IOC Report

loading gif

Files

File Path
Type
Category
Malicious
2W6FcgEeMy.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\E5F0NRSV\www.msn[2].xml
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\URW0GA4Q\contextual.media[1].xml
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{EBFDF002-4B97-11EC-90EB-ECF4BBEA1588}.dat
Composite Document File V2 Document, Cannot read section info
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{EBFDF004-4B97-11EC-90EB-ECF4BBEA1588}.dat
Composite Document File V2 Document, Cannot read section info
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\gee00pr\imagestore.dat
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\17-361657-68ddb2ab[1].js
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\55a804ab-e5c6-4b97-9319-86263d365d28[1].json
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AA7XCQ3[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAMqFmF[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAPFmi4[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQBdIv[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 622x368, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQXXJy[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQXevg[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQXiy5[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQXrMl[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQY08U[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 311x333, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQYPIL[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 311x333, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQYUQR[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQYUU3[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 311x333, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQYVTM[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQYYTT[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 311x333, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQYrvs[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 622x368, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\AAQYvQT[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 622x368, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\BB7hg4[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\BBUZVvV[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\a5ea21[1].ico
PNG image data, 32 x 32, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\cfdbd9[1].png
PNG image data, 27 x 27, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\checksync[1].htm
HTML document, ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\checksync[2].htm
HTML document, ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\checksync[3].htm
HTML document, ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\otCommonStyles[1].css
ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\otFlat[1].json
ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\otPcCenter[2].json
ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\otSDKStub[1].js
ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\264bf325-c7e4-4939-8912-2424a7abe532[1].jpg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 300x300, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\AAOdxvW[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 622x368, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\AAOr6Ee[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 622x368, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\AAQTQg3[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\AAQY4m2[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\AAQY5wp[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 311x333, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\AAQY8Zl[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\AAQYCwH[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 622x368, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\AAQYWm8[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\AAQYqMl[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 311x333, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\AAycUpK[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\BB10MkbM[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\BB7hjL[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\de-ch[2].json
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\f69ed47f-3ddb-476a-9d92-3f337b2721b0[1].jpg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 300x300, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\favicon[2].ico
MS Windows icon resource - 2 icons, 16x16, 16 colors, 32x32, 16 colors
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\iab2Data[2].json
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\medianet[1].htm
HTML document, ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\medianet[2].htm
HTML document, ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\otTCF-ie[1].js
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\px[1].gif
GIF image data, version 89a, 1 x 1
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\4996b9[1].woff
Web Open Font Format, TrueType, length 45633, version 1.0
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAPQoxX[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 622x368, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAQVPm6[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 100x75, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAQVtAu[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 622x368, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAQW0Fs[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 100x75, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAQY2pC[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 100x75, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAQY5UV[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAQY7HF[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 300x250, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAQYCIb[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 311x333, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAQYV96[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 311x333, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAQYd7s[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 206x250, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAQYvGE[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 300x250, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAQZ3BL[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 100x75, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAud6Gv[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\AAzb5EX[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\BB1ftEY0[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\BBMW3y8[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\BBVuddh[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\BBY7ARN[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\checksync[3].htm
HTML document, ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\nrrV52461[1].js
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\nrrV52461[2].js
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\otBannerSdk[1].js
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\tag[1].js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\2d-0e97d4-185735b[1].css
UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\52-478955-68ddb2ab[1].js
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\AAKp8YX[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\AAPwesU[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\AAQCmUS[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 622x368, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\AAQT0oN[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 622x368, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\AAQXTtj[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 311x333, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\AAQXYTC[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 310x166, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\AAQY2dE[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 311x333, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\AAQYSOX[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 310x166, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\AAQYSTg[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 622x368, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\AAQYULr[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 311x333, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\BB1aXBV1[1].png
PNG image data, 27 x 27, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\BB1cEP3G[1].png
PNG image data, 27 x 27, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\BB1cG73h[1].png
PNG image data, 27 x 27, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\BB1fdtSt[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
modified
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\BB1kc8s[1].png
PNG image data, 30 x 30, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\BB6Ma4a[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\BB7gRE[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\BBPfCZL[1].png
GIF image data, version 89a, 50 x 50
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\BBX2afX[1].png
PNG image data, 27 x 27, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\a8a064[1].gif
GIF image data, version 89a, 28 x 28
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\de-ch[1].htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\e151e5[1].gif
GIF image data, version 89a, 1 x 1
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\jquery-2.1.1.min[1].js
ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF511C5929B225C7AA.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF7F454687EFA0D2F9.TMP
data
dropped
clean
There are 106 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Windows\System32\loaddll32.exe
loaddll32.exe "C:\Users\user\Desktop\2W6FcgEeMy.dll"
malicious
C:\Windows\SysWOW64\regsvr32.exe
regsvr32.exe /s C:\Users\user\Desktop\2W6FcgEeMy.dll
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe "C:\Users\user\Desktop\2W6FcgEeMy.dll",#1
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe C:\Users\user\Desktop\2W6FcgEeMy.dll,DllRegisterServer
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe C:\Users\user\Desktop\2W6FcgEeMy.dll,adqehmqaggtoqofda
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe C:\Users\user\Desktop\2W6FcgEeMy.dll,awkikcxxkllcr
malicious
C:\Windows\SysWOW64\cmd.exe
cmd.exe /C rundll32.exe "C:\Users\user\Desktop\2W6FcgEeMy.dll",#1
clean
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:6068 CREDAT:17410 /prefetch:2
clean

URLs

Name
IP
Malicious
http://avolebukoneh.website
unknown
malicious
http://technoshoper.com
unknown
malicious
https://avolebukoneh.website
unknown
malicious
https://ad-delivery.net/px.gif?ch=1&e=0.5207611127885279
172.67.69.19
clean
https://aka.ms/MicrosoftEdgeDownload"
unknown
clean
https://assets.msn.com/staticsb/statics/latest/oneTrust/1.2/consent/55a804ab-e5c6-4b97-9319-86263d36
unknown
clean
http://searchads.msn.net/.cfm?&&kp=1&
unknown
clean
https://contextual.media.net/medianet.php?cid=8CU157172
unknown
clean
https://www.msn.com/de-ch/nachrichten/coronareisen
unknown
clean
https://www.msn.com/de-ch/news/other/jacqueline-hofer-tritt-doch-nicht-zur-wiederwahl-an/ar-AAQTAnf?
unknown
clean
https://www.msn.com/de-ch/news/other/sie-bew%c3%a4ltigen-alltagsstress-und-todesszenen/ar-AAQUall?oc
unknown
clean
https://www.google.com/favicon.ico~
unknown
clean
https://click.linksynergy.com/deeplink?id=xoqYgl4JDe8&mid=46130&u1=dech_promotionalstripe_na
unknown
clean
https://onedrive.live.com;Fotos
unknown
clean
https://www.msn.com/de-ch/sport?ocid=StripeOCID
unknown
clean
https://www.onenote.com/notebooks?WT.mc_id=MSN_OneNote_TopMenu&auth=1&wdorigin=msn
unknown
clean
https://office.live.com/start/Word.aspx?WT.mc_id=MSN_site;Excel
unknown
clean
https://www.msn.com/de-ch/sport/fussball/der-fcz-zittert-und-steht-doch-ganz-oben/ar-AAQWrxt?ocid=hp
unknown
clean
https://www.msn.com/de-ch/news/other/mehrere-tausend-menschen-demonstrieren-in-z%c3%bcrich/ar-AAQWtO
unknown
clean
http://ogp.me/ns/fb#
unknown
clean
https://www.botman.ninja/privacy-policy
unknown
clean
https://outlook.live.com/mail/deeplink/compose;Kalender
unknown
clean
https://res-a.akamaihd.net/__media__/pics/8000/72/941/fallback1.jpg
unknown
clean
https://www.queryclick.com/privacy-policy
unknown
clean
https://www.skyscanner.net/g/referrals/v1/cars/home?associateid=API_B2B_19305_00002
unknown
clean
https://www.onenote.com/notebooks?WT.mc_id=MSN_OneNote_Recent&auth=1&wdorigin=msn
unknown
clean
https://www.msn.com/de-ch/news/other/t%c3%b6fffahrer-st%c3%bcrzt-nach-verfolgungsjagd-mit-der-polize
unknown
clean
https://www.msn.com/de-ch/news/other/t%c3%b6fffahrer-liefert-sich-wilde-verfolgungsjagd-mit-der-poli
unknown
clean
https://btloader.com/tag?o=6208086025961472&upapi=true
172.67.70.134
clean
http://www.reddit.com/
unknown
clean
https://www.skype.com/
unknown
clean
https://clkde.tradedoubler.com/click?p=245744&a=3064090&g=24545562
unknown
clean
https://sp.booking.com/index.html?aid=1589774&label=travelnavlink
unknown
clean
https://www.msn.com/de-ch/nachrichten/regional
unknown
clean
https://www.stroeer.de/werben-mit-stroeer/onlinewerbung/programmatic-data/sdi-datenschutz-b2c
unknown
clean
https://onedrive.live.com/?qt=allmyphotos;Aktuelle
unknown
clean
http://avolebukoneh.website/glik/.lwe.bmp088991256473871MNTYA%-
unknown
clean
https://amzn.to/2TTxhNg
unknown
clean
https://www.skype.com/go/onedrivepromo.download?cm_mmc=MSFT_2390_MSN-com
unknown
clean
https://client-s.gateway.messenger.live.com
unknown
clean
https://secure.adnxs.com/clktrb?id=764680&t=1
unknown
clean
https://www.msn.com/de-ch/
unknown
clean
https://office.live.com/start/PowerPoint.aspx?WT.mc_id=MSN_site
unknown
clean
https://contextual.media.net/medianet.php?cid=8CU157172&crid=858412214&size=306x271&https=1
unknown
clean
https://www.msn.com/de-ch
unknown
clean
https://click.linksynergy.com/deeplink?id=xoqYgl4JDe8&mid=46130&u1=dech_mestripe_store&m
unknown
clean
https://twitter.com/i/notifications;Ich
unknown
clean
https://contextual.media.net/medianet.php?cid=8CU157172&crid=722878611&size=306x271&http
unknown
clean
https://www.google.com/favicon.ico
unknown
clean
https://ad.doubleclick.net/favicon.ico?ad=300x250&ad_box_=1&adnet=1&showad=1&size=250x250
216.58.215.230
clean
https://nextmillennium.io/privacy-policy/
unknown
clean
https://silvermob.com/privacy
unknown
clean
https://www.sway.com/?WT.mc_id=MSN_site&utm_source=MSN&utm_medium=Topnav&utm_campaign=link;PowerPoin
unknown
clean
https://www.msn.com/de-ch/?ocid=iehp&item=deferred_page%3a1&ignorejs=webcore%2fmodules%2fjsb
unknown
clean
http://www.youtube.com/
unknown
clean
http://ogp.me/ns#
unknown
clean
http://schema.org/Organization
unknown
clean
https://play.google.com/store/apps/details?id=com.microsoft.amp.apps.bingnews&hl=de-ch&refer
unknown
clean
https://onedrive.live.com/?qt=mru;OneDrive-App
unknown
clean
https://www.skype.com/de
unknown
clean
https://www.tippsundtricks.co/lifehacks/schwamm-kuhlschrank/?utm_campaign=DECH-schwamm&utm_sourc
unknown
clean
https://sp.booking.com/index.html?aid=1589774&label=dech-prime-hp-me
unknown
clean
https://tools.applemediaservices.com/api/badges/download-on-the-app-store/black/de-de?"
unknown
clean
https://www.skype.com/de/download-skype
unknown
clean
https://onedrive.live.com/?wt.mc_id=oo_msn_msnhomepage_header
unknown
clean
http://www.hotmail.msn.com/pii/ReadOutlookEmail/
unknown
clean
https://onedrive.live.com;OneDrive-App
unknown
clean
https://www.msn.com/de-ch/news/other/bei-den-%c3%a4rzten-schauen-die-beh%c3%b6rden-einfach-weg/ar-AA
unknown
clean
https://click.linksynergy.com/deeplink?id=xoqYgl4JDe8&mid=46130&u1=dech_mestripe_office&
unknown
clean
https://clkde.tradedoubler.com/click?p=295926&a=3064090&g=24886692
unknown
clean
https://www.google.com/chrome/static/images/favicons/favicon-16x16.png
unknown
clean
https://geolocation.onetrust.com/cookieconsentpub/v1/geo/location
unknown
clean
http://www.amazon.com/
unknown
clean
https://www.onenote.com/notebooks?WT.mc_id=MSN_OneNote_QuickNote&auth=1
unknown
clean
http://avolebukoneh.website/glik/.lwe.bmp08899
unknown
clean
https://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.9.1.min.js
unknown
clean
http://www.twitter.com/
unknown
clean
https://office.live.com/start/Excel.aspx?WT.mc_id=MSN_site;Sway
unknown
clean
https://cdn.cookielaw.org/vendorlist/googleData.json
unknown
clean
https://clkde.tradedoubler.com/click?p=195119&a=3064090&g=25021476
unknown
clean
https://outlook.com/
unknown
clean
https://play.google.com/intl/en_us/badges/images/generic/de_badge_web_generic.png"
unknown
clean
https://contextual.media.net/checksync.php?&vsSync=1&cs=1&hb=1&cv=37&ndec=1&cid=8HBI57XIG&prvid=77%2
unknown
clean
https://www.stroeer.com/fileadmin/com/StroeerDSP_deviceStorage.json
unknown
clean
https://cdn.cookielaw.org/vendorlist/iabData.json
unknown
clean
https://onedrive.live.com/?qt=mru;Aktuelle
unknown
clean
https://www.msn.com/de-ch/?ocid=iehp
unknown
clean
https://sp.booking.com/index.html?aid=1589774&label=dech-prime-hp-shoppingstripe-nav
unknown
clean
https://www.ebay.ch/?mkcid=1&mkrid=5222-53480-19255-0&siteid=193&campid=5338626668&t
unknown
clean
https://doceree.com/.well-known/deviceStorage.json
unknown
clean
http://www.nytimes.com/
unknown
clean
https://web.vortex.data.msn.com/collect/v1/t.gif?name=%27Ms.Webi.PageView%27&ver=%272.1%27&a
unknown
clean
https://www.msn.com/de-ch/sport/other/runter-rauf-runter-wie-gc-in-genf-vom-weg-abkommt/ar-AAQYdQe?o
unknown
clean
https://www.bidstack.com/privacy-policy/
unknown
clean
https://onedrive.live.com/about/en/download/
unknown
clean
https://www.msn.com/de-ch/news/other/defektes-paket-mit-radioaktivem-inhalt-in-swiss-flieger-entdeck
unknown
clean
https://www.ricardo.ch/?utm_source=msn&utm_medium=affiliate&utm_campaign=msn_mestripe_logo_d
unknown
clean
https://twitter.com/
unknown
clean
http://avolebukoneh.website/glik/.lwe.bmp088991256473871MNTYA
unknown
clean
https://www.stroeer.de/ssp-datenschutz
unknown
clean
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
contextual.media.net
2.18.160.23
clean
avolebukoneh.website
37.120.206.119
clean
dart.l.doubleclick.net
216.58.215.230
clean
hblg.media.net
2.18.160.23
clean
lg3.media.net
2.18.160.23
clean
technoshoper.com
45.9.20.245
clean
btloader.com
172.67.70.134
clean
ad-delivery.net
172.67.69.19
clean
assets.msn.com
unknown
clean
web.vortex.data.msn.com
unknown
clean
www.msn.com
unknown
clean
ad.doubleclick.net
unknown
clean
cvision.media.net
unknown
clean
There are 3 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
172.67.69.19
ad-delivery.net
United States
clean
45.9.20.245
technoshoper.com
Russian Federation
clean
216.58.215.230
dart.l.doubleclick.net
United States
clean
172.67.70.134
btloader.com
United States
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\AdminActive
{EBFDF002-4B97-11EC-90EB-ECF4BBEA1588}
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\iexplore
Count
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\iexplore
Time
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\iexplore
Blocked
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
LoadTimeArray
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTimeArray
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation
CVListPingLastYMD
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation
CVListPingBitmap
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation
CVListPingRandomizedBitmap
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DomainSuggestion
NextUpdateDate
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\NewTabPage
DecayDateQueue
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\NewTabPage
LastProcessed
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\NewTabPage
DecayDateQueue
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\NewTabPage
LastProcessed
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\www.msn.com
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\msn.com
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\msn.com
NumberOfSubdomains
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\contextual.media.net
NULL
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\media.net
Total
clean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
NULL
clean
There are 84 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
4919000
heap private
page read and write
malicious
4F48000
heap private
page read and write
malicious
1100000
unkown
page execute and read and write
malicious
6F0000
stack
page execute and read and write
malicious
531B000
heap private
page read and write
malicious
5498000
heap private
page read and write
malicious
4F48000
heap private
page read and write
malicious
4F48000
heap private
page read and write
malicious
2258000
heap private
page read and write
malicious
5498000
heap private
page read and write
malicious
4FB9000
heap private
page read and write
malicious
5498000
heap private
page read and write
malicious
2F90000
unkown
page read and write
malicious
4F48000
heap private
page read and write
malicious
5498000
heap private
page read and write
malicious
6E0000
stack
page read and write
malicious
2258000
heap private
page read and write
malicious
5498000
heap private
page read and write
malicious
4F48000
heap private
page read and write
malicious
4F48000
heap private
page read and write
malicious
4F48000
heap private
page read and write
malicious
2258000
heap private
page read and write
malicious
5498000
heap private
page read and write
malicious
2258000
heap private
page read and write
malicious
2258000
heap private
page read and write
malicious
4F48000
heap private
page read and write
malicious
4F48000
heap private
page read and write
malicious
2258000
heap private
page read and write
malicious
5498000
heap private
page read and write
malicious
10F0000
unkown
page read and write
malicious
2258000
heap private
page read and write
malicious
5498000
heap private
page read and write
malicious
2258000
heap private
page read and write
malicious
1979000
heap private
page read and write
malicious
4F48000
heap private
page read and write
malicious
2FA0000
unkown
page execute and read and write
malicious
2258000
heap private
page read and write
malicious
5498000
heap private
page read and write
malicious
2258000
heap private
page read and write
malicious
1432000
unkown
page read and write
clean
49CE000
stack
page read and write
clean
2D19000
unkown image
page readonly
clean
A50000
unkown
page read and write
clean
2FB0000
unkown
page read and write
clean
1340000
unkown image
page read and write
clean
49EE000
stack
page read and write
clean
2EB1000
heap default
page read and write
clean
700000
stack
page read and write
clean
1540000
unkown
page read and write
clean
CCE000
stack
page read and write
clean
2F43000
unkown image
page readonly
clean
1AB000
unkown
page read and write
clean
10E0000
unkown
page read and write
clean
11D0000
unkown
page read and write
clean
2F43000
unkown image
page readonly
clean
2E9F000
unkown image
page readonly
clean
2E43000
unkown image
page readonly
clean
11D0000
unkown
page read and write
clean
2FB0000
unkown
page read and write
clean
2D53000
unkown image
page readonly
clean
2C4B000
unkown
page read and write
clean
2EC9000
heap default
page read and write
clean
7FE70000
unkown image
page readonly
clean
7F862000
unkown image
page readonly
clean
28AC000
unkown image
page readonly
clean
27AC000
unkown image
page readonly
clean
2470000
unkown image
page readonly
clean
700000
stack
page read and write
clean
11CE000
stack
page read and write
clean
6FB000
unkown
page read and write
clean
DC0000
unkown image
page readonly
clean
2F43000
unkown image
page readonly
clean
281F000
unkown image
page readonly
clean
11D0000
unkown
page read and write
clean
11D0000
unkown
page read and write
clean
A40000
unkown image
page read and write
clean
2D76000
unkown image
page readonly
clean
2E80000
unkown image
page readonly
clean
2F15000
unkown
page read and write
clean
7F842000
unkown image
page readonly
clean
780000
heap private
page read and write
clean
2E39000
unkown image
page readonly
clean
6EDA0000
unkown image
page readonly
clean
2E9F000
unkown image
page readonly
clean
137C000
heap default
page read and write
clean
11D0000
unkown
page read and write
clean
134D000
unkown image
page read and write
clean
2E39000
unkown image
page readonly
clean
3570000
unkown image
page readonly
clean
660000
unkown image
page readonly
clean
2F15000
unkown image
page readonly
clean
2F24000
unkown image
page readonly
clean
7FE72000
unkown image
page readonly
clean
2E89000
unkown image
page readonly
clean
2FE5000
heap default
page read and write
clean
A50000
unkown image
page readonly
clean
7FD50000
unkown image
page readonly
clean
2E5D000
unkown image
page readonly
clean
500000
unkown image
page readonly
clean
2EAF000
unkown image
page readonly
clean
2823000
unkown image
page readonly
clean
2E24000
unkown image
page readonly
clean
593E000
stack
page read and write
clean
B00000
unkown image
page readonly
clean
2BE0000
unkown image
page readonly
clean
11D0000
unkown
page read and write
clean
2FDF000
unkown image
page readonly
clean
25E5000
unkown image
page readonly
clean
11D0000
unkown
page read and write
clean
2D10000
unkown image
page readonly
clean
2FE0000
heap default
page read and write
clean
CCA000
heap default
page read and write
clean
28B8000
unkown image
page readonly
clean
5120000
unkown
page read and write
clean
2E7C000
unkown image
page readonly
clean
3620000
unkown image
page readonly
clean
2EA2000
unkown
page read and write
clean
740000
heap default
page read and write
clean
2815000
unkown image
page readonly
clean
2E2C000
unkown image
page readonly
clean
58B000
unkown
page read and write
clean
11D0000
unkown
page read and write
clean
13FE000
heap default
page read and write
clean
2F24000
unkown image
page readonly
clean
700000
stack
page read and write
clean
7F832000
unkown image
page readonly
clean
6EDAE000
unkown image
page readonly
clean
549C000
heap private
page read and write
clean
2FB0000
unkown
page read and write
clean
7FD30000
unkown image
page readonly
clean
4A5E000
stack
page read and write
clean
11D0000
unkown
page read and write
clean
2EC2000
unkown image
page readonly
clean
2E97000
unkown image
page readonly
clean
1435000
unkown
page read and write
clean
700000
stack
page read and write
clean
501E000
stack
page read and write
clean
2E39000
unkown image
page readonly
clean
2FB0000
unkown
page read and write
clean
11D0000
unkown
page read and write
clean
3300000
unkown image
page readonly
clean
5080000
unkown
page read and write
clean
11D0000
unkown
page read and write
clean
2F43000
unkown image
page readonly
clean
2B30000
unkown image
page readonly
clean
2EAF000
unkown image
page readonly
clean
2ECB000
unkown image
page readonly
clean
710000
unkown image
page readonly
clean
1600000
heap private
page read and write
clean
2F38000
unkown image
page readonly
clean
152E000
stack
page read and write
clean
2E65000
unkown image
page readonly
clean
2C60000
unkown
page read and write
clean
2638000
unkown image
page readonly
clean
2600000
unkown image
page readonly
clean
F90000
heap default
page read and write
clean
5080000
unkown
page read and write
clean
B60000
unkown image
page readonly
clean
2E95000
unkown image
page readonly
clean
7EFF2000
unkown image
page readonly
clean
2EA4000
heap default
page read and write
clean
1350000
unkown image
page readonly
clean
414D000
stack
page read and write
clean
2E30000
unkown
page read and write
clean
4A6F000
unkown
page read and write
clean
3C0000
unkown
page read and write
clean
7F000000
unkown image
page readonly
clean
2F11000
unkown image
page readonly
clean
31D0000
heap private
page read and write
clean
282A000
unkown image
page readonly
clean
6EDC7000
unkown image
page readonly
clean
7F0D0000
unkown image
page readonly
clean
2D10000
unkown image
page readonly
clean
26E8000
unkown image
page readonly
clean
3F4F000
stack
page read and write
clean
AF0000
unkown image
page readonly
clean
7EFF0000
unkown image
page readonly
clean
2E9D000
unkown image
page readonly
clean
27EC000
unkown image
page readonly
clean
549A000
heap private
page read and write
clean
2FDD000
unkown image
page read and write
clean
13C4000
heap default
page read and write
clean
2ED5000
heap default
page read and write
clean
2E95000
unkown image
page readonly
clean
1540000
unkown
page read and write
clean
AAC000
unkown
page read and write
clean
2FB0000
unkown
page read and write
clean
31E0000
unkown image
page readonly
clean
1341000
unkown image
page execute read
clean
2891000
unkown image
page readonly
clean
6EDA0000
unkown image
page readonly
clean
2E3C000
unkown image
page readonly
clean
3E4F000
stack
page read and write
clean
2EAA000
unkown image
page readonly
clean
B00000
unkown image
page readonly
clean
2FD0000
unkown image
page read and write
clean
4BD0000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
2FB0000
unkown
page read and write
clean
6EDA0000
unkown image
page readonly
clean
11D0000
unkown
page read and write
clean
6EDA0000
unkown image
page readonly
clean
6EDC3000
unkown image
page read and write
clean
2EAA000
unkown image
page readonly
clean
14EE000
stack
page read and write
clean
1105000
unkown
page execute and read and write
clean
133C000
stack
page read and write
clean
3E0000
unkown image
page readonly
clean
7F880000
unkown image
page readonly
clean
2F43000
unkown image
page readonly
clean
582E000
stack
page read and write
clean
3560000
unkown image
page readonly
clean
2EAF000
unkown image
page readonly
clean
700000
stack
page read and write
clean
4B30000
unkown
page read and write
clean
700000
stack
page read and write
clean
2FB0000
unkown
page read and write
clean
2D19000
unkown image
page readonly
clean
4F9D000
stack
page read and write
clean
7F840000
unkown image
page readonly
clean
8F7000
heap private
page read and write
clean
586F000
stack
page read and write
clean
4ADD000
stack
page read and write
clean
7F0B2000
unkown image
page readonly
clean
2E65000
unkown image
page readonly
clean
2FB0000
unkown
page read and write
clean
2270000
unkown image
page readonly
clean
1070000
unkown image
page readonly
clean
11D0000
unkown
page read and write
clean
11D0000
unkown
page read and write
clean
2E3C000
unkown image
page readonly
clean
2E89000
unkown image
page readonly
clean
5AF000
stack
page read and write
clean
2ECB000
unkown image
page readonly
clean
7F0C2000
unkown image
page readonly
clean
7F850000
unkown image
page readonly
clean
2831000
unkown image
page readonly
clean
6EDAE000
unkown image
page readonly
clean
25F3000
unkown image
page readonly
clean
2FB0000
unkown
page read and write
clean
2ECB000
unkown image
page readonly
clean
FC3000
unkown
page read and write
clean
2846000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
710000
unkown image
page read and write
clean
6EDC7000
unkown image
page readonly
clean
4F4B000
heap private
page read and write
clean
28A4000
unkown image
page readonly
clean
11D0000
unkown
page read and write
clean
7FD40000
unkown image
page readonly
clean
7F0B0000
unkown image
page readonly
clean
11D0000
unkown
page read and write
clean
25C7000
unkown image
page readonly
clean
11D0000
unkown
page read and write
clean
2F32000
unkown image
page readonly
clean
2E4A000
unkown image
page readonly
clean
7FE82000
unkown image
page readonly
clean
1B0000
unkown image
page readonly
clean
2E7B000
unkown image
page readonly
clean
2842000
unkown image
page readonly
clean
2E9D000
heap default
page read and write
clean
7F730000
unkown image
page readonly
clean
2D19000
unkown image
page readonly
clean
11D0000
unkown
page read and write
clean
2EA3000
unkown image
page readonly
clean
5C0000
unkown
page read and write
clean
27B9000
unkown image
page readonly
clean
1D0B000
stack
page read and write
clean
7FE70000
unkown image
page readonly
clean
9DD000
unkown
page read and write
clean
33E0000
unkown image
page readonly
clean
F10000
unkown image
page readonly
clean
7F850000
unkown image
page readonly
clean
7F0C0000
unkown image
page readonly
clean
2D68000
unkown image
page readonly
clean
340000
unkown
page read and write
clean
790000
unkown image
page readonly
clean
2EC6000
unkown image
page readonly
clean
4BAC000
stack
page read and write
clean
2817000
unkown image
page readonly
clean
7FE80000
unkown image
page readonly
clean
FC0000
unkown image
page readonly
clean
5050000
unkown
page read and write
clean
31BB000
stack
page read and write
clean
DA0000
unkown image
page readonly
clean
6F5000
stack
page execute and read and write
clean
2E3C000
unkown image
page readonly
clean
6EDA0000
unkown image
page readonly
clean
313E000
stack
page read and write
clean
4F4D000
heap private
page read and write
clean
2FB0000
unkown
page read and write
clean
5419000
heap private
page read and write
clean
D85000
unkown
page read and write
clean
B00000
unkown image
page readonly
clean
6EDC3000
unkown image
page read and write
clean
2FB0000
unkown
page read and write
clean
700000
stack
page read and write
clean
CD0000
heap private
page read and write
clean
4C40000
heap private
page read and write
clean
969000
unkown
page read and write
clean
1C0F000
stack
page read and write
clean
2C5A000
unkown
page read and write
clean
7F0C0000
unkown image
page readonly
clean
45A0000
heap private
page read and write
clean
15DD000
stack
page read and write
clean
D81000
unkown
page read and write
clean
2C54000
unkown
page read and write
clean
6BC000
unkown
page read and write
clean
7FE72000
unkown image
page readonly
clean
FB7000
unkown
page read and write
clean
900000
unkown image
page readonly
clean
6EDAE000
unkown image
page readonly
clean
317C000
stack
page read and write
clean
963000
unkown
page read and write
clean
2C41000
unkown
page read and write
clean
2F15000
unkown image
page readonly
clean
50A0000
heap private
page read and write
clean
2FB0000
unkown
page read and write
clean
71D000
unkown image
page read and write
clean
2FB0000
unkown
page read and write
clean
700000
stack
page read and write
clean
2EB1000
unkown
page read and write
clean
4F4C000
heap private
page read and write
clean
FC0000
unkown
page read and write
clean
2D37000
unkown image
page readonly
clean
2F32000
unkown image
page readonly
clean
2FB0000
unkown
page read and write
clean
11D0000
unkown
page read and write
clean
332A000
heap default
page read and write
clean
6EDA1000
unkown image
page execute read
clean
2D10000
unkown image
page readonly
clean
2E9D000
unkown image
page readonly
clean
700000
stack
page read and write
clean
760000
unkown
page read and write
clean
11D0000
unkown
page read and write
clean
6EDAE000
unkown image
page readonly
clean
3320000
heap default
page read and write
clean
971000
unkown
page read and write
clean
71C000
unkown image
page readonly
clean
142E000
heap default
page read and write
clean
560000
heap default
page read and write
clean
B70000
unkown image
page readonly
clean
2FB0000
unkown
page read and write
clean
975000
unkown
page read and write
clean
2E97000
unkown
page read and write
clean
4FDB000
stack
page read and write
clean
30FE000
stack
page read and write
clean
2E73000
unkown image
page readonly
clean
A3F000
stack
page read and write
clean
2D37000
unkown image
page readonly
clean
2FB0000
unkown
page read and write
clean
2B8C000
unkown
page read and write
clean
2E43000
unkown image
page readonly
clean
4700000
heap private
page read and write
clean
11D0000
unkown
page read and write
clean
F20000
unkown image
page readonly
clean
4B6D000
stack
page read and write
clean
9DF000
unkown
page read and write
clean
26F1000
unkown image
page readonly
clean
142C000
unkown
page read and write
clean
2C0000
unkown image
page readonly
clean
142E000
unkown
page read and write
clean
755000
heap default
page read and write
clean
71F000
unkown image
page readonly
clean
4290000
unkown
page read and write
clean
404D000
stack
page read and write
clean
7FD42000
unkown image
page readonly
clean
225D000
heap private
page read and write
clean
2800000
unkown image
page readonly
clean
2F43000
unkown image
page readonly
clean
5080000
unkown
page read and write
clean
8F0000
heap private
page read and write
clean
2D68000
unkown image
page readonly
clean
418E000
stack
page read and write
clean
118D000
stack
page read and write
clean
DF0000
unkown
page read and write
clean
2EB1000
unkown image
page readonly
clean
2699000
unkown image
page readonly
clean
5038000
heap private
page read and write
clean
2C5D000
unkown
page read and write
clean
2FDC000
unkown image
page readonly
clean
2C73000
unkown image
page readonly
clean
7FD70000
unkown image
page readonly
clean
7F0B2000
unkown image
page readonly
clean
760000
unkown image
page readonly
clean
700000
stack
page read and write
clean
700000
stack
page read and write
clean
2F17000
unkown
page read and write
clean
134C000
unkown image
page readonly
clean
7FD32000
unkown image
page readonly
clean
2E97000
unkown image
page readonly
clean
4998000
heap private
page read and write
clean
2EA3000
unkown image
page readonly
clean
2E4A000
unkown image
page readonly
clean
2E40000
heap default
page read and write
clean
7F0000
unkown image
page readonly
clean
C10000
unkown image
page readonly
clean
FA4000
unkown
page read and write
clean
A40000
unkown image
page readonly
clean
2E73000
unkown image
page readonly
clean
134F000
unkown image
page readonly
clean
2F43000
unkown image
page readonly
clean
7F760000
unkown image
page readonly
clean
4F4A000
heap private
page read and write
clean
27A4000
unkown image
page readonly
clean
FA8000
unkown
page read and write
clean
5E0000
unkown image
page readonly
clean
2EC2000
unkown image
page readonly
clean
1423000
heap default
page read and write
clean
2E6C000
unkown image
page readonly
clean
7F860000
unkown image
page readonly
clean
428F000
stack
page read and write
clean
11D0000
unkown
page read and write
clean
700000
stack
page read and write
clean
549B000
heap private
page read and write
clean
2809000
unkown image
page readonly
clean
700000
stack
page read and write
clean
2E73000
unkown image
page readonly
clean
BD0000
unkown image
page readonly
clean
7F880000
unkown image
page readonly
clean
2F24000
unkown image
page readonly
clean
2BD0000
unkown image
page readonly
clean
2D37000
unkown image
page readonly
clean
9E2000
unkown
page read and write
clean
25F0000
unkown image
page readonly
clean
1550000
heap private
page read and write
clean
13B4000
heap default
page read and write
clean
55E000
stack
page read and write
clean
7F840000
unkown image
page readonly
clean
2E39000
unkown image
page readonly
clean
7EE000
stack
page read and write
clean
26B7000
unkown image
page readonly
clean
50DE000
stack
page read and write
clean
FBD000
unkown
page read and write
clean
2F38000
unkown image
page readonly
clean
2B0000
unkown image
page read and write
clean
2E95000
heap default
page read and write
clean
5080000
unkown
page read and write
clean
2E95000
unkown image
page readonly
clean
BE0000
unkown
page read and write
clean
2F32000
unkown image
page readonly
clean
2F24000
unkown image
page readonly
clean
284B000
unkown image
page readonly
clean
7FD30000
unkown image
page readonly
clean
11D0000
unkown
page read and write
clean
7FE82000
unkown image
page readonly
clean
25E7000
unkown image
page readonly
clean
2FB0000
unkown
page read and write
clean
2ECC000
heap default
page read and write
clean
2E9D000
unkown image
page readonly
clean
5880000
unkown
page read and write
clean
D90000
heap private
page read and write
clean
2E80000
unkown image
page readonly
clean
4B20000
heap private
page read and write
clean
2FB0000
unkown
page read and write
clean
2E4A000
unkown image
page readonly
clean
2EB1000
unkown image
page readonly
clean
136B000
heap default
page read and write
clean
2E97000
unkown image
page readonly
clean
2E9F000
unkown image
page readonly
clean
9E0000
unkown
page read and write
clean
C40000
unkown image
page readonly
clean
1430000
heap default
page read and write
clean
10D0000
unkown image
page readonly
clean
6EDA1000
unkown image
page execute read
clean
11D0000
unkown
page read and write
clean
11D0000
unkown
page read and write
clean
1E0E000
stack
page read and write
clean
2F11000
unkown image
page readonly
clean
11F0000
heap default
page read and write
clean
7F872000
unkown image
page readonly
clean
2E5D000
unkown image
page readonly
clean
700000
stack
page read and write
clean
2E97000
unkown image
page readonly
clean
142C000
heap default
page read and write
clean
4EC9000
heap private
page read and write
clean
2ED5000
unkown
page read and write
clean
1E60000
heap private
page read and write
clean
2EB1000
unkown image
page readonly
clean
4A9F000
stack
page read and write
clean
1432000
heap default
page read and write
clean
28C3000
unkown image
page readonly
clean
370000
unkown image
page readonly
clean
700000
stack
page read and write
clean
2F38000
unkown image
page readonly
clean
9E6000
unkown
page read and write
clean
11D0000
unkown
page read and write
clean
700000
stack
page read and write
clean
2EAA000
unkown image
page readonly
clean
9E0000
unkown
page read and write
clean
2E43000
unkown image
page readonly
clean
7F0B0000
unkown image
page readonly
clean
2B30000
unkown image
page readonly
clean
1020000
heap private
page read and write
clean
FBA000
unkown
page read and write
clean
650000
unkown image
page read and write
clean
281D000
unkown image
page readonly
clean
700000
stack
page read and write
clean
2E6C000
unkown image
page readonly
clean
2F80000
unkown
page read and write
clean
AEB000
unkown
page read and write
clean
2EC9000
unkown
page read and write
clean
2C45000
unkown
page read and write
clean
511F000
stack
page read and write
clean
2FB0000
unkown
page read and write
clean
2E4A000
unkown image
page readonly
clean
27E5000
unkown image
page readonly
clean
2FB0000
unkown
page read and write
clean
2ECC000
unkown
page read and write
clean
2F19000
unkown
page read and write
clean
6EDC7000
unkown image
page readonly
clean
2EAA000
unkown image
page readonly
clean
1E4D000
stack
page read and write
clean
2F38000
unkown image
page readonly
clean
2C0000
unkown image
page readonly
clean
14A0000
heap private
page read and write
clean
7FD40000
unkown image
page readonly
clean
35B000
unkown
page read and write
clean
7FC30000
unkown image
page readonly
clean
6EDC7000
unkown image
page readonly
clean
4C2F000
stack
page read and write
clean
2E6C000
unkown image
page readonly
clean
750000
heap default
page read and write
clean
DDC000
stack
page read and write
clean
549A000
heap private
page read and write
clean
2F15000
unkown image
page readonly
clean
28B2000
unkown image
page readonly
clean
BC0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7F830000
unkown image
page readonly
clean
2E9D000
unkown image
page readonly
clean
7F870000
unkown image
page readonly
clean
7FD50000
unkown image
page readonly
clean
2F32000
unkown image
page readonly
clean
159E000
stack
page read and write
clean
AC0000
heap default
page read and write
clean
2FB0000
unkown
page read and write
clean
549D000
heap private
page read and write
clean
2FA5000
unkown
page execute and read and write
clean
711000
unkown image
page execute read
clean
2C67000
unkown image
page readonly
clean
11D0000
unkown
page read and write
clean
2FB0000
unkown
page read and write
clean
9AD000
unkown
page read and write
clean
27BC000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
2B20000
unkown image
page read and write
clean
28C3000
unkown image
page readonly
clean
96A000
unkown
page read and write
clean
2895000
unkown image
page readonly
clean
971000
unkown
page read and write
clean
2FB0000
unkown
page read and write
clean
C8E000
stack
page read and write
clean
2D37000
unkown image
page readonly
clean
7F000000
unkown image
page readonly
clean
7F862000
unkown image
page readonly
clean
2C47000
unkown image
page readonly
clean
7FD32000
unkown image
page readonly
clean
969000
unkown
page read and write
clean
B50000
unkown
page read and write
clean
6EDA0000
unkown image
page readonly
clean
2F11000
unkown image
page readonly
clean
700000
stack
page read and write
clean
225C000
heap private
page read and write
clean
670000
heap private
page read and write
clean
2FB0000
unkown
page read and write
clean
2FB0000
unkown
page read and write
clean
7EFF0000
unkown image
page readonly
clean
1060000
heap private
page read and write
clean
2E43000
unkown image
page readonly
clean
5080000
unkown
page read and write
clean
16C000
unkown
page read and write
clean
2FB0000
unkown
page read and write
clean
B5D000
unkown
page read and write
clean
2FD1000
unkown image
page execute read
clean
225B000
heap private
page read and write
clean
E1B000
stack
page read and write
clean
4590000
unkown
page read and write
clean
700000
stack
page read and write
clean
9E3000
unkown
page read and write
clean
587000
unkown
page read and write
clean
7FE80000
unkown image
page readonly
clean
7EEE0000
unkown image
page readonly
clean
2BCB000
unkown
page read and write
clean
4BEE000
stack
page read and write
clean
6EDA0000
unkown image
page readonly
clean
2CB8000
unkown image
page readonly
clean
2D68000
unkown image
page readonly
clean
4A0F000
stack
page read and write
clean
11D0000
unkown
page read and write
clean
21D9000
heap private
page read and write
clean
1360000
heap default
page read and write
clean
6EDA0000
unkown image
page readonly
clean
2EC6000
unkown image
page readonly
clean
2EA3000
unkown image
page readonly
clean
2FB0000
unkown
page read and write
clean
4B50000
heap private
page read and write
clean
4AED000
stack
page read and write
clean
5080000
unkown
page read and write
clean
2F43000
unkown image
page readonly
clean
910000
heap default
page read and write
clean
2FB0000
unkown
page read and write
clean
660000
unkown image
page readonly
clean
1434000
unkown
page read and write
clean
2E7C000
unkown image
page readonly
clean
7EFE2000
unkown image
page readonly
clean
2D71000
unkown image
page readonly
clean
33C000
unkown
page read and write
clean
2E65000
unkown image
page readonly
clean
1140000
unkown image
page readonly
clean
2EA3000
unkown image
page readonly
clean
CC0000
heap default
page read and write
clean
8E0000
unkown image
page readonly
clean
110000
unkown image
page readonly
clean
FB4000
unkown
page read and write
clean
700000
stack
page read and write
clean
2D10000
unkown image
page readonly
clean
4B2C000
stack
page read and write
clean
6EDC3000
unkown image
page read and write
clean
6EDA0000
unkown image
page readonly
clean
2E5D000
unkown image
page readonly
clean
840000
unkown image
page readonly
clean
2E6C000
unkown image
page readonly
clean
2D68000
unkown image
page readonly
clean
2EAF000
unkown image
page readonly
clean
7F0D0000
unkown image
page readonly
clean
4B1B000
stack
page read and write
clean
2E4A000
heap default
page read and write
clean
1540000
unkown
page read and write
clean
2E89000
unkown image
page readonly
clean
2EB1000
unkown image
page readonly
clean
2690000
unkown image
page readonly
clean
2F2C000
unkown image
page readonly
clean
91A000
heap default
page read and write
clean
2FB0000
unkown
page read and write
clean
3180000
unkown image
page readonly
clean
2FB0000
unkown
page read and write
clean
7F830000
unkown image
page readonly
clean
5870000
unkown
page read and write
clean
100000
unkown image
page read and write
clean
5498000
heap private
page read and write
clean
74A000
heap default
page read and write
clean
11D0000
unkown
page read and write
clean
4A6E000
stack
page read and write
clean
2F14000
unkown
page read and write
clean
2F70000
unkown image
page readonly
clean
2E89000
unkown image
page readonly
clean
12FE000
stack
page read and write
clean
27F3000
unkown image
page readonly
clean
D9C000
unkown
page read and write
clean
7F860000
unkown image
page readonly
clean
225A000
heap private
page read and write
clean
19F8000
heap private
page read and write
clean
6EDA1000
unkown image
page execute read
clean
2E95000
unkown image
page readonly
clean
C20000
unkown
page read and write
clean
6D0000
stack
page read and write
clean
3180000
unkown image
page readonly
clean
2E5D000
unkown image
page readonly
clean
2EC6000
unkown image
page readonly
clean
A10000
unkown image
page readonly
clean
2F11000
unkown image
page readonly
clean
7F872000
unkown image
page readonly
clean
2C57000
unkown
page read and write
clean
27CA000
unkown image
page readonly
clean
26F6000
unkown image
page readonly
clean
26D3000
unkown image
page readonly
clean
7F0C2000
unkown image
page readonly
clean
7F832000
unkown image
page readonly
clean
A50000
unkown image
page readonly
clean
AF0000
unkown image
page read and write
clean
6EDA1000
unkown image
page execute read
clean
597E000
stack
page read and write
clean
4A2F000
stack
page read and write
clean
7F842000
unkown image
page readonly
clean
2E3C000
unkown image
page readonly
clean
2ECB000
unkown image
page readonly
clean
2E73000
unkown image
page readonly
clean
3420000
unkown image
page readonly
clean
700000
stack
page read and write
clean
2EC2000
unkown image
page readonly
clean
2FB0000
unkown
page read and write
clean
977000
unkown
page read and write
clean
1C0000
unkown image
page readonly
clean
6EDC3000
unkown image
page read and write
clean
7EFE2000
unkown image
page readonly
clean
2F50000
unkown image
page readonly
clean
31C000
unkown
page read and write
clean
2EC2000
unkown image
page readonly
clean
2E80000
unkown image
page readonly
clean
2F15000
unkown image
page readonly
clean
2FB0000
unkown
page read and write
clean
27FB000
unkown image
page readonly
clean
6EDA0000
unkown image
page readonly
clean
31D7000
heap private
page read and write
clean
700000
stack
page read and write
clean
4AAF000
stack
page read and write
clean
2D19000
unkown image
page readonly
clean
6EDA0000
unkown image
page readonly
clean
7FE90000
unkown image
page readonly
clean
2C65000
unkown image
page readonly
clean
1B0E000
stack
page read and write
clean
700000
unkown image
page readonly
clean
11D0000
unkown
page read and write
clean
282F000
unkown image
page readonly
clean
963000
unkown
page read and write
clean
1421000
unkown
page read and write
clean
FC6000
unkown
page read and write
clean
2F17000
unkown
page read and write
clean
1430000
unkown
page read and write
clean
2E80000
unkown image
page readonly
clean
2E9F000
unkown image
page readonly
clean
27C3000
unkown image
page readonly
clean
CE0000
unkown image
page readonly
clean
2E65000
unkown image
page readonly
clean
7FD42000
unkown image
page readonly
clean
1434000
heap default
page read and write
clean
7FE90000
unkown image
page readonly
clean
700000
stack
page read and write
clean
360000
unkown image
page readonly
clean
2E7C000
unkown image
page readonly
clean
2EC6000
unkown image
page readonly
clean
7F870000
unkown image
page readonly
clean
505F000
stack
page read and write
clean
7EFF2000
unkown image
page readonly
clean
110000
unkown image
page readonly
clean
114E000
stack
page read and write
clean
There are 717 hidden memdumps, click here to show them.