Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\mIzAhxUQjY.exe
|
"C:\Users\user\Desktop\mIzAhxUQjY.exe"
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER_Classes\Local Settings\MuiCache\24\417C44EB
|
@%SystemRoot%\System32\ndfapi.dll,-40001
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
106E000
|
heap
|
page read and write
|
||
1020000
|
heap
|
page read and write
|
||
3D8E000
|
stack
|
page read and write
|
||
BD5000
|
heap
|
page read and write
|
||
1059000
|
heap
|
page read and write
|
||
1011000
|
heap
|
page read and write
|
||
B20000
|
heap
|
page read and write
|
||
103A000
|
heap
|
page read and write
|
||
1059000
|
heap
|
page read and write
|
||
1043000
|
heap
|
page read and write
|
||
1067000
|
heap
|
page read and write
|
||
1039000
|
heap
|
page read and write
|
||
1059000
|
heap
|
page read and write
|
||
7640000
|
trusted library allocation
|
page read and write
|
||
106E000
|
heap
|
page read and write
|
||
1070000
|
heap
|
page read and write
|
||
1037000
|
heap
|
page read and write
|
||
E68000
|
unkown
|
page readonly
|
||
1059000
|
heap
|
page read and write
|
||
1020000
|
heap
|
page read and write
|
||
FD3000
|
heap
|
page read and write
|
||
350000
|
heap
|
page read and write
|
||
1056000
|
heap
|
page read and write
|
||
106F000
|
heap
|
page read and write
|
||
FD5000
|
heap
|
page read and write
|
||
722E000
|
stack
|
page read and write
|
||
1038000
|
heap
|
page read and write
|
||
1056000
|
heap
|
page read and write
|
||
105B000
|
heap
|
page read and write
|
||
1043000
|
heap
|
page read and write
|
||
107E000
|
heap
|
page read and write
|
||
1059000
|
heap
|
page read and write
|
||
1020000
|
heap
|
page read and write
|
||
106E000
|
heap
|
page read and write
|
||
FE2000
|
heap
|
page read and write
|
||
BD0000
|
heap
|
page read and write
|
||
393E000
|
stack
|
page read and write
|
||
9BF000
|
stack
|
page read and write
|
||
1068000
|
heap
|
page read and write
|
||
1056000
|
heap
|
page read and write
|
||
1022000
|
heap
|
page read and write
|
||
1012000
|
heap
|
page read and write
|
||
1056000
|
heap
|
page read and write
|
||
FB0000
|
heap
|
page read and write
|
||
1059000
|
heap
|
page read and write
|
||
1056000
|
heap
|
page read and write
|
||
106E000
|
heap
|
page read and write
|
||
B26000
|
heap
|
page read and write
|
||
1025000
|
heap
|
page read and write
|
||
1017000
|
heap
|
page read and write
|
||
106E000
|
heap
|
page read and write
|
||
1022000
|
heap
|
page read and write
|
||
1016000
|
heap
|
page read and write
|
||
E63000
|
unkown
|
page write copy
|
||
9FC000
|
stack
|
page read and write
|
||
1059000
|
heap
|
page read and write
|
||
1056000
|
heap
|
page read and write
|
||
3D3E000
|
stack
|
page read and write
|
||
106E000
|
heap
|
page read and write
|
||
1013000
|
heap
|
page read and write
|
||
9DD000
|
stack
|
page read and write
|
||
1068000
|
heap
|
page read and write
|
||
FDD000
|
heap
|
page read and write
|
||
E55000
|
unkown
|
page readonly
|
||
FB8000
|
heap
|
page read and write
|
||
1059000
|
heap
|
page read and write
|
||
1056000
|
heap
|
page read and write
|
||
106F000
|
heap
|
page read and write
|
||
FCF000
|
heap
|
page read and write
|
||
E5F000
|
unkown
|
page write copy
|
||
1007000
|
heap
|
page read and write
|
||
B10000
|
heap
|
page read and write
|
||
D80000
|
heap
|
page read and write
|
||
1056000
|
heap
|
page read and write
|
||
1026000
|
heap
|
page read and write
|
||
7630000
|
heap
|
page read and write
|
||
1059000
|
heap
|
page read and write
|
||
103A000
|
heap
|
page read and write
|
||
101F000
|
heap
|
page read and write
|
||
3E0000
|
heap
|
page read and write
|
||
E2F000
|
unkown
|
page readonly
|
||
1059000
|
heap
|
page read and write
|
||
106E000
|
heap
|
page read and write
|
||
1059000
|
heap
|
page read and write
|
||
1059000
|
heap
|
page read and write
|
||
1053000
|
heap
|
page read and write
|
||
107F000
|
heap
|
page read and write
|
||
DA0000
|
unkown
|
page readonly
|
||
B14000
|
heap
|
page read and write
|
||
E5F000
|
unkown
|
page read and write
|
||
FD8000
|
heap
|
page read and write
|
||
106E000
|
heap
|
page read and write
|
||
1077000
|
heap
|
page read and write
|
||
1044000
|
heap
|
page read and write
|
||
106E000
|
heap
|
page read and write
|
||
103A000
|
heap
|
page read and write
|
||
B29000
|
heap
|
page read and write
|
||
1059000
|
heap
|
page read and write
|
||
DA0000
|
unkown
|
page readonly
|
||
107E000
|
heap
|
page read and write
|
||
1056000
|
heap
|
page read and write
|
||
1059000
|
heap
|
page read and write
|
||
1059000
|
heap
|
page read and write
|
||
106E000
|
heap
|
page read and write
|
||
1007000
|
heap
|
page read and write
|
||
104C000
|
heap
|
page read and write
|
||
1016000
|
heap
|
page read and write
|
||
FE3000
|
heap
|
page read and write
|
||
1020000
|
heap
|
page read and write
|
||
3DD000
|
stack
|
page read and write
|
||
DA1000
|
unkown
|
page execute read
|
||
1056000
|
heap
|
page read and write
|
||
BC0000
|
heap
|
page read and write
|
||
1007000
|
heap
|
page read and write
|
||
762F000
|
stack
|
page read and write
|
||
1022000
|
heap
|
page read and write
|
||
103B000
|
heap
|
page read and write
|
||
1007000
|
heap
|
page read and write
|
||
FD6000
|
heap
|
page read and write
|
||
1056000
|
heap
|
page read and write
|
||
101A000
|
heap
|
page read and write
|
||
1056000
|
heap
|
page read and write
|
||
E2F000
|
unkown
|
page readonly
|
||
9CF000
|
stack
|
page read and write
|
||
1038000
|
heap
|
page read and write
|
||
7640000
|
trusted library allocation
|
page read and write
|
||
107E000
|
heap
|
page read and write
|
||
39E000
|
stack
|
page read and write
|
||
1016000
|
heap
|
page read and write
|
||
1012000
|
heap
|
page read and write
|
||
1056000
|
heap
|
page read and write
|
||
DA1000
|
unkown
|
page execute read
|
||
2EA000
|
stack
|
page read and write
|
||
1056000
|
heap
|
page read and write
|
||
418F000
|
stack
|
page read and write
|
||
FD2000
|
heap
|
page read and write
|
||
17AE000
|
stack
|
page read and write
|
||
FF7000
|
heap
|
page read and write
|
||
1056000
|
heap
|
page read and write
|
||
104E000
|
heap
|
page read and write
|
||
E68000
|
unkown
|
page readonly
|
||
1039000
|
heap
|
page read and write
|
||
1059000
|
heap
|
page read and write
|
||
FE3000
|
heap
|
page read and write
|
||
E55000
|
unkown
|
page readonly
|
||
FE3000
|
heap
|
page read and write
|
||
1BAF000
|
stack
|
page read and write
|
||
1056000
|
heap
|
page read and write
|
||
104D000
|
heap
|
page read and write
|
||
103B000
|
heap
|
page read and write
|
There are 140 hidden memdumps, click here to show them.