IOC Report
Payslip_APR_2022.doc

loading gif

Files

File Path
Type
Category
Malicious
Payslip_APR_2022.doc
data
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\jnstp[1].exe
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
downloaded
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{E418C216-F903-4F08-9D65-89DE9868688C}.tmp
Composite Document File V2 Document, Cannot read section info
dropped
malicious
C:\Users\user\AppData\Local\Temp\jqenyeo.exe
PE32 executable (console) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\run.dat
ISO-8859 text, with no line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\dll.exe
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
dropped
malicious
C:\Users\user\AppData\Roaming\mtmgxghqo\ltqmdmdi.exe
PE32 executable (console) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{70D846B3-DCAC-4A39-983B-1268AFAC60AA}.tmp
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{BD369796-5E3E-4B27-9B02-9FE798ADC5FC}.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\hjmxlwxk
data
dropped
C:\Users\user\AppData\Local\Temp\lcjspmd3kk4i8bc40b
data
dropped
C:\Users\user\AppData\Local\Temp\nsb484E.tmp
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Payslip_APR_2022.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Tue Mar 8 15:45:53 2022, mtime=Tue Mar 8 15:45:53 2022, atime=Tue May 17 04:07:13 2022, length=4697, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
dropped
C:\Users\user\Desktop\~$yslip_APR_2022.doc
data
dropped
There are 6 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
"C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
malicious
C:\Users\user\AppData\Roaming\dll.exe
C:\Users\user\AppData\Roaming\dll.exe
malicious
C:\Users\user\AppData\Local\Temp\jqenyeo.exe
C:\Users\user\AppData\Local\Temp\jqenyeo.exe C:\Users\user\AppData\Local\Temp\hjmxlwxk
malicious
C:\Users\user\AppData\Local\Temp\jqenyeo.exe
C:\Users\user\AppData\Local\Temp\jqenyeo.exe C:\Users\user\AppData\Local\Temp\hjmxlwxk
malicious
C:\Users\user\AppData\Roaming\mtmgxghqo\ltqmdmdi.exe
"C:\Users\user\AppData\Roaming\mtmgxghqo\ltqmdmdi.exe"
malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /Automation -Embedding

URLs

Name
IP
Malicious
http://lutanedukasi.co.id/wp-includes/jnstp.exej
unknown
malicious
http://lutanedukasi.co.id/wp-includes/jnstp.exe
43.245.183.172
malicious
http://lutanedukasi.co.id/wp-includes/jnstp.exejjC:
unknown
malicious
http://lutanedukasi.co.id/wp-includes/jnstp.exeC:
unknown
malicious
http://lutanedukasi.co.id/wp-includes/jnstp.exeT
unknown
malicious
stonecold.ddns.net
malicious
http://nsis.sf.net/NSIS_ErrorError
unknown

Domains

Name
IP
Malicious
lutanedukasi.co.id
43.245.183.172
malicious
stonecold.ddns.net
45.132.226.1
malicious

IPs

IP
Domain
Country
Malicious
45.132.226.1
stonecold.ddns.net
Netherlands
malicious
43.245.183.172
lutanedukasi.co.id
Indonesia
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
&:)
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
};)
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
,>)
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\67DC7
67DC7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Batang
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Dotum
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@FangSong
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gulim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@NSimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Agency FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aharoni
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Algerian
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Andalus
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Angsana New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
AngsanaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aparajita
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arabic Typesetting
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Narrow
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Rounded MT Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Baskerville Old Face
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Batang
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bauhaus 93
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bell MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB Demi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bernard MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Blackadder ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Poster Compressed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Book Antiqua
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookman Old Style
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookshelf Symbol 7
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bradley Hand ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Britannic Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Broadway
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Browallia New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BrowalliaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Brush Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Californian FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calisto MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria Math
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Candara
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Castellar
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Centaur
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Schoolbook
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Chiller
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Colonna MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Comic Sans MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Consolas
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Constantia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cooper Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Corbel
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cordia New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
CordiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Courier New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Curlz MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DaunPenh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
David
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DilleniaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DokChampa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Dotum
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ebrima
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Edwardian Script ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Elephant
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Engravers MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Bold ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Demi ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Light ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Medium ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Estrangelo Edessa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
EucrosiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Euphemia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FangSong
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Felix Titling
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Footlight MT Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Forte
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Book
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi Cond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Heavy
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium Cond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FrankRuehl
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FreesiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Freestyle Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
French Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gabriola
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Garamond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gautami
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Georgia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gigi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Ext Condensed Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gisha
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gloucester MT Extra Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Old Style
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Stout
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gulim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Haettenschweiler
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harlow Solid Italic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harrington
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
High Tower Text
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Impact
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Imprint MT Shadow
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Informal Roman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
IrisUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Iskoola Pota
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
JasmineUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Jokerman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Juice ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kalinga
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kartika
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Khmer UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KodchiangUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kokila
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kristen ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kunstler Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lao UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Latha
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Leelawadee
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Levenim MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
LilyUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Bright
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Calligraphy
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Console
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Fax
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Handwriting
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Typewriter
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Unicode
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Magneto
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Maiandra GD
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mangal
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Marlett
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Matura MT Script Capitals
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Himalaya
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft New Tai Lue
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft PhagsPa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Tai Le
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Uighur
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Yi Baiti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam Fixed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mistral
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Modern No. 20
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mongolian Baiti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Monotype Corsiva
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MoolBoran
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Outlook
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Specialty
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MT Extra
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MV Boli
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Narkisim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Engraved
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Solid
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
NSimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Nyala
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
OCR A Extended
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Old English Text MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Onyx
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palace Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palatino Linotype
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Papyrus
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Parchment
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua Titling MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Plantagenet Cherokee
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Playbill
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Poor Richard
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Pristina
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Raavi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rage Italic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ravie
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Extra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rod
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sakkal Majalla
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Script MT Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Print
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Semibold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Symbol
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shonar Bangla
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Showcard Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shruti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic Fixed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Snap ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Stencil
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sylfaen
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Symbol
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tahoma
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tempus Sans ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Times New Roman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Traditional Arabic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Trebuchet MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tunga
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed Extra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Utsaah
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vani
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Verdana
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vijaya
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Viner Hand ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vivaldi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vladimir Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vrinda
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Webdings
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wide Latin
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 2
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 3
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\70DF5
70DF5
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Security\Trusted Documents
LastPurgeTime
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
WORDFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\70DF5
70DF5
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Data
Settings
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Options
ZoomApp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTF
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
EquationEditorFilesIntl_1033
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
wboyuqknqhxiar
There are 314 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
400000
remote allocation
page execute and read and write
malicious
32E9000
trusted library allocation
page read and write
malicious
414000
remote allocation
page execute and read and write
malicious
414000
remote allocation
page execute and read and write
malicious
4AE0000
trusted library section
page read and write
malicious
550000
trusted library section
page read and write
malicious
330000
direct allocation
page read and write
malicious
2271000
trusted library allocation
page read and write
malicious
5ED000
heap
page read and write
malicious
1ED2000
direct allocation
page execute and read and write
malicious
32C0000
direct allocation
page read and write
250000
heap
page read and write
400000
unkown
page readonly
273D000
direct allocation
page read and write
562E000
stack
page read and write
43C5000
trusted library allocation
page read and write
2240000
heap
page read and write
34A1000
trusted library allocation
page read and write
3401000
trusted library allocation
page read and write
34A1000
trusted library allocation
page read and write
2261000
heap
page read and write
3541000
trusted library allocation
page read and write
324000
heap
page read and write
27000
heap
page read and write
5400000
trusted library allocation
page read and write
3481000
trusted library allocation
page read and write
43B000
unkown
page readonly
47A0000
trusted library allocation
page read and write
292000
trusted library allocation
page execute and read and write
4F2E000
stack
page read and write
43C0000
trusted library allocation
page read and write
400000
unkown
page readonly
2750000
trusted library allocation
page read and write
3541000
trusted library allocation
page read and write
20000
heap
page read and write
382E000
stack
page read and write
401000
unkown
page execute read
1E3F000
trusted library section
page readonly
14D000
stack
page read and write
34C000
heap
page read and write
3381000
trusted library allocation
page read and write
43C6000
trusted library allocation
page read and write
34A1000
trusted library allocation
page read and write
400000
unkown
page readonly
43D0000
trusted library allocation
page read and write
281F000
stack
page read and write
35A1000
trusted library allocation
page read and write
33A1000
trusted library allocation
page read and write
400000
unkown
page readonly
400000
remote allocation
page execute and read and write
3461000
trusted library allocation
page read and write
1EF2000
direct allocation
page execute and read and write
2C24000
heap
page read and write
10000
heap
page read and write
34C1000
trusted library allocation
page read and write
5B6000
heap
page read and write
3342000
trusted library allocation
page read and write
458000
trusted library allocation
page read and write
35AD000
trusted library allocation
page read and write
43C0000
trusted library allocation
page read and write
47C5000
trusted library allocation
page read and write
32E0000
direct allocation
page read and write
32D7000
direct allocation
page read and write
18C000
stack
page read and write
33C1000
trusted library allocation
page read and write
3421000
trusted library allocation
page read and write
3541000
trusted library allocation
page read and write
3361000
trusted library allocation
page read and write
3401000
trusted library allocation
page read and write
32D7000
direct allocation
page read and write
499F000
stack
page read and write
401000
unkown
page execute read
5560000
trusted library allocation
page read and write
43C6000
trusted library allocation
page read and write
3441000
trusted library allocation
page read and write
401000
unkown
page execute read
342000
heap
page read and write
3401000
trusted library allocation
page read and write
662000
heap
page read and write
3581000
trusted library allocation
page read and write
4AF0000
trusted library allocation
page read and write
43C0000
trusted library allocation
page read and write
2660000
direct allocation
page read and write
32C0000
direct allocation
page read and write
34A1000
trusted library allocation
page read and write
273A000
direct allocation
page read and write
5C4000
heap
page read and write
34C1000
trusted library allocation
page read and write
374000
heap
page read and write
273A000
direct allocation
page read and write
3342000
trusted library allocation
page read and write
413000
unkown
page write copy
33E1000
trusted library allocation
page read and write
33C1000
trusted library allocation
page read and write
32E0000
direct allocation
page read and write
52EE000
stack
page read and write
3481000
trusted library allocation
page read and write
35A1000
trusted library allocation
page read and write
5630000
trusted library allocation
page read and write
3342000
trusted library allocation
page read and write
3E4000
heap
page read and write
3342000
trusted library allocation
page read and write
3581000
trusted library allocation
page read and write
1C7000
heap
page read and write
4EF0000
trusted library allocation
page read and write
3401000
trusted library allocation
page read and write
3340000
direct allocation
page read and write
29C000
trusted library allocation
page execute and read and write
56FE000
stack
page read and write
5680000
heap
page read and write
43B000
unkown
page readonly
3C1E000
stack
page read and write
33C1000
trusted library allocation
page read and write
3461000
trusted library allocation
page read and write
3342000
trusted library allocation
page read and write
244F000
stack
page read and write
3421000
trusted library allocation
page read and write
590000
trusted library allocation
page read and write
47F4000
heap
page execute and read and write
18D000
stack
page read and write
47C0000
trusted library section
page read and write
3521000
trusted library allocation
page read and write
2BDE000
stack
page read and write
3521000
trusted library allocation
page read and write
5B6F000
stack
page read and write
186000
stack
page read and write | page guard
1F30000
trusted library allocation
page read and write
273D000
direct allocation
page read and write
600000
heap
page read and write
400000
remote allocation
page execute and read and write
43C0000
trusted library allocation
page read and write
3481000
trusted library allocation
page read and write
40E000
unkown
page readonly
400000
remote allocation
page execute and read and write
3381000
trusted library allocation
page read and write
34A1000
trusted library allocation
page read and write
3521000
trusted library allocation
page read and write
273D000
direct allocation
page read and write
234F000
stack
page read and write
502F000
stack
page read and write
3501000
trusted library allocation
page read and write
3381000
trusted library allocation
page read and write
43C6000
trusted library allocation
page read and write
400000
unkown
page readonly
39DE000
stack
page read and write
378D000
stack
page read and write
3561000
trusted library allocation
page read and write
322000
heap
page read and write
400000
unkown
page readonly
A8F000
stack
page read and write
3B1E000
stack
page read and write
47C0000
trusted library allocation
page read and write
5C6F000
stack
page read and write
392F000
stack
page read and write
18A000
stack
page read and write
413000
unkown
page write copy
3381000
trusted library allocation
page read and write
437000
unkown
page read and write
3421000
trusted library allocation
page read and write
32C0000
direct allocation
page read and write
3421000
trusted library allocation
page read and write
3561000
trusted library allocation
page read and write
3421000
trusted library allocation
page read and write
3342000
trusted library allocation
page read and write
34E1000
trusted library allocation
page read and write
3521000
trusted library allocation
page read and write
3401000
trusted library allocation
page read and write
33E1000
trusted library allocation
page read and write
32D7000
direct allocation
page read and write
1B0000
heap
page read and write
413000
unkown
page write copy
334000
heap
page read and write
1E2E000
stack
page read and write
2660000
direct allocation
page read and write
34A1000
trusted library allocation
page read and write
34C1000
trusted library allocation
page read and write
401000
unkown
page execute read
43C0000
trusted library allocation
page read and write
425000
unkown
page read and write
3521000
trusted library allocation
page read and write
34A1000
trusted library allocation
page read and write
43D0000
trusted library allocation
page read and write
24DB000
trusted library allocation
page read and write
2244000
heap
page read and write
43C7000
trusted library allocation
page read and write
32D1000
direct allocation
page read and write
40E000
unkown
page readonly
3401000
trusted library allocation
page read and write
290000
trusted library allocation
page read and write
3461000
trusted library allocation
page read and write
32C9000
trusted library allocation
page read and write
47C7000
trusted library allocation
page read and write
31D0000
direct allocation
page read and write
31D0000
direct allocation
page read and write
3481000
trusted library allocation
page read and write
324000
heap
page read and write
47C0000
trusted library allocation
page read and write
40E000
unkown
page readonly
250000
trusted library allocation
page read and write
32D4000
direct allocation
page read and write
270000
trusted library allocation
page read and write
33C1000
trusted library allocation
page read and write
400000
unkown
page readonly
544000
heap
page read and write
43C0000
trusted library allocation
page read and write
31E0000
direct allocation
page read and write
43C6000
trusted library allocation
page read and write
463E000
stack
page read and write
3461000
trusted library allocation
page read and write
400000
remote allocation
page execute and read and write
26A000
trusted library allocation
page execute and read and write
1ED0000
direct allocation
page execute and read and write
33E1000
trusted library allocation
page read and write
40A000
unkown
page read and write
34A1000
trusted library allocation
page read and write
33A1000
trusted library allocation
page read and write
43E0000
heap
page read and write
40A000
unkown
page write copy
33A1000
trusted library allocation
page read and write
34C1000
trusted library allocation
page read and write
40A000
unkown
page write copy
3421000
trusted library allocation
page read and write
35C1000
trusted library allocation
page read and write
286000
trusted library allocation
page execute and read and write
40E000
unkown
page readonly
1FD000
heap
page read and write
34A1000
trusted library allocation
page read and write
273A000
direct allocation
page read and write
35C1000
trusted library allocation
page read and write
3521000
trusted library allocation
page read and write
3541000
trusted library allocation
page read and write
24B2000
trusted library allocation
page read and write
2A7000
trusted library allocation
page execute and read and write
273D000
direct allocation
page read and write
43C0000
trusted library allocation
page read and write
2251000
heap
page read and write
2F8000
heap
page read and write
35A1000
trusted library allocation
page read and write
47A7000
trusted library allocation
page read and write
3441000
trusted library allocation
page read and write
624000
heap
page read and write
43C6000
trusted library allocation
page read and write
32D4000
direct allocation
page read and write
3340000
direct allocation
page read and write
3501000
trusted library allocation
page read and write
408000
unkown
page readonly
1C80000
heap
page read and write
31D0000
direct allocation
page read and write
34E1000
trusted library allocation
page read and write
47C6000
trusted library allocation
page read and write
408000
unkown
page readonly
5B0000
heap
page read and write
400000
unkown
page readonly
3342000
trusted library allocation
page read and write
2230000
heap
page read and write
33E1000
trusted library allocation
page read and write
29A000
trusted library allocation
page execute and read and write
187000
stack
page read and write
401000
unkown
page execute read
43C7000
trusted library allocation
page read and write
8D000
stack
page read and write
3340000
direct allocation
page read and write
33E1000
trusted library allocation
page read and write
33A1000
trusted library allocation
page read and write
400000
unkown
page readonly
2A0000
heap
page read and write
2BE0000
heap
page read and write
3581000
trusted library allocation
page read and write
334000
heap
page read and write
40E000
unkown
page readonly
2660000
direct allocation
page read and write
3501000
trusted library allocation
page read and write
3441000
trusted library allocation
page read and write
270000
trusted library allocation
page read and write
3340000
direct allocation
page read and write
43C0000
trusted library allocation
page read and write
47C5000
trusted library allocation
page read and write
47C0000
trusted library allocation
page read and write
271F000
stack
page read and write
34E1000
trusted library allocation
page read and write
380000
direct allocation
page read and write
1F30000
trusted library allocation
page read and write
33A1000
trusted library allocation
page read and write
401000
unkown
page execute read
3561000
trusted library allocation
page read and write
35C1000
trusted library allocation
page read and write
273D000
direct allocation
page read and write
3361000
trusted library allocation
page read and write
2A7000
heap
page read and write
3461000
trusted library allocation
page read and write
2B0000
heap
page read and write
3C5C000
stack
page read and write
32E0000
direct allocation
page read and write
3541000
trusted library allocation
page read and write
43C0000
trusted library allocation
page read and write
43C0000
trusted library allocation
page read and write
291F000
stack
page read and write
550000
heap
page read and write
5560000
trusted library allocation
page read and write
2F6000
heap
page read and write
2C28000
heap
page read and write
35A1000
trusted library allocation
page read and write
34A1000
trusted library allocation
page read and write
607000
heap
page read and write
3501000
trusted library allocation
page read and write
35A1000
trusted library allocation
page read and write
40E000
unkown
page readonly
5568000
trusted library allocation
page read and write
3541000
trusted library allocation
page read and write
413000
unkown
page write copy
3581000
trusted library allocation
page read and write
3481000
trusted library allocation
page read and write
18C000
stack
page read and write
3DF000
stack
page read and write
261E000
stack
page read and write
3E0000
heap
page read and write
2C2B000
heap
page read and write
40A000
unkown
page write copy
400000
unkown
page readonly
3461000
trusted library allocation
page read and write
3401000
trusted library allocation
page read and write
47C8000
trusted library allocation
page read and write
32D4000
direct allocation
page read and write
2FA000
heap
page read and write
34E1000
trusted library allocation
page read and write
3D9C000
stack
page read and write
2A2000
trusted library allocation
page read and write
40A000
unkown
page write copy
654000
heap
page read and write
3381000
trusted library allocation
page read and write
3361000
trusted library allocation
page read and write
33E1000
trusted library allocation
page read and write
230000
trusted library section
page read and write
32D7000
direct allocation
page read and write
273A000
direct allocation
page read and write
3340000
direct allocation
page read and write
240000
trusted library section
page read and write
3F50000
heap
page read and write
32D7000
direct allocation
page read and write
33C1000
trusted library allocation
page read and write
650000
heap
page read and write
33A1000
trusted library allocation
page read and write
40E000
unkown
page readonly
3401000
trusted library allocation
page read and write
31E0000
direct allocation
page read and write
300000
heap
page read and write
40E000
unkown
page readonly
7EFE0000
unkown
page readonly
3461000
trusted library allocation
page read and write
1C84000
heap
page read and write
3501000
trusted library allocation
page read and write
31D0000
direct allocation
page read and write
2CF000
heap
page read and write
273A000
direct allocation
page read and write
262000
trusted library allocation
page execute and read and write
32D4000
direct allocation
page read and write
4ADD000
stack
page read and write
43C0000
trusted library allocation
page read and write
2C0000
heap
page execute and read and write
35E1000
trusted library allocation
page read and write
3340000
direct allocation
page read and write
400000
unkown
page readonly
31E0000
direct allocation
page read and write
5570000
heap
page read and write
3590000
trusted library allocation
page read and write
31E0000
direct allocation
page read and write
34E1000
trusted library allocation
page read and write
2660000
direct allocation
page read and write
1F30000
trusted library allocation
page read and write
47D7000
heap
page execute and read and write
5DAE000
stack
page read and write
3581000
trusted library allocation
page read and write
240000
heap
page read and write
43C0000
trusted library allocation
page read and write
413000
unkown
page write copy
489E000
stack
page read and write
33E1000
trusted library allocation
page read and write
31D0000
direct allocation
page read and write
5770000
trusted library allocation
page read and write
43D0000
trusted library allocation
page read and write
2F4000
heap
page read and write
3561000
trusted library allocation
page read and write
401000
unkown
page execute read
3361000
trusted library allocation
page read and write
32C0000
direct allocation
page read and write
40A000
unkown
page write copy
401000
unkown
page execute read
206000
heap
page read and write
4610000
trusted library allocation
page read and write
3421000
trusted library allocation
page read and write
47C0000
unkown
page read and write
43C0000
trusted library allocation
page read and write
3481000
trusted library allocation
page read and write
35A1000
trusted library allocation
page read and write
3521000
trusted library allocation
page read and write
1F30000
trusted library allocation
page read and write
3361000
trusted library allocation
page read and write
380000
heap
page read and write
2660000
direct allocation
page read and write
3541000
trusted library allocation
page read and write
273A000
direct allocation
page read and write
43C0000
trusted library allocation
page read and write
516B000
stack
page read and write
3441000
trusted library allocation
page read and write
33E1000
trusted library allocation
page read and write
3442000
trusted library allocation
page read and write
30E000
heap
page read and write
32D4000
direct allocation
page read and write
32E0000
direct allocation
page read and write
3293000
trusted library allocation
page read and write
413000
unkown
page write copy
34C000
heap
page read and write
3341000
trusted library allocation
page read and write
43C5000
trusted library allocation
page read and write
2751000
trusted library allocation
page read and write
3481000
trusted library allocation
page read and write
1C0000
heap
page read and write
3381000
trusted library allocation
page read and write
1CA2000
heap
page read and write
52AF000
stack
page read and write
32D1000
direct allocation
page read and write
3401000
trusted library allocation
page read and write
34C000
heap
page read and write
31E0000
direct allocation
page read and write
8D000
stack
page read and write
408000
unkown
page readonly
24F6000
trusted library allocation
page read and write
401000
unkown
page execute read
32D1000
direct allocation
page read and write
400000
unkown
page readonly
43C0000
trusted library allocation
page read and write
3461000
trusted library allocation
page read and write
31D0000
direct allocation
page read and write
3582000
trusted library allocation
page read and write
47C0000
trusted library allocation
page read and write
53EE000
stack
page read and write
43C5000
trusted library allocation
page read and write
40E000
unkown
page readonly
2660000
direct allocation
page read and write
43C0000
trusted library allocation
page read and write
562000
heap
page read and write
3461000
trusted library allocation
page read and write
34E1000
trusted library allocation
page read and write
3481000
trusted library allocation
page read and write
32D4000
direct allocation
page read and write
34A1000
trusted library allocation
page read and write
273D000
direct allocation
page read and write
32D7000
direct allocation
page read and write
3581000
trusted library allocation
page read and write
45FE000
stack
page read and write
273D000
direct allocation
page read and write
2920000
trusted library allocation
page read and write
5A7000
heap
page read and write
506C000
stack
page read and write
43C0000
trusted library allocation
page read and write
4AE0000
trusted library allocation
page read and write
1F20000
trusted library allocation
page read and write
47C0000
trusted library allocation
page read and write
34C1000
trusted library allocation
page read and write
3361000
trusted library allocation
page read and write
1F60000
trusted library allocation
page read and write
400000
remote allocation
page execute and read and write
43C0000
trusted library allocation
page read and write
3581000
trusted library allocation
page read and write
40C000
unkown
page read and write
545F000
stack
page read and write
3561000
trusted library allocation
page read and write
33A1000
trusted library allocation
page read and write
3561000
trusted library allocation
page read and write
3501000
trusted library allocation
page read and write
3271000
trusted library allocation
page read and write
566E000
stack
page read and write
401000
unkown
page execute read
3960000
heap
page read and write
578D000
trusted library allocation
page read and write
373000
unkown
page read and write
1F35000
trusted library allocation
page read and write
3561000
trusted library allocation
page read and write
473C000
stack
page read and write
2411000
trusted library allocation
page read and write
43AC000
stack
page read and write
3441000
trusted library allocation
page read and write
3541000
trusted library allocation
page read and write
500000
heap
page execute and read and write
34C1000
trusted library allocation
page read and write
33E1000
trusted library allocation
page read and write
1530000
heap
page read and write
3481000
trusted library allocation
page read and write
237000
heap
page read and write
32C0000
direct allocation
page read and write
5FE000
stack
page read and write
3461000
trusted library allocation
page read and write
32C0000
direct allocation
page read and write
3441000
trusted library allocation
page read and write
837000
heap
page read and write
33E1000
trusted library allocation
page read and write
49DC000
stack
page read and write
32D1000
direct allocation
page read and write
32C0000
direct allocation
page read and write
254000
heap
page read and write
2810000
heap
page read and write
34E1000
trusted library allocation
page read and write
5CAC000
stack
page read and write
43C0000
trusted library allocation
page read and write
35D4000
trusted library allocation
page read and write
51AF000
stack
page read and write
20000
heap
page read and write
401000
unkown
page execute read
555F000
stack
page read and write
35A1000
trusted library allocation
page read and write
31E0000
direct allocation
page read and write
3361000
trusted library allocation
page read and write
1F50000
trusted library allocation
page execute and read and write
31E0000
direct allocation
page read and write
43B000
unkown
page readonly
436F000
stack
page read and write
32D1000
direct allocation
page read and write
1F30000
trusted library allocation
page read and write
3E9C000
stack
page read and write
43C0000
trusted library allocation
page read and write
47C0000
trusted library allocation
page read and write
3ADF000
stack
page read and write
3561000
trusted library allocation
page read and write
1ECF000
stack
page read and write
3421000
trusted library allocation
page read and write
47B0000
trusted library section
page read and write
43D0000
trusted library allocation
page read and write
43C0000
trusted library allocation
page read and write
35A1000
trusted library allocation
page read and write
3441000
trusted library allocation
page read and write
5730000
heap
page read and write
30D000
heap
page read and write
89000
stack
page read and write
596F000
stack
page read and write
33C1000
trusted library allocation
page read and write
2AB000
trusted library allocation
page execute and read and write
32E0000
direct allocation
page read and write
3461000
trusted library allocation
page read and write
34C1000
trusted library allocation
page read and write
1C5E000
stack
page read and write
43D0000
trusted library allocation
page read and write
43E4000
heap
page read and write
32E0000
direct allocation
page read and write
3461000
trusted library allocation
page read and write
35E1000
trusted library allocation
page read and write
35C1000
trusted library allocation
page read and write
2750000
trusted library allocation
page read and write
35C1000
trusted library allocation
page read and write
32D7000
direct allocation
page read and write
408000
unkown
page readonly
343000
heap
page read and write
34E1000
trusted library allocation
page read and write
34E1000
trusted library allocation
page read and write
1F0000
heap
page read and write
67C000
heap
page read and write
27C000
trusted library allocation
page execute and read and write
1E40000
heap
page read and write
34C1000
trusted library allocation
page read and write
3521000
trusted library allocation
page read and write
10000
heap
page read and write
34E1000
trusted library allocation
page read and write
10000
heap
page read and write
31E0000
direct allocation
page read and write
3541000
trusted library allocation
page read and write
3481000
trusted library allocation
page read and write
35A1000
trusted library allocation
page read and write
400000
unkown
page readonly
35C1000
trusted library allocation
page read and write
540000
heap
page read and write
2C20000
heap
page read and write
3342000
trusted library allocation
page read and write
32E0000
direct allocation
page read and write
3361000
trusted library allocation
page read and write
260000
direct allocation
page execute and read and write
3340000
direct allocation
page read and write
3421000
trusted library allocation
page read and write
8B000
stack
page read and write
3441000
trusted library allocation
page read and write
47C0000
trusted library allocation
page read and write
3442000
trusted library allocation
page read and write
413000
unkown
page read and write
1F90000
heap
page read and write
47C0000
trusted library allocation
page read and write
47C0000
trusted library allocation
page read and write
210000
heap
page read and write
3501000
trusted library allocation
page read and write
830000
heap
page read and write
33C1000
trusted library allocation
page read and write
3342000
trusted library allocation
page read and write
43B000
unkown
page readonly
3521000
trusted library allocation
page read and write
32D4000
direct allocation
page read and write
3581000
trusted library allocation
page read and write
43B000
unkown
page readonly
401000
unkown
page execute read
47D0000
heap
page execute and read and write
34C1000
trusted library allocation
page read and write
7EF50000
trusted library allocation
page execute and read and write
3521000
trusted library allocation
page read and write
10000
heap
page read and write
4402000
heap
page read and write
33C1000
trusted library allocation
page read and write
400000
remote allocation
page execute and read and write
35A1000
trusted library allocation
page read and write
3501000
trusted library allocation
page read and write
1CFD000
stack
page read and write
32D1000
direct allocation
page read and write
43B0000
trusted library allocation
page execute and read and write
272000
trusted library allocation
page execute and read and write
43C0000
trusted library allocation
page read and write
32C0000
direct allocation
page read and write
34C1000
trusted library allocation
page read and write
10000
heap
page read and write
273A000
direct allocation
page read and write
35CF000
trusted library allocation
page read and write
8B000
stack
page read and write
28A000
trusted library allocation
page execute and read and write
55EF000
stack
page read and write
35BF000
trusted library allocation
page read and write
1F40000
heap
page read and write
2F90000
heap
page read and write
3421000
trusted library allocation
page read and write
408000
unkown
page readonly
48A000
stack
page read and write
401000
unkown
page execute read
427000
unkown
page read and write
34C1000
trusted library allocation
page read and write
43C0000
trusted library allocation
page read and write
3521000
trusted library allocation
page read and write
408000
unkown
page readonly
3401000
trusted library allocation
page read and write
33A1000
trusted library allocation
page read and write
47C0000
trusted library allocation
page read and write
43C0000
trusted library allocation
page read and write
1E50000
direct allocation
page read and write
25DF000
stack
page read and write
34E000
heap
page read and write
2750000
trusted library allocation
page read and write
3340000
direct allocation
page read and write
3BE000
stack
page read and write
540000
trusted library allocation
page read and write
34A1000
trusted library allocation
page read and write
35A1000
trusted library allocation
page read and write
1E34000
trusted library section
page readonly
3D5D000
stack
page read and write
43B000
unkown
page readonly
3501000
trusted library allocation
page read and write
2C0000
heap
page read and write
43C6000
trusted library allocation
page read and write
3FE000
stack
page read and write
5A6F000
stack
page read and write
5A0000
heap
page read and write
34C1000
trusted library allocation
page read and write
32D4000
direct allocation
page read and write
33C2000
trusted library allocation
page read and write
31D0000
direct allocation
page read and write
32E0000
direct allocation
page read and write
273A000
direct allocation
page read and write
47C8000
trusted library allocation
page read and write
230000
heap
page read and write
3581000
trusted library allocation
page read and write
2C4000
heap
page read and write
43C0000
trusted library allocation
page read and write
3581000
trusted library allocation
page read and write
43D5000
trusted library allocation
page read and write
47C0000
trusted library allocation
page read and write
53F000
stack
page read and write
35A1000
trusted library allocation
page read and write
41C0000
heap
page read and write
35A1000
trusted library allocation
page read and write
33C1000
trusted library allocation
page read and write
3501000
trusted library allocation
page read and write
36D000
heap
page read and write
544000
heap
page read and write
43C6000
trusted library allocation
page read and write
3441000
trusted library allocation
page read and write
400000
unkown
page readonly
273D000
direct allocation
page read and write
4AE0000
trusted library allocation
page read and write
1E30000
trusted library section
page readonly
1D00000
heap
page read and write
3481000
trusted library allocation
page read and write
22F9000
trusted library allocation
page read and write
20000
heap
page read and write
53F1000
trusted library allocation
page read and write
3381000
trusted library allocation
page read and write
2660000
direct allocation
page read and write
34E1000
trusted library allocation
page read and write
32D1000
direct allocation
page read and write
33A1000
trusted library allocation
page read and write
3EDF000
stack
page read and write
35C1000
trusted library allocation
page read and write
405F000
stack
page read and write
3561000
trusted library allocation
page read and write
37B0000
heap
page read and write
3481000
trusted library allocation
page read and write
31D0000
direct allocation
page read and write
570000
heap
page read and write
4600000
trusted library allocation
page read and write
2B9D000
stack
page read and write
3581000
trusted library allocation
page read and write
43C0000
trusted library allocation
page read and write
43C0000
trusted library allocation
page read and write
2A9C000
stack
page read and write
32D7000
direct allocation
page read and write
3361000
trusted library allocation
page read and write
32D1000
direct allocation
page read and write
10000
heap
page read and write
43C0000
trusted library allocation
page read and write
2234000
heap
page read and write
43C0000
trusted library allocation
page read and write
520000
heap
page read and write
43D0000
trusted library allocation
page execute and read and write
401000
unkown
page execute read
413000
unkown
page read and write
43C0000
trusted library allocation
page read and write
43C0000
unkown
page read and write
4600000
trusted library allocation
page read and write
527000
heap
page read and write
400000
unkown
page readonly
3561000
trusted library allocation
page read and write
43D8000
trusted library allocation
page read and write
3541000
trusted library allocation
page read and write
1F30000
trusted library allocation
page read and write
43C0000
trusted library allocation
page read and write
43CC000
trusted library allocation
page read and write
34E000
heap
page read and write
413000
unkown
page write copy
2660000
direct allocation
page read and write
3441000
trusted library allocation
page read and write
34E000
heap
page read and write
401000
unkown
page execute read
43C4000
trusted library allocation
page read and write
3582000
trusted library allocation
page read and write
5410000
trusted library allocation
page read and write
3501000
trusted library allocation
page read and write
35C1000
trusted library allocation
page read and write
3381000
trusted library allocation
page read and write
3561000
trusted library allocation
page read and write
There are 729 hidden memdumps, click here to show them.