Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
2W6FcgEeMy.dll
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\E5F0NRSV\www.msn[2].xml
|
ASCII text, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\URW0GA4Q\contextual.media[1].xml
|
ASCII text, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{EBFDF002-4B97-11EC-90EB-ECF4BBEA1588}.dat
|
Composite Document File V2 Document, Cannot read section info
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{EBFDF004-4B97-11EC-90EB-ECF4BBEA1588}.dat
|
Composite Document File V2 Document, Cannot read section info
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
|
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
|
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
|
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
|
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
|
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
|
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
|
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
|
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
|
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\gee00pr\imagestore.dat
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\17-361657-68ddb2ab[1].js
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\55a804ab-e5c6-4b97-9319-86263d365d28[1].json
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AA7XCQ3[1].png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAMqFmF[1].png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAPFmi4[1].png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQBdIv[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 622x368, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQXXJy[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQXevg[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQXiy5[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQXrMl[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQY08U[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 311x333, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQYPIL[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 311x333, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQYUQR[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQYUU3[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 311x333, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQYVTM[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQYYTT[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 311x333, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQYrvs[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 622x368, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQYvQT[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 622x368, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\BB7hg4[1].png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\BBUZVvV[1].png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\a5ea21[1].ico
|
PNG image data, 32 x 32, 8-bit/color RGB, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\cfdbd9[1].png
|
PNG image data, 27 x 27, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\checksync[1].htm
|
HTML document, ASCII text, with very long lines
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\checksync[2].htm
|
HTML document, ASCII text, with very long lines
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\checksync[3].htm
|
HTML document, ASCII text, with very long lines
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\otCommonStyles[1].css
|
ASCII text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\otFlat[1].json
|
ASCII text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\otPcCenter[2].json
|
ASCII text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\otSDKStub[1].js
|
ASCII text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\264bf325-c7e4-4939-8912-2424a7abe532[1].jpg
|
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 300x300, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\AAOdxvW[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 622x368, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\AAOr6Ee[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 622x368, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\AAQTQg3[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\AAQY4m2[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\AAQY5wp[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 311x333, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\AAQY8Zl[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\AAQYCwH[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 622x368, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\AAQYWm8[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\AAQYqMl[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 311x333, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\AAycUpK[1].png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\BB10MkbM[1].png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\BB7hjL[1].png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\de-ch[2].json
|
UTF-8 Unicode text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\f69ed47f-3ddb-476a-9d92-3f337b2721b0[1].jpg
|
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 300x300, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\favicon[2].ico
|
MS Windows icon resource - 2 icons, 16x16, 16 colors, 32x32, 16 colors
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\iab2Data[2].json
|
UTF-8 Unicode text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\medianet[1].htm
|
HTML document, ASCII text, with very long lines
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\medianet[2].htm
|
HTML document, ASCII text, with very long lines
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\otTCF-ie[1].js
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\px[1].gif
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\4996b9[1].woff
|
Web Open Font Format, TrueType, length 45633, version 1.0
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAPQoxX[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 622x368, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAQVPm6[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 100x75, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAQVtAu[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 622x368, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAQW0Fs[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 100x75, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAQY2pC[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 100x75, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAQY5UV[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAQY7HF[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 300x250, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAQYCIb[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 311x333, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAQYV96[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 311x333, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAQYd7s[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAQYvGE[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 300x250, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAQZ3BL[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 100x75, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAud6Gv[1].png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAzb5EX[1].png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\BB1ftEY0[1].png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\BBMW3y8[1].png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\BBVuddh[1].png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\BBY7ARN[1].png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\checksync[3].htm
|
HTML document, ASCII text, with very long lines
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\nrrV52461[1].js
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\nrrV52461[2].js
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\otBannerSdk[1].js
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\tag[1].js
|
ASCII text, with very long lines
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\2d-0e97d4-185735b[1].css
|
UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\52-478955-68ddb2ab[1].js
|
UTF-8 Unicode text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\AAKp8YX[1].png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\AAPwesU[1].png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\AAQCmUS[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 622x368, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\AAQT0oN[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 622x368, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\AAQXTtj[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 311x333, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\AAQXYTC[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 310x166, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\AAQY2dE[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 311x333, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\AAQYSOX[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 310x166, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\AAQYSTg[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 622x368, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\AAQYULr[1].jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 311x333, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\BB1aXBV1[1].png
|
PNG image data, 27 x 27, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\BB1cEP3G[1].png
|
PNG image data, 27 x 27, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\BB1cG73h[1].png
|
PNG image data, 27 x 27, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\BB1fdtSt[1].png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
modified
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\BB1kc8s[1].png
|
PNG image data, 30 x 30, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\BB6Ma4a[1].png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\BB7gRE[1].png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\BBPfCZL[1].png
|
GIF image data, version 89a, 50 x 50
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\BBX2afX[1].png
|
PNG image data, 27 x 27, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\a8a064[1].gif
|
GIF image data, version 89a, 28 x 28
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\de-ch[1].htm
|
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\e151e5[1].gif
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\jquery-2.1.1.min[1].js
|
ASCII text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\~DF511C5929B225C7AA.TMP
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\~DF7F454687EFA0D2F9.TMP
|
data
|
dropped
|
There are 106 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Windows\System32\loaddll32.exe
|
loaddll32.exe "C:\Users\user\Desktop\2W6FcgEeMy.dll"
|
||
C:\Windows\SysWOW64\regsvr32.exe
|
regsvr32.exe /s C:\Users\user\Desktop\2W6FcgEeMy.dll
|
||
C:\Windows\SysWOW64\rundll32.exe
|
rundll32.exe "C:\Users\user\Desktop\2W6FcgEeMy.dll",#1
|
||
C:\Windows\SysWOW64\rundll32.exe
|
rundll32.exe C:\Users\user\Desktop\2W6FcgEeMy.dll,DllRegisterServer
|
||
C:\Windows\SysWOW64\rundll32.exe
|
rundll32.exe C:\Users\user\Desktop\2W6FcgEeMy.dll,adqehmqaggtoqofda
|
||
C:\Windows\SysWOW64\rundll32.exe
|
rundll32.exe C:\Users\user\Desktop\2W6FcgEeMy.dll,awkikcxxkllcr
|
||
C:\Windows\SysWOW64\cmd.exe
|
cmd.exe /C rundll32.exe "C:\Users\user\Desktop\2W6FcgEeMy.dll",#1
|
||
C:\Program Files\internet explorer\iexplore.exe
|
C:\Program Files\Internet Explorer\iexplore.exe
|
||
C:\Program Files (x86)\Internet Explorer\iexplore.exe
|
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:6068 CREDAT:17410 /prefetch:2
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://avolebukoneh.website
|
unknown
|
||
http://technoshoper.com
|
unknown
|
||
https://avolebukoneh.website
|
unknown
|
||
https://ad-delivery.net/px.gif?ch=1&e=0.5207611127885279
|
172.67.69.19
|
||
https://aka.ms/MicrosoftEdgeDownload"
|
unknown
|
||
https://assets.msn.com/staticsb/statics/latest/oneTrust/1.2/consent/55a804ab-e5c6-4b97-9319-86263d36
|
unknown
|
||
http://searchads.msn.net/.cfm?&&kp=1&
|
unknown
|
||
https://contextual.media.net/medianet.php?cid=8CU157172
|
unknown
|
||
https://www.msn.com/de-ch/nachrichten/coronareisen
|
unknown
|
||
https://www.msn.com/de-ch/news/other/jacqueline-hofer-tritt-doch-nicht-zur-wiederwahl-an/ar-AAQTAnf?
|
unknown
|
||
https://www.msn.com/de-ch/news/other/sie-bew%c3%a4ltigen-alltagsstress-und-todesszenen/ar-AAQUall?oc
|
unknown
|
||
https://www.google.com/favicon.ico~
|
unknown
|
||
https://click.linksynergy.com/deeplink?id=xoqYgl4JDe8&mid=46130&u1=dech_promotionalstripe_na
|
unknown
|
||
https://onedrive.live.com;Fotos
|
unknown
|
||
https://www.msn.com/de-ch/sport?ocid=StripeOCID
|
unknown
|
||
https://www.onenote.com/notebooks?WT.mc_id=MSN_OneNote_TopMenu&auth=1&wdorigin=msn
|
unknown
|
||
https://office.live.com/start/Word.aspx?WT.mc_id=MSN_site;Excel
|
unknown
|
||
https://www.msn.com/de-ch/sport/fussball/der-fcz-zittert-und-steht-doch-ganz-oben/ar-AAQWrxt?ocid=hp
|
unknown
|
||
https://www.msn.com/de-ch/news/other/mehrere-tausend-menschen-demonstrieren-in-z%c3%bcrich/ar-AAQWtO
|
unknown
|
||
http://ogp.me/ns/fb#
|
unknown
|
||
https://www.botman.ninja/privacy-policy
|
unknown
|
||
https://outlook.live.com/mail/deeplink/compose;Kalender
|
unknown
|
||
https://res-a.akamaihd.net/__media__/pics/8000/72/941/fallback1.jpg
|
unknown
|
||
https://www.queryclick.com/privacy-policy
|
unknown
|
||
https://www.skyscanner.net/g/referrals/v1/cars/home?associateid=API_B2B_19305_00002
|
unknown
|
||
https://www.onenote.com/notebooks?WT.mc_id=MSN_OneNote_Recent&auth=1&wdorigin=msn
|
unknown
|
||
https://www.msn.com/de-ch/news/other/t%c3%b6fffahrer-st%c3%bcrzt-nach-verfolgungsjagd-mit-der-polize
|
unknown
|
||
https://www.msn.com/de-ch/news/other/t%c3%b6fffahrer-liefert-sich-wilde-verfolgungsjagd-mit-der-poli
|
unknown
|
||
https://btloader.com/tag?o=6208086025961472&upapi=true
|
172.67.70.134
|
||
http://www.reddit.com/
|
unknown
|
||
https://www.skype.com/
|
unknown
|
||
https://clkde.tradedoubler.com/click?p=245744&a=3064090&g=24545562
|
unknown
|
||
https://sp.booking.com/index.html?aid=1589774&label=travelnavlink
|
unknown
|
||
https://www.msn.com/de-ch/nachrichten/regional
|
unknown
|
||
https://www.stroeer.de/werben-mit-stroeer/onlinewerbung/programmatic-data/sdi-datenschutz-b2c
|
unknown
|
||
https://onedrive.live.com/?qt=allmyphotos;Aktuelle
|
unknown
|
||
http://avolebukoneh.website/glik/.lwe.bmp088991256473871MNTYA%-
|
unknown
|
||
https://amzn.to/2TTxhNg
|
unknown
|
||
https://www.skype.com/go/onedrivepromo.download?cm_mmc=MSFT_2390_MSN-com
|
unknown
|
||
https://client-s.gateway.messenger.live.com
|
unknown
|
||
https://secure.adnxs.com/clktrb?id=764680&t=1
|
unknown
|
||
https://www.msn.com/de-ch/
|
unknown
|
||
https://office.live.com/start/PowerPoint.aspx?WT.mc_id=MSN_site
|
unknown
|
||
https://contextual.media.net/medianet.php?cid=8CU157172&crid=858412214&size=306x271&https=1
|
unknown
|
||
https://www.msn.com/de-ch
|
unknown
|
||
https://click.linksynergy.com/deeplink?id=xoqYgl4JDe8&mid=46130&u1=dech_mestripe_store&m
|
unknown
|
||
https://twitter.com/i/notifications;Ich
|
unknown
|
||
https://contextual.media.net/medianet.php?cid=8CU157172&crid=722878611&size=306x271&http
|
unknown
|
||
https://www.google.com/favicon.ico
|
unknown
|
||
https://ad.doubleclick.net/favicon.ico?ad=300x250&ad_box_=1&adnet=1&showad=1&size=250x250
|
216.58.215.230
|
||
https://nextmillennium.io/privacy-policy/
|
unknown
|
||
https://silvermob.com/privacy
|
unknown
|
||
https://www.sway.com/?WT.mc_id=MSN_site&utm_source=MSN&utm_medium=Topnav&utm_campaign=link;PowerPoin
|
unknown
|
||
https://www.msn.com/de-ch/?ocid=iehp&item=deferred_page%3a1&ignorejs=webcore%2fmodules%2fjsb
|
unknown
|
||
http://www.youtube.com/
|
unknown
|
||
http://ogp.me/ns#
|
unknown
|
||
http://schema.org/Organization
|
unknown
|
||
https://play.google.com/store/apps/details?id=com.microsoft.amp.apps.bingnews&hl=de-ch&refer
|
unknown
|
||
https://onedrive.live.com/?qt=mru;OneDrive-App
|
unknown
|
||
https://www.skype.com/de
|
unknown
|
||
https://www.tippsundtricks.co/lifehacks/schwamm-kuhlschrank/?utm_campaign=DECH-schwamm&utm_sourc
|
unknown
|
||
https://sp.booking.com/index.html?aid=1589774&label=dech-prime-hp-me
|
unknown
|
||
https://tools.applemediaservices.com/api/badges/download-on-the-app-store/black/de-de?"
|
unknown
|
||
https://www.skype.com/de/download-skype
|
unknown
|
||
https://onedrive.live.com/?wt.mc_id=oo_msn_msnhomepage_header
|
unknown
|
||
http://www.hotmail.msn.com/pii/ReadOutlookEmail/
|
unknown
|
||
https://onedrive.live.com;OneDrive-App
|
unknown
|
||
https://www.msn.com/de-ch/news/other/bei-den-%c3%a4rzten-schauen-die-beh%c3%b6rden-einfach-weg/ar-AA
|
unknown
|
||
https://click.linksynergy.com/deeplink?id=xoqYgl4JDe8&mid=46130&u1=dech_mestripe_office&
|
unknown
|
||
https://clkde.tradedoubler.com/click?p=295926&a=3064090&g=24886692
|
unknown
|
||
https://www.google.com/chrome/static/images/favicons/favicon-16x16.png
|
unknown
|
||
https://geolocation.onetrust.com/cookieconsentpub/v1/geo/location
|
unknown
|
||
http://www.amazon.com/
|
unknown
|
||
https://www.onenote.com/notebooks?WT.mc_id=MSN_OneNote_QuickNote&auth=1
|
unknown
|
||
http://avolebukoneh.website/glik/.lwe.bmp08899
|
unknown
|
||
https://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.9.1.min.js
|
unknown
|
||
http://www.twitter.com/
|
unknown
|
||
https://office.live.com/start/Excel.aspx?WT.mc_id=MSN_site;Sway
|
unknown
|
||
https://cdn.cookielaw.org/vendorlist/googleData.json
|
unknown
|
||
https://clkde.tradedoubler.com/click?p=195119&a=3064090&g=25021476
|
unknown
|
||
https://outlook.com/
|
unknown
|
||
https://play.google.com/intl/en_us/badges/images/generic/de_badge_web_generic.png"
|
unknown
|
||
https://contextual.media.net/checksync.php?&vsSync=1&cs=1&hb=1&cv=37&ndec=1&cid=8HBI57XIG&prvid=77%2
|
unknown
|
||
https://www.stroeer.com/fileadmin/com/StroeerDSP_deviceStorage.json
|
unknown
|
||
https://cdn.cookielaw.org/vendorlist/iabData.json
|
unknown
|
||
https://onedrive.live.com/?qt=mru;Aktuelle
|
unknown
|
||
https://www.msn.com/de-ch/?ocid=iehp
|
unknown
|
||
https://sp.booking.com/index.html?aid=1589774&label=dech-prime-hp-shoppingstripe-nav
|
unknown
|
||
https://www.ebay.ch/?mkcid=1&mkrid=5222-53480-19255-0&siteid=193&campid=5338626668&t
|
unknown
|
||
https://doceree.com/.well-known/deviceStorage.json
|
unknown
|
||
http://www.nytimes.com/
|
unknown
|
||
https://web.vortex.data.msn.com/collect/v1/t.gif?name=%27Ms.Webi.PageView%27&ver=%272.1%27&a
|
unknown
|
||
https://www.msn.com/de-ch/sport/other/runter-rauf-runter-wie-gc-in-genf-vom-weg-abkommt/ar-AAQYdQe?o
|
unknown
|
||
https://www.bidstack.com/privacy-policy/
|
unknown
|
||
https://onedrive.live.com/about/en/download/
|
unknown
|
||
https://www.msn.com/de-ch/news/other/defektes-paket-mit-radioaktivem-inhalt-in-swiss-flieger-entdeck
|
unknown
|
||
https://www.ricardo.ch/?utm_source=msn&utm_medium=affiliate&utm_campaign=msn_mestripe_logo_d
|
unknown
|
||
https://twitter.com/
|
unknown
|
||
http://avolebukoneh.website/glik/.lwe.bmp088991256473871MNTYA
|
unknown
|
||
https://www.stroeer.de/ssp-datenschutz
|
unknown
|
There are 90 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
contextual.media.net
|
2.18.160.23
|
||
avolebukoneh.website
|
37.120.206.119
|
||
dart.l.doubleclick.net
|
216.58.215.230
|
||
hblg.media.net
|
2.18.160.23
|
||
lg3.media.net
|
2.18.160.23
|
||
technoshoper.com
|
45.9.20.245
|
||
btloader.com
|
172.67.70.134
|
||
ad-delivery.net
|
172.67.69.19
|
||
assets.msn.com
|
unknown
|
||
web.vortex.data.msn.com
|
unknown
|
||
www.msn.com
|
unknown
|
||
ad.doubleclick.net
|
unknown
|
||
cvision.media.net
|
unknown
|
There are 3 hidden domains, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
172.67.69.19
|
ad-delivery.net
|
United States
|
||
45.9.20.245
|
technoshoper.com
|
Russian Federation
|
||
216.58.215.230
|
dart.l.doubleclick.net
|
United States
|
||
172.67.70.134
|
btloader.com
|
United States
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\AdminActive
|
{EBFDF002-4B97-11EC-90EB-ECF4BBEA1588}
|
||
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\iexplore
|
Count
|
||
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\iexplore
|
Time
|
||
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\iexplore
|
Blocked
|
||
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
|
Count
|
||
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
|
Time
|
||
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
|
LoadTimeArray
|
||
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
|
Count
|
||
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
|
Time
|
||
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
|
LoadTimeArray
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation
|
CVListPingLastYMD
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation
|
CVListPingBitmap
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation
|
CVListPingRandomizedBitmap
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DomainSuggestion
|
NextUpdateDate
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\NewTabPage
|
DecayDateQueue
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\NewTabPage
|
LastProcessed
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\NewTabPage
|
DecayDateQueue
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\NewTabPage
|
LastProcessed
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\www.msn.com
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\msn.com
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\msn.com
|
NumberOfSubdomains
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
|
NULL
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
|
Total
|
||
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
|
NULL
|
There are 84 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
4919000
|
heap private
|
page read and write
|
||
4F48000
|
heap private
|
page read and write
|
||
1100000
|
unkown
|
page execute and read and write
|
||
6F0000
|
stack
|
page execute and read and write
|
||
531B000
|
heap private
|
page read and write
|
||
5498000
|
heap private
|
page read and write
|
||
4F48000
|
heap private
|
page read and write
|
||
4F48000
|
heap private
|
page read and write
|
||
2258000
|
heap private
|
page read and write
|
||
5498000
|
heap private
|
page read and write
|
||
4FB9000
|
heap private
|
page read and write
|
||
5498000
|
heap private
|
page read and write
|
||
2F90000
|
unkown
|
page read and write
|
||
4F48000
|
heap private
|
page read and write
|
||
5498000
|
heap private
|
page read and write
|
||
6E0000
|
stack
|
page read and write
|
||
2258000
|
heap private
|
page read and write
|
||
5498000
|
heap private
|
page read and write
|
||
4F48000
|
heap private
|
page read and write
|
||
4F48000
|
heap private
|
page read and write
|
||
4F48000
|
heap private
|
page read and write
|
||
2258000
|
heap private
|
page read and write
|
||
5498000
|
heap private
|
page read and write
|
||
2258000
|
heap private
|
page read and write
|
||
2258000
|
heap private
|
page read and write
|
||
4F48000
|
heap private
|
page read and write
|
||
4F48000
|
heap private
|
page read and write
|
||
2258000
|
heap private
|
page read and write
|
||
5498000
|
heap private
|
page read and write
|
||
10F0000
|
unkown
|
page read and write
|
||
2258000
|
heap private
|
page read and write
|
||
5498000
|
heap private
|
page read and write
|
||
2258000
|
heap private
|
page read and write
|
||
1979000
|
heap private
|
page read and write
|
||
4F48000
|
heap private
|
page read and write
|
||
2FA0000
|
unkown
|
page execute and read and write
|
||
2258000
|
heap private
|
page read and write
|
||
5498000
|
heap private
|
page read and write
|
||
2258000
|
heap private
|
page read and write
|
||
1432000
|
unkown
|
page read and write
|
||
49CE000
|
stack
|
page read and write
|
||
2D19000
|
unkown image
|
page readonly
|
||
A50000
|
unkown
|
page read and write
|
||
2FB0000
|
unkown
|
page read and write
|
||
1340000
|
unkown image
|
page read and write
|
||
49EE000
|
stack
|
page read and write
|
||
2EB1000
|
heap default
|
page read and write
|
||
700000
|
stack
|
page read and write
|
||
1540000
|
unkown
|
page read and write
|
||
CCE000
|
stack
|
page read and write
|
||
2F43000
|
unkown image
|
page readonly
|
||
1AB000
|
unkown
|
page read and write
|
||
10E0000
|
unkown
|
page read and write
|
||
11D0000
|
unkown
|
page read and write
|
||
2F43000
|
unkown image
|
page readonly
|
||
2E9F000
|
unkown image
|
page readonly
|
||
2E43000
|
unkown image
|
page readonly
|
||
11D0000
|
unkown
|
page read and write
|
||
2FB0000
|
unkown
|
page read and write
|
||
2D53000
|
unkown image
|
page readonly
|
||
2C4B000
|
unkown
|
page read and write
|
||
2EC9000
|
heap default
|
page read and write
|
||
7FE70000
|
unkown image
|
page readonly
|
||
7F862000
|
unkown image
|
page readonly
|
||
28AC000
|
unkown image
|
page readonly
|
||
27AC000
|
unkown image
|
page readonly
|
||
2470000
|
unkown image
|
page readonly
|
||
700000
|
stack
|
page read and write
|
||
11CE000
|
stack
|
page read and write
|
||
6FB000
|
unkown
|
page read and write
|
||
DC0000
|
unkown image
|
page readonly
|
||
2F43000
|
unkown image
|
page readonly
|
||
281F000
|
unkown image
|
page readonly
|
||
11D0000
|
unkown
|
page read and write
|
||
11D0000
|
unkown
|
page read and write
|
||
A40000
|
unkown image
|
page read and write
|
||
2D76000
|
unkown image
|
page readonly
|
||
2E80000
|
unkown image
|
page readonly
|
||
2F15000
|
unkown
|
page read and write
|
||
7F842000
|
unkown image
|
page readonly
|
||
780000
|
heap private
|
page read and write
|
||
2E39000
|
unkown image
|
page readonly
|
||
6EDA0000
|
unkown image
|
page readonly
|
||
2E9F000
|
unkown image
|
page readonly
|
||
137C000
|
heap default
|
page read and write
|
||
11D0000
|
unkown
|
page read and write
|
||
134D000
|
unkown image
|
page read and write
|
||
2E39000
|
unkown image
|
page readonly
|
||
3570000
|
unkown image
|
page readonly
|
||
660000
|
unkown image
|
page readonly
|
||
2F15000
|
unkown image
|
page readonly
|
||
2F24000
|
unkown image
|
page readonly
|
||
7FE72000
|
unkown image
|
page readonly
|
||
2E89000
|
unkown image
|
page readonly
|
||
2FE5000
|
heap default
|
page read and write
|
||
A50000
|
unkown image
|
page readonly
|
||
7FD50000
|
unkown image
|
page readonly
|
||
2E5D000
|
unkown image
|
page readonly
|
||
500000
|
unkown image
|
page readonly
|
||
2EAF000
|
unkown image
|
page readonly
|
||
2823000
|
unkown image
|
page readonly
|
||
2E24000
|
unkown image
|
page readonly
|
||
593E000
|
stack
|
page read and write
|
||
B00000
|
unkown image
|
page readonly
|
||
2BE0000
|
unkown image
|
page readonly
|
||
11D0000
|
unkown
|
page read and write
|
||
2FDF000
|
unkown image
|
page readonly
|
||
25E5000
|
unkown image
|
page readonly
|
||
11D0000
|
unkown
|
page read and write
|
||
2D10000
|
unkown image
|
page readonly
|
||
2FE0000
|
heap default
|
page read and write
|
||
CCA000
|
heap default
|
page read and write
|
||
28B8000
|
unkown image
|
page readonly
|
||
5120000
|
unkown
|
page read and write
|
||
2E7C000
|
unkown image
|
page readonly
|
||
3620000
|
unkown image
|
page readonly
|
||
2EA2000
|
unkown
|
page read and write
|
||
740000
|
heap default
|
page read and write
|
||
2815000
|
unkown image
|
page readonly
|
||
2E2C000
|
unkown image
|
page readonly
|
||
58B000
|
unkown
|
page read and write
|
||
11D0000
|
unkown
|
page read and write
|
||
13FE000
|
heap default
|
page read and write
|
||
2F24000
|
unkown image
|
page readonly
|
||
700000
|
stack
|
page read and write
|
||
7F832000
|
unkown image
|
page readonly
|
||
6EDAE000
|
unkown image
|
page readonly
|
||
549C000
|
heap private
|
page read and write
|
||
2FB0000
|
unkown
|
page read and write
|
||
7FD30000
|
unkown image
|
page readonly
|
||
4A5E000
|
stack
|
page read and write
|
||
11D0000
|
unkown
|
page read and write
|
||
2EC2000
|
unkown image
|
page readonly
|
||
2E97000
|
unkown image
|
page readonly
|
||
1435000
|
unkown
|
page read and write
|
||
700000
|
stack
|
page read and write
|
||
501E000
|
stack
|
page read and write
|
||
2E39000
|
unkown image
|
page readonly
|
||
2FB0000
|
unkown
|
page read and write
|
||
11D0000
|
unkown
|
page read and write
|
||
3300000
|
unkown image
|
page readonly
|
||
5080000
|
unkown
|
page read and write
|
||
11D0000
|
unkown
|
page read and write
|
||
2F43000
|
unkown image
|
page readonly
|
||
2B30000
|
unkown image
|
page readonly
|
||
2EAF000
|
unkown image
|
page readonly
|
||
2ECB000
|
unkown image
|
page readonly
|
||
710000
|
unkown image
|
page readonly
|
||
1600000
|
heap private
|
page read and write
|
||
2F38000
|
unkown image
|
page readonly
|
||
152E000
|
stack
|
page read and write
|
||
2E65000
|
unkown image
|
page readonly
|
||
2C60000
|
unkown
|
page read and write
|
||
2638000
|
unkown image
|
page readonly
|
||
2600000
|
unkown image
|
page readonly
|
||
F90000
|
heap default
|
page read and write
|
||
5080000
|
unkown
|
page read and write
|
||
B60000
|
unkown image
|
page readonly
|
||
2E95000
|
unkown image
|
page readonly
|
||
7EFF2000
|
unkown image
|
page readonly
|
||
2EA4000
|
heap default
|
page read and write
|
||
1350000
|
unkown image
|
page readonly
|
||
414D000
|
stack
|
page read and write
|
||
2E30000
|
unkown
|
page read and write
|
||
4A6F000
|
unkown
|
page read and write
|
||
3C0000
|
unkown
|
page read and write
|
||
7F000000
|
unkown image
|
page readonly
|
||
2F11000
|
unkown image
|
page readonly
|
||
31D0000
|
heap private
|
page read and write
|
||
282A000
|
unkown image
|
page readonly
|
||
6EDC7000
|
unkown image
|
page readonly
|
||
7F0D0000
|
unkown image
|
page readonly
|
||
2D10000
|
unkown image
|
page readonly
|
||
26E8000
|
unkown image
|
page readonly
|
||
3F4F000
|
stack
|
page read and write
|
||
AF0000
|
unkown image
|
page readonly
|
||
7EFF0000
|
unkown image
|
page readonly
|
||
2E9D000
|
unkown image
|
page readonly
|
||
27EC000
|
unkown image
|
page readonly
|
||
549A000
|
heap private
|
page read and write
|
||
2FDD000
|
unkown image
|
page read and write
|
||
13C4000
|
heap default
|
page read and write
|
||
2ED5000
|
heap default
|
page read and write
|
||
2E95000
|
unkown image
|
page readonly
|
||
1540000
|
unkown
|
page read and write
|
||
AAC000
|
unkown
|
page read and write
|
||
2FB0000
|
unkown
|
page read and write
|
||
31E0000
|
unkown image
|
page readonly
|
||
1341000
|
unkown image
|
page execute read
|
||
2891000
|
unkown image
|
page readonly
|
||
6EDA0000
|
unkown image
|
page readonly
|
||
2E3C000
|
unkown image
|
page readonly
|
||
3E4F000
|
stack
|
page read and write
|
||
2EAA000
|
unkown image
|
page readonly
|
||
B00000
|
unkown image
|
page readonly
|
||
2FD0000
|
unkown image
|
page read and write
|
||
4BD0000
|
unkown
|
page read and write
|
||
1F0000
|
unkown
|
page read and write
|
||
2FB0000
|
unkown
|
page read and write
|
||
6EDA0000
|
unkown image
|
page readonly
|
||
11D0000
|
unkown
|
page read and write
|
||
6EDA0000
|
unkown image
|
page readonly
|
||
6EDC3000
|
unkown image
|
page read and write
|
||
2EAA000
|
unkown image
|
page readonly
|
||
14EE000
|
stack
|
page read and write
|
||
1105000
|
unkown
|
page execute and read and write
|
||
133C000
|
stack
|
page read and write
|
||
3E0000
|
unkown image
|
page readonly
|
||
7F880000
|
unkown image
|
page readonly
|
||
2F43000
|
unkown image
|
page readonly
|
||
582E000
|
stack
|
page read and write
|
||
3560000
|
unkown image
|
page readonly
|
||
2EAF000
|
unkown image
|
page readonly
|
||
700000
|
stack
|
page read and write
|
||
4B30000
|
unkown
|
page read and write
|
||
700000
|
stack
|
page read and write
|
||
2FB0000
|
unkown
|
page read and write
|
||
2D19000
|
unkown image
|
page readonly
|
||
4F9D000
|
stack
|
page read and write
|
||
7F840000
|
unkown image
|
page readonly
|
||
8F7000
|
heap private
|
page read and write
|
||
586F000
|
stack
|
page read and write
|
||
4ADD000
|
stack
|
page read and write
|
||
7F0B2000
|
unkown image
|
page readonly
|
||
2E65000
|
unkown image
|
page readonly
|
||
2FB0000
|
unkown
|
page read and write
|
||
2270000
|
unkown image
|
page readonly
|
||
1070000
|
unkown image
|
page readonly
|
||
11D0000
|
unkown
|
page read and write
|
||
11D0000
|
unkown
|
page read and write
|
||
2E3C000
|
unkown image
|
page readonly
|
||
2E89000
|
unkown image
|
page readonly
|
||
5AF000
|
stack
|
page read and write
|
||
2ECB000
|
unkown image
|
page readonly
|
||
7F0C2000
|
unkown image
|
page readonly
|
||
7F850000
|
unkown image
|
page readonly
|
||
2831000
|
unkown image
|
page readonly
|
||
6EDAE000
|
unkown image
|
page readonly
|
||
25F3000
|
unkown image
|
page readonly
|
||
2FB0000
|
unkown
|
page read and write
|
||
2ECB000
|
unkown image
|
page readonly
|
||
FC3000
|
unkown
|
page read and write
|
||
2846000
|
unkown image
|
page readonly
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
710000
|
unkown image
|
page read and write
|
||
6EDC7000
|
unkown image
|
page readonly
|
||
4F4B000
|
heap private
|
page read and write
|
||
28A4000
|
unkown image
|
page readonly
|
||
11D0000
|
unkown
|
page read and write
|
||
7FD40000
|
unkown image
|
page readonly
|
||
7F0B0000
|
unkown image
|
page readonly
|
||
11D0000
|
unkown
|
page read and write
|
||
25C7000
|
unkown image
|
page readonly
|
||
11D0000
|
unkown
|
page read and write
|
||
2F32000
|
unkown image
|
page readonly
|
||
2E4A000
|
unkown image
|
page readonly
|
||
7FE82000
|
unkown image
|
page readonly
|
||
1B0000
|
unkown image
|
page readonly
|
||
2E7B000
|
unkown image
|
page readonly
|
||
2842000
|
unkown image
|
page readonly
|
||
2E9D000
|
heap default
|
page read and write
|
||
7F730000
|
unkown image
|
page readonly
|
||
2D19000
|
unkown image
|
page readonly
|
||
11D0000
|
unkown
|
page read and write
|
||
2EA3000
|
unkown image
|
page readonly
|
||
5C0000
|
unkown
|
page read and write
|
||
27B9000
|
unkown image
|
page readonly
|
||
1D0B000
|
stack
|
page read and write
|
||
7FE70000
|
unkown image
|
page readonly
|
||
9DD000
|
unkown
|
page read and write
|
||
33E0000
|
unkown image
|
page readonly
|
||
F10000
|
unkown image
|
page readonly
|
||
7F850000
|
unkown image
|
page readonly
|
||
7F0C0000
|
unkown image
|
page readonly
|
||
2D68000
|
unkown image
|
page readonly
|
||
340000
|
unkown
|
page read and write
|
||
790000
|
unkown image
|
page readonly
|
||
2EC6000
|
unkown image
|
page readonly
|
||
4BAC000
|
stack
|
page read and write
|
||
2817000
|
unkown image
|
page readonly
|
||
7FE80000
|
unkown image
|
page readonly
|
||
FC0000
|
unkown image
|
page readonly
|
||
5050000
|
unkown
|
page read and write
|
||
31BB000
|
stack
|
page read and write
|
||
DA0000
|
unkown image
|
page readonly
|
||
6F5000
|
stack
|
page execute and read and write
|
||
2E3C000
|
unkown image
|
page readonly
|
||
6EDA0000
|
unkown image
|
page readonly
|
||
313E000
|
stack
|
page read and write
|
||
4F4D000
|
heap private
|
page read and write
|
||
2FB0000
|
unkown
|
page read and write
|
||
5419000
|
heap private
|
page read and write
|
||
D85000
|
unkown
|
page read and write
|
||
B00000
|
unkown image
|
page readonly
|
||
6EDC3000
|
unkown image
|
page read and write
|
||
2FB0000
|
unkown
|
page read and write
|
||
700000
|
stack
|
page read and write
|
||
CD0000
|
heap private
|
page read and write
|
||
4C40000
|
heap private
|
page read and write
|
||
969000
|
unkown
|
page read and write
|
||
1C0F000
|
stack
|
page read and write
|
||
2C5A000
|
unkown
|
page read and write
|
||
7F0C0000
|
unkown image
|
page readonly
|
||
45A0000
|
heap private
|
page read and write
|
||
15DD000
|
stack
|
page read and write
|
||
D81000
|
unkown
|
page read and write
|
||
2C54000
|
unkown
|
page read and write
|
||
6BC000
|
unkown
|
page read and write
|
||
7FE72000
|
unkown image
|
page readonly
|
||
FB7000
|
unkown
|
page read and write
|
||
900000
|
unkown image
|
page readonly
|
||
6EDAE000
|
unkown image
|
page readonly
|
||
317C000
|
stack
|
page read and write
|
||
963000
|
unkown
|
page read and write
|
||
2C41000
|
unkown
|
page read and write
|
||
2F15000
|
unkown image
|
page readonly
|
||
50A0000
|
heap private
|
page read and write
|
||
2FB0000
|
unkown
|
page read and write
|
||
71D000
|
unkown image
|
page read and write
|
||
2FB0000
|
unkown
|
page read and write
|
||
700000
|
stack
|
page read and write
|
||
2EB1000
|
unkown
|
page read and write
|
||
4F4C000
|
heap private
|
page read and write
|
||
FC0000
|
unkown
|
page read and write
|
||
2D37000
|
unkown image
|
page readonly
|
||
2F32000
|
unkown image
|
page readonly
|
||
2FB0000
|
unkown
|
page read and write
|
||
11D0000
|
unkown
|
page read and write
|
||
332A000
|
heap default
|
page read and write
|
||
6EDA1000
|
unkown image
|
page execute read
|
||
2D10000
|
unkown image
|
page readonly
|
||
2E9D000
|
unkown image
|
page readonly
|
||
700000
|
stack
|
page read and write
|
||
760000
|
unkown
|
page read and write
|
||
11D0000
|
unkown
|
page read and write
|
||
6EDAE000
|
unkown image
|
page readonly
|
||
3320000
|
heap default
|
page read and write
|
||
971000
|
unkown
|
page read and write
|
||
71C000
|
unkown image
|
page readonly
|
||
142E000
|
heap default
|
page read and write
|
||
560000
|
heap default
|
page read and write
|
||
B70000
|
unkown image
|
page readonly
|
||
2FB0000
|
unkown
|
page read and write
|
||
975000
|
unkown
|
page read and write
|
||
2E97000
|
unkown
|
page read and write
|
||
4FDB000
|
stack
|
page read and write
|
||
30FE000
|
stack
|
page read and write
|
||
2E73000
|
unkown image
|
page readonly
|
||
A3F000
|
stack
|
page read and write
|
||
2D37000
|
unkown image
|
page readonly
|
||
2FB0000
|
unkown
|
page read and write
|
||
2B8C000
|
unkown
|
page read and write
|
||
2E43000
|
unkown image
|
page readonly
|
||
4700000
|
heap private
|
page read and write
|
||
11D0000
|
unkown
|
page read and write
|
||
F20000
|
unkown image
|
page readonly
|
||
4B6D000
|
stack
|
page read and write
|
||
9DF000
|
unkown
|
page read and write
|
||
26F1000
|
unkown image
|
page readonly
|
||
142C000
|
unkown
|
page read and write
|
||
2C0000
|
unkown image
|
page readonly
|
||
142E000
|
unkown
|
page read and write
|
||
755000
|
heap default
|
page read and write
|
||
71F000
|
unkown image
|
page readonly
|
||
4290000
|
unkown
|
page read and write
|
||
404D000
|
stack
|
page read and write
|
||
7FD42000
|
unkown image
|
page readonly
|
||
225D000
|
heap private
|
page read and write
|
||
2800000
|
unkown image
|
page readonly
|
||
2F43000
|
unkown image
|
page readonly
|
||
5080000
|
unkown
|
page read and write
|
||
8F0000
|
heap private
|
page read and write
|
||
2D68000
|
unkown image
|
page readonly
|
||
418E000
|
stack
|
page read and write
|
||
118D000
|
stack
|
page read and write
|
||
DF0000
|
unkown
|
page read and write
|
||
2EB1000
|
unkown image
|
page readonly
|
||
2699000
|
unkown image
|
page readonly
|
||
5038000
|
heap private
|
page read and write
|
||
2C5D000
|
unkown
|
page read and write
|
||
2FDC000
|
unkown image
|
page readonly
|
||
2C73000
|
unkown image
|
page readonly
|
||
7FD70000
|
unkown image
|
page readonly
|
||
7F0B2000
|
unkown image
|
page readonly
|
||
760000
|
unkown image
|
page readonly
|
||
700000
|
stack
|
page read and write
|
||
700000
|
stack
|
page read and write
|
||
2F17000
|
unkown
|
page read and write
|
||
134C000
|
unkown image
|
page readonly
|
||
7FD32000
|
unkown image
|
page readonly
|
||
2E97000
|
unkown image
|
page readonly
|
||
4998000
|
heap private
|
page read and write
|
||
2EA3000
|
unkown image
|
page readonly
|
||
2E4A000
|
unkown image
|
page readonly
|
||
2E40000
|
heap default
|
page read and write
|
||
7F0000
|
unkown image
|
page readonly
|
||
C10000
|
unkown image
|
page readonly
|
||
FA4000
|
unkown
|
page read and write
|
||
A40000
|
unkown image
|
page readonly
|
||
2E73000
|
unkown image
|
page readonly
|
||
134F000
|
unkown image
|
page readonly
|
||
2F43000
|
unkown image
|
page readonly
|
||
7F760000
|
unkown image
|
page readonly
|
||
4F4A000
|
heap private
|
page read and write
|
||
27A4000
|
unkown image
|
page readonly
|
||
FA8000
|
unkown
|
page read and write
|
||
5E0000
|
unkown image
|
page readonly
|
||
2EC2000
|
unkown image
|
page readonly
|
||
1423000
|
heap default
|
page read and write
|
||
2E6C000
|
unkown image
|
page readonly
|
||
7F860000
|
unkown image
|
page readonly
|
||
428F000
|
stack
|
page read and write
|
||
11D0000
|
unkown
|
page read and write
|
||
700000
|
stack
|
page read and write
|
||
549B000
|
heap private
|
page read and write
|
||
2809000
|
unkown image
|
page readonly
|
||
700000
|
stack
|
page read and write
|
||
2E73000
|
unkown image
|
page readonly
|
||
BD0000
|
unkown image
|
page readonly
|
||
7F880000
|
unkown image
|
page readonly
|
||
2F24000
|
unkown image
|
page readonly
|
||
2BD0000
|
unkown image
|
page readonly
|
||
2D37000
|
unkown image
|
page readonly
|
||
9E2000
|
unkown
|
page read and write
|
||
25F0000
|
unkown image
|
page readonly
|
||
1550000
|
heap private
|
page read and write
|
||
13B4000
|
heap default
|
page read and write
|
||
55E000
|
stack
|
page read and write
|
||
7F840000
|
unkown image
|
page readonly
|
||
2E39000
|
unkown image
|
page readonly
|
||
7EE000
|
stack
|
page read and write
|
||
26B7000
|
unkown image
|
page readonly
|
||
50DE000
|
stack
|
page read and write
|
||
FBD000
|
unkown
|
page read and write
|
||
2F38000
|
unkown image
|
page readonly
|
||
2B0000
|
unkown image
|
page read and write
|
||
2E95000
|
heap default
|
page read and write
|
||
5080000
|
unkown
|
page read and write
|
||
2E95000
|
unkown image
|
page readonly
|
||
BE0000
|
unkown
|
page read and write
|
||
2F32000
|
unkown image
|
page readonly
|
||
2F24000
|
unkown image
|
page readonly
|
||
284B000
|
unkown image
|
page readonly
|
||
7FD30000
|
unkown image
|
page readonly
|
||
11D0000
|
unkown
|
page read and write
|
||
7FE82000
|
unkown image
|
page readonly
|
||
25E7000
|
unkown image
|
page readonly
|
||
2FB0000
|
unkown
|
page read and write
|
||
2ECC000
|
heap default
|
page read and write
|
||
2E9D000
|
unkown image
|
page readonly
|
||
5880000
|
unkown
|
page read and write
|
||
D90000
|
heap private
|
page read and write
|
||
2E80000
|
unkown image
|
page readonly
|
||
4B20000
|
heap private
|
page read and write
|
||
2FB0000
|
unkown
|
page read and write
|
||
2E4A000
|
unkown image
|
page readonly
|
||
2EB1000
|
unkown image
|
page readonly
|
||
136B000
|
heap default
|
page read and write
|
||
2E97000
|
unkown image
|
page readonly
|
||
2E9F000
|
unkown image
|
page readonly
|
||
9E0000
|
unkown
|
page read and write
|
||
C40000
|
unkown image
|
page readonly
|
||
1430000
|
heap default
|
page read and write
|
||
10D0000
|
unkown image
|
page readonly
|
||
6EDA1000
|
unkown image
|
page execute read
|
||
11D0000
|
unkown
|
page read and write
|
||
11D0000
|
unkown
|
page read and write
|
||
1E0E000
|
stack
|
page read and write
|
||
2F11000
|
unkown image
|
page readonly
|
||
11F0000
|
heap default
|
page read and write
|
||
7F872000
|
unkown image
|
page readonly
|
||
2E5D000
|
unkown image
|
page readonly
|
||
700000
|
stack
|
page read and write
|
||
2E97000
|
unkown image
|
page readonly
|
||
142C000
|
heap default
|
page read and write
|
||
4EC9000
|
heap private
|
page read and write
|
||
2ED5000
|
unkown
|
page read and write
|
||
1E60000
|
heap private
|
page read and write
|
||
2EB1000
|
unkown image
|
page readonly
|
||
4A9F000
|
stack
|
page read and write
|
||
1432000
|
heap default
|
page read and write
|
||
28C3000
|
unkown image
|
page readonly
|
||
370000
|
unkown image
|
page readonly
|
||
700000
|
stack
|
page read and write
|
||
2F38000
|
unkown image
|
page readonly
|
||
9E6000
|
unkown
|
page read and write
|
||
11D0000
|
unkown
|
page read and write
|
||
700000
|
stack
|
page read and write
|
||
2EAA000
|
unkown image
|
page readonly
|
||
9E0000
|
unkown
|
page read and write
|
||
2E43000
|
unkown image
|
page readonly
|
||
7F0B0000
|
unkown image
|
page readonly
|
||
2B30000
|
unkown image
|
page readonly
|
||
1020000
|
heap private
|
page read and write
|
||
FBA000
|
unkown
|
page read and write
|
||
650000
|
unkown image
|
page read and write
|
||
281D000
|
unkown image
|
page readonly
|
||
700000
|
stack
|
page read and write
|
||
2E6C000
|
unkown image
|
page readonly
|
||
2F80000
|
unkown
|
page read and write
|
||
AEB000
|
unkown
|
page read and write
|
||
2EC9000
|
unkown
|
page read and write
|
||
2C45000
|
unkown
|
page read and write
|
||
511F000
|
stack
|
page read and write
|
||
2FB0000
|
unkown
|
page read and write
|
||
2E4A000
|
unkown image
|
page readonly
|
||
27E5000
|
unkown image
|
page readonly
|
||
2FB0000
|
unkown
|
page read and write
|
||
2ECC000
|
unkown
|
page read and write
|
||
2F19000
|
unkown
|
page read and write
|
||
6EDC7000
|
unkown image
|
page readonly
|
||
2EAA000
|
unkown image
|
page readonly
|
||
1E4D000
|
stack
|
page read and write
|
||
2F38000
|
unkown image
|
page readonly
|
||
2C0000
|
unkown image
|
page readonly
|
||
14A0000
|
heap private
|
page read and write
|
||
7FD40000
|
unkown image
|
page readonly
|
||
35B000
|
unkown
|
page read and write
|
||
7FC30000
|
unkown image
|
page readonly
|
||
6EDC7000
|
unkown image
|
page readonly
|
||
4C2F000
|
stack
|
page read and write
|
||
2E6C000
|
unkown image
|
page readonly
|
||
750000
|
heap default
|
page read and write
|
||
DDC000
|
stack
|
page read and write
|
||
549A000
|
heap private
|
page read and write
|
||
2F15000
|
unkown image
|
page readonly
|
||
28B2000
|
unkown image
|
page readonly
|
||
BC0000
|
unkown image
|
page readonly
|
||
7EFE0000
|
unkown image
|
page readonly
|
||
7F830000
|
unkown image
|
page readonly
|
||
2E9D000
|
unkown image
|
page readonly
|
||
7F870000
|
unkown image
|
page readonly
|
||
7FD50000
|
unkown image
|
page readonly
|
||
2F32000
|
unkown image
|
page readonly
|
||
159E000
|
stack
|
page read and write
|
||
AC0000
|
heap default
|
page read and write
|
||
2FB0000
|
unkown
|
page read and write
|
||
549D000
|
heap private
|
page read and write
|
||
2FA5000
|
unkown
|
page execute and read and write
|
||
711000
|
unkown image
|
page execute read
|
||
2C67000
|
unkown image
|
page readonly
|
||
11D0000
|
unkown
|
page read and write
|
||
2FB0000
|
unkown
|
page read and write
|
||
9AD000
|
unkown
|
page read and write
|
||
27BC000
|
unkown image
|
page readonly
|
||
7EFE0000
|
unkown image
|
page readonly
|
||
2B20000
|
unkown image
|
page read and write
|
||
28C3000
|
unkown image
|
page readonly
|
||
96A000
|
unkown
|
page read and write
|
||
2895000
|
unkown image
|
page readonly
|
||
971000
|
unkown
|
page read and write
|
||
2FB0000
|
unkown
|
page read and write
|
||
C8E000
|
stack
|
page read and write
|
||
2D37000
|
unkown image
|
page readonly
|
||
7F000000
|
unkown image
|
page readonly
|
||
7F862000
|
unkown image
|
page readonly
|
||
2C47000
|
unkown image
|
page readonly
|
||
7FD32000
|
unkown image
|
page readonly
|
||
969000
|
unkown
|
page read and write
|
||
B50000
|
unkown
|
page read and write
|
||
6EDA0000
|
unkown image
|
page readonly
|
||
2F11000
|
unkown image
|
page readonly
|
||
700000
|
stack
|
page read and write
|
||
225C000
|
heap private
|
page read and write
|
||
670000
|
heap private
|
page read and write
|
||
2FB0000
|
unkown
|
page read and write
|
||
2FB0000
|
unkown
|
page read and write
|
||
7EFF0000
|
unkown image
|
page readonly
|
||
1060000
|
heap private
|
page read and write
|
||
2E43000
|
unkown image
|
page readonly
|
||
5080000
|
unkown
|
page read and write
|
||
16C000
|
unkown
|
page read and write
|
||
2FB0000
|
unkown
|
page read and write
|
||
B5D000
|
unkown
|
page read and write
|
||
2FD1000
|
unkown image
|
page execute read
|
||
225B000
|
heap private
|
page read and write
|
||
E1B000
|
stack
|
page read and write
|
||
4590000
|
unkown
|
page read and write
|
||
700000
|
stack
|
page read and write
|
||
9E3000
|
unkown
|
page read and write
|
||
587000
|
unkown
|
page read and write
|
||
7FE80000
|
unkown image
|
page readonly
|
||
7EEE0000
|
unkown image
|
page readonly
|
||
2BCB000
|
unkown
|
page read and write
|
||
4BEE000
|
stack
|
page read and write
|
||
6EDA0000
|
unkown image
|
page readonly
|
||
2CB8000
|
unkown image
|
page readonly
|
||
2D68000
|
unkown image
|
page readonly
|
||
4A0F000
|
stack
|
page read and write
|
||
11D0000
|
unkown
|
page read and write
|
||
21D9000
|
heap private
|
page read and write
|
||
1360000
|
heap default
|
page read and write
|
||
6EDA0000
|
unkown image
|
page readonly
|
||
2EC6000
|
unkown image
|
page readonly
|
||
2EA3000
|
unkown image
|
page readonly
|
||
2FB0000
|
unkown
|
page read and write
|
||
4B50000
|
heap private
|
page read and write
|
||
4AED000
|
stack
|
page read and write
|
||
5080000
|
unkown
|
page read and write
|
||
2F43000
|
unkown image
|
page readonly
|
||
910000
|
heap default
|
page read and write
|
||
2FB0000
|
unkown
|
page read and write
|
||
660000
|
unkown image
|
page readonly
|
||
1434000
|
unkown
|
page read and write
|
||
2E7C000
|
unkown image
|
page readonly
|
||
7EFE2000
|
unkown image
|
page readonly
|
||
2D71000
|
unkown image
|
page readonly
|
||
33C000
|
unkown
|
page read and write
|
||
2E65000
|
unkown image
|
page readonly
|
||
1140000
|
unkown image
|
page readonly
|
||
2EA3000
|
unkown image
|
page readonly
|
||
CC0000
|
heap default
|
page read and write
|
||
8E0000
|
unkown image
|
page readonly
|
||
110000
|
unkown image
|
page readonly
|
||
FB4000
|
unkown
|
page read and write
|
||
700000
|
stack
|
page read and write
|
||
2D10000
|
unkown image
|
page readonly
|
||
4B2C000
|
stack
|
page read and write
|
||
6EDC3000
|
unkown image
|
page read and write
|
||
6EDA0000
|
unkown image
|
page readonly
|
||
2E5D000
|
unkown image
|
page readonly
|
||
840000
|
unkown image
|
page readonly
|
||
2E6C000
|
unkown image
|
page readonly
|
||
2D68000
|
unkown image
|
page readonly
|
||
2EAF000
|
unkown image
|
page readonly
|
||
7F0D0000
|
unkown image
|
page readonly
|
||
4B1B000
|
stack
|
page read and write
|
||
2E4A000
|
heap default
|
page read and write
|
||
1540000
|
unkown
|
page read and write
|
||
2E89000
|
unkown image
|
page readonly
|
||
2EB1000
|
unkown image
|
page readonly
|
||
2690000
|
unkown image
|
page readonly
|
||
2F2C000
|
unkown image
|
page readonly
|
||
91A000
|
heap default
|
page read and write
|
||
2FB0000
|
unkown
|
page read and write
|
||
3180000
|
unkown image
|
page readonly
|
||
2FB0000
|
unkown
|
page read and write
|
||
7F830000
|
unkown image
|
page readonly
|
||
5870000
|
unkown
|
page read and write
|
||
100000
|
unkown image
|
page read and write
|
||
5498000
|
heap private
|
page read and write
|
||
74A000
|
heap default
|
page read and write
|
||
11D0000
|
unkown
|
page read and write
|
||
4A6E000
|
stack
|
page read and write
|
||
2F14000
|
unkown
|
page read and write
|
||
2F70000
|
unkown image
|
page readonly
|
||
2E89000
|
unkown image
|
page readonly
|
||
12FE000
|
stack
|
page read and write
|
||
27F3000
|
unkown image
|
page readonly
|
||
D9C000
|
unkown
|
page read and write
|
||
7F860000
|
unkown image
|
page readonly
|
||
225A000
|
heap private
|
page read and write
|
||
19F8000
|
heap private
|
page read and write
|
||
6EDA1000
|
unkown image
|
page execute read
|
||
2E95000
|
unkown image
|
page readonly
|
||
C20000
|
unkown
|
page read and write
|
||
6D0000
|
stack
|
page read and write
|
||
3180000
|
unkown image
|
page readonly
|
||
2E5D000
|
unkown image
|
page readonly
|
||
2EC6000
|
unkown image
|
page readonly
|
||
A10000
|
unkown image
|
page readonly
|
||
2F11000
|
unkown image
|
page readonly
|
||
7F872000
|
unkown image
|
page readonly
|
||
2C57000
|
unkown
|
page read and write
|
||
27CA000
|
unkown image
|
page readonly
|
||
26F6000
|
unkown image
|
page readonly
|
||
26D3000
|
unkown image
|
page readonly
|
||
7F0C2000
|
unkown image
|
page readonly
|
||
7F832000
|
unkown image
|
page readonly
|
||
A50000
|
unkown image
|
page readonly
|
||
AF0000
|
unkown image
|
page read and write
|
||
6EDA1000
|
unkown image
|
page execute read
|
||
597E000
|
stack
|
page read and write
|
||
4A2F000
|
stack
|
page read and write
|
||
7F842000
|
unkown image
|
page readonly
|
||
2E3C000
|
unkown image
|
page readonly
|
||
2ECB000
|
unkown image
|
page readonly
|
||
2E73000
|
unkown image
|
page readonly
|
||
3420000
|
unkown image
|
page readonly
|
||
700000
|
stack
|
page read and write
|
||
2EC2000
|
unkown image
|
page readonly
|
||
2FB0000
|
unkown
|
page read and write
|
||
977000
|
unkown
|
page read and write
|
||
1C0000
|
unkown image
|
page readonly
|
||
6EDC3000
|
unkown image
|
page read and write
|
||
7EFE2000
|
unkown image
|
page readonly
|
||
2F50000
|
unkown image
|
page readonly
|
||
31C000
|
unkown
|
page read and write
|
||
2EC2000
|
unkown image
|
page readonly
|
||
2E80000
|
unkown image
|
page readonly
|
||
2F15000
|
unkown image
|
page readonly
|
||
2FB0000
|
unkown
|
page read and write
|
||
27FB000
|
unkown image
|
page readonly
|
||
6EDA0000
|
unkown image
|
page readonly
|
||
31D7000
|
heap private
|
page read and write
|
||
700000
|
stack
|
page read and write
|
||
4AAF000
|
stack
|
page read and write
|
||
2D19000
|
unkown image
|
page readonly
|
||
6EDA0000
|
unkown image
|
page readonly
|
||
7FE90000
|
unkown image
|
page readonly
|
||
2C65000
|
unkown image
|
page readonly
|
||
1B0E000
|
stack
|
page read and write
|
||
700000
|
unkown image
|
page readonly
|
||
11D0000
|
unkown
|
page read and write
|
||
282F000
|
unkown image
|
page readonly
|
||
963000
|
unkown
|
page read and write
|
||
1421000
|
unkown
|
page read and write
|
||
FC6000
|
unkown
|
page read and write
|
||
2F17000
|
unkown
|
page read and write
|
||
1430000
|
unkown
|
page read and write
|
||
2E80000
|
unkown image
|
page readonly
|
||
2E9F000
|
unkown image
|
page readonly
|
||
27C3000
|
unkown image
|
page readonly
|
||
CE0000
|
unkown image
|
page readonly
|
||
2E65000
|
unkown image
|
page readonly
|
||
7FD42000
|
unkown image
|
page readonly
|
||
1434000
|
heap default
|
page read and write
|
||
7FE90000
|
unkown image
|
page readonly
|
||
700000
|
stack
|
page read and write
|
||
360000
|
unkown image
|
page readonly
|
||
2E7C000
|
unkown image
|
page readonly
|
||
2EC6000
|
unkown image
|
page readonly
|
||
7F870000
|
unkown image
|
page readonly
|
||
505F000
|
stack
|
page read and write
|
||
7EFF2000
|
unkown image
|
page readonly
|
||
110000
|
unkown image
|
page readonly
|
||
114E000
|
stack
|
page read and write
|
There are 717 hidden memdumps, click here to show them.