IOC Report

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Local\Temp\webwcryn.4k5\new-2048176346.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Jun 5 19:19:34 2015, Last Saved Time/Date: Wed Nov 24 13:02:13 2021, Security: 0
dropped
malicious
C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\02075ce4-1d91-4b2b-a739-bc8ac342dc4b.tmp
ASCII text, with very long lines, with no line terminators
modified
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\192520eb-2bde-4020-8c7b-eba88eec3553.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\55143009-8041-40b5-91ed-d73c44c5bec4.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\5ea14e38-aed2-4584-be4b-914b462ae2f4.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\6e8fc09e-9c68-444c-a10a-c4d0a26e7e27.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\82eff488-1d66-4fda-b9a5-5fc7e9acafb7.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\871238ee-f035-4881-8e0c-1639e86c7ad3.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\98762c02-18cd-4bdd-aded-c0951ebd276d.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\000001.dbtmp
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\000002.dbtmp
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\0d0e3b03-aa61-4f82-bc17-500620085963.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\10dd846f-83bc-4342-a3d3-76d079f9b9d7.tmp
ASCII text, with very long lines, with no line terminators
modified
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\141f427a-af72-4a42-9e35-48e08bccfb4a.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\248a4332-23c1-4649-800c-6c44f31cf0a5.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\3662965d-c6b0-497a-9411-8f7a1cdded30.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\3dc995d3-862c-49f6-b5b2-50b52cb90d53.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\50b7666c-d418-4e66-994a-abfbb8ca0602.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\6172a17e-dade-463a-bc46-3cd107d284f5.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\7516e95c-b10e-4da2-b7d0-1c1b30344a91.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\9869c764-8479-4fed-a2c4-14b66d8eb40c.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.oldG (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\CURRENT. (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\CURRENTT (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Current Session
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Current Tabs
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.oldoi (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_metadata\computed_hashes.json
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8520.615.0.5_1\_metadata\computed_hashes.json
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old@ (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.old. (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.oldg (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History-journal
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Last Session.{ (copy)
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Last Tabsd (copy)
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\MANIFEST-000001
PGP\011Secret Key -
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\MANIFEST-000002
MPEG-4 LOAS
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent Statemp (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG.oldr (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences* (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Reporting and NEL
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences (copy)
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences0q (copy)
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure PreferencesDe (copy)
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.oldMP (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\032bd314-c0ad-43ff-859e-805db691f873.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\GPUCache\data_1
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Local Storage\leveldb\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Local Storage\leveldb\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Network Persistent State (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Platform Notifications\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Platform Notifications\LOG.olde/ (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\5314b2be-46f0-4012-8f43-eed4843e1078.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\GPUCache\data_1
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb\LOG.oldg (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Network Persistent Statei (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Platform Notifications\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Platform Notifications\LOG.oldg (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Visited Links
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000004.dbtmp
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\MANIFEST-000004
MPEG-4 LOAS
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\e1b83851-7f64-4365-a3b4-5cc609abd707.tmp
very short file (no magic)
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\e492a2ec-6a30-4c7b-9bc7-017de4d4916c.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Browser
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Version
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State1 (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Module Info Cache (copy)
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Module Info CacheMP (copy)
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Subresource Filter\Indexed Rules\27\scoped_dir676_1884660702\Ruleset Data
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\a59f0fe5-e81b-41e3-9aea-9a5db8bf100b.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\cc231be7-6de0-4158-af18-32fc9eec0d81.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\F90B3D14-54E1-4326-A222-CA0FF043C276
XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\27038ea0-529c-4aa0-bbfc-39fc0b911dc8.tmp
Google Chrome extension, version 3
dropped
clean
C:\Users\user\AppData\Local\Temp\2879ecf8-ca29-4638-907b-537ca21172fc.tmp
Google Chrome extension, version 3
dropped
clean
C:\Users\user\AppData\Local\Temp\5b5f5261-4fd5-4ba0-86aa-8fd6fc2ffb60.tmp
very short file (no magic)
dropped
clean
C:\Users\user\AppData\Local\Temp\676_1656799962\Filtering Rules
data
dropped
clean
C:\Users\user\AppData\Local\Temp\676_1656799962\LICENSE.txt
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\676_1656799962\_metadata\verified_contents.json
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\676_1656799962\manifest.fingerprint
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\676_1656799962\manifest.json
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Temp\browser-sslkeys.log
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Temp\d0afa5a6-350b-4ca2-94ce-7d9d12ecc437.tmp
very short file (no magic)
dropped
clean
C:\Users\user\AppData\Local\Temp\e4mv0t3c.b0c\unarchiver.log
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\27038ea0-529c-4aa0-bbfc-39fc0b911dc8.tmp
Google Chrome extension, version 3
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\bg\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\ca\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\cs\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\da\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\de\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\el\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\en\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\en_GB\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\es\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\es_419\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\et\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\fi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\fil\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\fr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\hi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\hr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\hu\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\id\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\it\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\ja\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\ko\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\lt\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\lv\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\nb\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\nl\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\pl\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\pt_BR\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\pt_PT\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\ro\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\ru\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\sk\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\sl\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\sr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\sv\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\th\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\tr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\uk\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\vi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\zh_CN\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_locales\zh_TW\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\_metadata\verified_contents.json
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\craw_background.js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\craw_window.js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\css\craw_window.css
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\html\craw_window.html
HTML document, ASCII text
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\images\flapper.gif
GIF image data, version 89a, 30 x 30
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\images\icon_128.png
PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\images\icon_16.png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\images\topbar_floating_button.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\images\topbar_floating_button_close.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\images\topbar_floating_button_hover.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\images\topbar_floating_button_maximize.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\images\topbar_floating_button_pressed.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_1581278968\CRX_INSTALL\manifest.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\2879ecf8-ca29-4638-907b-537ca21172fc.tmp
Google Chrome extension, version 3
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\am\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\ar\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\bg\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\bn\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\ca\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\cs\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\da\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\de\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\el\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\en\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\es\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\et\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\fa\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\fi\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\fil\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\fr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\gu\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\hi\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\hr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\hu\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\id\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\it\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\iw\messages.json
HTML document, ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\ja\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\kn\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\ko\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\lt\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\lv\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\ml\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\mr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\ms\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\nb\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\nl\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\pl\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\pt\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\ro\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\ru\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\sk\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\sl\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\sr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\sv\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\sw\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\ta\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\te\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\th\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\tr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\uk\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\vi\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\zh\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_locales\zh_TW\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\_metadata\verified_contents.json
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\angular.js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\background_script.js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\cast_sender.js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\common.js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\feedback.css
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\feedback.html
HTML document, ASCII text
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\feedback_script.js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\manifest.json
ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\material_css_min.css
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\mirroring_cast_streaming.js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\mirroring_common.js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\mirroring_hangouts.js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir676_964466428\CRX_INSTALL\mirroring_webrtc.js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF706937ADB0FEF781.TMP
data
dropped
clean
C:\Users\user\Downloads\0a22b7a7-f9f1-463a-b21c-1dad8200ac24.tmp
Zip archive data, at least v2.0 to extract
dropped
clean
C:\Users\user\Downloads\laboriosampariatur-6199055.zip.crdownload3{ (copy)
Zip archive data, at least v2.0 to extract
dropped
clean
C:\Users\user\Downloads\laboriosampariatur-6199055.zip:Zone.Identifier
ASCII text, with CRLF line terminators
dropped
clean
There are 248 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
"C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE" /dde
malicious
C:\Windows\SysWOW64\regsvr32.exe
"C:\Windows\System32\regsvr32.exe" C:\Datop\besta.ocx
malicious
C:\Windows\SysWOW64\regsvr32.exe
"C:\Windows\System32\regsvr32.exe" C:\Datop\bestb.ocx
malicious
C:\Windows\SysWOW64\regsvr32.exe
"C:\Windows\System32\regsvr32.exe" C:\Datop\bestc.ocx
malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --enable-automation "http://vulkanbonus.karmaguru.in/voluptasquis/laboriosampariatur-6199055
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1528,3653659809805504951,3020769216982181712,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1956 /prefetch:8
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --field-trial-handle=1528,3653659809805504951,3020769216982181712,131072 --lang=en-US --service-sandbox-type=none --enable-audio-service-sandbox --mojo-platform-channel-handle=6296 /prefetch:8
clean
C:\Windows\SysWOW64\unarchiver.exe
C:\Windows\SysWOW64\unarchiver.exe" "C:\Users\user\Downloads\laboriosampariatur-6199055.zip
clean
C:\Windows\SysWOW64\7za.exe
C:\Windows\System32\7za.exe" x -pinfected -y -o"C:\Users\user\AppData\Local\Temp\webwcryn.4k5" "C:\Users\user\Downloads\laboriosampariatur-6199055.zip
clean
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
clean
C:\Windows\SysWOW64\cmd.exe
cmd.exe" /C "C:\Users\user\AppData\Local\Temp\webwcryn.4k5\new-2048176346.xls
clean
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
clean
There are 2 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://vulkanbonus.karmaguru.in/voluptasquis/laboriosampariatur-6199055
malicious
https://api.diagnosticssdf.office.com
unknown
clean
https://login.microsoftonline.com/
unknown
clean
https://shell.suite.office.com:1443
unknown
clean
https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
unknown
clean
https://apis.google.com/js/client.js
unknown
clean
https://autodiscover-s.outlook.com/
unknown
clean
https://roaming.edog.
unknown
clean
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
unknown
clean
https://cdn.entity.
unknown
clean
https://api.addins.omex.office.net/appinfo/query
unknown
clean
https://crash.corp.google.com/samples?reportid=&q=
unknown
clean
https://clients.config.office.net/user/v1.0/tenantassociationkey
unknown
clean
https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
unknown
clean
https://powerlift.acompli.net
unknown
clean
https://rpsticket.partnerservices.getmicrosoftkey.com
unknown
clean
https://easylist.to/)
unknown
clean
https://lookup.onenote.com/lookup/geolocation/v1
unknown
clean
https://cortana.ai
unknown
clean
http://vulkanbonus.karmaguru.in/voluptasquis/laboriosampariatur-61990552
unknown
clean
https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
unknown
clean
http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions-01
unknown
clean
https://cloudfiles.onenote.com/upload.aspx
unknown
clean
https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
unknown
clean
https://entitlement.diagnosticssdf.office.com
unknown
clean
https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
unknown
clean
https://api.aadrm.com/
unknown
clean
https://preprod-hangouts-googleapis.sandbox.google.com
unknown
clean
https://orthomay.com.br/GD7A3PSD4zc/tw.html
108.179.253.213
clean
https://ofcrecsvcapi-int.azurewebsites.net/
unknown
clean
https://www.google.com
unknown
clean
https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
unknown
clean
https://hangouts.google.com/hangouts/_/logpref
unknown
clean
https://api.microsoftstream.com/api/
unknown
clean
https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
unknown
clean
https://cr.office.com
unknown
clean
https://augloop.office.com;https://augloop-int.officeppe.com;https://augloop-dogfood.officeppe.com;h
unknown
clean
https://creativecommons.org/publicdomain/zero/1.0/.
unknown
clean
https://portal.office.com/account/?ref=ClientMeControl
unknown
clean
https://www.google.com/accounts/OAuthLogin?issueuberauth=1
unknown
clean
https://mustafakhafimsp.af/UnE5kOnX/tw.html
104.161.44.139
clean
https://github.com/madler/zlib/blob/master/zlib.h
unknown
clean
https://graph.ppe.windows.net
unknown
clean
https://res.getmicrosoftkey.com/api/redemptionevents
unknown
clean
https://powerlift-frontdesk.acompli.net
unknown
clean
https://tasks.office.com
unknown
clean
https://officeci.azurewebsites.net/api/
unknown
clean
https://sr.outlook.office.net/ws/speech/recognize/assistant/work
unknown
clean
https://www.google.com/tools/feedback
unknown
clean
https://dns.google
unknown
clean
https://github.com/google/closure-library/wiki/goog.module:-an-ES6-module-like-alternative-to-goog.p
unknown
clean
https://store.office.cn/addinstemplate
unknown
clean
https://support.google.com/chromecast/troubleshooter/2995236
unknown
clean
https://api.aadrm.com
unknown
clean
http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions
unknown
clean
https://outlook.office.com/autosuggest/api/v1/init?cvid=
unknown
clean
http://vulkanbonus.karmaguru.in/voluptasquis/laboriosampariatur-6199055/0(m
unknown
clean
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=85.0.4183.121&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1
142.250.203.110
clean
https://globaldisco.crm.dynamics.com
unknown
clean
https://payments.google.com/payments/v4/js/integrator.js
unknown
clean
https://www.google.com;
unknown
clean
https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
unknown
clean
https://dev0-api.acompli.net/autodetect
unknown
clean
https://www.odwebp.svc.ms
unknown
clean
https://api.powerbi.com/v1.0/myorg/groups
unknown
clean
https://web.microsoftstream.com/video/
unknown
clean
https://api.addins.store.officeppe.com/addinstemplate
unknown
clean
https://www.google.com/images/x2.gif
unknown
clean
https://graph.windows.net
unknown
clean
https://dataservice.o365filtering.com/
unknown
clean
https://officesetup.getmicrosoftkey.com
unknown
clean
https://analysis.windows.net/powerbi/api
unknown
clean
https://prod-global-autodetect.acompli.net/autodetect
unknown
clean
https://www.google.com/images/dot2.gif
unknown
clean
https://play.google.com/log?format=json&hasfast=true
unknown
clean
https://outlook.office365.com/autodiscover/autodiscover.json
unknown
clean
https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
unknown
clean
https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
unknown
clean
http://tools.ietf.org/html/rfc1950
unknown
clean
https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
unknown
clean
http://vulkanbonus.karmaguru.in/voluptasquis/laboriosampariatur-6199055http://vulkanbonus.karmaguru.
unknown
clean
https://ncus.contentsync.
unknown
clean
https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
unknown
clean
https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
unknown
clean
http://weather.service.msn.com/data.aspx
unknown
clean
https://apis.live.net/v5.0/
unknown
clean
https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
unknown
clean
https://docs.google.com
unknown
clean
https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
unknown
clean
https://www.google.com/
unknown
clean
https://feedback.googleusercontent.com
unknown
clean
https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
unknown
clean
https://clients6.google.com
unknown
clean
https://management.azure.com
unknown
clean
https://outlook.office365.com
unknown
clean
https://wus2.contentsync.
unknown
clean
https://incidents.diagnostics.office.com
unknown
clean
https://clients.config.office.net/user/v1.0/ios
unknown
clean
https://www.google.com/images/cleardot.gif
unknown
clean
https://insertmedia.bing.office.net/odc/insertmedia
unknown
clean
https://o365auditrealtimeingestion.manage.office.com
unknown
clean
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
vulkanbonus.karmaguru.in
116.206.105.115
clean
accounts.google.com
172.217.168.45
clean
mustafakhafimsp.af
104.161.44.139
clean
orthomay.com.br
108.179.253.213
clean
clients.l.google.com
142.250.203.110
clean
quebradadigital.com.br
108.179.253.213
clean
googlehosted.l.googleusercontent.com
142.250.203.97
clean
clients2.googleusercontent.com
unknown
clean
clients2.google.com
unknown
clean

IPs

IP
Domain
Country
Malicious
192.168.2.1
unknown
unknown
clean
142.250.203.110
clients.l.google.com
United States
clean
192.168.2.7
unknown
unknown
clean
192.168.2.4
unknown
unknown
clean
192.168.2.3
unknown
unknown
clean
172.217.168.45
accounts.google.com
United States
clean
108.179.253.213
orthomay.com.br
United States
clean
142.250.203.97
googlehosted.l.googleusercontent.com
United States
clean
104.161.44.139
mustafakhafimsp.af
United States
clean
239.255.255.250
unknown
Reserved
clean
116.206.105.115
vulkanbonus.karmaguru.in
Seychelles
clean
127.0.0.1
unknown
unknown
clean
There are 2 hidden IPs, click here to show them.

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\LastWasDefault
S-1-5-21-3853321935-2125563209-4053062332-1002
clean
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
LangID
clean
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Windows\SysWOW64\unarchiver.exe.FriendlyAppName
clean
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Windows\SysWOW64\unarchiver.exe.ApplicationCompany
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
ahfgeienlihckogmohjhadlkjgocpleb
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gdaefkejpgkiemlaofpalmlakkmbjdnl
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gfdkimpbcpahaombhbimeihdjnejgicl
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
kmendfapggjehodndflmmgagdbamhnfd
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
mfehgcgbbipciphmccgaenjidiccnmng
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
mhjfbmdgcfjbbpaeojofohoefgiehjai
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
neajdppkdcdipfabeoofebfddakdcjhd
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nkeimhogjdpnpccoofpliimaahmaaome
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
pkedcjkdefgpdelpbcmbmeomcjbeemfm
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
prefs.preference_reset_time
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gfdkimpbcpahaombhbimeihdjnejgicl
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
pkedcjkdefgpdelpbcmbmeomcjbeemfm
clean
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
clean
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
clean
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
clean
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.reporting
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
module_blacklist_cache_md5_digest
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
media.storage_id_salt
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.last_account_id
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.account_id
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.prompt_seed
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_homepage
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
default_search_provider_data.template_url_data
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
safebrowsing.incidents_sent
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
pinned_tabs
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
search_provider_overrides
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_default_search
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
prefs.preference_reset_time
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.last_username
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
session.startup_urls
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
session.restore_on_startup
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.prompt_version
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_startup_urls
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.prompt_wave
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
homepage
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
homepage_is_newtabpage
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
browser.show_home_button
clean
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
clean
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
{2781761E-28E0-4109-99FE-B9D127C57AFE} {56FFCC30-D398-11D0-B2AE-00A0C908FA49} 0xFFFF
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories64\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Implementing
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
{97E467B4-98C6-4F19-9588-161B7773D6F6} {886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99} 0xFFFF
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\DDECache\Excel\system
ProcessName
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\DDECache\Excel\system
WindowName
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\DDECache\Excel\system
WindowClassName
clean
HKEY_CURRENT_USER_Classes\Local Settings\MuiCache\f0\52C64B7E
@C:\Program Files (x86)\Common Files\Microsoft Shared\Office16\oregres.dll,-206
clean
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE.FriendlyAppName
clean
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE.ApplicationCompany
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109110000000000000000F01FEC\Usage
EXCELFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems
3%6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems
4%6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache
RemoteClearDate
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.4954&crev=3
Last
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems
/+6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\DocumentRecovery\31F90
31F90
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\IOAV
LastBootTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.4954&crev=3\0
FilePath
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.4954&crev=3\0
StartDate
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.4954&crev=3\0
EndDate
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.4954&crev=3\0
Properties
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.4954&crev=3\0
Url
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache
LastClean
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
DisableWinHttpCertAuth
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
DisableIsOwnerRegex
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
DisableSessionAwareHttpClose
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
DisableADALForExtendedApps
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
DisableADALSetSilentAuth
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
msoridDisableGuestCredProvider
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
msoridDisableOstringReplace
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\DocumentRecovery\32184
32184
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109E60090400000000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109110000000000000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
en-US
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
en-US
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109110000000000000000F01FEC\Usage
EXCELFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming
RoamingConfigurableSettings
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming
RoamingLastSyncTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming
RoamingLastWriteTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\DocumentRecovery\31F90
31F90
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog
CacheReady
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog
LastRequest
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog
CacheReady
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog
LastUpdate
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog
NextUpdate
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\IOAV
LastBootTime
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109E60090400000000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
There are 86 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
282D000
unkown image
page readonly
clean
214C1718000
unkown
page read and write
clean
2DB0000
unkown image
page readonly
clean
214C0E00000
unkown
page read and write
clean
2A4D000
unkown
page read and write
clean
7FF578D9F000
unkown image
page readonly
clean
28D8000
unkown image
page readonly
clean
7990000
unkown
page read and write
clean
5CE0000
unkown image
page readonly
clean
2C50000
unkown
page read and write
clean
D90000
unkown image
page read and write
clean
7FF578E6A000
unkown image
page readonly
clean
2DE8000
unkown
page read and write
clean
24B0000
unkown image
page readonly
clean
274A000
unkown
page read and write
clean
2E8A000
heap private
page read and write
clean
2590000
unkown image
page read and write
clean
1EDC2B20000
unkown image
page readonly
clean
2BFD000
unkown
page read and write
clean
7FB70000
unkown image
page readonly
clean
7FB62000
unkown image
page readonly
clean
26E0000
unkown image
page read and write
clean
3D40000
unkown image
page readonly
clean
214C0E76000
unkown
page read and write
clean
2970000
unkown
page read and write
clean
7FF578DAD000
unkown image
page readonly
clean
25A0000
unkown image
page readonly
clean
2D74FF000
stack
page read and write
clean
1EDC28F0000
unkown image
page readonly
clean
214C62D0000
unkown
page read and write
clean
2DDF000
unkown
page read and write
clean
2DE6000
unkown
page read and write
clean
28FB000
unkown image
page readonly
clean
7FBA2000
unkown image
page readonly
clean
214C63A0000
unkown
page read and write
clean
5970000
unkown image
page readonly
clean
7830000
unkown
page read and write
clean
7FF50EF37000
unkown image
page readonly
clean
214C1C30000
unkown
page read and write
clean
2A49000
unkown
page read and write
clean
214C1713000
unkown
page read and write
clean
FF3C0000
unkown image
page readonly
clean
7FF578E92000
unkown image
page readonly
clean
7C7307F000
stack
page read and write
clean
214C66B9000
unkown
page read and write
clean
9C0000
unkown image
page readonly
clean
F40000
unkown image
page readonly
clean
7FF50EF24000
unkown image
page readonly
clean
26F0000
unkown image
page readonly
clean
9D0000
unkown image
page readonly
clean
28FE000
unkown image
page readonly
clean
27DA000
unkown image
page readonly
clean
CA0000
unkown image
page readonly
clean
568E000
stack
page read and write
clean
7FF578DD6000
unkown image
page readonly
clean
7FF578DB6000
unkown image
page readonly
clean
2323000
unkown image
page readonly
clean
7FF578D84000
unkown image
page readonly
clean
253F000
unkown image
page readonly
clean
7FE10000
unkown image
page readonly
clean
22EB000
unkown image
page readonly
clean
3490000
unkown image
page readonly
clean
7FF22000
unkown image
page readonly
clean
7FF578B65000
unkown image
page readonly
clean
FF3C2000
unkown image
page readonly
clean
214C1390000
unkown image
page readonly
clean
7C72D7B000
stack
page read and write
clean
3580000
unkown image
page readonly
clean
FF3B2000
unkown image
page readonly
clean
7FDF2000
unkown image
page readonly
clean
214C668C000
unkown
page read and write
clean
2A6D000
unkown
page read and write
clean
7FF30000
unkown image
page readonly
clean
78A0000
unkown
page read and write
clean
2A65000
unkown
page read and write
clean
7F300000
unkown image
page readonly
clean
C80000
unkown image
page readonly
clean
7FF578E44000
unkown image
page readonly
clean
214C0D70000
unkown
page read and write
clean
FF3D0000
unkown image
page readonly
clean
7F2F2000
unkown image
page readonly
clean
2903000
unkown image
page readonly
clean
E3B000
heap default
page read and write
clean
2BBE000
stack
page read and write
clean
884000
unkown
page read and write
clean
7FF50EDA1000
unkown image
page readonly
clean
29DE000
unkown image
page readonly
clean
1F5F000
unkown image
page readonly
clean
7FF578626000
unkown image
page readonly
clean
2BE0000
unkown image
page readonly
clean
29D3000
unkown image
page readonly
clean
214C0DE1000
unkown
page read and write
clean
1EDC3540000
unkown
page read and write
clean
1EDC299A000
heap default
page read and write
clean
228A000
unkown image
page readonly
clean
29C6000
unkown image
page readonly
clean
2C01000
unkown
page read and write
clean
7FF4F3E1B000
unkown image
page readonly
clean
7FF578BD0000
unkown image
page readonly
clean
3035000
unkown
page read and write
clean
1EDC2B85000
heap private
page read and write
clean
301D000
unkown
page read and write
clean
2E3B000
unkown
page read and write
clean
214C0C10000
heap private
page read and write
clean
7FDF2000
unkown image
page readonly
clean
12E0000
unkown image
page readonly
clean
7FF578E97000
unkown image
page readonly
clean
840000
unkown image
page read and write
clean
7FB52000
unkown image
page readonly
clean
2DC0000
unkown image
page readonly
clean
214C6400000
unkown
page read and write
clean
7FF10000
unkown image
page readonly
clean
214C63F0000
unkown
page read and write
clean
23D2000
unkown image
page readonly
clean
214C6618000
unkown
page read and write
clean
7C7347C000
stack
page read and write
clean
2EC0000
unkown
page read and write
clean
7F2E2000
unkown image
page readonly
clean
2EF0000
heap default
page read and write
clean
2332000
unkown image
page readonly
clean
29A5000
unkown image
page readonly
clean
214C670A000
unkown
page read and write
clean
301D000
unkown
page read and write
clean
214C1380000
unkown image
page readonly
clean
DEF000
unkown
page read and write
clean
7DF582C32000
unkown image
page readonly
clean
245D000
unkown image
page readonly
clean
2A10000
unkown image
page readonly
clean
29E2000
unkown image
page readonly
clean
2A60000
heap default
page read and write
clean
7FB92000
unkown image
page readonly
clean
3021000
unkown
page read and write
clean
EFF000
stack
page read and write
clean
2DD0000
unkown
page read and write
clean
7FF578E83000
unkown image
page readonly
clean
214C62D1000
unkown
page read and write
clean
233F000
unkown image
page readonly
clean
214C66B9000
unkown
page read and write
clean
4F90000
unkown
page read and write
clean
214C63E0000
unkown
page read and write
clean
7DF582C42000
unkown image
page readonly
clean
49DE000
stack
page read and write
clean
7DF518D12000
unkown image
page readonly
clean
214C6623000
unkown
page read and write
clean
3011000
unkown
page read and write
clean
7DF582C32000
unkown image
page readonly
clean
7FF50EE6F000
unkown image
page readonly
clean
7FF578B43000
unkown image
page readonly
clean
7FF578D8F000
unkown image
page readonly
clean
7FF578B94000
unkown image
page readonly
clean
31CB000
heap default
page read and write
clean
214C670C000
unkown
page read and write
clean
7FF50EE96000
unkown image
page readonly
clean
860000
unkown image
page readonly
clean
7F2E0000
unkown image
page readonly
clean
2917000
unkown image
page readonly
clean
214C179A000
unkown
page read and write
clean
11E0000
unkown image
page readonly
clean
2E80000
unkown
page read and write
clean
2282000
unkown image
page readonly
clean
7DF518D10000
unkown image
page readonly
clean
7DF518D12000
unkown image
page readonly
clean
7F2E2000
unkown image
page readonly
clean
2E7E000
stack
page read and write
clean
7F2E0000
unkown image
page readonly
clean
554E000
stack
page read and write
clean
7C7317E000
stack
page read and write
clean
3566000
heap private
page read and write
clean
2945000
unkown image
page readonly
clean
214C6430000
unkown
page read and write
clean
214C66D1000
unkown
page read and write
clean
7DF416BE0000
unkown image
page readonly
clean
247E000
unkown image
page readonly
clean
2B80000
unkown image
page readonly
clean
4FB0000
unkown
page read and write
clean
214C62DE000
unkown
page read and write
clean
7FF50EE84000
unkown image
page readonly
clean
214C0C00000
unkown image
page read and write
clean
7CBF000
stack
page read and write
clean
7FA90000
unkown image
page readonly
clean
7FBA2000
unkown image
page readonly
clean
788F000
stack
page read and write
clean
E00000
heap default
page read and write
clean
29B4000
heap private
page read and write
clean
7F2E2000
unkown image
page readonly
clean
7FF5789C2000
unkown image
page readonly
clean
2DF0000
unkown
page read and write
clean
214C0EA1000
unkown
page read and write
clean
515E000
stack
page read and write
clean
7FF578B96000
unkown image
page readonly
clean
7C72FFF000
stack
page read and write
clean
2DB0000
unkown image
page readonly
clean
2991000
unkown image
page readonly
clean
2A40000
unkown
page read and write
clean
2948000
unkown image
page readonly
clean
2FFA000
heap default
page read and write
clean
7DF582C30000
unkown image
page readonly
clean
1EDC2FA0000
unkown image
page readonly
clean
214C6715000
unkown
page read and write
clean
2895000
heap private
page read and write
clean
2E90000
unkown image
page readonly
clean
214C1758000
unkown
page read and write
clean
2C05000
unkown
page read and write
clean
27D4000
unkown image
page readonly
clean
2A4E000
unkown
page read and write
clean
C90000
heap private
page read and write
clean
7FF50ED88000
unkown image
page readonly
clean
B90000
unkown image
page readonly
clean
3200000
unkown image
page readonly
clean
7FB70000
unkown image
page readonly
clean
FF3C0000
unkown image
page readonly
clean
7D3F000
stack
page read and write
clean
BA0000
unkown image
page readonly
clean
7750000
unkown
page read and write
clean
7FB52000
unkown image
page readonly
clean
FF3B2000
unkown image
page readonly
clean
A8D000
unkown
page read and write
clean
2C02000
unkown
page read and write
clean
293D000
unkown image
page readonly
clean
270E000
unkown image
page readonly
clean
4A1E000
stack
page read and write
clean
26C8000
unkown
page read and write
clean
5AE0000
unkown
page read and write
clean
7FF4F3E1B000
unkown image
page readonly
clean
292E000
stack
page read and write
clean
578F000
stack
page read and write
clean
2A18000
unkown image
page readonly
clean
3025000
unkown
page read and write
clean
214C6645000
unkown
page read and write
clean
7FF578E41000
unkown image
page readonly
clean
203F000
unkown image
page readonly
clean
28F6000
unkown image
page readonly
clean
7C72EFF000
stack
page read and write
clean
7FF50EF21000
unkown image
page readonly
clean
7DF518D30000
unkown image
page readonly
clean
214C1799000
unkown
page read and write
clean
2C40000
unkown image
page read and write
clean
7C72C7E000
stack
page read and write
clean
214C6663000
unkown
page read and write
clean
278B000
unkown
page read and write
clean
22E1000
unkown image
page readonly
clean
7FF50E6F7000
unkown image
page readonly
clean
24B8000
unkown image
page readonly
clean
2CD0000
unkown image
page readonly
clean
7F2E0000
unkown image
page readonly
clean
3400000
unkown image
page readonly
clean
230D000
unkown image
page readonly
clean
7FF50E7F1000
unkown image
page readonly
clean
2862000
unkown image
page readonly
clean
1EDC3810000
unkown
page read and write
clean
31FF000
heap default
page read and write
clean
301D000
unkown
page read and write
clean
214C179A000
unkown
page read and write
clean
2D767E000
stack
page read and write
clean
214C1602000
unkown
page read and write
clean
7FF578BCE000
unkown image
page readonly
clean
860000
unkown image
page readonly
clean
7FB92000
unkown image
page readonly
clean
3019000
unkown
page read and write
clean
7C72A7A000
stack
page read and write
clean
B86000
unkown
page read and write
clean
214C6314000
unkown
page read and write
clean
7FF578D45000
unkown image
page readonly
clean
2B74000
heap private
page read and write
clean
245B000
unkown image
page readonly
clean
214C6704000
unkown
page read and write
clean
12A7000
unkown
page execute and read and write
clean
7FBA0000
unkown image
page readonly
clean
2BB0000
unkown
page read and write
clean
2790000
unkown image
page readonly
clean
214C66D7000
unkown
page read and write
clean
218D000
unkown image
page readonly
clean
3050000
unkown image
page readonly
clean
7FF50E6FF000
unkown image
page readonly
clean
27CC000
unkown image
page readonly
clean
7FF578A19000
unkown image
page readonly
clean
282E000
stack
page read and write
clean
2BF0000
unkown image
page readonly
clean
3135000
heap default
page read and write
clean
3190000
heap default
page read and write
clean
7DF518D22000
unkown image
page readonly
clean
2924000
unkown image
page readonly
clean
7DF518D20000
unkown image
page readonly
clean
25A0000
unkown image
page readonly
clean
9D0000
unkown image
page readonly
clean
2DCB000
unkown
page read and write
clean
7FDF0000
unkown image
page readonly
clean
214C6300000
unkown
page read and write
clean
7FF578E4D000
unkown image
page readonly
clean
FF3C2000
unkown image
page readonly
clean
214C0E71000
unkown
page read and write
clean
9E0000
unkown
page read and write
clean
FF3B2000
unkown image
page readonly
clean
7FF50EF34000
unkown image
page readonly
clean
7FB90000
unkown image
page readonly
clean
4F80000
unkown image
page readonly
clean
7FF50EDB1000
unkown image
page readonly
clean
7FF578BF4000
unkown image
page readonly
clean
FF3C0000
unkown image
page readonly
clean
7F2F0000
unkown image
page readonly
clean
7CFE000
stack
page read and write
clean
27F0000
unkown
page read and write
clean
FF2B0000
unkown image
page readonly
clean
214C0C40000
unkown image
page readonly
clean
7FF578CD1000
unkown image
page readonly
clean
214C0E29000
unkown
page read and write
clean
7DF518D30000
unkown image
page readonly
clean
2BDA000
unkown
page read and write
clean
2A2E000
stack
page read and write
clean
860000
unkown image
page readonly
clean
292D000
unkown image
page readonly
clean
214C62D8000
unkown
page read and write
clean
10E8000
heap default
page read and write
clean
7FF578D74000
unkown image
page readonly
clean
7FF578E47000
unkown image
page readonly
clean
214C21A0000
unkown
page read and write
clean
26F0000
unkown image
page readonly
clean
1280000
unkown image
page readonly
clean
214C6715000
unkown
page read and write
clean
214C62F4000
unkown
page read and write
clean
214C1C10000
unkown
page read and write
clean
7FB62000
unkown image
page readonly
clean
2A51000
unkown
page read and write
clean
2DC0000
unkown image
page readonly
clean
214C17DB000
unkown
page read and write
clean
2847000
unkown image
page readonly
clean
2A2E000
stack
page read and write
clean
59BD000
stack
page read and write
clean
3021000
unkown
page read and write
clean
529E000
stack
page read and write
clean
319C000
heap default
page read and write
clean
2ED0000
unkown image
page readonly
clean
29A8000
unkown image
page readonly
clean
1EDC28A0000
unkown image
page read and write
clean
2A51000
unkown
page read and write
clean
2A20000
heap default
page read and write
clean
BF0000
unkown
page read and write
clean
3022000
unkown
page read and write
clean
7FF578C2A000
unkown image
page readonly
clean
1EDC3120000
unkown image
page readonly
clean
3390000
unkown
page read and write
clean
7FF578DC2000
unkown image
page readonly
clean
214C6702000
unkown
page read and write
clean
A20000
unkown image
page read and write
clean
FF3B0000
unkown image
page readonly
clean
7FCF0000
unkown image
page readonly
clean
7DF582C30000
unkown image
page readonly
clean
214C6420000
unkown
page read and write
clean
14E0000
unkown image
page readonly
clean
31FA000
heap private
page read and write
clean
3180000
unkown
page read and write
clean
29CE000
unkown image
page readonly
clean
7FF578B06000
unkown image
page readonly
clean
7FBB0000
unkown image
page readonly
clean
4AE0000
unkown
page read and write
clean
3021000
unkown
page read and write
clean
DB0000
heap private
page read and write
clean
28ED000
unkown image
page readonly
clean
3560000
heap private
page read and write
clean
214C15E0000
unkown
page read and write
clean
7FE00000
unkown image
page readonly
clean
1EDC2982000
unkown
page read and write
clean
2E30000
unkown image
page readonly
clean
2840000
unkown image
page readonly
clean
3520000
unkown
page read and write
clean
1EDC2930000
heap default
page read and write
clean
DEA000
unkown
page execute and read and write
clean
214C66BD000
unkown
page read and write
clean
225E000
unkown image
page readonly
clean
214C1615000
unkown
page read and write
clean
10E0000
heap default
page read and write
clean
29E0000
heap private
page read and write
clean
2A50000
heap private
page execute and read and write
clean
5ABE000
stack
page read and write
clean
7DF582C42000
unkown image
page readonly
clean
7FF578CD8000
unkown image
page readonly
clean
3028000
unkown
page read and write
clean
4FC0000
unkown image
page readonly
clean
2C1D000
unkown
page read and write
clean
7DF518D20000
unkown image
page readonly
clean
7FF50EDB8000
unkown image
page readonly
clean
214C1700000
unkown
page read and write
clean
2D713B000
unkown
page read and write
clean
7FF50EF63000
unkown image
page readonly
clean
214C66BE000
unkown
page read and write
clean
7FF50EF4A000
unkown image
page readonly
clean
7FF578B4A000
unkown image
page readonly
clean
2B30000
unkown
page read and write
clean
12B0000
unkown
page read and write
clean
7FF50EF3B000
unkown image
page readonly
clean
23BE000
unkown image
page readonly
clean
2EA0000
unkown image
page readonly
clean
2B70000
heap private
page read and write
clean
2C50000
unkown image
page readonly
clean
2368000
unkown image
page readonly
clean
A50000
unkown image
page readonly
clean
29A0000
unkown
page read and write
clean
28D5000
unkown image
page readonly
clean
2A18000
unkown image
page readonly
clean
2E80000
heap private
page read and write
clean
214C1881000
unkown
page read and write
clean
214C15D0000
unkown
page read and write
clean
246E000
unkown image
page readonly
clean
214C6300000
unkown
page read and write
clean
2C50000
unkown image
page readonly
clean
8BC000
unkown
page read and write
clean
261F000
unkown image
page readonly
clean
FF3B0000
unkown image
page readonly
clean
E0B000
heap default
page read and write
clean
1EDC28B0000
unkown
page read and write
clean
2368000
unkown image
page readonly
clean
7FF578B9A000
unkown image
page readonly
clean
7FF578BA0000
unkown image
page readonly
clean
29B0000
heap private
page read and write
clean
2941000
unkown image
page readonly
clean
9BC000
unkown
page read and write
clean
214C0E57000
unkown
page read and write
clean
1EDC3130000
unkown image
page readonly
clean
2C54000
unkown
page read and write
clean
2DBE000
unkown
page read and write
clean
214C6410000
unkown
page read and write
clean
214C62D0000
unkown
page read and write
clean
A60000
unkown
page read and write
clean
7FF578D58000
unkown image
page readonly
clean
23E5000
unkown image
page readonly
clean
276D000
unkown image
page readonly
clean
214C0C70000
heap default
page read and write
clean
2CB0000
unkown image
page readonly
clean
76CE000
stack
page read and write
clean
7FB50000
unkown image
page readonly
clean
214C1759000
unkown
page read and write
clean
293A000
unkown image
page readonly
clean
214C0C20000
unkown image
page readonly
clean
1100000
unkown image
page readonly
clean
299F000
stack
page read and write
clean
291F000
unkown image
page readonly
clean
1EDC28E0000
unkown image
page readonly
clean
FF3B0000
unkown image
page readonly
clean
1EDC3820000
unkown
page read and write
clean
7FF578B53000
unkown image
page readonly
clean
214C0C50000
unkown image
page readonly
clean
2C1D000
unkown
page read and write
clean
4F7F000
stack
page read and write
clean
7FF20000
unkown image
page readonly
clean
7FF50EB41000
unkown image
page readonly
clean
214C1E20000
unkown image
page readonly
clean
214C6420000
unkown
page read and write
clean
214C66D1000
unkown
page read and write
clean
74C000
unkown image
page readonly
clean
9C0000
unkown image
page readonly
clean
218F000
unkown image
page readonly
clean
A70000
unkown
page read and write
clean
2851000
unkown image
page readonly
clean
214C0E8F000
unkown
page read and write
clean
214C15C3000
unkown
page read and write
clean
7FB90000
unkown image
page readonly
clean
2DDC000
unkown
page read and write
clean
2A49000
unkown
page read and write
clean
860000
unkown image
page readonly
clean
214C1801000
unkown
page read and write
clean
FF3D0000
unkown image
page readonly
clean
283B000
unkown
page read and write
clean
FF3B2000
unkown image
page readonly
clean
2BFD000
unkown
page read and write
clean
214C1C20000
unkown
page read and write
clean
7FF578BDB000
unkown image
page readonly
clean
FF3B2000
unkown image
page readonly
clean
7FF5789F2000
unkown image
page readonly
clean
7F9F0000
unkown
page execute and read and write
clean
283E000
unkown image
page readonly
clean
214C0E13000
unkown
page read and write
clean
7FF578DA3000
unkown image
page readonly
clean
7FF578C5F000
unkown image
page readonly
clean
29BB000
unkown image
page readonly
clean
1EDC37F0000
unkown
page read and write
clean
7C72E7B000
stack
page read and write
clean
214C6540000
unkown
page read and write
clean
7FF578C3D000
unkown image
page readonly
clean
2A52000
unkown
page read and write
clean
7FF50EF77000
unkown image
page readonly
clean
2F7F000
unkown
page read and write
clean
214C62F1000
unkown
page read and write
clean
7C72F7E000
stack
page read and write
clean
7FF578B58000
unkown image
page readonly
clean
248F000
unkown image
page readonly
clean
7FE02000
unkown image
page readonly
clean
DEC000
unkown
page execute and read and write
clean
22B2000
unkown image
page readonly
clean
229B000
unkown image
page readonly
clean
7FF578D79000
unkown image
page readonly
clean
2B50000
unkown image
page readonly
clean
2C01000
unkown
page read and write
clean
27CE000
unkown image
page readonly
clean
226E000
unkown image
page readonly
clean
214C0F02000
unkown
page read and write
clean
2BD0000
heap default
page read and write
clean
2D757A000
stack
page read and write
clean
2DC0000
unkown image
page readonly
clean
7FBA0000
unkown image
page readonly
clean
7FF50EF77000
unkown image
page readonly
clean
23DA000
unkown image
page readonly
clean
214C1799000
unkown
page read and write
clean
7FF50EF66000
unkown image
page readonly
clean
214C1B00000
unkown
page read and write
clean
214C0C20000
unkown image
page readonly
clean
23EB000
unkown image
page readonly
clean
7DF582C50000
unkown image
page readonly
clean
274D000
unkown image
page readonly
clean
3019000
unkown
page read and write
clean
12AB000
unkown
page execute and read and write
clean
214C0E3D000
unkown
page read and write
clean
214C61D0000
unkown
page read and write
clean
2940000
unkown image
page readonly
clean
29EA000
heap private
page read and write
clean
540E000
stack
page read and write
clean
9D0000
unkown image
page readonly
clean
2B9E000
stack
page read and write
clean
CB5000
heap default
page read and write
clean
214C15C0000
unkown
page read and write
clean
2C01000
unkown
page read and write
clean
214C1E00000
unkown image
page readonly
clean
7FF578D01000
unkown image
page readonly
clean
28EB000
unkown image
page readonly
clean
214C1759000
unkown
page read and write
clean
23C1000
unkown image
page readonly
clean
219B000
unkown image
page readonly
clean
214C66BB000
unkown
page read and write
clean
2B80000
unkown image
page readonly
clean
284B000
unkown image
page readonly
clean
214C0EAF000
unkown
page read and write
clean
2431000
unkown image
page readonly
clean
7FF578E57000
unkown image
page readonly
clean
2812000
unkown image
page readonly
clean
9C0000
unkown image
page readonly
clean
1EDC2B00000
unkown
page read and write
clean
7F300000
unkown image
page readonly
clean
28C1000
unkown image
page readonly
clean
214C1D20000
unkown
page read and write
clean
8240000
unkown
page read and write
clean
7FDF0000
unkown image
page readonly
clean
7FF578B89000
unkown image
page readonly
clean
228D000
unkown image
page readonly
clean
7FF578DE9000
unkown image
page readonly
clean
214C6430000
unkown
page read and write
clean
2C08000
unkown
page read and write
clean
7F2F2000
unkown image
page readonly
clean
1EDC2DA0000
unkown image
page readonly
clean
214C0E94000
unkown
page read and write
clean
231E000
unkown image
page readonly
clean
FF3B0000
unkown image
page readonly
clean
2295000
unkown image
page readonly
clean
214C62D5000
unkown
page read and write
clean
1EDC3800000
unkown
page readonly
clean
29FD000
unkown image
page readonly
clean
7FF578DEE000
unkown image
page readonly
clean
214C1E40000
unkown image
page readonly
clean
2BD0000
heap default
page read and write
clean
2CAC000
unkown
page read and write
clean
23AE000
unkown image
page readonly
clean
2494000
unkown image
page readonly
clean
10C0000
unkown image
page readonly
clean
2473000
unkown image
page readonly
clean
7C7327A000
stack
page read and write
clean
4B20000
unkown
page read and write
clean
501E000
stack
page read and write
clean
7FF578DE7000
unkown image
page readonly
clean
7FF50EF2D000
unkown image
page readonly
clean
29F4000
unkown image
page readonly
clean
2990000
unkown image
page readonly
clean
7FF578A0C000
unkown image
page readonly
clean
214C0F13000
unkown
page read and write
clean
7F2F2000
unkown image
page readonly
clean
24B8000
unkown image
page readonly
clean
29EC000
unkown image
page readonly
clean
27DC000
unkown image
page readonly
clean
4A20000
unkown image
page readonly
clean
2DF9000
unkown
page read and write
clean
2BFE000
unkown
page read and write
clean
FF3D0000
unkown image
page readonly
clean
2A58000
unkown
page read and write
clean
31B5000
heap default
page read and write
clean
2C15000
unkown
page read and write
clean
7FBB0000
unkown image
page readonly
clean
214C66D1000
unkown
page read and write
clean
2FD0000
unkown
page read and write
clean
303D000
unkown
page read and write
clean
3D30000
unkown image
page readonly
clean
2316000
unkown image
page readonly
clean
3DA1000
unkown
page read and write
clean
2DEE000
unkown
page read and write
clean
2445000
unkown image
page readonly
clean
2A6D000
unkown
page read and write
clean
7FF578C43000
unkown image
page readonly
clean
230B000
unkown image
page readonly
clean
2BDA000
heap default
page read and write
clean
290E000
unkown image
page readonly
clean
7FF12000
unkown image
page readonly
clean
214C0E8D000
unkown
page read and write
clean
1EDC2981000
unkown
page read and write
clean
9C0000
unkown image
page readonly
clean
2948000
unkown image
page readonly
clean
BDE000
stack
page read and write
clean
290E000
unkown image
page readonly
clean
539E000
stack
page read and write
clean
2DC3000
unkown
page read and write
clean
FF3C0000
unkown image
page readonly
clean
7C734FE000
stack
page read and write
clean
321B000
heap default
page read and write
clean
7FE00000
unkown image
page readonly
clean
214C6310000
unkown
page read and write
clean
232E000
unkown image
page readonly
clean
4E7E000
stack
page read and write
clean
2DB0000
unkown image
page readonly
clean
7FF578D15000
unkown image
page readonly
clean
214C66D1000
unkown
page read and write
clean
B8A000
unkown
page read and write
clean
2BF4000
heap default
page read and write
clean
1EDC2910000
unkown
page read and write
clean
294B000
unkown image
page readonly
clean
214C1E30000
unkown image
page readonly
clean
214C1E50000
unkown image
page readonly
clean
2827000
unkown image
page readonly
clean
7C728F7000
stack
page read and write
clean
2912000
unkown image
page readonly
clean
3BB0000
unkown image
page readonly
clean
214C669C000
unkown
page read and write
clean
214C1C40000
unkown image
page read and write
clean
3014000
heap default
page read and write
clean
2C50000
unkown image
page readonly
clean
DD2000
unkown
page execute and read and write
clean
2A18000
unkown image
page readonly
clean
525E000
stack
page read and write
clean
DDA000
unkown
page execute and read and write
clean
214C0E9F000
unkown
page read and write
clean
23B7000
unkown image
page readonly
clean
768D000
stack
page read and write
clean
7F300000
unkown image
page readonly
clean
2360000
unkown image
page readonly
clean
2C50000
unkown image
page readonly
clean
3540000
heap private
page read and write
clean
3130000
heap default
page read and write
clean
7FF578D0E000
unkown image
page readonly
clean
20AF000
unkown image
page readonly
clean
7FF50EEC7000
unkown image
page readonly
clean
5AD0000
unkown image
page readonly
clean
7FF50EF27000
unkown image
page readonly
clean
7C72B7A000
stack
page read and write
clean
1EDC2B89000
heap private
page read and write
clean
7FF578E86000
unkown image
page readonly
clean
2BFD000
unkown
page read and write
clean
31F7000
heap private
page read and write
clean
214C1E10000
unkown image
page readonly
clean
27A0000
unkown image
page readonly
clean
33B2000
unkown
page read and write
clean
234D000
unkown image
page readonly
clean
2AA0000
unkown
page read and write
clean
12D0000
heap private
page read and write
clean
2466000
unkown image
page readonly
clean
7FB60000
unkown image
page readonly
clean
214C1200000
unkown image
page readonly
clean
7F2E2000
unkown image
page readonly
clean
7FF578B3D000
unkown image
page readonly
clean
7FA50000
unkown image
page readonly
clean
5BC0000
unkown image
page readonly
clean
FF3D0000
unkown image
page readonly
clean
214C0D50000
unkown image
page readonly
clean
F30000
heap default
page read and write
clean
284E000
unkown image
page readonly
clean
7FF578703000
unkown image
page readonly
clean
C7D000
unkown image
page readonly
clean
33A1000
unkown
page read and write
clean
2A41000
unkown
page read and write
clean
7F2F0000
unkown image
page readonly
clean
7FF50ECFC000
unkown image
page readonly
clean
2E87000
heap private
page read and write
clean
2BC0000
unkown
page read and write
clean
7FE10000
unkown image
page readonly
clean
2328000
unkown image
page readonly
clean
7DF582C40000
unkown image
page readonly
clean
31A5000
heap default
page read and write
clean
CB0000
heap default
page read and write
clean
7FF578D70000
unkown image
page readonly
clean
7FF50EEC9000
unkown image
page readonly
clean
7F300000
unkown image
page readonly
clean
22BD000
unkown image
page readonly
clean
214C66A4000
unkown
page read and write
clean
286A000
unkown image
page readonly
clean
511D000
stack
page read and write
clean
1EDC2B80000
heap private
page read and write
clean
888000
unkown
page read and write
clean
22F5000
unkown image
page readonly
clean
7DF582C40000
unkown image
page readonly
clean
FF3D0000
unkown image
page readonly
clean
214C6630000
unkown
page read and write
clean
3021000
unkown
page read and write
clean
1EDC35B0000
unkown
page read and write
clean
2271000
unkown image
page readonly
clean
2162000
unkown image
page readonly
clean
2DA1000
unkown
page read and write
clean
A30000
unkown image
page readonly
clean
7FF20000
unkown image
page readonly
clean
214C6700000
unkown
page read and write
clean
7FF578C37000
unkown image
page readonly
clean
214C0E7B000
unkown
page read and write
clean
A30000
unkown image
page readonly
clean
7FF30000
unkown image
page readonly
clean
1EDC2981000
unkown
page read and write
clean
2932000
unkown image
page readonly
clean
7FF578D91000
unkown image
page readonly
clean
7FF12000
unkown image
page readonly
clean
2A30000
unkown image
page readonly
clean
2291000
unkown image
page readonly
clean
277B000
unkown image
page readonly
clean
2B70000
unkown image
page read and write
clean
2DC0000
unkown image
page readonly
clean
29E7000
heap private
page read and write
clean
DEB000
unkown
page read and write
clean
4B10000
heap private
page read and write
clean
7FF578B6F000
unkown image
page readonly
clean
1EDC2B90000
unkown
page read and write
clean
7FF578E54000
unkown image
page readonly
clean
7DF518D10000
unkown image
page readonly
clean
7C730FF000
stack
page read and write
clean
2FF0000
heap default
page read and write
clean
564F000
stack
page read and write
clean
29FE000
unkown
page read and write
clean
1EDC28C0000
unkown image
page readonly
clean
7F1E0000
unkown image
page readonly
clean
7DF518D22000
unkown image
page readonly
clean
214C1600000
unkown
page read and write
clean
216D000
unkown image
page readonly
clean
2A55000
unkown
page read and write
clean
2482000
unkown image
page readonly
clean
2DB2000
unkown
page read and write
clean
7FF578630000
unkown image
page readonly
clean
2BF1000
unkown
page read and write
clean
214C1718000
unkown
page read and write
clean
2742000
unkown image
page readonly
clean
7FE02000
unkown image
page readonly
clean
214C6430000
unkown
page read and write
clean
249D000
unkown image
page readonly
clean
283D000
unkown image
page readonly
clean
1292000
unkown
page execute and read and write
clean
2267000
unkown image
page readonly
clean
8A3000
unkown image
page readonly
clean
7890000
unkown
page read and write
clean
2A2A000
heap default
page read and write
clean
1EDC28C0000
unkown image
page readonly
clean
29D8000
unkown image
page readonly
clean
2EE0000
unkown image
page readonly
clean
7FF10000
unkown image
page readonly
clean
214C6600000
unkown
page read and write
clean
2875000
unkown image
page readonly
clean
303D000
unkown
page read and write
clean
2890000
heap private
page read and write
clean
FF3C2000
unkown image
page readonly
clean
23DD000
unkown image
page readonly
clean
FF3C2000
unkown image
page readonly
clean
2DB0000
unkown image
page readonly
clean
1EDC297A000
unkown
page read and write
clean
7FF50EEB6000
unkown image
page readonly
clean
2DAB000
unkown
page read and write
clean
7F2F0000
unkown image
page readonly
clean
7FF578C67000
unkown image
page readonly
clean
7F2F0000
unkown image
page readonly
clean
DE0000
unkown
page read and write
clean
7FF578B82000
unkown image
page readonly
clean
780F000
stack
page read and write
clean
29C0000
unkown
page read and write
clean
7FF22000
unkown image
page readonly
clean
7FF578D67000
unkown image
page readonly
clean
2478000
unkown image
page readonly
clean
2A51000
unkown
page read and write
clean
2A4D000
unkown
page read and write
clean
7DF582C50000
unkown image
page readonly
clean
4B14000
heap private
page read and write
clean
214C1759000
unkown
page read and write
clean
7F2E0000
unkown image
page readonly
clean
214C62F0000
unkown
page read and write
clean
214C6652000
unkown
page read and write
clean
2BF9000
unkown
page read and write
clean
DE2000
unkown
page execute and read and write
clean
4FB0000
unkown
page read and write
clean
7DF480B00000
unkown image
page readonly
clean
31F0000
heap private
page read and write
clean
770E000
stack
page read and write
clean
286D000
unkown image
page readonly
clean
FF3B0000
unkown image
page readonly
clean
784E000
stack
page read and write
clean
26C4000
unkown
page read and write
clean
214C1000000
unkown image
page readonly
clean
1EDC2B70000
unkown
page read and write
clean
2BF9000
unkown
page read and write
clean
7FE10000
unkown image
page readonly
clean
1EDC3870000
unkown
page read and write
clean
2448000
unkown image
page readonly
clean
2850000
unkown image
page readonly
clean
2908000
unkown image
page readonly
clean
7FF578D64000
unkown image
page readonly
clean
214C6430000
unkown
page read and write
clean
39B0000
unkown image
page readonly
clean
7C724CC000
unkown
page read and write
clean
FF3C2000
unkown image
page readonly
clean
860000
unkown image
page readonly
clean
7FF50EB44000
unkown image
page readonly
clean
23E1000
unkown image
page readonly
clean
7FB50000
unkown image
page readonly
clean
9D0000
unkown image
page readonly
clean
22DD000
unkown image
page readonly
clean
4FA0000
unkown
page execute and read and write
clean
7FF578672000
unkown image
page readonly
clean
7FF578DDD000
unkown image
page readonly
clean
214C0D80000
unkown image
page read and write
clean
7FB60000
unkown image
page readonly
clean
2A44000
heap default
page read and write
clean
287B000
unkown image
page readonly
clean
2A18000
unkown image
page readonly
clean
77CE000
stack
page read and write
clean
7FF50EB3F000
unkown image
page readonly
clean
214C0E79000
unkown
page read and write
clean
7FF578C3F000
unkown image
page readonly
clean
BE0000
unkown
page read and write
clean
2C01000
unkown
page read and write
clean
2D75F9000
stack
page read and write
clean
2A4D000
unkown
page read and write
clean
7FF578DBA000
unkown image
page readonly
clean
2A51000
unkown
page read and write
clean
301E000
unkown
page read and write
clean
2DDA000
unkown
page read and write
clean
2DEA000
unkown
page read and write
clean
774F000
stack
page read and write
clean
7C7E000
stack
page read and write
clean
2871000
unkown image
page readonly
clean
2A10000
unkown image
page readonly
clean
1EDC35A0000
unkown
page read and write
clean
DC0000
unkown
page read and write
clean
22F8000
unkown image
page readonly
clean
7FF578C53000
unkown image
page readonly
clean
25FA000
unkown
page read and write
clean
214C0EFD000
unkown
page read and write
clean
2F7B000
unkown
page read and write
clean
2D76F9000
stack
page read and write
clean
7FF50EEBD000
unkown image
page readonly
clean
2344000
unkown image
page readonly
clean
FF3C0000
unkown image
page readonly
clean
7F2F2000
unkown image
page readonly
clean
2D71BE000
stack
page read and write
clean
550F000
stack
page read and write
clean
2921000
unkown image
page readonly
clean
There are 839 hidden memdumps, click here to show them.