Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
file.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Roaming\fbtdajh
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Roaming\fbtdajh:Zone.Identifier
|
ASCII text, with CRLF line terminators
|
modified
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\file.exe
|
"C:\Users\user\Desktop\file.exe"
|
||
C:\Windows\explorer.exe
|
C:\Windows\Explorer.EXE
|
||
C:\Users\user\AppData\Roaming\fbtdajh
|
C:\Users\user\AppData\Roaming\fbtdajh
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://unicea.ws/tmp/index.php
|
|||
http://nwgrus.ru/tmp/index.php
|
|||
http://tech-servers.in.net/tmp/index.php
|
|||
https://api.msn.com/v1/news/Feed/Windows?
|
unknown
|
||
http://www.autoitscript.com/autoit3/J
|
unknown
|
||
https://api.msn.com/I
|
unknown
|
||
https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DV
|
unknown
|
||
https://www.msn.com/en-us/money/savingandinvesting/americans-average-net-worth-by-age/ar-AA1h4ngF
|
unknown
|
||
https://assets.msn.com/weathermapdata/1/static/finance/1stparty/FinanceTaskbarIcons/Finance_Earnings
|
unknown
|
||
https://api.msn.com:443/v1/news/Feed/Windows?
|
unknown
|
||
https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gMhz
|
unknown
|
||
https://excel.office.com-
|
unknown
|
||
https://word.office.comM
|
unknown
|
||
https://api.msn.com/v1/news/Feed/Windows?activityId=435B7A89D7D74BDF801F2DA188906BAF&timeOut=5000&oc
|
unknown
|
||
https://assets.msn.com/weathermapdata/1/static/weather/Icons/JyNGQgA=/Condition/AAehwh2.svg
|
unknown
|
||
https://windows.msn.com:443/shell?osLocale=en-GB&chosenMarketReason=ImplicitNew
|
unknown
|
||
https://www.msn.com/en-us/money/realestate/why-this-florida-city-is-a-safe-haven-from-hurricanes/ar-
|
unknown
|
||
https://www.msn.com/en-us/travel/news/you-can-t-beat-bobby-flay-s-phoenix-airport-restaurant-one-of-
|
unknown
|
||
http://schemas.micro
|
unknown
|
||
https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gMhz-dark
|
unknown
|
||
https://www.msn.com/en-us/news/politics/how-donald-trump-helped-kari-lake-become-arizona-s-and-ameri
|
unknown
|
||
https://www.msn.com/en-us/money/personalfinance/money-matters-changing-institution-of-marriage/ar-AA
|
unknown
|
||
https://www.msn.com/en-us/news/us/biden-administration-waives-26-federal-laws-to-allow-border-wall-c
|
unknown
|
||
https://www.msn.com/en-us/weather/topstories/california-s-reservoirs-runneth-over-in-astounding-reve
|
unknown
|
||
https://powerpoint.office.comEMd
|
unknown
|
||
https://windows.msn.com:443/shellv2?osLocale=en-GB&chosenMarketReason=ImplicitNew
|
unknown
|
||
https://android.notify.windows.com/iOS
|
unknown
|
||
https://outlook.come
|
unknown
|
||
https://www.msn.com/en-us/news/technology/a-federal-emergency-alert-will-be-sent-to-us-phones-nation
|
unknown
|
||
https://activity.windows.com/UserActivity.ReadWrite.CreatedByApp
|
unknown
|
||
https://www.msn.com/en-us/news/us/dumb-and-dumber-12-states-with-the-absolute-worst-education-in-the
|
unknown
|
||
https://api.msn.com/
|
unknown
|
||
https://www.msn.com/en-us/news/politics/republicans-already-barred-trump-from-being-speaker-of-the-h
|
unknown
|
||
https://www.msn.com/en-us/news/politics/trump-campaign-says-he-raised-more-than-45-million-in-3rd-qu
|
unknown
|
||
https://wns.windows.com/e
|
unknown
|
||
https://www.msn.com/en-us/news/politics/kevin-mccarthy-s-ouster-as-house-speaker-could-cost-gop-its-
|
unknown
|
||
https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DV-dark
|
unknown
|
||
https://www.msn.com:443/en-us/feed
|
unknown
|
||
https://www.msn.com/en-us/news/world/us-supplies-ukraine-with-a-million-rounds-of-ammunition-seized-
|
unknown
|
||
https://www.msn.com/en-us/money/personalfinance/10-things-rich-people-never-buy-and-you-shouldn-t-ei
|
unknown
|
There are 30 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
nwgrus.ru
|
125.7.253.10
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
211.171.233.129
|
unknown
|
Korea Republic of
|
||
125.7.253.10
|
nwgrus.ru
|
Korea Republic of
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithProgids
|
Unpacker
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER_Classes\Local Settings\MuiCache\1e\417C44EB
|
@explorerframe.dll,-13137
|
||
HKEY_CURRENT_USER_Classes\Local Settings\MuiCache\1e\417C44EB
|
@explorerframe.dll,-13138
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
|
{A38B883C-1682-497E-97B0-0A3A9E801682} {886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99} 0xFFFF
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
Classes
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew
|
~reserved~
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop
|
IconLayouts
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Security and Maintenance\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.102
|
CheckSetting
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
|
SlowContextMenuEntries
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2\OpenWithProgids
|
WMP11.AssocFile.3G2
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp\OpenWithProgids
|
WMP11.AssocFile.3GP
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aac\OpenWithProgids
|
WMP11.AssocFile.ADTS
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\OpenWithProgids
|
WMP11.AssocFile.AIFF
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\OpenWithProgids
|
WMP11.AssocFile.ASF
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asx\OpenWithProgids
|
WMP11.AssocFile.ASX
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\OpenWithProgids
|
WMP11.AssocFile.AU
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au3\OpenWithProgids
|
AutoIt3Script
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\OpenWithProgids
|
WMP11.AssocFile.AVI
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\OpenWithProgids
|
Paint.Picture
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cab\OpenWithProgids
|
CABFolder
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cdxml\OpenWithProgids
|
Microsoft.PowerShellCmdletDefinitionXML.1
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.css\OpenWithProgids
|
CSSfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.csv\OpenWithProgids
|
Excel.CSV
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dds\OpenWithProgids
|
ddsfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\OpenWithProgids
|
Paint.Picture
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dll\OpenWithProgids
|
dllfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.doc\OpenWithProgids
|
Word.Document.8
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.docm\OpenWithProgids
|
Word.DocumentMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.docx\OpenWithProgids
|
Word.Document.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dot\OpenWithProgids
|
Word.Template.8
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotm\OpenWithProgids
|
Word.TemplateMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotx\OpenWithProgids
|
Word.Template.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\OpenWithProgids
|
emffile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\OpenWithProgids
|
exefile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\OpenWithProgids
|
WMP11.AssocFile.FLAC
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fon\OpenWithProgids
|
fonfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\OpenWithProgids
|
giffile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\OpenWithProgids
|
htmlfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ico\OpenWithProgids
|
icofile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inf\OpenWithProgids
|
inffile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ini\OpenWithProgids
|
inifile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\OpenWithProgids
|
pjpegfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\OpenWithProgids
|
jpegfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\OpenWithProgids
|
jpegfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jxr\OpenWithProgids
|
wdpfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lnk\OpenWithProgids
|
lnkfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v\OpenWithProgids
|
WMP11.AssocFile.MPEG
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2t\OpenWithProgids
|
WMP11.AssocFile.M2TS
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2ts\OpenWithProgids
|
WMP11.AssocFile.M2TS
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2V\OpenWithProgids
|
WMP11.AssocFile.MPEG
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\OpenWithProgids
|
WMP11.AssocFile.m3u
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\OpenWithProgids
|
WMP11.AssocFile.M4A
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v\OpenWithProgids
|
WMP11.AssocFile.MP4
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\OpenWithProgids
|
mhtmlfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\OpenWithProgids
|
mhtmlfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\OpenWithProgids
|
WMP11.AssocFile.MIDI
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\OpenWithProgids
|
WMP11.AssocFile.MIDI
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mk3d\OpenWithProgids
|
WMP11.AssocFile.MK3D
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mka\OpenWithProgids
|
WMP11.AssocFile.MKA
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mkv\OpenWithProgids
|
WMP11.AssocFile.MKV
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mod\OpenWithProgids
|
WMP11.AssocFile.MPEG
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov\OpenWithProgids
|
WMP11.AssocFile.MOV
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MP2\OpenWithProgids
|
WMP11.AssocFile.MP3
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2v\OpenWithProgids
|
WMP11.AssocFile.MPEG
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\OpenWithProgids
|
WMP11.AssocFile.MP3
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\OpenWithProgids
|
WMP11.AssocFile.MP4
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4v\OpenWithProgids
|
WMP11.AssocFile.MP4
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MPE\OpenWithProgids
|
WMP11.AssocFile.MPEG
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\OpenWithProgids
|
WMP11.AssocFile.MPEG
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.msg\OpenWithProgids
|
Outlook.File.msg.15
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mts\OpenWithProgids
|
WMP11.AssocFile.M2TS
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ocx\OpenWithProgids
|
ocxfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odp\OpenWithProgids
|
PowerPoint.OpenDocumentPresentation.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ods\OpenWithProgids
|
Excel.OpenDocumentSpreadsheet.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odt\OpenWithProgids
|
Word.OpenDocumentText.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.otf\OpenWithProgids
|
otffile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\OpenWithProgids
|
pngfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pot\OpenWithProgids
|
PowerPoint.Template.8
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potm\OpenWithProgids
|
PowerPoint.TemplateMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potx\OpenWithProgids
|
PowerPoint.Template.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppam\OpenWithProgids
|
PowerPoint.Addin.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsm\OpenWithProgids
|
PowerPoint.SlideShowMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsx\OpenWithProgids
|
PowerPoint.SlideShow.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppt\OpenWithProgids
|
PowerPoint.Show.8
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pptm\OpenWithProgids
|
PowerPoint.ShowMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pptx\OpenWithProgids
|
PowerPoint.Show.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ps1\OpenWithProgids
|
Microsoft.PowerShellScript.1
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ps1xml\OpenWithProgids
|
Microsoft.PowerShellXMLData.1
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd1\OpenWithProgids
|
Microsoft.PowerShellData.1
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psm1\OpenWithProgids
|
Microsoft.PowerShellModule.1
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pssc\OpenWithProgids
|
Microsoft.PowerShellSessionConfiguration.1
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\OpenWithProgids
|
rlefile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi\OpenWithProgids
|
WMP11.AssocFile.MIDI
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rtf\OpenWithProgids
|
Word.RTF.8
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.scf\OpenWithProgids
|
SHCmdFile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.search-ms\OpenWithProgids
|
SearchFolder
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\OpenWithProgids
|
shtmlfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sldm\OpenWithProgids
|
PowerPoint.SlideMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sldx\OpenWithProgids
|
PowerPoint.Slide.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\OpenWithProgids
|
WMP11.AssocFile.AU
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sys\OpenWithProgids
|
sysfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\OpenWithProgids
|
TIFImage.Document
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\OpenWithProgids
|
TIFImage.Document
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TS\OpenWithProgids
|
WMP11.AssocFile.TTS
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\OpenWithProgids
|
ttcfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\OpenWithProgids
|
ttffile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TTS\OpenWithProgids
|
WMP11.AssocFile.TTS
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt\OpenWithProgids
|
txtfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vsto\OpenWithProgids
|
bootstrap.vsto.1
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\OpenWithProgids
|
WMP11.AssocFile.WAV
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wax\OpenWithProgids
|
WMP11.AssocFile.WAX
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wdp\OpenWithProgids
|
wdpfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\OpenWithProgids
|
WMP11.AssocFile.ASF
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\OpenWithProgids
|
WMP11.AssocFile.WMA
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\OpenWithProgids
|
wmffile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\OpenWithProgids
|
WMP11.AssocFile.WMV
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmx\OpenWithProgids
|
WMP11.AssocFile.ASX
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.WPL\OpenWithProgids
|
WMP11.AssocFile.WPL
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wvx\OpenWithProgids
|
WMP11.AssocFile.WVX
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlam\OpenWithProgids
|
Excel.AddInMacroEnabled
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xls\OpenWithProgids
|
Excel.Sheet.8
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsb\OpenWithProgids
|
Excel.SheetBinaryMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsm\OpenWithProgids
|
Excel.SheetMacroEnabled.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsx\OpenWithProgids
|
Excel.Sheet.12
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlt\OpenWithProgids
|
Excel.Template.8
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xltm\OpenWithProgids
|
Excel.TemplateMacroEnabled
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xltx\OpenWithProgids
|
Excel.Template
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xml\OpenWithProgids
|
xmlfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xsl\OpenWithProgids
|
xslfile
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
|
SlowContextMenuEntries
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
TaskbarStateLastRun
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories64\{00021492-0000-0000-C000-000000000046}\Enum
|
Implementing
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
|
SlowContextMenuEntries
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
|
SlowContextMenuEntries
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
|
SlowContextMenuEntries
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
|
SlowContextMenuEntries
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
|
SlowContextMenuEntries
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
TaskbarStateLastRun
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories64\{00021492-0000-0000-C000-000000000046}\Enum
|
Implementing
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
|
SlowContextMenuEntries
|
There are 176 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
2D00000
|
direct allocation
|
page read and write
|
||
4A91000
|
unclassified section
|
page read and write
|
||
47A1000
|
unclassified section
|
page read and write
|
||
47A0000
|
direct allocation
|
page read and write
|
||
95EE000
|
stack
|
page read and write
|
||
EC44000
|
unkown
|
page read and write
|
||
7FF5DF156000
|
unkown
|
page readonly
|
||
BCB0000
|
unkown
|
page read and write
|
||
7FF5DF341000
|
unkown
|
page readonly
|
||
2DF0000
|
unkown
|
page read and write
|
||
7FF5DF458000
|
unkown
|
page readonly
|
||
7C10000
|
unkown
|
page read and write
|
||
9718000
|
unkown
|
page read and write
|
||
92F0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
C34E000
|
unkown
|
page read and write
|
||
7FF5DF3B9000
|
unkown
|
page readonly
|
||
31D0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
AFFD000
|
stack
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
92F0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
9605000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
7FF5DF21B000
|
unkown
|
page readonly
|
||
7DF4E6781000
|
unkown
|
page execute read
|
||
31D0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
7FF5DF04D000
|
unkown
|
page readonly
|
||
BCB0000
|
unkown
|
page read and write
|
||
7FF5DF25E000
|
unkown
|
page readonly
|
||
9370000
|
unkown
|
page read and write
|
||
7FF5DF582000
|
unkown
|
page readonly
|
||
7FF5DF519000
|
unkown
|
page readonly
|
||
7FF5DF380000
|
unkown
|
page readonly
|
||
87E0000
|
stack
|
page read and write
|
||
52C3000
|
unkown
|
page read and write
|
||
9020000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
7FF5DEFF0000
|
unkown
|
page readonly
|
||
7C10000
|
unkown
|
page read and write
|
||
8BA0000
|
unkown
|
page read and write
|
||
7FF5DEFB7000
|
unkown
|
page readonly
|
||
9330000
|
unkown
|
page read and write
|
||
AB50000
|
unkown
|
page read and write
|
||
BFAF000
|
unkown
|
page read and write
|
||
7870000
|
unkown
|
page read and write
|
||
7DF4E6791000
|
unkown
|
page execute read
|
||
2DF0000
|
unkown
|
page read and write
|
||
7FF5DF45C000
|
unkown
|
page readonly
|
||
2D14000
|
heap
|
page read and write
|
||
E06000
|
heap
|
page read and write
|
||
7FF5DF507000
|
unkown
|
page readonly
|
||
2DF0000
|
unkown
|
page read and write
|
||
86C0000
|
unkown
|
page read and write
|
||
4830000
|
heap
|
page read and write
|
||
86C0000
|
unkown
|
page read and write
|
||
9020000
|
unkown
|
page read and write
|
||
2890000
|
unkown
|
page readonly
|
||
31B0000
|
unkown
|
page read and write
|
||
7B00000
|
unkown
|
page read and write
|
||
ACAE000
|
stack
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
86C0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
1066A000
|
heap
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7FF5DF4FB000
|
unkown
|
page readonly
|
||
83F0000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
99AB000
|
unkown
|
page read and write
|
||
7FF5DEFF8000
|
unkown
|
page readonly
|
||
7FF5DF5FC000
|
unkown
|
page readonly
|
||
7FF5DF435000
|
unkown
|
page readonly
|
||
BF10000
|
unkown
|
page readonly
|
||
2C0E000
|
heap
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
2B50000
|
heap
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
A6F1000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
848E000
|
stack
|
page read and write
|
||
9330000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
E70000
|
unkown
|
page readonly
|
||
31A0000
|
unkown
|
page read and write
|
||
9020000
|
unkown
|
page read and write
|
||
7FF5DEFF5000
|
unkown
|
page readonly
|
||
418000
|
unkown
|
page readonly
|
||
76F0000
|
unkown
|
page read and write
|
||
92F0000
|
unkown
|
page read and write
|
||
86C0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
3200000
|
unkown
|
page read and write
|
||
92F0000
|
unkown
|
page read and write
|
||
8BA0000
|
unkown
|
page read and write
|
||
E80000
|
unkown
|
page read and write
|
||
BE80000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
2CF0000
|
direct allocation
|
page execute and read and write
|
||
32B0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
7FF5DF47E000
|
unkown
|
page readonly
|
||
AB50000
|
unkown
|
page read and write
|
||
73B2000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
7FF5DF248000
|
unkown
|
page readonly
|
||
7399000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
AB50000
|
unkown
|
page read and write
|
||
9E0000
|
unkown
|
page readonly
|
||
7C10000
|
unkown
|
page read and write
|
||
7FF5DE9C3000
|
unkown
|
page readonly
|
||
D69000
|
heap
|
page read and write
|
||
7FF5DF59E000
|
unkown
|
page readonly
|
||
3190000
|
stack
|
page read and write
|
||
73A7000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
2C2B000
|
heap
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
2BDE000
|
stack
|
page read and write
|
||
BF6D000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
739B000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
400000
|
unkown
|
page execute and read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
9020000
|
unkown
|
page read and write
|
||
7FF5DEFBD000
|
unkown
|
page readonly
|
||
BCB0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
73CD000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
8590000
|
unkown
|
page readonly
|
||
7C10000
|
unkown
|
page read and write
|
||
A6CF000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
31E0000
|
unkown
|
page read and write
|
||
7FF5DF2CB000
|
unkown
|
page readonly
|
||
9330000
|
unkown
|
page read and write
|
||
4855000
|
unkown
|
page read and write
|
||
7230000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
A6EE000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7800000
|
unkown
|
page read and write
|
||
27F0000
|
unkown
|
page readonly
|
||
BFEF000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
34B0000
|
unkown
|
page readonly
|
||
7C10000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7D0E000
|
stack
|
page read and write
|
||
9716000
|
unkown
|
page read and write
|
||
9F27000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
7AD0000
|
unkown
|
page read and write
|
||
86C0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
7FF5DF5FF000
|
unkown
|
page readonly
|
||
7C10000
|
unkown
|
page read and write
|
||
C19D000
|
unkown
|
page read and write
|
||
D99000
|
heap
|
page read and write
|
||
31F0000
|
unkown
|
page read and write
|
||
ED04000
|
unkown
|
page read and write
|
||
7FF5DF50F000
|
unkown
|
page readonly
|
||
7FF5DF54D000
|
unkown
|
page readonly
|
||
31D0000
|
unkown
|
page read and write
|
||
2C0D000
|
heap
|
page execute and read and write
|
||
7860000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
7FF5DEFAC000
|
unkown
|
page readonly
|
||
2DF0000
|
unkown
|
page read and write
|
||
86C0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
EC83000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
BFA1000
|
unkown
|
page read and write
|
||
B11C000
|
stack
|
page read and write
|
||
2E60000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
AB50000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
86C0000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7FF5DF452000
|
unkown
|
page readonly
|
||
31D0000
|
unkown
|
page read and write
|
||
4828000
|
unkown
|
page read and write
|
||
92F0000
|
unkown
|
page read and write
|
||
B500000
|
unkown
|
page readonly
|
||
7FF5DF422000
|
unkown
|
page readonly
|
||
92F0000
|
unkown
|
page read and write
|
||
31C0000
|
unkown
|
page read and write
|
||
AB50000
|
unkown
|
page read and write
|
||
7FF5DEFE2000
|
unkown
|
page readonly
|
||
7FF5DF364000
|
unkown
|
page readonly
|
||
2DF0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7AD0000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
9E9E000
|
stack
|
page read and write
|
||
7FF5DF08F000
|
unkown
|
page readonly
|
||
7FF5DF57F000
|
unkown
|
page readonly
|
||
31A0000
|
unkown
|
page read and write
|
||
7FF5DEF06000
|
unkown
|
page readonly
|
||
86C0000
|
unkown
|
page read and write
|
||
47A2000
|
unkown
|
page read and write
|
||
885E000
|
stack
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
7FF5DF017000
|
unkown
|
page readonly
|
||
7FF5DF2FE000
|
unkown
|
page readonly
|
||
83F0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
3200000
|
unkown
|
page read and write
|
||
7FF5DF0C1000
|
unkown
|
page readonly
|
||
AEEE000
|
stack
|
page read and write
|
||
8390000
|
unkown
|
page read and write
|
||
7FF5DF36A000
|
unkown
|
page readonly
|
||
9700000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
3200000
|
unkown
|
page read and write
|
||
74F1000
|
unkown
|
page read and write
|
||
7FF5DF09B000
|
unkown
|
page readonly
|
||
31A0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
83E0000
|
unkown
|
page read and write
|
||
2E60000
|
unkown
|
page read and write
|
||
BF98000
|
unkown
|
page read and write
|
||
87E0000
|
unkown
|
page read and write
|
||
7DF5E896A000
|
unkown
|
page readonly
|
||
BCB0000
|
unkown
|
page read and write
|
||
86C0000
|
unkown
|
page read and write
|
||
3190000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
86C0000
|
unkown
|
page read and write
|
||
C034000
|
unkown
|
page read and write
|
||
2B50000
|
heap
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
7B00000
|
unkown
|
page read and write
|
||
C18A000
|
unkown
|
page read and write
|
||
86C0000
|
unkown
|
page read and write
|
||
A0F7000
|
unkown
|
page read and write
|
||
BA76000
|
stack
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
A08D000
|
unkown
|
page read and write
|
||
47B0000
|
unclassified section
|
page read and write
|
||
2D00000
|
direct allocation
|
page read and write
|
||
400000
|
unkown
|
page execute and read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
9F74000
|
unkown
|
page read and write
|
||
9370000
|
unkown
|
page read and write
|
||
C003000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
AC0D000
|
stack
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
2EC0000
|
unkown
|
page readonly
|
||
47D9000
|
unkown
|
page read and write
|
||
7FF5DF4A6000
|
unkown
|
page readonly
|
||
B9E0000
|
unkown
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
83F0000
|
unkown
|
page read and write
|
||
3356000
|
unkown
|
page read and write
|
||
31F0000
|
unkown
|
page read and write
|
||
A0FC000
|
unkown
|
page read and write
|
||
7FF5DF62C000
|
unkown
|
page readonly
|
||
AB10000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
7930000
|
unkown
|
page readonly
|
||
10542000
|
unkown
|
page read and write
|
||
BFA7000
|
unkown
|
page read and write
|
||
1F0000
|
heap
|
page read and write
|
||
9704000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
73E5000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
1C4000
|
heap
|
page read and write
|
||
9729000
|
unkown
|
page read and write
|
||
7FF5DF211000
|
unkown
|
page readonly
|
||
BCB0000
|
unkown
|
page read and write
|
||
838B000
|
stack
|
page read and write
|
||
7FF5DF3F7000
|
unkown
|
page readonly
|
||
7FF5DF0A2000
|
unkown
|
page readonly
|
||
4780000
|
heap
|
page read and write
|
||
9C000
|
stack
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
9C000
|
stack
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
7AD0000
|
unkown
|
page read and write
|
||
86C0000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
7DF4E67A1000
|
unkown
|
page execute read
|
||
7991000
|
unkown
|
page read and write
|
||
7AD0000
|
unkown
|
page read and write
|
||
7FF5DF584000
|
unkown
|
page readonly
|
||
31A0000
|
unkown
|
page read and write
|
||
7FF5DEF87000
|
unkown
|
page readonly
|
||
3200000
|
unkown
|
page read and write
|
||
7D89000
|
stack
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
7FF5DF478000
|
unkown
|
page readonly
|
||
9E1E000
|
stack
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
7FF5DF349000
|
unkown
|
page readonly
|
||
3200000
|
unkown
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
7840000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
2E30000
|
unkown
|
page read and write
|
||
971A000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7D90000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
4824000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
7FF5C0B6B000
|
unkown
|
page readonly
|
||
7FF5DF392000
|
unkown
|
page readonly
|
||
2DF0000
|
unkown
|
page read and write
|
||
51DC000
|
stack
|
page read and write
|
||
7FF5DF5B0000
|
unkown
|
page readonly
|
||
7C10000
|
unkown
|
page read and write
|
||
7FF5DF2DA000
|
unkown
|
page readonly
|
||
31D0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
7FF5DF3DF000
|
unkown
|
page readonly
|
||
2DF0000
|
unkown
|
page read and write
|
||
7FF5DEFC2000
|
unkown
|
page readonly
|
||
31D0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
52D9000
|
unkown
|
page read and write
|
||
7B00000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
7FF5DF229000
|
unkown
|
page readonly
|
||
7FF5DEFCB000
|
unkown
|
page readonly
|
||
40B000
|
unkown
|
page execute read
|
||
86C0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
9F3E000
|
unkown
|
page read and write
|
||
10662000
|
heap
|
page read and write
|
||
7FF5DF623000
|
unkown
|
page readonly
|
||
2D50000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7FF5DF24E000
|
unkown
|
page readonly
|
||
BCB0000
|
unkown
|
page read and write
|
||
4970000
|
heap
|
page read and write
|
||
914B000
|
stack
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
10660000
|
heap
|
page read and write
|
||
9330000
|
unkown
|
page read and write
|
||
7B60000
|
unkown
|
page readonly
|
||
A0A7000
|
unkown
|
page read and write
|
||
31C0000
|
unkown
|
page read and write
|
||
B60A000
|
stack
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
7FF5DF486000
|
unkown
|
page readonly
|
||
7AD0000
|
unkown
|
page read and write
|
||
9330000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
9F7C000
|
unkown
|
page read and write
|
||
7A30000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
3200000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
A104000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
41B000
|
unkown
|
page write copy
|
||
8BA0000
|
unkown
|
page read and write
|
||
3200000
|
unkown
|
page read and write
|
||
7C70000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
7AD0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
7FF5DF23A000
|
unkown
|
page readonly
|
||
2C9A000
|
stack
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
AB50000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
ADC0000
|
unkown
|
page readonly
|
||
2D31000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
418000
|
unkown
|
page readonly
|
||
83F0000
|
unkown
|
page read and write
|
||
3200000
|
unkown
|
page read and write
|
||
418000
|
unkown
|
page readonly
|
||
31D0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
9020000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
3200000
|
unkown
|
page read and write
|
||
4B31000
|
heap
|
page read and write
|
||
7FF5DF3B5000
|
unkown
|
page readonly
|
||
A098000
|
unkown
|
page read and write
|
||
7FF5DF081000
|
unkown
|
page readonly
|
||
BEB0000
|
unkown
|
page read and write
|
||
ECCB000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
40A000
|
unkown
|
page execute read
|
||
7FF5DF1D1000
|
unkown
|
page readonly
|
||
1053D000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
8400000
|
heap
|
page read and write
|
||
9330000
|
unkown
|
page read and write
|
||
BF40000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
7C30000
|
unkown
|
page read and write
|
||
C183000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
B9BF000
|
stack
|
page read and write
|
||
77F0000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
7C20000
|
unkown
|
page read and write
|
||
7FF5DF4C6000
|
unkown
|
page readonly
|
||
A749000
|
unkown
|
page read and write
|
||
30D0000
|
unkown
|
page read and write
|
||
92DB000
|
stack
|
page read and write
|
||
B259000
|
stack
|
page read and write
|
||
7FF5DF1F4000
|
unkown
|
page readonly
|
||
EA0000
|
unkown
|
page read and write
|
||
C354000
|
unkown
|
page read and write
|
||
7FF5DF1CD000
|
unkown
|
page readonly
|
||
31D0000
|
unkown
|
page read and write
|
||
3394000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
7FF5DF191000
|
unkown
|
page readonly
|
||
2F10000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
FF1000
|
unkown
|
page readonly
|
||
3200000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
7FF5DF095000
|
unkown
|
page readonly
|
||
2DF0000
|
unkown
|
page read and write
|
||
7C30000
|
unkown
|
page read and write
|
||
86C0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
30D0000
|
unkown
|
page read and write
|
||
F48000
|
stack
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
7FF5DF606000
|
unkown
|
page readonly
|
||
7FF5DEF94000
|
unkown
|
page readonly
|
||
C1C4000
|
unkown
|
page read and write
|
||
2E60000
|
unkown
|
page read and write
|
||
28A0000
|
unkown
|
page readonly
|
||
BCB0000
|
unkown
|
page read and write
|
||
5110000
|
unkown
|
page write copy
|
||
BCB0000
|
unkown
|
page read and write
|
||
A08A000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
B9F0000
|
unkown
|
page read and write
|
||
973C000
|
unkown
|
page read and write
|
||
BF82000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
7FF5DF25B000
|
unkown
|
page readonly
|
||
7C10000
|
unkown
|
page read and write
|
||
73BA000
|
unkown
|
page read and write
|
||
9020000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
ADAD000
|
stack
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
E91000
|
unkown
|
page read and write
|
||
8BA0000
|
unkown
|
page read and write
|
||
8BA0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
73AF000
|
unkown
|
page read and write
|
||
73BC000
|
unkown
|
page read and write
|
||
4991000
|
heap
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
7FF5DF26F000
|
unkown
|
page readonly
|
||
2DF0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
11A0000
|
unkown
|
page readonly
|
||
2B25000
|
unkown
|
page readonly
|
||
BEB0000
|
unkown
|
page read and write
|
||
2870000
|
unkown
|
page read and write
|
||
47EC000
|
unkown
|
page read and write
|
||
7FF5DF571000
|
unkown
|
page readonly
|
||
31A0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
9330000
|
unkown
|
page read and write
|
||
7FF5DF537000
|
unkown
|
page readonly
|
||
AB10000
|
unkown
|
page read and write
|
||
9D1F000
|
stack
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7B00000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
7FF5DF195000
|
unkown
|
page readonly
|
||
BEF0000
|
heap
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7FF5DF53F000
|
unkown
|
page readonly
|
||
7C10000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
7FF5DEF84000
|
unkown
|
page readonly
|
||
AB10000
|
unkown
|
page read and write
|
||
73B4000
|
unkown
|
page read and write
|
||
7FF5DF12A000
|
unkown
|
page readonly
|
||
31D0000
|
unkown
|
page read and write
|
||
2E60000
|
unkown
|
page read and write
|
||
7FF5DEF57000
|
unkown
|
page readonly
|
||
83F0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
3190000
|
unkown
|
page read and write
|
||
7FF5DF366000
|
unkown
|
page readonly
|
||
31A0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
AEF0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
3200000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
9B99000
|
stack
|
page read and write
|
||
940C000
|
stack
|
page read and write
|
||
7FF5DF07D000
|
unkown
|
page readonly
|
||
31F0000
|
unkown
|
page read and write
|
||
950C000
|
stack
|
page read and write
|
||
7FF5DF343000
|
unkown
|
page readonly
|
||
7FF5DEFAF000
|
unkown
|
page readonly
|
||
2DF0000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
4766000
|
unkown
|
page read and write
|
||
96DF000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
C24C000
|
unkown
|
page read and write
|
||
7FF5DF091000
|
unkown
|
page readonly
|
||
BCB0000
|
unkown
|
page read and write
|
||
92F0000
|
unkown
|
page read and write
|
||
86C0000
|
unkown
|
page read and write
|
||
47B6000
|
unkown
|
page read and write
|
||
7B00000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
868F000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
BF84000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
A73B000
|
unkown
|
page read and write
|
||
B830000
|
unkown
|
page readonly
|
||
83F0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
C474000
|
unkown
|
page read and write
|
||
2E50000
|
unkown
|
page readonly
|
||
86C0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
C23D000
|
unkown
|
page read and write
|
||
3349000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
738E000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
8C28000
|
stack
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
AB50000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
BFA5000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
C39F000
|
unkown
|
page read and write
|
||
3200000
|
unkown
|
page read and write
|
||
970C000
|
unkown
|
page read and write
|
||
AD2B000
|
stack
|
page read and write
|
||
97F3000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7FF5DF551000
|
unkown
|
page readonly
|
||
31B0000
|
unkown
|
page read and write
|
||
8900000
|
unkown
|
page read and write
|
||
7FF5DF0F6000
|
unkown
|
page readonly
|
||
7FF5DF4F7000
|
unkown
|
page readonly
|
||
2DF0000
|
unkown
|
page read and write
|
||
C187000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
31C0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
BF9D000
|
unkown
|
page read and write
|
||
41B000
|
unkown
|
page read and write
|
||
7FF5DF3C2000
|
unkown
|
page readonly
|
||
2DF0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
7FF5DEF4B000
|
unkown
|
page readonly
|
||
A106000
|
unkown
|
page read and write
|
||
7C30000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
2C1C000
|
heap
|
page read and write
|
||
9020000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
BFAB000
|
unkown
|
page read and write
|
||
2E60000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
7FF5DF4BD000
|
unkown
|
page readonly
|
||
AB10000
|
unkown
|
page read and write
|
||
7FF5DF284000
|
unkown
|
page readonly
|
||
8BA0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7AD0000
|
unkown
|
page read and write
|
||
9F23000
|
unkown
|
page read and write
|
||
A757000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
47F1000
|
unkown
|
page read and write
|
||
47D0000
|
heap
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7C20000
|
unkown
|
page read and write
|
||
9D9F000
|
stack
|
page read and write
|
||
7FF5DF16B000
|
unkown
|
page readonly
|
||
31B0000
|
unkown
|
page read and write
|
||
7FF5DF2ED000
|
unkown
|
page readonly
|
||
7FF5DF2F3000
|
unkown
|
page readonly
|
||
7FF5DF08B000
|
unkown
|
page readonly
|
||
7FF5DF48B000
|
unkown
|
page readonly
|
||
BCB0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
7C20000
|
unkown
|
page read and write
|
||
7FF5DF3EA000
|
unkown
|
page readonly
|
||
7FF5DF591000
|
unkown
|
page readonly
|
||
2B25000
|
unkown
|
page readonly
|
||
9370000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
C319000
|
unkown
|
page read and write
|
||
BE80000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
AB50000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
96F1000
|
unkown
|
page read and write
|
||
7FF5DF429000
|
unkown
|
page readonly
|
||
3200000
|
unkown
|
page read and write
|
||
B45A000
|
stack
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7FF5DF3A1000
|
unkown
|
page readonly
|
||
47F3000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
BE80000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
7FF5DF2E2000
|
unkown
|
page readonly
|
||
31A0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
10548000
|
unkown
|
page read and write
|
||
AB50000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
7FF5DE539000
|
unkown
|
page readonly
|
||
3190000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
3200000
|
unkown
|
page read and write
|
||
2E60000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
7FF5DF2BA000
|
unkown
|
page readonly
|
||
48B0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
7FF5DF5A3000
|
unkown
|
page readonly
|
||
86C0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
10500000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
87E0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
A02D000
|
unkown
|
page read and write
|
||
3190000
|
unkown
|
page read and write
|
||
7FF5DF3AA000
|
unkown
|
page readonly
|
||
31A0000
|
unkown
|
page read and write
|
||
7FF5DE5CC000
|
unkown
|
page readonly
|
||
2DF0000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
7FF5DEE43000
|
unkown
|
page readonly
|
||
9C1D000
|
stack
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
9020000
|
unkown
|
page read and write
|
||
40A000
|
unkown
|
page execute read
|
||
83F0000
|
unkown
|
page read and write
|
||
3375000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
9F51000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
9020000
|
unkown
|
page read and write
|
||
4750000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7499000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7FF5DF0D2000
|
unkown
|
page readonly
|
||
7C10000
|
unkown
|
page read and write
|
||
7FF5DE9CB000
|
unkown
|
page readonly
|
||
2DF0000
|
unkown
|
page read and write
|
||
96F5000
|
unkown
|
page read and write
|
||
7FF5DF310000
|
unkown
|
page readonly
|
||
AB10000
|
unkown
|
page read and write
|
||
8A36000
|
unkown
|
page read and write
|
||
971C000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
7830000
|
unkown
|
page read and write
|
||
8900000
|
unkown
|
page read and write
|
||
4788000
|
unkown
|
page read and write
|
||
7FF5DF3F1000
|
unkown
|
page readonly
|
||
AB10000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
3304000
|
unkown
|
page read and write
|
||
4790000
|
unclassified section
|
page read and write
|
||
28D3000
|
heap
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
87E0000
|
unkown
|
page read and write
|
||
7FF5DF42F000
|
unkown
|
page readonly
|
||
9330000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
88E0000
|
unkown
|
page read and write
|
||
7FF5DF3FC000
|
unkown
|
page readonly
|
||
2BAE000
|
stack
|
page read and write
|
||
7C20000
|
unkown
|
page read and write
|
||
7B50000
|
unkown
|
page readonly
|
||
7FF5DF20A000
|
unkown
|
page readonly
|
||
9330000
|
unkown
|
page read and write
|
||
7FF5DEE5A000
|
unkown
|
page readonly
|
||
7C10000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
83B0000
|
unkown
|
page readonly
|
||
9370000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
7FF5DF045000
|
unkown
|
page readonly
|
||
AB50000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
3364000
|
unkown
|
page read and write
|
||
B010000
|
unkown
|
page read and write
|
||
AB50000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
1190000
|
heap
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
7FF5DF5B3000
|
unkown
|
page readonly
|
||
BCB0000
|
unkown
|
page read and write
|
||
BFC3000
|
unkown
|
page read and write
|
||
92F0000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
9060000
|
unkown
|
page read and write
|
||
7FF5DF4E3000
|
unkown
|
page readonly
|
||
A740000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
C1CC000
|
unkown
|
page read and write
|
||
7FF5DF577000
|
unkown
|
page readonly
|
||
B2DB000
|
stack
|
page read and write
|
||
2D1E000
|
stack
|
page read and write
|
||
7FF5DF55A000
|
unkown
|
page readonly
|
||
83F0000
|
unkown
|
page read and write
|
||
7FF5DF5F0000
|
unkown
|
page readonly
|
||
7FF5DF43C000
|
unkown
|
page readonly
|
||
7C10000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
7C50000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
7FF5DF5CC000
|
unkown
|
page readonly
|
||
2BFE000
|
stack
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
92F0000
|
unkown
|
page read and write
|
||
4B30000
|
heap
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
AB89000
|
stack
|
page read and write
|
||
C070000
|
unkown
|
page read and write
|
||
C159000
|
unkown
|
page read and write
|
||
73A3000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7FF5DF0F1000
|
unkown
|
page readonly
|
||
BF9B000
|
unkown
|
page read and write
|
||
9060000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
7FF5DE531000
|
unkown
|
page readonly
|
||
BCB0000
|
unkown
|
page read and write
|
||
7B00000
|
unkown
|
page read and write
|
||
7FF5DEF90000
|
unkown
|
page readonly
|
||
AB10000
|
unkown
|
page read and write
|
||
34C0000
|
unkown
|
page read and write
|
||
7FF5DF3BE000
|
unkown
|
page readonly
|
||
3090000
|
stack
|
page read and write
|
||
339C000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
2B9E000
|
stack
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
C75000
|
stack
|
page read and write
|
||
40B000
|
unkown
|
page execute read
|
||
31A0000
|
unkown
|
page read and write
|
||
BD7F000
|
stack
|
page read and write
|
||
AB50000
|
unkown
|
page read and write
|
||
962B000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
92F0000
|
unkown
|
page read and write
|
||
7FF5DF361000
|
unkown
|
page readonly
|
||
7AD0000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
B120000
|
unkown
|
page readonly
|
||
7FF5DF5BE000
|
unkown
|
page readonly
|
||
9330000
|
unkown
|
page read and write
|
||
BFDF000
|
unkown
|
page read and write
|
||
2B60000
|
heap
|
page read and write
|
||
92F0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
7810000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
7FF5DF3F5000
|
unkown
|
page readonly
|
||
7C10000
|
unkown
|
page read and write
|
||
7B00000
|
unkown
|
page read and write
|
||
8B67000
|
unkown
|
page read and write
|
||
7FF5DF52D000
|
unkown
|
page readonly
|
||
3185000
|
stack
|
page read and write
|
||
9330000
|
unkown
|
page read and write
|
||
7FF5DF3C6000
|
unkown
|
page readonly
|
||
7FF5DF396000
|
unkown
|
page readonly
|
||
2ECF000
|
stack
|
page read and write
|
||
7FF5DF5AE000
|
unkown
|
page readonly
|
||
AB10000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
7FF5DF4AB000
|
unkown
|
page readonly
|
||
83F0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
9F10000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
3200000
|
unkown
|
page read and write
|
||
3190000
|
unkown
|
page read and write
|
||
31C0000
|
unkown
|
page read and write
|
||
D50000
|
unkown
|
page read and write
|
||
C3FD000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
7AD0000
|
unkown
|
page read and write
|
||
41B000
|
unkown
|
page write copy
|
||
7DF5E895F000
|
unkown
|
page readonly
|
||
7395000
|
unkown
|
page read and write
|
||
4860000
|
unkown
|
page read and write
|
||
970000
|
unkown
|
page readonly
|
||
BCB0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
7FF5DEFA6000
|
unkown
|
page readonly
|
||
83F0000
|
unkown
|
page read and write
|
||
7FF5DF0C9000
|
unkown
|
page readonly
|
||
BCB0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
B358000
|
stack
|
page read and write
|
||
2EEF000
|
stack
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
8EA8000
|
stack
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
4770000
|
heap
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
7FF5DF549000
|
unkown
|
page readonly
|
||
7C10000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
336C000
|
unkown
|
page read and write
|
||
8BA0000
|
unkown
|
page read and write
|
||
7AD0000
|
unkown
|
page read and write
|
||
3200000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
7DF4E6771000
|
unkown
|
page execute read
|
||
D60000
|
heap
|
page read and write
|
||
7FF5DF126000
|
unkown
|
page readonly
|
||
BCB0000
|
unkown
|
page read and write
|
||
7AD0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
980000
|
unkown
|
page readonly
|
||
AB10000
|
unkown
|
page read and write
|
||
7FF5DF089000
|
unkown
|
page readonly
|
||
BCB0000
|
unkown
|
page read and write
|
||
10563000
|
unkown
|
page read and write
|
||
88DE000
|
stack
|
page read and write
|
||
13A1000
|
unkown
|
page readonly
|
||
31A0000
|
unkown
|
page read and write
|
||
27D0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
7FF5DF45A000
|
unkown
|
page readonly
|
||
9A6C000
|
stack
|
page read and write
|
||
ECC6000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
86C0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7C50000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
7FF5DF067000
|
unkown
|
page readonly
|
||
9F92000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
2FEF000
|
stack
|
page read and write
|
||
86C0000
|
unkown
|
page read and write
|
||
31C0000
|
unkown
|
page read and write
|
||
92F0000
|
unkown
|
page read and write
|
||
9B1E000
|
stack
|
page read and write
|
||
7C20000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
98A1000
|
unkown
|
page read and write
|
||
79E0000
|
unkown
|
page readonly
|
||
7FF5DEE56000
|
unkown
|
page readonly
|
||
2E60000
|
unkown
|
page read and write
|
||
92F0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
3200000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
7FF5DF122000
|
unkown
|
page readonly
|
||
C01A000
|
unkown
|
page read and write
|
||
1055F000
|
unkown
|
page read and write
|
||
73B6000
|
unkown
|
page read and write
|
||
B1C0000
|
unkown
|
page readonly
|
||
B589000
|
stack
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
86C0000
|
unkown
|
page read and write
|
||
BE80000
|
unkown
|
page read and write
|
||
335B000
|
unkown
|
page read and write
|
||
874C000
|
stack
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
3290000
|
unkown
|
page readonly
|
||
7C89000
|
stack
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
74D6000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
7FF5DEFE8000
|
unkown
|
page readonly
|
||
31A0000
|
unkown
|
page read and write
|
||
7FF5DF5E9000
|
unkown
|
page readonly
|
||
C048000
|
unkown
|
page read and write
|
||
7FF5DF169000
|
unkown
|
page readonly
|
||
BEB0000
|
unkown
|
page read and write
|
||
9FA0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
BF7E000
|
unkown
|
page read and write
|
||
19D000
|
stack
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
978C000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
7C20000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
10540000
|
unkown
|
page read and write
|
||
989F000
|
unkown
|
page read and write
|
||
3371000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
7FF5DF01B000
|
unkown
|
page readonly
|
||
2DF0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
E00000
|
heap
|
page read and write
|
||
9020000
|
unkown
|
page read and write
|
||
2E20000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
7FF5DF49C000
|
unkown
|
page readonly
|
||
31D0000
|
unkown
|
page read and write
|
||
8910000
|
unkown
|
page read and write
|
||
86C0000
|
unkown
|
page read and write
|
||
4990000
|
heap
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7FF5C0B65000
|
unkown
|
page readonly
|
||
83F0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
9020000
|
unkown
|
page read and write
|
||
2C1D000
|
heap
|
page execute and read and write
|
||
7FF5DF567000
|
unkown
|
page readonly
|
||
9FC3000
|
unkown
|
page read and write
|
||
9380000
|
unkown
|
page readonly
|
||
31A0000
|
unkown
|
page read and write
|
||
2BFE000
|
heap
|
page read and write
|
||
9F63000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7FF5DEFDD000
|
unkown
|
page readonly
|
||
2C0A000
|
heap
|
page read and write
|
||
73B8000
|
unkown
|
page read and write
|
||
7AD0000
|
unkown
|
page read and write
|
||
3090000
|
unkown
|
page read and write
|
||
86C0000
|
unkown
|
page read and write
|
||
7ACE000
|
stack
|
page read and write
|
||
AB0D000
|
stack
|
page read and write
|
||
7910000
|
unkown
|
page readonly
|
||
33C0000
|
unkown
|
page readonly
|
||
7AD0000
|
unkown
|
page read and write
|
||
C13B000
|
unkown
|
page read and write
|
||
7FF5DF5B5000
|
unkown
|
page readonly
|
||
3362000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
2B25000
|
unkown
|
page readonly
|
||
BCB0000
|
unkown
|
page read and write
|
||
7FF5DF5A8000
|
unkown
|
page readonly
|
||
2DF0000
|
unkown
|
page read and write
|
||
AB50000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
31F0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
7FF5DF488000
|
unkown
|
page readonly
|
||
7FF5DE4F2000
|
unkown
|
page readonly
|
||
10531000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
7FF5DF39C000
|
unkown
|
page readonly
|
||
AB10000
|
unkown
|
page read and write
|
||
47A0000
|
direct allocation
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
3373000
|
unkown
|
page read and write
|
||
2C00000
|
heap
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
790A000
|
stack
|
page read and write
|
||
C192000
|
unkown
|
page read and write
|
||
9F78000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
7FF5DF3E4000
|
unkown
|
page readonly
|
||
2DF0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
AB50000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
28D0000
|
heap
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
C149000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
C1A9000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
92F0000
|
unkown
|
page read and write
|
||
2C39000
|
heap
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
7FF5DF58A000
|
unkown
|
page readonly
|
||
2DF0000
|
unkown
|
page read and write
|
||
7FF5DF4EC000
|
unkown
|
page readonly
|
||
7AD0000
|
unkown
|
page read and write
|
||
3200000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
BF90000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
BFB3000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
2BFA000
|
heap
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
7FF5DF398000
|
unkown
|
page readonly
|
||
7FF5DF5D6000
|
unkown
|
page readonly
|
||
31A0000
|
unkown
|
page read and write
|
||
7FF5DF038000
|
unkown
|
page readonly
|
||
AB10000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
7FF5DF60D000
|
unkown
|
page readonly
|
||
7FF5DE535000
|
unkown
|
page readonly
|
||
31B0000
|
unkown
|
page read and write
|
||
98A7000
|
unkown
|
page read and write
|
||
7FF5DF626000
|
unkown
|
page readonly
|
||
83F0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
336F000
|
unkown
|
page read and write
|
||
8BA0000
|
unkown
|
page read and write
|
||
7380000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7DF4E6770000
|
unkown
|
page readonly
|
||
31A0000
|
unkown
|
page read and write
|
||
A690000
|
unkown
|
page read and write
|
||
96ED000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
9489000
|
stack
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
4790000
|
direct allocation
|
page execute and read and write
|
||
7C30000
|
unkown
|
page read and write
|
||
A73E000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
86C0000
|
unkown
|
page read and write
|
||
3281000
|
stack
|
page read and write
|
||
AB50000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
7FF5DEE52000
|
unkown
|
page readonly
|
||
7DF4E6760000
|
unkown
|
page readonly
|
||
9F60000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
A6D2000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
A6EA000
|
unkown
|
page read and write
|
||
1195000
|
heap
|
page read and write
|
||
2D10000
|
heap
|
page read and write
|
||
3107000
|
stack
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
3200000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
3200000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
7FF5DF06F000
|
unkown
|
page readonly
|
||
830F000
|
stack
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
7FF5DF0C3000
|
unkown
|
page readonly
|
||
9330000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
7AD0000
|
unkown
|
page read and write
|
||
2B25000
|
unkown
|
page readonly
|
||
9020000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
7FF5DF221000
|
unkown
|
page readonly
|
||
31D0000
|
unkown
|
page read and write
|
||
86C0000
|
unkown
|
page read and write
|
||
7FF5DEEEB000
|
unkown
|
page readonly
|
||
BCB0000
|
unkown
|
page read and write
|
||
7A40000
|
unkown
|
page readonly
|
||
BCB0000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
479B000
|
unkown
|
page read and write
|
||
3200000
|
unkown
|
page read and write
|
||
7FF5DF388000
|
unkown
|
page readonly
|
||
31B0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
7DF4E6780000
|
unkown
|
page readonly
|
||
AB10000
|
unkown
|
page read and write
|
||
909B000
|
stack
|
page read and write
|
||
4910000
|
heap
|
page read and write
|
||
97B5000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
7FF5DF0A5000
|
unkown
|
page readonly
|
||
2C1B000
|
heap
|
page read and write
|
||
AE6F000
|
stack
|
page read and write
|
||
C13F000
|
unkown
|
page read and write
|
||
7FF5DEFFC000
|
unkown
|
page readonly
|
||
31D0000
|
unkown
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
8BA0000
|
unkown
|
page read and write
|
||
9F0000
|
heap
|
page read and write
|
||
7FF5DF2E5000
|
unkown
|
page readonly
|
||
A072000
|
unkown
|
page read and write
|
||
901B000
|
stack
|
page read and write
|
||
7AD0000
|
unkown
|
page read and write
|
||
A0B1000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7FF5DF425000
|
unkown
|
page readonly
|
||
3200000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
A09A000
|
unkown
|
page read and write
|
||
7B4B000
|
stack
|
page read and write
|
||
7FF5DF029000
|
unkown
|
page readonly
|
||
92F0000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
3382000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
3200000
|
unkown
|
page read and write
|
||
7C20000
|
unkown
|
page read and write
|
||
7940000
|
unkown
|
page readonly
|
||
418000
|
unkown
|
page readonly
|
||
73C3000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
4760000
|
unkown
|
page read and write
|
||
A0A5000
|
unkown
|
page read and write
|
||
8BA0000
|
unkown
|
page read and write
|
||
7FF5DF3D4000
|
unkown
|
page readonly
|
||
7B10000
|
unkown
|
page read and write
|
||
7FF5DF4F3000
|
unkown
|
page readonly
|
||
7FF5DF4D5000
|
unkown
|
page readonly
|
||
C2E4000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
9564000
|
unkown
|
page read and write
|
||
7FF5DF532000
|
unkown
|
page readonly
|
||
9F2A000
|
unkown
|
page read and write
|
||
3190000
|
unkown
|
page read and write
|
||
BF8C000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
9330000
|
unkown
|
page read and write
|
||
92F0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
5241000
|
unkown
|
page read and write
|
||
98AD000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
EA0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
48E0000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
2BF0000
|
heap
|
page read and write
|
||
C298000
|
unkown
|
page read and write
|
||
7FF5DF443000
|
unkown
|
page readonly
|
||
AB50000
|
unkown
|
page read and write
|
||
7FF5DF539000
|
unkown
|
page readonly
|
||
31D0000
|
unkown
|
page read and write
|
||
476F000
|
stack
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7FF5DF18E000
|
unkown
|
page readonly
|
||
7FF5DEE4E000
|
unkown
|
page readonly
|
||
2DF0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
320C000
|
stack
|
page read and write
|
||
7FF5DF4E7000
|
unkown
|
page readonly
|
||
7FF5DF0CC000
|
unkown
|
page readonly
|
||
B4DB000
|
stack
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
3190000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
7FF5DF41B000
|
unkown
|
page readonly
|
||
9C9F000
|
stack
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
7FF5DF382000
|
unkown
|
page readonly
|
||
AB50000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
86C0000
|
unkown
|
page read and write
|
||
FE0000
|
unkown
|
page read and write
|
||
1C0000
|
heap
|
page read and write
|
||
935B000
|
stack
|
page read and write
|
||
C013000
|
unkown
|
page read and write
|
||
7FF5DF207000
|
unkown
|
page readonly
|
||
3200000
|
unkown
|
page read and write
|
||
48A0000
|
unkown
|
page read and write
|
||
19D000
|
stack
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
7AD0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
41B000
|
unkown
|
page read and write
|
||
7FF5DF5F6000
|
unkown
|
page readonly
|
||
7DF4E6761000
|
unkown
|
page execute read
|
||
987C000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
95F0000
|
unkown
|
page read and write
|
||
AF7E000
|
stack
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
C525000
|
unkown
|
page read and write
|
||
B09E000
|
stack
|
page read and write
|
||
2EB0000
|
unkown
|
page readonly
|
||
AB10000
|
unkown
|
page read and write
|
||
7C10000
|
unkown
|
page read and write
|
||
2DF0000
|
unkown
|
page read and write
|
||
7FF5DF21F000
|
unkown
|
page readonly
|
||
2DF0000
|
unkown
|
page read and write
|
||
83D0000
|
unkown
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
31F0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
83F0000
|
unkown
|
page read and write
|
||
BF9F000
|
unkown
|
page read and write
|
||
E0F000
|
heap
|
page read and write
|
||
9714000
|
unkown
|
page read and write
|
||
31F0000
|
unkown
|
page read and write
|
||
7C30000
|
unkown
|
page read and write
|
||
BFA3000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
AB10000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
7AD0000
|
unkown
|
page read and write
|
||
BCB0000
|
unkown
|
page read and write
|
||
BFAD000
|
unkown
|
page read and write
|
||
86C0000
|
unkown
|
page read and write
|
||
A735000
|
unkown
|
page read and write
|
||
BEB0000
|
unkown
|
page read and write
|
There are 1368 hidden memdumps, click here to show them.