Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
Outlook-ghmt04mr.png
|
PNG image data, 91 x 24, 8-bit/color RGBA, non-interlaced
|
initial sample
|
||
C:\Windows\debug\WIA\wiatrace.log
|
ASCII text, with CRLF, LF line terminators
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Windows\SysWOW64\mspaint.exe
|
mspaint.exe "C:\Users\user\Desktop\Outlook-ghmt04mr.png"
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
|
{A38B883C-1682-497E-97B0-0A3A9E801682} {886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99} 0xFFFF
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4CEE000
|
stack
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
27EE000
|
stack
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4CAE000
|
stack
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA0000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2C7A000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4AF0000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4DAE000
|
stack
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4790000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
47A1000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4B3B000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
8530000
|
trusted library allocation
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2A35000
|
stack
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
51CE000
|
stack
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4B00000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2C74000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2B80000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
46D0000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4AE0000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
65C0000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
65DF000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
65C1000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2E6A000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
46AD000
|
stack
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
518E000
|
stack
|
page read and write
|
||
2E6D000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2B87000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4C60000
|
trusted library allocation
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2BBD000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2B97000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2D90000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2C0F000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4DEE000
|
stack
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
46E0000
|
trusted library allocation
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
6620000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4D2E000
|
stack
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4B75000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
5520000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AB0000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
8350000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2E60000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4D6F000
|
stack
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
466C000
|
stack
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
46D3000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4B1A000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
2AA4000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4791000
|
heap
|
page read and write
|
||
4780000
|
heap
|
page read and write
|
||
4C00000
|
heap
|
page read and write
|
There are 925 hidden memdumps, click here to show them.