IOC Report

loading gif

Files

File Path
Type
Category
Malicious
sin t#U00edtulo_0212.xlsm
Microsoft Excel 2007+
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\Z8LJs4fFM8[1].dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
downloaded
malicious
C:\Users\user\Desktop\~$sin t#U00edtulo_0212.xlsm
data
dropped
malicious
C:\Users\user\besta.ocx
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\30817388.png
PNG image data, 1714 x 241, 8-bit colormap, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\CC15.tmp
Composite Document File V2 Document, Cannot read section info
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF20EA52A1DD92E798.TMP
data
dropped
clean
C:\Windows\SysWOW64\Nrenernv\nnave.jwm (copy)
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
malicious
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWow64\rundll32.exe ..\besta.ocx,44532.8898178241
malicious
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\besta.ocx",DllRegisterServer
malicious
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe "C:\Windows\SysWOW64\Nrenernv\nnave.jwm",ILDADvMws
malicious
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
clean

URLs

Name
IP
Malicious
http://www.duoyuhudong.cn/wp-content/we8xi/ooC:
unknown
malicious
http://www.duoyuhudong.cn/wp-content/we8xi/T
unknown
malicious
http://www.duoyuhudong.cn/wp-content/we8xi/R
unknown
malicious
http://www.duoyuhudong.cn/wp-content/we8xi/
47.96.4.95
malicious
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://schemas.openformatrg/drawml/2006/spreadsheetD
unknown
clean
http://sadabahar.com.np/wp-includes/pUM)http://sadabahar.com.np/wp-includes/pUMqI
unknown
clean
http://schemas.openformatrg/package/2006/content-t
unknown
clean
http://sadabahar.com.np/wp-inclu
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://sadabahar.com.np/wp-i
unknown
clean
http://schemas.open
unknown
clean
http://sadabahar.com.n
unknown
clean
http://sadabahar.c
unknown
clean
http://sadabahar.com
unknown
clean
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://sadabahar.co
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://sadabahar.com.np/wp-includes/pUMqITC-http://sadabahar.com.np/wp-includes/pUMqITCt8/http://sad
unknown
clean
http://schemas.openformatrg/package/2006/r
unknown
clean
http://investor.msn.com/
unknown
clean
http://sadabahar.com.np/wp-includes/pUMqITCt83a/
194.233.67.242
clean
http://sadabahar.com.np/w
unknown
clean
http://sadabahar.com.np/wp-inc
unknown
clean
http://sadabahar.com.np/wp-include%http://sadabahar.com.np/wp-includes/p
unknown
clean
There are 18 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
www.duoyuhudong.cn
47.96.4.95
clean
sadabahar.com.np
194.233.67.242
clean

IPs

IP
Domain
Country
Malicious
47.96.4.95
www.duoyuhudong.cn
China
clean
194.233.67.242
sadabahar.com.np
Germany
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
+%-
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2DD64
2DD64
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
/3-
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\3D5A7
3D5A7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\3E070
3E070
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
There are 48 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
210000
heap default
page read and write
clean
7425000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
143000
unkown
page read and write
clean
1DA0000
unkown
page read and write
clean
CC000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
598A000
unkown
page read and write
clean
5372000
unkown
page read and write
clean
41C0000
unkown
page read and write
clean
72B0000
unkown
page read and write
clean
460000
unkown
page read and write
clean
5500000
unkown
page read and write
clean
59D9000
unkown
page read and write
clean
7720000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
3B0000
unkown
page read and write
clean
7290000
unkown
page read and write
clean
4F90000
unkown image
page readonly
clean
7B78000
stack
page read and write
clean
342B000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
598F000
unkown
page read and write
clean
41FA000
unkown
page read and write
clean
204D000
unkown
page read and write
clean
7B30000
stack
page read and write
clean
6C22000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
54F0000
unkown
page read and write
clean
59B6000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
4E78000
unkown
page read and write
clean
200000
heap private
page read and write
clean
51E000
stack
page read and write
clean
7290000
unkown
page read and write
clean
5AC0000
unkown image
page read and write
clean
6E441000
unkown image
page execute read
clean
7570000
unkown image
page readonly
clean
76D0000
unkown
page read and write
clean
72F0000
unkown
page read and write
clean
7710000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
3020000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
4EDF000
unkown
page read and write
clean
72A0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
33F0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
6E48E000
unkown image
page readonly
clean
54F0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7B30000
stack
page read and write
clean
410000
heap private
page read and write
clean
7B78000
stack
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2600000
heap private
page read and write
clean
590F000
unkown
page read and write
clean
73F3000
unkown
page read and write
clean
3F70000
unkown
page read and write
clean
6E48E000
unkown image
page readonly
clean
6AD000
heap default
page read and write
clean
7290000
unkown
page read and write
clean
144000
unkown
page read and write
clean
2D0000
unkown
page read and write
clean
4EDD000
unkown
page read and write
clean
360000
unkown
page read and write
clean
7B95000
stack
page read and write
clean
A50000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
33D0000
unkown
page read and write
clean
6AF7000
unkown
page read and write
clean
797D000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
4C8E000
stack
page read and write
clean
24E0000
unkown
page read and write
clean
316000
unkown
page read and write
clean
3427000
heap private
page read and write
clean
3F00000
unkown
page read and write
clean
7860000
unkown
page read and write
clean
D0000
unkown image
page readonly
clean
4B20000
unkown
page read and write
clean
900000
unkown image
page readonly
clean
670000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
48F000
stack
page read and write
clean
7410000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
2120000
unkown image
page readonly
clean
7B50000
stack
page read and write
clean
54F0000
unkown
page read and write
clean
7860000
unkown
page read and write
clean
1CD6000
unkown
page read and write
clean
7B78000
stack
page read and write
clean
72A0000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
72A0000
unkown
page read and write
clean
3FA0000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
54F0000
unkown
page read and write
clean
7B9F000
stack
page read and write
clean
50000
unkown image
page readonly
clean
40E0000
unkown
page read and write
clean
3FA4000
heap private
page read and write
clean
41FE000
unkown
page read and write
clean
41E0000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7830000
unkown
page read and write
clean
5918000
unkown
page read and write
clean
7B30000
stack
page read and write
clean
72E0000
unkown
page read and write
clean
7B30000
stack
page read and write
clean
7890000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
30000
unkown image
page read and write
clean
3F10000
unkown
page read and write
clean
7304000
unkown
page read and write
clean
7860000
unkown
page read and write
clean
8280000
unkown
page read and write
clean
700000
unkown image
page readonly
clean
4847000
unkown
page read and write
clean
6E550000
unkown image
page readonly
clean
E0000
unkown
page read and write
clean
166000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
2064000
unkown
page read and write
clean
2A0000
heap private
page read and write
clean
7446000
unkown
page read and write
clean
6E479000
unkown image
page readonly
clean
32A0000
unkown
page read and write
clean
1A3000
unkown
page execute and read and write
clean
50000
unkown image
page readonly
clean
2069000
unkown
page read and write
clean
76D0000
unkown
page read and write
clean
480000
heap default
page read and write
clean
59A5000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
6CC6000
unkown
page read and write
clean
1E0000
heap default
page read and write
clean
7B30000
stack
page read and write
clean
433000
unkown
page read and write
clean
770000
unkown image
page readonly
clean
7554000
unkown image
page readonly
clean
59A5000
unkown
page read and write
clean
42E000
unkown
page read and write
clean
23E0000
heap private
page read and write
clean
7830000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
4EDA000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
3DD5000
unkown
page read and write
clean
4EF0000
unkown
page read and write
clean
3FC0000
unkown
page read and write
clean
7840000
unkown
page read and write
clean
4EF1000
unkown
page read and write
clean
2FB0000
unkown
page read and write
clean
170000
unkown image
page readonly
clean
40F0000
unkown
page read and write
clean
2060000
unkown
page read and write
clean
7360000
unkown
page read and write
clean
400000
heap default
page read and write
clean
154000
unkown
page read and write
clean
74B0000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
6CC8000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
3F60000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
660000
unkown image
page readonly
clean
7B30000
stack
page read and write
clean
116000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
78C0000
heap private
page read and write
clean
751D000
unkown
page read and write
clean
6E87F000
unkown image
page readonly
clean
90000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
79E0000
unkown
page read and write
clean
797C000
unkown
page read and write
clean
5380000
unkown
page read and write
clean
595D000
unkown
page read and write
clean
4B10000
unkown
page read and write
clean
4BE000
heap default
page read and write
clean
548E000
stack
page read and write
clean
73C4000
unkown
page read and write
clean
420F000
unkown
page read and write
clean
2500000
heap private
page read and write
clean
7EFD0000
unkown image
page readonly
clean
3010000
unkown
page read and write
clean
7720000
unkown
page read and write
clean
1EA0000
unkown image
page readonly
clean
7370000
unkown
page read and write
clean
419E000
unkown
page read and write
clean
1CA0000
unkown
page read and write
clean
3F40000
unkown
page read and write
clean
2030000
unkown
page read and write
clean
54F0000
unkown
page read and write
clean
7850000
unkown
page read and write
clean
72B0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
55B5000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7590000
unkown image
page read and write
clean
5388000
unkown
page read and write
clean
41F2000
unkown
page read and write
clean
5510000
heap private
page read and write
clean
21D000
heap default
page read and write
clean
7991000
unkown
page read and write
clean
430000
unkown
page read and write
clean
1CD000
unkown
page read and write
clean
7310000
unkown
page read and write
clean
40C4000
stack
page read and write
clean
7700000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
20A5000
heap private
page read and write
clean
4E90000
unkown
page read and write
clean
6E878000
unkown image
page write copy
clean
2010000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
3030000
unkown image
page readonly
clean
487000
heap default
page read and write
clean
6C1B000
unkown
page read and write
clean
7945000
unkown
page read and write
clean
7510000
unkown
page read and write
clean
595D000
unkown
page read and write
clean
7860000
unkown
page read and write
clean
7846000
unkown
page read and write
clean
7890000
unkown
page read and write
clean
4B70000
unkown
page read and write
clean
54B0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
4100000
unkown
page read and write
clean
22B000
heap default
page read and write
clean
5904000
unkown
page read and write
clean
6E10000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
1DA8000
unkown
page read and write
clean
59CF000
unkown
page read and write
clean
7B30000
stack
page read and write
clean
54F0000
unkown
page read and write
clean
1E0000
unkown
page read and write
clean
598F000
unkown
page read and write
clean
2023000
unkown
page read and write
clean
AA0000
unkown image
page readonly
clean
423000
unkown
page read and write
clean
32B8000
unkown
page read and write
clean
6AFC000
unkown
page read and write
clean
7462000
unkown
page read and write
clean
7290000
unkown
page read and write
clean
24000
heap private
page read and write
clean
7B30000
stack
page read and write
clean
73A8000
unkown
page read and write
clean
694000
heap default
page read and write
clean
6E440000
unkown image
page readonly
clean
390000
unkown
page read and write
clean
180000
unkown
page execute and read and write
clean
7B30000
stack
page read and write
clean
404000
heap default
page read and write
clean
33E0000
unkown
page read and write
clean
226000
heap default
page read and write
clean
7F15000
unkown
page read and write
clean
7B30000
stack
page read and write
clean
41F5000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7B95000
stack
page read and write
clean
3EED000
stack
page read and write
clean
72A0000
unkown
page read and write
clean
4800000
unkown
page read and write
clean
6E440000
unkown image
page readonly
clean
6CB0000
unkown
page read and write
clean
7384000
unkown
page read and write
clean
8090000
heap private
page read and write
clean
6C10000
unkown
page read and write
clean
7290000
unkown
page read and write
clean
55BE000
heap private
page read and write
clean
2040000
unkown
page read and write
clean
4EF5000
unkown
page read and write
clean
7842000
unkown
page read and write
clean
7290000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
20C000
unkown
page read and write
clean
6E821000
unkown image
page readonly
clean
594F000
unkown
page read and write
clean
2509000
heap private
page read and write
clean
60000
unkown image
page readonly
clean
20DB000
heap private
page read and write
clean
2505000
heap private
page read and write
clean
54F0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
4E87000
unkown
page read and write
clean
417000
heap default
page read and write
clean
550F000
unkown
page read and write
clean
4EE0000
unkown
page read and write
clean
4F4000
heap default
page read and write
clean
7EFD0000
unkown image
page readonly
clean
33CF000
stack
page read and write
clean
6E440000
unkown image
page readonly
clean
6AC0000
unkown
page read and write
clean
95F000
stack
page read and write
clean
C0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
6E551000
unkown image
page execute read
clean
50000
unkown image
page readonly
clean
7330000
unkown
page read and write
clean
440000
unkown
page read and write
clean
4D90000
unkown
page read and write
clean
3540000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
41D0000
unkown
page read and write
clean
3F50000
unkown
page read and write
clean
316F000
stack
page read and write
clean
2087000
unkown image
page readonly
clean
153000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
484B000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
6E86B000
unkown image
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7290000
unkown
page read and write
clean
59B9000
unkown
page read and write
clean
7F2C000
unkown
page read and write
clean
41BB000
unkown
page read and write
clean
160000
unkown image
page readonly
clean
1EA0000
unkown image
page readonly
clean
4190000
unkown
page read and write
clean
450000
unkown
page read and write
clean
7B30000
stack
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7EF8000
unkown
page read and write
clean
3C0000
unkown
page read and write
clean
7EAA000
stack
page read and write
clean
134000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
4ED7000
unkown
page read and write
clean
670000
heap default
page read and write
clean
2B4000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
3EF0000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
76D0000
unkown
page read and write
clean
6E48B000
unkown image
page read and write
clean
7B95000
stack
page read and write
clean
2020000
unkown
page read and write
clean
7290000
unkown
page read and write
clean
76D0000
unkown
page read and write
clean
4EF8000
unkown
page read and write
clean
59B9000
unkown
page read and write
clean
6B80000
unkown
page read and write
clean
3180000
unkown
page read and write
clean
41D000
heap default
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7290000
unkown
page read and write
clean
320000
unkown
page read and write
clean
3466000
unkown
page read and write
clean
3F88000
unkown
page read and write
clean
7B30000
stack
page read and write
clean
7B30000
stack
page read and write
clean
51C000
heap default
page read and write
clean
4310000
unkown image
page readonly
clean
72F9000
unkown
page read and write
clean
55B0000
heap private
page read and write
clean
3060000
unkown
page read and write
clean
2B6000
unkown
page read and write
clean
7300000
unkown
page read and write
clean
75D0000
heap private
page read and write
clean
2050000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
144000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
3430000
unkown
page read and write
clean
328E000
stack
page read and write
clean
3F58000
unkown
page read and write
clean
58BA000
stack
page read and write
clean
75A0000
unkown image
page read and write
clean
79A1000
unkown
page read and write
clean
7B30000
stack
page read and write
clean
78B0000
unkown
page read and write
clean
7380000
unkown
page read and write
clean
81F5000
unkown
page read and write
clean
72AB000
unkown
page read and write
clean
798D000
unkown
page read and write
clean
6CC0000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
800000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
76E0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
3F20000
unkown
page read and write
clean
72C4000
unkown
page read and write
clean
41F7000
unkown
page read and write
clean
755F000
unkown image
page readonly
clean
6A7000
heap default
page read and write
clean
7EFD0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
796C000
unkown
page read and write
clean
710000
unkown image
page readonly
clean
6CD0000
heap private
page read and write
clean
737F000
unkown
page read and write
clean
7390000
unkown image
page readonly
clean
7880000
unkown
page read and write
clean
72A0000
unkown
page read and write
clean
8F0000
unkown image
page readonly
clean
5590000
unkown
page read and write
clean
6C20000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
3FB0000
unkown
page read and write
clean
3F30000
unkown
page read and write
clean
2FAF000
stack
page read and write
clean
6E48B000
unkown image
page read and write
clean
140000
unkown
page read and write
clean
3E0000
heap default
page read and write
clean
3290000
unkown
page read and write
clean
7700000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
76D0000
unkown
page read and write
clean
7FEFF1A0000
unkown
page execute read
clean
32C0000
unkown
page read and write
clean
41A0000
unkown
page read and write
clean
30000
unkown image
page read and write
clean
3410000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
771A000
unkown
page read and write
clean
4AC0000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
7940000
unkown
page read and write
clean
7400000
heap private
page read and write
clean
78B6000
unkown
page read and write
clean
580000
unkown image
page readonly
clean
7B30000
stack
page read and write
clean
330000
heap private
page read and write
clean
414000
heap private
page read and write
clean
41BD000
unkown
page read and write
clean
76D0000
unkown
page read and write
clean
72ED000
unkown
page read and write
clean
7CC0000
heap private
page read and write
clean
7340000
unkown
page read and write
clean
6E441000
unkown image
page execute read
clean
577E000
stack
page read and write
clean
7B30000
stack
page read and write
clean
7290000
unkown
page read and write
clean
76D2000
unkown
page read and write
clean
76D0000
unkown
page read and write
clean
7B30000
stack
page read and write
clean
4110000
heap private
page execute and read and write
clean
5670000
unkown
page read and write
clean
2420000
heap private
page read and write
clean
20A0000
heap private
page read and write
clean
342B000
unkown
page read and write
clean
3F90000
unkown
page read and write
clean
76D0000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
4EF8000
unkown
page read and write
clean
8A0000
unkown image
page readonly
clean
2E0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
6CCA000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
54F0000
unkown
page read and write
clean
6AF0000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
59B1000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
130000
unkown
page read and write
clean
75B0000
unkown image
page read and write
clean
41B0000
unkown
page read and write
clean
58DF000
unkown
page read and write
clean
4EF5000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7886000
unkown
page read and write
clean
4E0000
unkown image
page readonly
clean
3A0000
unkown image
page readonly
clean
11D000
unkown
page read and write
clean
430F000
stack
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
6E874000
unkown image
page read and write
clean
7320000
unkown
page read and write
clean
3550000
heap private
page read and write
clean
7BAC000
stack
page read and write
clean
599A000
unkown
page read and write
clean
7B50000
stack
page read and write
clean
370000
heap private
page read and write
clean
54F0000
unkown
page read and write
clean
1DAE000
unkown
page read and write
clean
550C000
unkown
page read and write
clean
B0000
unkown image
page readonly
clean
75C0000
unkown
page read and write
clean
7BAC000
stack
page read and write
clean
455000
unkown
page read and write
clean
4700000
unkown
page read and write
clean
940000
heap private
page read and write
clean
7320000
unkown
page read and write
clean
6E90000
unkown
page read and write
clean
76D2000
unkown
page read and write
clean
730B000
unkown
page read and write
clean
3E7000
heap default
page read and write
clean
3DD3000
unkown
page read and write
clean
5A03000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
8232000
unkown
page read and write
clean
477000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
3E0000
unkown
page read and write
clean
161000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7BAC000
stack
page read and write
clean
420000
unkown
page read and write
clean
7295000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
3050000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
7716000
unkown
page read and write
clean
58C8000
unkown
page read and write
clean
6B90000
heap private
page read and write
clean
5660000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
600000
heap private
page read and write
clean
210000
unkown
page read and write
clean
6C2A000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
2044000
unkown
page read and write
clean
72A0000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
5177000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7ED0000
unkown
page read and write
clean
6E87C000
unkown image
page read and write
clean
7EFD0000
unkown image
page readonly
clean
4A2F000
stack
page read and write
clean
20000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
6B00000
heap private
page read and write
clean
40D0000
unkown
page read and write
clean
7350000
unkown
page read and write
clean
73F3000
unkown
page read and write
clean
41A8000
unkown
page read and write
clean
143000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
2ED000
unkown
page read and write
clean
300000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
73B4000
unkown
page read and write
clean
54A0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7550000
unkown image
page readonly
clean
41B9000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
677000
heap default
page read and write
clean
4200000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
7290000
unkown
page read and write
clean
72D0000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
3170000
unkown
page read and write
clean
2087000
unkown image
page readonly
clean
310000
unkown
page read and write
clean
6CBE000
unkown
page read and write
clean
7890000
unkown
page read and write
clean
1DBE000
unkown
page read and write
clean
7730000
heap private
page read and write
clean
375000
heap private
page read and write
clean
72A0000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
59B9000
unkown
page read and write
clean
7B30000
stack
page read and write
clean
41B2000
unkown
page read and write
clean
7EE5000
unkown
page read and write
clean
1E7000
heap default
page read and write
clean
6C27000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
4EF1000
unkown
page read and write
clean
598A000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
54D000
heap default
page read and write
clean
7F70000
unkown
page read and write
clean
65300000
unkown image
page readonly
clean
41B5000
unkown
page read and write
clean
6E479000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
3D0000
unkown
page read and write
clean
7290000
unkown
page read and write
clean
7F22000
unkown
page read and write
clean
7B50000
stack
page read and write
clean
7404000
heap private
page read and write
clean
342C000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
72B0000
unkown
page read and write
clean
153000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
4EDF000
unkown
page read and write
clean
3400000
unkown image
page read and write
clean
4F07000
unkown
page read and write
clean
58C0000
unkown
page read and write
clean
59B1000
unkown
page read and write
clean
6E440000
unkown image
page readonly
clean
32B0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
6C30000
heap private
page read and write
clean
3420000
heap private
page read and write
clean
There are 615 hidden memdumps, click here to show them.