IOC Report

loading gif

Files

File Path
Type
Category
Malicious
PO P232-2111228.xlsx
CDFV2 Encrypted
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\vbc[1].exe
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
downloaded
malicious
C:\Users\user\AppData\Local\Temp\nsv6C8A.tmp\gqsrfnlttu.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Desktop\~$PO P232-2111228.xlsx
data
dropped
malicious
C:\Users\Public\vbc.exe
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\20BB155C.png
PNG image data, 130 x 176, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\30E35F10.png
PNG image data, 413 x 220, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\37DCE79E.png
PNG image data, 1295 x 471, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\3B7C84B6.png
PNG image data, 130 x 176, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\48D05749.png
PNG image data, 1295 x 471, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\49FEBDAD.png
PNG image data, 458 x 211, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5BFC33D1.png
PNG image data, 600 x 306, 8-bit colormap, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\6E46C943.png
PNG image data, 413 x 220, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\7553EA68.png
PNG image data, 600 x 306, 8-bit colormap, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\78EEB707.png
PNG image data, 130 x 176, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\97F9413F.png
PNG image data, 130 x 176, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\BD94E032.png
PNG image data, 458 x 211, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\C7678FCA.png
PNG image data, 338 x 143, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\D6C54E8B.png
PNG image data, 338 x 143, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\D9815DB5.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Local\Temp\nui7qhl0vyqjy5hwe1a
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF4E1314DB88821996.TMP
CDFV2 Encrypted
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFB2A7C221D7E594E8.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFC80E7B9FF80D6354.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFF8360FFA42CFF728.TMP
data
dropped
clean
There are 15 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
"C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
malicious
C:\Users\Public\vbc.exe
"C:\Users\Public\vbc.exe"
malicious
C:\Users\Public\vbc.exe
"C:\Users\Public\vbc.exe"
malicious
C:\Windows\explorer.exe
C:\Windows\Explorer.EXE
malicious
C:\Windows\SysWOW64\wscript.exe
C:\Windows\SysWOW64\wscript.exe
malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
clean
C:\Windows\SysWOW64\cmd.exe
/c del "C:\Users\Public\vbc.exe"
clean

URLs

Name
IP
Malicious
www.lesventsfavorables.com/ecaq/
malicious
http://www.gzz06j.cloud/ecaq/?k0Dli=0bA4dpDh3xCt&z6BXjz6=4YbOQk8AO0vy4k2VmRJxI3NcMocUM9+uNZ05HSgMgTndh1RwRX9NSBB2ccr9KRceRZRXnw==
45.139.238.65
malicious
http://103.167.92.57/981900000_2/vbc.exe
103.167.92.57
malicious
http://www.14d7.com/ecaq/?k0Dli=0bA4dpDh3xCt&z6BXjz6=+tTxZdgcqU79mMd7wf6ovAKHVoLw/EhrDF3C/ckFTtMjuwl+tr3xRs8m7m6dFdAioc4v8g==
154.23.172.42
malicious
http://www.flagimir.store/ecaq/?z6BXjz6=qIaOAylHD+7nuLCKVj0dqMEagOlqUztLhCHwuYmgFKo0pBs1u2Qf4sHa5T8Epw0dehH0mQ==&k0Dli=0bA4dpDh3xCt
45.130.41.10
malicious
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://wellformedweb.org/CommentAPI/
unknown
clean
http://www.iis.fhg.de/audioPA
unknown
clean
https://credit-b2b.mn.co//ecaq/?z6BXjz6=bfQv/FP2vMWCXJ5
unknown
clean
http://www.mozilla.com0
unknown
clean
http://nsis.sf.net/NSIS_ErrorError
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://treyresearch.net
unknown
clean
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://java.sun.com
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://nsis.sf.net/NSIS_Error
unknown
clean
http://www.piriform.com/ccleanerhttp://www.piriform.com/ccleanerv
unknown
clean
http://investor.msn.com/
unknown
clean
http://www.piriform.com/ccleaner
unknown
clean
http://computername/printers/printername/.printer
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.autoitscript.com/autoit3
unknown
clean
https://support.mozilla.org
unknown
clean
http://www.piriform.com/ccleanerv
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://www.piriform.com/cBg
unknown
clean
There are 21 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
14d7.com
154.23.172.42
malicious
www.flagimir.store
45.130.41.10
malicious
trendyhunterr.com
192.0.78.25
malicious
www.gzz06j.cloud
45.139.238.65
malicious
www.trendyhunterr.com
unknown
malicious
www.14d7.com
unknown
malicious
www.creditb2b.com
74.208.236.119
clean

IPs

IP
Domain
Country
Malicious
45.139.238.65
www.gzz06j.cloud
Russian Federation
malicious
45.130.41.10
www.flagimir.store
Russian Federation
malicious
192.0.78.25
trendyhunterr.com
United States
malicious
154.23.172.42
14d7.com
United States
malicious
103.167.92.57
unknown
unknown
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
$9,
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2E1D7
2E1D7
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
u ,
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\32BD1
32BD1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\3427C
3427C
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 21
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\32BD1
32BD1
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
EquationEditorFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
There are 30 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
390000
unkown image
page execute and read and write
malicious
D0000
unkown image
page execute and read and write
malicious
70000
unkown image
page execute and read and write
malicious
9521000
unkown image
page execute and read and write
malicious
400000
unkown
page execute and read and write
malicious
400000
unkown
page execute and read and write
malicious
820000
unkown image
page execute and read and write
malicious
490000
unkown
page read and write
malicious
400000
unkown image
page execute and read and write
malicious
9521000
unkown image
page execute and read and write
malicious
400000
unkown
page execute and read and write
malicious
140000
unkown
page read and write
malicious
6A5A000
unkown
page read and write
clean
8C3E000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
840B000
unkown
page read and write
clean
2B57000
unkown
page read and write
clean
2A20000
unkown
page read and write
clean
2F50000
unkown
page read and write
clean
34E000
unkown
page read and write
clean
1CE000
unkown
page read and write
clean
78E9000
unkown
page read and write
clean
1DB2000
heap private
page read and write
clean
2550000
unkown
page read and write
clean
43B0000
heap private
page read and write
clean
1E00000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
6BBE000
unkown
page read and write
clean
5B0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
4D60000
unkown image
page readonly
clean
4300000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
1BE0000
unkown image
page readonly
clean
2921000
unkown
page read and write
clean
4249000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
70000
unkown image
page read and write
clean
7B40000
unkown
page read and write
clean
29DD000
unkown
page read and write
clean
29D0000
unkown
page read and write
clean
190000
unkown image
page readonly
clean
371000
unkown
page read and write
clean
95E3000
heap private
page read and write
clean
41A0000
heap private
page read and write
clean
4EEF000
stack
page read and write
clean
457A000
unkown
page read and write
clean
460B000
unkown
page read and write
clean
3D90000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2B57000
unkown
page read and write
clean
2520000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2900000
unkown
page read and write
clean
4B9D000
unkown
page read and write
clean
2646000
unkown
page read and write
clean
4593000
unkown
page read and write
clean
69BF000
unkown
page read and write
clean
D0000
unkown image
page readonly
clean
4D30000
unkown image
page readonly
clean
4150000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
480000
unkown image
page readonly
clean
A77000
unkown
page execute and read and write
clean
430000
unkown image
page readonly
clean
1B65000
heap private
page read and write
clean
556F000
unkown
page read and write
clean
20DA000
unkown
page read and write
clean
2940000
unkown
page read and write
clean
4D70000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
4F7000
heap default
page read and write
clean
18C000
unkown
page read and write
clean
1B83000
heap private
page read and write
clean
2533000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
4D70000
unkown image
page readonly
clean
4DB1000
unkown image
page read and write
clean
29E0000
unkown
page read and write
clean
2EC1000
unkown
page read and write
clean
92A4000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
27C0000
unkown
page read and write
clean
45A1000
unkown
page read and write
clean
4D30000
unkown image
page readonly
clean
29DA000
unkown
page read and write
clean
2120000
unkown image
page read and write
clean
8424000
unkown
page read and write
clean
2A30000
unkown
page read and write
clean
43A0000
unkown image
page readonly
clean
3DF8000
unkown
page read and write
clean
9360000
unkown
page read and write
clean
2BC0000
unkown
page read and write
clean
78E9000
unkown
page read and write
clean
45D6000
unkown
page read and write
clean
2A90000
unkown
page read and write
clean
2750000
unkown
page read and write
clean
2F20000
unkown
page read and write
clean
8355000
unkown
page read and write
clean
3D50000
unkown
page read and write
clean
5270000
unkown
page execute read
clean
4C7A000
heap private
page read and write
clean
2A4000
heap default
page read and write
clean
E0000
heap private
page read and write
clean
6D48000
unkown
page read and write
clean
6A50000
unkown
page read and write
clean
2130000
unkown image
page read and write
clean
69BF000
unkown
page read and write
clean
24E4000
unkown
page execute and read and write
clean
3E50000
unkown image
page readonly
clean
610000
heap default
page read and write
clean
728E000
unkown
page read and write
clean
36B000
unkown
page read and write
clean
BF4000
unkown
page execute and read and write
clean
263C000
unkown
page read and write
clean
69C8000
unkown
page read and write
clean
30D0000
unkown image
page readonly
clean
4BD000
unkown
page read and write
clean
457A000
unkown
page read and write
clean
25C3000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
2900000
unkown
page read and write
clean
7B4B000
unkown
page read and write
clean
9260000
unkown
page read and write
clean
249000
heap default
page read and write
clean
6A50000
unkown
page read and write
clean
2646000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
4300000
unkown
page read and write
clean
4D40000
unkown image
page readonly
clean
36F000
unkown
page read and write
clean
2750000
unkown
page read and write
clean
447A000
unkown
page read and write
clean
257000
unkown
page read and write
clean
20B6000
unkown
page read and write
clean
283F000
stack
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
3278000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
8DD8000
unkown
page read and write
clean
95C5000
heap private
page read and write
clean
4D50000
unkown image
page readonly
clean
1A0000
unkown image
page readonly
clean
2A70000
unkown
page read and write
clean
437000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
5C0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
4D40000
unkown image
page readonly
clean
5F0000
unkown image
page readonly
clean
29B000
heap default
page read and write
clean
29F0000
unkown
page read and write
clean
95E3000
heap private
page read and write
clean
45CB000
unkown
page read and write
clean
4450000
unkown
page read and write
clean
3CA0000
unkown
page read and write
clean
460B000
unkown
page read and write
clean
4160000
unkown
page read and write
clean
4D70000
unkown image
page readonly
clean
440000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
220000
unkown image
page readonly
clean
1F0000
unkown
page read and write
clean
23F0000
unkown
page execute and read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
2520000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
32A5000
heap private
page read and write
clean
5E7000
heap default
page read and write
clean
71C2000
unkown
page read and write
clean
27C0000
unkown
page read and write
clean
24F0000
unkown image
page readonly
clean
4C7A000
heap private
page read and write
clean
45BF000
unkown
page read and write
clean
32A9000
heap private
page read and write
clean
2A60000
unkown
page read and write
clean
430000
unkown image
page readonly
clean
27C0000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
4D20000
unkown
page execute and read and write
clean
44E7000
unkown
page read and write
clean
7E1E000
unkown
page read and write
clean
255000
heap default
page read and write
clean
32A5000
heap private
page read and write
clean
7B50000
heap private
page read and write
clean
834B000
unkown
page read and write
clean
1E0000
unkown
page read and write
clean
4D40000
unkown image
page readonly
clean
20E0000
unkown
page read and write
clean
4AF0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
744D000
unkown
page read and write
clean
288D000
stack
page read and write
clean
74B0000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
81AE000
unkown
page read and write
clean
556F000
unkown
page read and write
clean
301E000
unkown
page read and write
clean
2900000
unkown
page read and write
clean
5410000
heap private
page read and write
clean
729A000
unkown
page read and write
clean
27A0000
unkown image
page readonly
clean
23D000
heap default
page read and write
clean
8DD8000
unkown
page read and write
clean
3DF8000
unkown
page read and write
clean
74D3000
heap private
page read and write
clean
25C3000
unkown
page read and write
clean
30D0000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
69C8000
unkown
page read and write
clean
301E000
unkown
page read and write
clean
21BF000
unkown
page read and write
clean
750000
unkown image
page readonly
clean
2A00000
unkown
page read and write
clean
2B60000
unkown
page read and write
clean
2C87000
unkown image
page read and write
clean
728E000
unkown
page read and write
clean
2533000
unkown
page read and write
clean
2A50000
unkown
page read and write
clean
44E7000
unkown
page read and write
clean
244000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
30F0000
unkown image
page readonly
clean
330000
unkown
page read and write
clean
4575000
unkown
page read and write
clean
30F0000
unkown image
page readonly
clean
252000
heap default
page read and write
clean
36B000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2CC7000
unkown image
page readonly
clean
2B60000
unkown
page read and write
clean
2A50000
unkown
page read and write
clean
2B40000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
230000
heap default
page read and write
clean
F0000
unkown image
page read and write
clean
2A90000
unkown
page read and write
clean
32A0000
heap private
page read and write
clean
6BE000
stack
page read and write
clean
42C000
unkown image
page read and write
clean
D0000
unkown image
page readonly
clean
2370000
unkown
page execute and read and write
clean
750000
unkown image
page readonly
clean
7CFE000
unkown
page read and write
clean
4308000
unkown
page read and write
clean
9360000
unkown
page read and write
clean
2A10000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7CFE000
unkown
page read and write
clean
5390000
heap private
page read and write
clean
8374000
unkown
page read and write
clean
834B000
unkown
page read and write
clean
2C7000
heap default
page read and write
clean
2940000
unkown
page read and write
clean
2F50000
unkown
page read and write
clean
220000
unkown image
page readonly
clean
970000
unkown
page execute and read and write
clean
2A40000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
26AF000
stack
page read and write
clean
83D0000
unkown
page read and write
clean
23A0000
unkown image
page execute and read and write
clean
45CF000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7EFB0000
unkown image
page readonly
clean
45D4000
unkown
page read and write
clean
4B00000
unkown image
page readonly
clean
45D4000
unkown
page read and write
clean
30E0000
unkown image
page readonly
clean
4C70000
heap private
page read and write
clean
95C0000
heap private
page read and write
clean
9222000
unkown
page read and write
clean
3160000
unkown image
page readonly
clean
249000
heap default
page read and write
clean
E4000
heap private
page read and write
clean
29B000
heap default
page read and write
clean
243000
heap default
page read and write
clean
30000
unkown image
page readonly
clean
2AE0000
unkown image
page readonly
clean
401000
unkown image
page execute read
clean
10000000
unkown image
page readonly
clean
2760000
unkown image
page readonly
clean
3D50000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
220000
heap default
page read and write
clean
1CE000
unkown
page read and write
clean
110000
unkown
page read and write
clean
2F50000
unkown
page read and write
clean
3D50000
unkown
page read and write
clean
6A5A000
unkown
page read and write
clean
1B83000
heap private
page read and write
clean
2260000
unkown
page execute and read and write
clean
2B54000
unkown
page read and write
clean
8B000
unkown
page read and write
clean
330000
unkown
page read and write
clean
74D3000
heap private
page read and write
clean
3D4B000
unkown
page read and write
clean
2110000
unkown image
page read and write
clean
729A000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
2A50000
unkown
page read and write
clean
8720000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
3D40000
unkown
page read and write
clean
2520000
unkown
page read and write
clean
A60000
unkown
page execute and read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
420000
heap default
page read and write
clean
2B51000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
1B60000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
430000
unkown image
page execute and read and write
clean
2270000
unkown
page execute and read and write
clean
2A00000
unkown
page read and write
clean
71C7000
unkown
page read and write
clean
5270000
unkown
page execute read
clean
94E0000
unkown image
page execute and read and write
clean
2CC7000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
20DA000
unkown
page read and write
clean
2280000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
9260000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
2A00000
unkown
page read and write
clean
1A0000
unkown image
page readonly
clean
8C3E000
unkown
page read and write
clean
4AC0000
unkown
page read and write
clean
4C70000
heap private
page read and write
clean
A80000
unkown
page execute and read and write
clean
40000
unkown image
page readonly
clean
4AAD000
unkown
page read and write
clean
7D20000
heap private
page read and write
clean
6A5A000
unkown
page read and write
clean
309E000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
C70000
unkown
page execute and read and write
clean
43B0000
heap private
page read and write
clean
4308000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
45CB000
unkown
page read and write
clean
240000
unkown image
page readonly
clean
C60000
unkown
page execute and read and write
clean
2EC1000
unkown
page read and write
clean
29D0000
unkown
page read and write
clean
2B40000
unkown
page read and write
clean
4AF0000
unkown image
page readonly
clean
744D000
unkown
page read and write
clean
4B00000
unkown image
page readonly
clean
4249000
unkown
page read and write
clean
1B65000
heap private
page read and write
clean
2750000
unkown
page read and write
clean
4B9D000
unkown
page read and write
clean
728E000
unkown
page read and write
clean
4AAD000
unkown
page read and write
clean
BF7000
unkown
page execute and read and write
clean
1B65000
heap private
page read and write
clean
4AAD000
unkown
page read and write
clean
1D94000
heap private
page read and write
clean
C3E000
stack
page read and write
clean
407000
unkown image
page readonly
clean
30C0000
unkown
page read and write
clean
18B000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
782F000
unkown
page read and write
clean
4C70000
heap private
page read and write
clean
744D000
unkown
page read and write
clean
29E0000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
880000
unkown image
page readonly
clean
4B00000
unkown image
page readonly
clean
31FF000
unkown
page read and write
clean
243000
heap default
page read and write
clean
660000
unkown image
page execute and read and write
clean
25C3000
unkown
page read and write
clean
7BD0000
heap private
page read and write
clean
4593000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
20000
unkown
page read and write
clean
34E000
unkown
page read and write
clean
1B65000
heap private
page read and write
clean
449C000
unkown
page read and write
clean
4D70000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
8D000
unkown
page read and write
clean
2130000
unkown image
page read and write
clean
230000
heap default
page read and write
clean
449C000
unkown
page read and write
clean
23E0000
unkown
page execute and read and write
clean
2CC7000
unkown image
page readonly
clean
30A8000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
71C2000
unkown
page read and write
clean
8320000
unkown
page read and write
clean
E10000
unkown image
page readonly
clean
25D000
unkown
page read and write
clean
4DC0000
unkown
page read and write
clean
1DD0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
23D000
heap default
page read and write
clean
31D000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
300000
heap default
page read and write
clean
7EFB0000
unkown image
page readonly
clean
3E50000
unkown image
page readonly
clean
44E7000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
43A0000
unkown image
page readonly
clean
170000
heap default
page read and write
clean
2C7000
heap default
page read and write
clean
24D0000
unkown
page execute and read and write
clean
93A3000
unkown
page read and write
clean
74B0000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
532E000
unkown
page read and write
clean
457A000
unkown
page read and write
clean
23D000
heap default
page read and write
clean
7B40000
unkown
page read and write
clean
45D4000
unkown
page read and write
clean
2A70000
unkown
page read and write
clean
4513000
unkown
page read and write
clean
78E9000
unkown
page read and write
clean
4D60000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7839000
unkown
page read and write
clean
85E000
stack
page read and write
clean
140000
unkown image
page readonly
clean
C80000
unkown image
page readonly
clean
263C000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
4450000
unkown
page read and write
clean
6BBE000
unkown
page read and write
clean
45CB000
unkown
page read and write
clean
5390000
heap private
page read and write
clean
456F000
unkown
page read and write
clean
4513000
unkown
page read and write
clean
3BE000
stack
page read and write
clean
91E3000
unkown
page read and write
clean
10016000
unkown image
page execute and read and write
clean
309E000
unkown
page read and write
clean
4575000
unkown
page read and write
clean
2A60000
unkown
page read and write
clean
2A70000
unkown
page read and write
clean
8C20000
unkown
page read and write
clean
3DF8000
unkown
page read and write
clean
3D90000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
1F0000
unkown
page read and write
clean
2A60000
unkown
page read and write
clean
73BB000
unkown
page read and write
clean
5410000
heap private
page read and write
clean
430000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
2A50000
unkown
page read and write
clean
8428000
unkown
page read and write
clean
690000
unkown
page execute and read and write
clean
371000
unkown
page read and write
clean
C0000
unkown
page read and write
clean
31FF000
unkown
page read and write
clean
5360000
unkown image
page read and write
clean
3D40000
unkown
page read and write
clean
6D40000
unkown
page read and write
clean
24E000
unkown
page read and write
clean
45A1000
unkown
page read and write
clean
834B000
unkown
page read and write
clean
E0000
heap private
page read and write
clean
400000
unkown image
page readonly
clean
2120000
unkown image
page read and write
clean
401000
unkown image
page execute read
clean
5360000
unkown image
page read and write
clean
2500000
unkown image
page readonly
clean
29D0000
unkown
page read and write
clean
74B4000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7839000
unkown
page read and write
clean
4CAE000
stack
page read and write
clean
2900000
unkown
page read and write
clean
30D0000
unkown image
page readonly
clean
1B50000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
83F8000
unkown
page read and write
clean
45CF000
unkown
page read and write
clean
A0000
unkown
page read and write
clean
27E0000
unkown
page read and write
clean
3DF8000
unkown
page read and write
clean
45B4000
unkown
page read and write
clean
21D7000
unkown
page read and write
clean
4575000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
360000
heap private
page read and write
clean
2A90000
unkown
page read and write
clean
69C8000
unkown
page read and write
clean
71C2000
unkown
page read and write
clean
30D0000
unkown image
page readonly
clean
243000
heap default
page read and write
clean
2100000
unkown image
page readonly
clean
295C000
unkown
page read and write
clean
41A5000
heap private
page read and write
clean
69C8000
unkown
page read and write
clean
3298000
unkown
page read and write
clean
BE0000
unkown
page execute and read and write
clean
4DC0000
unkown
page read and write
clean
73B9000
unkown
page read and write
clean
2760000
unkown image
page readonly
clean
3D50000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
4CF000
stack
page read and write
clean
7EFC0000
unkown image
page readonly
clean
71C2000
unkown
page read and write
clean
401000
unkown image
page execute read
clean
50000
unkown image
page readonly
clean
30A8000
unkown
page read and write
clean
4AC0000
unkown
page read and write
clean
74B4000
heap private
page read and write
clean
73B9000
unkown
page read and write
clean
2B51000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7EFC0000
unkown image
page readonly
clean
400000
unkown image
page readonly
clean
556F000
unkown
page read and write
clean
6D48000
unkown
page read and write
clean
270000
heap default
page read and write
clean
2EC1000
unkown
page read and write
clean
29DA000
unkown
page read and write
clean
2940000
unkown
page read and write
clean
6E50000
heap private
page read and write
clean
5C0000
unkown image
page readonly
clean
7B4B000
unkown
page read and write
clean
255000
heap default
page read and write
clean
10001000
unkown image
page execute read
clean
10000
unkown image
page read and write
clean
7EFC0000
unkown image
page readonly
clean
2A50000
unkown
page read and write
clean
45B4000
unkown
page read and write
clean
2AA0000
unkown
page read and write
clean
870000
heap default
page read and write
clean
B00000
unkown
page execute and read and write
clean
36B000
unkown
page read and write
clean
5410000
heap private
page read and write
clean
6C59000
unkown
page read and write
clean
92A4000
unkown
page read and write
clean
74B4000
heap private
page read and write
clean
10010000
unkown image
page readonly
clean
32A9000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
690000
unkown image
page readonly
clean
4B3F000
stack
page read and write
clean
1E0000
unkown
page read and write
clean
24C000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2921000
unkown
page read and write
clean
41A0000
heap private
page read and write
clean
750000
unkown image
page readonly
clean
29B000
heap default
page read and write
clean
32A0000
heap private
page read and write
clean
400000
unkown
page execute and read and write
clean
6A60000
heap private
page read and write
clean
44E7000
unkown
page read and write
clean
2A40000
unkown
page read and write
clean
860000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
8C20000
unkown
page read and write
clean
380000
heap private
page read and write
clean
29B000
heap default
page read and write
clean
23D0000
unkown
page execute and read and write
clean
81AE000
unkown
page read and write
clean
1E0000
unkown
page read and write
clean
8320000
unkown
page read and write
clean
3D40000
unkown
page read and write
clean
2740000
unkown image
page readonly
clean
2360000
unkown
page execute and read and write
clean
407000
unkown image
page readonly
clean
263C000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
4389000
unkown
page read and write
clean
2533000
unkown
page read and write
clean
4D60000
unkown image
page readonly
clean
1F0000
unkown
page read and write
clean
4389000
unkown
page read and write
clean
E0000
heap private
page read and write
clean
447A000
unkown
page read and write
clean
534000
unkown
page read and write
clean
2B54000
unkown
page read and write
clean
3C90000
unkown image
page read and write
clean
30E0000
unkown image
page readonly
clean
9561000
unkown image
page execute and read and write
clean
27A0000
unkown image
page readonly
clean
4BB0000
heap private
page read and write
clean
4AF0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
4150000
unkown image
page readonly
clean
2A20000
unkown
page read and write
clean
91E3000
unkown
page read and write
clean
29DD000
unkown
page read and write
clean
BF1000
unkown
page execute and read and write
clean
7E1E000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
27C0000
unkown
page read and write
clean
2940000
unkown
page read and write
clean
E4000
heap private
page read and write
clean
3CC0000
unkown image
page readonly
clean
2500000
unkown image
page readonly
clean
28C0000
heap private
page read and write
clean
447A000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
8355000
unkown
page read and write
clean
532E000
unkown
page read and write
clean
2533000
unkown
page read and write
clean
4308000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
295C000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
2A30000
unkown
page read and write
clean
2110000
unkown image
page read and write
clean
407000
unkown image
page readonly
clean
4160000
unkown
page read and write
clean
21D1000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
32A5000
heap private
page read and write
clean
714E000
unkown
page read and write
clean
4300000
unkown
page read and write
clean
447A000
unkown
page read and write
clean
25D000
unkown
page read and write
clean
430000
unkown image
page readonly
clean
3C90000
unkown image
page read and write
clean
3C90000
unkown image
page read and write
clean
2A10000
unkown
page read and write
clean
4150000
unkown image
page readonly
clean
30000
unkown image
page read and write
clean
60000
unkown image
page readonly
clean
2B51000
unkown
page read and write
clean
520000
unkown
page read and write
clean
4E60000
unkown
page read and write
clean
45BF000
unkown
page read and write
clean
10019000
unkown image
page readonly
clean
24E1000
unkown
page execute and read and write
clean
2A10000
unkown
page read and write
clean
D0000
unkown image
page readonly
clean
6D40000
unkown
page read and write
clean
434000
unkown image
page read and write
clean
4DB1000
unkown image
page read and write
clean
4D30000
unkown image
page readonly
clean
4389000
unkown
page read and write
clean
237000
heap default
page read and write
clean
205A000
unkown
page read and write
clean
4D30000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
10000000
unkown image
page readonly
clean
93A3000
unkown
page read and write
clean
29DD000
unkown
page read and write
clean
79F0000
heap private
page read and write
clean
8424000
unkown
page read and write
clean
2740000
unkown image
page readonly
clean
3CA0000
unkown
page read and write
clean
7BD0000
heap private
page read and write
clean
750000
unkown image
page readonly
clean
4DD0000
heap private
page read and write
clean
744D000
unkown
page read and write
clean
5C0000
unkown image
page readonly
clean
1F80000
unkown
page read and write
clean
9360000
unkown
page read and write
clean
2120000
unkown image
page read and write
clean
258000
unkown
page read and write
clean
2F20000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
457A000
unkown
page read and write
clean
714E000
unkown
page read and write
clean
2646000
unkown
page read and write
clean
1A0000
unkown image
page readonly
clean
13D000
unkown
page read and write
clean
6E50000
heap private
page read and write
clean
3D4B000
unkown
page read and write
clean
45A1000
unkown
page read and write
clean
3CA0000
unkown
page read and write
clean
30E0000
unkown image
page readonly
clean
2110000
unkown image
page read and write
clean
140000
unkown image
page readonly
clean
41A5000
heap private
page read and write
clean
4BB0000
heap private
page read and write
clean
2A30000
unkown
page read and write
clean
4D40000
unkown image
page readonly
clean
3E50000
unkown image
page readonly
clean
2870000
unkown
page read and write
clean
2B54000
unkown
page read and write
clean
4D20000
unkown
page execute and read and write
clean
2B40000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
430000
unkown image
page readonly
clean
24F0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
894000
heap default
page read and write
clean
2A80000
unkown
page read and write
clean
1BE0000
unkown image
page readonly
clean
27A0000
unkown image
page readonly
clean
2A60000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
27E0000
unkown
page read and write
clean
5B0000
unkown image
page readonly
clean
3270000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
9222000
unkown
page read and write
clean
1FD0000
unkown image
page readonly
clean
E0000
heap private
page read and write
clean
42C000
unkown
page read and write
clean
227000
heap default
page read and write
clean
4C7A000
heap private
page read and write
clean
4593000
unkown
page read and write
clean
34B000
heap default
page read and write
clean
2B40000
unkown
page read and write
clean
1FBE000
stack
page read and write
clean
2AE0000
unkown image
page readonly
clean
36F000
unkown
page read and write
clean
249000
heap default
page read and write
clean
456F000
unkown
page read and write
clean
879000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
2740000
unkown image
page readonly
clean
45BF000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
400000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
75FE000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
2A00000
unkown
page read and write
clean
32A9000
heap private
page read and write
clean
34E000
unkown
page read and write
clean
3270000
unkown
page read and write
clean
1FD0000
unkown image
page readonly
clean
30E0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
2A50000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
32A9000
heap private
page read and write
clean
2B60000
unkown
page read and write
clean
190000
unkown image
page readonly
clean
3278000
unkown
page read and write
clean
43A0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
230000
unkown
page read and write
clean
6D40000
unkown
page read and write
clean
1A0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
2DD000
unkown
page read and write
clean
20DA000
unkown
page read and write
clean
110000
unkown
page read and write
clean
45D6000
unkown
page read and write
clean
295C000
unkown
page read and write
clean
346000
heap default
page read and write
clean
7BD0000
heap private
page read and write
clean
4450000
unkown
page read and write
clean
2A80000
unkown
page read and write
clean
83F8000
unkown
page read and write
clean
728E000
unkown
page read and write
clean
7D20000
heap private
page read and write
clean
2BC0000
unkown
page read and write
clean
449C000
unkown
page read and write
clean
4300000
unkown
page read and write
clean
2900000
unkown
page read and write
clean
190000
unkown image
page readonly
clean
33D000
heap default
page read and write
clean
531000
unkown
page read and write
clean
371000
unkown
page read and write
clean
5B0000
unkown image
page readonly
clean
31FF000
unkown
page read and write
clean
4E5E000
unkown
page read and write
clean
309E000
unkown
page read and write
clean
4450000
unkown
page read and write
clean
2367000
unkown
page execute and read and write
clean
2B54000
unkown
page read and write
clean
7CFE000
unkown
page read and write
clean
79F0000
heap private
page read and write
clean
514000
heap default
page read and write
clean
2C7000
heap default
page read and write
clean
1A0000
unkown image
page readonly
clean
1F0000
unkown
page read and write
clean
370000
heap private
page read and write
clean
6D40000
unkown
page read and write
clean
2B57000
unkown
page read and write
clean
4DD0000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
243000
heap default
page read and write
clean
2A70000
unkown
page read and write
clean
8720000
unkown
page read and write
clean
21D4000
unkown
page read and write
clean
30C0000
unkown
page read and write
clean
6E0000
unkown image
page readonly
clean
2100000
unkown
page execute and read and write
clean
782F000
unkown
page read and write
clean
E00000
unkown image
page readonly
clean
2550000
unkown
page read and write
clean
4650000
unkown image
page readonly
clean
8C20000
unkown
page read and write
clean
4D20000
unkown
page execute and read and write
clean
2760000
unkown image
page readonly
clean
AF0000
unkown
page execute and read and write
clean
1E0000
unkown
page read and write
clean
4AAD000
unkown
page read and write
clean
83DF000
unkown
page read and write
clean
29DA000
unkown
page read and write
clean
604000
heap default
page read and write
clean
5B0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
1B60000
heap private
page read and write
clean
660000
unkown image
page execute and read and write
clean
2B57000
unkown
page read and write
clean
456F000
unkown
page read and write
clean
2B57000
unkown
page read and write
clean
4C7A000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
220000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
255000
heap default
page read and write
clean
79F0000
heap private
page read and write
clean
100000
unkown
page read and write
clean
2B60000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
73F000
stack
page read and write
clean
1CE000
unkown
page read and write
clean
74D3000
heap private
page read and write
clean
2A90000
unkown
page read and write
clean
7839000
unkown
page read and write
clean
2BC0000
unkown
page read and write
clean
4E5E000
unkown
page read and write
clean
29DA000
unkown
page read and write
clean
71C7000
unkown
page read and write
clean
2921000
unkown
page read and write
clean
2100000
unkown image
page readonly
clean
449C000
unkown
page read and write
clean
2A30000
unkown
page read and write
clean
257000
unkown
page read and write
clean
340000
unkown image
page read and write
clean
36F000
unkown
page read and write
clean
23D000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
4AC0000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
8355000
unkown
page read and write
clean
6A60000
heap private
page read and write
clean
5270000
unkown
page execute read
clean
7EFB0000
unkown image
page readonly
clean
2500000
unkown image
page readonly
clean
20DA000
unkown
page read and write
clean
2364000
unkown
page execute and read and write
clean
30C0000
unkown
page read and write
clean
7839000
unkown
page read and write
clean
2A60000
unkown
page read and write
clean
24F0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
4B9D000
unkown
page read and write
clean
5360000
unkown image
page read and write
clean
7B50000
heap private
page read and write
clean
8DD8000
unkown
page read and write
clean
782F000
unkown
page read and write
clean
6C59000
unkown
page read and write
clean
AE0000
unkown
page execute and read and write
clean
50000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
45A1000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
2550000
unkown
page read and write
clean
41A5000
heap private
page read and write
clean
203E000
stack
page read and write
clean
78E9000
unkown
page read and write
clean
43A0000
unkown image
page readonly
clean
32AE000
heap private
page read and write
clean
2520000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2740000
unkown image
page readonly
clean
93A3000
unkown
page read and write
clean
1BE0000
unkown image
page readonly
clean
330000
unkown
page read and write
clean
9323000
unkown
page read and write
clean
370000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
8461000
unkown
page read and write
clean
3E50000
unkown image
page readonly
clean
4DD0000
heap private
page read and write
clean
45CF000
unkown
page read and write
clean
4D60000
unkown image
page readonly
clean
437000
unkown image
page readonly
clean
4650000
unkown image
page readonly
clean
1FD0000
unkown image
page readonly
clean
C00000
unkown
page execute and read and write
clean
95E3000
heap private
page read and write
clean
3160000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
3FF000
stack
page read and write
clean
4AF0000
unkown image
page readonly
clean
2B51000
unkown
page read and write
clean
409000
unkown image
page read and write
clean
9323000
unkown
page read and write
clean
3278000
unkown
page read and write
clean
30A000
unkown
page read and write
clean
63C000
stack
page read and write
clean
7EFC2000
unkown image
page readonly
clean
2F20000
unkown
page read and write
clean
7B40000
unkown
page read and write
clean
840B000
unkown
page read and write
clean
3CC0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
7B40000
unkown
page read and write
clean
20B6000
unkown
page read and write
clean
729A000
unkown
page read and write
clean
83DF000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
75FE000
unkown
page read and write
clean
24F0000
unkown
page execute and read and write
clean
366000
heap private
page read and write
clean
45BF000
unkown
page read and write
clean
1B83000
heap private
page read and write
clean
43B0000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
537000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
F0000
unkown image
page read and write
clean
7EFC2000
unkown image
page readonly
clean
33E000
stack
page read and write
clean
6B0000
unkown
page execute and read and write
clean
4513000
unkown
page read and write
clean
4308000
unkown
page read and write
clean
2100000
unkown image
page readonly
clean
4D80000
unkown image
page readonly
clean
8428000
unkown
page read and write
clean
30A8000
unkown
page read and write
clean
250000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
8C3E000
unkown
page read and write
clean
2A50000
unkown
page read and write
clean
556F000
unkown
page read and write
clean
E4000
heap private
page read and write
clean
1F0000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
2A60000
unkown
page read and write
clean
26F000
stack
page read and write
clean
73BB000
unkown
page read and write
clean
899000
heap default
page read and write
clean
71C7000
unkown
page read and write
clean
3270000
unkown
page read and write
clean
8720000
unkown
page read and write
clean
3278000
unkown
page read and write
clean
2EC1000
unkown
page read and write
clean
230000
heap default
page read and write
clean
6E50000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
249000
heap default
page read and write
clean
2A10000
unkown
page read and write
clean
27A0000
unkown image
page readonly
clean
255000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
30A8000
unkown
page read and write
clean
2A60000
unkown
page read and write
clean
460B000
unkown
page read and write
clean
25C3000
unkown
page read and write
clean
36F000
unkown
page read and write
clean
5390000
heap private
page read and write
clean
20D0000
unkown
page read and write
clean
29F0000
unkown
page read and write
clean
6E50000
heap private
page read and write
clean
2646000
unkown
page read and write
clean
2540000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
1D7000
unkown
page read and write
clean
81AE000
unkown
page read and write
clean
1C80000
unkown image
page readonly
clean
29DD000
unkown
page read and write
clean
2E02000
unkown image
page read and write
clean
2921000
unkown
page read and write
clean
8320000
unkown
page read and write
clean
6A60000
heap private
page read and write
clean
45CB000
unkown
page read and write
clean
4249000
unkown
page read and write
clean
1AD000
unkown
page read and write
clean
32A5000
heap private
page read and write
clean
8355000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
190000
unkown image
page readonly
clean
5C0000
unkown image
page readonly
clean
1B6000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
260000
heap private
page read and write
clean
2770000
unkown
page read and write
clean
10D000
unkown
page read and write
clean
2B40000
unkown
page read and write
clean
2B4000
heap private
page read and write
clean
53F000
heap default
page read and write
clean
3298000
unkown
page read and write
clean
437000
unkown image
page readonly
clean
6A60000
heap private
page read and write
clean
6A50000
unkown
page read and write
clean
41A0000
heap private
page read and write
clean
409000
unkown image
page write copy
clean
2550000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
9561000
unkown image
page execute and read and write
clean
24E7000
unkown
page execute and read and write
clean
20B6000
unkown
page read and write
clean
532E000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
94E0000
unkown image
page execute and read and write
clean
1D90000
heap private
page read and write
clean
9323000
unkown
page read and write
clean
2120000
unkown image
page read and write
clean
95C5000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
2560000
unkown
page execute and read and write
clean
36B000
unkown
page read and write
clean
45D4000
unkown
page read and write
clean
2550000
unkown
page execute and read and write
clean
20B6000
unkown
page read and write
clean
2A40000
unkown
page read and write
clean
7B4B000
unkown
page read and write
clean
205D000
unkown
page read and write
clean
190000
unkown image
page readonly
clean
24C000
unkown
page read and write
clean
8461000
unkown
page read and write
clean
2BC0000
unkown
page read and write
clean
20000
unkown
page read and write
clean
4DD0000
heap private
page read and write
clean
45CF000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7D20000
heap private
page read and write
clean
7E1E000
unkown
page read and write
clean
2540000
unkown
page read and write
clean
2350000
unkown
page execute and read and write
clean
6D48000
unkown
page read and write
clean
2A8A000
unkown image
page read and write
clean
4650000
unkown image
page readonly
clean
87E000
unkown
page read and write
clean
21BF000
unkown
page read and write
clean
4B1000
unkown image
page execute and read and write
clean
237000
heap default
page read and write
clean
2BB000
heap private
page read and write
clean
4D80000
unkown image
page readonly
clean
307000
heap default
page read and write
clean
1B60000
heap private
page read and write
clean
2870000
unkown
page read and write
clean
309E000
unkown
page read and write
clean
7CFE000
unkown
page read and write
clean
230000
heap default
page read and write
clean
276F000
stack
page read and write
clean
400000
unkown image
page readonly
clean
43B0000
heap private
page read and write
clean
83D0000
unkown
page read and write
clean
21E0000
unkown
page read and write
clean
29D0000
unkown
page read and write
clean
2A50000
unkown
page read and write
clean
6A50000
unkown
page read and write
clean
6BBE000
unkown
page read and write
clean
2760000
unkown image
page readonly
clean
31D000
heap default
page read and write
clean
190000
unkown image
page readonly
clean
301E000
unkown
page read and write
clean
4513000
unkown
page read and write
clean
95C5000
heap private
page read and write
clean
30C0000
unkown
page read and write
clean
4389000
unkown
page read and write
clean
220000
unkown image
page readonly
clean
83DF000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
3298000
unkown
page read and write
clean
4A0000
unkown image
page readonly
clean
8374000
unkown
page read and write
clean
73BB000
unkown
page read and write
clean
30F0000
unkown image
page readonly
clean
4DC0000
unkown
page read and write
clean
4E60000
unkown
page read and write
clean
5270000
unkown
page execute read
clean
3D90000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
110000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
4A1E000
stack
page read and write
clean
73B9000
unkown
page read and write
clean
4D20000
unkown
page execute and read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
1F0000
unkown
page read and write
clean
2240000
unkown
page read and write
clean
2A40000
unkown
page read and write
clean
71C7000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
532E000
unkown
page read and write
clean
7D20000
heap private
page read and write
clean
4150000
unkown image
page readonly
clean
4E5E000
unkown
page read and write
clean
32AE000
heap private
page read and write
clean
3160000
unkown image
page readonly
clean
45D6000
unkown
page read and write
clean
1D7000
unkown
page read and write
clean
2540000
unkown
page read and write
clean
8374000
unkown
page read and write
clean
7B50000
heap private
page read and write
clean
4E5E000
unkown
page read and write
clean
3270000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
1B50000
unkown
page read and write
clean
1FD0000
unkown image
page readonly
clean
8320000
unkown
page read and write
clean
F0000
unkown image
page read and write
clean
2A20000
unkown
page read and write
clean
79F0000
heap private
page read and write
clean
1B50000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
6A5A000
unkown
page read and write
clean
73B9000
unkown
page read and write
clean
2B0000
heap private
page read and write
clean
4575000
unkown
page read and write
clean
95C0000
heap private
page read and write
clean
29E0000
unkown
page read and write
clean
6D48000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
1B83000
heap private
page read and write
clean
8461000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
A70000
unkown
page execute and read and write
clean
30F0000
unkown image
page readonly
clean
2750000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
31D000
heap default
page read and write
clean
2AE0000
unkown image
page readonly
clean
295C000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
A74000
unkown
page execute and read and write
clean
460B000
unkown
page read and write
clean
540000
unkown
page read and write
clean
D0000
unkown image
page readonly
clean
1A0000
unkown image
page readonly
clean
32AE000
heap private
page read and write
clean
29DD000
unkown
page read and write
clean
7B50000
heap private
page read and write
clean
3D40000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
1B50000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
2100000
unkown image
page readonly
clean
237000
heap default
page read and write
clean
2A80000
unkown
page read and write
clean
2130000
unkown image
page read and write
clean
83DF000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
2AA0000
unkown
page read and write
clean
2B54000
unkown
page read and write
clean
74B0000
heap private
page read and write
clean
7BD0000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
75FE000
unkown
page read and write
clean
74D3000
heap private
page read and write
clean
3D4B000
unkown
page read and write
clean
4C70000
heap private
page read and write
clean
20000
unkown image
page read and write
clean
9260000
unkown
page read and write
clean
2A50000
unkown
page read and write
clean
32A0000
heap private
page read and write
clean
1F0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
69BF000
unkown
page read and write
clean
29E0000
unkown
page read and write
clean
301E000
unkown
page read and write
clean
36F000
stack
page read and write
clean
41A5000
heap private
page read and write
clean
45B4000
unkown
page read and write
clean
4F0000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
729A000
unkown
page read and write
clean
237000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
45B4000
unkown
page read and write
clean
840B000
unkown
page read and write
clean
110000
unkown
page read and write
clean
440000
unkown
page read and write
clean
4160000
unkown
page read and write
clean
2A60000
unkown
page read and write
clean
80F000
stack
page read and write
clean
456F000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
73BB000
unkown
page read and write
clean
3CC0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
4650000
unkown image
page readonly
clean
870000
unkown image
page readonly
clean
2110000
unkown image
page read and write
clean
34E000
unkown
page read and write
clean
140000
unkown image
page readonly
clean
F0000
unkown image
page read and write
clean
714E000
unkown
page read and write
clean
1B60000
heap private
page read and write
clean
8424000
unkown
page read and write
clean
2BC0000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
70F000
stack
page read and write
clean
140000
unkown image
page readonly
clean
4D50000
unkown image
page readonly
clean
180000
unkown
page read and write
clean
3CC0000
unkown image
page readonly
clean
3CA0000
unkown
page read and write
clean
620000
unkown image
page readonly
clean
780000
unkown image
page readonly
clean
782F000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
45D6000
unkown
page read and write
clean
4D80000
unkown image
page readonly
clean
6BBE000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
409000
unkown image
page write copy
clean
87F000
unkown
page read and write
clean
834B000
unkown
page read and write
clean
3D4B000
unkown
page read and write
clean
95C0000
heap private
page read and write
clean
2540000
unkown
page read and write
clean
4D80000
unkown image
page readonly
clean
21BF000
unkown
page read and write
clean
4DB1000
unkown image
page read and write
clean
74B4000
heap private
page read and write
clean
5410000
heap private
page read and write
clean
6C59000
unkown
page read and write
clean
2A80000
unkown
page read and write
clean
980000
unkown
page execute and read and write
clean
376000
heap private
page read and write
clean
2CC7000
unkown image
page readonly
clean
4E60000
unkown
page read and write
clean
9222000
unkown
page read and write
clean
29F0000
unkown
page read and write
clean
877000
heap default
page read and write
clean
27E0000
unkown
page read and write
clean
29F0000
unkown
page read and write
clean
2B60000
unkown
page read and write
clean
1D7000
unkown
page read and write
clean
227E000
stack
page read and write
clean
2AA0000
unkown
page read and write
clean
2190000
unkown
page execute and read and write
clean
7EFC2000
unkown image
page readonly
clean
5360000
unkown image
page read and write
clean
4160000
unkown
page read and write
clean
2970000
unkown
page read and write
clean
4D50000
unkown image
page readonly
clean
3C90000
unkown image
page read and write
clean
263C000
unkown
page read and write
clean
6C59000
unkown
page read and write
clean
60F000
stack
page read and write
clean
770000
unkown image
page readonly
clean
8428000
unkown
page read and write
clean
371000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
91E3000
unkown
page read and write
clean
2AE0000
unkown image
page readonly
clean
21BF000
unkown
page read and write
clean
4B9D000
unkown
page read and write
clean
1D7000
unkown
page read and write
clean
2130000
unkown image
page read and write
clean
870000
heap private
page read and write
clean
4DC0000
unkown
page read and write
clean
31D000
heap default
page read and write
clean
3160000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
8374000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2A20000
unkown
page read and write
clean
83F8000
unkown
page read and write
clean
3D90000
unkown
page read and write
clean
2C7000
heap default
page read and write
clean
4BB0000
heap private
page read and write
clean
2500000
unkown image
page readonly
clean
5E0000
heap default
page read and write
clean
4E60000
unkown
page read and write
clean
31FF000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
4B00000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
F0000
unkown image
page read and write
clean
83D0000
unkown
page read and write
clean
1BE0000
unkown image
page readonly
clean
7B4B000
unkown
page read and write
clean
2A60000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
74B0000
heap private
page read and write
clean
4DB1000
unkown image
page read and write
clean
1CE000
unkown
page read and write
clean
4D50000
unkown image
page readonly
clean
29DA000
unkown
page read and write
clean
81AE000
unkown
page read and write
clean
32A0000
heap private
page read and write
clean
4593000
unkown
page read and write
clean
4AC0000
unkown
page read and write
clean
69BF000
unkown
page read and write
clean
30D000
unkown
page read and write
clean
24F0000
unkown image
page readonly
clean
2AA0000
unkown
page read and write
clean
2870000
unkown
page read and write
clean
4249000
unkown
page read and write
clean
3298000
unkown
page read and write
clean
92A4000
unkown
page read and write
clean
21C0000
unkown
page read and write
clean
32AE000
heap private
page read and write
clean
2B51000
unkown
page read and write
clean
41A0000
heap private
page read and write
clean
27E0000
unkown
page read and write
clean
7E1E000
unkown
page read and write
clean
5390000
heap private
page read and write
clean
330000
unkown
page read and write
clean
4BB0000
heap private
page read and write
clean
E4000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
There are 1308 hidden memdumps, click here to show them.