write
clean
3C90000
unkown image
page read and write
clean
47E000
unkown
page read and write
clean
728E000
unkown
page read and write
clean
C0000
heap default
page read and write
clean
60000
unkown image
page readonly
clean
63D000
heap default
page read and write
clean
7EFD0000
unkown image
page readonly
clean
4F20000
heap private
page execute and read and write
clean
3D40000
unkown
page read and write
clean
7570000
unkown
page read and write
clean
7BD0000
heap private
page read and write
clean
71D8000
unkown
page read and write
clean
2140000
unkown
page read and write
clean
15C000
unkown
page read and write
clean
954000
unkown
page execute and read and write
clean
6A60000
heap private
page read and write
clean
2533000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
211B000
unkown image
page read and write
clean
1042000
unkown image
page execute read
clean
567000
heap default
page read and write
clean
1B60000
heap private
page read and write
clean
6A59000
unkown
page read and write
clean
292F000
unkown
page read and write
clean
27E0000
unkown
page read and write
clean
9840000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
5360000
unkown image
page read and write
clean
913C000
unkown image
page execute and read and write
clean
29B000
heap default
page read and write
clean
8374000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
25C3000
unkown
page read and write
clean
6A52000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
1FD0000
unkown
page read and write
clean
249000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
530000
unkown
page read and write
clean
936F000
unkown
page read and write
clean
1040000
unkown image
page readonly
clean
230000
heap default
page read and write
clean
6A50000
unkown
page read and write
clean
457A000
unkown
page read and write
clean
27A0000
unkown image
page readonly
clean
699E000
unkown
page read and write
clean
330000
unkown
page read and write
clean
556F000
unkown
page read and write
clean
309E000
unkown
page read and write
clean
570000
unkown
page read and write
clean
20DA000
unkown
page read and write
clean
360000
unkown
page read and write
clean
212B000
unkown image
page read and write
clean
31D000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
36B000
unkown
page read and write
clean
711A000
unkown
page read and write
clean
243000
heap default
page read and write
clean
5270000
unkown
page execute read
clean
5D0000
heap default
page read and write
clean
6C61000
unkown
page read and write
clean
7163000
unkown
page read and write
clean
1E0000
unkown
page read and write
clean
460B000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
4E60000
unkown
page read and write
clean
4C7A000
heap private
page read and write
clean
430000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
7B40000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
6E27000
unkown
page read and write
clean
2A60000
unkown
page read and write
clean
73B9000
unkown
page read and write
clean
6A57000
unkown
page read and write
clean
4308000
unkown
page read and write
clean
4D70000
unkown image
page readonly
clean
6A60000
heap private
page read and write
clean
8448000
unkown
page read and write
clean
D90000
unkown
page read and write
clean
3298000
unkown
page read and write
clean
32A5000
heap private
page read and write
clean
2540000
unkown
page read and write
clean
6787000
unkown
page read and write
clean
230000
heap default
page read and write
clean
2533000
unkown
page read and write
clean
2AE0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
91DE000
unkown
page read and write
clean
9884000
unkown
page read and write
clean
45A1000
unkown
page read and write
clean
9884000
unkown
page read and write
clean
4AAC000
unkown
page read and write
clean
2100000
unkown image
page readonly
clean
6A1C000
unkown
page read and write
clean
2980000
unkown
page read and write
clean
3270000
unkown
page read and write
clean
6D69000
unkown
page read and write
clean
5B0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
936F000
unkown
page read and write
clean
1B60000
heap private
page read and write
clean
2943000
unkown
page read and write
clean
2A70000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7159000
unkown
page read and write
clean
2110000
unkown image
page read and write
clean
2740000
unkown image
page readonly
clean
255000
heap default
page read and write
clean
7D0000
unkown image
page readonly
clean
320000
unkown
page read and write
clean
6BBE000
unkown
page read and write
clean
213B000
unkown image
page read and write
clean
6C26000
unkown
page read and write
clean
3C90000
unkown image
page read and write
clean
7839000
unkown
page read and write
clean
67AE000
unkown
page read and write
clean
9803000
unkown
page read and write
clean
255000
heap default
page read and write
clean
2943000
unkown
page read and write
clean
740000
unkown image
page execute and read and write
clean
1D0000
unkown
page read and write
clean
220000
unkown image
page readonly
clean
4AF0000
unkown image
page readonly
clean
2170000
unkown
page execute and read and write
clean
4450000
unkown
page read and write
clean
4E5E000
unkown
page read and write
clean
212B000
unkown image
page read and write
clean
7EFD0000
unkown image
page readonly
clean
556F000
unkown
page read and write
clean
4575000
unkown
page read and write
clean
22F0000
unkown
page execute and read and write
clean
30D0000
unkown image
page readonly
clean
4A2F000
stack
page read and write
clean
34D1000
unkown
page read and write
clean
4160000
unkown
page read and write
clean
270000
unkown
page read and write
clean
64D000
unkown
page read and write
clean
81AE000
unkown
page read and write
clean
510000
unkown
page read and write
clean
6B4C000
unkown
page read and write
clean
6AE0000
unkown
page read and write
clean
560000
heap default
page read and write
clean
255000
heap default
page read and write
clean
1042000
unkown image
page execute read
clean
32A5000
heap private
page read and write
clean
1CE000
unkown
page read and write
clean
1E80000
unkown
page execute and read and write
clean
4308000
unkown
page read and write
clean
36F000
unkown
page read and write
clean
6D40000
unkown
page read and write
clean
7581000
unkown
page read and write
clean
6A0000
unkown
page read and write
clean
74B0000
heap private
page read and write
clean
1D0000
unkown
page read and write
clean
8444000
unkown
page read and write
clean
309E000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
4445000
heap private
page read and write
clean
60000
unkown image
page readonly
clean
94A5000
heap private
page read and write
clean
81AE000
unkown
page read and write
clean
2CC7000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
213B000
unkown image
page read and write
clean
4C7A000
heap private
page read and write
clean
58A7000
unkown
page read and write
clean
3298000
unkown
page read and write
clean
31FF000
unkown
page read and write
clean
21BF000
unkown
page read and write
clean
330000
unkown
page read and write
clean
4445000
heap private
page read and write
clean
1B50000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
6C3B000
unkown
page read and write
clean
2540000
unkown
page read and write
clean
23E1000
unkown
page execute and read and write
clean
5360000
unkown image
page read and write
clean
2A80000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
9E0000
unkown
page execute and read and write
clean
7EFB0000
unkown image
page readonly
clean
3278000
unkown
page read and write
clean
6CC5000
unkown
page read and write
clean
2760000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
54C6000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
694F000
unkown
page read and write
clean
457000
heap default
page read and write
clean
6E0000
unkown
page read and write
clean
6E50000
heap private
page read and write
clean
2943000
unkown
page read and write
clean
45CF000
unkown
page read and write
clean
45CF000
unkown
page read and write
clean
380000
unkown
page read and write
clean
4AF0000
unkown image
page readonly
clean
449C000
unkown
page read and write
clean
2C7000
heap default
page read and write
clean
91DE000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
2100000
unkown image
page readonly
clean
4650000
unkown image
page readonly
clean
729A000
unkown
page read and write
clean
782F000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
4D30000
unkown image
page readonly
clean
AD1000
unkown
page execute and read and write
clean
249000
heap default
page read and write
clean
350000
unkown image
page read and write
clean
71D0000
unkown
page read and write
clean
4D70000
unkown image
page readonly
clean
4DC0000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
9803000
unkown
page read and write
clean
2C7000
heap default
page read and write
clean
728E000
unkown
page read and write
clean
F8F000
stack
page read and write
clean
7EFE0000
unkown image
page readonly
clean
1BE0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
2CC7000
unkown image
page readonly
clean
3D4B000
unkown
page read and write
clean
8407000
unkown
page read and write
clean
6A22000
unkown
page read and write
clean
31FF000
unkown
page read and write
clean
7C4000
unkown
page read and write
clean
550000
heap private
page execute and read and write
clean
7BD0000
heap private
page read and write
clean
4440000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
34E000
unkown
page read and write
clean
2EC1000
unkown
page read and write
clean
30F0000
unkown image
page readonly
clean
27E0000
unkown
page read and write
clean
2692000
unkown image
page read and write
clean
540000
unkown
page read and write
clean
73B9000
unkown
page read and write
clean
3CC0000
unkown image
page readonly
clean
7BC6000
unkown
page read and write
clean
22D0000
unkown
page execute and read and write
clean
60000
unkown image
page readonly
clean
6A31000
unkown
page read and write
clean
17C000
unkown
page read and write
clean
4B9D000
unkown
page read and write
clean
292000
unkown
page read and write
clean
59F000
unkown
page read and write
clean
2750000
unkown
page read and write
clean
F0000
unkown image
page read and write
clean
D70000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
9903000
unkown
page read and write
clean
699F000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
10C4000
unkown image
page readonly
clean
4C70000
heap private
page read and write
clean
E4000
heap private
page read and write
clean
46F000
stack
page read and write
clean
7EFC0000
unkown image
page readonly
clean
6CAC000
unkown
page read and write
clean
94A5000
heap private
page read and write
clean
3DF8000
unkown
page read and write
clean
E10000
heap private
page execute and read and write
clean
7BE7000
unkown
page read and write
clean
4E60000
unkown
page read and write
clean
4513000
unkown
page read and write
clean
2F10000
unkown
page read and write
clean
1D7000
unkown
page read and write
clean
E00000
unkown
page read and write
clean
24F0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
74B0000
heap private
page read and write
clean
4430000
unkown image
page readonly
clean
6A1A000
unkown
page read and write
clean
32A9000
heap private
page read and write
clean
4AC0000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
2AE0000
unkown image
page readonly
clean
2110000
unkown image
page read and write
clean
449C000
unkown
page read and write
clean
6A4F000
unkown
page read and write
clean
3D40000
unkown
page read and write
clean
8720000
unkown
page read and write
clean
750000
unkown image
page readonly
clean
2A20000
unkown
page read and write
clean
834B000
unkown
page read and write
clean
4DC0000
unkown
page read and write
clean
1D0000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
6E18000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
69A6000
unkown
page read and write
clean
292F000
unkown
page read and write
clean
760000
unkown image
page readonly
clean
54B2000
unkown
page read and write
clean
5DD000
heap default
page read and write
clean
29B000
heap default
page read and write
clean
4AF0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
91C0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
30C0000
unkown
page read and write
clean
8F0000
unkown image
page readonly
clean
70B6000
unkown
page read and write
clean
B30000
unkown
page read and write
clean
980000
unkown image
page readonly
clean
457A000
unkown
page read and write
clean
705E000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7150000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
5010000
unkown image
page readonly
clean
BDE000
stack
page read and write
clean
B80000
unkown
page read and write
clean
AD4000
unkown
page execute and read and write
clean
7B4B000
unkown
page read and write
clean
2A40000
unkown
page read and write
clean
3CC0000
unkown image
page readonly
clean
68CE000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
2A60000
unkown
page read and write
clean
255000
heap default
page read and write
clean
237000
heap default
page read and write
clean
7B50000
heap private
page read and write
clean
4E5E000
unkown
page read and write
clean
91C0000
unkown
page read and write
clean
243000
heap default
page read and write
clean
23E4000
unkown
page execute and read and write
clean
10C4000
unkown image
page readonly
clean
74F4000
unkown
page read and write
clean
6BBE000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
750000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
71D0000
unkown
page read and write
clean
6E50000
heap private
page read and write
clean
6A4F000
unkown
page read and write
clean
4160000
unkown
page read and write
clean
6D5A000
unkown
page read and write
clean
500000
unkown
page read and write
clean
1D7000
unkown
page read and write
clean
20000
unkown
page read and write
clean
2A50000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
4BB0000
heap private
page read and write
clean
71D0000
unkown
page read and write
clean
1040000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
27D000
unkown
page execute and read and write
clean
690000
unkown
page read and write
clean
2AB0000
unkown
page read and write
clean
5270000
unkown
page execute read
clean
8355000
unkown
page read and write
clean
6CB8000
unkown
page read and write
clean
2AC0000
unkown
page read and write
clean
6A57000
unkown
page read and write
clean
100000
unkown
page read and write
clean
3D50000
unkown
page read and write
clean
3D40000
unkown
page read and write
clean
2646000
unkown
page read and write
clean
300000
unkown image
page execute and read and write
clean
687E000
unkown
page read and write
clean
2A30000
unkown
page read and write
clean
4D50000
unkown image
page readonly
clean
1B83000
heap private
page read and write
clean
4D70000
unkown image
page readonly
clean
479000
unkown
page read and write
clean
32A9000
heap private
page read and write
clean
74B4000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
2F20000
unkown
page read and write
clean
3CA0000
unkown
page read and write
clean
30A8000
unkown
page read and write
clean
456F000
unkown
page read and write
clean
2750000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
450000
heap default
page read and write
clean
60000
unkown image
page readonly
clean
24F0000
unkown image
page readonly
clean
23D000
heap default
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7B4B000
unkown
page read and write
clean
7161000
unkown
page read and write
clean
20B6000
unkown
page read and write
clean
1B60000
heap private
page read and write
clean
2270000
unkown
page execute and read and write
clean
2AD0000
unkown
page read and write
clean
4513000
unkown
page read and write
clean
3D4B000
unkown
page read and write
clean
2AD0000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
228000
unkown
page read and write
clean
30C0000
unkown
page read and write
clean
4160000
unkown
page read and write
clean
596000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
4DB1000
unkown image
page read and write
clean
3DF8000
unkown
page read and write
clean
6DAE000
unkown
page read and write
clean
6A85000
unkown
page read and write
clean
2A00000
unkown
page read and write
clean
2264000
unkown
page execute and read and write
clean
3270000
unkown
page read and write
clean
1B65000
heap private
page read and write
clean
7EFDF000
unkown
page read and write
clean
4650000
unkown image
page readonly
clean
1D7000
unkown
page read and write
clean
330000
unkown
page read and write
clean
2A60000
unkown
page read and write
clean
170000
unkown
page read and write
clean
5B0000
unkown image
page readonly
clean
2250000
unkown
page execute and read and write
clean
D80000
unkown
page read and write
clean
21BF000
unkown
page read and write
clean
30F0000
unkown image
page readonly
clean
6A25000
unkown
page read and write
clean
1D7000
unkown
page read and write
clean
494000
heap default
page read and write
clean
29B000
heap default
page read and write
clean
10C4000
unkown image
page readonly
clean
546C000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
2450000
unkown
page execute and read and write
clean
4575000
unkown
page read and write
clean
7E1E000
unkown
page read and write
clean
5270000
unkown
page execute read
clean
6C85000
unkown
page read and write
clean
32A0000
heap private
page read and write
clean
2120000
unkown image
page read and write
clean
94C3000
heap private
page read and write
clean
4D80000
unkown image
page readonly
clean
68D0000
unkown
page read and write
clean
4513000
unkown
page read and write
clean
30C0000
unkown
page read and write
clean
E4000
heap private
page read and write
clean
54C6000
unkown
page read and write
clean
32A0000
heap private
page read and write
clean
43A0000
unkown image
page readonly
clean
8320000
unkown
page read and write
clean
2980000
unkown
page read and write
clean
B90000
unkown
page read and write
clean
36F000
unkown
page read and write
clean
1040000
unkown image
page readonly
clean
70D8000
unkown
page read and write
clean
3CA0000
unkown
page read and write
clean
2F20000
unkown
page read and write
clean
2750000
unkown
page read and write
clean
79F0000
heap private
page read and write
clean
68E000
stack
page read and write
clean
6A57000
unkown
page read and write
clean
D79000
unkown
page read and write
clean
7074000
unkown
page read and write
clean
7159000
unkown
page read and write
clean
20B6000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
DF0000
unkown
page read and write
clean
29B000
heap default
page read and write
clean
55CC000
heap private
page read and write
clean
4E60000
unkown
page read and write
clean
6E98000
unkown
page read and write
clean
309E000
unkown
page read and write
clean
73BB000
unkown
page read and write
clean
5390000
heap private
page read and write
clean
8320000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
50000
unkown image
page readonly
clean
3D4B000
unkown
page read and write
clean
220000
unkown image
page readonly
clean
97C2000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
390000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
1B83000
heap private
page read and write
clean
5468000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
20B6000
unkown
page read and write
clean
5410000
heap private
page read and write
clean
69A6000
unkown
page read and write
clean
20C0000
unkown
page read and write
clean
97C2000
unkown
page read and write
clean
447A000
unkown
page read and write
clean
2646000
unkown
page read and write
clean
32AE000
heap private
page read and write
clean
1D0000
unkown
page read and write
clean
2F6000
unkown
page read and write
clean
7330000
unkown
page read and write
clean
212B000
unkown image
page read and write
clean
4D20000
unkown
page execute and read and write
clean
20E0000
unkown
page read and write
clean
6D48000
unkown
page read and write
clean
10C4000
unkown image
page readonly
clean
20DA000
unkown
page read and write
clean
10C4000
unkown image
page readonly
clean
4E5E000
unkown
page read and write
clean
6D30000
unkown
page read and write
clean
556F000
unkown
page read and write
clean
45BF000
unkown
page read and write
clean
447A000
unkown
page read and write
clean
3DF8000
unkown
page read and write
clean
4308000
unkown
page read and write
clean
950000
unkown
page execute and read and write
clean
4DC0000
unkown
page read and write
clean
2130000
unkown image
page read and write
clean
10C4000
unkown image
page readonly
clean
728E000
unkown
page read and write
clean
BA000
unkown
page read and write
clean
140000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
34E000
unkown
page read and write
clean
7E1E000
unkown
page read and write
clean
6BA2000
unkown
page read and write
clean
2520000
unkown
page read and write
clean
20000
unkown
page read and write
clean
5000000
heap private
page read and write
clean
3278000
unkown
page read and write
clean
7D9000
unkown
page read and write
clean
3278000
unkown
page read and write
clean
64A000
unkown
page read and write
clean
4DC0000
unkown
page read and write
clean
7DF000
stack
page read and write
clean
7EFB0000
unkown image
page readonly
clean
6A60000
heap private
page read and write
clean
2A30000
unkown
page read and write
clean
990000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
4AF0000
unkown image
page readonly
clean
74D3000
heap private
page read and write
clean
36F000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
6D40000
unkown
page read and write
clean
6EF2000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
850000
unkown
page execute and read and write
clean
10000
unkown image
page read and write
clean
110000
unkown
page read and write
clean
110000
unkown
page read and write
clean
5360000
unkown image
page read and write
clean
4440000
heap private
page read and write
clean
3A0000
heap default
page read and write
clean
309E000
unkown
page read and write
clean
750000
unkown image
page readonly
clean
1042000
unkown image
page execute read
clean
5A5000
unkown
page read and write
clean
9C0000
unkown
page execute and read and write
clean
45B4000
unkown
page read and write
clean
3D50000
unkown
page read and write
clean
2110000
unkown image
page read and write
clean
8438000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
456F000
unkown
page read and write
clean
782F000
unkown
page read and write
clean
457A000
unkown
page read and write
clean
715B000
unkown
page read and write
clean
1E80000
unkown
page read and write
clean
45E000
stack
page read and write
clean
2A90000
unkown
page read and write
clean
6A28000
unkown
page read and write
clean
71D0000
unkown
page read and write
clean
5F5E000
stack
page read and write
clean
B2D000
unkown
page read and write
clean
7159000
unkown
page read and write
clean
90C0000
unkown image
page execute and read and write
clean
7095000
unkown
page read and write
clean
83A8000
unkown
page read and write
clean
3D50000
unkown
page read and write
clean
2130000
unkown image
page read and write
clean
2A70000
unkown
page read and write
clean
20B6000
unkown
page read and write
clean
2760000
unkown image
page readonly
clean
2A60000
unkown
page read and write
clean
FFE000
stack
page read and write | page guard
clean
2550000
unkown
page read and write
clean
4593000
unkown
page read and write
clean
8420000
unkown
page read and write
clean
2F20000
unkown
page read and write
clean
4300000
unkown
page read and write
clean
E50000
unkown
page read and write
clean
1CE000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
1B60000
heap private
page read and write
clean
1FD0000
unkown image
page readonly
clean
20DA000
unkown
page read and write
clean
5410000
heap private
page read and write
clean
94A5000
heap private
page read and write
clean
2100000
unkown image
page readonly
clean
4160000
unkown
page read and write
clean
1E0000
unkown
page read and write
clean
4E5E000
unkown
page read and write
clean
6B3F000
unkown
page read and write
clean
1F5A000
unkown
page read and write
clean
6B46000
unkown
page read and write
clean
25C000
unkown
page read and write
clean
1B65000
heap private
page read and write
clean
597000
heap default
page read and write
clean
30E0000
unkown image
page readonly
clean
94A0000
heap private
page read and write
clean
4B00000
unkown image
page readonly
clean
F0000
unkown image
page read and write
clean
4450000
unkown
page read and write
clean
4C70000
heap private
page read and write
clean
6CB8000
unkown
page read and write
clean
2AB0000
unkown
page read and write
clean
6A52000
unkown
page read and write
clean
5410000
heap private
page read and write
clean
4DD0000
heap private
page read and write
clean
50000
unkown image
page readonly
clean
6F0000
heap private
page read and write
clean
263C000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
23D000
heap default
page read and write
clean
7EFD0000
unkown image
page readonly
clean
730000
unkown image
page read and write
clean
54F6000
unkown
page read and write
clean
8BB8000
unkown
page read and write
clean
3E50000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
2120000
unkown image
page read and write
clean
790E000
unkown
page read and write
clean
69A6000
unkown
page read and write
clean
2F10000
unkown
page read and write
clean
740000
unkown image
page execute and read and write
clean
94A0000
heap private
page read and write
clean
744D000
unkown
page read and write
clean
74D3000
heap private
page read and write
clean
6A57000
unkown
page read and write
clean
37C000
unkown image
page execute and read and write
clean
81AE000
unkown
page read and write
clean
4BB0000
heap private
page read and write
clean
4D80000
unkown image
page readonly
clean
780000
unkown
page read and write
clean
97C2000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
4593000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
2540000
unkown
page read and write
clean
450000
unkown
page execute and read and write
clean
27A0000
unkown image
page readonly
clean
292F000
unkown
page read and write
clean
6DA0000
unkown
page read and write
clean
540000
unkown
page read and write
clean
6CF9000
unkown
page read and write
clean
140000
unkown image
page readonly
clean
6D48000
unkown
page read and write
clean
1040000
unkown image
page readonly
clean
1BE0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
2533000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
7E0000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
7024000
unkown
page read and write
clean
71D8000
unkown
page read and write
clean
2EC1000
unkown
page read and write
clean
2AC0000
unkown
page read and write
clean
83A8000
unkown
page read and write
clean
D0000
unkown image
page readonly
clean
301E000
unkown
page read and write
clean
27A0000
unkown image
page readonly
clean
6730000
unkown
page read and write
clean
3A0000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
B50000
unkown
page execute and read and write
clean
45B4000
unkown
page read and write
clean
54F6000
unkown
page read and write
clean
71D8000
unkown
page read and write
clean
1FE0000
unkown
page read and write
clean
249000
heap default
page read and write
clean
9983000
unkown
page read and write
clean
6E0000
unkown
page read and write
clean
4B00000
unkown image
page readonly
clean
2A80000
unkown
page read and write
clean
30E0000
unkown image
page readonly
clean
30D0000
unkown image
page readonly
clean
6A54000
unkown
page read and write
clean
237000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
5A5000
unkown
page read and write
clean
2943000
unkown
page read and write
clean
4E60000
unkown
page read and write
clean
1D0000
unkown
page read and write
clean
2120000
unkown image
page read and write
clean
693B000
unkown
page read and write
clean
2520000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
1D0000
unkown
page read and write
clean
3D40000
unkown
page read and write
clean
340000
unkown image
page readonly
clean
6CA6000
unkown
page read and write
clean
1040000
unkown image
page readonly
clean
4D40000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
63E000
unkown
page read and write
clean
690000
unkown
page read and write
clean
30D0000
unkown image
page readonly
clean
9903000
unkown
page read and write
clean
540000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
5270000
unkown
page execute read
clean
6D48000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
4C70000
heap private
page read and write
clean
1E0000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
1042000
unkown image
page execute read
clean
70A8000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
23E7000
unkown
page execute and read and write
clean
2EC1000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
4450000
unkown
page read and write
clean
263C000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
6FCB000
unkown
page read and write
clean
936F000
unkown
page read and write
clean
10C4000
unkown image
page readonly
clean
6DEB000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
FFF000
stack
page read and write
clean
8407000
unkown
page read and write
clean
2A90000
unkown
page read and write
clean
6A7D000
unkown
page read and write
clean
213B000
unkown image
page read and write
clean
7117000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
7E1E000
unkown
page read and write
clean
3D90000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
50000
unkown image
page readonly
clean
2500000
unkown image
page readonly
clean
4593000
unkown
page read and write
clean
1BE0000
unkown image
page readonly
clean
45A1000
unkown
page read and write
clean
70A0000
unkown
page read and write
clean
4B3E000
stack
page read and write
clean
60000
unkown image
page readonly
clean
9783000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
5B0000
unkown image
page readonly
clean
1D0000
unkown
page read and write
clean
6C1F000
unkown
page read and write
clean
1D0000
unkown
page read and write
clean
2533000
unkown
page read and write
clean
6A59000
unkown
page read and write
clean
6930000
unkown
page read and write
clean
70F7000
unkown
page read and write
clean
B0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
3CC0000
unkown image
page readonly
clean
4C7A000
heap private
page read and write
clean
360000
unkown
page read and write
clean
570000
unkown image
page execute and read and write
clean
2FC000
unkown
page read and write
clean
729A000
unkown
page read and write
clean
34E000
unkown
page read and write
clean
532E000
unkown
page read and write
clean
70E3000
unkown
page read and write
clean
2260000
unkown
page execute and read and write
clean
325D000
unkown
page read and write
clean
705B000
unkown
page read and write
clean
2A00000
unkown
page read and write
clean
73BB000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
8444000
unkown
page read and write
clean
6CB0000
unkown
page read and write
clean
2120000
unkown image
page read and write
clean
6CF7000
unkown
page read and write
clean
9D0000
unkown
page execute and read and write
clean
7CE000
stack
page read and write
clean
2646000
unkown
page read and write
clean
5B5E000
stack
page read and write | page guard
clean
830000
unkown
page read and write
clean
6D12000
unkown
page read and write
clean
5400000
unkown
page read and write
clean
584000
heap default
page read and write
clean
6A60000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
3CC0000
unkown image
page readonly
clean
447A000
unkown
page read and write
clean
20D7000
unkown
page read and write
clean
7BE3000
unkown
page read and write
clean
540000
unkown
page read and write
clean
6892000
unkown
page read and write
clean
6A52000
unkown
page read and write
clean
263000
unkown
page execute and read and write
clean
1EC000
unkown
page read and write
clean
213B000
unkown image
page read and write
clean
10C4000
unkown image
page readonly
clean
4D80000
unkown image
page readonly
clean
477000
heap default
page read and write
clean
30D0000
unkown image
page readonly
clean
1B50000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
AE0000
unkown
page execute and read and write
clean
5487000
unkown
page read and write
clean
4650000
unkown image
page readonly
clean
460B000
unkown
page read and write
clean
390000
unkown image
page read and write
clean
720C000
unkown
page read and write
clean
8BB8000
unkown
page read and write
clean
7D20000
heap private
page read and write
clean
27E0000
unkown
page read and write
clean
32A9000
heap private
page read and write
clean
23D000
heap default
page read and write
clean
4AAC000
unkown
page read and write
clean
211B000
unkown image
page read and write
clean
2550000
unkown
page read and write
clean
140000
unkown image
page readonly
clean
780000
unkown
page execute and read and write
clean
6D40000
unkown
page read and write
clean
69A6000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
1042000
unkown image
page execute read
clean
4D60000
unkown image
page readonly
clean
4D40000
unkown image
page readonly
clean
4DB1000
unkown image
page read and write
clean
6B8E000
unkown
page read and write
clean
5489000
unkown
page read and write
clean
250000
unkown
page read and write
clean
594000
unkown
page read and write
clean
C90000
unkown image
page readonly
clean
6D0B000
unkown
page read and write
clean
6CE000
stack
page read and write
clean
30000
unkown image
page readonly
clean
499000
heap default
page read and write
clean
54A3000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
4575000
unkown
page read and write
clean
6A59000
unkown
page read and write
clean
782F000
unkown
page read and write
clean
301E000
unkown
page read and write
clean
25C3000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
860000
unkown
page execute and read and write
clean
58A8000
unkown
page read and write
clean
3E50000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
6880000
unkown
page read and write
clean
30A8000
unkown
page read and write
clean
6E55000
unkown
page read and write
clean
44E7000
unkown
page read and write
clean
4445000
heap private
page read and write
clean
6CB0000
unkown
page read and write
clean
716B000
unkown
page read and write
clean
7537000
unkown
page read and write
clean
B20000
unkown
page read and write
clean
23F0000
unkown
page execute and read and write
clean
7BCB000
unkown
page read and write
clean
48FE000
stack
page read and write
clean
140000
unkown image
page readonly
clean
2F10000
unkown
page read and write
clean
2B5F000
unkown image
page read and write
clean
1D0000
unkown
page read and write
clean
7B3C000
unkown
page read and write
clean
D0000
unkown image
page readonly
clean
E0000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
4D50000
unkown image
page readonly
clean
546D000
unkown
page read and write
clean
297000
unkown
page execute and read and write
clean
4D50000
unkown image
page readonly
clean
2060000
unkown
page read and write
clean
31FF000
unkown
page read and write
clean
4445000
heap private
page read and write
clean
4D30000
unkown image
page readonly
clean
5444000
unkown
page read and write
clean
834B000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
8E0000
unkown image
page readonly
clean
3E50000
unkown image
page readonly
clean
6912000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
2100000
unkown image
page readonly
clean
7159000
unkown
page read and write
clean
3240000
unkown
page read and write
clean
7F0E000
unkown
page read and write
clean
6CB0000
unkown
page read and write
clean
9983000
unkown
page read and write
clean
2AE0000
unkown image
page readonly
clean
2520000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
8430000
unkown
page read and write
clean
7F0E000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
1B83000
heap private
page read and write
clean
10C4000
unkown image
page readonly
clean
7D20000
heap private
page read and write
clean
5CF000
stack
page read and write
clean
260000
unkown
page read and write
clean
55C0000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
9783000
unkown
page read and write
clean
8407000
unkown
page read and write
clean
532E000
unkown
page read and write
clean
74B4000
heap private
page read and write
clean
846B000
unkown
page read and write
clean
6CEF000
unkown
page read and write
clean
E4000
heap private
page read and write
clean
2160000
unkown
page execute and read and write
clean
54B2000
unkown
page read and write
clean
292F000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
1042000
unkown image
page execute read
clean
32A9000
heap private
page read and write
clean
6E0000
unkown
page read and write
clean
6C39000
unkown
page read and write
clean
6CB1000
unkown
page read and write
clean
230000
heap default
page read and write
clean
7D0000
unkown
page read and write
clean
2980000
unkown
page read and write
clean
6C66000
unkown
page read and write
clean
540000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
45B4000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
4D30000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
5C0000
unkown image
page readonly
clean
4430000
unkown image
page readonly
clean
698A000
unkown
page read and write
clean
846B000
unkown
page read and write
clean
7BD1000
unkown
page read and write
clean
1D0000
unkown
page read and write
clean
5B4000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
1042000
unkown image
page execute read
clean
77AE000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
6C31000
unkown
page read and write
clean
27E0000
unkown
page read and write
clean
45A1000
unkown
page read and write
clean
1040000
unkown image
page readonly
clean
460B000
unkown
page read and write
clean
1B83000
heap private
page read and write
clean
287000
unkown
page execute and read and write
clean
2CC7000
unkown image
page readonly
clean
4300000
unkown
page read and write
clean
6A4F000
unkown
page read and write
clean
73BB000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
430000
unkown image
page readonly
clean
8438000
unkown
page read and write
clean
3D4B000
unkown
page read and write
clean
21BF000
unkown
page read and write
clean
6CB4000
unkown
page read and write
clean
1B50000
unkown
page read and write
clean
25C3000
unkown
page read and write
clean
7446000
unkown
page read and write
clean
2A20000
unkown
page read and write
clean
6BBE000
unkown
page read and write
clean
5390000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
6BBE000
unkown
page read and write
clean
699F000
unkown
page read and write
clean
9884000
unkown
page read and write
clean
4300000
unkown
page read and write
clean
2130000
unkown image
page read and write
clean
45CB000
unkown
page read and write
clean
6CF2000
unkown
page read and write
clean
282000
unkown
page read and write
clean
4AAC000
unkown
page read and write
clean
32A5000
heap private
page read and write
clean
2476000
unkown image
page read and write
clean
8448000
unkown
page read and write
clean
2A10000
unkown
page read and write
clean
2A30000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
7330000
unkown
page read and write
clean
7CFE000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
330000
unkown
page read and write
clean
2520000
unkown
page read and write
clean
4DD0000
heap private
page read and write
clean
6CA8000
unkown
page read and write
clean
2A50000
unkown
page read and write
clean
57BD000
unkown
page read and write
clean
110000
unkown
page read and write
clean
44E7000
unkown
page read and write
clean
1B50000
unkown
page read and write
clean
57A0000
unkown
page read and write
clean
2AE0000
unkown image
page readonly
clean
7545000
unkown
page read and write
clean
1042000
unkown image
page execute read
clean
1D0000
unkown
page read and write
clean
79DA000
unkown
page read and write
clean
5390000
heap private
page read and write
clean
733A000
unkown
page read and write
clean
7150000
unkown
page read and write
clean
340000
unkown
page read and write
clean
2540000
unkown
page read and write
clean
94C3000
heap private
page read and write
clean
26D000
unkown
page execute and read and write
clean
3D90000
unkown
page read and write
clean
6ABD000
unkown
page read and write
clean
376000
heap private
page read and write
clean
1042000
unkown image
page execute read
clean
D0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
60BE000
stack
page read and write
clean
59F000
heap default
page read and write
clean
699F000
unkown
page read and write
clean
44E7000
unkown
page read and write
clean
68E2000
unkown
page read and write
clean
6A7F000
unkown
page read and write
clean
9940000
unkown
page read and write
clean
7138000
unkown
page read and write
clean
1040000
unkown image
page readonly
clean
4D60000
unkown image
page readonly
clean
2A90000
unkown
page read and write
clean
6A4F000
unkown
page read and write
clean
2646000
unkown
page read and write
clean
91C0000
unkown
page read and write
clean
4440000
heap private
page read and write
clean
45CD000
stack
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
54C6000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
4B00000
unkown image
page readonly
clean
371000
unkown
page read and write
clean
79F0000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
72FA000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
25C3000
unkown
page read and write
clean
7330000
unkown
page read and write
clean
54A3000
unkown
page read and write
clean
B40000
unkown
page execute and read and write
clean
There are 1542 hidden memdumps, click here to show them.