IOC Report
Revised RFQ-PO180911.doc

loading gif

Files

File Path
Type
Category
Malicious
Revised RFQ-PO180911.doc
data
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\cssati[1].exe
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
downloaded
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{E6E86BED-0A8E-45B4-8DBF-02AF74FFE8F6}.tmp
Composite Document File V2 Document, Cannot read section info
dropped
malicious
C:\Users\user\AppData\Local\Temp\dvukljmnr.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Roaming\word.exe
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{2B25940B-6835-4585-8FCF-CB425A08E6FD}.tmp
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{6C29C56C-3D5B-4878-9A01-77B8177CDD57}.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\4qh31ayyhk84s8sjtofn
data
dropped
C:\Users\user\AppData\Local\Temp\nstBFBE.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\xxsjdcnfw
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Revised RFQ-PO180911.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Tue Mar 8 15:45:54 2022, mtime=Tue Mar 8 15:45:54 2022, atime=Sat May 28 03:20:14 2022, length=4205, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\UProof\ExcludeDictionaryEN0409.lex
Little-endian UTF-16 Unicode text, with no line terminators
dropped
C:\Users\user\Desktop\~$vised RFQ-PO180911.doc
data
dropped
There are 5 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
"C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
malicious
C:\Users\user\AppData\Roaming\word.exe
C:\Users\user\AppData\Roaming\word.exe
malicious
C:\Users\user\AppData\Local\Temp\dvukljmnr.exe
C:\Users\user\AppData\Local\Temp\dvukljmnr.exe C:\Users\user\AppData\Local\Temp\xxsjdcnfw
malicious
C:\Users\user\AppData\Local\Temp\dvukljmnr.exe
C:\Users\user\AppData\Local\Temp\dvukljmnr.exe C:\Users\user\AppData\Local\Temp\xxsjdcnfw
malicious
C:\Windows\explorer.exe
C:\Windows\Explorer.EXE
malicious
C:\Windows\SysWOW64\wuapp.exe
C:\Windows\SysWOW64\wuapp.exe
malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /Automation -Embedding
C:\Windows\SysWOW64\cmd.exe
/c del "C:\Users\user\AppData\Local\Temp\dvukljmnr.exe"

URLs

Name
IP
Malicious
http://sanbarts.com/cssati.exe
194.9.94.86
malicious
www.rthearts.com/nk6l/
malicious
http://www.sanbarts.com/cssati.exeC:
unknown
malicious
http://www.sanbarts.com/cssati.exekkC:
unknown
malicious
http://www.sanbarts.com/cssati.exe
45.120.185.113
malicious
http://www.createacarepack.com/nk6l/?m6A=oZdYOW+9zhrIvNs3Uj0B160nPucVBdi4gaKHGG9IIOI6c6Yjw1TqFPH8yZ8k/nW4CFXcqw==&lJE=gtqHRlRHi
98.137.244.37
malicious
http://sanbarts.com/cssati.exej
unknown
malicious
http://www.windows.com/pctv.
unknown
http://investor.msn.com
unknown
http://www.msnbc.com/news/ticker.txt
unknown
http://www.sanbarts.com/YR$
unknown
http://wellformedweb.org/CommentAPI/
unknown
http://sanbarts.com/33
unknown
http://www.iis.fhg.de/audioPA
unknown
http://www.piriform.com/ccleanerq
unknown
http://www.piriform.com/ccleaner1SPS0
unknown
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
http://www.hotmail.com/oe
unknown
http://www.sanbarts.com/Couri
unknown
http://treyresearch.net
unknown
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
http://java.sun.com
unknown
http://www.icra.org/vocabulary/.
unknown
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
http://www.piriform.com/ccleanerhttp://www.piriform.com/ccleanerv
unknown
http://investor.msn.com/
unknown
http://www.piriform.com/ccleaner
unknown
http://computername/printers/printername/.printer
unknown
http://www.%s.comPA
unknown
http://www.autoitscript.com/autoit3
unknown
https://support.mozilla.org
unknown
http://www.piriform.com/ccleanerv
unknown
https://policies.yahoo.com/w3c/p3p.xml
unknown
http://servername/isapibackend.dll
unknown
There are 24 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
215ffbc1941f6023.7host.cn
45.120.185.113
malicious
sanbarts.com
194.9.94.86
malicious
sbsfe-p8.geo.mf0.yahoodns.net
98.137.244.37
malicious
www.sanbarts.com
unknown
malicious
www.paypal-caseid521.com
unknown
malicious
www.storyofsol.com
unknown
malicious
www.createacarepack.com
unknown
malicious

IPs

IP
Domain
Country
Malicious
194.9.94.86
sanbarts.com
Sweden
malicious
98.137.244.37
sbsfe-p8.geo.mf0.yahoodns.net
United States
malicious
45.120.185.113
215ffbc1941f6023.7host.cn
Hong Kong
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
)<)
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
m=)
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
| )
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\682F5
682F5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Batang
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Dotum
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@FangSong
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gulim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@NSimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Agency FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aharoni
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Algerian
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Andalus
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Angsana New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
AngsanaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aparajita
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arabic Typesetting
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Narrow
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Rounded MT Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Baskerville Old Face
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Batang
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bauhaus 93
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bell MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB Demi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bernard MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Blackadder ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Poster Compressed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Book Antiqua
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookman Old Style
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookshelf Symbol 7
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bradley Hand ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Britannic Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Broadway
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Browallia New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BrowalliaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Brush Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Californian FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calisto MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria Math
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Candara
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Castellar
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Centaur
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Schoolbook
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Chiller
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Colonna MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Comic Sans MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Consolas
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Constantia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cooper Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Corbel
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cordia New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
CordiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Courier New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Curlz MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DaunPenh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
David
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DilleniaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DokChampa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Dotum
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ebrima
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Edwardian Script ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Elephant
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Engravers MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Bold ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Demi ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Light ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Medium ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Estrangelo Edessa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
EucrosiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Euphemia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FangSong
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Felix Titling
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Footlight MT Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Forte
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Book
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi Cond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Heavy
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium Cond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FrankRuehl
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FreesiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Freestyle Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
French Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gabriola
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Garamond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gautami
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Georgia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gigi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Ext Condensed Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gisha
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gloucester MT Extra Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Old Style
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Stout
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gulim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Haettenschweiler
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harlow Solid Italic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harrington
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
High Tower Text
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Impact
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Imprint MT Shadow
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Informal Roman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
IrisUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Iskoola Pota
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
JasmineUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Jokerman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Juice ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kalinga
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kartika
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Khmer UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KodchiangUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kokila
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kristen ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kunstler Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lao UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Latha
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Leelawadee
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Levenim MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
LilyUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Bright
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Calligraphy
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Console
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Fax
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Handwriting
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Typewriter
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Unicode
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Magneto
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Maiandra GD
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mangal
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Marlett
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Matura MT Script Capitals
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Himalaya
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft New Tai Lue
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft PhagsPa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Tai Le
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Uighur
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Yi Baiti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam Fixed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mistral
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Modern No. 20
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mongolian Baiti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Monotype Corsiva
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MoolBoran
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Outlook
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Specialty
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MT Extra
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MV Boli
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Narkisim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Engraved
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Solid
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
NSimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Nyala
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
OCR A Extended
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Old English Text MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Onyx
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palace Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palatino Linotype
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Papyrus
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Parchment
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua Titling MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Plantagenet Cherokee
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Playbill
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Poor Richard
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Pristina
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Raavi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rage Italic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ravie
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Extra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rod
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sakkal Majalla
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Script MT Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Print
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Semibold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Symbol
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shonar Bangla
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Showcard Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shruti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic Fixed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Snap ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Stencil
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sylfaen
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Symbol
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tahoma
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tempus Sans ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Times New Roman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Traditional Arabic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Trebuchet MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tunga
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed Extra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Utsaah
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vani
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Verdana
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vijaya
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Viner Hand ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vivaldi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vladimir Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vrinda
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Webdings
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wide Latin
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 2
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 3
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\6FA75
6FA75
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Security\Trusted Documents
LastPurgeTime
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
WORDFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\6FA75
6FA75
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Data
Settings
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Options
ZoomApp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTF
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
EquationEditorFilesIntl_1033
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
There are 313 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
120000
unclassified section
page execute and read and write
malicious
130000
unclassified section
page execute and read and write
malicious
240000
unclassified section
page execute and read and write
malicious
400000
remote allocation
page execute and read and write
malicious
90000
system
page execute and read and write
malicious
400000
remote allocation
page execute and read and write
malicious
BAD3000
unkown
page execute and read and write
malicious
160000
direct allocation
page read and write
malicious
BAD3000
unkown
page execute and read and write
malicious
190000
trusted library allocation
page read and write
malicious
400000
remote allocation
page execute and read and write
malicious
2C3E000
stack
page read and write
2A20000
unkown
page read and write
2CA2000
unkown
page read and write
323000
heap
page read and write
8D0000
heap
page read and write
6F4A000
stack
page read and write
82D5000
unkown
page read and write
2AF0000
unkown
page read and write
28B0000
unkown
page readonly
6E4E000
stack
page read and write
310000
heap
page read and write
4DA0000
heap
page read and write
38E000
stack
page read and write
407000
unkown
page readonly
98D000
heap
page read and write
434F000
unkown
page read and write
335000
heap
page read and write
CF0000
unclassified section
page execute and read and write
2910000
unkown
page readonly
7E30000
stack
page read and write
244000
heap
page read and write
4385000
unkown
page read and write
31D000
stack
page read and write
785E000
stack
page read and write
323000
heap
page read and write
2D0000
unkown
page readonly
87E3000
unkown
page read and write
10000
heap
page read and write
42C000
unkown
page readonly
7D0000
heap
page read and write
690000
unkown
page readonly
1CE30000
direct allocation
page read and write
8569000
unkown
page read and write
400000
unkown
page readonly
B50000
trusted library allocation
page execute and read and write
9CE000
unkown
page write copy
421000
unkown
page read and write
7E30000
stack
page read and write
6F4A000
stack
page read and write
1CE21000
direct allocation
page read and write
D0000
trusted library allocation
page read and write
6D49000
stack
page read and write
83A7000
unkown
page read and write
320000
heap
page read and write
2B20000
unkown
page read and write
9A1000
unkown
page execute read
7428000
stack
page read and write
1D55000
heap
page read and write
3A4000
heap
page read and write
4464000
unkown
page read and write
2898000
stack
page read and write
7E37000
stack
page read and write
440D000
unkown
page read and write
4423000
unkown
page read and write
9CE000
unkown
page write copy
10000
heap
page read and write
2AA0000
unkown
page read and write
1D13000
unkown
page read and write
7567000
heap
page read and write
1F0000
unkown
page readonly
2AD0000
unkown
page read and write
8582000
unkown
page read and write
F0000
direct allocation
page execute and read and write
82D5000
unkown
page read and write
28B0000
unkown
page readonly
37CD000
trusted library allocation
page read and write
B39000
system
page execute and read and write
1F0000
unkown
page readonly
2B20000
unkown
page read and write
7567000
heap
page read and write
448F000
unkown
page read and write
2CA8000
unkown
page read and write
885F000
unkown
page read and write
290000
heap
page read and write
2AD0000
unkown
page read and write
B9B0000
heap
page read and write
886F000
unkown
page read and write
1EB4000
trusted library section
page readonly
8558000
unkown
page read and write
3B10000
unkown
page readonly
2C70000
heap
page read and write
4530000
unkown
page readonly
41D0000
unkown
page readonly
D0000
trusted library allocation
page read and write
1C30000
unkown
page readonly
240000
heap
page read and write
2047000
trusted library allocation
page execute and read and write
30000
trusted library allocation
page read and write
26FF000
stack
page read and write
1F40000
trusted library allocation
page execute and read and write
335000
heap
page read and write
88FD000
unkown
page read and write
2AE0000
unkown
page read and write
9D2000
unkown
page readonly
1D20000
unkown
page read and write
4E38000
stack
page read and write
8558000
unkown
page read and write
8A0000
trusted library allocation
page read and write
8558000
unkown
page read and write
B30000
system
page execute and read and write
B4D0000
unkown
page read and write
8802000
unkown
page read and write
19F000
stack
page read and write
850D000
unkown
page read and write
9A0000
unkown
page readonly
83A7000
unkown
page read and write
86C9000
unkown
page read and write
43F0000
unkown
page read and write
38D000
trusted library allocation
page read and write
37EF000
trusted library allocation
page read and write
2B30000
unkown
page readonly
4030000
unkown
page execute read
401000
unkown
page execute read
65D000
stack
page read and write
44D0000
unkown
page readonly
7930000
heap
page read and write
2044000
trusted library allocation
page execute and read and write
B9B5000
heap
page read and write
44B8000
unkown
page read and write
1D20000
unkown
page read and write
2B30000
unkown
page readonly
1CCAA000
direct allocation
page read and write
36D000
stack
page read and write
1CD30000
direct allocation
page read and write
2800000
trusted library allocation
page read and write
2B1000
unkown
page read and write
510000
unkown
page readonly
8675000
unkown
page read and write
410000
unkown
page read and write
2E9F000
stack
page read and write
8900000
unkown
page read and write
410000
unkown
page read and write
885B000
unkown
page read and write
20D0000
trusted library allocation
page execute and read and write
2A80000
unkown
page read and write
2CA5000
unkown
page read and write
6C79000
stack
page read and write
1CCAD000
direct allocation
page read and write
8807000
unkown
page read and write
3D5D000
stack
page read and write
21C1000
trusted library allocation
page execute and read and write
B9D3000
heap
page read and write
B893000
unkown
page read and write
8903000
unkown
page read and write
B4EE000
unkown
page read and write
1D30000
unkown
page read and write
9CE000
unkown
page write copy
564000
unkown
page read and write
2C78000
unkown
page read and write
8569000
unkown
page read and write
8805000
unkown
page read and write
240000
heap
page read and write
46CC000
stack
page read and write
B60000
trusted library allocation
page execute and read and write
2FC5000
heap
page read and write
9A1000
unkown
page execute read
223F000
stack
page read and write
1CE24000
direct allocation
page read and write
1CE27000
direct allocation
page read and write
2E0000
unkown
page readonly
15C000
stack
page read and write
1CE90000
direct allocation
page read and write
7E40000
heap
page read and write
2A50000
unkown
page read and write
D0000
unkown
page readonly
41E0000
unkown
page read and write
2C8000
heap
page read and write
8582000
unkown
page read and write
560000
heap
page read and write
506000
unkown
page read and write
1CCAA000
direct allocation
page read and write
2CB6000
unkown
page read and write
1CE24000
direct allocation
page read and write
7BE0000
heap
page read and write
100000
unkown
page read and write
2998000
unkown
page read and write
886F000
unkown
page read and write
6450000
unkown
page readonly
4570000
unkown
page readonly
6C79000
stack
page read and write
61E000
stack
page read and write
CE0000
trusted library allocation
page execute and read and write
1C30000
unkown
page readonly
8807000
unkown
page read and write
8669000
unkown
page read and write
315E000
stack
page read and write
B893000
unkown
page read and write
7E3A000
stack
page read and write
690000
unkown
page readonly
2CBF000
unkown
page read and write
84C8000
unkown
page read and write
4620000
unkown
page read and write
4317000
unkown
page read and write
4E0000
heap
page read and write
82D1000
unkown
page read and write
1CD20000
direct allocation
page read and write
100000
unkown
page read and write
885F000
unkown
page read and write
547000
unkown
page read and write
1F50000
trusted library allocation
page execute and read and write
39E0000
heap
page read and write
2CB9000
unkown
page read and write
8BE000
stack
page read and write
82CC000
unkown
page read and write
2256000
unclassified section
page read and write
1CE90000
direct allocation
page read and write
84D2000
unkown
page read and write
58E000
unkown
page read and write
10000
heap
page read and write
2643000
unkown
page read and write
4540000
unkown
page readonly
B4D0000
unkown
page read and write
6EC0000
heap
page read and write
2700000
trusted library allocation
page read and write
9A0000
unkown
page readonly
850D000
unkown
page read and write
8371000
unkown
page read and write
2700000
trusted library allocation
page read and write
2230000
trusted library allocation
page execute and read and write
9CE000
unkown
page write copy
39E0000
heap
page read and write
2643000
unkown
page read and write
2A40000
unkown
page read and write
866C000
unkown
page read and write
170000
heap
page read and write
3A6000
heap
page read and write
41D0000
unkown
page readonly
287000
heap
page read and write
30FF000
stack
page read and write
4550000
unkown
page readonly
41D0000
unkown
page readonly
B750000
unkown
page read and write
88FD000
unkown
page read and write
42D0000
unkown
page read and write
244F000
unclassified section
page read and write
1D73000
heap
page read and write
3960000
heap
page read and write
D0000
trusted library allocation
page read and write
1CD20000
direct allocation
page read and write
1F0000
trusted library allocation
page execute and read and write
4B39000
stack
page read and write
879E000
unkown
page read and write
2A10000
unkown
page read and write
2E9F000
stack
page read and write
6BD000
trusted library allocation
page read and write
883B000
unkown
page read and write
10000
heap
page read and write
690000
unkown
page readonly
449B000
unkown
page read and write
2B30000
unkown
page readonly
240000
heap
page read and write
1CD20000
direct allocation
page read and write
1CCAD000
direct allocation
page read and write
82D5000
unkown
page read and write
879E000
unkown
page read and write
2F1B000
stack
page read and write
886D000
unkown
page read and write
4520000
unkown
page readonly
440000
heap
page read and write
2AE0000
unkown
page read and write
409000
unkown
page write copy
1D50000
heap
page read and write
293F000
unclassified section
page read and write
450000
unkown
page read and write
28BF000
stack
page read and write
2B50000
unkown
page readonly
46D0000
unkown
page readonly
6750000
unkown
page read and write
85F2000
unkown
page read and write
7230000
heap
page read and write
74BE000
stack
page read and write
2C78000
unkown
page read and write
329000
heap
page read and write
1D20000
unkown
page read and write
448C000
unkown
page read and write
820000
trusted library allocation
page read and write
AE4000
trusted library allocation
page execute and read and write
690000
unkown
page readonly
2AC0000
unkown
page read and write
40B000
unkown
page read and write
F9F000
stack
page read and write
41C0000
unkown
page readonly
84EE000
unkown
page read and write
84C8000
unkown
page read and write
785E000
stack
page read and write
ADC8000
stack
page read and write
9D2000
unkown
page readonly
2CAE000
unkown
page read and write
7934000
heap
page read and write
851A000
unkown
page read and write
B39000
system
page execute and read and write
2801000
unkown
page read and write
2F1B000
stack
page read and write
2AB0000
unkown
page read and write
6BF0000
stack
page read and write
8FF000
heap
page read and write
4560000
unkown
page readonly
2F9E000
stack
page read and write
8844000
unkown
page read and write
2C50000
unkown
page read and write
6FC0000
heap
page read and write
28E000
stack
page read and write
4325000
unkown
page read and write
510000
unkown
page readonly
8512000
unkown
page read and write
8337000
unkown
page read and write
1DD0000
unkown
page readonly
434F000
unkown
page read and write
8844000
unkown
page read and write
1CD20000
direct allocation
page read and write
2973000
unkown
page read and write
20B0000
trusted library allocation
page execute and read and write
C64000
trusted library allocation
page execute and read and write
3C33000
heap
page read and write
310000
heap
page read and write
2CBC000
unkown
page read and write
1CD30000
direct allocation
page read and write
42C000
unkown
page readonly
4B39000
stack
page read and write
1CE24000
direct allocation
page read and write
410000
unkown
page read and write
18A000
stack
page read and write
7540000
heap
page read and write
B893000
unkown
page read and write
4464000
unkown
page read and write
297000
heap
page read and write
2A50000
unkown
page read and write
2C1000
unkown
page read and write
4E9000
heap
page read and write
2CBC000
unkown
page read and write
2FCE000
heap
page read and write
2A0000
heap
page read and write
2AF0000
unkown
page read and write
4530000
unkown
page readonly
B9D3000
heap
page read and write
ABEE000
stack
page read and write
2AC0000
unkown
page read and write
D0000
unkown
page readonly
26C6000
unkown
page read and write
42C000
unkown
page readonly
4484000
unkown
page read and write
1EB0000
trusted library section
page readonly
2CA0000
unkown
page read and write
4325000
unkown
page read and write
440D000
unkown
page read and write
2CBF000
unkown
page read and write
10000
heap
page read and write
7930000
heap
page read and write
2C50000
unkown
page read and write
2C21000
unkown
page read and write
7E37000
stack
page read and write
6BF9000
stack
page read and write
4338000
unkown
page read and write
2C7000
heap
page read and write
6F3F000
stack
page read and write
2CB3000
unkown
page read and write
1F22000
heap
page read and write
38EC000
stack
page read and write
D0000
trusted library allocation
page read and write
20000
unkown
page readonly
220000
unkown
page read and write
44E0000
unkown
page read and write
B850000
unkown
page read and write
8844000
unkown
page read and write
8903000
unkown
page read and write
831000
trusted library allocation
page read and write
6D49000
stack
page read and write
288D000
stack
page read and write
2E0000
unkown
page readonly
4510000
unkown
page execute and read and write
834000
trusted library allocation
page read and write
434F000
unkown
page read and write
410C000
stack
page read and write
8861000
unkown
page read and write
8867000
unkown
page read and write
50000
unkown
page readonly
329000
heap
page read and write
9A0000
trusted library allocation
page read and write
990000
trusted library allocation
page read and write
9C7000
unkown
page readonly
9A1000
unkown
page execute read
6E4E000
stack
page read and write
41C0000
unkown
page readonly
1A9000
stack
page read and write
2C7000
heap
page read and write
210000
trusted library allocation
page execute and read and write
2C78000
heap
page read and write
9A0000
unkown
page readonly
8575000
unkown
page read and write
D0000
trusted library allocation
page read and write
20000
trusted library allocation
page read and write
7549000
heap
page read and write
440D000
unkown
page read and write
2F7000
heap
page read and write
10000
heap
page read and write
841B000
unkown
page read and write
84C0000
unkown
page read and write
2A80000
unkown
page read and write
110000
unkown
page read and write
83A7000
unkown
page read and write
44F0000
unkown
page readonly
600000
heap
page read and write
4302000
unkown
page read and write
3970000
heap
page read and write
2A50000
unkown
page read and write
4D5E000
stack
page read and write
766B000
stack
page read and write
2C21000
unkown
page read and write
AF0000
trusted library allocation
page execute and read and write
2A90000
unkown
page read and write
42AE000
stack
page read and write
1F0000
unkown
page readonly
26C6000
unkown
page read and write
2A80000
unkown
page read and write
4550000
unkown
page readonly
2C50000
unkown
page read and write
82CC000
unkown
page read and write
110000
unkown
page read and write
2BE000
heap
page read and write
2A70000
unkown
page read and write
2F0F000
stack
page read and write
8805000
unkown
page read and write
26C6000
unkown
page read and write
79F0000
heap
page read and write
7E37000
stack
page read and write
9C7000
unkown
page readonly
9A0000
unkown
page readonly
2CA8000
unkown
page read and write
8807000
unkown
page read and write
210000
unkown
page readonly
7E32000
stack
page read and write
88BD000
unkown
page read and write
86C9000
unkown
page read and write
100000
unkown
page read and write
2CAB000
unkown
page read and write
B794000
unkown
page read and write
B712000
unkown
page read and write
4520000
unkown
page readonly
830000
unkown
page readonly
2A1000
unkown
page read and write
82C0000
unkown
page read and write
256000
unkown
page read and write
42E000
unkown
page read and write
2FC9000
heap
page read and write
2A50000
unkown
page read and write
4570000
unkown
page readonly
9C7000
unkown
page readonly
6F3F000
stack
page read and write
4060000
unkown
page readonly
409E000
stack
page read and write
1CBD0000
direct allocation
page read and write
3FD000
heap
page read and write
B9B5000
heap
page read and write
841B000
unkown
page read and write
7064000
heap
page read and write
250000
unkown
page read and write
8512000
unkown
page read and write
9D2000
unkown
page readonly
410000
unkown
page read and write
6EC0000
heap
page read and write
223F000
stack
page read and write
2BFD000
stack
page read and write
1CE21000
direct allocation
page read and write
2040000
trusted library allocation
page execute and read and write
948000
heap
page read and write
1CE27000
direct allocation
page read and write
4210000
unkown
page read and write
AE7000
trusted library allocation
page execute and read and write
4120000
trusted library allocation
page read and write
3B10000
unkown
page readonly
A84B000
stack
page read and write
8867000
unkown
page read and write
4560000
unkown
page readonly
2CA0000
unkown
page read and write
B9B5000
heap
page read and write
2AF0000
unkown
page read and write
1DD0000
unkown
page readonly
2FC9000
heap
page read and write
2A70000
unkown
page read and write
8371000
unkown
page read and write
1B0000
unkown
page read and write
401000
unkown
page execute read
2A1000
unkown
page read and write
2FC9000
heap
page read and write
2A20000
unkown
page read and write
89000
stack
page read and write
8820000
unkown
page read and write
E0000
unkown
page read and write
9C7000
unkown
page readonly
670000
heap
page read and write
B00000
trusted library allocation
page read and write
8861000
unkown
page read and write
42AE000
stack
page read and write
3FAF000
stack
page read and write
1CE90000
direct allocation
page read and write
9CE000
unkown
page write copy
449B000
unkown
page read and write
2F9E000
stack
page read and write
244000
heap
page read and write
2898000
stack
page read and write
2973000
unkown
page read and write
1D73000
heap
page read and write
82FD000
unkown
page read and write
88FA000
unkown
page read and write
88F5000
unkown
page read and write
84D2000
unkown
page read and write
8512000
unkown
page read and write
1EF0000
direct allocation
page read and write
84EE000
unkown
page read and write
44B8000
unkown
page read and write
C0000
trusted library allocation
page read and write
4040000
unkown
page readonly
2A1000
unkown
page read and write
2FC5000
heap
page read and write
1F00000
heap
page read and write
1CBD0000
direct allocation
page read and write
8B000
stack
page read and write
7060000
heap
page read and write
4510000
unkown
page execute and read and write
2CB6000
unkown
page read and write
6D49000
stack
page read and write
400000
unkown
page readonly
2A90000
unkown
page read and write
5E0000
trusted library allocation
page read and write
88F7000
unkown
page read and write
2910000
unkown
page readonly
1CCAD000
direct allocation
page read and write
220000
unkown
page read and write
7E32000
stack
page read and write
B7D3000
unkown
page read and write
1F0000
unkown
page readonly
36B000
stack
page read and write
8858000
unkown
page read and write
8667000
unkown
page read and write
2CBC000
unkown
page read and write
1CD30000
direct allocation
page read and write
2BFE000
stack
page read and write
256000
unkown
page read and write
60000
unkown
page readonly
342000
heap
page read and write
2C21000
unkown
page read and write
434F000
unkown
page read and write
2B50000
unkown
page readonly
B813000
unkown
page read and write
110000
unkown
page read and write
42C000
unkown
page readonly
2A30000
unkown
page read and write
4EEC000
stack
page read and write
7EC0000
unkown
page read and write
1D50000
heap
page read and write
44D000
unkown
page read and write
2D0000
unkown
page readonly
8664000
unkown
page read and write
82C0000
unkown
page read and write
79F0000
heap
page read and write
60000
unkown
page readonly
42E000
unkown
page read and write
4C10000
heap
page read and write
79FA000
heap
page read and write
335000
heap
page read and write
B4D0000
unkown
page read and write
9C7000
unkown
page readonly
4BBF000
stack
page read and write
4325000
unkown
page read and write
88BD000
unkown
page read and write
B813000
unkown
page read and write
20000
unkown
page readonly
98F000
stack
page read and write
B850000
unkown
page read and write
9D2000
unkown
page readonly
4210000
unkown
page read and write
504000
heap
page read and write
44B6000
unkown
page read and write
2CB9000
unkown
page read and write
7428000
stack
page read and write
85AC000
unkown
page read and write
ACEE000
stack
page read and write
766B000
stack
page read and write
B4EE000
unkown
page read and write
2240000
trusted library allocation
page execute and read and write
429000
unkown
page read and write
4317000
unkown
page read and write
392C000
stack
page read and write
A97000
trusted library allocation
page read and write
42D0000
unkown
page read and write
2AA0000
unkown
page read and write
4484000
unkown
page read and write
1D30000
unkown
page read and write
8926000
unkown
page read and write
8669000
unkown
page read and write
3B10000
unkown
page readonly
2AA0000
unkown
page read and write
6DDE000
stack
page read and write
2CBC000
unkown
page read and write
6450000
unkown
page readonly
1CBD0000
direct allocation
page read and write
770000
heap
page read and write
BB0F000
unkown
page execute and read and write
4DA0000
heap
page read and write
9A1000
unkown
page execute read
9CE000
unkown
page write copy
510000
heap
page read and write
6FC4000
heap
page read and write
72C0000
heap
page read and write
244000
heap
page read and write
36DF000
stack
page read and write
3770000
heap
page read and write
2B4000
heap
page read and write
88C0000
unkown
page read and write
6FC0000
heap
page read and write
39E0000
heap
page read and write
7934000
heap
page read and write
4E38000
stack
page read and write
1B0000
heap
page read and write
2E0000
unkown
page readonly
46CC000
stack
page read and write
1CE24000
direct allocation
page read and write
10000
heap
page read and write
8667000
unkown
page read and write
44C3000
unkown
page read and write
41C0000
unkown
page readonly
886D000
unkown
page read and write
830000
unkown
page readonly
998000
heap
page read and write
2643000
unkown
page read and write
84C0000
unkown
page read and write
2F0F000
stack
page read and write
1DD0000
unkown
page readonly
4CDD000
stack
page read and write
2AB0000
unkown
page read and write
72C0000
heap
page read and write
2CAB000
unkown
page read and write
27F0000
unkown
page read and write
6BF9000
stack
page read and write
1D0000
heap
page read and write
2CAE000
unkown
page read and write
540000
trusted library allocation
page read and write
1A9000
stack
page read and write
27F0000
unkown
page read and write
2C1000
unkown
page read and write
1CE10000
direct allocation
page read and write
7EC0000
unkown
page read and write
45A0000
unkown
page readonly
87E8000
unkown
page read and write
7953000
heap
page read and write
9C7000
unkown
page readonly
7953000
heap
page read and write
530000
heap
page read and write
2A40000
unkown
page read and write
4510000
unkown
page execute and read and write
2F0F000
stack
page read and write
7064000
heap
page read and write
2A20000
unkown
page read and write
2CA8000
unkown
page read and write
448C000
unkown
page read and write
1C30000
unkown
page readonly
7E3A000
stack
page read and write
2BFE000
stack
page read and write
87F9000
unkown
page read and write
D0000
unkown
page readonly
8575000
unkown
page read and write
2CA2000
unkown
page read and write
3AAD000
stack
page read and write
3E5D000
stack
page read and write
6FE3000
heap
page read and write
5030000
heap
page read and write
1EB9000
trusted library section
page readonly
4210000
unkown
page read and write
9A0000
unkown
page readonly
3A6000
heap
page read and write
4060000
unkown
page readonly
449F000
unkown
page read and write
2910000
unkown
page readonly
2AC0000
unkown
page read and write
3EC000
stack
page read and write
87F9000
unkown
page read and write
6CE000
stack
page read and write
D0000
unkown
page readonly
6FC4000
heap
page read and write
4DA0000
heap
page read and write
9A1000
unkown
page execute read
8582000
unkown
page read and write
335000
heap
page read and write
464000
heap
page read and write
44D000
unkown
page read and write
7060000
heap
page read and write
72C0000
heap
page read and write
1D73000
heap
page read and write
506000
unkown
page read and write
DCF000
unclassified section
page execute and read and write
D0000
trusted library allocation
page read and write
4EEC000
stack
page read and write
25F0000
unkown
page readonly
B712000
unkown
page read and write
CD0000
trusted library allocation
page execute and read and write
8D7000
heap
page read and write
4317000
unkown
page read and write
3A6000
heap
page read and write
2CB9000
unkown
page read and write
85AC000
unkown
page read and write
27F0000
unkown
page read and write
26F0000
unkown
page read and write
6D4B000
stack
page read and write
D0000
trusted library allocation
page read and write
290000
unkown
page readonly
BA30000
unkown
page execute and read and write
42C000
unkown
page readonly
3A4000
heap
page read and write
5030000
heap
page read and write
21C4000
trusted library allocation
page execute and read and write
2C58000
unkown
page read and write
6450000
unkown
page readonly
1D30000
unkown
page read and write
8805000
unkown
page read and write
2F2000
heap
page read and write
886A000
unkown
page read and write
256000
unkown
page read and write
88C0000
unkown
page read and write
41E0000
unkown
page read and write
1A9000
stack
page read and write
4060000
unkown
page readonly
84C0000
unkown
page read and write
D0000
trusted library allocation
page read and write
8864000
unkown
page read and write
1CCAA000
direct allocation
page read and write
8AF000
stack
page read and write
9A1000
unkown
page execute read
8506000
unkown
page read and write
2A40000
unkown
page read and write
6DDE000
stack
page read and write
B750000
unkown
page read and write
1CE21000
direct allocation
page read and write
42D0000
unkown
page read and write
3180000
heap
page read and write
450000
unkown
page read and write
11C000
stack
page read and write
3BEC000
stack
page read and write
44F0000
unkown
page readonly
4030000
unkown
page execute read
85D2000
unkown
page read and write
2B1000
unkown
page read and write
4C10000
heap
page read and write
2973000
unkown
page read and write
4EEC000
stack
page read and write
7660000
stack
page read and write
D0000
trusted library allocation
page read and write
400000
unkown
page readonly
AA0000
trusted library allocation
page read and write
2E9F000
stack
page read and write
27F000
stack
page read and write
4302000
unkown
page read and write
2C58000
unkown
page read and write
4030000
unkown
page execute read
3A6000
heap
page read and write
371E000
stack
page read and write
6FE3000
heap
page read and write
87E8000
unkown
page read and write
18C000
stack
page read and write
3CF7000
unkown
page readonly
50000
unkown
page readonly
8675000
unkown
page read and write
380000
heap
page read and write
2A30000
unkown
page read and write
88F5000
unkown
page read and write
42D0000
unkown
page read and write
8FE000
stack
page read and write
83E2000
unkown
page read and write
21D0000
trusted library allocation
page execute and read and write
7083000
heap
page read and write
2030000
trusted library allocation
page execute and read and write
4457000
unkown
page read and write
3CF7000
unkown
page readonly
3FD000
heap
page read and write
4317000
unkown
page read and write
840000
trusted library allocation
page read and write
85AC000
unkown
page read and write
19F000
stack
page read and write
2CB3000
unkown
page read and write
8F4000
heap
page read and write
2D0000
unkown
page readonly
2CD000
heap
page read and write
85F2000
unkown
page read and write
9A0000
unkown
page readonly
27A000
unkown
page read and write
8858000
unkown
page read and write
4620000
unkown
page read and write
21C7000
trusted library allocation
page execute and read and write
2A10000
unkown
page read and write
41D0000
unkown
page readonly
506000
unkown
page read and write
6FC0000
heap
page read and write
82C0000
unkown
page read and write
41C0000
unkown
page readonly
28B0000
unkown
page readonly
37B0000
trusted library allocation
page read and write
6DDE000
stack
page read and write
82FD000
unkown
page read and write
2CB0000
unkown
page read and write
28F0000
unkown
page read and write
7EC0000
unkown
page read and write
B9D3000
heap
page read and write
730000
trusted library allocation
page read and write
323000
heap
page read and write
9CE000
unkown
page read and write
2600000
unkown
page readonly
449F000
unkown
page read and write
8675000
unkown
page read and write
1CE30000
direct allocation
page read and write
20000
unkown
page readonly
856B000
unkown
page read and write
2A80000
unkown
page read and write
7953000
heap
page read and write
9D2000
unkown
page readonly
6D4B000
stack
page read and write
883B000
unkown
page read and write
407000
unkown
page readonly
2643000
unkown
page read and write
5030000
heap
page read and write
288D000
stack
page read and write
26C6000
unkown
page read and write
4EF000
heap
page read and write
1CD30000
direct allocation
page read and write
B4EE000
unkown
page read and write
9C7000
unkown
page readonly
448F000
unkown
page read and write
2F1B000
stack
page read and write
409000
unkown
page write copy
2CAE000
unkown
page read and write
71A0000
heap
page read and write
7083000
heap
page read and write
8337000
unkown
page read and write
87FF000
unkown
page read and write
7E32000
stack
page read and write
3FD000
heap
page read and write
87F9000
unkown
page read and write
7E40000
heap
page read and write
2B30000
unkown
page readonly
45A0000
unkown
page readonly
2CA0000
unkown
page read and write
8575000
unkown
page read and write
885B000
unkown
page read and write
2898000
stack
page read and write
2B1000
unkown
page read and write
1D50000
heap
page read and write
88FD000
unkown
page read and write
1CE30000
direct allocation
page read and write
3B10000
unkown
page readonly
25F0000
unkown
page readonly
886F000
unkown
page read and write
19C000
stack
page read and write
87FC000
unkown
page read and write
20C0000
trusted library allocation
page execute and read and write
450000
unkown
page read and write
324000
heap
page read and write
B7D3000
unkown
page read and write
9CF000
stack
page read and write
88F7000
unkown
page read and write
8667000
unkown
page read and write
E0000
unkown
page read and write
2F9E000
stack
page read and write
240000
heap
page read and write
4338000
unkown
page read and write
2CB3000
unkown
page read and write
44D000
unkown
page read and write
886A000
unkown
page read and write
87E3000
unkown
page read and write
87E8000
unkown
page read and write
7428000
stack
page read and write
3C20000
heap
page read and write
28F0000
unkown
page read and write
329000
heap
page read and write
1B0000
unkown
page read and write
4040000
unkown
page readonly
851A000
unkown
page read and write
2D0000
heap
page read and write
110000
unkown
page read and write
2B1000
unkown
page read and write
4CDD000
stack
page read and write
448F000
unkown
page read and write
27A000
unkown
page read and write
27A000
unkown
page read and write
79FA000
heap
page read and write
490000
heap
page read and write
8867000
unkown
page read and write
4423000
unkown
page read and write
440D000
unkown
page read and write
4F60000
heap
page read and write
2CAE000
unkown
page read and write
2AA0000
unkown
page read and write
2CB6000
unkown
page read and write
2AF0000
unkown
page read and write
88F7000
unkown
page read and write
3CF7000
unkown
page readonly
87BB000
unkown
page read and write
2CD000
heap
page read and write
29BF000
stack
page read and write
370000
trusted library allocation
page read and write
6E5A000
stack
page read and write
2FC9000
heap
page read and write
42AE000
stack
page read and write
7540000
heap
page read and write
44D000
unkown
page read and write
6FE3000
heap
page read and write
449F000
unkown
page read and write
510000
unkown
page readonly
837000
trusted library allocation
page read and write
4E38000
stack
page read and write
86C9000
unkown
page read and write
886A000
unkown
page read and write
2CAB000
unkown
page read and write
9C7000
unkown
page readonly
19F000
stack
page read and write
2CB0000
unkown
page read and write
2A90000
unkown
page read and write
329000
heap
page read and write
BB0F000
unkown
page execute and read and write
1D55000
heap
page read and write
879E000
unkown
page read and write
24EF000
stack
page read and write
2CB0000
unkown
page read and write
44B6000
unkown
page read and write
2CB3000
unkown
page read and write
9A1000
unkown
page execute read
30000
unclassified section
page execute and read and write
2700000
trusted library allocation
page read and write
84EE000
unkown
page read and write
B794000
unkown
page read and write
2A70000
unkown
page read and write
288D000
stack
page read and write
2C74000
heap
page read and write
244000
heap
page read and write
401000
unkown
page execute read
7060000
heap
page read and write
8861000
unkown
page read and write
256000
unkown
page read and write
9A0000
heap
page read and write
71A0000
heap
page read and write
3FAF000
stack
page read and write
2A60000
unkown
page read and write
2FC5000
heap
page read and write
2C50000
unkown
page read and write
4550000
unkown
page readonly
223F000
stack
page read and write
88FA000
unkown
page read and write
2A40000
unkown
page read and write
2CA2000
unkown
page read and write
27A000
unkown
page read and write
506000
unkown
page read and write
B850000
unkown
page read and write
2BFE000
stack
page read and write
83E2000
unkown
page read and write
8903000
unkown
page read and write
87E3000
unkown
page read and write
3FAF000
stack
page read and write
4484000
unkown
page read and write
1D13000
unkown
page read and write
88FA000
unkown
page read and write
37DF000
trusted library allocation
page read and write
4385000
unkown
page read and write
82D1000
unkown
page read and write
250000
unkown
page read and write
26BA000
unkown
page read and write
3FB5000
stack
page read and write
87FC000
unkown
page read and write
26BA000
unkown
page read and write
9F0000
trusted library allocation
page execute and read and write
82C5000
unkown
page read and write
2CB9000
unkown
page read and write
409000
unkown
page write copy
2BFE000
stack
page read and write
801000
heap
page read and write
44E0000
unkown
page read and write
2A20000
unkown
page read and write
AD0000
trusted library allocation
page execute and read and write
2801000
unkown
page read and write
401000
unkown
page execute read
C50000
trusted library allocation
page execute and read and write
375C000
stack
page read and write
11CF000
stack
page read and write
8858000
unkown
page read and write
4DA5000
heap
page read and write
2F1B000
stack
page read and write
1CE27000
direct allocation
page read and write
856B000
unkown
page read and write
1D55000
heap
page read and write
280000
heap
page read and write
9D2000
unkown
page readonly
2CB0000
unkown
page read and write
2898000
stack
page read and write
3A4000
heap
page read and write
405D000
stack
page read and write
7934000
heap
page read and write
2FC0000
heap
page read and write
7083000
heap
page read and write
4560000
unkown
page readonly
8900000
unkown
page read and write
9A1000
unkown
page execute read
4338000
unkown
page read and write
87FF000
unkown
page read and write
4D5E000
stack
page read and write
7567000
heap
page read and write
3CE000
stack
page read and write
2910000
unkown
page readonly
2B20000
unkown
page read and write
9D0000
trusted library allocation
page execute and read and write
2998000
unkown
page read and write
2F9E000
stack
page read and write
223F000
stack
page read and write
6750000
unkown
page read and write
4220000
unkown
page readonly
4BBF000
stack
page read and write
BC000
stack
page read and write
6FC4000
heap
page read and write
2FC5000
heap
page read and write
B9B0000
heap
page read and write
37B000
heap
page read and write
9D2000
unkown
page readonly
50000
unkown
page readonly
83E2000
unkown
page read and write
D0000
trusted library allocation
page read and write
4423000
unkown
page read and write
2CB6000
unkown
page read and write
2AC0000
unkown
page read and write
A84B000
stack
page read and write
A80000
trusted library allocation
page read and write
6BF9000
stack
page read and write
D0000
trusted library allocation
page read and write
91A000
trusted library allocation
page read and write
410C000
stack
page read and write
4040000
unkown
page readonly
9D2000
unkown
page readonly
2CBF000
unkown
page read and write
1CCAA000
direct allocation
page read and write
2A30000
unkown
page read and write
44E0000
unkown
page read and write
42C000
unkown
page readonly
9CE000
unkown
page write copy
100000
unkown
page read and write
8926000
unkown
page read and write
7540000
heap
page read and write
26F0000
unkown
page read and write
448F000
unkown
page read and write
26BA000
unkown
page read and write
31CF000
stack
page read and write
ACEE000
stack
page read and write
1DD0000
unkown
page readonly
2C58000
unkown
page read and write
4EE000
heap
page read and write
6BF0000
stack
page read and write
23EF000
stack
page read and write
ADC8000
stack
page read and write
2973000
unkown
page read and write
74BE000
stack
page read and write
37B000
heap
page read and write
4338000
unkown
page read and write
1B0000
unkown
page read and write
210000
unkown
page readonly
883B000
unkown
page read and write
4302000
unkown
page read and write
7F4000
heap
page read and write
1EE0000
heap
page read and write
1CCAD000
direct allocation
page read and write
2801000
unkown
page read and write
8337000
unkown
page read and write
1CE10000
direct allocation
page read and write
44D0000
unkown
page readonly
21B0000
trusted library allocation
page execute and read and write
1D55000
heap
page read and write
4D5E000
stack
page read and write
2A1000
unkown
page read and write
3FAF000
stack
page read and write
A94000
trusted library allocation
page read and write
25F0000
unkown
page readonly
2C1000
unkown
page read and write
2CA5000
unkown
page read and write
7D7000
heap
page read and write
4DA5000
heap
page read and write
85D2000
unkown
page read and write
1CE90000
direct allocation
page read and write
42E000
unkown
page read and write
4B39000
stack
page read and write
785E000
stack
page read and write
41E0000
unkown
page read and write
1F04000
heap
page read and write
43F0000
unkown
page read and write
44D0000
unkown
page readonly
7BE0000
heap
page read and write
448C000
unkown
page read and write
1CE10000
direct allocation
page read and write
2AD0000
unkown
page read and write
9D2000
unkown
page readonly
1B0000
unkown
page read and write
8802000
unkown
page read and write
ADC8000
stack
page read and write
1CE27000
direct allocation
page read and write
401000
unkown
page execute read
2CA5000
unkown
page read and write
82C5000
unkown
page read and write
85F2000
unkown
page read and write
A84B000
stack
page read and write
3AE000
stack
page read and write
4F60000
heap
page read and write
6BF0000
stack
page read and write
9A0000
unkown
page readonly
87FF000
unkown
page read and write
85D2000
unkown
page read and write
2600000
unkown
page readonly
82D1000
unkown
page read and write
8669000
unkown
page read and write
50E000
stack
page read and write
B794000
unkown
page read and write
2A60000
unkown
page read and write
290000
unkown
page readonly
29C0000
trusted library allocation
page read and write
2BC000
heap
page read and write
2600000
unkown
page readonly
39000
unclassified section
page execute and read and write
850D000
unkown
page read and write
464F000
stack
page read and write
2FCE000
heap
page read and write
3FB5000
stack
page read and write
2A10000
unkown
page read and write
9D2000
unkown
page readonly
1E5E000
stack
page read and write
409000
unkown
page read and write
B70000
trusted library allocation
page execute and read and write
4302000
unkown
page read and write
830000
unkown
page readonly
970000
heap
page read and write
1E60000
heap
page read and write
401000
unkown
page execute read
449F000
unkown
page read and write
210000
unkown
page readonly
449B000
unkown
page read and write
B7D3000
unkown
page read and write
4BBF000
stack
page read and write
2A70000
unkown
page read and write
41E0000
unkown
page read and write
410C000
stack
page read and write
B813000
unkown
page read and write
3BAF000
stack
page read and write
7930000
heap
page read and write
2600000
unkown
page readonly
8864000
unkown
page read and write
407000
unkown
page readonly
ABEE000
stack
page read and write
400000
unkown
page readonly
4520000
unkown
page readonly
46CC000
stack
page read and write
2A10000
unkown
page read and write
37B000
heap
page read and write
96C000
heap
page read and write
19F000
stack
page read and write
2C78000
unkown
page read and write
42E000
unkown
page read and write
4F60000
heap
page read and write
89E000
stack
page read and write
851A000
unkown
page read and write
2F0F000
stack
page read and write
4040000
unkown
page readonly
933000
heap
page read and write
3FB5000
stack
page read and write
866C000
unkown
page read and write
8506000
unkown
page read and write
2BC000
heap
page read and write
27F0000
unkown
page read and write
44B6000
unkown
page read and write
C67000
trusted library allocation
page execute and read and write
4620000
unkown
page read and write
9A0000
unkown
page readonly
325E000
stack
page read and write
840000
trusted library allocation
page read and write
42AE000
stack
page read and write
4CDD000
stack
page read and write
B9B0000
heap
page read and write
7064000
heap
page read and write
1CE21000
direct allocation
page read and write
8900000
unkown
page read and write
9CE000
unkown
page write copy
2AB0000
unkown
page read and write
ABEE000
stack
page read and write
7549000
heap
page read and write
407000
unkown
page readonly
88C0000
unkown
page read and write
2CA2000
unkown
page read and write
841B000
unkown
page read and write
400000
remote allocation
page execute and read and write
6750000
unkown
page read and write
6F4A000
stack
page read and write
2CAB000
unkown
page read and write
4530000
unkown
page readonly
8820000
unkown
page read and write
2B50000
unkown
page readonly
E0000
unkown
page read and write
9C7000
unkown
page readonly
400000
trusted library allocation
page execute and read and write
830000
unkown
page readonly
D0000
trusted library allocation
page read and write
91D000
trusted library allocation
page read and write
6BA000
trusted library allocation
page read and write
400000
unkown
page readonly
2050000
trusted library allocation
page execute and read and write
2700000
trusted library allocation
page read and write
60000
unkown
page readonly
290000
unkown
page readonly
37B000
heap
page read and write
856B000
unkown
page read and write
7E3A000
stack
page read and write
510000
unkown
page readonly
4E7000
heap
page read and write
2B20000
unkown
page read and write
74BE000
stack
page read and write
2AB0000
unkown
page read and write
6E5A000
stack
page read and write
8926000
unkown
page read and write
3CF7000
unkown
page readonly
4540000
unkown
page readonly
39E0000
heap
page read and write
4DA5000
heap
page read and write
28B0000
unkown
page readonly
43F0000
unkown
page read and write
2DD000
stack
page read and write
1D13000
unkown
page read and write
6F3F000
stack
page read and write
250000
unkown
page read and write
2A60000
unkown
page read and write
7549000
heap
page read and write
8636000
unkown
page read and write
9CE000
unkown
page write copy
2E9F000
stack
page read and write
8864000
unkown
page read and write
1D13000
unkown
page read and write
2FCE000
heap
page read and write
2A60000
unkown
page read and write
447000
heap
page read and write
2D0000
unkown
page readonly
4570000
unkown
page readonly
2B50000
unkown
page readonly
82CC000
unkown
page read and write
6EC0000
heap
page read and write
2FCE000
heap
page read and write
2C7B000
heap
page read and write
250000
unkown
page read and write
26F0000
unkown
page read and write
D0000
trusted library allocation
page read and write
2801000
unkown
page read and write
323000
heap
page read and write
9A0000
unkown
page readonly
2998000
unkown
page read and write
540000
unkown
page read and write
2C58000
unkown
page read and write
9A1000
unkown
page execute read
C61000
trusted library allocation
page execute and read and write
26BA000
unkown
page read and write
1D20000
unkown
page read and write
2C21000
unkown
page read and write
9A1000
unkown
page execute read
8636000
unkown
page read and write
4457000
unkown
page read and write
1C30000
unkown
page readonly
4220000
unkown
page readonly
82C5000
unkown
page read and write
71A0000
heap
page read and write
449B000
unkown
page read and write
2CBF000
unkown
page read and write
44C3000
unkown
page read and write
2C6000
heap
page read and write
87BB000
unkown
page read and write
2AE0000
unkown
page read and write
448C000
unkown
page read and write
4C10000
heap
page read and write
59E000
unkown
page read and write
50000
unkown
page readonly
46D0000
unkown
page readonly
8371000
unkown
page read and write
2A90000
unkown
page read and write
E0000
unkown
page read and write
8664000
unkown
page read and write
8636000
unkown
page read and write
3FD000
heap
page read and write
C70000
trusted library allocation
page execute and read and write
410C000
stack
page read and write
310000
heap
page read and write
8820000
unkown
page read and write
7BE0000
heap
page read and write
AE0000
trusted library allocation
page execute and read and write
740000
trusted library allocation
page read and write
9D2000
unkown
page readonly
1CE10000
direct allocation
page read and write
4325000
unkown
page read and write
18B000
stack
page read and write
82FD000
unkown
page read and write
4464000
unkown
page read and write
3F5C000
stack
page read and write
2E0000
unkown
page readonly
9C7000
unkown
page readonly
7230000
heap
page read and write
2FC0000
heap
page read and write
8664000
unkown
page read and write
7E30000
stack
page read and write
79F0000
heap
page read and write
4060000
unkown
page readonly
84D2000
unkown
page read and write
2CA5000
unkown
page read and write
88F5000
unkown
page read and write
288D000
stack
page read and write
87FC000
unkown
page read and write
8506000
unkown
page read and write
766B000
stack
page read and write
7660000
stack
page read and write
4385000
unkown
page read and write
4484000
unkown
page read and write
2A30000
unkown
page read and write
4457000
unkown
page read and write
1A9000
stack
page read and write
10000
heap
page read and write
400000
unkown
page readonly
886D000
unkown
page read and write
2C1000
unkown
page read and write
407000
unkown
page readonly
8569000
unkown
page read and write
9C7000
unkown
page readonly
6E4E000
stack
page read and write
1D50000
heap
page read and write
9A0000
unkown
page readonly
2FC0000
heap
page read and write
6C79000
stack
page read and write
45A0000
unkown
page readonly
7660000
stack
page read and write
6D4B000
stack
page read and write
2AD0000
unkown
page read and write
220000
unkown
page read and write
84C8000
unkown
page read and write
4220000
unkown
page readonly
BA30000
unkown
page execute and read and write
407000
unkown
page readonly
60000
unkown
page readonly
20000
unkown
page readonly
1D30000
unkown
page read and write
88BD000
unkown
page read and write
4457000
unkown
page read and write
3FB5000
stack
page read and write
2C0000
heap
page read and write
885F000
unkown
page read and write
26F0000
unkown
page read and write
866C000
unkown
page read and write
1CE30000
direct allocation
page read and write
2AE000
stack
page read and write
409000
unkown
page write copy
9CE000
unkown
page write copy
290000
unkown
page readonly
4385000
unkown
page read and write
B30000
system
page execute and read and write
1CBD0000
direct allocation
page read and write
4423000
unkown
page read and write
1D73000
heap
page read and write
87BB000
unkown
page read and write
2FC0000
heap
page read and write
220000
unkown
page read and write
44F0000
unkown
page readonly
46D0000
unkown
page readonly
A91000
trusted library allocation
page read and write
6E5A000
stack
page read and write
3A4000
heap
page read and write
2AE0000
unkown
page read and write
2C2000
heap
page read and write
10000
heap
page read and write
4210000
unkown
page read and write
44B8000
unkown
page read and write
9E0000
trusted library allocation
page execute and read and write
7230000
heap
page read and write
2CA0000
unkown
page read and write
37F4000
trusted library allocation
page read and write
2CA8000
unkown
page read and write
2998000
unkown
page read and write
2C78000
unkown
page read and write
ACEE000
stack
page read and write
9A1000
unkown
page execute read
B750000
unkown
page read and write
43F0000
unkown
page read and write
8802000
unkown
page read and write
44C3000
unkown
page read and write
7E40000
heap
page read and write
79FA000
heap
page read and write
10000
heap
page read and write
4030000
unkown
page execute read
20000
heap
page read and write
4220000
unkown
page readonly
9A0000
unkown
page readonly
25F0000
unkown
page readonly
496000
heap
page read and write
4464000
unkown
page read and write
B712000
unkown
page read and write
4540000
unkown
page readonly
310000
heap
page read and write
450000
unkown
page read and write
210000
unkown
page readonly
885B000
unkown
page read and write
409000
unkown
page write copy
There are 1400 hidden memdumps, click here to show them.