0% found this document useful (0 votes)
8 views56 pages

Autumn Scan Results

The document provides a detailed scan report indicating that there are 8 bad certificates and 143 neutral allocations, with no malicious or suspicious allocations detected. It includes snapshots of various files, most of which are marked as neutral, while one specific snapshot is flagged as malicious due to the presence of suspicious libraries. The report highlights the status and matched identifiers for each file scanned.

Uploaded by

cirdecllido
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views56 pages

Autumn Scan Results

The document provides a detailed scan report indicating that there are 8 bad certificates and 143 neutral allocations, with no malicious or suspicious allocations detected. It includes snapshots of various files, most of which are marked as neutral, while one specific snapshot is flagged as malicious due to the presence of suspicious libraries. The report highlights the status and matched identifiers for each file scanned.

Uploaded by

cirdecllido
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
You are on page 1/ 56

{

"isDetected": false,
"allocBadCertCount": 8,
"allocNeutralCount": 143,
"allocSuspiciousCount": 0,
"allocLikelyMaliciousCount": 0,
"allocMaliciousCount": 0,
"snapshot": [
{
"start": "0x2921b2b0000",
"end": "0x2921b2ce000",
"size": 122880,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"start": "0x2921e930000",
"end": "0x2921e9bd000",
"size": 577536,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"start": "0x29236e40000",
"end": "0x2923860a000",
"size": 24944640,
"status": "SCAN_MALICIOUS",
"statusCode": 5,
"matched": [
{
"id": 54,
"name": "lib-imgui"
},
{
"id": 23,
"name": "lib-syxsdk"
},
{
"id": 0,
"name": "found_suspicious_libs"
},
{
"id": 6,
"name": "s-urlrepo"
},
{
"id": 14,
"name": "r-key"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 41,
"name": "l-key"
},
{
"id": 30,
"name": "l-func"
},
{
"id": 17,
"name": "f-lua"
},
{
"id": 33,
"name": "e-sirhurt"
},
{
"id": 21,
"name": "eval_exploit"
},
{
"id": 55,
"name": "f-rbx"
},
{
"id": 63,
"name": "m-notpe"
},
{
"id": 61,
"name": "s-estrings"
},
{
"id": 59,
"name": "s-pipe"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\DriverStore\\FileRepository\\
nvcvi.inf_amd64_1b88e9d3d598ca1f\\nvwgf2umx.dll",
"start": "0x7ff9897c0000",
"end": "0x7ff98ec71000",
"size": 88805376,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 59,
"name": "s-pipe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\DriverStore\\FileRepository\\
nvcvi.inf_amd64_1b88e9d3d598ca1f\\nvgpucomp64.dll",
"start": "0x7ff98ec80000",
"end": "0x7ff992732000",
"size": 61546496,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\Users\\EXECUTE\\AppData\\Local\\Bloxstrap\\Versions\\
version-e1da58b32b1c4d64\\MSVCP140.dll",
"start": "0x7ff9c75e0000",
"end": "0x7ff9c7669000",
"size": 561152,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\GLU32.dll",
"start": "0x7ff9cd950000",
"end": "0x7ff9cd97d000",
"size": 184320,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\OPENGL32.dll",
"start": "0x7ff9cd980000",
"end": "0x7ff9cda8c000",
"size": 1097728,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\MSACM32.dll",
"start": "0x7ff9d2d00000",
"end": "0x7ff9d2d21000",
"size": 135168,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\Windows\\System32\\devenum.dll",
"start": "0x7ff9d3430000",
"end": "0x7ff9d3451000",
"size": 135168,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\d3d9.dll",
"start": "0x7ff9ec410000",
"end": "0x7ff9ec5c5000",
"size": 1789952,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 59,
"name": "s-pipe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\verifier.dll",
"start": "0x7ff9f1ea0000",
"end": "0x7ff9f1f12000",
"size": 466944,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"start": "0x7ffa0c1d0000",
"end": "0x7ffa0c1e0000",
"size": 65536,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 63,
"name": "m-notpe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\winrnr.dll",
"start": "0x7ffa119b0000",
"end": "0x7ffa119c2000",
"size": 73728,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\DriverStore\\FileRepository\\
nvcvi.inf_amd64_1b88e9d3d598ca1f\\nvppex.dll",
"start": "0x7ffa170f0000",
"end": "0x7ffa172a4000",
"size": 1785856,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\Users\\EXECUTE\\AppData\\Local\\Bloxstrap\\Versions\\
version-e1da58b32b1c4d64\\VCRUNTIME140.dll",
"start": "0x7ffa1a810000",
"end": "0x7ffa1a82b000",
"size": 110592,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\Users\\EXECUTE\\AppData\\Local\\Bloxstrap\\Versions\\
version-e1da58b32b1c4d64\\WebView2Loader.dll",
"start": "0x7ffa1bb60000",
"end": "0x7ffa1bb8e000",
"size": 188416,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\Windows\\System32\\dinput8.dll",
"start": "0x7ffa1c9d0000",
"end": "0x7ffa1ca1b000",
"size": 307200,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\system32\\napinsp.dll",
"start": "0x7ffa1e040000",
"end": "0x7ffa1e058000",
"size": 98304,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\system32\\nlansp_c.dll",
"start": "0x7ffa1e060000",
"end": "0x7ffa1e090000",
"size": 196608,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\TextShaping.dll",
"start": "0x7ffa23930000",
"end": "0x7ffa239db000",
"size": 700416,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\windows.staterepositoryclient.dll",
"start": "0x7ffa29660000",
"end": "0x7ffa296a6000",
"size": 286720,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\system32\\ncryptsslp.dll",
"start": "0x7ffa29730000",
"end": "0x7ffa2975d000",
"size": 184320,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\iertutil.dll",
"start": "0x7ffa2c4f0000",
"end": "0x7ffa2c7ba000",
"size": 2924544,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 31,
"name": "s-urlsocial"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\urlmon.dll",
"start": "0x7ffa2c830000",
"end": "0x7ffa2ca0c000",
"size": 1949696,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\WININET.dll",
"start": "0x7ffa2fad0000",
"end": "0x7ffa2fd53000",
"size": 2633728,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 47,
"name": "s-ename"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\WinSxS\\amd64_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.26100.1882_none_87f34cef7a28f535\\COMCTL32.dll",
"start": "0x7ffa30000000",
"end": "0x7ffa300b4000",
"size": 737280,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\srvcli.dll",
"start": "0x7ffa300c0000",
"end": "0x7ffa300e9000",
"size": 167936,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\system32\\wshbth.dll",
"start": "0x7ffa31ef0000",
"end": "0x7ffa31f10000",
"size": 131072,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\DriverStore\\FileRepository\\
nvcvi.inf_amd64_1b88e9d3d598ca1f\\Display.NvContainer\\NvMessageBus.dll",
"start": "0x7ffa330c0000",
"end": "0x7ffa33423000",
"size": 3551232,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 59,
"name": "s-pipe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\textinputframework.dll",
"start": "0x7ffa35d80000",
"end": "0x7ffa35ecd000",
"size": 1363968,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\windows.staterepositorycore.dll",
"start": "0x7ffa39d00000",
"end": "0x7ffa39d1a000",
"size": 106496,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\AUDIOSES.DLL",
"start": "0x7ffa3c4c0000",
"end": "0x7ffa3c67d000",
"size": 1822720,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\CompPkgSup.DLL",
"start": "0x7ffa3c7d0000",
"end": "0x7ffa3c804000",
"size": 212992,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\twinapi.appcore.dll",
"start": "0x7ffa3cac0000",
"end": "0x7ffa3ccfc000",
"size": 2342912,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\WINMM.dll",
"start": "0x7ffa3cd80000",
"end": "0x7ffa3cdb6000",
"size": 221184,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\dbghelp.dll",
"start": "0x7ffa3d410000",
"end": "0x7ffa3d651000",
"size": 2363392,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\DriverStore\\FileRepository\\
nvcvi.inf_amd64_1b88e9d3d598ca1f\\NvMemMapStoragex.dll",
"start": "0x7ffa3d8d0000",
"end": "0x7ffa3d9ac000",
"size": 901120,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\DriverStore\\FileRepository\\
nvcvi.inf_amd64_1b88e9d3d598ca1f\\nvldumdx.dll",
"start": "0x7ffa3da70000",
"end": "0x7ffa3db32000",
"size": 794624,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\MMDevApi.dll",
"start": "0x7ffa3e240000",
"end": "0x7ffa3e2da000",
"size": 630784,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\inputhost.dll",
"start": "0x7ffa3fbc0000",
"end": "0x7ffa3fda1000",
"size": 1970176,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\cryptnet.dll",
"start": "0x7ffa422e0000",
"end": "0x7ffa4231b000",
"size": 241664,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\fwpuclnt.dll",
"start": "0x7ffa42320000",
"end": "0x7ffa423a6000",
"size": 548864,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\drvstore.dll",
"start": "0x7ffa42870000",
"end": "0x7ffa429ec000",
"size": 1556480,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\CoreUIComponents.dll",
"start": "0x7ffa42dd0000",
"end": "0x7ffa430b3000",
"size": 3026944,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\dhcpcsvc.DLL",
"start": "0x7ffa43450000",
"end": "0x7ffa43475000",
"size": 151552,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\dhcpcsvc6.DLL",
"start": "0x7ffa43490000",
"end": "0x7ffa434af000",
"size": 126976,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\RTWorkQ.DLL",
"start": "0x7ffa434f0000",
"end": "0x7ffa43534000",
"size": 278528,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\MFPlat.DLL",
"start": "0x7ffa43750000",
"end": "0x7ffa43969000",
"size": 2199552,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\Microsoft.Internal.WarpPal.dll",
"start": "0x7ffa44eb0000",
"end": "0x7ffa44ec9000",
"size": 102400,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\D3DCOMPILER_47.dll",
"start": "0x7ffa44ed0000",
"end": "0x7ffa4534f000",
"size": 4714496,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\WindowsCodecs.dll",
"start": "0x7ffa45360000",
"end": "0x7ffa4559a000",
"size": 2334720,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\d3d11.dll",
"start": "0x7ffa45fa0000",
"end": "0x7ffa46206000",
"size": 2514944,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\dcomp.dll",
"start": "0x7ffa46210000",
"end": "0x7ffa46436000",
"size": 2252800,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\CoreMessaging.dll",
"start": "0x7ffa46950000",
"end": "0x7ffa46a76000",
"size": 1204224,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\wtsapi32.dll",
"start": "0x7ffa46df0000",
"end": "0x7ffa46e06000",
"size": 90112,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\system32\\uxtheme.dll",
"start": "0x7ffa46f30000",
"end": "0x7ffa46fdf000",
"size": 716800,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\dxcore.dll",
"start": "0x7ffa470a0000",
"end": "0x7ffa470e7000",
"size": 290816,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\directxdatabasehelper.dll",
"start": "0x7ffa470f0000",
"end": "0x7ffa47150000",
"size": 393216,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\dxgi.dll",
"start": "0x7ffa47160000",
"end": "0x7ffa47293000",
"size": 1257472,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\dwmapi.dll",
"start": "0x7ffa473c0000",
"end": "0x7ffa473f6000",
"size": 221184,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\windows.storage.dll",
"start": "0x7ffa47960000",
"end": "0x7ffa481b6000",
"size": 8740864,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\IPHLPAPI.DLL",
"start": "0x7ffa48500000",
"end": "0x7ffa48533000",
"size": 208896,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\DNSAPI.dll",
"start": "0x7ffa485a0000",
"end": "0x7ffa486c7000",
"size": 1208320,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\system32\\schannel.DLL",
"start": "0x7ffa488b0000",
"end": "0x7ffa4897a000",
"size": 827392,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\system32\\rsaenh.dll",
"start": "0x7ffa489d0000",
"end": "0x7ffa48a0a000",
"size": 237568,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\kernel.appcore.dll",
"start": "0x7ffa48a70000",
"end": "0x7ffa48a8a000",
"size": 106496,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\system32\\ntmarta.dll",
"start": "0x7ffa48b90000",
"end": "0x7ffa48bc5000",
"size": 217088,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\SSPICLI.dll",
"start": "0x7ffa48d10000",
"end": "0x7ffa48d58000",
"size": 294912,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\system32\\mswsock.dll",
"start": "0x7ffa48fe0000",
"end": "0x7ffa4904a000",
"size": 434176,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\GPAPI.dll",
"start": "0x7ffa49050000",
"end": "0x7ffa49077000",
"size": 159744,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\CRYPTSP.dll",
"start": "0x7ffa49280000",
"end": "0x7ffa4929c000",
"size": 114688,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\MSASN1.dll",
"start": "0x7ffa492f0000",
"end": "0x7ffa49303000",
"size": 77824,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\wldp.dll",
"start": "0x7ffa49360000",
"end": "0x7ffa493bd000",
"size": 380928,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\winsta.dll",
"start": "0x7ffa493c0000",
"end": "0x7ffa49427000",
"size": 421888,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\NTASN1.dll",
"start": "0x7ffa494b0000",
"end": "0x7ffa494ef000",
"size": 258048,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\ncrypt.dll",
"start": "0x7ffa49500000",
"end": "0x7ffa49530000",
"size": 196608,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\UMPDC.dll",
"start": "0x7ffa496a0000",
"end": "0x7ffa496b4000",
"size": 81920,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\powrprof.dll",
"start": "0x7ffa49880000",
"end": "0x7ffa498de000",
"size": 385024,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\DEVOBJ.dll",
"start": "0x7ffa498f0000",
"end": "0x7ffa4991d000",
"size": 184320,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\cfgmgr32.dll",
"start": "0x7ffa49920000",
"end": "0x7ffa49977000",
"size": 356352,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\bcrypt.dll",
"start": "0x7ffa49b90000",
"end": "0x7ffa49bb6000",
"size": 155648,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\profapi.dll",
"start": "0x7ffa49bc0000",
"end": "0x7ffa49bef000",
"size": 192512,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\msvcp_win.dll",
"start": "0x7ffa49cb0000",
"end": "0x7ffa49d53000",
"size": 667648,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\CRYPT32.dll",
"start": "0x7ffa49d60000",
"end": "0x7ffa49ed7000",
"size": 1536000,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\gdi32full.dll",
"start": "0x7ffa49ee0000",
"end": "0x7ffa4a012000",
"size": 1253376,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 47,
"name": "s-ename"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\KERNELBASE.dll",
"start": "0x7ffa4a020000",
"end": "0x7ffa4a3ec000",
"size": 3981312,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 59,
"name": "s-pipe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\ucrtbase.dll",
"start": "0x7ffa4a3f0000",
"end": "0x7ffa4a53b000",
"size": 1355776,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\WINTRUST.dll",
"start": "0x7ffa4a540000",
"end": "0x7ffa4a5c0000",
"size": 524288,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\bcryptPrimitives.dll",
"start": "0x7ffa4a5d0000",
"end": "0x7ffa4a669000",
"size": 626688,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\win32u.dll",
"start": "0x7ffa4a730000",
"end": "0x7ffa4a757000",
"size": 159744,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\wintypes.dll",
"start": "0x7ffa4a760000",
"end": "0x7ffa4a8d4000",
"size": 1523712,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\combase.dll",
"start": "0x7ffa4a960000",
"end": "0x7ffa4ace4000",
"size": 3686400,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\clbcatq.dll",
"start": "0x7ffa4acf0000",
"end": "0x7ffa4ad98000",
"size": 688128,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\advapi32.dll",
"start": "0x7ffa4ae00000",
"end": "0x7ffa4aeb2000",
"size": 729088,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\MSCTF.dll",
"start": "0x7ffa4aec0000",
"end": "0x7ffa4b01f000",
"size": 1437696,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\SHELL32.dll",
"start": "0x7ffa4b050000",
"end": "0x7ffa4b77d000",
"size": 7524352,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\GDI32.dll",
"start": "0x7ffa4b780000",
"end": "0x7ffa4b7ab000",
"size": 176128,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\imagehlp.dll",
"start": "0x7ffa4ba30000",
"end": "0x7ffa4ba50000",
"size": 131072,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\WS2_32.dll",
"start": "0x7ffa4ba60000",
"end": "0x7ffa4bad4000",
"size": 475136,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\KERNEL32.DLL",
"start": "0x7ffa4baf0000",
"end": "0x7ffa4bbb9000",
"size": 823296,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\sechost.dll",
"start": "0x7ffa4bbc0000",
"end": "0x7ffa4bc66000",
"size": 679936,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\OLEAUT32.dll",
"start": "0x7ffa4bc70000",
"end": "0x7ffa4bd50000",
"size": 917504,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\COMDLG32.dll",
"start": "0x7ffa4bdb0000",
"end": "0x7ffa4bea4000",
"size": 999424,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\IMM32.DLL",
"start": "0x7ffa4beb0000",
"end": "0x7ffa4bee0000",
"size": 196608,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 39,
"name": "m-mspe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\ole32.dll",
"start": "0x7ffa4bef0000",
"end": "0x7ffa4c08f000",
"size": 1699840,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\shcore.dll",
"start": "0x7ffa4c0a0000",
"end": "0x7ffa4c18f000",
"size": 978944,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\USER32.dll",
"start": "0x7ffa4c1a0000",
"end": "0x7ffa4c36a000",
"size": 1875968,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\SETUPAPI.dll",
"start": "0x7ffa4c370000",
"end": "0x7ffa4c7f6000",
"size": 4743168,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\RPCRT4.dll",
"start": "0x7ffa4c800000",
"end": "0x7ffa4c916000",
"size": 1138688,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\msvcrt.dll",
"start": "0x7ffa4c920000",
"end": "0x7ffa4c9c9000",
"size": 692224,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\System32\\SHLWAPI.dll",
"start": "0x7ffa4c9f0000",
"end": "0x7ffa4ca59000",
"size": 430080,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 7,
"name": "m-tfuture"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 46,
"name": "eval_neutral"
}
]
},
{
"file": "C:\\WINDOWS\\SYSTEM32\\ntdll.dll",
"start": "0x7ffa4cb20000",
"end": "0x7ffa4cd86000",
"size": 2514944,
"status": "SCAN_NEUTRAL",
"statusCode": 2,
"matched": [
{
"id": 4,
"name": "m-normal"
},
{
"id": 8,
"name": "m-pe"
},
{
"id": 15,
"name": "s-apivm"
},
{
"id": 19,
"name": "m-told"
},
{
"id": 46,
"name": "eval_neutral"
}
]
}
]
}

You might also like