Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
DOC-0212.xlsm
|
Microsoft Excel 2007+
|
initial sample
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\VZZdgPFp2xiOJtfpv[1].dll
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
downloaded
|
||
C:\Users\user\besta.ocx
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\E8FA61E5.png
|
PNG image data, 1714 x 241, 8-bit colormap, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\CC82.tmp
|
Composite Document File V2 Document, Cannot read section info
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\~DF09EB9009A60E04D7.TMP
|
data
|
dropped
|
||
C:\Users\user\Desktop\~$DOC-0212.xlsm
|
data
|
dropped
|
||
C:\Windows\SysWOW64\Hisdtuljbeshqtad\zvklxm.vbc (copy)
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
|
||
C:\Windows\SysWOW64\rundll32.exe
|
C:\Windows\SysWow64\rundll32.exe ..\besta.ocx,44532.6051013889
|
||
C:\Windows\SysWOW64\rundll32.exe
|
C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\besta.ocx",Control_RunDLL
|
||
C:\Windows\SysWOW64\rundll32.exe
|
C:\Windows\SysWOW64\rundll32.exe "C:\Windows\SysWOW64\Hisdtuljbeshqtad\zvklxm.vbc",qEPqGlpBy
|
||
C:\Windows\System32\svchost.exe
|
C:\Windows\System32\svchost.exe -k WerSvcGroup
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://www.duoyuhudong.cn/wp-content/we8xi/vvC:
|
unknown
|
||
http://www.duoyuhudong.cn/wp-content/we8xi/
|
47.96.4.95
|
||
http://www.windows.com/pctv.
|
unknown
|
||
http://investor.msn.com
|
unknown
|
||
http://www.msnbc.com/news/ticker.txt
|
unknown
|
||
http://schemas.openformatrg/drawml/2006/spreadsheetD
|
unknown
|
||
http://sadabahar.com.np/wp-includes/pUM)http://sadabahar.com.np/wp-includes/pUMqI
|
unknown
|
||
http://schemas.openformatrg/package/2006/content-t
|
unknown
|
||
http://sadabahar.com.np/wp-inclu
|
unknown
|
||
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
|
unknown
|
||
http://www.hotmail.com/oe
|
unknown
|
||
http://sadabahar.com.np/wp-i
|
unknown
|
||
http://schemas.open
|
unknown
|
||
http://sadabahar.com.n
|
unknown
|
||
http://sadabahar.c
|
unknown
|
||
http://sadabahar.com
|
unknown
|
||
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
|
unknown
|
||
http://sadabahar.co
|
unknown
|
||
http://www.icra.org/vocabulary/.
|
unknown
|
||
http://sadabahar.com.np/wp-includes/pUMqITC-http://sadabahar.com.np/wp-includes/pUMqITCt8/http://sad
|
unknown
|
||
http://schemas.openformatrg/package/2006/r
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
|
unknown
|
||
http://investor.msn.com/
|
unknown
|
||
http://sadabahar.com.np/wp-includes/pUMqITCt83a/
|
194.233.67.242
|
||
http://sadabahar.com.np/wp-includes/pUMqITCt83a/J
|
unknown
|
||
http://www.%s.comPA
|
unknown
|
||
http://sadabahar.com.np/w
|
unknown
|
||
http://sadabahar.com.np/wp-inc
|
unknown
|
||
http://sadabahar.com.np/wp-includes/pUMqITCt83a/A
|
unknown
|
||
http://sadabahar.com.np/wp-include%http://sadabahar.com.np/wp-includes/p
|
unknown
|
There are 20 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
www.duoyuhudong.cn
|
47.96.4.95
|
||
sadabahar.com.np
|
194.233.67.242
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
47.96.4.95
|
www.duoyuhudong.cn
|
China
|
||
194.233.67.242
|
sadabahar.com.np
|
Germany
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
|
2i,
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
|
MTTT
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
|
ReviewToken
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2E14A
|
2E14A
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
|
VBAFiles
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
|
"u,
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
|
LastPurgeTime
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
|
Max Display
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Max Display
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 1
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 2
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 3
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 4
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 5
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 6
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 7
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 8
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 9
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 10
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 11
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 12
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 13
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 14
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 15
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 16
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 17
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 18
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 19
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 20
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\3DD16
|
3DD16
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
|
Max Display
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Max Display
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 1
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 2
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 3
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 4
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 5
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 6
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 7
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 8
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 9
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 10
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 11
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 12
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 13
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 14
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 15
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 16
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 17
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 18
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 19
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 20
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\3E550
|
3E550
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
|
1033
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
|
1033
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
|
EXCELFiles
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
|
ProductFiles
|
||
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
|
SavedLegacySettings
|
There are 48 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
1EC0000
|
unkown
|
page execute and read and write
|
||
1A0000
|
unkown
|
page execute and read and write
|
||
29D000
|
heap default
|
page read and write
|
||
7D18000
|
unkown
|
page read and write
|
||
7CD0000
|
unkown
|
page read and write
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
4E0000
|
unkown image
|
page readonly
|
||
212D000
|
unkown
|
page read and write
|
||
6E520000
|
unkown image
|
page readonly
|
||
330000
|
unkown
|
page read and write
|
||
77FF000
|
heap private
|
page read and write
|
||
1BD000
|
unkown
|
page read and write
|
||
6DF0000
|
unkown
|
page read and write
|
||
640000
|
heap default
|
page read and write
|
||
4BE5000
|
unkown
|
page read and write
|
||
650000
|
heap private
|
page read and write
|
||
2145000
|
heap private
|
page read and write
|
||
34B0000
|
unkown
|
page read and write
|
||
638000
|
heap default
|
page read and write
|
||
6CC0000
|
unkown
|
page read and write
|
||
7A5C000
|
unkown
|
page read and write
|
||
458E000
|
stack
|
page read and write
|
||
34A0000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
5A30000
|
unkown image
|
page read and write
|
||
76C0000
|
unkown
|
page read and write
|
||
42F2000
|
unkown
|
page read and write
|
||
8075000
|
unkown
|
page read and write
|
||
3200000
|
unkown
|
page read and write
|
||
3B0000
|
heap default
|
page read and write
|
||
592000
|
heap private
|
page read and write
|
||
25F5000
|
heap private
|
page read and write
|
||
4980000
|
unkown
|
page read and write
|
||
55F0000
|
unkown
|
page read and write
|
||
228000
|
unkown
|
page read and write
|
||
5878000
|
unkown
|
page read and write
|
||
270D000
|
stack
|
page read and write
|
||
50000
|
unkown image
|
page readonly
|
||
7DE0000
|
stack
|
page read and write
|
||
3E06000
|
unkown
|
page read and write
|
||
33E0000
|
heap private
|
page read and write
|
||
7610000
|
unkown
|
page read and write
|
||
390000
|
unkown image
|
page readonly
|
||
6BD0000
|
unkown
|
page read and write
|
||
7CF0000
|
unkown
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
4F0000
|
heap private
|
page read and write
|
||
3400000
|
unkown
|
page read and write
|
||
6FC0000
|
unkown image
|
page readonly
|
||
6E48D000
|
unkown image
|
page readonly
|
||
6C0000
|
unkown image
|
page readonly
|
||
3020000
|
unkown image
|
page readonly
|
||
3E0000
|
heap private
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
430F000
|
unkown
|
page read and write
|
||
6DA0000
|
unkown
|
page read and write
|
||
71E0000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
30000
|
unkown image
|
page read and write
|
||
55F0000
|
unkown
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
2170000
|
unkown image
|
page readonly
|
||
2B3000
|
unkown
|
page read and write
|
||
170000
|
heap private
|
page read and write
|
||
7160000
|
heap private
|
page read and write
|
||
50000
|
unkown image
|
page readonly
|
||
7600000
|
unkown image
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
2D1000
|
unkown
|
page read and write
|
||
50000
|
unkown image
|
page readonly
|
||
60000
|
unkown image
|
page readonly
|
||
6FF0000
|
unkown
|
page read and write
|
||
6C30000
|
unkown
|
page read and write
|
||
50000
|
unkown image
|
page readonly
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
3F10000
|
unkown
|
page read and write
|
||
7ADF000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
7EFE0000
|
unkown image
|
page readonly
|
||
1DA0000
|
unkown
|
page read and write
|
||
3230000
|
unkown
|
page read and write
|
||
55F0000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
7D18000
|
unkown
|
page read and write
|
||
33D3000
|
unkown
|
page read and write
|
||
260C000
|
stack
|
page read and write
|
||
60000
|
unkown image
|
page readonly
|
||
640000
|
unkown
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
40000
|
unkown image
|
page readonly
|
||
50000
|
unkown image
|
page readonly
|
||
7DE0000
|
stack
|
page read and write
|
||
4BF7000
|
unkown
|
page read and write
|
||
4360000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
3EE000
|
heap default
|
page read and write
|
||
6E430000
|
unkown image
|
page readonly
|
||
1EE5000
|
unkown
|
page execute and read and write
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
50000
|
unkown image
|
page readonly
|
||
4B0000
|
unkown image
|
page readonly
|
||
76B6000
|
unkown
|
page read and write
|
||
50000
|
unkown image
|
page readonly
|
||
5830000
|
unkown
|
page read and write
|
||
6E7F1000
|
unkown image
|
page readonly
|
||
2124000
|
unkown
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
60000
|
unkown image
|
page readonly
|
||
2C3000
|
unkown
|
page read and write
|
||
3F35000
|
unkown
|
page read and write
|
||
6E430000
|
unkown image
|
page readonly
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
6E458000
|
unkown image
|
page readonly
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
34C0000
|
unkown
|
page read and write
|
||
6D00000
|
unkown
|
page read and write
|
||
20F0000
|
unkown image
|
page readonly
|
||
7FFFFFC0000
|
unkown image
|
page readonly
|
||
2100000
|
unkown
|
page read and write
|
||
1C40000
|
unkown
|
page read and write
|
||
6C1C000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
1DAE000
|
unkown
|
page read and write
|
||
3460000
|
unkown
|
page read and write
|
||
2E2E000
|
stack
|
page read and write
|
||
7000000
|
unkown
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
7FFFFFC2000
|
unkown image
|
page readonly
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
6C27000
|
unkown
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
80B2000
|
unkown
|
page read and write
|
||
6BD0000
|
unkown
|
page read and write
|
||
6CD0000
|
unkown
|
page read and write
|
||
2C0000
|
unkown image
|
page readonly
|
||
7CD0000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
2C3000
|
unkown
|
page read and write
|
||
6B35000
|
heap private
|
page read and write
|
||
6E48A000
|
unkown image
|
page read and write
|
||
7A81000
|
unkown
|
page read and write
|
||
8100000
|
unkown
|
page read and write
|
||
5630000
|
unkown
|
page read and write
|
||
42F5000
|
unkown
|
page read and write
|
||
7022000
|
unkown
|
page read and write
|
||
77A0000
|
unkown
|
page read and write
|
||
803B000
|
stack
|
page read and write
|
||
7FFFFFB2000
|
unkown image
|
page readonly
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
6B00000
|
unkown
|
page read and write
|
||
4BC7000
|
unkown
|
page read and write
|
||
33D5000
|
unkown
|
page read and write
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
677000
|
heap default
|
page read and write
|
||
77A6000
|
unkown
|
page read and write
|
||
6FCF000
|
unkown image
|
page readonly
|
||
76B2000
|
unkown
|
page read and write
|
||
2D6F000
|
stack
|
page read and write
|
||
7D4C000
|
unkown
|
page read and write
|
||
20000
|
unkown image
|
page readonly
|
||
3DD0000
|
unkown
|
page read and write
|
||
286000
|
unkown
|
page read and write
|
||
3210000
|
unkown
|
page read and write
|
||
3F28000
|
unkown
|
page read and write
|
||
5270000
|
unkown
|
page read and write
|
||
6CC0000
|
unkown
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
6C3E000
|
unkown
|
page read and write
|
||
7066000
|
unkown
|
page read and write
|
||
7FFFFFD0000
|
unkown image
|
page readonly
|
||
3380000
|
unkown image
|
page readonly
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
2130000
|
unkown
|
page read and write
|
||
2B4000
|
unkown
|
page read and write
|
||
260000
|
heap default
|
page read and write
|
||
840000
|
unkown image
|
page readonly
|
||
7A0000
|
unkown image
|
page readonly
|
||
7D35000
|
unkown
|
page read and write
|
||
6BC0000
|
unkown
|
page read and write
|
||
60000
|
unkown image
|
page readonly
|
||
4BCD000
|
unkown
|
page read and write
|
||
7CD0000
|
unkown
|
page read and write
|
||
6E80000
|
unkown
|
page read and write
|
||
55F0000
|
unkown
|
page read and write
|
||
337E000
|
stack
|
page read and write
|
||
6E48A000
|
unkown image
|
page read and write
|
||
3440000
|
unkown
|
page read and write
|
||
7CC0000
|
heap private
|
page read and write
|
||
6C00000
|
unkown
|
page read and write
|
||
D0000
|
unkown image
|
page readonly
|
||
6E83B000
|
unkown image
|
page read and write
|
||
60000
|
unkown image
|
page readonly
|
||
6DA0000
|
unkown
|
page read and write
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
10000
|
unkown image
|
page read and write
|
||
7630000
|
heap private
|
page read and write
|
||
3F3D000
|
unkown
|
page read and write
|
||
75E0000
|
unkown image
|
page read and write
|
||
6E430000
|
unkown image
|
page readonly
|
||
55A0000
|
unkown image
|
page readonly
|
||
6CD0000
|
unkown
|
page read and write
|
||
6BD0000
|
unkown
|
page read and write
|
||
120000
|
unkown
|
page read and write
|
||
76B0000
|
unkown
|
page read and write
|
||
3470000
|
unkown
|
page read and write
|
||
1E0000
|
unkown image
|
page readonly
|
||
3270000
|
unkown
|
page read and write
|
||
7CF0000
|
unkown
|
page read and write
|
||
4BE1000
|
unkown
|
page read and write
|
||
50000
|
unkown image
|
page readonly
|
||
6E73000
|
unkown
|
page read and write
|
||
7AA1000
|
unkown
|
page read and write
|
||
6FD0000
|
unkown
|
page read and write
|
||
55F0000
|
unkown
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
160000
|
unkown
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
6BD0000
|
unkown
|
page read and write
|
||
6DE0000
|
unkown
|
page read and write
|
||
6E04000
|
unkown
|
page read and write
|
||
65E000
|
stack
|
page read and write
|
||
40000
|
unkown image
|
page readonly
|
||
2D6000
|
unkown
|
page read and write
|
||
1D60000
|
unkown
|
page read and write
|
||
6E430000
|
unkown image
|
page readonly
|
||
50000
|
unkown image
|
page readonly
|
||
44C000
|
heap default
|
page read and write
|
||
7CD0000
|
unkown
|
page read and write
|
||
1A80000
|
unkown image
|
page readonly
|
||
6E44000
|
unkown
|
page read and write
|
||
1DE0000
|
unkown image
|
page readonly
|
||
6E48C000
|
unkown image
|
page write copy
|
||
DC000
|
unkown
|
page read and write
|
||
527000
|
heap default
|
page read and write
|
||
1C50000
|
heap private
|
page read and write
|
||
3410000
|
unkown
|
page read and write
|
||
6BF0000
|
unkown
|
page read and write
|
||
4310000
|
unkown
|
page read and write
|
||
6BD0000
|
unkown
|
page read and write
|
||
42D0000
|
unkown
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
D60000
|
heap private
|
page read and write
|
||
33A0000
|
unkown
|
page read and write
|
||
3220000
|
unkown
|
page read and write
|
||
19A000
|
unkown
|
page read and write
|
||
7F0000
|
unkown image
|
page readonly
|
||
7FFFFFB0000
|
unkown image
|
page readonly
|
||
7EFE0000
|
unkown image
|
page readonly
|
||
60000
|
unkown image
|
page readonly
|
||
6B20000
|
unkown
|
page read and write
|
||
1D84000
|
unkown
|
page read and write
|
||
4BE5000
|
unkown
|
page read and write
|
||
1C33000
|
unkown
|
page read and write
|
||
60000
|
unkown image
|
page readonly
|
||
2BB000
|
unkown
|
page read and write
|
||
6CC0000
|
unkown
|
page read and write
|
||
76F0000
|
heap private
|
page read and write
|
||
3150000
|
unkown
|
page read and write
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
3430000
|
unkown
|
page read and write
|
||
520000
|
heap default
|
page read and write
|
||
7FFFFFD0000
|
unkown image
|
page readonly
|
||
2490000
|
unkown
|
page read and write
|
||
3EE0000
|
unkown
|
page read and write
|
||
26D000
|
heap default
|
page read and write
|
||
E0000
|
heap default
|
page read and write
|
||
5883000
|
unkown
|
page read and write
|
||
424000
|
heap default
|
page read and write
|
||
1C96000
|
unkown
|
page read and write
|
||
620000
|
unkown image
|
page readonly
|
||
7024000
|
heap private
|
page read and write
|
||
7D4C000
|
unkown
|
page read and write
|
||
25F0000
|
heap private
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
42E0000
|
unkown
|
page read and write
|
||
6BC0000
|
unkown
|
page read and write
|
||
110000
|
unkown
|
page read and write
|
||
1BF0000
|
unkown
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
3ED0000
|
unkown
|
page read and write
|
||
3F20000
|
unkown
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
6D06000
|
unkown
|
page read and write
|
||
3390000
|
unkown image
|
page read and write
|
||
7010000
|
unkown
|
page read and write
|
||
217B000
|
heap private
|
page read and write
|
||
60000
|
unkown image
|
page readonly
|
||
75F0000
|
unkown image
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
3240000
|
heap private
|
page read and write
|
||
60000
|
unkown image
|
page readonly
|
||
6E34000
|
unkown
|
page read and write
|
||
50000
|
unkown image
|
page readonly
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
6DC7000
|
unkown
|
page read and write
|
||
50000
|
unkown image
|
page readonly
|
||
6E521000
|
unkown image
|
page execute read
|
||
5E4000
|
heap default
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
58F9000
|
unkown
|
page read and write
|
||
56F000
|
stack
|
page read and write
|
||
6E430000
|
unkown image
|
page readonly
|
||
4E8F000
|
stack
|
page read and write
|
||
4E90000
|
unkown image
|
page readonly
|
||
25CF000
|
stack
|
page read and write
|
||
557000
|
heap default
|
page read and write
|
||
7610000
|
unkown
|
page read and write
|
||
715A000
|
unkown
|
page read and write
|
||
250000
|
unkown
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
5464000
|
stack
|
page read and write
|
||
230000
|
heap default
|
page read and write
|
||
3FC0000
|
unkown
|
page read and write
|
||
5610000
|
unkown
|
page read and write
|
||
5C7000
|
heap default
|
page read and write
|
||
6C0F000
|
unkown
|
page read and write
|
||
41CF000
|
stack
|
page read and write
|
||
6C20000
|
unkown
|
page read and write
|
||
7FFFFFB2000
|
unkown image
|
page readonly
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
3450000
|
unkown
|
page read and write
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
1DBE000
|
unkown
|
page read and write
|
||
7FFFFFD0000
|
unkown image
|
page readonly
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
6BD0000
|
unkown
|
page read and write
|
||
7FFFFFB0000
|
unkown image
|
page readonly
|
||
27B0000
|
unkown image
|
page readonly
|
||
1C60000
|
unkown
|
page read and write
|
||
21D000
|
unkown
|
page read and write
|
||
35CF000
|
stack
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
6B29000
|
unkown
|
page read and write
|
||
A60000
|
heap private
|
page read and write
|
||
6E844000
|
unkown image
|
page read and write
|
||
3EF0000
|
unkown
|
page read and write
|
||
6CCA000
|
unkown
|
page read and write
|
||
5640000
|
heap private
|
page read and write
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
8100000
|
unkown
|
page read and write
|
||
5480000
|
unkown
|
page read and write
|
||
7FFFFFD0000
|
unkown image
|
page readonly
|
||
2DAE000
|
stack
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
1D97000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
2060000
|
unkown
|
page read and write
|
||
2490000
|
unkown
|
page read and write
|
||
60000
|
unkown image
|
page readonly
|
||
240000
|
unkown image
|
page readonly
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
5924000
|
unkown
|
page read and write
|
||
6FF2000
|
unkown
|
page read and write
|
||
76E0000
|
unkown
|
page read and write
|
||
2357000
|
unkown image
|
page readonly
|
||
6CD0000
|
unkown
|
page read and write
|
||
237000
|
heap default
|
page read and write
|
||
6D10000
|
unkown
|
page read and write
|
||
3498000
|
unkown
|
page read and write
|
||
77C9000
|
heap private
|
page read and write
|
||
6E00000
|
unkown
|
page read and write
|
||
1C43000
|
unkown
|
page read and write
|
||
10000
|
unkown image
|
page read and write
|
||
6FF0000
|
unkown
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
6D08000
|
unkown
|
page read and write
|
||
4BE0000
|
unkown
|
page read and write
|
||
60000
|
unkown image
|
page readonly
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
6DC0000
|
unkown
|
page read and write
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
42F7000
|
unkown
|
page read and write
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
7780000
|
unkown
|
page read and write
|
||
7D35000
|
unkown
|
page read and write
|
||
6E28000
|
unkown
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
7CD0000
|
unkown
|
page read and write
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
50000
|
unkown image
|
page readonly
|
||
7156000
|
unkown
|
page read and write
|
||
3468000
|
unkown
|
page read and write
|
||
60000
|
unkown image
|
page readonly
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
2FB0000
|
unkown
|
page read and write
|
||
5472000
|
unkown
|
page read and write
|
||
447D000
|
stack
|
page read and write
|
||
52B7000
|
unkown
|
page read and write
|
||
1D75000
|
unkown
|
page read and write
|
||
3260000
|
unkown
|
page read and write
|
||
7EFE0000
|
unkown image
|
page readonly
|
||
140000
|
unkown
|
page read and write
|
||
3238000
|
unkown
|
page read and write
|
||
7B00000
|
heap private
|
page read and write
|
||
560F000
|
unkown
|
page read and write
|
||
1C30000
|
unkown
|
page read and write
|
||
7FFFFFB2000
|
unkown image
|
page readonly
|
||
4BCA000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
10000
|
unkown image
|
page read and write
|
||
7DE0000
|
stack
|
page read and write
|
||
6E48C000
|
unkown image
|
page write copy
|
||
55F0000
|
unkown
|
page read and write
|
||
7FFFFFC2000
|
unkown image
|
page readonly
|
||
8075000
|
unkown
|
page read and write
|
||
592C000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
7D18000
|
unkown
|
page read and write
|
||
3F39000
|
unkown
|
page read and write
|
||
7CD0000
|
unkown
|
page read and write
|
||
6FE5000
|
unkown
|
page read and write
|
||
2499000
|
unkown
|
page read and write
|
||
544000
|
heap default
|
page read and write
|
||
6BD0000
|
unkown
|
page read and write
|
||
560C000
|
unkown
|
page read and write
|
||
7CD0000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
267000
|
heap default
|
page read and write
|
||
50000
|
unkown image
|
page readonly
|
||
6E48A000
|
unkown image
|
page read and write
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
6E430000
|
unkown image
|
page readonly
|
||
3010000
|
unkown
|
page read and write
|
||
6E458000
|
unkown image
|
page readonly
|
||
6DB0000
|
unkown
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
7FFFFFC2000
|
unkown image
|
page readonly
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
324C000
|
heap private
|
page read and write
|
||
F0000
|
unkown
|
page read and write
|
||
50000
|
unkown image
|
page readonly
|
||
7FFFFFB0000
|
unkown image
|
page readonly
|
||
380000
|
unkown
|
page read and write
|
||
5C0000
|
heap default
|
page read and write
|
||
3E8000
|
heap private
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
7CD0000
|
unkown
|
page read and write
|
||
6FC4000
|
unkown image
|
page readonly
|
||
25F9000
|
heap private
|
page read and write
|
||
7A50000
|
unkown
|
page read and write
|
||
6E458000
|
unkown image
|
page readonly
|
||
6FE0000
|
unkown image
|
page readonly
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
5CF000
|
stack
|
page read and write
|
||
1E80000
|
heap private
|
page read and write
|
||
4BD0000
|
unkown
|
page read and write
|
||
7030000
|
unkown
|
page read and write
|
||
56F0000
|
unkown
|
page read and write
|
||
4B80000
|
unkown
|
page read and write
|
||
7D4C000
|
unkown
|
page read and write
|
||
7780000
|
unkown
|
page read and write
|
||
76D0000
|
unkown
|
page read and write
|
||
7EFDF000
|
unkown
|
page read and write
|
||
60000
|
unkown image
|
page readonly
|
||
7CF0000
|
unkown
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
284000
|
heap default
|
page read and write
|
||
6E431000
|
unkown image
|
page execute read
|
||
6E84F000
|
unkown image
|
page readonly
|
||
25E0000
|
unkown
|
page read and write
|
||
4BE8000
|
unkown
|
page read and write
|
||
27AE000
|
stack
|
page read and write
|
||
10000
|
unkown image
|
page read and write
|
||
40C0000
|
unkown
|
page read and write
|
||
4FE000
|
stack
|
page read and write
|
||
6C22000
|
unkown
|
page read and write
|
||
3480000
|
unkown
|
page read and write
|
||
7A6D000
|
unkown
|
page read and write
|
||
1C55000
|
heap private
|
page read and write
|
||
13C000
|
unkown
|
page read and write
|
||
55D000
|
heap default
|
page read and write
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
7020000
|
heap private
|
page read and write
|
||
266F000
|
stack
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
2010000
|
unkown image
|
page readonly
|
||
BB0000
|
heap private
|
page read and write
|
||
120000
|
unkown image
|
page readonly
|
||
1FC7000
|
unkown image
|
page readonly
|
||
7D35000
|
unkown
|
page read and write
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
360000
|
unkown image
|
page readonly
|
||
3247000
|
heap private
|
page read and write
|
||
4F4000
|
heap private
|
page read and write
|
||
6E848000
|
unkown image
|
page write copy
|
||
4BCF000
|
unkown
|
page read and write
|
||
3160000
|
heap private
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
42FE000
|
unkown
|
page read and write
|
||
1D80000
|
unkown
|
page read and write
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
5F7000
|
heap default
|
page read and write
|
||
6CC0000
|
unkown
|
page read and write
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
588B000
|
unkown
|
page read and write
|
||
6CC0000
|
unkown
|
page read and write
|
||
6B3E000
|
heap private
|
page read and write
|
||
60000
|
unkown image
|
page readonly
|
||
7DE0000
|
stack
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
7FEFF1A0000
|
unkown
|
page execute read
|
||
90000
|
unkown image
|
page read and write
|
||
7770000
|
unkown
|
page read and write
|
||
1C67000
|
unkown image
|
page readonly
|
||
6E84C000
|
unkown image
|
page read and write
|
||
7010000
|
unkown
|
page read and write
|
||
1C5000
|
unkown
|
page execute and read and write
|
||
3420000
|
unkown
|
page read and write
|
||
D70000
|
unkown image
|
page readonly
|
||
60000
|
unkown image
|
page readonly
|
||
55F0000
|
unkown
|
page read and write
|
||
42FA000
|
unkown
|
page read and write
|
||
3F00000
|
unkown
|
page read and write
|
||
1D0000
|
heap private
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
324C000
|
unkown
|
page read and write
|
||
31E0000
|
unkown
|
page read and write
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
6DD0000
|
unkown
|
page read and write
|
||
E0000
|
unkown
|
page read and write
|
||
582A000
|
stack
|
page read and write
|
||
6E73000
|
unkown
|
page read and write
|
||
30000
|
unkown image
|
page read and write
|
||
6CC0000
|
unkown
|
page read and write
|
||
6BD0000
|
unkown
|
page read and write
|
||
7FFFFFC0000
|
unkown image
|
page readonly
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
65300000
|
unkown image
|
page readonly
|
||
7EFE0000
|
unkown image
|
page readonly
|
||
4590000
|
unkown image
|
page readonly
|
||
6F30000
|
heap private
|
page read and write
|
||
33E4000
|
heap private
|
page read and write
|
||
6E90000
|
heap private
|
page read and write
|
||
26BD000
|
stack
|
page read and write
|
||
366000
|
unkown
|
page read and write
|
||
20000
|
unkown image
|
page readonly
|
||
3A0000
|
unkown
|
page read and write
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
2140000
|
heap private
|
page read and write
|
||
6E10000
|
unkown image
|
page readonly
|
||
4300000
|
unkown
|
page read and write
|
||
1C3E000
|
unkown
|
page read and write
|
||
6D20000
|
heap private
|
page read and write
|
||
6BEA000
|
unkown
|
page read and write
|
||
2A4000
|
unkown
|
page read and write
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
7E7F000
|
unkown
|
page read and write
|
||
6E431000
|
unkown image
|
page execute read
|
||
50000
|
unkown image
|
page readonly
|
||
4BE1000
|
unkown
|
page read and write
|
||
4F0000
|
unkown image
|
page readonly
|
||
7776000
|
unkown
|
page read and write
|
||
5600000
|
unkown
|
page read and write
|
||
6C04000
|
unkown
|
page read and write
|
||
160000
|
unkown image
|
page readonly
|
||
7FFFFFC0000
|
unkown image
|
page readonly
|
||
52BB000
|
unkown
|
page read and write
|
||
7FFFFFB0000
|
unkown image
|
page readonly
|
||
1D70000
|
unkown
|
page read and write
|
||
2B3000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
360000
|
unkown
|
page read and write
|
||
7130000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
170000
|
heap private
|
page read and write
|
||
7610000
|
unkown
|
page read and write
|
||
6CE4000
|
unkown
|
page read and write
|
||
58DB000
|
unkown
|
page read and write
|
||
6DFF000
|
unkown
|
page read and write
|
||
7FFFFFB2000
|
unkown image
|
page readonly
|
||
6FF0000
|
unkown
|
page read and write
|
||
660000
|
unkown image
|
page readonly
|
||
6BD0000
|
unkown
|
page read and write
|
||
6B30000
|
heap private
|
page read and write
|
||
60000
|
unkown image
|
page readonly
|
||
7D35000
|
unkown
|
page read and write
|
||
7B0000
|
unkown image
|
page readonly
|
||
33C0000
|
unkown
|
page read and write
|
||
297000
|
heap default
|
page read and write
|
||
3030000
|
unkown image
|
page readonly
|
||
7DE0000
|
stack
|
page read and write
|
||
413000
|
heap default
|
page read and write
|
||
5077000
|
unkown image
|
page readonly
|
||
7D18000
|
unkown
|
page read and write
|
||
630000
|
unkown image
|
page readonly
|
||
6BD0000
|
unkown
|
page read and write
|
||
7010000
|
unkown
|
page read and write
|
||
7620000
|
unkown
|
page read and write
|
||
314F000
|
stack
|
page read and write
|
||
7EFDF000
|
unkown
|
page read and write
|
||
5FD000
|
heap default
|
page read and write
|
||
6BDC000
|
unkown
|
page read and write
|
||
574000
|
heap private
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
2494000
|
unkown
|
page read and write
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
2A0000
|
unkown
|
page read and write
|
||
2120000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
77C0000
|
heap private
|
page read and write
|
||
7CD0000
|
unkown
|
page read and write
|
||
7620000
|
unkown
|
page read and write
|
||
55F0000
|
unkown
|
page read and write
|
||
654000
|
heap private
|
page read and write
|
||
7CF0000
|
unkown
|
page read and write
|
||
6BD0000
|
unkown
|
page read and write
|
||
2C0E000
|
stack
|
page read and write
|
||
20000
|
unkown image
|
page readonly
|
||
31F0000
|
unkown
|
page read and write
|
||
5488000
|
unkown
|
page read and write
|
||
6D0A000
|
unkown
|
page read and write
|
||
4A7F000
|
unkown
|
page read and write
|
||
76D0000
|
unkown
|
page read and write
|
||
50000
|
unkown image
|
page readonly
|
||
6BF9000
|
unkown
|
page read and write
|
||
10000
|
unkown image
|
page read and write
|
||
3A0000
|
heap private
|
page read and write
|
||
7FFFFFC0000
|
unkown image
|
page readonly
|
||
469000
|
heap default
|
page read and write
|
||
6E48C000
|
unkown image
|
page write copy
|
||
3F32000
|
unkown
|
page read and write
|
||
1DA8000
|
unkown
|
page read and write
|
||
216000
|
unkown
|
page read and write
|
||
50000
|
unkown image
|
page readonly
|
||
850000
|
unkown image
|
page readonly
|
||
6BE0000
|
unkown
|
page read and write
|
||
3F1E000
|
unkown
|
page read and write
|
||
400000
|
heap default
|
page read and write
|
||
6E48D000
|
unkown image
|
page readonly
|
||
6E8D000
|
unkown
|
page read and write
|
||
7010000
|
unkown
|
page read and write
|
||
6E431000
|
unkown image
|
page execute read
|
||
7010000
|
unkown
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
276000
|
heap default
|
page read and write
|
||
6C2A000
|
unkown
|
page read and write
|
||
15D000
|
unkown
|
page read and write
|
||
4C80000
|
unkown
|
page read and write
|
||
4BCF000
|
unkown
|
page read and write
|
||
651000
|
heap default
|
page read and write
|
||
3B7000
|
heap default
|
page read and write
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
7012000
|
unkown
|
page read and write
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
1C00000
|
unkown
|
page read and write
|
||
55B0000
|
unkown
|
page read and write
|
||
7610000
|
unkown
|
page read and write
|
||
7EFDF000
|
unkown
|
page read and write
|
||
7790000
|
unkown
|
page read and write
|
||
6BD0000
|
unkown
|
page read and write
|
||
7CD0000
|
unkown
|
page read and write
|
||
100000
|
unkown image
|
page readonly
|
||
4BE8000
|
unkown
|
page read and write
|
||
2110000
|
unkown
|
page read and write
|
||
3F30000
|
unkown
|
page read and write
|
||
46C000
|
heap default
|
page read and write
|
||
100000
|
unkown
|
page read and write
|
||
3250000
|
unkown
|
page read and write
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
7FFFFFC2000
|
unkown image
|
page readonly
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
30000
|
unkown image
|
page readonly
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
20000
|
unkown image
|
page readonly
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
7130000
|
unkown
|
page read and write
|
||
380000
|
heap default
|
page read and write
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
30000
|
unkown image
|
page readonly
|
||
7070000
|
unkown
|
page read and write
|
||
55F0000
|
unkown
|
page read and write
|
||
5594000
|
stack
|
page read and write
|
||
CD000
|
unkown
|
page read and write
|
||
570000
|
heap private
|
page read and write
|
||
7150000
|
unkown
|
page read and write
|
||
60000
|
unkown image
|
page readonly
|
||
324A000
|
unkown
|
page read and write
|
||
6BD0000
|
unkown
|
page read and write
|
||
3F3B000
|
unkown
|
page read and write
|
||
130000
|
heap private
|
page read and write
|
||
7CD0000
|
unkown
|
page read and write
|
||
5853000
|
unkown
|
page read and write
|
||
5928000
|
unkown
|
page read and write
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
7CD0000
|
unkown
|
page read and write
|
||
7D4C000
|
unkown
|
page read and write
|
||
4DF000
|
stack
|
page read and write
|
||
7A8D000
|
unkown
|
page read and write
|
||
7A7C000
|
unkown
|
page read and write
|
||
6C40000
|
heap private
|
page read and write
|
||
7AE0000
|
unkown
|
page read and write
|
||
6E48D000
|
unkown image
|
page readonly
|
||
7CD0000
|
unkown
|
page read and write
|
||
7EFE0000
|
unkown image
|
page readonly
|
||
4370000
|
unkown
|
page read and write
|
||
80B2000
|
unkown
|
page read and write
|
||
3F40000
|
heap private
|
page execute and read and write
|
||
27B000
|
heap default
|
page read and write
|
||
6C10000
|
unkown
|
page read and write
|
||
2103000
|
unkown
|
page read and write
|
||
2C7E000
|
stack
|
page read and write
|
There are 704 hidden memdumps, click here to show them.