IOC Report

loading gif

Files

File Path
Type
Category
Malicious
sample2.xls.xls
Composite Document File V2 Document, Little Endian, Os: MacOS, Version 6.11, Code page: -535, Last Saved By: Microsoft Office User, Name of Creating Application: Microsoft Macintosh Excel, Create Time/Date: Fri Jun 5 19:19:34 2015, Last Saved Time/Date: Sun Nov 21 19:57:52 2021, Security: 0
initial sample
malicious
C:\Users\user\Desktop\sample2.xls.xls
Composite Document File V2 Document, Little Endian, Os: MacOS, Version 6.11, Code page: -535, Last Saved By: Microsoft Office User, Name of Creating Application: Microsoft Macintosh Excel, Create Time/Date: Fri Jun 5 19:19:34 2015, Last Saved Time/Date: Sun Nov 21 19:57:52 2021, Security: 0
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\3EDBDB2E-21C4-458B-81F0-642402DEC3FC
XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\5DA02DEB.tmp
Composite Document File V2 Document, Cannot read section info
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF4CC8EC7F64F458A9.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF620452FF3AABC9C7.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\7D1C.tmp
Composite Document File V2 Document, Cannot read section info
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF30EC3661E732423E.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF6FA4235239FD3AE0.TMP
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
"C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE" /automation -Embedding
malicious
C:\Windows\SysWOW64\regsvr32.exe
"C:\Windows\System32\regsvr32.exe" C:\Datop\test.test
malicious
C:\Windows\SysWOW64\regsvr32.exe
"C:\Windows\System32\regsvr32.exe" C:\Datop\test1.test
malicious
C:\Windows\SysWOW64\regsvr32.exe
"C:\Windows\System32\regsvr32.exe" C:\Datop\test2.test
malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
"C:\Windows\System32\regsvr32.exe" C:\Datop\test.test
malicious
C:\Windows\System32\regsvr32.exe
"C:\Windows\System32\regsvr32.exe" C:\Datop\test1.test
malicious
C:\Windows\System32\regsvr32.exe
"C:\Windows\System32\regsvr32.exe" C:\Datop\test2.test
malicious

URLs

Name
IP
Malicious
https://api.diagnosticssdf.office.com
unknown
clean
https://login.microsoftonline.com/
unknown
clean
https://shell.suite.office.com:1443
unknown
clean
https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
unknown
clean
https://autodiscover-s.outlook.com/
unknown
clean
https://roaming.edog.
unknown
clean
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
unknown
clean
https://cdn.entity.
unknown
clean
https://api.addins.omex.office.net/appinfo/query
unknown
clean
https://clients.config.office.net/user/v1.0/tenantassociationkey
unknown
clean
https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
unknown
clean
https://powerlift.acompli.net
unknown
clean
https://rpsticket.partnerservices.getmicrosoftkey.com
unknown
clean
https://lookup.onenote.com/lookup/geolocation/v1
unknown
clean
https://cortana.ai
unknown
clean
https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
unknown
clean
https://cloudfiles.onenote.com/upload.aspx
unknown
clean
https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
unknown
clean
https://entitlement.diagnosticssdf.office.com
unknown
clean
https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
unknown
clean
https://api.aadrm.com/
unknown
clean
https://ofcrecsvcapi-int.azurewebsites.net/
unknown
clean
https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
unknown
clean
https://api.microsoftstream.com/api/
unknown
clean
https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
unknown
clean
https://cr.office.com
unknown
clean
https://augloop.office.com;https://augloop-int.officeppe.com;https://augloop-dogfood.officeppe.com;h
unknown
clean
https://portal.office.com/account/?ref=ClientMeControl
unknown
clean
https://graph.ppe.windows.net
unknown
clean
https://res.getmicrosoftkey.com/api/redemptionevents
unknown
clean
https://powerlift-frontdesk.acompli.net
unknown
clean
https://tasks.office.com
unknown
clean
https://officeci.azurewebsites.net/api/
unknown
clean
https://sr.outlook.office.net/ws/speech/recognize/assistant/work
unknown
clean
https://store.office.cn/addinstemplate
unknown
clean
https://api.aadrm.com
unknown
clean
https://outlook.office.com/autosuggest/api/v1/init?cvid=
unknown
clean
https://globaldisco.crm.dynamics.com
unknown
clean
https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
unknown
clean
https://dev0-api.acompli.net/autodetect
unknown
clean
https://www.odwebp.svc.ms
unknown
clean
https://api.powerbi.com/v1.0/myorg/groups
unknown
clean
https://web.microsoftstream.com/video/
unknown
clean
https://api.addins.store.officeppe.com/addinstemplate
unknown
clean
https://graph.windows.net
unknown
clean
https://dataservice.o365filtering.com/
unknown
clean
https://officesetup.getmicrosoftkey.com
unknown
clean
https://analysis.windows.net/powerbi/api
unknown
clean
https://prod-global-autodetect.acompli.net/autodetect
unknown
clean
https://outlook.office365.com/autodiscover/autodiscover.json
unknown
clean
https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
unknown
clean
https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
unknown
clean
https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
unknown
clean
https://ncus.contentsync.
unknown
clean
https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
unknown
clean
https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
unknown
clean
http://weather.service.msn.com/data.aspx
unknown
clean
https://apis.live.net/v5.0/
unknown
clean
https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
unknown
clean
https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
unknown
clean
https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
unknown
clean
https://management.azure.com
unknown
clean
https://outlook.office365.com
unknown
clean
https://wus2.contentsync.
unknown
clean
https://incidents.diagnostics.office.com
unknown
clean
https://clients.config.office.net/user/v1.0/ios
unknown
clean
https://insertmedia.bing.office.net/odc/insertmedia
unknown
clean
https://o365auditrealtimeingestion.manage.office.com
unknown
clean
https://outlook.office365.com/api/v1.0/me/Activities
unknown
clean
https://api.office.net
unknown
clean
https://incidents.diagnosticssdf.office.com
unknown
clean
https://asgsmsproxyapi.azurewebsites.net/
unknown
clean
https://clients.config.office.net/user/v1.0/android/policies
unknown
clean
https://entitlement.diagnostics.office.com
unknown
clean
https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
unknown
clean
https://substrate.office.com/search/api/v2/init
unknown
clean
https://outlook.office.com/
unknown
clean
https://storage.live.com/clientlogs/uploadlocation
unknown
clean
https://outlook.office365.com/
unknown
clean
https://webshell.suite.office.com
unknown
clean
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
unknown
clean
https://substrate.office.com/search/api/v1/SearchHistory
unknown
clean
https://management.azure.com/
unknown
clean
https://login.windows.net/common/oauth2/authorize
unknown
clean
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
unknown
clean
https://graph.windows.net/
unknown
clean
https://api.powerbi.com/beta/myorg/imports
unknown
clean
https://devnull.onenote.com
unknown
clean
https://ncus.pagecontentsync.
unknown
clean
https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
unknown
clean
https://messaging.office.com/
unknown
clean
https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
unknown
clean
https://augloop.office.com/v2
unknown
clean
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
unknown
clean
https://skyapi.live.net/Activity/
unknown
clean
https://clients.config.office.net/user/v1.0/mac
unknown
clean
https://dataservice.o365filtering.com
unknown
clean
https://api.cortana.ai
unknown
clean
https://onedrive.live.com
unknown
clean
https://ovisualuiapp.azurewebsites.net/pbiagave/
unknown
clean
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://investor.msn.com/
unknown
clean
There are 101 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
gupta-foods.xyz
51.15.56.22
malicious
gupta-airways.icu
51.15.56.22
clean
gupta-technologies.sbs
51.15.56.22
clean

IPs

IP
Domain
Country
Malicious
51.15.56.22
gupta-foods.xyz
France
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems
e '
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems
f '
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\IOAV
LastBootTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache
RemoteClearDate
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.4954&crev=3
Last
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\DocumentRecovery\2195B
2195B
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109110000000000000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ExdCache\Excel8.0
MSForms
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ExdCache\Excel8.0
MSComctlLib
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.4954&crev=3\0
FilePath
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.4954&crev=3\0
StartDate
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.4954&crev=3\0
EndDate
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.4954&crev=3\0
Properties
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.4954&crev=3\0
Url
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache
LastClean
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
DisableWinHttpCertAuth
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
DisableIsOwnerRegex
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
DisableSessionAwareHttpClose
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
DisableADALForExtendedApps
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
DisableADALSetSilentAuth
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
msoridDisableGuestCredProvider
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
msoridDisableOstringReplace
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems
ey'
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109E60090400000000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\DocumentRecovery\38BE6
38BE6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\DocumentRecovery\39D1D
39D1D
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General
FileFormatBallotBoxAppIDBootedOnce
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109110000000000000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
en-US
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
en-US
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109110000000000000000F01FEC\Usage
EXCELFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming
RoamingConfigurableSettings
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming
RoamingLastSyncTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming
RoamingLastWriteTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\IOAV
LastBootTime
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109E60090400000000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
r--
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2E031
2E031
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
>-
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\48778
48778
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\48EE7
48EE7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
There are 88 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
7DF586150000
unkown image
page readonly
clean
1036ADC6000
heap default
page read and write
clean
1BB11E02000
unkown
page read and write
clean
697000
heap private
page read and write
clean
1D461650000
unkown
page read and write
clean
1D4EE47E000
unkown
page read and write
clean
7FF5571B5000
unkown image
page readonly
clean
7FF53660E000
unkown image
page readonly
clean
27D6000
unkown image
page readonly
clean
1BB11687000
unkown
page read and write
clean
7FF4FE927000
unkown image
page readonly
clean
7FF591B11000
unkown image
page readonly
clean
1D461FB0000
unkown
page read and write
clean
6DC000
unkown
page read and write
clean
95F207E000
stack
page read and write
clean
7FF536BFC000
unkown image
page readonly
clean
2A720FE000
stack
page read and write
clean
7FF53653A000
unkown image
page readonly
clean
1D4EE300000
unkown image
page readonly
clean
DB708FE000
stack
page read and write
clean
7FF57841E000
unkown image
page readonly
clean
1D4EEC02000
unkown
page read and write
clean
7FF59912C000
unkown image
page readonly
clean
26EF000
unkown image
page readonly
clean
100000
unkown image
page readonly
clean
1D4EE2F0000
heap private
page read and write
clean
7FF522CA1000
unkown image
page readonly
clean
7FF4FE977000
unkown image
page readonly
clean
7DF50C670000
unkown image
page readonly
clean
1D4EE400000
unkown
page read and write
clean
7FF4FE7B1000
unkown image
page readonly
clean
7FF591B11000
unkown image
page readonly
clean
1D462400000
unkown
page read and write
clean
3360000
unkown image
page readonly
clean
2706000
unkown image
page readonly
clean
1BB11650000
unkown
page read and write
clean
9C0000
heap private
page read and write
clean
2AE7000
unkown image
page readonly
clean
7FF4FE937000
unkown image
page readonly
clean
7FF591896000
unkown image
page readonly
clean
7FF599292000
unkown image
page readonly
clean
7FF5991E7000
unkown image
page readonly
clean
7FF5570E7000
unkown image
page readonly
clean
72FF000
stack
page read and write
clean
9C4000
heap private
page read and write
clean
23EB000
unkown image
page readonly
clean
7FF55713D000
unkown image
page readonly
clean
DB706FE000
stack
page read and write
clean
7F0C2000
unkown image
page readonly
clean
1BB1168D000
unkown
page read and write
clean
7FF4FE9E4000
unkown image
page readonly
clean
27B4000
unkown image
page readonly
clean
1D461FBE000
unkown
page read and write
clean
7FF4FE8E3000
unkown image
page readonly
clean
7DF59F772000
unkown image
page readonly
clean
4D7000
heap private
page read and write
clean
1D4EE500000
unkown
page read and write
clean
7FF591A23000
unkown image
page readonly
clean
1036AD20000
unkown image
page readonly
clean
1D461FB7000
unkown
page read and write
clean
1D461613000
unkown
page read and write
clean
7FF578417000
unkown image
page readonly
clean
1D4EE43C000
unkown
page read and write
clean
2725000
unkown image
page readonly
clean
7FF4FE367000
unkown image
page readonly
clean
67E000
stack
page read and write
clean
7FF5992C1000
unkown image
page readonly
clean
100000
unkown image
page readonly
clean
1D4615D0000
unkown
page read and write
clean
7FF591A5B000
unkown image
page readonly
clean
2716000
unkown image
page readonly
clean
1D4614B0000
unkown image
page readonly
clean
8850BFD000
stack
page read and write
clean
7300000
unkown
page read and write
clean
7FF5782A1000
unkown image
page readonly
clean
7DF50C670000
unkown image
page readonly
clean
7DF59F790000
unkown image
page readonly
clean
1B0000
unkown image
page readonly
clean
7FF591A37000
unkown image
page readonly
clean
7DF50C672000
unkown image
page readonly
clean
27B4000
unkown image
page readonly
clean
7DF5A6F20000
unkown image
page readonly
clean
2A10000
unkown image
page readonly
clean
7FF536BA2000
unkown image
page readonly
clean
7FF536D74000
unkown image
page readonly
clean
7DF5A6F32000
unkown image
page readonly
clean
7DF564E40000
unkown image
page readonly
clean
7F0D2000
unkown image
page readonly
clean
1D461F89000
unkown
page read and write
clean
4F5000
unkown
page read and write
clean
7FF59923D000
unkown image
page readonly
clean
1BB11670000
unkown
page read and write
clean
7FF4FE7EB000
unkown image
page readonly
clean
26EF000
unkown image
page readonly
clean
7DF564E20000
unkown image
page readonly
clean
1036ABE0000
unkown image
page readonly
clean
7FF57844E000
unkown image
page readonly
clean
7FF5782C0000
unkown image
page readonly
clean
1D4EE350000
heap default
page read and write
clean
1D4EE48D000
unkown
page read and write
clean
7FF591A19000
unkown image
page readonly
clean
33DA000
heap private
page read and write
clean
2725000
unkown image
page readonly
clean
512000
unkown
page read and write
clean
2FD000
unkown
page read and write
clean
7FF5784D4000
unkown image
page readonly
clean
7FF5570E0000
unkown image
page readonly
clean
7FF578403000
unkown image
page readonly
clean
7FF5365A8000
unkown image
page readonly
clean
2C39000
unkown image
page readonly
clean
2A723F9000
stack
page read and write
clean
7FF536CB3000
unkown image
page readonly
clean
7FF591A63000
unkown image
page readonly
clean
248DDC00000
unkown
page read and write
clean
3400000
heap default
page read and write
clean
7F0C0000
unkown image
page readonly
clean
2746000
unkown image
page readonly
clean
340A000
heap default
page read and write
clean
19B000
unkown
page read and write
clean
1D461657000
unkown
page read and write
clean
1D461F62000
unkown
page read and write
clean
6E1000
unkown
page read and write
clean
248DDC6E000
unkown
page read and write
clean
7FF536D91000
unkown image
page readonly
clean
1D462402000
unkown
page read and write
clean
6BA000
heap default
page read and write
clean
7FF4FE90F000
unkown image
page readonly
clean
7FF536D0D000
unkown image
page readonly
clean
7FF5784EA000
unkown image
page readonly
clean
7DF59F790000
unkown image
page readonly
clean
27BB000
unkown image
page readonly
clean
1D4EE508000
unkown
page read and write
clean
218C7E60000
unkown
page read and write
clean
218C7AFF000
unkown
page read and write
clean
7FF591B01000
unkown image
page readonly
clean
7FF591965000
unkown image
page readonly
clean
26DE000
unkown image
page readonly
clean
1D461B80000
unkown image
page readonly
clean
7FF5990CF000
unkown image
page readonly
clean
2D7BFA000
stack
page read and write
clean
7FF578175000
unkown image
page readonly
clean
1BB11602000
unkown
page read and write
clean
6B0000
heap default
page read and write
clean
248DDC2A000
unkown
page read and write
clean
7FF5992A4000
unkown image
page readonly
clean
515000
unkown
page read and write
clean
2719000
unkown image
page readonly
clean
40A0000
unkown
page read and write
clean
7FF4FE923000
unkown image
page readonly
clean
1BB11708000
unkown
page read and write
clean
7FF4FEA00000
unkown image
page readonly
clean
7FF4FE7D0000
unkown image
page readonly
clean
7FF4FE80F000
unkown image
page readonly
clean
248DE402000
unkown
page read and write
clean
69F000
stack
page read and write
clean
1D4EE467000
unkown
page read and write
clean
95F1C7B000
stack
page read and write
clean
5D0000
unkown
page read and write
clean
7DF59F780000
unkown image
page readonly
clean
7DF59F772000
unkown image
page readonly
clean
620000
unkown
page read and write
clean
1D461F89000
unkown
page read and write
clean
7FF4FE8EE000
unkown image
page readonly
clean
1D4EE45C000
unkown
page read and write
clean
6D8000
unkown
page read and write
clean
7DF586170000
unkown image
page readonly
clean
26DE000
unkown image
page readonly
clean
3445000
unkown
page read and write
clean
2D08000
unkown image
page readonly
clean
7DF50C662000
unkown image
page readonly
clean
7DF5A6F40000
unkown image
page readonly
clean
540000
heap default
page read and write
clean
4DA000
heap default
page read and write
clean
248DDD13000
unkown
page read and write
clean
3270000
heap default
page read and write
clean
7FF5784E1000
unkown image
page readonly
clean
1D462402000
unkown
page read and write
clean
1BB11560000
unkown image
page read and write
clean
1D4EEA50000
unkown image
page readonly
clean
7DF49D640000
unkown image
page readonly
clean
7FF4FE817000
unkown image
page readonly
clean
1D461F89000
unkown
page read and write
clean
1BB11570000
heap private
page read and write
clean
7FF59908D000
unkown image
page readonly
clean
2973000
unkown image
page readonly
clean
7F0C2000
unkown image
page readonly
clean
33A0000
unkown image
page readonly
clean
29E000
unkown
page read and write
clean
2C66000
unkown image
page readonly
clean
1D4EE465000
unkown
page read and write
clean
1BB11700000
unkown
page read and write
clean
7FF59191F000
unkown image
page readonly
clean
2C4F000
unkown image
page readonly
clean
27BB000
unkown image
page readonly
clean
1D462402000
unkown
page read and write
clean
88503FE000
stack
page read and write
clean
7FF578276000
unkown image
page readonly
clean
DB709FF000
stack
page read and write
clean
7FF536C9D000
unkown image
page readonly
clean
1D4EE8D0000
unkown image
page readonly
clean
1BB11C50000
unkown image
page readonly
clean
1D4EE2E0000
unkown image
page read and write
clean
248DDD00000
unkown
page read and write
clean
2C6B000
unkown image
page readonly
clean
218C7E00000
unkown image
page readonly
clean
218C7AFF000
unkown
page read and write
clean
7FF5918FB000
unkown image
page readonly
clean
7FF5991E0000
unkown image
page readonly
clean
7F0F2000
unkown image
page readonly
clean
4FC000
unkown
page read and write
clean
7FF536C96000
unkown image
page readonly
clean
1D461F9C000
unkown
page read and write
clean
7F0E0000
unkown image
page readonly
clean
7F0D2000
unkown image
page readonly
clean
7FF536B2A000
unkown image
page readonly
clean
7FF536D7A000
unkown image
page readonly
clean
732687E000
stack
page read and write
clean
218C8900000
unkown
page read and write
clean
7F0F2000
unkown image
page readonly
clean
1D4EE502000
unkown
page read and write
clean
218C7E20000
unkown
page read and write
clean
4E0000
unkown image
page readonly
clean
885067D000
stack
page read and write
clean
1D461655000
unkown
page read and write
clean
1D461F4E000
unkown
page read and write
clean
2C5D000
unkown image
page readonly
clean
7F0E0000
unkown image
page readonly
clean
2B2C000
unkown image
page readonly
clean
1D461F6A000
unkown
page read and write
clean
7FF591A8D000
unkown image
page readonly
clean
27AB000
unkown image
page readonly
clean
1D461CF0000
unkown
page read and write
clean
1D4EE46A000
unkown
page read and write
clean
1D461F9C000
unkown
page read and write
clean
1D4EE360000
unkown image
page readonly
clean
1E0000
unkown image
page readonly
clean
1D461F9E000
unkown
page read and write
clean
248DDBB0000
unkown
page read and write
clean
7FF5784C2000
unkown image
page readonly
clean
1D462500000
unkown
page read and write
clean
1D461F81000
unkown
page read and write
clean
7FF5571A4000
unkown image
page readonly
clean
2719000
unkown image
page readonly
clean
2D08000
unkown image
page readonly
clean
7DF50C680000
unkown image
page readonly
clean
7FF591A87000
unkown image
page readonly
clean
7FF591AE2000
unkown image
page readonly
clean
7F0D0000
unkown image
page readonly
clean
7FF55713A000
unkown image
page readonly
clean
6570000
unkown image
page readonly
clean
3210000
unkown image
page readonly
clean
1D462563000
unkown
page read and write
clean
7DF50C680000
unkown image
page readonly
clean
7DF59F780000
unkown image
page readonly
clean
1036ADD9000
unkown
page read and write
clean
7F100000
unkown image
page readonly
clean
4D20000
heap private
page read and write
clean
1B0000
unkown image
page readonly
clean
7FAA0000
unkown image
page readonly
clean
7FA92000
unkown image
page readonly
clean
27D6000
unkown image
page readonly
clean
248DDC7C000
unkown
page read and write
clean
1D462402000
unkown
page read and write
clean
3380000
unkown
page read and write
clean
95F1AFE000
stack
page read and write
clean
4F8000
unkown
page read and write
clean
1D461FAA000
unkown
page read and write
clean
7326BF7000
stack
page read and write
clean
7F102000
unkown image
page readonly
clean
7FF5784F1000
unkown image
page readonly
clean
33B0000
unkown
page read and write
clean
7FF4FE9D2000
unkown image
page readonly
clean
3428000
unkown
page read and write
clean
3260000
unkown
page read and write
clean
5740000
unkown image
page readonly
clean
7FF591A6E000
unkown image
page readonly
clean
4CDE000
stack
page read and write
clean
2C2A000
unkown image
page readonly
clean
7FF59894C000
unkown image
page readonly
clean
7FF59197C000
unkown image
page readonly
clean
7DF4A4DF0000
unkown image
page readonly
clean
7FF536CB0000
unkown image
page readonly
clean
F0000
unkown image
page read and write
clean
7FA80000
unkown image
page readonly
clean
7FF599145000
unkown image
page readonly
clean
1D461600000
unkown
page read and write
clean
7DF586162000
unkown image
page readonly
clean
7FF599046000
unkown image
page readonly
clean
7DF564E20000
unkown image
page readonly
clean
7FF57843B000
unkown image
page readonly
clean
1D461670000
unkown
page read and write
clean
2453000
unkown image
page readonly
clean
7F0F0000
unkown image
page readonly
clean
2746000
unkown image
page readonly
clean
3700000
unkown image
page readonly
clean
7FF4FE855000
unkown image
page readonly
clean
DB707F7000
stack
page read and write
clean
7250000
unkown
page read and write
clean
218C8920000
unkown
page read and write
clean
1D0000
unkown image
page readonly
clean
1036ADEF000
unkown
page read and write
clean
1D461F6F000
unkown
page read and write
clean
7FF536533000
unkown image
page readonly
clean
73E0000
unkown
page read and write
clean
7FF536D0A000
unkown image
page readonly
clean
2AF3000
unkown image
page readonly
clean
7FF578467000
unkown image
page readonly
clean
33D0000
heap private
page read and write
clean
7DF544A10000
unkown image
page readonly
clean
1D461FAA000
unkown
page read and write
clean
260C000
unkown image
page readonly
clean
8170000
unkown
page read and write
clean
7FA80000
unkown image
page readonly
clean
7FF4FE95E000
unkown image
page readonly
clean
7FF536CEE000
unkown image
page readonly
clean
7DF586160000
unkown image
page readonly
clean
1D46163C000
unkown
page read and write
clean
1D461F7F000
unkown
page read and write
clean
573E000
stack
page read and write
clean
7FF577D06000
unkown image
page readonly
clean
1D4615B0000
unkown image
page readonly
clean
7DF50C660000
unkown image
page readonly
clean
1D461FB1000
unkown
page read and write
clean
248DDC4A000
unkown
page read and write
clean
7FF591995000
unkown image
page readonly
clean
1D4EE513000
unkown
page read and write
clean
1D4616F9000
unkown
page read and write
clean
1D46164F000
unkown
page read and write
clean
1BB11AD0000
unkown image
page readonly
clean
47B000
unkown
page read and write
clean
7FF5569F9000
unkown image
page readonly
clean
1D4616DF000
unkown
page read and write
clean
7FF5570CD000
unkown image
page readonly
clean
7FF536C9F000
unkown image
page readonly
clean
218C79F0000
unkown image
page readonly
clean
7DF5A6F30000
unkown image
page readonly
clean
7FF557199000
unkown image
page readonly
clean
218C8910000
unkown
page readonly
clean
7FF4FE9F1000
unkown image
page readonly
clean
7FF5782DB000
unkown image
page readonly
clean
1BB1162A000
unkown
page read and write
clean
7FF5784DA000
unkown image
page readonly
clean
7FF57846D000
unkown image
page readonly
clean
260C000
unkown image
page readonly
clean
218C7AFF000
unkown
page read and write
clean
7DF544A00000
unkown image
page readonly
clean
7326AFA000
stack
page read and write
clean
7FF4FE8DA000
unkown image
page readonly
clean
1D46246A000
unkown
page read and write
clean
1D46246A000
unkown
page read and write
clean
218C7A00000
unkown image
page readonly
clean
7FF5992C1000
unkown image
page readonly
clean
1D4EE469000
unkown
page read and write
clean
7FF4FE75F000
unkown image
page readonly
clean
273D000
unkown image
page readonly
clean
33F0000
unkown
page read and write
clean
1BB11613000
unkown
page read and write
clean
2FFB000
unkown
page read and write
clean
1D4EE461000
unkown
page read and write
clean
2A10000
unkown image
page readonly
clean
7FF599299000
unkown image
page readonly
clean
1BB115D0000
heap default
page read and write
clean
218C79D0000
unkown image
page readonly
clean
1D4616D6000
unkown
page read and write
clean
1D461F90000
unkown
page read and write
clean
3425000
unkown
page read and write
clean
512000
unkown
page read and write
clean
7326EF8000
stack
page read and write
clean
1D4616A8000
unkown
page read and write
clean
2BFE000
unkown image
page readonly
clean
600000
unkown image
page readonly
clean
218C86D0000
unkown
page read and write
clean
1036ADC6000
unkown
page read and write
clean
1BB11702000
unkown
page read and write
clean
248DDC50000
unkown
page read and write
clean
1D461FAA000
unkown
page read and write
clean
7FF557192000
unkown image
page readonly
clean
1036AD30000
unkown image
page readonly
clean
27CB000
unkown image
page readonly
clean
7FF598952000
unkown image
page readonly
clean
248DDC4E000
unkown
page read and write
clean
7FF4FE746000
unkown image
page readonly
clean
29A000
unkown
page read and write
clean
43B000
unkown
page read and write
clean
7FF4FE885000
unkown image
page readonly
clean
1BB11600000
unkown
page read and write
clean
7FF578375000
unkown image
page readonly
clean
218C7E55000
heap private
page read and write
clean
3880000
unkown image
page readonly
clean
7FF5915F7000
unkown image
page readonly
clean
1D461480000
unkown image
page readonly
clean
1D4616C5000
unkown
page read and write
clean
1D462502000
unkown
page read and write
clean
1D461FB0000
unkown
page read and write
clean
7DF4428C0000
unkown image
page readonly
clean
7FF5569FC000
unkown image
page readonly
clean
1D4616BE000
unkown
page read and write
clean
27DC000
unkown image
page readonly
clean
33D7000
heap private
page read and write
clean
7DF50C672000
unkown image
page readonly
clean
1BB11580000
unkown image
page readonly
clean
27E3000
unkown image
page readonly
clean
1D461F81000
unkown
page read and write
clean
6F5000
unkown
page read and write
clean
1D461800000
unkown image
page readonly
clean
1A0000
unkown image
page readonly
clean
7FF5991E3000
unkown image
page readonly
clean
7FF591B0A000
unkown image
page readonly
clean
7FF5991EE000
unkown image
page readonly
clean
248DDA80000
unkown image
page readonly
clean
7FF5570D3000
unkown image
page readonly
clean
4D0000
heap default
page read and write
clean
2615000
unkown image
page readonly
clean
2CCB000
unkown image
page readonly
clean
1D462402000
unkown
page read and write
clean
2CDB000
unkown image
page readonly
clean
1D46168B000
unkown
page read and write
clean
803D000
stack
page read and write
clean
7FF4FE953000
unkown image
page readonly
clean
680000
unkown image
page readonly
clean
7DF5A6F32000
unkown image
page readonly
clean
23EB000
unkown image
page readonly
clean
7FF536D85000
unkown image
page readonly
clean
7FF536CDB000
unkown image
page readonly
clean
7FF5570E3000
unkown image
page readonly
clean
7FF5991D3000
unkown image
page readonly
clean
7FF4FE8DE000
unkown image
page readonly
clean
7FF5571C1000
unkown image
page readonly
clean
7FF591AF4000
unkown image
page readonly
clean
7DF5A6F22000
unkown image
page readonly
clean
27C1000
unkown image
page readonly
clean
7FF53661E000
unkown image
page readonly
clean
7FF591A47000
unkown image
page readonly
clean
7FF599237000
unkown image
page readonly
clean
1D461F13000
unkown
page read and write
clean
73269FC000
stack
page read and write
clean
1D4616A1000
unkown
page read and write
clean
7FF4FE913000
unkown image
page readonly
clean
7FF5991C9000
unkown image
page readonly
clean
1D462563000
unkown
page read and write
clean
2701000
unkown image
page readonly
clean
DB701EE000
stack
page read and write
clean
2A7217D000
stack
page read and write
clean
7FF5991CD000
unkown image
page readonly
clean
1036ABC0000
unkown image
page readonly
clean
1D461F6F000
unkown
page read and write
clean
7FF577B7C000
unkown image
page readonly
clean
6D5000
unkown
page read and write
clean
1036ADE0000
unkown
page read and write
clean
724F000
stack
page read and write
clean
2C4B000
unkown image
page readonly
clean
7FF591AFA000
unkown image
page readonly
clean
7DF40A530000
unkown image
page readonly
clean
7FF5991B7000
unkown image
page readonly
clean
7FF4FE70B000
unkown image
page readonly
clean
270A000
unkown image
page readonly
clean
7FF5911A2000
unkown image
page readonly
clean
7FF536D8A000
unkown image
page readonly
clean
1D4EE468000
unkown
page read and write
clean
7FF536960000
unkown image
page readonly
clean
2F60000
unkown image
page readonly
clean
248DDC8A000
unkown
page read and write
clean
9FE000
stack
page read and write
clean
7FF4FE092000
unkown image
page readonly
clean
6D3000
heap default
page read and write
clean
27AB000
unkown image
page readonly
clean
7FF5365AA000
unkown image
page readonly
clean
7FF599141000
unkown image
page readonly
clean
DB7047D000
stack
page read and write
clean
1D461716000
unkown
page read and write
clean
1D4EE330000
unkown image
page readonly
clean
1D461480000
unkown image
page readonly
clean
7FF4FE744000
unkown image
page readonly
clean
8080000
unkown
page read and write
clean
1D46164D000
unkown
page read and write
clean
7FF536619000
unkown image
page readonly
clean
7DF544A02000
unkown image
page readonly
clean
7FF578371000
unkown image
page readonly
clean
1D4616AC000
unkown
page read and write
clean
7FF5992AA000
unkown image
page readonly
clean
290B000
unkown image
page readonly
clean
1036ADD8000
unkown
page read and write
clean
218C79B0000
unkown image
page read and write
clean
7FF578413000
unkown image
page readonly
clean
2B35000
unkown image
page readonly
clean
95F1E77000
stack
page read and write
clean
1036ADE0000
unkown
page read and write
clean
7FF591991000
unkown image
page readonly
clean
272F000
unkown image
page readonly
clean
1D462421000
unkown
page read and write
clean
8850AFF000
stack
page read and write
clean
2CD4000
unkown image
page readonly
clean
7FF4FE9EA000
unkown image
page readonly
clean
1D461F9C000
unkown
page read and write
clean
4D0000
heap private
page read and write
clean
1D46164C000
unkown
page read and write
clean
1D461702000
unkown
page read and write
clean
7FF578427000
unkown image
page readonly
clean
2A721FE000
stack
page read and write
clean
1036ADF0000
unkown
page read and write
clean
7FF598F45000
unkown image
page readonly
clean
4F3000
heap default
page read and write
clean
2C0F000
unkown image
page readonly
clean
2CEB000
unkown image
page readonly
clean
218C7AB7000
heap default
page read and write
clean
6D8000
unkown
page read and write
clean
7FF59921E000
unkown image
page readonly
clean
7FF598DA1000
unkown image
page readonly
clean
248DDA60000
unkown image
page readonly
clean
7FF5571B1000
unkown image
page readonly
clean
7FAA0000
unkown image
page readonly
clean
15B000
unkown
page read and write
clean
7FF536D91000
unkown image
page readonly
clean
7FF4FE9D9000
unkown image
page readonly
clean
4B0000
unkown
page read and write
clean
7FF599090000
unkown image
page readonly
clean
2C45000
unkown image
page readonly
clean
1D4EE413000
unkown
page read and write
clean
218C7E10000
unkown
page read and write
clean
4D24000
heap private
page read and write
clean
7FF4FE97A000
unkown image
page readonly
clean
7FF577B82000
unkown image
page readonly
clean
7DF462CF0000
unkown image
page readonly
clean
1D461D00000
unkown image
page read and write
clean
1036AD85000
heap private
page read and write
clean
7326DFF000
stack
page read and write
clean
1D4614A0000
unkown image
page readonly
clean
248DE180000
unkown image
page readonly
clean
1BB1167B000
unkown
page read and write
clean
218C7E30000
unkown
page read and write
clean
DB7067B000
stack
page read and write
clean
7FF5783E7000
unkown image
page readonly
clean
7FF57834B000
unkown image
page readonly
clean
2D7AFF000
stack
page read and write
clean
27E8000
unkown image
page readonly
clean
218C7C80000
unkown image
page readonly
clean
807E000
stack
page read and write
clean
27AF000
unkown image
page readonly
clean
1D461708000
unkown
page read and write
clean
95F1B7D000
stack
page read and write
clean
7FF4FE8B1000
unkown image
page readonly
clean
7F110000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7F102000
unkown image
page readonly
clean
218C8980000
unkown
page read and write
clean
7DF564E40000
unkown image
page readonly
clean
7FF4FE881000
unkown image
page readonly
clean
2CF6000
unkown image
page readonly
clean
690000
heap private
page read and write
clean
2FBA000
unkown
page read and write
clean
3431000
unkown
page read and write
clean
7DF59F782000
unkown image
page readonly
clean
7FF4FEA01000
unkown image
page readonly
clean
6D0000
unkown
page read and write
clean
2A7207C000
unkown
page read and write
clean
520000
unkown image
page readonly
clean
248DDB90000
unkown image
page readonly
clean
1D46164B000
unkown
page read and write
clean
7FF59911B000
unkown image
page readonly
clean
218C7A40000
unkown
page read and write
clean
218C7AF7000
unkown
page read and write
clean
7FF578345000
unkown image
page readonly
clean
27DC000
unkown image
page readonly
clean
8850A7E000
stack
page read and write
clean
7FF591A1D000
unkown image
page readonly
clean
1133000
unkown image
page readonly
clean
7DF5449F0000
unkown image
page readonly
clean
1D4615F0000
unkown image
page readonly
clean
1036AD80000
heap private
page read and write
clean
1BB1163C000
unkown
page read and write
clean
7FF4FE569000
unkown image
page readonly
clean
7DF5A6F22000
unkown image
page readonly
clean
501000
unkown
page read and write
clean
7FF5918E0000
unkown image
page readonly
clean
7DF5A6F20000
unkown image
page readonly
clean
7326F7F000
stack
page read and write
clean
7FF5918C1000
unkown image
page readonly
clean
3500000
unkown image
page readonly
clean
7FF4FE97D000
unkown image
page readonly
clean
1BB115E0000
unkown image
page readonly
clean
73268FE000
stack
page read and write
clean
2706000
unkown image
page readonly
clean
7FF577FD7000
unkown image
page readonly
clean
732707A000
stack
page read and write
clean
2D7C7E000
stack
page read and write
clean
2B90000
unkown image
page readonly
clean
1036ADC1000
unkown
page read and write
clean
7FF4FE812000
unkown image
page readonly
clean
3428000
unkown
page read and write
clean
248DDA90000
unkown image
page readonly
clean
248DDD08000
unkown
page read and write
clean
270A000
unkown image
page readonly
clean
248DDA60000
unkown image
page readonly
clean
272F000
unkown image
page readonly
clean
2D03000
unkown image
page readonly
clean
2D77BA000
unkown
page read and write
clean
1D461F81000
unkown
page read and write
clean
7DF544A10000
unkown image
page readonly
clean
1D4EE446000
unkown
page read and write
clean
1D462402000
unkown
page read and write
clean
1BB11655000
unkown
page read and write
clean
720E000
stack
page read and write
clean
7DF50C662000
unkown image
page readonly
clean
7DF5A6F40000
unkown image
page readonly
clean
500000
unkown
page read and write
clean
7FF4FE765000
unkown image
page readonly
clean
7FF557113000
unkown image
page readonly
clean
7FF4FE8C2000
unkown image
page readonly
clean
7FF4FE85B000
unkown image
page readonly
clean
7FF5918DD000
unkown image
page readonly
clean
2D7A7E000
stack
page read and write
clean
7DF59F770000
unkown image
page readonly
clean
2CCF000
unkown image
page readonly
clean
1D461FCE000
unkown
page read and write
clean
7DF586152000
unkown image
page readonly
clean
1D461F6D000
unkown
page read and write
clean
7DF564E30000
unkown image
page readonly
clean
6A0000
unkown image
page readonly
clean
1D4EE45B000
unkown
page read and write
clean
1D461FB0000
unkown
page read and write
clean
2B90000
unkown image
page readonly
clean
1D4614D0000
heap default
page read and write
clean
25C7000
unkown image
page readonly
clean
7FF591A30000
unkown image
page readonly
clean
2C26000
unkown image
page readonly
clean
1036ACF0000
unkown
page read and write
clean
1D4EE460000
unkown
page read and write
clean
7FF577FD1000
unkown image
page readonly
clean
7FF5571BA000
unkown image
page readonly
clean
2760000
unkown image
page readonly
clean
7DF544A02000
unkown image
page readonly
clean
7FF4FE909000
unkown image
page readonly
clean
7FF5782FF000
unkown image
page readonly
clean
7DF5449F2000
unkown image
page readonly
clean
1D461FAA000
unkown
page read and write
clean
2F60000
unkown image
page readonly
clean
1D461658000
unkown
page read and write
clean
272B000
unkown image
page readonly
clean
27E8000
unkown image
page readonly
clean
7FF55710B000
unkown image
page readonly
clean
7FF5783FD000
unkown image
page readonly
clean
7FF599115000
unkown image
page readonly
clean
2D7CFF000
stack
page read and write
clean
95F1A7B000
unkown
page read and write
clean
7FF55711E000
unkown image
page readonly
clean
1036B230000
unkown image
page readonly
clean
1A0000
unkown image
page read and write
clean
248DDC13000
unkown
page read and write
clean
3200000
unkown image
page readonly
clean
7FF4FE36B000
unkown image
page readonly
clean
7DF5449F2000
unkown image
page readonly
clean
2A7237F000
stack
page read and write
clean
7EFF0000
unkown image
page readonly
clean
7326CF7000
stack
page read and write
clean
248DDA50000
heap private
page read and write
clean
2701000
unkown image
page readonly
clean
7DF564E30000
unkown image
page readonly
clean
7FF4FE567000
unkown image
page readonly
clean
7FF4FE7B9000
unkown image
page readonly
clean
1D461460000
unkown image
page read and write
clean
7FF5915F1000
unkown image
page readonly
clean
3117000
unkown
page read and write
clean
7FF5784F1000
unkown image
page readonly
clean
7DF586170000
unkown image
page readonly
clean
7FF4FE685000
unkown image
page readonly
clean
3420000
unkown
page read and write
clean
218C8930000
unkown
page read and write
clean
7FF59920B000
unkown image
page readonly
clean
7FF536D69000
unkown image
page readonly
clean
218C8270000
unkown image
page readonly
clean
273D000
unkown image
page readonly
clean
7FA92000
unkown image
page readonly
clean
1036AEB0000
unkown image
page readonly
clean
7FF5990AB000
unkown image
page readonly
clean
1D461FA8000
unkown
page read and write
clean
7FF5782BD000
unkown image
page readonly
clean
1BB118D0000
unkown image
page readonly
clean
7FF4FE7CD000
unkown image
page readonly
clean
1D461E02000
unkown
page read and write
clean
1D461F19000
unkown
page read and write
clean
7FF59196B000
unkown image
page readonly
clean
4DA000
heap private
page read and write
clean
1D461F62000
unkown
page read and write
clean
7FA90000
unkown image
page readonly
clean
7FF591A07000
unkown image
page readonly
clean
218C8070000
unkown image
page readonly
clean
1D462402000
unkown
page read and write
clean
7FF4FE751000
unkown image
page readonly
clean
1BB115A0000
unkown image
page readonly
clean
7FF591795000
unkown image
page readonly
clean
1D462403000
unkown
page read and write
clean
7FF5992BA000
unkown image
page readonly
clean
7FF4FE920000
unkown image
page readonly
clean
7FF536CA6000
unkown image
page readonly
clean
1D4EE424000
unkown
page read and write
clean
1D4616B2000
unkown
page read and write
clean
7327179000
stack
page read and write
clean
2760000
unkown image
page readonly
clean
40D4000
heap private
page read and write
clean
248DDD02000
unkown
page read and write
clean
7FF5991F7000
unkown image
page readonly
clean
7FF591A3E000
unkown image
page readonly
clean
885077B000
stack
page read and write
clean
7F0C0000
unkown image
page readonly
clean
1D461629000
unkown
page read and write
clean
2C36000
unkown image
page readonly
clean
2F50000
unkown image
page read and write
clean
1036ABA0000
unkown image
page read and write
clean
7DF484020000
unkown image
page readonly
clean
512000
unkown
page read and write
clean
7FF5784C9000
unkown image
page readonly
clean
7FF4FE239000
unkown image
page readonly
clean
7FF5570EE000
unkown image
page readonly
clean
1D461FAA000
unkown
page read and write
clean
25D3000
unkown image
page readonly
clean
65E000
stack
page read and write
clean
73265CB000
unkown
page read and write
clean
7FF591A33000
unkown image
page readonly
clean
990000
unkown
page read and write
clean
7FF4FE6D2000
unkown image
page readonly
clean
2CFC000
unkown image
page readonly
clean
1D461FAC000
unkown
page read and write
clean
7F100000
unkown image
page readonly
clean
2CE1000
unkown image
page readonly
clean
1D4EE45A000
unkown
page read and write
clean
1D461C80000
unkown image
page write copy
clean
25D3000
unkown image
page readonly
clean
1D461F00000
unkown
page read and write
clean
7FF59923A000
unkown image
page readonly
clean
7FF598DA7000
unkown image
page readonly
clean
27E8000
unkown image
page readonly
clean
5830000
unkown image
page readonly
clean
7FF4FE786000
unkown image
page readonly
clean
248DDA40000
unkown image
page read and write
clean
7DF586160000
unkown image
page readonly
clean
7DF586162000
unkown image
page readonly
clean
7FF591AE9000
unkown image
page readonly
clean
1D461A00000
unkown image
page readonly
clean
7FF536D62000
unkown image
page readonly
clean
7DF544A00000
unkown image
page readonly
clean
7FF5571AA000
unkown image
page readonly
clean
7FF4FE37C000
unkown image
page readonly
clean
7FF4FE90D000
unkown image
page readonly
clean
7FF536BA7000
unkown image
page readonly
clean
248DE000000
unkown image
page readonly
clean
1D461713000
unkown
page read and write
clean
7DF564E32000
unkown image
page readonly
clean
7FF536CA3000
unkown image
page readonly
clean
7FF4FE4E1000
unkown image
page readonly
clean
7FF4FE23C000
unkown image
page readonly
clean
2D7B79000
stack
page read and write
clean
1D462402000
unkown
page read and write
clean
1D4EE380000
unkown
page read and write
clean
7FF4FE5D7000
unkown image
page readonly
clean
7DF59F770000
unkown image
page readonly
clean
7DF5449F0000
unkown image
page readonly
clean
7DF564E32000
unkown image
page readonly
clean
1BB115B0000
unkown image
page readonly
clean
7FF57835C000
unkown image
page readonly
clean
530000
unkown
page read and write
clean
8850977000
stack
page read and write
clean
4D1E000
stack
page read and write
clean
1D4EE45E000
unkown
page read and write
clean
2453000
unkown image
page readonly
clean
DB7016B000
unkown
page read and write
clean
DB7057B000
stack
page read and write
clean
1D46165A000
unkown
page read and write
clean
1D461F62000
unkown
page read and write
clean
1D461F8B000
unkown
page read and write
clean
69A000
heap private
page read and write
clean
27C1000
unkown image
page readonly
clean
7FF5783F9000
unkown image
page readonly
clean
1D4EE489000
unkown
page read and write
clean
1BB11D30000
unkown
page read and write
clean
8850CFE000
stack
page read and write
clean
7FF4FE4E7000
unkown image
page readonly
clean
1D462502000
unkown
page read and write
clean
4F0000
unkown
page read and write
clean
7F0F0000
unkown image
page readonly
clean
7F110000
unkown image
page readonly
clean
1036ACD0000
unkown
page read and write
clean
27AF000
unkown image
page readonly
clean
1BB11713000
unkown
page read and write
clean
7FF599071000
unkown image
page readonly
clean
40D0000
heap private
page read and write
clean
7DF5A6F30000
unkown image
page readonly
clean
7FF4FE7B5000
unkown image
page readonly
clean
1D4EE6D0000
unkown image
page readonly
clean
342C000
unkown
page read and write
clean
7FF5992B1000
unkown image
page readonly
clean
27E8000
unkown image
page readonly
clean
218C7A20000
unkown
page read and write
clean
7FA82000
unkown image
page readonly
clean
7FF4FE6C7000
unkown image
page readonly
clean
95F1F7F000
stack
page read and write
clean
7FF522CA1000
unkown image
page readonly
clean
7DF564E22000
unkown image
page readonly
clean
7DF50C660000
unkown image
page readonly
clean
2A7227A000
stack
page read and write
clean
2716000
unkown image
page readonly
clean
1D4616EE000
unkown
page read and write
clean
1036ABC0000
unkown image
page readonly
clean
3423000
heap default
page read and write
clean
1D4EE300000
unkown image
page readonly
clean
9D0000
unkown
page read and write
clean
1D4EE463000
unkown
page read and write
clean
248DDE00000
unkown image
page readonly
clean
7FF5783FF000
unkown image
page readonly
clean
2C21000
unkown image
page readonly
clean
7FF4FE86C000
unkown image
page readonly
clean
7FF57846A000
unkown image
page readonly
clean
2615000
unkown image
page readonly
clean
7FF599213000
unkown image
page readonly
clean
7FF4FE9FA000
unkown image
page readonly
clean
1D461FB0000
unkown
page read and write
clean
218C7AB0000
heap default
page read and write
clean
7DF59F782000
unkown image
page readonly
clean
1B0000
unkown image
page readonly
clean
1D461652000
unkown
page read and write
clean
7FF4FE8AF000
unkown image
page readonly
clean
1D461F7F000
unkown
page read and write
clean
1036ADB0000
heap default
page read and write
clean
272B000
unkown image
page readonly
clean
218C7E50000
heap private
page read and write
clean
1D4EE320000
unkown image
page readonly
clean
7330000
unkown
page read and write
clean
218C7A60000
unkown image
page readonly
clean
7DF564E22000
unkown image
page readonly
clean
7FF4FE94B000
unkown image
page readonly
clean
1D461FCD000
unkown
page read and write
clean
1036B0B0000
unkown image
page readonly
clean
7FF5570CF000
unkown image
page readonly
clean
95F1D7B000
stack
page read and write
clean
7FF591A1F000
unkown image
page readonly
clean
7FF5570D6000
unkown image
page readonly
clean
27CB000
unkown image
page readonly
clean
274B000
unkown image
page readonly
clean
7FF5571C1000
unkown image
page readonly
clean
7DF586150000
unkown image
page readonly
clean
7FF591A8A000
unkown image
page readonly
clean
7FF536CE2000
unkown image
page readonly
clean
885087B000
stack
page read and write
clean
7F0D0000
unkown image
page readonly
clean
7FF4FE8F7000
unkown image
page readonly
clean
7FF578410000
unkown image
page readonly
clean
1BB11580000
unkown image
page readonly
clean
1D461FB0000
unkown
page read and write
clean
25C7000
unkown image
page readonly
clean
311B000
unkown
page read and write
clean
7FF4FE5FC000
unkown image
page readonly
clean
2C80000
unkown image
page readonly
clean
5E0000
heap default
page read and write
clean
7FF5991CF000
unkown image
page readonly
clean
7FF4FE5D4000
unkown image
page readonly
clean
1036ADE0000
unkown
page read and write
clean
7FF598AD6000
unkown image
page readonly
clean
218C7E59000
heap private
page read and write
clean
218C79D0000
unkown image
page readonly
clean
1D461FAC000
unkown
page read and write
clean
7FF536D81000
unkown image
page readonly
clean
218C7AF0000
heap default
page read and write
clean
1D461CF0000
unkown
page read and write
clean
1D4EE45D000
unkown
page read and write
clean
218C79C0000
unkown
page read and write
clean
7FA82000
unkown image
page readonly
clean
1D461470000
heap private
page read and write
clean
7DF586152000
unkown image
page readonly
clean
885037C000
unkown
page read and write
clean
7B0000
unkown image
page readonly
clean
248DDC3C000
unkown
page read and write
clean
7FF578443000
unkown image
page readonly
clean
7FA90000
unkown image
page readonly
clean
2F9000
unkown
page read and write
clean
27E3000
unkown image
page readonly
clean
1D4EE457000
unkown
page read and write
clean
7FF4FE08C000
unkown image
page readonly
clean
274B000
unkown image
page readonly
clean
4F8000
unkown
page read and write
clean
7F980000
unkown image
page readonly
clean
248DDC55000
unkown
page read and write
clean
248DDAB0000
heap default
page read and write
clean
7FF4FE92E000
unkown image
page readonly
clean
1D461CF0000
unkown
page read and write
clean
2A722F9000
stack
page read and write
clean
There are 874 hidden memdumps, click here to show them.