Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
Confirm!!.exe
|
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Confirm!!.exe.log
|
ASCII text, with CRLF line terminators
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\Confirm!!.exe
|
"C:\Users\user\Desktop\Confirm!!.exe"
|
||
C:\Users\user\Desktop\Confirm!!.exe
|
"C:\Users\user\Desktop\Confirm!!.exe"
|
||
C:\Users\user\Desktop\Confirm!!.exe
|
"C:\Users\user\Desktop\Confirm!!.exe"
|
||
C:\Windows\explorer.exe
|
C:\Windows\Explorer.EXE
|
||
C:\Windows\SysWOW64\systray.exe
|
"C:\Windows\SysWOW64\systray.exe"
|
||
C:\Windows\SysWOW64\autoconv.exe
|
"C:\Windows\SysWOW64\autoconv.exe"
|
||
C:\Windows\SysWOW64\cmd.exe
|
/c del "C:\Users\user\Desktop\Confirm!!.exe"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://www.dp77.shop/he2a/www.emsculptcenterofne.com
|
unknown
|
||
http://www.dp77.shop/he2a/
|
unknown
|
||
http://www.24eu-ru-startup.xyz/he2a/
|
unknown
|
||
http://www.qfs-capital.com/he2a/
|
unknown
|
||
http://www.qfs-capital.com/he2a/?JzrDMTwh=DlTSXcqNMc/eIm04yg00yQhMr4k/78J4L3shN4/4/VEr7otGcEkt4QUsswClQbB7ROijRjUf3A==&uDHX=NtTTaB
|
192.227.130.26
|
||
http://www.theaustralianbrisketboard.com/he2a/?uDHX=NtTTaB&JzrDMTwh=OUTCM60j1GyCH9lbRdMZH2fDR4+aODlMrRGupFh1zUOB6Dok3GIrGaEH03LGWK74faeOXvHbbw==
|
202.124.241.178
|
||
www.qfs-capital.com/he2a/
|
|||
http://www.notbokin.onlineReferer:
|
unknown
|
||
https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DV
|
unknown
|
||
https://www.msn.com/en-us/money/savingandinvesting/americans-average-net-worth-by-age/ar-AA1h4ngF
|
unknown
|
||
https://api.msn.com:443/v1/news/Feed/Windows?
|
unknown
|
||
https://word.office.comM
|
unknown
|
||
https://www.msn.com/en-us/money/realestate/why-this-florida-city-is-a-safe-haven-from-hurricanes/ar-
|
unknown
|
||
http://www.24eu-ru-startup.xyz/he2a/www.notbokin.online
|
unknown
|
||
https://www.msn.com/en-us/news/politics/how-donald-trump-helped-kari-lake-become-arizona-s-and-ameri
|
unknown
|
||
http://www.dcmdot.com/he2a/www.24eu-ru-startup.xyz
|
unknown
|
||
http://www.epeople.storeReferer:
|
unknown
|
||
http://www.emsculptcenterofne.comReferer:
|
unknown
|
||
http://www.emsculptcenterofne.com/he2a/www.dcmdot.com
|
unknown
|
||
http://www.desire-dating.comReferer:
|
unknown
|
||
https://wns.windows.com/e
|
unknown
|
||
http://www.myjbtest.net/he2a/www.dp77.shop
|
unknown
|
||
http://www.autoitscript.com/autoit3/J
|
unknown
|
||
http://www.theaustralianbrisketboard.com
|
unknown
|
||
http://www.epeople.store/he2a/
|
unknown
|
||
http://www.taylorranchtrail.comReferer:
|
unknown
|
||
https://assets.msn.com/weathermapdata/1/static/finance/1stparty/FinanceTaskbarIcons/Finance_Earnings
|
unknown
|
||
http://www.giuila.online/he2a/www.taylorranchtrail.com
|
unknown
|
||
https://api.msn.com/v1/news/Feed/Windows?activityId=435B7A89D7D74BDF801F2DA188906BAF&timeOut=5000&oc
|
unknown
|
||
https://windows.msn.com:443/shell?osLocale=en-GB&chosenMarketReason=ImplicitNew
|
unknown
|
||
http://www.dp77.shopReferer:
|
unknown
|
||
https://www.msn.com/en-us/travel/news/you-can-t-beat-bobby-flay-s-phoenix-airport-restaurant-one-of-
|
unknown
|
||
http://www.qfs-capital.com/he2a/www.theaustralianbrisketboard.com
|
unknown
|
||
http://www.cyg8wm3zfb.xyz/he2a/www.epeople.store
|
unknown
|
||
http://www.b-store.shop
|
unknown
|
||
http://www.oktravelhi.com/he2a/www.qfs-capital.com
|
unknown
|
||
https://android.notify.windows.com/iOS
|
unknown
|
||
https://outlook.come
|
unknown
|
||
https://activity.windows.com/UserActivity.ReadWrite.CreatedByApp
|
unknown
|
||
https://www.msn.com/en-us/news/us/dumb-and-dumber-12-states-with-the-absolute-worst-education-in-the
|
unknown
|
||
http://www.emsculptcenterofne.com/he2a/
|
unknown
|
||
http://www.desire-dating.com/he2a/
|
unknown
|
||
http://www.dcmdot.comReferer:
|
unknown
|
||
http://www.dp77.shop
|
unknown
|
||
http://www.myjbtest.netReferer:
|
unknown
|
||
http://www.oktravelhi.com/he2a/
|
unknown
|
||
https://www.msn.com/en-us/news/politics/kevin-mccarthy-s-ouster-as-house-speaker-could-cost-gop-its-
|
unknown
|
||
http://www.taylorranchtrail.com
|
unknown
|
||
http://www.24eu-ru-startup.xyz
|
unknown
|
||
https://api.msn.com/v1/news/Feed/Windows?
|
unknown
|
||
http://www.dcmdot.com
|
unknown
|
||
https://api.msn.com/I
|
unknown
|
||
http://www.meet-friends.onlineReferer:
|
unknown
|
||
http://www.b-store.shop/he2a/www.desire-dating.com
|
unknown
|
||
http://www.meet-friends.online
|
unknown
|
||
http://www.notbokin.online
|
unknown
|
||
http://www.theaustralianbrisketboard.com/he2a/
|
unknown
|
||
http://schemas.micro
|
unknown
|
||
http://www.desire-dating.com
|
unknown
|
||
http://www.giuila.online/he2a/
|
unknown
|
||
http://www.qfs-capital.com
|
unknown
|
||
http://www.b-store.shop/he2a/
|
unknown
|
||
http://www.giuila.online
|
unknown
|
||
https://windows.msn.com:443/shellv2?osLocale=en-GB&chosenMarketReason=ImplicitNew
|
unknown
|
||
http://www.qfs-capital.comReferer:
|
unknown
|
||
http://www.giuila.onlineReferer:
|
unknown
|
||
http://www.dcmdot.com/he2a/
|
unknown
|
||
http://www.theaustralianbrisketboard.com/he2a/www.giuila.online
|
unknown
|
||
http://www.b-store.shopReferer:
|
unknown
|
||
https://www.msn.com/en-us/news/politics/republicans-already-barred-trump-from-being-speaker-of-the-h
|
unknown
|
||
http://www.emsculptcenterofne.com
|
unknown
|
||
http://www.theaustralianbrisketboard.comReferer:
|
unknown
|
||
https://www.msn.com/en-us/news/politics/trump-campaign-says-he-raised-more-than-45-million-in-3rd-qu
|
unknown
|
||
http://www.oktravelhi.com
|
unknown
|
||
http://www.notbokin.online/he2a/
|
unknown
|
||
http://www.cyg8wm3zfb.xyz/he2a/
|
unknown
|
||
http://www.notbokin.online/he2a/www.b-store.shop
|
unknown
|
||
http://www.taylorranchtrail.com/he2a/
|
unknown
|
||
http://www.cyg8wm3zfb.xyzReferer:
|
unknown
|
||
http://www.meet-friends.online/he2a/www.myjbtest.net
|
unknown
|
||
https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gMhz
|
unknown
|
||
https://excel.office.com-
|
unknown
|
||
http://www.taylorranchtrail.com/he2a/www.cyg8wm3zfb.xyz
|
unknown
|
||
https://assets.msn.com/weathermapdata/1/static/weather/Icons/JyNGQgA=/Condition/AAehwh2.svg
|
unknown
|
||
https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gMhz-dark
|
unknown
|
||
http://www.myjbtest.net/he2a/
|
unknown
|
||
https://www.msn.com/en-us/money/personalfinance/money-matters-changing-institution-of-marriage/ar-AA
|
unknown
|
||
http://www.cyg8wm3zfb.xyz
|
unknown
|
||
http://www.desire-dating.com/he2a/.
|
unknown
|
||
https://www.msn.com/en-us/news/us/biden-administration-waives-26-federal-laws-to-allow-border-wall-c
|
unknown
|
||
https://www.msn.com/en-us/weather/topstories/california-s-reservoirs-runneth-over-in-astounding-reve
|
unknown
|
||
http://www.myjbtest.net
|
unknown
|
||
https://powerpoint.office.comEMd
|
unknown
|
||
http://www.oktravelhi.comReferer:
|
unknown
|
||
http://www.epeople.store/he2a/www.meet-friends.online
|
unknown
|
||
http://www.24eu-ru-startup.xyzReferer:
|
unknown
|
||
https://www.msn.com/en-us/news/technology/a-federal-emergency-alert-will-be-sent-to-us-phones-nation
|
unknown
|
||
https://api.msn.com/
|
unknown
|
||
https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DV-dark
|
unknown
|
||
https://www.msn.com:443/en-us/feed
|
unknown
|
There are 90 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
www.theaustralianbrisketboard.com
|
202.124.241.178
|
||
qfs-capital.com
|
192.227.130.26
|
||
www.oktravelhi.com
|
unknown
|
||
www.qfs-capital.com
|
unknown
|
||
www.giuila.online
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
202.124.241.178
|
www.theaustralianbrisketboard.com
|
Australia
|
||
192.227.130.26
|
qfs-capital.com
|
United States
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithProgids
|
Unpacker
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop
|
IconLayouts
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Security and Maintenance\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.102
|
CheckSetting
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
|
SlowContextMenuEntries
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
|
SlowContextMenuEntries
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
|
SlowContextMenuEntries
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2\OpenWithProgids
|
WMP11.AssocFile.3G2
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp\OpenWithProgids
|
WMP11.AssocFile.3GP
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2\OpenWithProgids
|
WMP11.AssocFile.3G2
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aac\OpenWithProgids
|
WMP11.AssocFile.ADTS
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.adt\OpenWithProgids
|
WMP11.AssocFile.ADTS
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\OpenWithProgids
|
WMP11.AssocFile.AIFF
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\OpenWithProgids
|
WMP11.AssocFile.ASF
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asx\OpenWithProgids
|
WMP11.AssocFile.ASX
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\OpenWithProgids
|
WMP11.AssocFile.AU
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au3\OpenWithProgids
|
AutoIt3Script
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\OpenWithProgids
|
WMP11.AssocFile.AVI
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\OpenWithProgids
|
Paint.Picture
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cab\OpenWithProgids
|
CABFolder
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cdxml\OpenWithProgids
|
Microsoft.PowerShellCmdletDefinitionXML.1
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.css\OpenWithProgids
|
CSSfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.csv\OpenWithProgids
|
Excel.CSV
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dds\OpenWithProgids
|
ddsfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dll\OpenWithProgids
|
dllfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.doc\OpenWithProgids
|
Word.Document.8
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.docm\OpenWithProgids
|
Word.DocumentMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.docx\OpenWithProgids
|
Word.Document.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dot\OpenWithProgids
|
Word.Template.8
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotm\OpenWithProgids
|
Word.TemplateMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotx\OpenWithProgids
|
Word.Template.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\OpenWithProgids
|
emffile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\OpenWithProgids
|
exefile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\OpenWithProgids
|
WMP11.AssocFile.FLAC
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fon\OpenWithProgids
|
fonfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\OpenWithProgids
|
giffile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\OpenWithProgids
|
htmlfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\OpenWithProgids
|
htmlfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ico\OpenWithProgids
|
icofile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inf\OpenWithProgids
|
inffile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ini\OpenWithProgids
|
inifile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\OpenWithProgids
|
pjpegfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\OpenWithProgids
|
jpegfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jxr\OpenWithProgids
|
wdpfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lnk\OpenWithProgids
|
lnkfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v\OpenWithProgids
|
WMP11.AssocFile.MPEG
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2t\OpenWithProgids
|
WMP11.AssocFile.M2TS
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\OpenWithProgids
|
WMP11.AssocFile.m3u
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\OpenWithProgids
|
WMP11.AssocFile.M4A
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v\OpenWithProgids
|
WMP11.AssocFile.MP4
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\OpenWithProgids
|
mhtmlfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\OpenWithProgids
|
WMP11.AssocFile.MIDI
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mk3d\OpenWithProgids
|
WMP11.AssocFile.MK3D
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mka\OpenWithProgids
|
WMP11.AssocFile.MKA
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mkv\OpenWithProgids
|
WMP11.AssocFile.MKV
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov\OpenWithProgids
|
WMP11.AssocFile.MOV
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MP2\OpenWithProgids
|
WMP11.AssocFile.MP3
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\OpenWithProgids
|
WMP11.AssocFile.MP4
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.msg\OpenWithProgids
|
Outlook.File.msg.15
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ocx\OpenWithProgids
|
ocxfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odp\OpenWithProgids
|
PowerPoint.OpenDocumentPresentation.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ods\OpenWithProgids
|
Excel.OpenDocumentSpreadsheet.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odt\OpenWithProgids
|
Word.OpenDocumentText.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.otf\OpenWithProgids
|
otffile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\OpenWithProgids
|
pngfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pot\OpenWithProgids
|
PowerPoint.Template.8
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potm\OpenWithProgids
|
PowerPoint.TemplateMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potx\OpenWithProgids
|
PowerPoint.Template.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppam\OpenWithProgids
|
PowerPoint.Addin.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsm\OpenWithProgids
|
PowerPoint.SlideShowMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsx\OpenWithProgids
|
PowerPoint.SlideShow.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppt\OpenWithProgids
|
PowerPoint.Show.8
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pptm\OpenWithProgids
|
PowerPoint.ShowMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pptx\OpenWithProgids
|
PowerPoint.Show.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ps1\OpenWithProgids
|
Microsoft.PowerShellScript.1
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ps1xml\OpenWithProgids
|
Microsoft.PowerShellXMLData.1
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd1\OpenWithProgids
|
Microsoft.PowerShellData.1
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psm1\OpenWithProgids
|
Microsoft.PowerShellModule.1
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pssc\OpenWithProgids
|
Microsoft.PowerShellSessionConfiguration.1
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\OpenWithProgids
|
rlefile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi\OpenWithProgids
|
WMP11.AssocFile.MIDI
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rtf\OpenWithProgids
|
Word.RTF.8
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.scf\OpenWithProgids
|
SHCmdFile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.search-ms\OpenWithProgids
|
SearchFolder
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\OpenWithProgids
|
shtmlfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sldm\OpenWithProgids
|
PowerPoint.SlideMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sldx\OpenWithProgids
|
PowerPoint.Slide.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sys\OpenWithProgids
|
sysfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\OpenWithProgids
|
TIFImage.Document
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TS\OpenWithProgids
|
WMP11.AssocFile.TTS
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\OpenWithProgids
|
ttcfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\OpenWithProgids
|
ttffile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt\OpenWithProgids
|
txtfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vsto\OpenWithProgids
|
bootstrap.vsto.1
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\OpenWithProgids
|
WMP11.AssocFile.WAV
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wax\OpenWithProgids
|
WMP11.AssocFile.WAX
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wdp\OpenWithProgids
|
wdpfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\OpenWithProgids
|
WMP11.AssocFile.ASF
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\OpenWithProgids
|
WMP11.AssocFile.WMA
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\OpenWithProgids
|
wmffile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\OpenWithProgids
|
WMP11.AssocFile.WMV
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.WPL\OpenWithProgids
|
WMP11.AssocFile.WPL
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wvx\OpenWithProgids
|
WMP11.AssocFile.WVX
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlam\OpenWithProgids
|
Excel.AddInMacroEnabled
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xls\OpenWithProgids
|
Excel.Sheet.8
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsb\OpenWithProgids
|
Excel.SheetBinaryMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsm\OpenWithProgids
|
Excel.SheetMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsx\OpenWithProgids
|
Excel.Sheet.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlt\OpenWithProgids
|
Excel.Template.8
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xltm\OpenWithProgids
|
Excel.TemplateMacroEnabled
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xltx\OpenWithProgids
|
Excel.Template
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xml\OpenWithProgids
|
xmlfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xsl\OpenWithProgids
|
xslfile
|
There are 126 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
980000
|
system
|
page execute and read and write
|
||
52C0000
|
trusted library section
|
page read and write
|
||
400000
|
remote allocation
|
page execute and read and write
|
||
2BB0000
|
unclassified section
|
page execute and read and write
|
||
2991000
|
trusted library allocation
|
page read and write
|
||
2BFE000
|
trusted library allocation
|
page read and write
|
||
3B6E000
|
trusted library allocation
|
page read and write
|
||
2F90000
|
trusted library allocation
|
page read and write
|
||
C034000
|
unkown
|
page read and write
|
||
7FF5DF45C000
|
unkown
|
page readonly
|
||
E2E3000
|
system
|
page execute and read and write
|
||
5D20000
|
trusted library allocation
|
page read and write
|
||
27F0000
|
unkown
|
page readonly
|
||
838B000
|
stack
|
page read and write
|
||
2DC0000
|
heap
|
page read and write
|
||
7FF5DF3F1000
|
unkown
|
page readonly
|
||
7FF5DF55A000
|
unkown
|
page readonly
|
||
73CD000
|
unkown
|
page read and write
|
||
ED88000
|
unkown
|
page read and write
|
||
7FF5DF156000
|
unkown
|
page readonly
|
||
BF7E000
|
unkown
|
page read and write
|
||
7FF5DF382000
|
unkown
|
page readonly
|
||
BFC2000
|
unkown
|
page read and write
|
||
9F27000
|
unkown
|
page read and write
|
||
95EE000
|
stack
|
page read and write
|
||
51DC000
|
stack
|
page read and write
|
||
7FF5DF0A5000
|
unkown
|
page readonly
|
||
7FF5DF2ED000
|
unkown
|
page readonly
|
||
9F0000
|
trusted library allocation
|
page read and write
|
||
73A7000
|
unkown
|
page read and write
|
||
A0B1000
|
unkown
|
page read and write
|
||
10506000
|
system
|
page read and write
|
||
7061000
|
trusted library allocation
|
page read and write
|
||
3107000
|
stack
|
page read and write
|
||
BFB3000
|
unkown
|
page read and write
|
||
1890000
|
heap
|
page read and write
|
||
7FF5DF58A000
|
unkown
|
page readonly
|
||
4824000
|
unkown
|
page read and write
|
||
28D3000
|
heap
|
page read and write
|
||
7FF5DF21C000
|
unkown
|
page readonly
|
||
A6FC000
|
unkown
|
page read and write
|
||
BFA3000
|
unkown
|
page read and write
|
||
2EB0000
|
heap
|
page read and write
|
||
BA76000
|
stack
|
page read and write
|
||
B9E0000
|
unkown
|
page read and write
|
||
7B50000
|
unkown
|
page readonly
|
||
C159000
|
unkown
|
page read and write
|
||
C24C000
|
unkown
|
page read and write
|
||
EDA2000
|
unkown
|
page read and write
|
||
163D000
|
direct allocation
|
page execute and read and write
|
||
7E7000
|
stack
|
page read and write
|
||
7FF5DF5BE000
|
unkown
|
page readonly
|
||
7FF5DF537000
|
unkown
|
page readonly
|
||
BF8C000
|
unkown
|
page read and write
|
||
7FF5DEF94000
|
unkown
|
page readonly
|
||
A744000
|
unkown
|
page read and write
|
||
A6D2000
|
unkown
|
page read and write
|
||
7DF5E895F000
|
unkown
|
page readonly
|
||
B500000
|
unkown
|
page readonly
|
||
4971000
|
trusted library allocation
|
page execute and read and write
|
||
4F56000
|
unclassified section
|
page read and write
|
||
7FF5DEFE2000
|
unkown
|
page readonly
|
||
7FF5DF458000
|
unkown
|
page readonly
|
||
BF84000
|
unkown
|
page read and write
|
||
11A0000
|
unkown
|
page readonly
|
||
4F42000
|
direct allocation
|
page execute and read and write
|
||
52D9000
|
unkown
|
page read and write
|
||
7FF5DEFAF000
|
unkown
|
page readonly
|
||
4F60000
|
trusted library allocation
|
page read and write
|
||
7FF5DF1CD000
|
unkown
|
page readonly
|
||
7FF5DF36A000
|
unkown
|
page readonly
|
||
ED8C000
|
unkown
|
page read and write
|
||
FFC2000
|
unkown
|
page read and write
|
||
484E000
|
stack
|
page read and write
|
||
C40D000
|
unkown
|
page read and write
|
||
970000
|
unkown
|
page readonly
|
||
8910000
|
unkown
|
page read and write
|
||
28DE000
|
stack
|
page read and write
|
||
ED71000
|
unkown
|
page read and write
|
||
47D9000
|
unkown
|
page read and write
|
||
4960000
|
trusted library allocation
|
page execute and read and write
|
||
E2BE000
|
system
|
page execute and read and write
|
||
E70000
|
unkown
|
page readonly
|
||
7FF5DF310000
|
unkown
|
page readonly
|
||
7FF5DF2FE000
|
unkown
|
page readonly
|
||
73AF000
|
unkown
|
page read and write
|
||
D0E000
|
stack
|
page read and write
|
||
7FF5DF20A000
|
unkown
|
page readonly
|
||
7FF5DF284000
|
unkown
|
page readonly
|
||
4810000
|
trusted library allocation
|
page read and write
|
||
7FF5DF16B000
|
unkown
|
page readonly
|
||
39E7000
|
trusted library allocation
|
page read and write
|
||
AFFE000
|
stack
|
page read and write
|
||
9FA0000
|
unkown
|
page read and write
|
||
1730000
|
unclassified section
|
page execute and read and write
|
||
32B0000
|
unkown
|
page read and write
|
||
980000
|
unkown
|
page readonly
|
||
8A36000
|
unkown
|
page read and write
|
||
9F7C000
|
unkown
|
page read and write
|
||
2980000
|
heap
|
page execute and read and write
|
||
7FF5DF507000
|
unkown
|
page readonly
|
||
7FF5DF3C6000
|
unkown
|
page readonly
|
||
7FF5DF380000
|
unkown
|
page readonly
|
||
7FF5DF519000
|
unkown
|
page readonly
|
||
A09A000
|
unkown
|
page read and write
|
||
2932000
|
trusted library allocation
|
page read and write
|
||
A08A000
|
unkown
|
page read and write
|
||
A707000
|
unkown
|
page read and write
|
||
A74E000
|
unkown
|
page read and write
|
||
DB0000
|
heap
|
page read and write
|
||
4FE2000
|
trusted library allocation
|
page read and write
|
||
BF98000
|
unkown
|
page read and write
|
||
7DF4E6760000
|
unkown
|
page readonly
|
||
2F10000
|
unkown
|
page read and write
|
||
894F000
|
stack
|
page read and write
|
||
C183000
|
unkown
|
page read and write
|
||
7FF5DF2FE000
|
unkown
|
page readonly
|
||
A106000
|
unkown
|
page read and write
|
||
2D5D000
|
stack
|
page read and write
|
||
7FF5DF4EC000
|
unkown
|
page readonly
|
||
D10000
|
trusted library allocation
|
page read and write
|
||
C39F000
|
unkown
|
page read and write
|
||
7FF5DF1CD000
|
unkown
|
page readonly
|
||
99AB000
|
unkown
|
page read and write
|
||
7FF5DF4A6000
|
unkown
|
page readonly
|
||
4750000
|
unkown
|
page read and write
|
||
2FCD000
|
heap
|
page read and write
|
||
49D0000
|
heap
|
page read and write
|
||
4810000
|
trusted library allocation
|
page read and write
|
||
A703000
|
unkown
|
page read and write
|
||
BFDF000
|
unkown
|
page read and write
|
||
B589000
|
stack
|
page read and write
|
||
7FF5DE539000
|
unkown
|
page readonly
|
||
7FF5DF582000
|
unkown
|
page readonly
|
||
52B0000
|
trusted library allocation
|
page execute and read and write
|
||
DE3000
|
heap
|
page read and write
|
||
2BE4000
|
heap
|
page read and write
|
||
7FF5DF54D000
|
unkown
|
page readonly
|
||
7FF5DF01B000
|
unkown
|
page readonly
|
||
48E0000
|
unkown
|
page read and write
|
||
9729000
|
unkown
|
page read and write
|
||
48B0000
|
unkown
|
page read and write
|
||
7FF5DF207000
|
unkown
|
page readonly
|
||
7FF5DF4E3000
|
unkown
|
page readonly
|
||
79E0000
|
unkown
|
page readonly
|
||
7FF5DEFF5000
|
unkown
|
page readonly
|
||
C39F000
|
unkown
|
page read and write
|
||
FF1000
|
unkown
|
page readonly
|
||
848E000
|
stack
|
page read and write
|
||
C319000
|
unkown
|
page read and write
|
||
A106000
|
unkown
|
page read and write
|
||
7DF4E6770000
|
unkown
|
page readonly
|
||
1499000
|
direct allocation
|
page execute and read and write
|
||
C1CC000
|
unkown
|
page read and write
|
||
7FF5DEFBD000
|
unkown
|
page readonly
|
||
C50C000
|
unkown
|
page read and write
|
||
7FF5DF0F6000
|
unkown
|
page readonly
|
||
C034000
|
unkown
|
page read and write
|
||
10C3000
|
trusted library allocation
|
page read and write
|
||
7380000
|
unkown
|
page read and write
|
||
BFB3000
|
unkown
|
page read and write
|
||
7FF5DEFAC000
|
unkown
|
page readonly
|
||
C45D000
|
unkown
|
page read and write
|
||
7DF4E6761000
|
unkown
|
page execute read
|
||
ED40000
|
unkown
|
page read and write
|
||
9F60000
|
unkown
|
page read and write
|
||
92DE000
|
stack
|
page read and write
|
||
4FD0000
|
heap
|
page read and write
|
||
9F92000
|
unkown
|
page read and write
|
||
B9F0000
|
unkown
|
page read and write
|
||
7FF5DF366000
|
unkown
|
page readonly
|
||
7FF5DF207000
|
unkown
|
page readonly
|
||
7FF5DF53F000
|
unkown
|
page readonly
|
||
7FF5DEF84000
|
unkown
|
page readonly
|
||
7FF5DF54D000
|
unkown
|
page readonly
|
||
7FF5DEF94000
|
unkown
|
page readonly
|
||
7FF5DF5B3000
|
unkown
|
page readonly
|
||
4EE0000
|
heap
|
page read and write
|
||
2BE4000
|
heap
|
page read and write
|
||
9C9C000
|
stack
|
page read and write
|
||
C34E000
|
unkown
|
page read and write
|
||
52D0000
|
trusted library allocation
|
page read and write
|
||
830F000
|
stack
|
page read and write
|
||
7FF5DF398000
|
unkown
|
page readonly
|
||
9700000
|
unkown
|
page read and write
|
||
ADC0000
|
unkown
|
page readonly
|
||
E91000
|
unkown
|
page read and write
|
||
A0FC000
|
unkown
|
page read and write
|
||
5480000
|
trusted library allocation
|
page execute and read and write
|
||
885D000
|
stack
|
page read and write
|
||
BF9F000
|
unkown
|
page read and write
|
||
7FF5DF537000
|
unkown
|
page readonly
|
||
ED8A000
|
unkown
|
page read and write
|
||
A0F7000
|
unkown
|
page read and write
|
||
B9F0000
|
unkown
|
page read and write
|
||
9718000
|
unkown
|
page read and write
|
||
BFA7000
|
unkown
|
page read and write
|
||
4860000
|
unkown
|
page read and write
|
||
ADC0000
|
unkown
|
page readonly
|
||
7FF5DF52D000
|
unkown
|
page readonly
|
||
3364000
|
unkown
|
page read and write
|
||
289E000
|
stack
|
page read and write
|
||
73B6000
|
unkown
|
page read and write
|
||
738E000
|
unkown
|
page read and write
|
||
2870000
|
unkown
|
page read and write
|
||
5200000
|
heap
|
page execute and read and write
|
||
134F000
|
stack
|
page read and write
|
||
7FF5DF2CB000
|
unkown
|
page readonly
|
||
978C000
|
unkown
|
page read and write
|
||
A0A7000
|
unkown
|
page read and write
|
||
E00000
|
heap
|
page read and write
|
||
EDA2000
|
unkown
|
page read and write
|
||
7FF5DF48B000
|
unkown
|
page readonly
|
||
10000000
|
unkown
|
page read and write
|
||
7FF5DF28E000
|
unkown
|
page readonly
|
||
7FF5DEE52000
|
unkown
|
page readonly
|
||
73BC000
|
unkown
|
page read and write
|
||
A50000
|
heap
|
page read and write
|
||
ED88000
|
unkown
|
page read and write
|
||
7A30000
|
unkown
|
page read and write
|
||
C35F000
|
unkown
|
page read and write
|
||
901B000
|
stack
|
page read and write
|
||
7FF5DF284000
|
unkown
|
page readonly
|
||
7399000
|
unkown
|
page read and write
|
||
7B50000
|
unkown
|
page readonly
|
||
E00000
|
heap
|
page read and write
|
||
7FF5DF36A000
|
unkown
|
page readonly
|
||
7FF5DF5B5000
|
unkown
|
page readonly
|
||
971A000
|
unkown
|
page read and write
|
||
3304000
|
unkown
|
page read and write
|
||
33C0000
|
unkown
|
page readonly
|
||
B11D000
|
stack
|
page read and write
|
||
D50000
|
unkown
|
page read and write
|
||
4766000
|
unkown
|
page read and write
|
||
A690000
|
unkown
|
page read and write
|
||
7FF5DEFFC000
|
unkown
|
page readonly
|
||
7FF5DF343000
|
unkown
|
page readonly
|
||
9099000
|
stack
|
page read and write
|
||
7FF5DF3A1000
|
unkown
|
page readonly
|
||
7FF5DF3F5000
|
unkown
|
page readonly
|
||
7FF5DF4C6000
|
unkown
|
page readonly
|
||
7FF5DF07D000
|
unkown
|
page readonly
|
||
EEA0000
|
heap
|
page read and write
|
||
7FF5DF0CC000
|
unkown
|
page readonly
|
||
97F3000
|
unkown
|
page read and write
|
||
F1F000
|
stack
|
page read and write
|
||
BF9D000
|
unkown
|
page read and write
|
||
7FF5DF01B000
|
unkown
|
page readonly
|
||
2BE4000
|
heap
|
page read and write
|
||
5D20000
|
trusted library allocation
|
page read and write
|
||
7FF5DF57F000
|
unkown
|
page readonly
|
||
C2E4000
|
unkown
|
page read and write
|
||
7FF5DF0F6000
|
unkown
|
page readonly
|
||
335B000
|
unkown
|
page read and write
|
||
7FF5DF45A000
|
unkown
|
page readonly
|
||
479B000
|
unkown
|
page read and write
|
||
7FF5DF067000
|
unkown
|
page readonly
|
||
7DF5E896A000
|
unkown
|
page readonly
|
||
753F000
|
unkown
|
page read and write
|
||
7FF5DF229000
|
unkown
|
page readonly
|
||
C525000
|
unkown
|
page read and write
|
||
7870000
|
unkown
|
page read and write
|
||
7FF5C0B65000
|
unkown
|
page readonly
|
||
9380000
|
unkown
|
page readonly
|
||
7FF5DF0CC000
|
unkown
|
page readonly
|
||
AB8D000
|
stack
|
page read and write
|
||
2E30000
|
unkown
|
page read and write
|
||
563F000
|
unclassified section
|
page read and write
|
||
9F63000
|
unkown
|
page read and write
|
||
C187000
|
unkown
|
page read and write
|
||
BD7F000
|
stack
|
page read and write
|
||
27D0000
|
unkown
|
page read and write
|
||
ED40000
|
unkown
|
page read and write
|
||
D62000
|
heap
|
page read and write
|
||
4828000
|
unkown
|
page read and write
|
||
7FF5DF211000
|
unkown
|
page readonly
|
||
9F10000
|
unkown
|
page read and write
|
||
7FF5DEFC2000
|
unkown
|
page readonly
|
||
32C0000
|
heap
|
page read and write
|
||
7FF5DF58A000
|
unkown
|
page readonly
|
||
9F0000
|
trusted library allocation
|
page read and write
|
||
7FF5DF519000
|
unkown
|
page readonly
|
||
C418000
|
unkown
|
page read and write
|
||
858E000
|
stack
|
page read and write
|
||
7FF5DF089000
|
unkown
|
page readonly
|
||
C071000
|
unkown
|
page read and write
|
||
52C3000
|
unkown
|
page read and write
|
||
7FF5DF429000
|
unkown
|
page readonly
|
||
C149000
|
unkown
|
page read and write
|
||
973C000
|
unkown
|
page read and write
|
||
BF82000
|
unkown
|
page read and write
|
||
4EF0000
|
trusted library allocation
|
page read and write
|
||
3999000
|
trusted library allocation
|
page read and write
|
||
4860000
|
unkown
|
page read and write
|
||
854E000
|
stack
|
page read and write
|
||
7FF5DF39C000
|
unkown
|
page readonly
|
||
7395000
|
unkown
|
page read and write
|
||
970C000
|
unkown
|
page read and write
|
||
BF40000
|
unkown
|
page read and write
|
||
4810000
|
trusted library allocation
|
page read and write
|
||
A6EA000
|
unkown
|
page read and write
|
||
7FF5DF2E2000
|
unkown
|
page readonly
|
||
A6D2000
|
unkown
|
page read and write
|
||
73B2000
|
unkown
|
page read and write
|
||
7FF5DF25B000
|
unkown
|
page readonly
|
||
7D89000
|
stack
|
page read and write
|
||
FF84000
|
unkown
|
page read and write
|
||
9F0000
|
trusted library allocation
|
page read and write
|
||
98A7000
|
unkown
|
page read and write
|
||
7FF5DF5F0000
|
unkown
|
page readonly
|
||
7FF5DF623000
|
unkown
|
page readonly
|
||
7FF5DF392000
|
unkown
|
page readonly
|
||
7FF5DF2E5000
|
unkown
|
page readonly
|
||
7FF5DF571000
|
unkown
|
page readonly
|
||
7FF5DF3E4000
|
unkown
|
page readonly
|
||
149D000
|
direct allocation
|
page execute and read and write
|
||
BFC3000
|
unkown
|
page read and write
|
||
7940000
|
unkown
|
page readonly
|
||
AB0D000
|
stack
|
page read and write
|
||
9F0000
|
trusted library allocation
|
page read and write
|
||
1195000
|
heap
|
page read and write
|
||
BFAB000
|
unkown
|
page read and write
|
||
7FF5DEFB7000
|
unkown
|
page readonly
|
||
7940000
|
unkown
|
page readonly
|
||
7FF5DF4F3000
|
unkown
|
page readonly
|
||
C140000
|
unkown
|
page read and write
|
||
BFEF000
|
unkown
|
page read and write
|
||
7FF5DF42F000
|
unkown
|
page readonly
|
||
ED7E000
|
unkown
|
page read and write
|
||
9E9E000
|
stack
|
page read and write
|
||
5D20000
|
trusted library allocation
|
page read and write
|
||
47A2000
|
unkown
|
page read and write
|
||
C354000
|
unkown
|
page read and write
|
||
34C0000
|
unkown
|
page read and write
|
||
9F63000
|
unkown
|
page read and write
|
||
7FF5DF41B000
|
unkown
|
page readonly
|
||
7FF5DF3BE000
|
unkown
|
page readonly
|
||
7800000
|
unkown
|
page read and write
|
||
7FF5DE9CB000
|
unkown
|
page readonly
|
||
7FF5DF4F3000
|
unkown
|
page readonly
|
||
2BE4000
|
heap
|
page read and write
|
||
47F1000
|
unkown
|
page read and write
|
||
7FF5DEEEB000
|
unkown
|
page readonly
|
||
D65000
|
heap
|
page read and write
|
||
7499000
|
unkown
|
page read and write
|
||
875A000
|
unkown
|
page read and write
|
||
7ACE000
|
stack
|
page read and write
|
||
98A7000
|
unkown
|
page read and write
|
||
98AD000
|
unkown
|
page read and write
|
||
4855000
|
unkown
|
page read and write
|
||
17EF000
|
unclassified section
|
page execute and read and write
|
||
BF9B000
|
unkown
|
page read and write
|
||
D5B000
|
stack
|
page read and write
|
||
2BE4000
|
heap
|
page read and write
|
||
7FF5DF067000
|
unkown
|
page readonly
|
||
9F0000
|
trusted library allocation
|
page read and write
|
||
C474000
|
unkown
|
page read and write
|
||
10EB000
|
trusted library allocation
|
page execute and read and write
|
||
9714000
|
unkown
|
page read and write
|
||
B010000
|
unkown
|
page read and write
|
||
2BE4000
|
heap
|
page read and write
|
||
7FF5DF2E2000
|
unkown
|
page readonly
|
||
3375000
|
unkown
|
page read and write
|
||
48A8000
|
heap
|
page read and write
|
||
7FF5DEE43000
|
unkown
|
page readonly
|
||
7FF5DF0C1000
|
unkown
|
page readonly
|
||
73A7000
|
unkown
|
page read and write
|
||
A6F9000
|
unkown
|
page read and write
|
||
73BC000
|
unkown
|
page read and write
|
||
77F0000
|
unkown
|
page read and write
|
||
B85000
|
heap
|
page read and write
|
||
C19D000
|
unkown
|
page read and write
|
||
9A6C000
|
stack
|
page read and write
|
||
7FF5DF539000
|
unkown
|
page readonly
|
||
2BE4000
|
heap
|
page read and write
|
||
7FF5DF45A000
|
unkown
|
page readonly
|
||
73A3000
|
unkown
|
page read and write
|
||
7FF5DF2CB000
|
unkown
|
page readonly
|
||
4D29000
|
direct allocation
|
page execute and read and write
|
||
52D9000
|
unkown
|
page read and write
|
||
BFA3000
|
unkown
|
page read and write
|
||
7A30000
|
unkown
|
page read and write
|
||
96F1000
|
unkown
|
page read and write
|
||
7800000
|
unkown
|
page read and write
|
||
7DF4E6791000
|
unkown
|
page execute read
|
||
9F51000
|
unkown
|
page read and write
|
||
C13F000
|
unkown
|
page read and write
|
||
C140000
|
unkown
|
page read and write
|
||
4710000
|
heap
|
page read and write
|
||
47D9000
|
unkown
|
page read and write
|
||
7FF5DF5A8000
|
unkown
|
page readonly
|
||
7FF5DF49C000
|
unkown
|
page readonly
|
||
73C3000
|
unkown
|
page read and write
|
||
9E0000
|
heap
|
page read and write
|
||
7FF5DF3F7000
|
unkown
|
page readonly
|
||
971C000
|
unkown
|
page read and write
|
||
2E9E000
|
stack
|
page read and write
|
||
7FF5DF349000
|
unkown
|
page readonly
|
||
DC5000
|
heap
|
page read and write
|
||
4F2D000
|
trusted library allocation
|
page read and write
|
||
7FF5DEF06000
|
unkown
|
page readonly
|
||
FE0000
|
unkown
|
page read and write
|
||
4DD0000
|
trusted library allocation
|
page execute and read and write
|
||
7FF5DF5B5000
|
unkown
|
page readonly
|
||
4810000
|
trusted library allocation
|
page read and write
|
||
C34E000
|
unkown
|
page read and write
|
||
5241000
|
unkown
|
page read and write
|
||
7FF5DF06F000
|
unkown
|
page readonly
|
||
C1C4000
|
unkown
|
page read and write
|
||
1100000
|
trusted library allocation
|
page read and write
|
||
C187000
|
unkown
|
page read and write
|
||
FFCB000
|
unkown
|
page read and write
|
||
5D5E000
|
stack
|
page read and write
|
||
BD7F000
|
stack
|
page read and write
|
||
9F0000
|
trusted library allocation
|
page read and write
|
||
73C3000
|
unkown
|
page read and write
|
||
4B81000
|
heap
|
page read and write
|
||
7FF5DEF87000
|
unkown
|
page readonly
|
||
4788000
|
unkown
|
page read and write
|
||
7FF5DF038000
|
unkown
|
page readonly
|
||
C1C4000
|
unkown
|
page read and write
|
||
2890000
|
unkown
|
page readonly
|
||
BF10000
|
unkown
|
page readonly
|
||
7FF5DF122000
|
unkown
|
page readonly
|
||
7FF5DF4D5000
|
unkown
|
page readonly
|
||
BF10000
|
unkown
|
page readonly
|
||
7DF5E896A000
|
unkown
|
page readonly
|
||
7910000
|
unkown
|
page readonly
|
||
96F1000
|
unkown
|
page read and write
|
||
C187000
|
unkown
|
page read and write
|
||
7FF5DF04D000
|
unkown
|
page readonly
|
||
8EA8000
|
stack
|
page read and write
|
||
7FF5DF18E000
|
unkown
|
page readonly
|
||
7FF5DF5F0000
|
unkown
|
page readonly
|
||
7FF5DEF90000
|
unkown
|
page readonly
|
||
34C0000
|
unkown
|
page read and write
|
||
124E000
|
stack
|
page read and write
|
||
7FF5DF3EA000
|
unkown
|
page readonly
|
||
7FF5DEE56000
|
unkown
|
page readonly
|
||
A0FC000
|
unkown
|
page read and write
|
||
7FF5DF486000
|
unkown
|
page readonly
|
||
C298000
|
unkown
|
page read and write
|
||
2E10000
|
heap
|
page read and write
|
||
7FF5DEFA6000
|
unkown
|
page readonly
|
||
1636000
|
direct allocation
|
page execute and read and write
|
||
E0F000
|
heap
|
page read and write
|
||
97C5000
|
unkown
|
page read and write
|
||
A0A5000
|
unkown
|
page read and write
|
||
2D1E000
|
stack
|
page read and write
|
||
7FF5DE539000
|
unkown
|
page readonly
|
||
7FF5DF089000
|
unkown
|
page readonly
|
||
7230000
|
unkown
|
page read and write
|
||
7FF5DF3EA000
|
unkown
|
page readonly
|
||
7FF5DF5CC000
|
unkown
|
page readonly
|
||
B010000
|
unkown
|
page read and write
|
||
7FF5DF47E000
|
unkown
|
page readonly
|
||
C43D000
|
unkown
|
page read and write
|
||
7FF5DF3FC000
|
unkown
|
page readonly
|
||
7FF5DF380000
|
unkown
|
page readonly
|
||
FE0000
|
unkown
|
page read and write
|
||
E70000
|
unkown
|
page readonly
|
||
7FF5DF248000
|
unkown
|
page readonly
|
||
7FF5DEFE8000
|
unkown
|
page readonly
|
||
98A1000
|
unkown
|
page read and write
|
||
7FF5DF43C000
|
unkown
|
page readonly
|
||
E30000
|
heap
|
page read and write
|
||
2D1E000
|
stack
|
page read and write
|
||
83B0000
|
unkown
|
page readonly
|
||
C1A9000
|
unkown
|
page read and write
|
||
9F27000
|
unkown
|
page read and write
|
||
EEA0000
|
heap
|
page read and write
|
||
7FF5DF221000
|
unkown
|
page readonly
|
||
7FF5DF017000
|
unkown
|
page readonly
|
||
83F0000
|
unkown
|
page read and write
|
||
336F000
|
unkown
|
page read and write
|
||
ED9F000
|
unkown
|
page read and write
|
||
5280000
|
trusted library section
|
page read and write
|
||
5C50000
|
heap
|
page read and write
|
||
A072000
|
unkown
|
page read and write
|
||
7FF5DF045000
|
unkown
|
page readonly
|
||
FF03000
|
unkown
|
page read and write
|
||
B45A000
|
stack
|
page read and write
|
||
7FF5DE4F2000
|
unkown
|
page readonly
|
||
28D0000
|
heap
|
page read and write
|
||
7FF5DF4EC000
|
unkown
|
page readonly
|
||
4711000
|
heap
|
page read and write
|
||
7FF5DF5D6000
|
unkown
|
page readonly
|
||
96F5000
|
unkown
|
page read and write
|
||
7FF5C0B65000
|
unkown
|
page readonly
|
||
7FF5DF25E000
|
unkown
|
page readonly
|
||
7FF5DEF4B000
|
unkown
|
page readonly
|
||
970000
|
unkown
|
page readonly
|
||
9D9F000
|
stack
|
page read and write
|
||
7FF5DF591000
|
unkown
|
page readonly
|
||
962B000
|
unkown
|
page read and write
|
||
4F90000
|
trusted library allocation
|
page read and write
|
||
AEF0000
|
unkown
|
page read and write
|
||
10C0000
|
trusted library allocation
|
page read and write
|
||
7FF5DE5CC000
|
unkown
|
page readonly
|
||
4F65000
|
trusted library allocation
|
page read and write
|
||
7FF5DF2ED000
|
unkown
|
page readonly
|
||
A104000
|
unkown
|
page read and write
|
||
A08A000
|
unkown
|
page read and write
|
||
7840000
|
unkown
|
page read and write
|
||
D2A000
|
heap
|
page read and write
|
||
B1C0000
|
unkown
|
page readonly
|
||
7FF5DF62C000
|
unkown
|
page readonly
|
||
A6EE000
|
unkown
|
page read and write
|
||
7FF5DF2DA000
|
unkown
|
page readonly
|
||
9B1D000
|
stack
|
page read and write
|
||
88E0000
|
unkown
|
page read and write
|
||
980000
|
unkown
|
page readonly
|
||
7870000
|
unkown
|
page read and write
|
||
1723000
|
unclassified section
|
page execute and read and write
|
||
950C000
|
stack
|
page read and write
|
||
7FF5DF3BE000
|
unkown
|
page readonly
|
||
73BA000
|
unkown
|
page read and write
|
||
7FF5DF169000
|
unkown
|
page readonly
|
||
A6F9000
|
unkown
|
page read and write
|
||
ED88000
|
unkown
|
page read and write
|
||
7FF5DEFAF000
|
unkown
|
page readonly
|
||
BFAB000
|
unkown
|
page read and write
|
||
3382000
|
unkown
|
page read and write
|
||
7FF5DF156000
|
unkown
|
page readonly
|
||
2EC0000
|
unkown
|
page readonly
|
||
2BE4000
|
heap
|
page read and write
|
||
4828000
|
unkown
|
page read and write
|
||
C192000
|
unkown
|
page read and write
|
||
5A0000
|
unkown
|
page readonly
|
||
7FF5DF5B0000
|
unkown
|
page readonly
|
||
7499000
|
unkown
|
page read and write
|
||
7FF5DF59E000
|
unkown
|
page readonly
|
||
4B85000
|
heap
|
page read and write
|
||
73A3000
|
unkown
|
page read and write
|
||
7FF5DF191000
|
unkown
|
page readonly
|
||
A0A7000
|
unkown
|
page read and write
|
||
7FF5DF5CC000
|
unkown
|
page readonly
|
||
9F0000
|
heap
|
page read and write
|
||
83B0000
|
unkown
|
page readonly
|
||
5290000
|
trusted library allocation
|
page execute and read and write
|
||
2FD8000
|
heap
|
page read and write
|
||
7FF5DF095000
|
unkown
|
page readonly
|
||
7FF5DE9CB000
|
unkown
|
page readonly
|
||
4A00000
|
trusted library allocation
|
page execute and read and write
|
||
C4FD000
|
unkown
|
page read and write
|
||
7FF5DF488000
|
unkown
|
page readonly
|
||
7FF5DEF57000
|
unkown
|
page readonly
|
||
2C5D000
|
stack
|
page read and write
|
||
ED72000
|
unkown
|
page read and write
|
||
7FF5DF366000
|
unkown
|
page readonly
|
||
7FF5DF52D000
|
unkown
|
page readonly
|
||
7FF5DF5A3000
|
unkown
|
page readonly
|
||
AD2B000
|
stack
|
page read and write
|
||
C18A000
|
unkown
|
page read and write
|
||
7FF5DF43C000
|
unkown
|
page readonly
|
||
F71000
|
unkown
|
page read and write
|
||
9F0000
|
heap
|
page read and write
|
||
28A0000
|
unkown
|
page readonly
|
||
7FF5DF5E9000
|
unkown
|
page readonly
|
||
7B60000
|
unkown
|
page readonly
|
||
7FF5DF349000
|
unkown
|
page readonly
|
||
7FF5DF25E000
|
unkown
|
page readonly
|
||
320C000
|
stack
|
page read and write
|
||
7FF5DF41B000
|
unkown
|
page readonly
|
||
884F000
|
stack
|
page read and write
|
||
ED7D000
|
unkown
|
page read and write
|
||
BFA5000
|
unkown
|
page read and write
|
||
C1CC000
|
unkown
|
page read and write
|
||
962B000
|
unkown
|
page read and write
|
||
7FF5DF551000
|
unkown
|
page readonly
|
||
FF4B000
|
unkown
|
page read and write
|
||
7FF5DEE43000
|
unkown
|
page readonly
|
||
7991000
|
unkown
|
page read and write
|
||
970C000
|
unkown
|
page read and write
|
||
28E0000
|
trusted library allocation
|
page read and write
|
||
BF9F000
|
unkown
|
page read and write
|
||
C5C000
|
stack
|
page read and write
|
||
47B6000
|
unkown
|
page read and write
|
||
4F00000
|
trusted library allocation
|
page read and write
|
||
4F1E000
|
trusted library allocation
|
page read and write
|
||
6EA000
|
stack
|
page read and write
|
||
7FF5DF0C9000
|
unkown
|
page readonly
|
||
9F51000
|
unkown
|
page read and write
|
||
7FF5DF567000
|
unkown
|
page readonly
|
||
9F3E000
|
unkown
|
page read and write
|
||
A6CF000
|
unkown
|
page read and write
|
||
7FF5DF2BA000
|
unkown
|
page readonly
|
||
BFAD000
|
unkown
|
page read and write
|
||
2BE4000
|
heap
|
page read and write
|
||
A6FD000
|
unkown
|
page read and write
|
||
10DA000
|
trusted library allocation
|
page execute and read and write
|
||
74A9000
|
unkown
|
page read and write
|
||
7FF5DF2E5000
|
unkown
|
page readonly
|
||
88DE000
|
stack
|
page read and write
|
||
7FF5DE531000
|
unkown
|
page readonly
|
||
2890000
|
unkown
|
page readonly
|
||
7FF5DF50F000
|
unkown
|
page readonly
|
||
8390000
|
unkown
|
page read and write
|
||
9716000
|
unkown
|
page read and write
|
||
C45E000
|
unkown
|
page read and write
|
||
7FF5DF5D6000
|
unkown
|
page readonly
|
||
9605000
|
unkown
|
page read and write
|
||
2A28000
|
trusted library allocation
|
page read and write
|
||
A744000
|
unkown
|
page read and write
|
||
BF82000
|
unkown
|
page read and write
|
||
2790000
|
heap
|
page read and write
|
||
BF84000
|
unkown
|
page read and write
|
||
514F000
|
unclassified section
|
page read and write
|
||
7380000
|
unkown
|
page read and write
|
||
9F74000
|
unkown
|
page read and write
|
||
7FF5DF0D2000
|
unkown
|
page readonly
|
||
7FF5DF3F5000
|
unkown
|
page readonly
|
||
C13B000
|
unkown
|
page read and write
|
||
A02D000
|
unkown
|
page read and write
|
||
2BE4000
|
heap
|
page read and write
|
||
2FCF000
|
heap
|
page read and write
|
||
7FF5DF49C000
|
unkown
|
page readonly
|
||
9C1F000
|
stack
|
page read and write
|
||
C35C000
|
unkown
|
page read and write
|
||
9B99000
|
stack
|
page read and write
|
||
7D0D000
|
stack
|
page read and write
|
||
7FF5DF4E3000
|
unkown
|
page readonly
|
||
4890000
|
heap
|
page read and write
|
||
7FF5DF26F000
|
unkown
|
page readonly
|
||
7860000
|
unkown
|
page read and write
|
||
F28000
|
stack
|
page read and write
|
||
5D20000
|
trusted library allocation
|
page read and write
|
||
D2E000
|
heap
|
page read and write
|
||
2930000
|
trusted library allocation
|
page read and write
|
||
276E000
|
stack
|
page read and write
|
||
7FF5DEFE2000
|
unkown
|
page readonly
|
||
B09F000
|
stack
|
page read and write
|
||
A08D000
|
unkown
|
page read and write
|
||
C429000
|
unkown
|
page read and write
|
||
7FF5DF361000
|
unkown
|
page readonly
|
||
7FF5DF4FB000
|
unkown
|
page readonly
|
||
B60A000
|
stack
|
page read and write
|
||
7FF5DF5B3000
|
unkown
|
page readonly
|
||
E5D000
|
heap
|
page read and write
|
||
9C9C000
|
stack
|
page read and write
|
||
7FF5DF0A2000
|
unkown
|
page readonly
|
||
7FF5DF458000
|
unkown
|
page readonly
|
||
FEC4000
|
unkown
|
page read and write
|
||
7FF5DF388000
|
unkown
|
page readonly
|
||
3356000
|
unkown
|
page read and write
|
||
9605000
|
unkown
|
page read and write
|
||
7FF5DF623000
|
unkown
|
page readonly
|
||
3107000
|
stack
|
page read and write
|
||
47B6000
|
unkown
|
page read and write
|
||
10B4000
|
trusted library allocation
|
page read and write
|
||
7830000
|
unkown
|
page read and write
|
||
13A1000
|
unkown
|
page readonly
|
||
5330000
|
trusted library allocation
|
page read and write
|
||
9564000
|
unkown
|
page read and write
|
||
A748000
|
unkown
|
page read and write
|
||
7FF5DF08B000
|
unkown
|
page readonly
|
||
5A2000
|
unkown
|
page readonly
|
||
7FF5DF4BD000
|
unkown
|
page readonly
|
||
EEA2000
|
heap
|
page read and write
|
||
AE6F000
|
stack
|
page read and write
|
||
7FF5DF3AA000
|
unkown
|
page readonly
|
||
7FF5DF626000
|
unkown
|
page readonly
|
||
4F40000
|
trusted library allocation
|
page read and write
|
||
9F3E000
|
unkown
|
page read and write
|
||
4EE3000
|
heap
|
page read and write
|
||
4711000
|
heap
|
page read and write
|
||
7DF4E6771000
|
unkown
|
page execute read
|
||
8910000
|
unkown
|
page read and write
|
||
C4C5000
|
unkown
|
page read and write
|
||
C048000
|
unkown
|
page read and write
|
||
7DF4E6761000
|
unkown
|
page execute read
|
||
B11D000
|
stack
|
page read and write
|
||
7FF5DF4A6000
|
unkown
|
page readonly
|
||
BF6D000
|
unkown
|
page read and write
|
||
A0F7000
|
unkown
|
page read and write
|
||
8400000
|
heap
|
page read and write
|
||
4711000
|
heap
|
page read and write
|
||
7FF5DF507000
|
unkown
|
page readonly
|
||
2BE4000
|
heap
|
page read and write
|
||
7FF5C0B6B000
|
unkown
|
page readonly
|
||
7FF5DF42F000
|
unkown
|
page readonly
|
||
ED8C000
|
unkown
|
page read and write
|
||
874E000
|
stack
|
page read and write
|
||
7FF5DEFDD000
|
unkown
|
page readonly
|
||
7FF5DF396000
|
unkown
|
page readonly
|
||
7FF5DF0C1000
|
unkown
|
page readonly
|
||
9F78000
|
unkown
|
page read and write
|
||
A02D000
|
unkown
|
page read and write
|
||
7FF5DF3B5000
|
unkown
|
page readonly
|
||
7FF5DEF87000
|
unkown
|
page readonly
|
||
2E0E000
|
unkown
|
page read and write
|
||
4F5F000
|
trusted library allocation
|
page read and write
|
||
7FF5DF12A000
|
unkown
|
page readonly
|
||
73E5000
|
unkown
|
page read and write
|
||
7FF5DF038000
|
unkown
|
page readonly
|
||
7FF5DF3AA000
|
unkown
|
page readonly
|
||
7FF5DF5FC000
|
unkown
|
page readonly
|
||
8590000
|
unkown
|
page readonly
|
||
7FF5DF5AE000
|
unkown
|
page readonly
|
||
2E50000
|
heap
|
page read and write
|
||
73CD000
|
unkown
|
page read and write
|
||
2F10000
|
unkown
|
page read and write
|
||
BF9B000
|
unkown
|
page read and write
|
||
7FF5DF382000
|
unkown
|
page readonly
|
||
5110000
|
unkown
|
page write copy
|
||
EEAA000
|
heap
|
page read and write
|
||
874C000
|
stack
|
page read and write
|
||
E06000
|
heap
|
page read and write
|
||
7FF5DF0A2000
|
unkown
|
page readonly
|
||
E2BC000
|
system
|
page execute and read and write
|
||
7B4B000
|
stack
|
page read and write
|
||
7FF5DF443000
|
unkown
|
page readonly
|
||
7FF5DF48B000
|
unkown
|
page readonly
|
||
BFA1000
|
unkown
|
page read and write
|
||
3364000
|
unkown
|
page read and write
|
||
BA76000
|
stack
|
page read and write
|
||
7C85000
|
stack
|
page read and write
|
||
C192000
|
unkown
|
page read and write
|
||
C1CC000
|
unkown
|
page read and write
|
||
7FF5DF549000
|
unkown
|
page readonly
|
||
FFD9000
|
unkown
|
page read and write
|
||
ED74000
|
unkown
|
page read and write
|
||
7FF5DF443000
|
unkown
|
page readonly
|
||
F18000
|
heap
|
page read and write
|
||
2E30000
|
unkown
|
page read and write
|
||
2BE4000
|
heap
|
page read and write
|
||
BCE000
|
stack
|
page read and write
|
||
7FF5DEFFC000
|
unkown
|
page readonly
|
||
7FF5DF2F3000
|
unkown
|
page readonly
|
||
A758000
|
unkown
|
page read and write
|
||
BF40000
|
unkown
|
page read and write
|
||
FF84000
|
unkown
|
page read and write
|
||
3394000
|
unkown
|
page read and write
|
||
4F30000
|
trusted library allocation
|
page read and write
|
||
2EB0000
|
unkown
|
page readonly
|
||
90C000
|
stack
|
page read and write
|
||
7FF5DF08F000
|
unkown
|
page readonly
|
||
7FF5DF21F000
|
unkown
|
page readonly
|
||
B359000
|
stack
|
page read and write
|
||
9D9F000
|
stack
|
page read and write
|
||
7FF5DF0D2000
|
unkown
|
page readonly
|
||
7FF5DF211000
|
unkown
|
page readonly
|
||
7FF5DEF57000
|
unkown
|
page readonly
|
||
ACAF000
|
stack
|
page read and write
|
||
7FF5DF20A000
|
unkown
|
page readonly
|
||
7FF5DF584000
|
unkown
|
page readonly
|
||
FF46000
|
unkown
|
page read and write
|
||
7FF5DF4AB000
|
unkown
|
page readonly
|
||
28D0000
|
heap
|
page read and write
|
||
1190000
|
heap
|
page read and write
|
||
ED8C000
|
unkown
|
page read and write
|
||
A6F1000
|
unkown
|
page read and write
|
||
7FF5DF5F6000
|
unkown
|
page readonly
|
||
73AF000
|
unkown
|
page read and write
|
||
9700000
|
unkown
|
page read and write
|
||
AEEE000
|
stack
|
page read and write
|
||
B359000
|
stack
|
page read and write
|
||
7FF5DF4F7000
|
unkown
|
page readonly
|
||
2FD9000
|
heap
|
page read and write
|
||
D98000
|
heap
|
page read and write
|
||
E00000
|
heap
|
page read and write
|
||
7FF5DEF84000
|
unkown
|
page readonly
|
||
7FF5DF0C3000
|
unkown
|
page readonly
|
||
7FF5DF4F7000
|
unkown
|
page readonly
|
||
3371000
|
unkown
|
page read and write
|
||
7FF5DF081000
|
unkown
|
page readonly
|
||
3281000
|
stack
|
page read and write
|
||
3356000
|
unkown
|
page read and write
|
||
7FF5DF08B000
|
unkown
|
page readonly
|
||
C01A000
|
unkown
|
page read and write
|
||
7FF5DF3DF000
|
unkown
|
page readonly
|
||
7FF5DEFCB000
|
unkown
|
page readonly
|
||
7FF5DF0F1000
|
unkown
|
page readonly
|
||
987C000
|
unkown
|
page read and write
|
||
73B6000
|
unkown
|
page read and write
|
||
7FF5DF3F7000
|
unkown
|
page readonly
|
||
7FF5DEE4E000
|
unkown
|
page readonly
|
||
4810000
|
trusted library allocation
|
page read and write
|
||
BFAF000
|
unkown
|
page read and write
|
||
971A000
|
unkown
|
page read and write
|
||
728E000
|
stack
|
page read and write
|
||
7FF5DF0C3000
|
unkown
|
page readonly
|
||
B45A000
|
stack
|
page read and write
|
||
1720000
|
unclassified section
|
page execute and read and write
|
||
BFAF000
|
unkown
|
page read and write
|
||
95F0000
|
unkown
|
page read and write
|
||
ED8A000
|
unkown
|
page read and write
|
||
B589000
|
stack
|
page read and write
|
||
7FF5DF398000
|
unkown
|
page readonly
|
||
16B8000
|
direct allocation
|
page execute and read and write
|
||
C354000
|
unkown
|
page read and write
|
||
A09A000
|
unkown
|
page read and write
|
||
C42C000
|
unkown
|
page read and write
|
||
C183000
|
unkown
|
page read and write
|
||
1190000
|
heap
|
page read and write
|
||
7FF5DF126000
|
unkown
|
page readonly
|
||
3185000
|
stack
|
page read and write
|
||
7A40000
|
unkown
|
page readonly
|
||
C030000
|
unkown
|
page read and write
|
||
A74E000
|
unkown
|
page read and write
|
||
A759000
|
unkown
|
page read and write
|
||
7FF5DF392000
|
unkown
|
page readonly
|
||
7FF5DF571000
|
unkown
|
page readonly
|
||
3375000
|
unkown
|
page read and write
|
||
C2E4000
|
unkown
|
page read and write
|
||
96F5000
|
unkown
|
page read and write
|
||
9729000
|
unkown
|
page read and write
|
||
339C000
|
unkown
|
page read and write
|
||
B4DB000
|
stack
|
page read and write
|
||
7FF5DF396000
|
unkown
|
page readonly
|
||
7FF5DF5FF000
|
unkown
|
page readonly
|
||
2B50000
|
heap
|
page read and write
|
||
973C000
|
unkown
|
page read and write
|
||
DAE000
|
heap
|
page read and write
|
||
B9E0000
|
unkown
|
page read and write
|
||
DBC000
|
heap
|
page read and write
|
||
940B000
|
stack
|
page read and write
|
||
9FA0000
|
unkown
|
page read and write
|
||
BFC0000
|
unkown
|
page read and write
|
||
7FF5DF388000
|
unkown
|
page readonly
|
||
7930000
|
unkown
|
page readonly
|
||
A758000
|
unkown
|
page read and write
|
||
C159000
|
unkown
|
page read and write
|
||
2BE4000
|
heap
|
page read and write
|
||
9F23000
|
unkown
|
page read and write
|
||
88E0000
|
unkown
|
page read and write
|
||
7909000
|
stack
|
page read and write
|
||
7FF5DEFAC000
|
unkown
|
page readonly
|
||
3362000
|
unkown
|
page read and write
|
||
3394000
|
unkown
|
page read and write
|
||
97C0000
|
unkown
|
page read and write
|
||
F71000
|
unkown
|
page read and write
|
||
A098000
|
unkown
|
page read and write
|
||
7FF5DF577000
|
unkown
|
page readonly
|
||
9FC3000
|
unkown
|
page read and write
|
||
9E0000
|
unkown
|
page readonly
|
||
BFA5000
|
unkown
|
page read and write
|
||
7FF5DF3E4000
|
unkown
|
page readonly
|
||
7FF5DEFDD000
|
unkown
|
page readonly
|
||
34B0000
|
unkown
|
page readonly
|
||
C013000
|
unkown
|
page read and write
|
||
95EE000
|
stack
|
page read and write
|
||
9C1F000
|
stack
|
page read and write
|
||
48AD000
|
heap
|
page read and write
|
||
487A000
|
unkown
|
page read and write
|
||
7FF5DEE5A000
|
unkown
|
page readonly
|
||
7FF5DF23A000
|
unkown
|
page readonly
|
||
FF03000
|
unkown
|
page read and write
|
||
74D6000
|
unkown
|
page read and write
|
||
9F0000
|
trusted library allocation
|
page read and write
|
||
5190000
|
trusted library allocation
|
page read and write
|
||
7FF5DF3A1000
|
unkown
|
page readonly
|
||
2BE4000
|
heap
|
page read and write
|
||
C474000
|
unkown
|
page read and write
|
||
7C89000
|
stack
|
page read and write
|
||
7FF5DEFF0000
|
unkown
|
page readonly
|
||
8400000
|
heap
|
page read and write
|
||
F28000
|
stack
|
page read and write
|
||
7FF5DF06F000
|
unkown
|
page readonly
|
||
E250000
|
system
|
page execute and read and write
|
||
7FF5DF126000
|
unkown
|
page readonly
|
||
9380000
|
unkown
|
page readonly
|
||
BF6D000
|
unkown
|
page read and write
|
||
ED71000
|
unkown
|
page read and write
|
||
FF1000
|
unkown
|
page readonly
|
||
5D20000
|
trusted library allocation
|
page read and write
|
||
C159000
|
unkown
|
page read and write
|
||
4855000
|
unkown
|
page read and write
|
||
7FF5DF0C9000
|
unkown
|
page readonly
|
||
3290000
|
unkown
|
page readonly
|
||
7FF5DF47E000
|
unkown
|
page readonly
|
||
92DD000
|
stack
|
page read and write
|
||
7FF5DEFE8000
|
unkown
|
page readonly
|
||
5D20000
|
trusted library allocation
|
page read and write
|
||
7D90000
|
unkown
|
page read and write
|
||
A690000
|
unkown
|
page read and write
|
||
7FF5DEE56000
|
unkown
|
page readonly
|
||
7FF5DEFF8000
|
unkown
|
page readonly
|
||
DCD000
|
heap
|
page read and write
|
||
987C000
|
unkown
|
page read and write
|
||
C319000
|
unkown
|
page read and write
|
||
7FF5DF081000
|
unkown
|
page readonly
|
||
7FF5DF57F000
|
unkown
|
page readonly
|
||
7FF5DF5B0000
|
unkown
|
page readonly
|
||
E10000
|
trusted library allocation
|
page execute and read and write
|
||
C39F000
|
unkown
|
page read and write
|
||
7FF5DEE4E000
|
unkown
|
page readonly
|
||
27F0000
|
unkown
|
page readonly
|
||
9F2A000
|
unkown
|
page read and write
|
||
7FF5DF029000
|
unkown
|
page readonly
|
||
7D90000
|
unkown
|
page read and write
|
||
73B4000
|
unkown
|
page read and write
|
||
AB0D000
|
stack
|
page read and write
|
||
48A0000
|
unkown
|
page read and write
|
||
2EB7000
|
heap
|
page read and write
|
||
7FF5DF2F3000
|
unkown
|
page readonly
|
||
AE6F000
|
stack
|
page read and write
|
||
BF90000
|
unkown
|
page read and write
|
||
10D6000
|
trusted library allocation
|
page execute and read and write
|
||
7399000
|
unkown
|
page read and write
|
||
83D0000
|
unkown
|
page read and write
|
||
2870000
|
unkown
|
page read and write
|
||
7FF5DEFF8000
|
unkown
|
page readonly
|
||
B60A000
|
stack
|
page read and write
|
||
3371000
|
unkown
|
page read and write
|
||
7FF5DF60D000
|
unkown
|
page readonly
|
||
B80000
|
heap
|
page read and write
|
||
83E0000
|
unkown
|
page read and write
|
||
7FF5DEFBD000
|
unkown
|
page readonly
|
||
B4DB000
|
stack
|
page read and write
|
||
10B0000
|
trusted library allocation
|
page read and write
|
||
7FF5DF191000
|
unkown
|
page readonly
|
||
C23D000
|
unkown
|
page read and write
|
||
7FF5DF435000
|
unkown
|
page readonly
|
||
7FF5DF582000
|
unkown
|
page readonly
|
||
77F0000
|
unkown
|
page read and write
|
||
FFD9000
|
unkown
|
page read and write
|
||
2FC0000
|
heap
|
page read and write
|
||
BF7E000
|
unkown
|
page read and write
|
||
935B000
|
stack
|
page read and write
|
||
9FC3000
|
unkown
|
page read and write
|
||
7840000
|
unkown
|
page read and write
|
||
C40F000
|
unkown
|
page read and write
|
||
7930000
|
unkown
|
page readonly
|
||
7FF5DF435000
|
unkown
|
page readonly
|
||
7FF5DF62C000
|
unkown
|
page readonly
|
||
7FF5DF478000
|
unkown
|
page readonly
|
||
8C29000
|
stack
|
page read and write
|
||
7FF5DF09B000
|
unkown
|
page readonly
|
||
B830000
|
unkown
|
page readonly
|
||
7FF5DF3B9000
|
unkown
|
page readonly
|
||
C19D000
|
unkown
|
page read and write
|
||
2BE0000
|
heap
|
page read and write
|
||
B259000
|
stack
|
page read and write
|
||
989F000
|
unkown
|
page read and write
|
||
A08D000
|
unkown
|
page read and write
|
||
16DF000
|
unclassified section
|
page execute and read and write
|
||
4FE0000
|
trusted library allocation
|
page read and write
|
||
7FF5DF3B5000
|
unkown
|
page readonly
|
||
7FF5DF361000
|
unkown
|
page readonly
|
||
4ECD000
|
direct allocation
|
page execute and read and write
|
||
C13A000
|
unkown
|
page read and write
|
||
10BD000
|
trusted library allocation
|
page execute and read and write
|
||
4BCF000
|
stack
|
page read and write
|
||
4A11000
|
trusted library allocation
|
page execute and read and write
|
||
4C00000
|
direct allocation
|
page execute and read and write
|
||
106FF000
|
system
|
page read and write
|
||
A072000
|
unkown
|
page read and write
|
||
3290000
|
unkown
|
page readonly
|
||
3382000
|
unkown
|
page read and write
|
||
27D0000
|
unkown
|
page read and write
|
||
4750000
|
unkown
|
page read and write
|
||
7B4B000
|
stack
|
page read and write
|
||
3373000
|
unkown
|
page read and write
|
||
4760000
|
unkown
|
page read and write
|
||
2EC0000
|
unkown
|
page readonly
|
||
B9BF000
|
stack
|
page read and write
|
||
28A0000
|
unkown
|
page readonly
|
||
7FF5DF12A000
|
unkown
|
page readonly
|
||
4F21000
|
trusted library allocation
|
page read and write
|
||
C048000
|
unkown
|
page read and write
|
||
C4C4000
|
unkown
|
page read and write
|
||
7FF5DF452000
|
unkown
|
page readonly
|
||
5A60000
|
heap
|
page read and write
|
||
C1A9000
|
unkown
|
page read and write
|
||
7FF5DF09B000
|
unkown
|
page readonly
|
||
7FF5DF091000
|
unkown
|
page readonly
|
||
10E2000
|
trusted library allocation
|
page read and write
|
||
874C000
|
stack
|
page read and write
|
||
7FF5DF2BA000
|
unkown
|
page readonly
|
||
7DF4E67A1000
|
unkown
|
page execute read
|
||
7FF5DF04D000
|
unkown
|
page readonly
|
||
74F1000
|
unkown
|
page read and write
|
||
7FF5DEFC2000
|
unkown
|
page readonly
|
||
7FF5DF2DA000
|
unkown
|
page readonly
|
||
7FF5DF577000
|
unkown
|
page readonly
|
||
336C000
|
unkown
|
page read and write
|
||
9714000
|
unkown
|
page read and write
|
||
95F0000
|
unkown
|
page read and write
|
||
A6EA000
|
unkown
|
page read and write
|
||
A098000
|
unkown
|
page read and write
|
||
ED9F000
|
unkown
|
page read and write
|
||
4DE0000
|
heap
|
page read and write
|
||
C4EF000
|
unkown
|
page read and write
|
||
7FF5DF4D5000
|
unkown
|
page readonly
|
||
875A000
|
unkown
|
page read and write
|
||
7FF5DF24E000
|
unkown
|
page readonly
|
||
7FF5DF364000
|
unkown
|
page readonly
|
||
D50000
|
unkown
|
page read and write
|
||
2C9A000
|
stack
|
page read and write
|
||
73B8000
|
unkown
|
page read and write
|
||
96DF000
|
unkown
|
page read and write
|
||
7FF5DF3C6000
|
unkown
|
page readonly
|
||
7FF5DF429000
|
unkown
|
page readonly
|
||
83F0000
|
unkown
|
page read and write
|
||
7FF5DF45C000
|
unkown
|
page readonly
|
||
1195000
|
heap
|
page read and write
|
||
7FF5DE535000
|
unkown
|
page readonly
|
||
7DF4E6780000
|
unkown
|
page readonly
|
||
914B000
|
stack
|
page read and write
|
||
16C0000
|
unclassified section
|
page execute and read and write
|
||
4B4F000
|
stack
|
page read and write
|
||
AD2B000
|
stack
|
page read and write
|
||
7FF5DF5FF000
|
unkown
|
page readonly
|
||
7FF5DF3D4000
|
unkown
|
page readonly
|
||
B30000
|
heap
|
page read and write
|
||
7FF5DF5E9000
|
unkown
|
page readonly
|
||
7A40000
|
unkown
|
page readonly
|
||
8EA8000
|
stack
|
page read and write
|
||
7FF5DE5CC000
|
unkown
|
page readonly
|
||
C34E000
|
unkown
|
page read and write
|
||
7FF5DF3C2000
|
unkown
|
page readonly
|
||
83E0000
|
unkown
|
page read and write
|
||
9D1F000
|
stack
|
page read and write
|
||
97C0000
|
unkown
|
page read and write
|
||
A6F1000
|
unkown
|
page read and write
|
||
C75000
|
stack
|
page read and write
|
||
10CD000
|
trusted library allocation
|
page execute and read and write
|
||
3362000
|
unkown
|
page read and write
|
||
7FF5DF229000
|
unkown
|
page readonly
|
||
3A83000
|
trusted library allocation
|
page read and write
|
||
C410000
|
unkown
|
page read and write
|
||
297C000
|
stack
|
page read and write
|
||
4788000
|
unkown
|
page read and write
|
||
4F26000
|
trusted library allocation
|
page read and write
|
||
489A000
|
unkown
|
page read and write
|
||
3304000
|
unkown
|
page read and write
|
||
3373000
|
unkown
|
page read and write
|
||
4D9E000
|
direct allocation
|
page execute and read and write
|
||
9B1E000
|
stack
|
page read and write
|
||
ED8A000
|
unkown
|
page read and write
|
||
532B000
|
stack
|
page read and write
|
||
7FF5DF606000
|
unkown
|
page readonly
|
||
7FF5DF341000
|
unkown
|
page readonly
|
||
7FF5DEF4B000
|
unkown
|
page readonly
|
||
2EB0000
|
unkown
|
page readonly
|
||
5370000
|
heap
|
page read and write
|
||
10D2000
|
trusted library allocation
|
page read and write
|
||
7810000
|
unkown
|
page read and write
|
||
336C000
|
unkown
|
page read and write
|
||
7FF5DE531000
|
unkown
|
page readonly
|
||
7FF5C0B6B000
|
unkown
|
page readonly
|
||
7FF5DF60D000
|
unkown
|
page readonly
|
||
BFA7000
|
unkown
|
page read and write
|
||
74D6000
|
unkown
|
page read and write
|
||
C23D000
|
unkown
|
page read and write
|
||
C354000
|
unkown
|
page read and write
|
||
EEAA000
|
heap
|
page read and write
|
||
ED7D000
|
unkown
|
page read and write
|
||
C75000
|
stack
|
page read and write
|
||
135D000
|
trusted library allocation
|
page execute and read and write
|
||
7FF5DEF06000
|
unkown
|
page readonly
|
||
940B000
|
stack
|
page read and write
|
||
73BA000
|
unkown
|
page read and write
|
||
7FF5DF626000
|
unkown
|
page readonly
|
||
BFEF000
|
unkown
|
page read and write
|
||
C525000
|
unkown
|
page read and write
|
||
FFC2000
|
unkown
|
page read and write
|
||
7FF5DEE5A000
|
unkown
|
page readonly
|
||
7FF5DF486000
|
unkown
|
page readonly
|
||
9564000
|
unkown
|
page read and write
|
||
7DF4E6791000
|
unkown
|
page execute read
|
||
830F000
|
stack
|
page read and write
|
||
E0F000
|
heap
|
page read and write
|
||
4760000
|
unkown
|
page read and write
|
||
74A9000
|
unkown
|
page read and write
|
||
C23D000
|
unkown
|
page read and write
|
||
7FF5DF4BD000
|
unkown
|
page readonly
|
||
BEF0000
|
heap
|
page read and write
|
||
C24C000
|
unkown
|
page read and write
|
||
AFFE000
|
stack
|
page read and write
|
||
E130000
|
unkown
|
page execute and read and write
|
||
B830000
|
unkown
|
page readonly
|
||
A30000
|
system
|
page execute and read and write
|
||
C18A000
|
unkown
|
page read and write
|
||
7FF5DEE52000
|
unkown
|
page readonly
|
||
16DB000
|
unclassified section
|
page execute and read and write
|
||
2FDE000
|
heap
|
page read and write
|
||
9F92000
|
unkown
|
page read and write
|
||
A74E000
|
unkown
|
page read and write
|
||
5490000
|
trusted library allocation
|
page read and write
|
||
9F60000
|
unkown
|
page read and write
|
||
7DF5E895F000
|
unkown
|
page readonly
|
||
7FF5DF26F000
|
unkown
|
page readonly
|
||
150E000
|
direct allocation
|
page execute and read and write
|
||
914B000
|
stack
|
page read and write
|
||
2E50000
|
unkown
|
page readonly
|
||
C298000
|
unkown
|
page read and write
|
||
3A35000
|
trusted library allocation
|
page read and write
|
||
3185000
|
stack
|
page read and write
|
||
7ACE000
|
stack
|
page read and write
|
||
AB87000
|
stack
|
page read and write
|
||
BFA1000
|
unkown
|
page read and write
|
||
7FF5DF3D4000
|
unkown
|
page readonly
|
||
E1B0000
|
unkown
|
page execute and read and write
|
||
E21000
|
trusted library allocation
|
page execute and read and write
|
||
1370000
|
direct allocation
|
page execute and read and write
|
||
D60000
|
heap
|
page read and write
|
||
5110000
|
unkown
|
page write copy
|
||
7830000
|
unkown
|
page read and write
|
||
2BE4000
|
heap
|
page read and write
|
||
7910000
|
unkown
|
page readonly
|
||
D69000
|
heap
|
page read and write
|
||
52A0000
|
trusted library allocation
|
page read and write
|
||
4745000
|
heap
|
page read and write
|
||
DFE000
|
stack
|
page read and write
|
||
9E1E000
|
stack
|
page read and write
|
||
7FF5DF551000
|
unkown
|
page readonly
|
||
96ED000
|
unkown
|
page read and write
|
||
83D0000
|
unkown
|
page read and write
|
||
7FF5DF248000
|
unkown
|
page readonly
|
||
7FF5DF0F1000
|
unkown
|
page readonly
|
||
7FF5DEFA6000
|
unkown
|
page readonly
|
||
4F04000
|
trusted library allocation
|
page read and write
|
||
4ED1000
|
direct allocation
|
page execute and read and write
|
||
47EC000
|
unkown
|
page read and write
|
||
3349000
|
unkown
|
page read and write
|
||
7FF5DF478000
|
unkown
|
page readonly
|
||
848E000
|
stack
|
page read and write
|
||
2FCB000
|
heap
|
page read and write
|
||
7FF5DF24E000
|
unkown
|
page readonly
|
||
AC0D000
|
stack
|
page read and write
|
||
C003000
|
unkown
|
page read and write
|
||
7FF5DF50F000
|
unkown
|
page readonly
|
||
7FF5DF28E000
|
unkown
|
page readonly
|
||
32B0000
|
heap
|
page read and write
|
||
C149000
|
unkown
|
page read and write
|
||
5A64000
|
heap
|
page read and write
|
||
9489000
|
stack
|
page read and write
|
||
C24C000
|
unkown
|
page read and write
|
||
B500000
|
unkown
|
page readonly
|
||
C003000
|
unkown
|
page read and write
|
||
97F3000
|
unkown
|
page read and write
|
||
7FF5DF341000
|
unkown
|
page readonly
|
||
120F000
|
stack
|
page read and write
|
||
7FF5DF452000
|
unkown
|
page readonly
|
||
10B3000
|
trusted library allocation
|
page execute and read and write
|
||
9F7C000
|
unkown
|
page read and write
|
||
7860000
|
unkown
|
page read and write
|
||
4A8C000
|
stack
|
page read and write
|
||
B9BF000
|
stack
|
page read and write
|
||
7FF5DF5A8000
|
unkown
|
page readonly
|
||
4F32000
|
trusted library allocation
|
page read and write
|
||
479B000
|
unkown
|
page read and write
|
||
488A000
|
unkown
|
page read and write
|
||
74F1000
|
unkown
|
page read and write
|
||
FF46000
|
unkown
|
page read and write
|
||
73B2000
|
unkown
|
page read and write
|
||
1621000
|
direct allocation
|
page execute and read and write
|
||
C13D000
|
unkown
|
page read and write
|
||
10BEF000
|
system
|
page read and write
|
||
7FF5DF5F6000
|
unkown
|
page readonly
|
||
7DF4E6771000
|
unkown
|
page execute read
|
||
317F000
|
unkown
|
page read and write
|
||
C1C4000
|
unkown
|
page read and write
|
||
48B0000
|
unkown
|
page read and write
|
||
9D1F000
|
stack
|
page read and write
|
||
336F000
|
unkown
|
page read and write
|
||
7991000
|
unkown
|
page read and write
|
||
7FF5DF53F000
|
unkown
|
page readonly
|
||
7D0D000
|
stack
|
page read and write
|
||
47EC000
|
unkown
|
page read and write
|
||
7FF5DF195000
|
unkown
|
page readonly
|
||
AF7E000
|
stack
|
page read and write
|
||
901B000
|
stack
|
page read and write
|
||
BF90000
|
unkown
|
page read and write
|
||
7FF5DF195000
|
unkown
|
page readonly
|
||
9F78000
|
unkown
|
page read and write
|
||
48E0000
|
unkown
|
page read and write
|
||
7FF5DF539000
|
unkown
|
page readonly
|
||
7FF5DE535000
|
unkown
|
page readonly
|
||
A6FC000
|
unkown
|
page read and write
|
||
C02F000
|
unkown
|
page read and write
|
||
28D3000
|
heap
|
page read and write
|
||
47F3000
|
unkown
|
page read and write
|
||
292E000
|
stack
|
page read and write
|
||
1110000
|
heap
|
page read and write
|
||
7FF5DF3F1000
|
unkown
|
page readonly
|
||
51FE000
|
stack
|
page read and write
|
||
8390000
|
unkown
|
page read and write
|
||
FFCB000
|
unkown
|
page read and write
|
||
7FF5DF1F8000
|
unkown
|
page readonly
|
||
7FF5DEFCB000
|
unkown
|
page readonly
|
||
47A2000
|
unkown
|
page read and write
|
||
BFDF000
|
unkown
|
page read and write
|
||
C39F000
|
unkown
|
page read and write
|
||
D99000
|
heap
|
page read and write
|
||
96DF000
|
unkown
|
page read and write
|
||
4F50000
|
trusted library allocation
|
page read and write
|
||
7FF5DF4C6000
|
unkown
|
page readonly
|
||
7B60000
|
unkown
|
page readonly
|
||
7FF5DF1D1000
|
unkown
|
page readonly
|
||
C43E000
|
unkown
|
page read and write
|
||
CCF000
|
stack
|
page read and write
|
||
7FF5DF532000
|
unkown
|
page readonly
|
||
7FF5DF122000
|
unkown
|
page readonly
|
||
47F3000
|
unkown
|
page read and write
|
||
7FF5DF221000
|
unkown
|
page readonly
|
||
9F23000
|
unkown
|
page read and write
|
||
7FF5DF091000
|
unkown
|
page readonly
|
||
7FF5DF310000
|
unkown
|
page readonly
|
||
94C000
|
stack
|
page read and write
|
||
33C0000
|
unkown
|
page readonly
|
||
9F0000
|
trusted library allocation
|
page read and write
|
||
7FF5DF424000
|
unkown
|
page readonly
|
||
7FF5DF029000
|
unkown
|
page readonly
|
||
B50000
|
heap
|
page read and write
|
||
88DC000
|
stack
|
page read and write
|
||
4BF6000
|
heap
|
page read and write
|
||
FF4B000
|
unkown
|
page read and write
|
||
8A36000
|
unkown
|
page read and write
|
||
739B000
|
unkown
|
page read and write
|
||
9489000
|
stack
|
page read and write
|
||
739B000
|
unkown
|
page read and write
|
||
99AB000
|
unkown
|
page read and write
|
||
C1A9000
|
unkown
|
page read and write
|
||
7FF5DEFF5000
|
unkown
|
page readonly
|
||
A0B1000
|
unkown
|
page read and write
|
||
7FF5DF3B9000
|
unkown
|
page readonly
|
||
C2E4000
|
unkown
|
page read and write
|
||
7FF5DF364000
|
unkown
|
page readonly
|
||
B120000
|
unkown
|
page readonly
|
||
4766000
|
unkown
|
page read and write
|
||
B259000
|
stack
|
page read and write
|
||
7909000
|
stack
|
page read and write
|
||
8590000
|
unkown
|
page readonly
|
||
7FF5DF3DF000
|
unkown
|
page readonly
|
||
AEF0000
|
unkown
|
page read and write
|
||
A758000
|
unkown
|
page read and write
|
||
B1C0000
|
unkown
|
page readonly
|
||
7FF5DF4E7000
|
unkown
|
page readonly
|
||
7FF5DF18E000
|
unkown
|
page readonly
|
||
C192000
|
unkown
|
page read and write
|
||
C149000
|
unkown
|
page read and write
|
||
7FF5DEEEB000
|
unkown
|
page readonly
|
||
7FF5DF343000
|
unkown
|
page readonly
|
||
A6EE000
|
unkown
|
page read and write
|
||
4A58000
|
heap
|
page read and write
|
||
13A0000
|
unkown
|
page readonly
|
||
A6F6000
|
unkown
|
page read and write
|
||
838B000
|
stack
|
page read and write
|
||
7DF4E67A1000
|
unkown
|
page execute read
|
||
48A0000
|
unkown
|
page read and write
|
||
7FF5DEFB7000
|
unkown
|
page readonly
|
||
8C28000
|
stack
|
page read and write
|
||
488D000
|
stack
|
page read and write
|
||
C319000
|
unkown
|
page read and write
|
||
E2CE000
|
system
|
page execute and read and write
|
||
7FF5DF07D000
|
unkown
|
page readonly
|
||
7FF5DF21B000
|
unkown
|
page readonly
|
||
950C000
|
stack
|
page read and write
|
||
98A1000
|
unkown
|
page read and write
|
||
7FF5DF08F000
|
unkown
|
page readonly
|
||
335B000
|
unkown
|
page read and write
|
||
E5E000
|
heap
|
page read and write
|
||
7DF4E6780000
|
unkown
|
page readonly
|
||
7FF5DF1D1000
|
unkown
|
page readonly
|
||
2770000
|
heap
|
page read and write
|
||
76F0000
|
unkown
|
page read and write
|
||
5D60000
|
heap
|
page read and write
|
||
7FF5DF4AB000
|
unkown
|
page readonly
|
||
FEC4000
|
unkown
|
page read and write
|
||
E1EF000
|
unkown
|
page execute and read and write
|
||
7FF5DEF90000
|
unkown
|
page readonly
|
||
4824000
|
unkown
|
page read and write
|
||
D99000
|
heap
|
page read and write
|
||
C40F000
|
unkown
|
page read and write
|
||
7FF5DF3FC000
|
unkown
|
page readonly
|
||
9F0000
|
trusted library allocation
|
page read and write
|
||
9F10000
|
unkown
|
page read and write
|
||
7542000
|
unkown
|
page read and write
|
||
978C000
|
unkown
|
page read and write
|
||
4ADE000
|
stack
|
page read and write
|
||
AC0D000
|
stack
|
page read and write
|
||
5FE0000
|
trusted library section
|
page read and write
|
||
7FF5DF5BE000
|
unkown
|
page readonly
|
||
11A0000
|
unkown
|
page readonly
|
||
A6CF000
|
unkown
|
page read and write
|
||
7FF5DF169000
|
unkown
|
page readonly
|
||
9E9E000
|
stack
|
page read and write
|
||
C048000
|
unkown
|
page read and write
|
||
7FF5DE9C3000
|
unkown
|
page readonly
|
||
7FF5DF422000
|
unkown
|
page readonly
|
||
547F000
|
stack
|
page read and write
|
||
7FF5DF606000
|
unkown
|
page readonly
|
||
BFAD000
|
unkown
|
page read and write
|
||
73E5000
|
unkown
|
page read and write
|
||
2E50000
|
unkown
|
page readonly
|
||
73B4000
|
unkown
|
page read and write
|
||
F10000
|
heap
|
page read and write
|
||
7DF4E6781000
|
unkown
|
page execute read
|
||
7FF5DF095000
|
unkown
|
page readonly
|
||
7FF5DF0A5000
|
unkown
|
page readonly
|
||
ACAF000
|
stack
|
page read and write
|
||
C013000
|
unkown
|
page read and write
|
||
9718000
|
unkown
|
page read and write
|
||
10D0000
|
trusted library allocation
|
page read and write
|
||
BF9D000
|
unkown
|
page read and write
|
||
BF98000
|
unkown
|
page read and write
|
||
C18A000
|
unkown
|
page read and write
|
||
7FF5DF59E000
|
unkown
|
page readonly
|
||
16F0000
|
unclassified section
|
page execute and read and write
|
||
A0A5000
|
unkown
|
page read and write
|
||
327F000
|
stack
|
page read and write
|
||
4B8E000
|
stack
|
page read and write
|
||
3991000
|
trusted library allocation
|
page read and write
|
||
10E7000
|
trusted library allocation
|
page execute and read and write
|
||
BEF0000
|
heap
|
page read and write
|
||
9F2A000
|
unkown
|
page read and write
|
||
3281000
|
stack
|
page read and write
|
||
7FF5DF017000
|
unkown
|
page readonly
|
||
7FF5DF4E7000
|
unkown
|
page readonly
|
||
C19D000
|
unkown
|
page read and write
|
||
98AD000
|
unkown
|
page read and write
|
||
73B8000
|
unkown
|
page read and write
|
||
EEA2000
|
heap
|
page read and write
|
||
7FF5DF488000
|
unkown
|
page readonly
|
||
4F70000
|
trusted library allocation
|
page read and write
|
||
7FF5DF4FB000
|
unkown
|
page readonly
|
||
7FF5DF25B000
|
unkown
|
page readonly
|
||
7810000
|
unkown
|
page read and write
|
||
9F0000
|
trusted library allocation
|
page read and write
|
||
A104000
|
unkown
|
page read and write
|
||
C298000
|
unkown
|
page read and write
|
||
7FF5DE9C3000
|
unkown
|
page readonly
|
||
A33000
|
system
|
page execute and read and write
|
||
989F000
|
unkown
|
page read and write
|
||
E80000
|
unkown
|
page read and write
|
||
7FF5DF567000
|
unkown
|
page readonly
|
||
C034000
|
unkown
|
page read and write
|
||
C4C4000
|
unkown
|
page read and write
|
||
9704000
|
unkown
|
page read and write
|
||
7FF5DF16B000
|
unkown
|
page readonly
|
||
B09F000
|
stack
|
page read and write
|
||
7395000
|
unkown
|
page read and write
|
||
9A6C000
|
stack
|
page read and write
|
||
4FF0000
|
trusted library allocation
|
page execute and read and write
|
||
ED75000
|
unkown
|
page read and write
|
||
C183000
|
unkown
|
page read and write
|
||
1010000
|
heap
|
page read and write
|
||
7FF5DEFF0000
|
unkown
|
page readonly
|
||
BF8C000
|
unkown
|
page read and write
|
||
971C000
|
unkown
|
page read and write
|
||
B2DD000
|
stack
|
page read and write
|
||
2BE4000
|
heap
|
page read and write
|
||
96ED000
|
unkown
|
page read and write
|
||
C01A000
|
unkown
|
page read and write
|
||
C415000
|
unkown
|
page read and write
|
||
D60000
|
heap
|
page read and write
|
||
A744000
|
unkown
|
page read and write
|
||
9716000
|
unkown
|
page read and write
|
||
885E000
|
stack
|
page read and write
|
||
7FF5DF584000
|
unkown
|
page readonly
|
||
7FF5DF55A000
|
unkown
|
page readonly
|
||
7FF5DF532000
|
unkown
|
page readonly
|
||
4F0B000
|
trusted library allocation
|
page read and write
|
||
9E1E000
|
stack
|
page read and write
|
||
5241000
|
unkown
|
page read and write
|
||
C381000
|
unkown
|
page read and write
|
||
10E0000
|
trusted library allocation
|
page read and write
|
||
4D2D000
|
direct allocation
|
page execute and read and write
|
||
B120000
|
unkown
|
page readonly
|
||
32B0000
|
unkown
|
page read and write
|
||
7DF4E6770000
|
unkown
|
page readonly
|
||
9F74000
|
unkown
|
page read and write
|
||
E80000
|
unkown
|
page read and write
|
||
7FF5DF5AE000
|
unkown
|
page readonly
|
||
D20000
|
heap
|
page read and write
|
||
7FF5DF5A3000
|
unkown
|
page readonly
|
||
7D89000
|
stack
|
page read and write
|
||
7FF5DF3C2000
|
unkown
|
page readonly
|
||
7FF5DF5FC000
|
unkown
|
page readonly
|
||
7FF5DF39C000
|
unkown
|
page readonly
|
||
7DF4E6760000
|
unkown
|
page readonly
|
||
7FF5DF045000
|
unkown
|
page readonly
|
||
47F1000
|
unkown
|
page read and write
|
||
52C3000
|
unkown
|
page read and write
|
||
7FF5DF549000
|
unkown
|
page readonly
|
||
7230000
|
unkown
|
page read and write
|
||
9E0000
|
unkown
|
page readonly
|
||
7DF4E6781000
|
unkown
|
page execute read
|
||
9704000
|
unkown
|
page read and write
|
||
34B0000
|
unkown
|
page readonly
|
||
76F0000
|
unkown
|
page read and write
|
||
7FF5DF591000
|
unkown
|
page readonly
|
There are 1375 hidden memdumps, click here to show them.