Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
RFQ-1024.exe
|
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\RFQ-1024.exe.log
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_2tihkhxm.250.ps1
|
ASCII text, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_adz5nwtc.fvh.psm1
|
ASCII text, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_c4kazcal.p1k.psm1
|
ASCII text, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_fzv4q0z5.ktp.ps1
|
ASCII text, with no line terminators
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\RFQ-1024.exe
|
"C:\Users\user\Desktop\RFQ-1024.exe"
|
||
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
|
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\RFQ-1024.exe"
|
||
C:\Users\user\Desktop\RFQ-1024.exe
|
"C:\Users\user\Desktop\RFQ-1024.exe"
|
||
C:\Windows\explorer.exe
|
C:\Windows\Explorer.EXE
|
||
C:\Windows\SysWOW64\netsh.exe
|
"C:\Windows\SysWOW64\netsh.exe"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
||
C:\Windows\System32\wbem\WmiPrvSE.exe
|
C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
|
||
C:\Windows\SysWOW64\cmd.exe
|
/c del "C:\Users\user\Desktop\RFQ-1024.exe"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
www.ridges-freezers-56090.bond/c24t/
|
|||
http://www.rvinsadeli.devReferer:
|
unknown
|
||
http://www.sx9u.shop/c24t/www.024tengxun396.buzz
|
unknown
|
||
http://www.rvinsadeli.dev
|
unknown
|
||
http://www.aketrtpmvpslot88.info/c24t/www.venir-bienne.info
|
unknown
|
||
https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DV
|
unknown
|
||
https://www.msn.com/en-us/money/savingandinvesting/americans-average-net-worth-by-age/ar-AA1h4ngF
|
unknown
|
||
http://www.ridges-freezers-56090.bondReferer:
|
unknown
|
||
http://www.02s-pest-control-us-ze.fun
|
unknown
|
||
http://www.024tengxun396.buzz/c24t/www.458881233.men
|
unknown
|
||
https://api.msn.com:443/v1/news/Feed/Windows?
|
unknown
|
||
http://www.rvinsadeli.dev/c24t/www.yrhbt.shop
|
unknown
|
||
https://word.office.comM
|
unknown
|
||
http://www.024tengxun396.buzz/c24t/
|
unknown
|
||
https://www.msn.com/en-us/money/realestate/why-this-florida-city-is-a-safe-haven-from-hurricanes/ar-
|
unknown
|
||
https://www.msn.com/en-us/news/politics/how-donald-trump-helped-kari-lake-become-arizona-s-and-ameri
|
unknown
|
||
http://www.sx9u.shopReferer:
|
unknown
|
||
http://www.yrhbt.shop/c24t/
|
unknown
|
||
http://www.472.top
|
unknown
|
||
http://www.472.top/c24t/
|
unknown
|
||
http://www.aketrtpmvpslot88.infoReferer:
|
unknown
|
||
http://www.23fd595ig.autos/c24t/
|
unknown
|
||
http://www.02s-pest-control-us-ze.funReferer:
|
unknown
|
||
http://www.ourhealthyourlife.shop/c24t/www.consuyt.xyz
|
unknown
|
||
https://wns.windows.com/e
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
|
unknown
|
||
http://www.yrhbt.shop
|
unknown
|
||
http://www.nline-courses-classes-lv-1.bond/c24t/
|
unknown
|
||
http://www.ilw.legal/c24t/www.472.top
|
unknown
|
||
http://www.venir-bienne.info/c24t/www.rvinsadeli.dev
|
unknown
|
||
http://www.yrhbt.shopReferer:
|
unknown
|
||
http://www.venir-bienne.info/c24t/
|
unknown
|
||
http://www.458881233.men/c24t/www.ourhealthyourlife.shop
|
unknown
|
||
http://www.472.top/c24t/www.ridges-freezers-56090.bond
|
unknown
|
||
http://www.02s-pest-control-us-ze.fun/c24t/www.loud-computing-intl-3455364.fyi
|
unknown
|
||
http://www.ilw.legal/c24t/
|
unknown
|
||
https://assets.msn.com/weathermapdata/1/static/finance/1stparty/FinanceTaskbarIcons/Finance_Earnings
|
unknown
|
||
http://www.consuyt.xyz/c24t/www.nline-courses-classes-lv-1.bond
|
unknown
|
||
http://www.consuyt.xyz/c24t/
|
unknown
|
||
http://www.ridges-freezers-56090.bond/c24t/www.23fd595ig.autos
|
unknown
|
||
https://api.msn.com/v1/news/Feed/Windows?activityId=435B7A89D7D74BDF801F2DA188906BAF&timeOut=5000&oc
|
unknown
|
||
https://windows.msn.com:443/shell?osLocale=en-GB&chosenMarketReason=ImplicitNew
|
unknown
|
||
http://www.aketrtpmvpslot88.info
|
unknown
|
||
https://www.msn.com/en-us/travel/news/you-can-t-beat-bobby-flay-s-phoenix-airport-restaurant-one-of-
|
unknown
|
||
http://www.23fd595ig.autos/c24t/www.aketrtpmvpslot88.info
|
unknown
|
||
https://android.notify.windows.com/iOS
|
unknown
|
||
https://outlook.come
|
unknown
|
||
https://activity.windows.com/UserActivity.ReadWrite.CreatedByApp
|
unknown
|
||
https://www.msn.com/en-us/news/us/dumb-and-dumber-12-states-with-the-absolute-worst-education-in-the
|
unknown
|
||
http://www.ridges-freezers-56090.bond/c24t/
|
unknown
|
||
http://www.024tengxun396.buzzReferer:
|
unknown
|
||
http://www.yrhbt.shop/c24t/www.02s-pest-control-us-ze.fun
|
unknown
|
||
http://www.aketrtpmvpslot88.info/c24t/
|
unknown
|
||
https://www.msn.com/en-us/news/politics/kevin-mccarthy-s-ouster-as-house-speaker-could-cost-gop-its-
|
unknown
|
||
http://www.23fd595ig.autos
|
unknown
|
||
http://www.nline-courses-classes-lv-1.bond/c24t/www.ilw.legal
|
unknown
|
||
https://api.msn.com/v1/news/Feed/Windows?
|
unknown
|
||
https://api.msn.com/I
|
unknown
|
||
http://www.sx9u.shop
|
unknown
|
||
http://www.ilw.legal
|
unknown
|
||
http://www.ilw.legalReferer:
|
unknown
|
||
http://www.ourhealthyourlife.shop
|
unknown
|
||
http://www.ridges-freezers-56090.bond
|
unknown
|
||
http://schemas.micro
|
unknown
|
||
http://www.loud-computing-intl-3455364.fyi
|
unknown
|
||
http://www.024tengxun396.buzz
|
unknown
|
||
http://www.458881233.men/c24t/
|
unknown
|
||
http://www.ourhealthyourlife.shopReferer:
|
unknown
|
||
http://www.rvinsadeli.dev/c24t/
|
unknown
|
||
https://windows.msn.com:443/shellv2?osLocale=en-GB&chosenMarketReason=ImplicitNew
|
unknown
|
||
http://www.nline-courses-classes-lv-1.bondReferer:
|
unknown
|
||
https://www.msn.com/en-us/news/politics/republicans-already-barred-trump-from-being-speaker-of-the-h
|
unknown
|
||
https://www.msn.com/en-us/news/politics/trump-campaign-says-he-raised-more-than-45-million-in-3rd-qu
|
unknown
|
||
http://www.nline-courses-classes-lv-1.bond
|
unknown
|
||
http://www.458881233.menReferer:
|
unknown
|
||
http://www.venir-bienne.info
|
unknown
|
||
http://www.458881233.men
|
unknown
|
||
http://www.02s-pest-control-us-ze.fun/c24t/
|
unknown
|
||
http://www.23fd595ig.autosReferer:
|
unknown
|
||
https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gMhz
|
unknown
|
||
https://excel.office.com-
|
unknown
|
||
http://www.472.topReferer:
|
unknown
|
||
https://assets.msn.com/weathermapdata/1/static/weather/Icons/JyNGQgA=/Condition/AAehwh2.svg
|
unknown
|
||
http://www.sx9u.shop/c24t/
|
unknown
|
||
https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gMhz-dark
|
unknown
|
||
https://www.chiark.greenend.org.uk/~sgtatham/putty/0
|
unknown
|
||
https://www.msn.com/en-us/money/personalfinance/money-matters-changing-institution-of-marriage/ar-AA
|
unknown
|
||
https://www.msn.com/en-us/news/us/biden-administration-waives-26-federal-laws-to-allow-border-wall-c
|
unknown
|
||
https://www.msn.com/en-us/weather/topstories/california-s-reservoirs-runneth-over-in-astounding-reve
|
unknown
|
||
http://www.loud-computing-intl-3455364.fyi/c24t/
|
unknown
|
||
https://powerpoint.office.comEMd
|
unknown
|
||
http://www.venir-bienne.infoReferer:
|
unknown
|
||
https://www.msn.com/en-us/news/technology/a-federal-emergency-alert-will-be-sent-to-us-phones-nation
|
unknown
|
||
http://www.loud-computing-intl-3455364.fyiReferer:
|
unknown
|
||
https://api.msn.com/
|
unknown
|
||
http://www.consuyt.xyz
|
unknown
|
||
http://www.ourhealthyourlife.shop/c24t/
|
unknown
|
||
https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DV-dark
|
unknown
|
||
https://www.msn.com:443/en-us/feed
|
unknown
|
||
https://www.msn.com/en-us/news/world/us-supplies-ukraine-with-a-million-rounds-of-ammunition-seized-
|
unknown
|
There are 90 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
www.472.top
|
unknown
|
||
www.024tengxun396.buzz
|
unknown
|
||
www.ourhealthyourlife.shop
|
unknown
|
||
www.23fd595ig.autos
|
unknown
|
||
www.458881233.men
|
unknown
|
||
www.ilw.legal
|
unknown
|
||
www.ridges-freezers-56090.bond
|
unknown
|
||
www.sx9u.shop
|
unknown
|
||
www.venir-bienne.info
|
unknown
|
||
www.nline-courses-classes-lv-1.bond
|
unknown
|
||
www.aketrtpmvpslot88.info
|
unknown
|
There are 1 hidden domains, click here to show them.
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
unknown
|
Classes
|
||
unknown
|
~reserved~
|
||
unknown
|
Classes
|
||
unknown
|
~reserved~
|
||
unknown
|
Unpacker
|
||
unknown
|
Classes
|
||
unknown
|
~reserved~
|
||
unknown
|
Classes
|
||
unknown
|
~reserved~
|
||
unknown
|
{5985FC23-2588-4D9A-B38B-7E7AFFAB3155} {886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99} 0xFFFF
|
||
unknown
|
Classes
|
||
unknown
|
~reserved~
|
||
unknown
|
Classes
|
||
unknown
|
~reserved~
|
||
unknown
|
Classes
|
||
unknown
|
~reserved~
|
||
unknown
|
@explorerframe.dll,-13137
|
||
unknown
|
@explorerframe.dll,-13138
|
||
unknown
|
Classes
|
||
unknown
|
~reserved~
|
||
unknown
|
Classes
|
||
unknown
|
~reserved~
|
||
unknown
|
Classes
|
||
unknown
|
~reserved~
|
||
unknown
|
Classes
|
||
unknown
|
~reserved~
|
||
unknown
|
Classes
|
||
unknown
|
~reserved~
|
||
unknown
|
Classes
|
||
unknown
|
~reserved~
|
||
unknown
|
Classes
|
||
unknown
|
~reserved~
|
||
unknown
|
Classes
|
||
unknown
|
~reserved~
|
||
unknown
|
Classes
|
||
unknown
|
~reserved~
|
||
unknown
|
Classes
|
||
unknown
|
~reserved~
|
||
unknown
|
SlowContextMenuEntries
|
||
unknown
|
SlowContextMenuEntries
|
||
unknown
|
SlowContextMenuEntries
|
||
unknown
|
SlowContextMenuEntries
|
||
unknown
|
SlowContextMenuEntries
|
||
unknown
|
SlowContextMenuEntries
|
||
unknown
|
SlowContextMenuEntries
|
||
unknown
|
WMP11.AssocFile.3G2
|
||
unknown
|
WMP11.AssocFile.3GP
|
||
unknown
|
WMP11.AssocFile.3G2
|
||
unknown
|
WMP11.AssocFile.ADTS
|
||
unknown
|
WMP11.AssocFile.ADTS
|
||
unknown
|
WMP11.AssocFile.ADTS
|
||
unknown
|
WMP11.AssocFile.AIFF
|
||
unknown
|
WMP11.AssocFile.ASF
|
||
unknown
|
WMP11.AssocFile.ASX
|
||
unknown
|
WMP11.AssocFile.AU
|
||
unknown
|
AutoIt3Script
|
||
unknown
|
WMP11.AssocFile.AVI
|
||
unknown
|
Paint.Picture
|
||
unknown
|
CABFolder
|
||
unknown
|
Microsoft.PowerShellCmdletDefinitionXML.1
|
||
unknown
|
CSSfile
|
||
unknown
|
Excel.CSV
|
||
unknown
|
ddsfile
|
||
unknown
|
dllfile
|
||
unknown
|
Word.Document.8
|
||
unknown
|
Word.DocumentMacroEnabled.12
|
||
unknown
|
Word.Document.12
|
||
unknown
|
Word.Template.8
|
||
unknown
|
Word.TemplateMacroEnabled.12
|
||
unknown
|
Word.Template.12
|
||
unknown
|
emffile
|
||
unknown
|
exefile
|
||
unknown
|
WMP11.AssocFile.FLAC
|
||
unknown
|
fonfile
|
||
unknown
|
giffile
|
||
unknown
|
htmlfile
|
||
unknown
|
htmlfile
|
||
unknown
|
icofile
|
||
unknown
|
inffile
|
||
unknown
|
inifile
|
||
unknown
|
pjpegfile
|
||
unknown
|
jpegfile
|
||
unknown
|
jpegfile
|
||
unknown
|
wdpfile
|
||
unknown
|
lnkfile
|
||
unknown
|
WMP11.AssocFile.MPEG
|
||
unknown
|
WMP11.AssocFile.M2TS
|
||
unknown
|
WMP11.AssocFile.MPEG
|
||
unknown
|
WMP11.AssocFile.m3u
|
||
unknown
|
WMP11.AssocFile.M4A
|
||
unknown
|
WMP11.AssocFile.MP4
|
||
unknown
|
mhtmlfile
|
||
unknown
|
mhtmlfile
|
||
unknown
|
WMP11.AssocFile.MIDI
|
||
unknown
|
WMP11.AssocFile.MK3D
|
||
unknown
|
WMP11.AssocFile.MKA
|
||
unknown
|
WMP11.AssocFile.MKV
|
||
unknown
|
WMP11.AssocFile.MPEG
|
||
unknown
|
WMP11.AssocFile.MOV
|
||
unknown
|
WMP11.AssocFile.MP3
|
||
unknown
|
WMP11.AssocFile.MP4
|
||
unknown
|
Outlook.File.msg.15
|
||
unknown
|
WMP11.AssocFile.M2TS
|
||
unknown
|
ocxfile
|
||
unknown
|
PowerPoint.OpenDocumentPresentation.12
|
||
unknown
|
Excel.OpenDocumentSpreadsheet.12
|
||
unknown
|
Word.OpenDocumentText.12
|
||
unknown
|
otffile
|
||
unknown
|
pngfile
|
||
unknown
|
PowerPoint.Template.8
|
||
unknown
|
PowerPoint.TemplateMacroEnabled.12
|
||
unknown
|
PowerPoint.Template.12
|
||
unknown
|
PowerPoint.Addin.12
|
||
unknown
|
PowerPoint.SlideShowMacroEnabled.12
|
||
unknown
|
PowerPoint.SlideShow.12
|
||
unknown
|
PowerPoint.Show.8
|
||
unknown
|
PowerPoint.ShowMacroEnabled.12
|
||
unknown
|
PowerPoint.Show.12
|
||
unknown
|
Microsoft.PowerShellScript.1
|
||
unknown
|
Microsoft.PowerShellXMLData.1
|
||
unknown
|
Microsoft.PowerShellData.1
|
||
unknown
|
Microsoft.PowerShellModule.1
|
||
unknown
|
Microsoft.PowerShellSessionConfiguration.1
|
||
unknown
|
rlefile
|
||
unknown
|
WMP11.AssocFile.MIDI
|
||
unknown
|
Word.RTF.8
|
||
unknown
|
SHCmdFile
|
||
unknown
|
SearchFolder
|
||
unknown
|
shtmlfile
|
||
unknown
|
PowerPoint.SlideMacroEnabled.12
|
||
unknown
|
PowerPoint.Slide.12
|
||
unknown
|
sysfile
|
||
unknown
|
TIFImage.Document
|
||
unknown
|
TIFImage.Document
|
||
unknown
|
WMP11.AssocFile.TTS
|
||
unknown
|
ttcfile
|
||
unknown
|
ttffile
|
||
unknown
|
txtfile
|
||
unknown
|
bootstrap.vsto.1
|
||
unknown
|
WMP11.AssocFile.WAV
|
||
unknown
|
WMP11.AssocFile.WAX
|
||
unknown
|
wdpfile
|
||
unknown
|
WMP11.AssocFile.ASF
|
||
unknown
|
WMP11.AssocFile.WMA
|
||
unknown
|
wmffile
|
||
unknown
|
WMP11.AssocFile.WMV
|
||
unknown
|
WMP11.AssocFile.ASX
|
||
unknown
|
WMP11.AssocFile.WPL
|
||
unknown
|
WMP11.AssocFile.WVX
|
||
unknown
|
Excel.AddInMacroEnabled
|
||
unknown
|
Excel.Sheet.8
|
||
unknown
|
Excel.SheetBinaryMacroEnabled.12
|
||
unknown
|
Excel.SheetMacroEnabled.12
|
||
unknown
|
Excel.Sheet.12
|
||
unknown
|
Excel.Template.8
|
||
unknown
|
Excel.TemplateMacroEnabled
|
||
unknown
|
Excel.Template
|
||
unknown
|
xmlfile
|
||
unknown
|
xslfile
|
||
unknown
|
SlowContextMenuEntries
|
||
unknown
|
SlowContextMenuEntries
|
||
unknown
|
SlowContextMenuEntries
|
||
unknown
|
SlowContextMenuEntries
|
||
unknown
|
SlowContextMenuEntries
|
||
unknown
|
SlowContextMenuEntries
|
||
unknown
|
SlowContextMenuEntries
|
||
unknown
|
TaskbarStateLastRun
|
||
unknown
|
Implementing
|
||
unknown
|
SlowContextMenuEntries
|
||
unknown
|
TaskbarStateLastRun
|
||
unknown
|
Implementing
|
||
unknown
|
SlowContextMenuEntries
|
||
unknown
|
SlowContextMenuEntries
|
||
unknown
|
TaskbarStateLastRun
|
||
unknown
|
Implementing
|
||
unknown
|
TaskbarStateLastRun
|
||
unknown
|
Implementing
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
|
{0BF754AA-C967-445C-AB3D-D8FDA9BAE7EF} {000214E4-0000-0000-C000-000000000046} 0xFFFF
|
||
HKEY_CURRENT_USER_Classes\Local Settings\MuiCache\1e\417C44EB
|
@C:\Windows\System32\display.dll,-4
|
||
HKEY_CURRENT_USER_Classes\Local Settings\MuiCache\1e\417C44EB
|
@C:\Windows\system32\themecpl.dll,-10
|
||
HKEY_CURRENT_USER_Classes\Local Settings\MuiCache\1e\417C44EB
|
@C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\oregres.dll,-123
|
||
HKEY_CURRENT_USER_Classes\Local Settings\MuiCache\1e\417C44EB
|
@C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\oregres.dll,-174
|
||
HKEY_CURRENT_USER_Classes\Local Settings\MuiCache\1e\417C44EB
|
@C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\oregres.dll,-131
|
||
HKEY_CURRENT_USER_Classes\Local Settings\MuiCache\1e\417C44EB
|
@C:\Windows\system32\notepad.exe,-469
|
||
HKEY_CURRENT_USER_Classes\Local Settings\MuiCache\1e\417C44EB
|
@C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\oregres.dll,-101
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
|
{A38B883C-1682-497E-97B0-0A3A9E801682} {886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99} 0xFFFF
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
|
SlowContextMenuEntries
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop
|
IconLayouts
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Security and Maintenance\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.102
|
CheckSetting
|
There are 203 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
400000
|
remote allocation
|
page execute and read and write
|
||
3720000
|
trusted library allocation
|
page read and write
|
||
34B0000
|
unclassified section
|
page execute and read and write
|
||
3E29000
|
trusted library allocation
|
page read and write
|
||
3310000
|
system
|
page execute and read and write
|
||
970000
|
unkown
|
page readonly
|
||
48A0000
|
unkown
|
page read and write
|
||
7FF5DEF4B000
|
unkown
|
page readonly
|
||
10531000
|
unkown
|
page read and write
|
||
98AD000
|
unkown
|
page read and write
|
||
98A1000
|
unkown
|
page read and write
|
||
C374000
|
unkown
|
page read and write
|
||
11A0000
|
unkown
|
page readonly
|
||
BF10000
|
unkown
|
page readonly
|
||
7DF4E6770000
|
unkown
|
page readonly
|
||
7930000
|
unkown
|
page readonly
|
||
C1CC000
|
unkown
|
page read and write
|
||
C034000
|
unkown
|
page read and write
|
||
A0A7000
|
unkown
|
page read and write
|
||
D60000
|
heap
|
page read and write
|
||
7DF4E6791000
|
unkown
|
page execute read
|
||
7FF5DF089000
|
unkown
|
page readonly
|
||
962B000
|
unkown
|
page read and write
|
||
BF82000
|
unkown
|
page read and write
|
||
2EB0000
|
unkown
|
page readonly
|
||
70CE000
|
heap
|
page read and write
|
||
7FF5DF591000
|
unkown
|
page readonly
|
||
980000
|
unkown
|
page readonly
|
||
7FF5DF122000
|
unkown
|
page readonly
|
||
7FF5DEF94000
|
unkown
|
page readonly
|
||
BFEF000
|
unkown
|
page read and write
|
||
F48000
|
stack
|
page read and write
|
||
7FF5DF3DF000
|
unkown
|
page readonly
|
||
1AFF000
|
stack
|
page read and write
|
||
A0B1000
|
unkown
|
page read and write
|
||
C4D7000
|
unkown
|
page read and write
|
||
2F10000
|
unkown
|
page read and write
|
||
4860000
|
unkown
|
page read and write
|
||
7870000
|
unkown
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
7FF5DF623000
|
unkown
|
page readonly
|
||
7FF5DF24E000
|
unkown
|
page readonly
|
||
A79000
|
system
|
page execute and read and write
|
||
537B000
|
trusted library allocation
|
page read and write
|
||
10531000
|
unkown
|
page read and write
|
||
59A0000
|
trusted library section
|
page read and write
|
||
7FF5DF045000
|
unkown
|
page readonly
|
||
7930000
|
unkown
|
page readonly
|
||
A6D2000
|
unkown
|
page read and write
|
||
308E000
|
trusted library allocation
|
page read and write
|
||
7FF5DE539000
|
unkown
|
page readonly
|
||
C183000
|
unkown
|
page read and write
|
||
9F74000
|
unkown
|
page read and write
|
||
A6F4000
|
unkown
|
page read and write
|
||
9718000
|
unkown
|
page read and write
|
||
34C0000
|
unkown
|
page read and write
|
||
BFA3000
|
unkown
|
page read and write
|
||
7FF5DF388000
|
unkown
|
page readonly
|
||
7FF5DEFAC000
|
unkown
|
page readonly
|
||
12D0000
|
heap
|
page read and write
|
||
14DC000
|
unclassified section
|
page execute and read and write
|
||
989F000
|
unkown
|
page read and write
|
||
7FF5DF169000
|
unkown
|
page readonly
|
||
7FF5DF39C000
|
unkown
|
page readonly
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
A104000
|
unkown
|
page read and write
|
||
3304000
|
unkown
|
page read and write
|
||
AF7E000
|
stack
|
page read and write
|
||
A7C000
|
system
|
page execute and read and write
|
||
A754000
|
unkown
|
page read and write
|
||
7FF5DF45C000
|
unkown
|
page readonly
|
||
A6D2000
|
unkown
|
page read and write
|
||
1195000
|
heap
|
page read and write
|
||
7FF5DF191000
|
unkown
|
page readonly
|
||
A104000
|
unkown
|
page read and write
|
||
AB0D000
|
stack
|
page read and write
|
||
A6EA000
|
unkown
|
page read and write
|
||
AC0D000
|
stack
|
page read and write
|
||
9F63000
|
unkown
|
page read and write
|
||
52C3000
|
unkown
|
page read and write
|
||
76F0000
|
unkown
|
page read and write
|
||
34EE000
|
heap
|
page read and write
|
||
7FF5DF549000
|
unkown
|
page readonly
|
||
7FF5DEE4E000
|
unkown
|
page readonly
|
||
7FF5DF539000
|
unkown
|
page readonly
|
||
3750000
|
trusted library allocation
|
page read and write
|
||
C1CC000
|
unkown
|
page read and write
|
||
B60A000
|
stack
|
page read and write
|
||
92DB000
|
stack
|
page read and write
|
||
BFA7000
|
unkown
|
page read and write
|
||
489A000
|
unkown
|
page read and write
|
||
7FF5DF310000
|
unkown
|
page readonly
|
||
97C9000
|
unkown
|
page read and write
|
||
A6F1000
|
unkown
|
page read and write
|
||
7830000
|
unkown
|
page read and write
|
||
53A0000
|
trusted library allocation
|
page read and write
|
||
9489000
|
stack
|
page read and write
|
||
7FF5DF349000
|
unkown
|
page readonly
|
||
7FF5DF343000
|
unkown
|
page readonly
|
||
B120000
|
unkown
|
page readonly
|
||
7FF5DF0CC000
|
unkown
|
page readonly
|
||
3E21000
|
trusted library allocation
|
page read and write
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
272D000
|
stack
|
page read and write
|
||
738E000
|
unkown
|
page read and write
|
||
D99000
|
heap
|
page read and write
|
||
4766000
|
unkown
|
page read and write
|
||
7FF5DF59E000
|
unkown
|
page readonly
|
||
C3B2000
|
unkown
|
page read and write
|
||
C149000
|
unkown
|
page read and write
|
||
7FF5DF08B000
|
unkown
|
page readonly
|
||
7FF5DF396000
|
unkown
|
page readonly
|
||
3454000
|
heap
|
page read and write
|
||
73A7000
|
unkown
|
page read and write
|
||
9409000
|
stack
|
page read and write
|
||
7A30000
|
unkown
|
page read and write
|
||
1063A000
|
heap
|
page read and write
|
||
7FF5DF26F000
|
unkown
|
page readonly
|
||
79E0000
|
unkown
|
page readonly
|
||
3D3D000
|
direct allocation
|
page execute and read and write
|
||
B1C0000
|
unkown
|
page readonly
|
||
BFA3000
|
unkown
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
7FF5DF48B000
|
unkown
|
page readonly
|
||
7FF5DF39C000
|
unkown
|
page readonly
|
||
5FD0000
|
heap
|
page read and write
|
||
73B8000
|
unkown
|
page read and write
|
||
ED04000
|
unkown
|
page read and write
|
||
3304000
|
unkown
|
page read and write
|
||
7FF5DEFC2000
|
unkown
|
page readonly
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
7FF5DF4BD000
|
unkown
|
page readonly
|
||
7FF5DF095000
|
unkown
|
page readonly
|
||
3454000
|
heap
|
page read and write
|
||
52C3000
|
unkown
|
page read and write
|
||
7840000
|
unkown
|
page read and write
|
||
97C1000
|
unkown
|
page read and write
|
||
7FF5DF18E000
|
unkown
|
page readonly
|
||
7FF5DF2E5000
|
unkown
|
page readonly
|
||
B9F0000
|
unkown
|
page read and write
|
||
C23D000
|
unkown
|
page read and write
|
||
7FF5DF195000
|
unkown
|
page readonly
|
||
7FF5DF3C6000
|
unkown
|
page readonly
|
||
13C0000
|
unclassified section
|
page execute and read and write
|
||
7FF5DF45A000
|
unkown
|
page readonly
|
||
ED04000
|
unkown
|
page read and write
|
||
BEF0000
|
heap
|
page read and write
|
||
7FF5DF3EA000
|
unkown
|
page readonly
|
||
1055F000
|
unkown
|
page read and write
|
||
96DF000
|
unkown
|
page read and write
|
||
7991000
|
unkown
|
page read and write
|
||
9F74000
|
unkown
|
page read and write
|
||
A708000
|
unkown
|
page read and write
|
||
BF40000
|
unkown
|
page read and write
|
||
7FF5DF20A000
|
unkown
|
page readonly
|
||
9C1D000
|
stack
|
page read and write
|
||
7FF5DF478000
|
unkown
|
page readonly
|
||
2E50000
|
unkown
|
page readonly
|
||
7FF5DF577000
|
unkown
|
page readonly
|
||
47F3000
|
unkown
|
page read and write
|
||
32B0000
|
unkown
|
page read and write
|
||
7C85000
|
stack
|
page read and write
|
||
B9E0000
|
unkown
|
page read and write
|
||
96F1000
|
unkown
|
page read and write
|
||
9F7C000
|
unkown
|
page read and write
|
||
5396000
|
trusted library allocation
|
page read and write
|
||
3375000
|
unkown
|
page read and write
|
||
7FF5DEFFC000
|
unkown
|
page readonly
|
||
7FF5DF0C3000
|
unkown
|
page readonly
|
||
7FF5DF229000
|
unkown
|
page readonly
|
||
479B000
|
unkown
|
page read and write
|
||
7FF5DEFE2000
|
unkown
|
page readonly
|
||
7FF5DF16B000
|
unkown
|
page readonly
|
||
96F1000
|
unkown
|
page read and write
|
||
7FF5DE4F2000
|
unkown
|
page readonly
|
||
7FF5DEE5A000
|
unkown
|
page readonly
|
||
73C3000
|
unkown
|
page read and write
|
||
7FF5DF2DA000
|
unkown
|
page readonly
|
||
7FF5DF4F7000
|
unkown
|
page readonly
|
||
7FF5DEFF5000
|
unkown
|
page readonly
|
||
73BA000
|
unkown
|
page read and write
|
||
7FF5DF47E000
|
unkown
|
page readonly
|
||
7FF5DF21B000
|
unkown
|
page readonly
|
||
3454000
|
heap
|
page read and write
|
||
7860000
|
unkown
|
page read and write
|
||
E2B0000
|
system
|
page execute and read and write
|
||
A690000
|
unkown
|
page read and write
|
||
9F23000
|
unkown
|
page read and write
|
||
405C000
|
trusted library allocation
|
page read and write
|
||
83B0000
|
unkown
|
page readonly
|
||
3454000
|
heap
|
page read and write
|
||
C4AE000
|
unkown
|
page read and write
|
||
A08D000
|
unkown
|
page read and write
|
||
C192000
|
unkown
|
page read and write
|
||
7C86000
|
stack
|
page read and write
|
||
48E0000
|
unkown
|
page read and write
|
||
C187000
|
unkown
|
page read and write
|
||
83B0000
|
unkown
|
page readonly
|
||
2F10000
|
unkown
|
page read and write
|
||
7FF5DF1ED000
|
unkown
|
page readonly
|
||
7FF5DF284000
|
unkown
|
page readonly
|
||
7FF5DE9C3000
|
unkown
|
page readonly
|
||
3394000
|
unkown
|
page read and write
|
||
2D61000
|
unkown
|
page read and write
|
||
C24C000
|
unkown
|
page read and write
|
||
4760000
|
unkown
|
page read and write
|
||
479B000
|
unkown
|
page read and write
|
||
7FF5DE531000
|
unkown
|
page readonly
|
||
7FF5DF36A000
|
unkown
|
page readonly
|
||
1190000
|
heap
|
page read and write
|
||
7FF5DF0A5000
|
unkown
|
page readonly
|
||
9E0000
|
unkown
|
page readonly
|
||
8C29000
|
stack
|
page read and write
|
||
7FF5DF211000
|
unkown
|
page readonly
|
||
9729000
|
unkown
|
page read and write
|
||
53A2000
|
trusted library allocation
|
page read and write
|
||
2DF0000
|
heap
|
page read and write
|
||
7FF5DF04D000
|
unkown
|
page readonly
|
||
C23D000
|
unkown
|
page read and write
|
||
AB2F000
|
stack
|
page read and write
|
||
1280000
|
trusted library allocation
|
page read and write
|
||
10548000
|
unkown
|
page read and write
|
||
7FF5DF380000
|
unkown
|
page readonly
|
||
1294000
|
trusted library allocation
|
page read and write
|
||
7FF5DF452000
|
unkown
|
page readonly
|
||
7FF5DF571000
|
unkown
|
page readonly
|
||
98A7000
|
unkown
|
page read and write
|
||
3450000
|
heap
|
page read and write
|
||
962B000
|
unkown
|
page read and write
|
||
12A0000
|
trusted library allocation
|
page read and write
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
C3E4000
|
unkown
|
page read and write
|
||
7FF5DF1D1000
|
unkown
|
page readonly
|
||
A760000
|
unkown
|
page read and write
|
||
7FF5DF4FB000
|
unkown
|
page readonly
|
||
B9BF000
|
stack
|
page read and write
|
||
C319000
|
unkown
|
page read and write
|
||
7FF5DE539000
|
unkown
|
page readonly
|
||
33C0000
|
unkown
|
page readonly
|
||
7FF5DF3B5000
|
unkown
|
page readonly
|
||
96F5000
|
unkown
|
page read and write
|
||
2E50000
|
unkown
|
page readonly
|
||
7FF5DF3FC000
|
unkown
|
page readonly
|
||
16CE000
|
direct allocation
|
page execute and read and write
|
||
7FF5DF089000
|
unkown
|
page readonly
|
||
BF6D000
|
unkown
|
page read and write
|
||
7FF5DF52D000
|
unkown
|
page readonly
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
10565000
|
unkown
|
page read and write
|
||
7FF5DF5B0000
|
unkown
|
page readonly
|
||
7FF5DF53F000
|
unkown
|
page readonly
|
||
7FF5DF3B9000
|
unkown
|
page readonly
|
||
73AF000
|
unkown
|
page read and write
|
||
3375000
|
unkown
|
page read and write
|
||
C19D000
|
unkown
|
page read and write
|
||
7FF5DF343000
|
unkown
|
page readonly
|
||
1056E000
|
unkown
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
C187000
|
unkown
|
page read and write
|
||
7FF5DF49C000
|
unkown
|
page readonly
|
||
2DED000
|
stack
|
page read and write
|
||
7870000
|
unkown
|
page read and write
|
||
3750000
|
trusted library allocation
|
page read and write
|
||
7FF5DF584000
|
unkown
|
page readonly
|
||
7FF5DF0D2000
|
unkown
|
page readonly
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
95EE000
|
stack
|
page read and write
|
||
C18A000
|
unkown
|
page read and write
|
||
7B60000
|
unkown
|
page readonly
|
||
7DF4E6780000
|
unkown
|
page readonly
|
||
7A30000
|
unkown
|
page read and write
|
||
A760000
|
unkown
|
page read and write
|
||
5630000
|
heap
|
page read and write
|
||
7FF5DF2ED000
|
unkown
|
page readonly
|
||
8A36000
|
unkown
|
page read and write
|
||
BFA7000
|
unkown
|
page read and write
|
||
7FF5DF606000
|
unkown
|
page readonly
|
||
7FF5DEF06000
|
unkown
|
page readonly
|
||
C1C4000
|
unkown
|
page read and write
|
||
5450000
|
heap
|
page read and write
|
||
C24C000
|
unkown
|
page read and write
|
||
488A000
|
unkown
|
page read and write
|
||
7FF5DF091000
|
unkown
|
page readonly
|
||
EC86000
|
unkown
|
page read and write
|
||
3185000
|
stack
|
page read and write
|
||
E06000
|
heap
|
page read and write
|
||
9F3E000
|
unkown
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
1491000
|
trusted library allocation
|
page execute and read and write
|
||
802E000
|
stack
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
7FF5DF5A8000
|
unkown
|
page readonly
|
||
83D0000
|
unkown
|
page read and write
|
||
C087000
|
unkown
|
page read and write
|
||
73E5000
|
unkown
|
page read and write
|
||
C18A000
|
unkown
|
page read and write
|
||
A708000
|
unkown
|
page read and write
|
||
7FF5DF478000
|
unkown
|
page readonly
|
||
9F10000
|
unkown
|
page read and write
|
||
53C0000
|
trusted library allocation
|
page read and write
|
||
9E9E000
|
stack
|
page read and write
|
||
7FF5DF0A2000
|
unkown
|
page readonly
|
||
7FF5DF09B000
|
unkown
|
page readonly
|
||
A8AE000
|
stack
|
page read and write
|
||
C18A000
|
unkown
|
page read and write
|
||
10534000
|
unkown
|
page read and write
|
||
4766000
|
unkown
|
page read and write
|
||
7FF5DF2F3000
|
unkown
|
page readonly
|
||
7FF5DEE43000
|
unkown
|
page readonly
|
||
3454000
|
heap
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
13F0000
|
heap
|
page read and write
|
||
A40000
|
unkown
|
page readonly
|
||
7FF5DF5B3000
|
unkown
|
page readonly
|
||
7FF5DF23B000
|
unkown
|
page readonly
|
||
7FF5DF248000
|
unkown
|
page readonly
|
||
3454000
|
heap
|
page read and write
|
||
AB8D000
|
stack
|
page read and write
|
||
7FF5DF0F6000
|
unkown
|
page readonly
|
||
9D1F000
|
stack
|
page read and write
|
||
5453000
|
heap
|
page read and write
|
||
790A000
|
stack
|
page read and write
|
||
27DE000
|
unkown
|
page read and write
|
||
10535000
|
unkown
|
page read and write
|
||
7FF5DF4AB000
|
unkown
|
page readonly
|
||
48B0000
|
unkown
|
page read and write
|
||
FF1000
|
unkown
|
page readonly
|
||
A02D000
|
unkown
|
page read and write
|
||
1195000
|
heap
|
page read and write
|
||
7FF5DF55A000
|
unkown
|
page readonly
|
||
C76000
|
stack
|
page read and write
|
||
9F7C000
|
unkown
|
page read and write
|
||
48A0000
|
unkown
|
page read and write
|
||
4F1C000
|
stack
|
page read and write
|
||
AD2B000
|
stack
|
page read and write
|
||
9FA0000
|
unkown
|
page read and write
|
||
C54B000
|
unkown
|
page read and write
|
||
10632000
|
heap
|
page read and write
|
||
34FD000
|
heap
|
page read and write
|
||
7FF5DF58A000
|
unkown
|
page readonly
|
||
53D0000
|
trusted library allocation
|
page read and write
|
||
76B0000
|
trusted library allocation
|
page execute and read and write
|
||
A9EE000
|
stack
|
page read and write
|
||
38E9000
|
heap
|
page read and write
|
||
7FF5DF3A1000
|
unkown
|
page readonly
|
||
ACCE000
|
stack
|
page read and write
|
||
7FF5DEF57000
|
unkown
|
page readonly
|
||
739B000
|
unkown
|
page read and write
|
||
6810000
|
trusted library allocation
|
page read and write
|
||
BF9F000
|
unkown
|
page read and write
|
||
C4BD000
|
unkown
|
page read and write
|
||
FF1000
|
unkown
|
page readonly
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
7FF5DF3D4000
|
unkown
|
page readonly
|
||
70C0000
|
heap
|
page read and write
|
||
96F5000
|
unkown
|
page read and write
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
7FF5DF364000
|
unkown
|
page readonly
|
||
38B7000
|
heap
|
page read and write
|
||
7690000
|
trusted library allocation
|
page read and write
|
||
C048000
|
unkown
|
page read and write
|
||
AC0D000
|
stack
|
page read and write
|
||
A76C000
|
unkown
|
page read and write
|
||
73CD000
|
unkown
|
page read and write
|
||
9605000
|
unkown
|
page read and write
|
||
D60000
|
heap
|
page read and write
|
||
ADCF000
|
stack
|
page read and write
|
||
95F0000
|
unkown
|
page read and write
|
||
13DE000
|
stack
|
page read and write
|
||
970000
|
unkown
|
page readonly
|
||
1190000
|
heap
|
page read and write
|
||
2DEE000
|
stack
|
page read and write
|
||
C23D000
|
unkown
|
page read and write
|
||
C75000
|
stack
|
page read and write
|
||
E80000
|
unkown
|
page read and write
|
||
848E000
|
stack
|
page read and write
|
||
7FF5DF5BE000
|
unkown
|
page readonly
|
||
7FF5DF2E2000
|
unkown
|
page readonly
|
||
3382000
|
unkown
|
page read and write
|
||
7FF5DEFAC000
|
unkown
|
page readonly
|
||
A0F7000
|
unkown
|
page read and write
|
||
B4DB000
|
stack
|
page read and write
|
||
7ACE000
|
stack
|
page read and write
|
||
1055E000
|
unkown
|
page read and write
|
||
7FF5DF58A000
|
unkown
|
page readonly
|
||
7FF5DE9CB000
|
unkown
|
page readonly
|
||
5480000
|
trusted library allocation
|
page read and write
|
||
14C0000
|
unclassified section
|
page execute and read and write
|
||
5640000
|
trusted library allocation
|
page execute and read and write
|
||
34EE000
|
heap
|
page read and write
|
||
2F0C000
|
trusted library allocation
|
page read and write
|
||
7FF5DF207000
|
unkown
|
page readonly
|
||
5110000
|
unkown
|
page write copy
|
||
47EC000
|
unkown
|
page read and write
|
||
1053D000
|
unkown
|
page read and write
|
||
AF0C000
|
stack
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
7FF5DF429000
|
unkown
|
page readonly
|
||
7FF5DF0C9000
|
unkown
|
page readonly
|
||
A703000
|
unkown
|
page read and write
|
||
7FF5DF08F000
|
unkown
|
page readonly
|
||
C192000
|
unkown
|
page read and write
|
||
1880000
|
unclassified section
|
page execute and read and write
|
||
99AB000
|
unkown
|
page read and write
|
||
A0FC000
|
unkown
|
page read and write
|
||
7395000
|
unkown
|
page read and write
|
||
A106000
|
unkown
|
page read and write
|
||
7FF5DF486000
|
unkown
|
page readonly
|
||
9564000
|
unkown
|
page read and write
|
||
7910000
|
unkown
|
page readonly
|
||
1530000
|
direct allocation
|
page execute and read and write
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
7399000
|
unkown
|
page read and write
|
||
9716000
|
unkown
|
page read and write
|
||
9B1D000
|
stack
|
page read and write
|
||
ADC0000
|
unkown
|
page readonly
|
||
C159000
|
unkown
|
page read and write
|
||
A42000
|
unkown
|
page readonly
|
||
AEF0000
|
unkown
|
page read and write
|
||
7E80000
|
trusted library section
|
page read and write
|
||
7FF5DF081000
|
unkown
|
page readonly
|
||
A09A000
|
unkown
|
page read and write
|
||
10520000
|
unkown
|
page read and write
|
||
7FF5DF341000
|
unkown
|
page readonly
|
||
874C000
|
stack
|
page read and write
|
||
971A000
|
unkown
|
page read and write
|
||
2890000
|
unkown
|
page readonly
|
||
978C000
|
unkown
|
page read and write
|
||
2E10000
|
heap
|
page execute and read and write
|
||
7FF5DF25B000
|
unkown
|
page readonly
|
||
3362000
|
unkown
|
page read and write
|
||
143E000
|
stack
|
page read and write
|
||
7FF5DF0C1000
|
unkown
|
page readonly
|
||
A754000
|
unkown
|
page read and write
|
||
C35A000
|
unkown
|
page read and write
|
||
BFA5000
|
unkown
|
page read and write
|
||
C525000
|
unkown
|
page read and write
|
||
73E5000
|
unkown
|
page read and write
|
||
B500000
|
unkown
|
page readonly
|
||
3454000
|
heap
|
page read and write
|
||
28D0000
|
heap
|
page read and write
|
||
B589000
|
stack
|
page read and write
|
||
7FF5DF2CB000
|
unkown
|
page readonly
|
||
8EA8000
|
stack
|
page read and write
|
||
C24C000
|
unkown
|
page read and write
|
||
4750000
|
unkown
|
page read and write
|
||
5750000
|
heap
|
page execute and read and write
|
||
3454000
|
heap
|
page read and write
|
||
34F9000
|
heap
|
page read and write
|
||
9716000
|
unkown
|
page read and write
|
||
5360000
|
trusted library allocation
|
page read and write
|
||
E5A000
|
heap
|
page read and write
|
||
7DF4E6781000
|
unkown
|
page execute read
|
||
7800000
|
unkown
|
page read and write
|
||
A106000
|
unkown
|
page read and write
|
||
47B6000
|
unkown
|
page read and write
|
||
7FF5DEF94000
|
unkown
|
page readonly
|
||
7FF5DF0C3000
|
unkown
|
page readonly
|
||
5260000
|
heap
|
page read and write
|
||
7FF5DEEEB000
|
unkown
|
page readonly
|
||
7DF4E6771000
|
unkown
|
page execute read
|
||
73C3000
|
unkown
|
page read and write
|
||
7FF5DEFCB000
|
unkown
|
page readonly
|
||
5370000
|
trusted library allocation
|
page read and write
|
||
7ACE000
|
stack
|
page read and write
|
||
7FF5DF3F7000
|
unkown
|
page readonly
|
||
7FF5DF3AA000
|
unkown
|
page readonly
|
||
A703000
|
unkown
|
page read and write
|
||
B589000
|
stack
|
page read and write
|
||
A690000
|
unkown
|
page read and write
|
||
987C000
|
unkown
|
page read and write
|
||
4855000
|
unkown
|
page read and write
|
||
7FF5DF1F4000
|
unkown
|
page readonly
|
||
E246000
|
unkown
|
page execute and read and write
|
||
8400000
|
heap
|
page read and write
|
||
7D89000
|
stack
|
page read and write
|
||
BFDF000
|
unkown
|
page read and write
|
||
A6EE000
|
unkown
|
page read and write
|
||
973C000
|
unkown
|
page read and write
|
||
7FF5DF25E000
|
unkown
|
page readonly
|
||
7FF5DF392000
|
unkown
|
page readonly
|
||
10500000
|
unkown
|
page read and write
|
||
7FF5DF50F000
|
unkown
|
page readonly
|
||
7FF5DF07D000
|
unkown
|
page readonly
|
||
336F000
|
unkown
|
page read and write
|
||
A6EE000
|
unkown
|
page read and write
|
||
C4B5000
|
unkown
|
page read and write
|
||
12BA000
|
trusted library allocation
|
page execute and read and write
|
||
1490000
|
heap
|
page read and write
|
||
BF10000
|
unkown
|
page readonly
|
||
7800000
|
unkown
|
page read and write
|
||
E5E000
|
heap
|
page read and write
|
||
12A3000
|
trusted library allocation
|
page read and write
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
7910000
|
unkown
|
page readonly
|
||
7FF5DEE52000
|
unkown
|
page readonly
|
||
7FF5DF0C1000
|
unkown
|
page readonly
|
||
32FB000
|
stack
|
page read and write
|
||
790A000
|
stack
|
page read and write
|
||
7FF5DF4D5000
|
unkown
|
page readonly
|
||
A7AD000
|
stack
|
page read and write
|
||
FCE000
|
heap
|
page read and write
|
||
9F2A000
|
unkown
|
page read and write
|
||
F0E000
|
heap
|
page read and write
|
||
7FF5DF591000
|
unkown
|
page readonly
|
||
3454000
|
heap
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
7FF5DF3F5000
|
unkown
|
page readonly
|
||
C183000
|
unkown
|
page read and write
|
||
7830000
|
unkown
|
page read and write
|
||
7FF5DF0F6000
|
unkown
|
page readonly
|
||
3454000
|
heap
|
page read and write
|
||
7FF5DF5D6000
|
unkown
|
page readonly
|
||
AF4D000
|
stack
|
page read and write
|
||
A6CF000
|
unkown
|
page read and write
|
||
7FF5DEFE2000
|
unkown
|
page readonly
|
||
34F8000
|
heap
|
page read and write
|
||
F00000
|
heap
|
page read and write
|
||
7395000
|
unkown
|
page read and write
|
||
C159000
|
unkown
|
page read and write
|
||
AE0B000
|
stack
|
page read and write
|
||
A09A000
|
unkown
|
page read and write
|
||
5241000
|
unkown
|
page read and write
|
||
7FF5DF57F000
|
unkown
|
page readonly
|
||
7FF5DEFE8000
|
unkown
|
page readonly
|
||
970C000
|
unkown
|
page read and write
|
||
2FDC000
|
stack
|
page read and write
|
||
7FF5DF21C000
|
unkown
|
page readonly
|
||
2D1E000
|
stack
|
page read and write
|
||
7DF5E895F000
|
unkown
|
page readonly
|
||
AEF0000
|
unkown
|
page read and write
|
||
10630000
|
heap
|
page read and write
|
||
54EB000
|
stack
|
page read and write
|
||
7DF4E6771000
|
unkown
|
page execute read
|
||
C1CC000
|
unkown
|
page read and write
|
||
C2E4000
|
unkown
|
page read and write
|
||
7DF4E6781000
|
unkown
|
page execute read
|
||
34FF000
|
heap
|
page read and write
|
||
47EC000
|
unkown
|
page read and write
|
||
7FF5DF169000
|
unkown
|
page readonly
|
||
7FF5DEFC2000
|
unkown
|
page readonly
|
||
E00000
|
heap
|
page read and write
|
||
A6CF000
|
unkown
|
page read and write
|
||
14D9000
|
unclassified section
|
page execute and read and write
|
||
E80000
|
unkown
|
page read and write
|
||
A760000
|
unkown
|
page read and write
|
||
9A6C000
|
stack
|
page read and write
|
||
73BC000
|
unkown
|
page read and write
|
||
9D9F000
|
stack
|
page read and write
|
||
7FF5DEF06000
|
unkown
|
page readonly
|
||
7FF5DF5FF000
|
unkown
|
page readonly
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
7370000
|
heap
|
page read and write
|
||
7FF5DF5B5000
|
unkown
|
page readonly
|
||
A08D000
|
unkown
|
page read and write
|
||
7FF5DF577000
|
unkown
|
page readonly
|
||
73B6000
|
unkown
|
page read and write
|
||
98AD000
|
unkown
|
page read and write
|
||
E70000
|
unkown
|
page readonly
|
||
7FF5DF195000
|
unkown
|
page readonly
|
||
27F0000
|
heap
|
page read and write
|
||
28A0000
|
unkown
|
page readonly
|
||
7FF5DEE43000
|
unkown
|
page readonly
|
||
3362000
|
unkown
|
page read and write
|
||
C034000
|
unkown
|
page read and write
|
||
B259000
|
stack
|
page read and write
|
||
7FF5DF248000
|
unkown
|
page readonly
|
||
1083F000
|
system
|
page read and write
|
||
3DAE000
|
direct allocation
|
page execute and read and write
|
||
3B89000
|
heap
|
page read and write
|
||
BF6D000
|
unkown
|
page read and write
|
||
7FF5DEFB7000
|
unkown
|
page readonly
|
||
7FF5DEE52000
|
unkown
|
page readonly
|
||
C435000
|
unkown
|
page read and write
|
||
3373000
|
unkown
|
page read and write
|
||
9F2A000
|
unkown
|
page read and write
|
||
7230000
|
unkown
|
page read and write
|
||
1055E000
|
unkown
|
page read and write
|
||
4788000
|
unkown
|
page read and write
|
||
9E9E000
|
stack
|
page read and write
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
9E0000
|
unkown
|
page readonly
|
||
A8EE000
|
stack
|
page read and write
|
||
7FF5DF361000
|
unkown
|
page readonly
|
||
ECC4000
|
unkown
|
page read and write
|
||
7FF5DEF4B000
|
unkown
|
page readonly
|
||
A767000
|
unkown
|
page read and write
|
||
7FF5DF12A000
|
unkown
|
page readonly
|
||
AA2D000
|
stack
|
page read and write
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
7FF5DF60D000
|
unkown
|
page readonly
|
||
2E3E000
|
stack
|
page read and write
|
||
2790000
|
heap
|
page read and write
|
||
AD2B000
|
stack
|
page read and write
|
||
7DF4E67A1000
|
unkown
|
page execute read
|
||
96ED000
|
unkown
|
page read and write
|
||
7DFE000
|
stack
|
page read and write
|
||
7FF5DF2E5000
|
unkown
|
page readonly
|
||
1878000
|
direct allocation
|
page execute and read and write
|
||
3750000
|
trusted library allocation
|
page read and write
|
||
B45A000
|
stack
|
page read and write
|
||
B60A000
|
stack
|
page read and write
|
||
3750000
|
trusted library allocation
|
page read and write
|
||
9729000
|
unkown
|
page read and write
|
||
C4E9000
|
unkown
|
page read and write
|
||
A0F7000
|
unkown
|
page read and write
|
||
2EC0000
|
unkown
|
page readonly
|
||
27E0000
|
heap
|
page read and write
|
||
C187000
|
unkown
|
page read and write
|
||
7FF5DF443000
|
unkown
|
page readonly
|
||
38B1000
|
heap
|
page read and write
|
||
7FF5DF0A2000
|
unkown
|
page readonly
|
||
A6F8000
|
unkown
|
page read and write
|
||
7FF5DF626000
|
unkown
|
page readonly
|
||
7FF5DF017000
|
unkown
|
page readonly
|
||
4824000
|
unkown
|
page read and write
|
||
980000
|
unkown
|
page readonly
|
||
BFA1000
|
unkown
|
page read and write
|
||
73AF000
|
unkown
|
page read and write
|
||
39B8000
|
heap
|
page read and write
|
||
3A50000
|
trusted library allocation
|
page execute and read and write
|
||
53B0000
|
trusted library allocation
|
page read and write
|
||
7FF5DF4E7000
|
unkown
|
page readonly
|
||
48B0000
|
unkown
|
page read and write
|
||
74A9000
|
unkown
|
page read and write
|
||
2870000
|
unkown
|
page read and write
|
||
5A00000
|
trusted library allocation
|
page read and write
|
||
7FF5DF091000
|
unkown
|
page readonly
|
||
C359000
|
unkown
|
page read and write
|
||
BF90000
|
unkown
|
page read and write
|
||
B1C0000
|
unkown
|
page readonly
|
||
7FF5DF3B5000
|
unkown
|
page readonly
|
||
7FF5DF3BE000
|
unkown
|
page readonly
|
||
BFDF000
|
unkown
|
page read and write
|
||
A772000
|
unkown
|
page read and write
|
||
7FF5DF567000
|
unkown
|
page readonly
|
||
7FF5DEFDD000
|
unkown
|
page readonly
|
||
7FF5DF038000
|
unkown
|
page readonly
|
||
E0F000
|
heap
|
page read and write
|
||
47A2000
|
unkown
|
page read and write
|
||
C51D000
|
unkown
|
page read and write
|
||
7FF5DF49C000
|
unkown
|
page readonly
|
||
9380000
|
unkown
|
page readonly
|
||
EC43000
|
unkown
|
page read and write
|
||
1055E000
|
unkown
|
page read and write
|
||
973C000
|
unkown
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
34F9000
|
heap
|
page read and write
|
||
D69000
|
heap
|
page read and write
|
||
10544000
|
unkown
|
page read and write
|
||
B09E000
|
stack
|
page read and write
|
||
8A36000
|
unkown
|
page read and write
|
||
901B000
|
stack
|
page read and write
|
||
5470000
|
trusted library allocation
|
page execute and read and write
|
||
BF7E000
|
unkown
|
page read and write
|
||
7FF5DE535000
|
unkown
|
page readonly
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
9C9C000
|
stack
|
page read and write
|
||
2E21000
|
trusted library allocation
|
page read and write
|
||
7FF5DF26F000
|
unkown
|
page readonly
|
||
2EC0000
|
unkown
|
page readonly
|
||
C4D6000
|
unkown
|
page read and write
|
||
7FF5DEFCB000
|
unkown
|
page readonly
|
||
7FF5DF519000
|
unkown
|
page readonly
|
||
A098000
|
unkown
|
page read and write
|
||
909E000
|
stack
|
page read and write
|
||
7FF5DEFF8000
|
unkown
|
page readonly
|
||
FF0000
|
heap
|
page read and write
|
||
73B2000
|
unkown
|
page read and write
|
||
2890000
|
unkown
|
page readonly
|
||
7FF5DEE56000
|
unkown
|
page readonly
|
||
1045000
|
heap
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
9E1E000
|
stack
|
page read and write
|
||
C50A000
|
unkown
|
page read and write
|
||
BF8C000
|
unkown
|
page read and write
|
||
7FF5DF55A000
|
unkown
|
page readonly
|
||
7DF4E6760000
|
unkown
|
page readonly
|
||
77F0000
|
unkown
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
5400000
|
trusted library allocation
|
page read and write
|
||
7FF5DEFE8000
|
unkown
|
page readonly
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
7FF5DF067000
|
unkown
|
page readonly
|
||
7FF5DEE5A000
|
unkown
|
page readonly
|
||
7FF5DF59E000
|
unkown
|
page readonly
|
||
BA76000
|
stack
|
page read and write
|
||
7FF5DF08F000
|
unkown
|
page readonly
|
||
12C7000
|
trusted library allocation
|
page execute and read and write
|
||
C319000
|
unkown
|
page read and write
|
||
336F000
|
unkown
|
page read and write
|
||
C1C4000
|
unkown
|
page read and write
|
||
7FF5DEFA6000
|
unkown
|
page readonly
|
||
2E30000
|
unkown
|
page read and write
|
||
14AD000
|
trusted library allocation
|
page execute and read and write
|
||
5660000
|
heap
|
page read and write
|
||
7FF5DF23A000
|
unkown
|
page readonly
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
7FF5DEFDD000
|
unkown
|
page readonly
|
||
C3DD000
|
unkown
|
page read and write
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
7FF5DF537000
|
unkown
|
page readonly
|
||
7FF5DF017000
|
unkown
|
page readonly
|
||
7FF5DF582000
|
unkown
|
page readonly
|
||
3720000
|
trusted library allocation
|
page read and write
|
||
848E000
|
stack
|
page read and write
|
||
C4E2000
|
unkown
|
page read and write
|
||
7D0D000
|
stack
|
page read and write
|
||
C003000
|
unkown
|
page read and write
|
||
B120000
|
unkown
|
page readonly
|
||
2C9A000
|
stack
|
page read and write
|
||
3382000
|
unkown
|
page read and write
|
||
10632000
|
heap
|
page read and write
|
||
7FF5DF5F6000
|
unkown
|
page readonly
|
||
7FF5DEE56000
|
unkown
|
page readonly
|
||
73B4000
|
unkown
|
page read and write
|
||
874C000
|
stack
|
page read and write
|
||
7FF5C0B6B000
|
unkown
|
page readonly
|
||
3EDD000
|
direct allocation
|
page execute and read and write
|
||
7FF5DF3B9000
|
unkown
|
page readonly
|
||
BF82000
|
unkown
|
page read and write
|
||
7FF5DE9C3000
|
unkown
|
page readonly
|
||
A5AE000
|
stack
|
page read and write
|
||
7FF5DF54D000
|
unkown
|
page readonly
|
||
336C000
|
unkown
|
page read and write
|
||
7FF5DF08B000
|
unkown
|
page readonly
|
||
3373000
|
unkown
|
page read and write
|
||
987C000
|
unkown
|
page read and write
|
||
7FF5DF567000
|
unkown
|
page readonly
|
||
9F60000
|
unkown
|
page read and write
|
||
9B99000
|
stack
|
page read and write
|
||
C319000
|
unkown
|
page read and write
|
||
7FF5DF0D2000
|
unkown
|
page readonly
|
||
8590000
|
unkown
|
page readonly
|
||
7FF5DF532000
|
unkown
|
page readonly
|
||
7FF5DF507000
|
unkown
|
page readonly
|
||
7FF5DF156000
|
unkown
|
page readonly
|
||
51DC000
|
stack
|
page read and write
|
||
7DF4E67A1000
|
unkown
|
page execute read
|
||
9564000
|
unkown
|
page read and write
|
||
E5E000
|
heap
|
page read and write
|
||
9718000
|
unkown
|
page read and write
|
||
C01A000
|
unkown
|
page read and write
|
||
9F63000
|
unkown
|
page read and write
|
||
7FF5DF277000
|
unkown
|
page readonly
|
||
17FD000
|
direct allocation
|
page execute and read and write
|
||
B45A000
|
stack
|
page read and write
|
||
7FF5DF156000
|
unkown
|
page readonly
|
||
9FC3000
|
unkown
|
page read and write
|
||
7FF5DF435000
|
unkown
|
page readonly
|
||
3454000
|
heap
|
page read and write
|
||
7FF5DF398000
|
unkown
|
page readonly
|
||
97F3000
|
unkown
|
page read and write
|
||
96DF000
|
unkown
|
page read and write
|
||
4788000
|
unkown
|
page read and write
|
||
AE6F000
|
stack
|
page read and write
|
||
47D9000
|
unkown
|
page read and write
|
||
C1A9000
|
unkown
|
page read and write
|
||
8670000
|
unkown
|
page read and write
|
||
7FF5DF4F7000
|
unkown
|
page readonly
|
||
FB00000
|
unkown
|
page read and write
|
||
7FF5DF5AE000
|
unkown
|
page readonly
|
||
EC86000
|
unkown
|
page read and write
|
||
7FF5DF3F7000
|
unkown
|
page readonly
|
||
5110000
|
unkown
|
page write copy
|
||
7FF5DF01B000
|
unkown
|
page readonly
|
||
7FF5DF310000
|
unkown
|
page readonly
|
||
3371000
|
unkown
|
page read and write
|
||
1659000
|
direct allocation
|
page execute and read and write
|
||
83D0000
|
unkown
|
page read and write
|
||
7FF5DF3FC000
|
unkown
|
page readonly
|
||
950B000
|
unkown
|
page read and write
|
||
7499000
|
unkown
|
page read and write
|
||
E3A9000
|
system
|
page execute and read and write
|
||
9C9B000
|
stack
|
page read and write
|
||
7FF5DF0C9000
|
unkown
|
page readonly
|
||
C474000
|
unkown
|
page read and write
|
||
7FF5DF038000
|
unkown
|
page readonly
|
||
9F78000
|
unkown
|
page read and write
|
||
34F5000
|
heap
|
page read and write
|
||
7FF5DF582000
|
unkown
|
page readonly
|
||
7FF5DF4F3000
|
unkown
|
page readonly
|
||
EF7000
|
stack
|
page read and write
|
||
E5E000
|
heap
|
page read and write
|
||
34F9000
|
heap
|
page read and write
|
||
BD7F000
|
stack
|
page read and write
|
||
3356000
|
unkown
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
48E0000
|
unkown
|
page read and write
|
||
8910000
|
unkown
|
page read and write
|
||
3370000
|
heap
|
page read and write
|
||
487A000
|
unkown
|
page read and write
|
||
7FF5DF458000
|
unkown
|
page readonly
|
||
C435000
|
unkown
|
page read and write
|
||
7FF5DF126000
|
unkown
|
page readonly
|
||
9F0000
|
heap
|
page read and write
|
||
BF40000
|
unkown
|
page read and write
|
||
3281000
|
stack
|
page read and write
|
||
B830000
|
unkown
|
page readonly
|
||
FF7000
|
heap
|
page read and write
|
||
2D61000
|
unkown
|
page read and write
|
||
E0F000
|
heap
|
page read and write
|
||
335B000
|
unkown
|
page read and write
|
||
47F1000
|
unkown
|
page read and write
|
||
7FF5DF5F6000
|
unkown
|
page readonly
|
||
F43000
|
heap
|
page read and write
|
||
5270000
|
heap
|
page read and write
|
||
9489000
|
stack
|
page read and write
|
||
2C0C000
|
heap
|
page read and write
|
||
7FF5DEE4E000
|
unkown
|
page readonly
|
||
7FF5DF3F1000
|
unkown
|
page readonly
|
||
99AB000
|
unkown
|
page read and write
|
||
7FF5DF4F3000
|
unkown
|
page readonly
|
||
A0B1000
|
unkown
|
page read and write
|
||
8F3C000
|
unkown
|
page read and write
|
||
74D6000
|
unkown
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
A0A5000
|
unkown
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
7FF5DF606000
|
unkown
|
page readonly
|
||
EC8B000
|
unkown
|
page read and write
|
||
A08A000
|
unkown
|
page read and write
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
BF84000
|
unkown
|
page read and write
|
||
989F000
|
unkown
|
page read and write
|
||
1497000
|
heap
|
page read and write
|
||
830F000
|
stack
|
page read and write
|
||
1053E000
|
unkown
|
page read and write
|
||
B9F0000
|
unkown
|
page read and write
|
||
7FF5DF4AB000
|
unkown
|
page readonly
|
||
C147000
|
unkown
|
page read and write
|
||
C4B4000
|
unkown
|
page read and write
|
||
38B1000
|
heap
|
page read and write
|
||
7FF5DF2CB000
|
unkown
|
page readonly
|
||
3EE1000
|
direct allocation
|
page execute and read and write
|
||
A5EE000
|
stack
|
page read and write
|
||
7FF5DF4E3000
|
unkown
|
page readonly
|
||
C34E000
|
unkown
|
page read and write
|
||
9F3E000
|
unkown
|
page read and write
|
||
7FF5DEF87000
|
unkown
|
page readonly
|
||
7FF5DF5F0000
|
unkown
|
page readonly
|
||
BFAF000
|
unkown
|
page read and write
|
||
7FF5DF126000
|
unkown
|
page readonly
|
||
7FF5DF366000
|
unkown
|
page readonly
|
||
BFAF000
|
unkown
|
page read and write
|
||
38B0000
|
heap
|
page read and write
|
||
7A40000
|
unkown
|
page readonly
|
||
73B4000
|
unkown
|
page read and write
|
||
7DF5E895F000
|
unkown
|
page readonly
|
||
12C2000
|
trusted library allocation
|
page read and write
|
||
3BCE000
|
stack
|
page read and write
|
||
838B000
|
stack
|
page read and write
|
||
7FF5DF42F000
|
unkown
|
page readonly
|
||
ACAE000
|
stack
|
page read and write
|
||
A0FC000
|
unkown
|
page read and write
|
||
7FF5DF47E000
|
unkown
|
page readonly
|
||
BFAB000
|
unkown
|
page read and write
|
||
7FF5DF4D5000
|
unkown
|
page readonly
|
||
147B000
|
stack
|
page read and write
|
||
830F000
|
stack
|
page read and write
|
||
C013000
|
unkown
|
page read and write
|
||
7FF5DF25B000
|
unkown
|
page readonly
|
||
D50000
|
unkown
|
page read and write
|
||
13A0000
|
unkown
|
page readonly
|
||
7FF5DF425000
|
unkown
|
page readonly
|
||
739B000
|
unkown
|
page read and write
|
||
487A000
|
unkown
|
page read and write
|
||
FCE000
|
stack
|
page read and write
|
||
7FF5DF62C000
|
unkown
|
page readonly
|
||
7DF4E6761000
|
unkown
|
page execute read
|
||
539D000
|
trusted library allocation
|
page read and write
|
||
7FF5DF229000
|
unkown
|
page readonly
|
||
BFA1000
|
unkown
|
page read and write
|
||
9FC3000
|
unkown
|
page read and write
|
||
C048000
|
unkown
|
page read and write
|
||
8670000
|
unkown
|
page read and write
|
||
7FF5C0B6B000
|
unkown
|
page readonly
|
||
3394000
|
unkown
|
page read and write
|
||
B6A000
|
stack
|
page read and write
|
||
B010000
|
unkown
|
page read and write
|
||
7FF5DEFFC000
|
unkown
|
page readonly
|
||
7DF4E6780000
|
unkown
|
page readonly
|
||
7FF5C0B65000
|
unkown
|
page readonly
|
||
7FF5DEFB7000
|
unkown
|
page readonly
|
||
7940000
|
unkown
|
page readonly
|
||
BD7F000
|
stack
|
page read and write
|
||
C354000
|
unkown
|
page read and write
|
||
901B000
|
stack
|
page read and write
|
||
7FF5DEFF8000
|
unkown
|
page readonly
|
||
7FF5DF5FC000
|
unkown
|
page readonly
|
||
73BC000
|
unkown
|
page read and write
|
||
935D000
|
stack
|
page read and write
|
||
C013000
|
unkown
|
page read and write
|
||
37A0000
|
heap
|
page read and write
|
||
F35000
|
heap
|
page read and write
|
||
7FF5DF2E2000
|
unkown
|
page readonly
|
||
C423000
|
unkown
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
7FF5DF3C2000
|
unkown
|
page readonly
|
||
7FF5DE5CC000
|
unkown
|
page readonly
|
||
7FF5DF382000
|
unkown
|
page readonly
|
||
E399000
|
system
|
page execute and read and write
|
||
7FF5DF507000
|
unkown
|
page readonly
|
||
7FF5DF5FF000
|
unkown
|
page readonly
|
||
C14E000
|
unkown
|
page read and write
|
||
C34E000
|
unkown
|
page read and write
|
||
7FF5DEFA6000
|
unkown
|
page readonly
|
||
5620000
|
heap
|
page read and write
|
||
7FF5DF4EC000
|
unkown
|
page readonly
|
||
7FF5DF5BE000
|
unkown
|
page readonly
|
||
3D39000
|
direct allocation
|
page execute and read and write
|
||
9F51000
|
unkown
|
page read and write
|
||
971A000
|
unkown
|
page read and write
|
||
BF90000
|
unkown
|
page read and write
|
||
13F0000
|
trusted library allocation
|
page read and write
|
||
7FF5DF5CC000
|
unkown
|
page readonly
|
||
BCE000
|
unkown
|
page read and write
|
||
7FF5DF539000
|
unkown
|
page readonly
|
||
C183000
|
unkown
|
page read and write
|
||
7DF4E6760000
|
unkown
|
page readonly
|
||
7FF5DF5A3000
|
unkown
|
page readonly
|
||
7FF5DF41B000
|
unkown
|
page readonly
|
||
7FF5DF095000
|
unkown
|
page readonly
|
||
C1A9000
|
unkown
|
page read and write
|
||
28D0000
|
heap
|
page read and write
|
||
7FF5DEFF5000
|
unkown
|
page readonly
|
||
D99000
|
heap
|
page read and write
|
||
27F0000
|
unkown
|
page readonly
|
||
7B4A000
|
stack
|
page read and write
|
||
7FF5DF067000
|
unkown
|
page readonly
|
||
C19D000
|
unkown
|
page read and write
|
||
9700000
|
unkown
|
page read and write
|
||
34F7000
|
heap
|
page read and write
|
||
7FF5DF2BA000
|
unkown
|
page readonly
|
||
7FF5DF2BA000
|
unkown
|
page readonly
|
||
7DF4E6761000
|
unkown
|
page execute read
|
||
726E000
|
stack
|
page read and write
|
||
7FF5DF443000
|
unkown
|
page readonly
|
||
7FF5DF122000
|
unkown
|
page readonly
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
7FF5DF626000
|
unkown
|
page readonly
|
||
C1C4000
|
unkown
|
page read and write
|
||
3110000
|
heap
|
page read and write
|
||
320B000
|
stack
|
page read and write
|
||
7FF5DF3D4000
|
unkown
|
page readonly
|
||
34B0000
|
unkown
|
page readonly
|
||
7FF5DF081000
|
unkown
|
page readonly
|
||
BFEF000
|
unkown
|
page read and write
|
||
88E0000
|
unkown
|
page read and write
|
||
B4DB000
|
stack
|
page read and write
|
||
129D000
|
trusted library allocation
|
page execute and read and write
|
||
BF9B000
|
unkown
|
page read and write
|
||
73B8000
|
unkown
|
page read and write
|
||
C4B3000
|
unkown
|
page read and write
|
||
76E2000
|
trusted library allocation
|
page read and write
|
||
7FF5DF1D1000
|
unkown
|
page readonly
|
||
7FF5DF4C6000
|
unkown
|
page readonly
|
||
A6F1000
|
unkown
|
page read and write
|
||
A0A5000
|
unkown
|
page read and write
|
||
7502000
|
unkown
|
page read and write
|
||
9F23000
|
unkown
|
page read and write
|
||
FD0000
|
heap
|
page read and write
|
||
34A0000
|
heap
|
page read and write
|
||
3371000
|
unkown
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
73B2000
|
unkown
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
7810000
|
unkown
|
page read and write
|
||
3F66000
|
unclassified section
|
page read and write
|
||
121E000
|
stack
|
page read and write
|
||
3356000
|
unkown
|
page read and write
|
||
7FF5DF2F3000
|
unkown
|
page readonly
|
||
3454000
|
heap
|
page read and write
|
||
103E000
|
stack
|
page read and write
|
||
7FF5DF4A6000
|
unkown
|
page readonly
|
||
10500000
|
unkown
|
page read and write
|
||
3750000
|
trusted library allocation
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
E207000
|
unkown
|
page execute and read and write
|
||
10532000
|
unkown
|
page read and write
|
||
2C48000
|
trusted library allocation
|
page read and write
|
||
940D000
|
stack
|
page read and write
|
||
7FF5DF09B000
|
unkown
|
page readonly
|
||
7FF5DEF87000
|
unkown
|
page readonly
|
||
7FF5DF488000
|
unkown
|
page readonly
|
||
7FF5DEFAF000
|
unkown
|
page readonly
|
||
914B000
|
stack
|
page read and write
|
||
7FF5DF01B000
|
unkown
|
page readonly
|
||
7FF5DF41B000
|
unkown
|
page readonly
|
||
3454000
|
heap
|
page read and write
|
||
ECC4000
|
unkown
|
page read and write
|
||
8C28000
|
stack
|
page read and write
|
||
7FF5DF388000
|
unkown
|
page readonly
|
||
7FF5DF3E4000
|
unkown
|
page readonly
|
||
5650000
|
trusted library allocation
|
page read and write
|
||
7FF5DF62C000
|
unkown
|
page readonly
|
||
7FF5DF54D000
|
unkown
|
page readonly
|
||
5460000
|
trusted library allocation
|
page read and write
|
||
7FA10000
|
trusted library allocation
|
page execute and read and write
|
||
76AA000
|
trusted library allocation
|
page read and write
|
||
598E000
|
stack
|
page read and write
|
||
3349000
|
unkown
|
page read and write
|
||
1034000
|
heap
|
page read and write
|
||
BEF0000
|
heap
|
page read and write
|
||
17F6000
|
direct allocation
|
page execute and read and write
|
||
95EE000
|
stack
|
page read and write
|
||
7FF5DF21F000
|
unkown
|
page readonly
|
||
7FF5DF571000
|
unkown
|
page readonly
|
||
E397000
|
system
|
page execute and read and write
|
||
34B0000
|
unkown
|
page readonly
|
||
7FF5DF16B000
|
unkown
|
page readonly
|
||
A6EA000
|
unkown
|
page read and write
|
||
7FF5DF5E9000
|
unkown
|
page readonly
|
||
9D9F000
|
stack
|
page read and write
|
||
4824000
|
unkown
|
page read and write
|
||
BFAD000
|
unkown
|
page read and write
|
||
7FF5DF5E9000
|
unkown
|
page readonly
|
||
A75B000
|
unkown
|
page read and write
|
||
7B50000
|
unkown
|
page readonly
|
||
7FF5DEFBD000
|
unkown
|
page readonly
|
||
2F40000
|
heap
|
page read and write
|
||
9700000
|
unkown
|
page read and write
|
||
7FF5DF24E000
|
unkown
|
page readonly
|
||
7FF5DF488000
|
unkown
|
page readonly
|
||
7FF5DF07D000
|
unkown
|
page readonly
|
||
488A000
|
unkown
|
page read and write
|
||
7FF5DF532000
|
unkown
|
page readonly
|
||
7F2E000
|
stack
|
page read and write
|
||
7FF5DF211000
|
unkown
|
page readonly
|
||
7FF5DF2DA000
|
unkown
|
page readonly
|
||
736F000
|
stack
|
page read and write
|
||
7FF5DF42F000
|
unkown
|
page readonly
|
||
7FF5DF57F000
|
unkown
|
page readonly
|
||
C34E000
|
unkown
|
page read and write
|
||
10646000
|
system
|
page read and write
|
||
7FF5DF06F000
|
unkown
|
page readonly
|
||
C474000
|
unkown
|
page read and write
|
||
53D5000
|
trusted library allocation
|
page read and write
|
||
C1A9000
|
unkown
|
page read and write
|
||
33C0000
|
unkown
|
page readonly
|
||
C298000
|
unkown
|
page read and write
|
||
27D0000
|
unkown
|
page read and write
|
||
9F0000
|
heap
|
page read and write
|
||
3106000
|
stack
|
page read and write
|
||
7FF5DF36A000
|
unkown
|
page readonly
|
||
C354000
|
unkown
|
page read and write
|
||
F3B000
|
stack
|
page read and write
|
||
7FF5DF5B5000
|
unkown
|
page readonly
|
||
A0A7000
|
unkown
|
page read and write
|
||
76F0000
|
unkown
|
page read and write
|
||
C298000
|
unkown
|
page read and write
|
||
3F52000
|
direct allocation
|
page execute and read and write
|
||
32B0000
|
unkown
|
page read and write
|
||
8390000
|
unkown
|
page read and write
|
||
5391000
|
trusted library allocation
|
page read and write
|
||
BE0000
|
heap
|
page read and write
|
||
7FF5DEFAF000
|
unkown
|
page readonly
|
||
10548000
|
unkown
|
page read and write
|
||
7840000
|
unkown
|
page read and write
|
||
7FF5DE535000
|
unkown
|
page readonly
|
||
73A3000
|
unkown
|
page read and write
|
||
3BFE000
|
heap
|
page read and write
|
||
7FF5DF48B000
|
unkown
|
page readonly
|
||
335B000
|
unkown
|
page read and write
|
||
7FF5DF029000
|
unkown
|
page readonly
|
||
BF98000
|
unkown
|
page read and write
|
||
C192000
|
unkown
|
page read and write
|
||
C003000
|
unkown
|
page read and write
|
||
971C000
|
unkown
|
page read and write
|
||
47D9000
|
unkown
|
page read and write
|
||
7FF5DF425000
|
unkown
|
page readonly
|
||
C2E4000
|
unkown
|
page read and write
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
7FF5DF221000
|
unkown
|
page readonly
|
||
3C10000
|
direct allocation
|
page execute and read and write
|
||
7386000
|
heap
|
page read and write
|
||
34FF000
|
heap
|
page read and write
|
||
7FF5DF0F1000
|
unkown
|
page readonly
|
||
7FF5DF3E4000
|
unkown
|
page readonly
|
||
2DFF000
|
unkown
|
page read and write
|
||
7FF5DF60D000
|
unkown
|
page readonly
|
||
12B2000
|
trusted library allocation
|
page read and write
|
||
73A3000
|
unkown
|
page read and write
|
||
BF9D000
|
unkown
|
page read and write
|
||
7FF5DF3AA000
|
unkown
|
page readonly
|
||
3454000
|
heap
|
page read and write
|
||
AE6F000
|
stack
|
page read and write
|
||
FAC000
|
heap
|
page read and write
|
||
3290000
|
unkown
|
page readonly
|
||
98AD000
|
unkown
|
page read and write
|
||
4855000
|
unkown
|
page read and write
|
||
8400000
|
heap
|
page read and write
|
||
10565000
|
unkown
|
page read and write
|
||
54F0000
|
trusted library section
|
page readonly
|
||
7FF5DF2FE000
|
unkown
|
page readonly
|
||
5FC0000
|
heap
|
page read and write
|
||
34F9000
|
heap
|
page read and write
|
||
6820000
|
trusted library allocation
|
page read and write
|
||
1996000
|
unclassified section
|
page execute and read and write
|
||
28A0000
|
unkown
|
page readonly
|
||
7FF5DF458000
|
unkown
|
page readonly
|
||
10544000
|
unkown
|
page read and write
|
||
BF9D000
|
unkown
|
page read and write
|
||
7FF5DF364000
|
unkown
|
page readonly
|
||
34EA000
|
heap
|
page read and write
|
||
125E000
|
stack
|
page read and write
|
||
B830000
|
unkown
|
page readonly
|
||
7FF5DF3BE000
|
unkown
|
page readonly
|
||
2EB0000
|
unkown
|
page readonly
|
||
10544000
|
unkown
|
page read and write
|
||
7FF5DF361000
|
unkown
|
page readonly
|
||
7FF5DF45A000
|
unkown
|
page readonly
|
||
C3E7000
|
unkown
|
page read and write
|
||
1480000
|
trusted library allocation
|
page execute and read and write
|
||
7FF5DEF90000
|
unkown
|
page readonly
|
||
11A0000
|
unkown
|
page readonly
|
||
77F0000
|
unkown
|
page read and write
|
||
9704000
|
unkown
|
page read and write
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
914B000
|
stack
|
page read and write
|
||
34F9000
|
heap
|
page read and write
|
||
5241000
|
unkown
|
page read and write
|
||
7FF5DF396000
|
unkown
|
page readonly
|
||
9F92000
|
unkown
|
page read and write
|
||
7D90000
|
unkown
|
page read and write
|
||
39DA000
|
heap
|
page read and write
|
||
BFB3000
|
unkown
|
page read and write
|
||
9FA0000
|
unkown
|
page read and write
|
||
7FF5DEF84000
|
unkown
|
page readonly
|
||
74F1000
|
unkown
|
page read and write
|
||
98A1000
|
unkown
|
page read and write
|
||
10548000
|
unkown
|
page read and write
|
||
88DE000
|
stack
|
page read and write
|
||
C2E4000
|
unkown
|
page read and write
|
||
7FF5DF5F0000
|
unkown
|
page readonly
|
||
7380000
|
unkown
|
page read and write
|
||
2C00000
|
heap
|
page read and write
|
||
2D1E000
|
stack
|
page read and write
|
||
3364000
|
unkown
|
page read and write
|
||
7380000
|
unkown
|
page read and write
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
1293000
|
trusted library allocation
|
page execute and read and write
|
||
2EC0000
|
trusted library allocation
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
9704000
|
unkown
|
page read and write
|
||
7FF5DF5A8000
|
unkown
|
page readonly
|
||
7FF5C0B65000
|
unkown
|
page readonly
|
||
12CB000
|
trusted library allocation
|
page execute and read and write
|
||
3364000
|
unkown
|
page read and write
|
||
7FF5DF3A1000
|
unkown
|
page readonly
|
||
A072000
|
unkown
|
page read and write
|
||
7FF5DF537000
|
unkown
|
page readonly
|
||
7FF5DF029000
|
unkown
|
page readonly
|
||
7FF5DF349000
|
unkown
|
page readonly
|
||
C354000
|
unkown
|
page read and write
|
||
53E0000
|
trusted library allocation
|
page read and write
|
||
7FF5DF4BD000
|
unkown
|
page readonly
|
||
4828000
|
unkown
|
page read and write
|
||
950B000
|
unkown
|
page read and write
|
||
7FF5DEFBD000
|
unkown
|
page readonly
|
||
76A0000
|
trusted library allocation
|
page read and write
|
||
401B000
|
trusted library allocation
|
page read and write
|
||
7FF5DF25E000
|
unkown
|
page readonly
|
||
7DF5E896A000
|
unkown
|
page readonly
|
||
7D89000
|
stack
|
page read and write
|
||
BFA5000
|
unkown
|
page read and write
|
||
4828000
|
unkown
|
page read and write
|
||
B010000
|
unkown
|
page read and write
|
||
7FF5DF191000
|
unkown
|
page readonly
|
||
A02D000
|
unkown
|
page read and write
|
||
987C000
|
unkown
|
page read and write
|
||
1063A000
|
heap
|
page read and write
|
||
52D9000
|
unkown
|
page read and write
|
||
A703000
|
unkown
|
page read and write
|
||
F70000
|
heap
|
page read and write
|
||
7FF5DF5B0000
|
unkown
|
page readonly
|
||
E130000
|
unkown
|
page execute and read and write
|
||
7FF5DF392000
|
unkown
|
page readonly
|
||
AB0D000
|
stack
|
page read and write
|
||
E70000
|
unkown
|
page readonly
|
||
7FF5DEFF0000
|
unkown
|
page readonly
|
||
9A6C000
|
stack
|
page read and write
|
||
147E000
|
stack
|
page read and write
|
||
7CBE000
|
stack
|
page read and write
|
||
7FF5DF5FC000
|
unkown
|
page readonly
|
||
7FF5DF1CD000
|
unkown
|
page readonly
|
||
7DF5E896A000
|
unkown
|
page readonly
|
||
6820000
|
trusted library allocation
|
page read and write
|
||
B9E0000
|
unkown
|
page read and write
|
||
6820000
|
trusted library allocation
|
page read and write
|
||
27F0000
|
unkown
|
page readonly
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
3A61000
|
trusted library allocation
|
page execute and read and write
|
||
3454000
|
heap
|
page read and write
|
||
47B6000
|
unkown
|
page read and write
|
||
3B01000
|
trusted library allocation
|
page execute and read and write
|
||
38B1000
|
heap
|
page read and write
|
||
7B4C000
|
stack
|
page read and write
|
||
5FF0000
|
heap
|
page read and write
|
||
59B5000
|
heap
|
page read and write
|
||
7FF5DF207000
|
unkown
|
page readonly
|
||
7FF5DEF57000
|
unkown
|
page readonly
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
AEEE000
|
stack
|
page read and write
|
||
594E000
|
stack
|
page read and write
|
||
7FF5DF5B3000
|
unkown
|
page readonly
|
||
971C000
|
unkown
|
page read and write
|
||
8390000
|
unkown
|
page read and write
|
||
8F2B000
|
stack
|
page read and write
|
||
7FF5DF3F1000
|
unkown
|
page readonly
|
||
9F51000
|
unkown
|
page read and write
|
||
6820000
|
trusted library allocation
|
page read and write
|
||
97F3000
|
unkown
|
page read and write
|
||
3B8D000
|
heap
|
page read and write
|
||
13DB000
|
unclassified section
|
page execute and read and write
|
||
83E0000
|
unkown
|
page read and write
|
||
3AF0000
|
trusted library allocation
|
page execute and read and write
|
||
3454000
|
heap
|
page read and write
|
||
88E0000
|
unkown
|
page read and write
|
||
989F000
|
unkown
|
page read and write
|
||
95F0000
|
unkown
|
page read and write
|
||
7D0D000
|
stack
|
page read and write
|
||
B04E000
|
stack
|
page read and write
|
||
73BA000
|
unkown
|
page read and write
|
||
13A1000
|
unkown
|
page readonly
|
||
7FF5DF52D000
|
unkown
|
page readonly
|
||
BFC3000
|
unkown
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
7DF4E6791000
|
unkown
|
page execute read
|
||
A6F8000
|
unkown
|
page read and write
|
||
9B1E000
|
stack
|
page read and write
|
||
7FF5DF4FB000
|
unkown
|
page readonly
|
||
3A60000
|
heap
|
page read and write
|
||
7FF5DEEEB000
|
unkown
|
page readonly
|
||
7FF5DF045000
|
unkown
|
page readonly
|
||
E91000
|
unkown
|
page read and write
|
||
7FF5DF3F5000
|
unkown
|
page readonly
|
||
7FF5DE9CB000
|
unkown
|
page readonly
|
||
9714000
|
unkown
|
page read and write
|
||
7FF5DF4A6000
|
unkown
|
page readonly
|
||
FA7000
|
heap
|
page read and write
|
||
74F1000
|
unkown
|
page read and write
|
||
7FF5DEF84000
|
unkown
|
page readonly
|
||
12C0000
|
trusted library allocation
|
page read and write
|
||
7FF5DF5AE000
|
unkown
|
page readonly
|
||
7B50000
|
unkown
|
page readonly
|
||
C525000
|
unkown
|
page read and write
|
||
7FF5DF43C000
|
unkown
|
page readonly
|
||
ADC0000
|
unkown
|
page readonly
|
||
7FF5DF3DF000
|
unkown
|
page readonly
|
||
7230000
|
unkown
|
page read and write
|
||
970C000
|
unkown
|
page read and write
|
||
12B6000
|
trusted library allocation
|
page execute and read and write
|
||
8910000
|
unkown
|
page read and write
|
||
3290000
|
unkown
|
page readonly
|
||
9E1E000
|
stack
|
page read and write
|
||
C4B1000
|
unkown
|
page read and write
|
||
9F92000
|
unkown
|
page read and write
|
||
BF9B000
|
unkown
|
page read and write
|
||
978C000
|
unkown
|
page read and write
|
||
7FF5DF398000
|
unkown
|
page readonly
|
||
7FF5DF2ED000
|
unkown
|
page readonly
|
||
12AD000
|
trusted library allocation
|
page execute and read and write
|
||
9F27000
|
unkown
|
page read and write
|
||
7390000
|
heap
|
page read and write
|
||
3185000
|
stack
|
page read and write
|
||
EC43000
|
unkown
|
page read and write
|
||
98A7000
|
unkown
|
page read and write
|
||
7A40000
|
unkown
|
page readonly
|
||
B500000
|
unkown
|
page readonly
|
||
7FF5DF519000
|
unkown
|
page readonly
|
||
AFFD000
|
stack
|
page read and write
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
7FF5DF4E3000
|
unkown
|
page readonly
|
||
3454000
|
heap
|
page read and write
|
||
59FE000
|
stack
|
page read and write
|
||
E3C000
|
stack
|
page read and write
|
||
7FF5DF20A000
|
unkown
|
page readonly
|
||
7FF5DF3C6000
|
unkown
|
page readonly
|
||
EC8B000
|
unkown
|
page read and write
|
||
A072000
|
unkown
|
page read and write
|
||
2AFE000
|
stack
|
page read and write
|
||
7D90000
|
unkown
|
page read and write
|
||
9714000
|
unkown
|
page read and write
|
||
BF84000
|
unkown
|
page read and write
|
||
7991000
|
unkown
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
C424000
|
unkown
|
page read and write
|
||
83E0000
|
unkown
|
page read and write
|
||
415F000
|
unclassified section
|
page read and write
|
||
E5B000
|
heap
|
page read and write
|
||
73B6000
|
unkown
|
page read and write
|
||
7810000
|
unkown
|
page read and write
|
||
10630000
|
heap
|
page read and write
|
||
9D1F000
|
stack
|
page read and write
|
||
7CFE000
|
stack
|
page read and write
|
||
7FF5DE531000
|
unkown
|
page readonly
|
||
7FF5DF549000
|
unkown
|
page readonly
|
||
9F60000
|
unkown
|
page read and write
|
||
BD0000
|
heap
|
page read and write
|
||
7FF5DF12A000
|
unkown
|
page readonly
|
||
8F2C000
|
stack
|
page read and write
|
||
7FF5DF18E000
|
unkown
|
page readonly
|
||
F80000
|
heap
|
page read and write
|
||
73A7000
|
unkown
|
page read and write
|
||
538E000
|
trusted library allocation
|
page read and write
|
||
838B000
|
stack
|
page read and write
|
||
7BBE000
|
stack
|
page read and write
|
||
7940000
|
unkown
|
page readonly
|
||
E09000
|
heap
|
page read and write
|
||
7FF5DF551000
|
unkown
|
page readonly
|
||
7FF5DF222000
|
unkown
|
page readonly
|
||
7FF5DEF90000
|
unkown
|
page readonly
|
||
D50000
|
unkown
|
page read and write
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
34E0000
|
heap
|
page read and write
|
||
3281000
|
stack
|
page read and write
|
||
FE0000
|
unkown
|
page read and write
|
||
7399000
|
unkown
|
page read and write
|
||
7FF5DF45C000
|
unkown
|
page readonly
|
||
7FF5DF0CC000
|
unkown
|
page readonly
|
||
C298000
|
unkown
|
page read and write
|
||
52D9000
|
unkown
|
page read and write
|
||
2CE0000
|
heap
|
page read and write
|
||
7FF5DE5CC000
|
unkown
|
page readonly
|
||
47F3000
|
unkown
|
page read and write
|
||
17E1000
|
direct allocation
|
page execute and read and write
|
||
1480000
|
trusted library allocation
|
page execute and read and write
|
||
B09E000
|
stack
|
page read and write
|
||
1290000
|
trusted library allocation
|
page read and write
|
||
13BF000
|
stack
|
page read and write
|
||
73CD000
|
unkown
|
page read and write
|
||
BA76000
|
stack
|
page read and write
|
||
339D000
|
unkown
|
page read and write
|
||
13DF000
|
unclassified section
|
page execute and read and write
|
||
7FF5DF1CD000
|
unkown
|
page readonly
|
||
7FF5DF06F000
|
unkown
|
page readonly
|
||
7FF5DF5D6000
|
unkown
|
page readonly
|
||
B359000
|
stack
|
page read and write
|
||
A60000
|
system
|
page execute and read and write
|
||
7FF5DF5A3000
|
unkown
|
page readonly
|
||
7FF5DF341000
|
unkown
|
page readonly
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
74A9000
|
unkown
|
page read and write
|
||
5462000
|
trusted library allocation
|
page read and write
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
9380000
|
unkown
|
page readonly
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
7860000
|
unkown
|
page read and write
|
||
1040000
|
heap
|
page read and write
|
||
96ED000
|
unkown
|
page read and write
|
||
7FF5DF1ED000
|
unkown
|
page readonly
|
||
4750000
|
unkown
|
page read and write
|
||
7FF5DF429000
|
unkown
|
page readonly
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
1015000
|
heap
|
page read and write
|
||
C01A000
|
unkown
|
page read and write
|
||
E00000
|
heap
|
page read and write
|
||
165D000
|
direct allocation
|
page execute and read and write
|
||
C159000
|
unkown
|
page read and write
|
||
7FF5DF4E7000
|
unkown
|
page readonly
|
||
BF9F000
|
unkown
|
page read and write
|
||
BFB3000
|
unkown
|
page read and write
|
||
7FF5DF382000
|
unkown
|
page readonly
|
||
B119000
|
stack
|
page read and write
|
||
7B60000
|
unkown
|
page readonly
|
||
BF98000
|
unkown
|
page read and write
|
||
2870000
|
unkown
|
page read and write
|
||
7FF5DF43C000
|
unkown
|
page readonly
|
||
9605000
|
unkown
|
page read and write
|
||
7FF5DF435000
|
unkown
|
page readonly
|
||
7FF5DF623000
|
unkown
|
page readonly
|
||
7DF4E6770000
|
unkown
|
page readonly
|
||
2E30000
|
unkown
|
page read and write
|
||
7FF5DF5CC000
|
unkown
|
page readonly
|
||
7FF5DF203000
|
unkown
|
page readonly
|
||
1031000
|
heap
|
page read and write
|
||
9F27000
|
unkown
|
page read and write
|
||
ACAE000
|
stack
|
page read and write
|
||
34F0000
|
heap
|
page read and write
|
||
7FF5DF452000
|
unkown
|
page readonly
|
||
12B0000
|
trusted library allocation
|
page read and write
|
||
6820000
|
trusted library allocation
|
page read and write
|
||
7FF5DF4EC000
|
unkown
|
page readonly
|
||
4860000
|
unkown
|
page read and write
|
||
9C1D000
|
stack
|
page read and write
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
34C0000
|
unkown
|
page read and write
|
||
3460000
|
trusted library allocation
|
page read and write
|
||
C19D000
|
unkown
|
page read and write
|
||
A098000
|
unkown
|
page read and write
|
||
7FF5DF0F1000
|
unkown
|
page readonly
|
||
3107000
|
stack
|
page read and write
|
||
8F3C000
|
unkown
|
page read and write
|
||
B9BF000
|
stack
|
page read and write
|
||
4E2E000
|
stack
|
page read and write
|
||
2F3E000
|
stack
|
page read and write
|
||
28D3000
|
heap
|
page read and write
|
||
59B0000
|
heap
|
page read and write
|
||
7FF5DF551000
|
unkown
|
page readonly
|
||
7499000
|
unkown
|
page read and write
|
||
BFC3000
|
unkown
|
page read and write
|
||
A08A000
|
unkown
|
page read and write
|
||
74D6000
|
unkown
|
page read and write
|
||
BFAB000
|
unkown
|
page read and write
|
||
885E000
|
stack
|
page read and write
|
||
7FF5DF04D000
|
unkown
|
page readonly
|
||
7FF5DF3EA000
|
unkown
|
page readonly
|
||
C3AF000
|
unkown
|
page read and write
|
||
BF7E000
|
unkown
|
page read and write
|
||
7FF5DF3C2000
|
unkown
|
page readonly
|
||
98A1000
|
unkown
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
7FF5DF366000
|
unkown
|
page readonly
|
||
7FF5DF584000
|
unkown
|
page readonly
|
||
7FF5DF53F000
|
unkown
|
page readonly
|
||
7FF5DF50F000
|
unkown
|
page readonly
|
||
28D3000
|
heap
|
page read and write
|
||
7FF5DF4C6000
|
unkown
|
page readonly
|
||
99AB000
|
unkown
|
page read and write
|
||
4760000
|
unkown
|
page read and write
|
||
47A2000
|
unkown
|
page read and write
|
||
8590000
|
unkown
|
page readonly
|
||
7FF5DF0A5000
|
unkown
|
page readonly
|
||
BFAD000
|
unkown
|
page read and write
|
||
489A000
|
unkown
|
page read and write
|
||
5440000
|
heap
|
page read and write
|
||
7FF5DF486000
|
unkown
|
page readonly
|
||
34FA000
|
heap
|
page read and write
|
||
1053D000
|
unkown
|
page read and write
|
||
1056E000
|
unkown
|
page read and write
|
||
5374000
|
trusted library allocation
|
page read and write
|
||
34F4000
|
heap
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
27D0000
|
unkown
|
page read and write
|
||
7FF5DEFF0000
|
unkown
|
page readonly
|
||
9F78000
|
unkown
|
page read and write
|
||
11C0000
|
heap
|
page read and write
|
||
336C000
|
unkown
|
page read and write
|
||
3454000
|
heap
|
page read and write
|
||
7FF5DF380000
|
unkown
|
page readonly
|
||
7FF5DF2FE000
|
unkown
|
page readonly
|
||
9F10000
|
unkown
|
page read and write
|
||
98A7000
|
unkown
|
page read and write
|
||
BF8C000
|
unkown
|
page read and write
|
||
FE0000
|
unkown
|
page read and write
|
||
7FF5DF284000
|
unkown
|
page readonly
|
||
47F1000
|
unkown
|
page read and write
|
||
A754000
|
unkown
|
page read and write
|
||
97F3000
|
unkown
|
page read and write
|
There are 1444 hidden memdumps, click here to show them.