IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Purchase Order_0131021.doc
Rich Text Format data, unknown version
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\gufoxqa[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Roaming\gudostrp.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{4877C7E7-A321-4438-A27A-0B7C6E560902}.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{FF3D13C6-F9AF-46D5-857E-918FB2A2DE9E}.tmp
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Purchase Order_0131021.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Mon Aug 30 20:08:56 2021, mtime=Mon Aug 30 20:08:56 2021, atime=Thu Oct 14 16:22:13 2021, length=15658, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\UProof\ExcludeDictionaryEN0409.lex
Little-endian UTF-16 Unicode text, with no line terminators
dropped
clean
C:\Users\user\Desktop\~$rchase Order_0131021.doc
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
malicious
C:\Users\user\AppData\Roaming\gudostrp.exe
C:\Users\user\AppData\Roaming\gudostrp.exe
malicious
C:\Users\user\AppData\Roaming\gudostrp.exe
C:\Users\user\AppData\Roaming\gudostrp.exe
malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
'C:\Program Files\Microsoft Office\Office14\WINWORD.EXE' /Automation -Embedding
clean

URLs

Name
IP
Malicious
http://palangavra.lt/jukiestay/gufoxqa.exe
144.76.47.167
malicious
http://127.0.0.1:HTTP/1.1
unknown
clean
http://SwonTwAJYn3XCAV3.net
unknown
clean
http://DynDns.comDynDNS
unknown
clean
http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
https://api.telegram.org
unknown
clean
http://crl.entrust.net/server1.crl0
unknown
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
unknown
clean
http://ocsp.entrust.net03
unknown
clean
https://api.telegram.orgP
unknown
clean
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.diginotar.nl/cps/pkioverheid0
unknown
clean
http://api.telegram.org
unknown
clean
http://ocsp.entrust.net0D
unknown
clean
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
clean
https://secure.comodo.com/CPS0
unknown
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
unknown
clean
http://yBlQIu.com
unknown
clean
http://crl.entrust.net/2048ca.crl0
unknown
clean
There are 11 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
palangavra.lt
144.76.47.167
malicious
api.telegram.org
149.154.167.220
clean

IPs

IP
Domain
Country
Malicious
144.76.47.167
palangavra.lt
Germany
malicious
149.154.167.220
api.telegram.org
United Kingdom
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
/%'
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
)&'
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
k('
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\34682
34682
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Arial Unicode MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Batang
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@BatangChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DFKai-SB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Dotum
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DotumChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@FangSong
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gulim
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GulimChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gungsuh
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GungsuhChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@KaiTi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Malgun Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft JhengHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft YaHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Mincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PGothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PMincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS UI Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@NSimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Agency FB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aharoni
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Algerian
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Andalus
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Angsana New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
AngsanaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aparajita
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arabic Typesetting
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Black
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Narrow
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Rounded MT Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Unicode MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Baskerville Old Face
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Batang
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BatangChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bauhaus 93
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bell MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB Demi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bernard MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Blackadder ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Black
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Poster Compressed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Book Antiqua
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookman Old Style
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookshelf Symbol 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bradley Hand ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Britannic Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Broadway
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Browallia New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BrowalliaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Brush Script MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Californian FB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calisto MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria Math
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Candara
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Castellar
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Centaur
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Schoolbook
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Chiller
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Colonna MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Comic Sans MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Consolas
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Constantia
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cooper Black
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Corbel
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cordia New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
CordiaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Courier New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Curlz MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DaunPenh
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
David
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DFKai-SB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DilleniaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DokChampa
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Dotum
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DotumChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ebrima
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Edwardian Script ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Elephant
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Engravers MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Bold ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Demi ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Light ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Medium ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Estrangelo Edessa
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
EucrosiaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Euphemia
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FangSong
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Felix Titling
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Footlight MT Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Forte
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Book
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi Cond
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Heavy
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium Cond
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FrankRuehl
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FreesiaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Freestyle Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
French Script MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gabriola
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Garamond
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gautami
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Georgia
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gigi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Ext Condensed Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gisha
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gloucester MT Extra Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Old Style
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Stout
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gulim
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GulimChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gungsuh
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GungsuhChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Haettenschweiler
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harlow Solid Italic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harrington
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
High Tower Text
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Impact
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Imprint MT Shadow
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Informal Roman
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
IrisUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Iskoola Pota
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
JasmineUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Jokerman
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Juice ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KaiTi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kalinga
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kartika
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Khmer UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KodchiangUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kokila
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kristen ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kunstler Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lao UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Latha
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Leelawadee
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Levenim MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
LilyUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Bright
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Calligraphy
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Console
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Fax
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Handwriting
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Typewriter
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Unicode
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Magneto
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Maiandra GD
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Malgun Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mangal
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Marlett
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Matura MT Script Capitals
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Himalaya
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft JhengHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft New Tai Lue
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft PhagsPa
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Sans Serif
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Tai Le
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Uighur
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft YaHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Yi Baiti
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam Fixed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mistral
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Modern No. 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mongolian Baiti
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Monotype Corsiva
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MoolBoran
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Mincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Outlook
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PGothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PMincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Sans Serif
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Specialty
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS UI Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MT Extra
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MV Boli
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Narkisim
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Engraved
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Solid
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
NSimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Nyala
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
OCR A Extended
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Old English Text MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Onyx
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palace Script MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palatino Linotype
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Papyrus
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Parchment
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua Titling MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Plantagenet Cherokee
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Playbill
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Poor Richard
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Pristina
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Raavi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rage Italic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ravie
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Extra Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rod
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sakkal Majalla
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Script MT Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Print
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Semibold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Symbol
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shonar Bangla
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Showcard Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shruti
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic Fixed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Snap ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Stencil
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sylfaen
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Symbol
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tahoma
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tempus Sans ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Times New Roman
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Traditional Arabic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Trebuchet MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tunga
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed Extra Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Utsaah
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vani
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Verdana
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vijaya
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Viner Hand ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vivaldi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vladimir Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vrinda
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Webdings
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wide Latin
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\3BB15
3BB15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
WORDFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\3BB15
3BB15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Data
Settings
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Options
ZoomApp
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTF
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTA
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
EquationEditorFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\gudostrp_RASAPI32
EnableFileTracing
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\gudostrp_RASAPI32
EnableConsoleTracing
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\gudostrp_RASAPI32
FileTracingMask
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\gudostrp_RASAPI32
ConsoleTracingMask
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\gudostrp_RASAPI32
MaxFileSize
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\gudostrp_RASAPI32
FileDirectory
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\gudostrp_RASMANCS
EnableFileTracing
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\gudostrp_RASMANCS
EnableConsoleTracing
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\gudostrp_RASMANCS
FileTracingMask
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\gudostrp_RASMANCS
ConsoleTracingMask
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\gudostrp_RASMANCS
MaxFileSize
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\gudostrp_RASMANCS
FileDirectory
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
clean
There are 332 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
238D000
unkown
page read and write
malicious
2338000
unkown
page read and write
malicious
22B1000
unkown
page read and write
malicious
402000
unkown
page execute and read and write
malicious
31C9000
unkown
page read and write
malicious
444000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
2C0000
unkown
page read and write
clean
545E000
stack
page read and write
clean
12D000
unkown
page execute and read and write
clean
330000
unkown
page read and write
clean
6B3000
unkown
page read and write
clean
330000
unkown
page read and write
clean
60E0000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
640000
heap private
page execute and read and write
clean
444000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
1F90000
unkown
page read and write
clean
5127000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
6AE0000
unkown
page read and write
clean
555000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
900000
unkown
page read and write
clean
630000
unkown
page read and write
clean
29D000
stack
page read and write
clean
1B2000
unkown
page read and write
clean
5210000
unkown
page read and write
clean
20E0000
unkown
page read and write
clean
5F0000
unkown
page read and write
clean
5650000
heap private
page read and write
clean
1D0000
unkown image
page readonly
clean
1D2000
unkown image
page execute read
clean
2144000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
446000
unkown
page read and write
clean
555000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
5F0000
unkown
page read and write
clean
6B0000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
6D5000
unkown
page read and write
clean
8E0000
unkown
page read and write
clean
5CF0000
unkown image
page readonly
clean
555000
unkown
page read and write
clean
619000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
8D0000
unkown
page read and write
clean
619000
unkown
page read and write
clean
1F90000
unkown
page read and write
clean
50F9000
unkown
page read and write
clean
720000
unkown
page read and write
clean
8E0000
unkown
page read and write
clean
600000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
2140000
unkown
page read and write
clean
8F0000
unkown
page read and write
clean
555000
unkown
page read and write
clean
760000
heap default
page read and write
clean
600000
unkown
page read and write
clean
620000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
550000
unkown
page read and write
clean
8D0000
unkown
page read and write
clean
2260000
unkown
page read and write
clean
20E0000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
100000
unkown
page read and write
clean
788000
heap default
page read and write
clean
132000
unkown
page read and write
clean
960000
stack
page read and write
clean
6C0000
unkown
page read and write
clean
400000
unkown
page execute and read and write
clean
2B0000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
1C7000
unkown
page execute and read and write
clean
B30000
unkown image
page readonly
clean
8E0000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
5F0000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
6C0000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
20F5000
stack
page read and write
clean
5F0000
unkown
page read and write
clean
629000
unkown
page read and write
clean
900000
unkown
page read and write
clean
432000
unkown
page read and write
clean
960000
stack
page read and write
clean
5F0000
unkown image
page readonly
clean
8D0000
unkown
page read and write
clean
50D0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
2040000
unkown
page read and write
clean
1A0000
unkown
page read and write
clean
720000
unkown
page read and write
clean
2100000
stack
page read and write
clean
1F90000
unkown
page read and write
clean
90000
unkown
page read and write
clean
4794000
heap private
page read and write
clean
300000
unkown
page execute and read and write
clean
5F0000
unkown
page read and write
clean
727000
heap default
page read and write
clean
2B8000
unkown
page read and write
clean
550000
unkown
page read and write
clean
630000
unkown
page read and write
clean
8E0000
unkown
page read and write
clean
619000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
444000
unkown
page read and write
clean
555000
unkown
page read and write
clean
8D0000
unkown
page read and write
clean
900000
unkown
page read and write
clean
559000
unkown
page read and write
clean
5F0000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
630000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
2120000
stack
page read and write
clean
71E000
stack
page read and write
clean
5F0000
unkown
page read and write
clean
42B0000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
740000
unkown image
page readonly
clean
248000
unkown image
page readonly
clean
6C0000
unkown
page read and write
clean
720000
unkown
page read and write
clean
248000
unkown image
page readonly
clean
6D0000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
610000
unkown
page read and write
clean
B0000
heap default
page read and write
clean
440000
unkown
page read and write
clean
2090000
unkown
page read and write
clean
48D2000
heap private
page read and write
clean
42B0000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
493C000
stack
page read and write
clean
8D0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
2B5000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
4B30000
heap private
page execute and read and write
clean
558000
unkown
page read and write
clean
2050000
heap private
page read and write
clean
900000
unkown
page read and write
clean
1D0000
unkown image
page readonly
clean
6DC000
unkown
page read and write
clean
130000
unkown
page read and write
clean
8D0000
unkown
page read and write
clean
550000
unkown
page read and write
clean
1F90000
unkown
page read and write
clean
5F6000
unkown
page read and write
clean
5672000
heap private
page read and write
clean
1EB0000
unkown image
page readonly
clean
1F90000
unkown
page read and write
clean
5211000
unkown
page read and write
clean
60F3000
unkown
page read and write
clean
556000
unkown
page read and write
clean
540000
heap private
page read and write
clean
620000
unkown
page read and write
clean
145000
unkown
page execute and read and write
clean
600000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
8D0000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
600000
unkown
page read and write
clean
610000
unkown
page read and write
clean
1C2000
unkown
page read and write
clean
336000
unkown
page read and write
clean
336000
unkown
page read and write
clean
2030000
unkown
page read and write
clean
730000
heap private
page read and write
clean
20F0000
stack
page read and write
clean
2B5000
unkown
page read and write
clean
8E0000
unkown
page read and write
clean
8D0000
unkown
page read and write
clean
440000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
347000
heap default
page read and write
clean
5F2000
unkown
page read and write
clean
5F0000
unkown
page read and write
clean
8F0000
unkown
page read and write
clean
60E7000
unkown
page read and write
clean
720000
unkown
page read and write
clean
550000
unkown
page read and write
clean
23E4000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
8D0000
unkown
page read and write
clean
8D0000
unkown
page read and write
clean
550000
unkown
page read and write
clean
570000
heap default
page read and write
clean
414000
unkown
page read and write
clean
336000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
6ADE000
unkown
page read and write
clean
336000
unkown
page read and write
clean
5127000
unkown
page read and write
clean
339000
unkown
page read and write
clean
619000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
619000
unkown
page read and write
clean
550000
unkown
page read and write
clean
440E000
stack
page read and write
clean
6D0000
unkown
page read and write
clean
600000
unkown
page read and write
clean
630000
unkown
page read and write
clean
4F2D000
stack
page read and write
clean
330000
unkown
page read and write
clean
7BF000
heap default
page read and write
clean
2250000
unkown
page read and write
clean
330000
unkown
page read and write
clean
620000
unkown
page read and write
clean
900000
unkown
page read and write
clean
444000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
620000
unkown
page read and write
clean
2140000
unkown
page read and write
clean
96B000
stack
page read and write
clean
52C5000
unkown
page read and write
clean
550000
unkown
page read and write
clean
6CE000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
5F6000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
440000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
500000
unkown image
page read and write
clean
6C0000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
8F0000
unkown
page read and write
clean
5127000
unkown
page read and write
clean
432000
unkown
page read and write
clean
552000
unkown
page read and write
clean
6DA0000
heap private
page read and write
clean
6CE000
unkown
page read and write
clean
8F0000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
6C6000
unkown
page read and write
clean
380000
heap default
page read and write
clean
4AFE000
stack
page read and write
clean
2B5000
unkown
page read and write
clean
4FFE000
stack
page read and write
clean
238A000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
720000
unkown
page execute and read and write
clean
2B5000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
6C0000
unkown
page read and write
clean
619000
unkown
page read and write
clean
2140000
unkown
page read and write
clean
1F90000
unkown
page read and write
clean
960000
stack
page read and write
clean
610000
unkown
page read and write
clean
70000
unkown image
page read and write
clean
2020000
unkown
page read and write
clean
6D1000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
960000
stack
page read and write
clean
555000
unkown
page read and write
clean
5F6000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
8E0000
unkown
page read and write
clean
8D0000
unkown
page read and write
clean
330000
unkown
page read and write
clean
619000
unkown
page read and write
clean
620000
unkown
page read and write
clean
120000
unkown
page read and write
clean
64CE000
stack
page read and write
clean
23FF000
unkown
page read and write
clean
1FA0000
unkown
page execute and read and write
clean
1F90000
unkown
page read and write
clean
610000
unkown
page read and write
clean
8F0000
unkown
page read and write
clean
8F0000
unkown
page read and write
clean
610000
unkown
page read and write
clean
20A0000
unkown
page read and write
clean
444000
unkown
page read and write
clean
1F90000
unkown
page read and write
clean
1D2000
unkown image
page execute read
clean
1FD0000
unkown
page read and write
clean
2264000
unkown
page read and write
clean
440000
unkown
page read and write
clean
8D0000
unkown
page read and write
clean
620000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
5F0000
unkown
page read and write
clean
54CF000
stack
page read and write
clean
6C0000
unkown
page read and write
clean
550000
unkown
page read and write
clean
20F0000
stack
page read and write
clean
7FD000
heap default
page read and write
clean
5F6000
unkown
page read and write
clean
440000
unkown
page read and write
clean
620000
unkown
page read and write
clean
21C1000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
960000
stack
page read and write
clean
2090000
unkown
page read and write
clean
5F6000
unkown
page read and write
clean
6CE000
unkown
page read and write
clean
440000
unkown
page read and write
clean
630000
unkown
page read and write
clean
444000
unkown
page read and write
clean
600000
unkown
page read and write
clean
720000
unkown
page read and write
clean
23FC000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
2110000
stack
page read and write
clean
2090000
unkown
page read and write
clean
602000
unkown
page read and write
clean
5810000
unkown
page read and write
clean
51A6000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
620000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
521E000
stack
page read and write
clean
6CE000
unkown
page read and write
clean
610000
unkown
page read and write
clean
20D0000
unkown
page read and write
clean
320000
unkown
page read and write
clean
8E0000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
8F0000
unkown
page read and write
clean
432000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
336000
unkown
page read and write
clean
619000
unkown
page read and write
clean
630000
unkown
page read and write
clean
336000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
23E2000
unkown
page read and write
clean
4E50000
unkown
page read and write
clean
113000
unkown
page execute and read and write
clean
550000
unkown
page execute and read and write
clean
7EFB2000
unkown image
page readonly
clean
550000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
60EF000
unkown
page read and write
clean
920000
unkown image
page readonly
clean
6D0000
unkown
page read and write
clean
8E0000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
2BB000
unkown
page read and write
clean
42F0000
unkown
page read and write
clean
6A0000
unkown
page read and write
clean
619000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
7DB000
heap default
page read and write
clean
6C0000
unkown
page read and write
clean
6C3000
unkown
page read and write
clean
2100000
stack
page read and write
clean
1D0000
unkown image
page readonly
clean
2B5000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
1FC0000
unkown
page execute and read and write
clean
14B000
unkown
page execute and read and write
clean
2250000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
20000
unkown
page read and write
clean
440000
unkown
page execute and read and write
clean
1FB0000
unkown
page execute and read and write
clean
550000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
628000
unkown
page read and write
clean
960000
stack
page read and write
clean
619000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
550000
unkown
page read and write
clean
560D000
stack
page read and write
clean
2250000
unkown
page read and write
clean
900000
unkown
page read and write
clean
720000
unkown
page read and write
clean
484E000
stack
page read and write
clean
1D0000
unkown image
page readonly
clean
414000
unkown
page read and write
clean
550000
unkown
page read and write
clean
630000
unkown
page read and write
clean
5F0000
unkown
page read and write
clean
4BE000
stack
page read and write
clean
8E0000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
720000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
619000
unkown
page read and write
clean
6CE000
unkown
page read and write
clean
56CE000
stack
page read and write
clean
960000
stack
page read and write
clean
6CE000
unkown
page read and write
clean
5F6000
unkown
page read and write
clean
5200000
heap private
page read and write
clean
6B0000
unkown
page read and write
clean
5162000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
744000
heap default
page read and write
clean
2B0000
unkown
page read and write
clean
2C0000
unkown
page read and write
clean
2270000
heap private
page read and write
clean
4790000
heap private
page read and write
clean
24A9000
unkown
page read and write
clean
21BF000
stack
page read and write
clean
2B0000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
550000
unkown
page read and write
clean
49ED000
stack
page read and write
clean
6D0000
unkown
page read and write
clean
442E000
stack
page read and write
clean
8E0000
unkown
page read and write
clean
5CEC000
unkown
page read and write
clean
900000
unkown
page read and write
clean
600000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
20EA000
unkown
page read and write
clean
91F000
stack
page read and write
clean
1F90000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
555000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
444000
unkown
page read and write
clean
720000
unkown
page read and write
clean
610000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
8D0000
unkown
page read and write
clean
6CE000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
600000
unkown
page read and write
clean
48B4000
heap private
page read and write
clean
4B0F000
stack
page read and write
clean
610000
unkown
page read and write
clean
720000
unkown
page read and write
clean
550000
unkown
page read and write
clean
9B0000
unkown image
page readonly
clean
547000
heap private
page read and write
clean
6DE000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
444000
unkown
page read and write
clean
610000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
2260000
unkown
page read and write
clean
2100000
stack
page read and write
clean
550000
unkown
page read and write
clean
444000
unkown
page read and write
clean
610000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
900000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
23EA000
unkown
page read and write
clean
6BD000
stack
page read and write
clean
6C0000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
2260000
unkown
page read and write
clean
440000
unkown
page read and write
clean
6B0000
unkown
page read and write
clean
3D9000
heap default
page read and write
clean
53CE000
stack
page read and write
clean
600000
unkown
page read and write
clean
610000
unkown image
page readonly
clean
600000
unkown
page read and write
clean
330000
unkown
page read and write
clean
6B0000
unkown
page read and write
clean
8F0000
unkown
page read and write
clean
3E6000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
CD0000
unkown image
page readonly
clean
7D3000
heap default
page read and write
clean
76D000
heap default
page read and write
clean
610000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
620000
unkown
page read and write
clean
6CE000
unkown
page read and write
clean
550000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
1F90000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
1D2000
unkown image
page execute read
clean
2250000
unkown
page read and write
clean
8F0000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
51A6000
unkown
page read and write
clean
414000
heap default
page read and write
clean
336000
unkown
page read and write
clean
414000
unkown
page read and write
clean
600000
unkown
page read and write
clean
41E0000
unkown
page read and write
clean
440000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
5F0000
unkown
page read and write
clean
1CB000
unkown
page execute and read and write
clean
2B0000
unkown
page read and write
clean
6B0000
unkown image
page readonly
clean
720000
unkown
page read and write
clean
530000
unkown
page read and write
clean
630000
unkown
page read and write
clean
20F0000
stack
page read and write
clean
6D0000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
5F6000
unkown
page read and write
clean
6C80000
heap private
page read and write
clean
568000
heap private
page read and write
clean
550000
unkown
page read and write
clean
431E000
stack
page read and write
clean
6C0000
unkown
page read and write
clean
6CE000
unkown
page read and write
clean
336000
unkown
page read and write
clean
41C0000
unkown
page read and write
clean
5129000
unkown
page read and write
clean
406000
heap default
page read and write
clean
444000
unkown
page read and write
clean
444000
unkown
page read and write
clean
555000
unkown
page read and write
clean
5F0000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
5F4000
unkown
page read and write
clean
1AD000
unkown
page execute and read and write
clean
42EF000
stack
page read and write
clean
6D0000
unkown
page read and write
clean
610000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
5F0000
unkown
page read and write
clean
630000
unkown
page read and write
clean
5F6000
unkown
page read and write
clean
8E0000
unkown
page read and write
clean
6CE000
unkown
page read and write
clean
2260000
unkown
page read and write
clean
620000
unkown
page read and write
clean
80000
unkown image
page read and write
clean
AD000
unkown
page execute and read and write
clean
2250000
unkown
page read and write
clean
2FA000
unkown
page read and write
clean
6B0000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
555000
unkown
page read and write
clean
429000
heap default
page read and write
clean
2B0000
unkown
page read and write
clean
71E000
stack
page read and write
clean
960000
stack
page read and write
clean
4F80000
heap private
page read and write
clean
6C0000
unkown
page read and write
clean
600000
unkown
page read and write
clean
330000
unkown
page read and write
clean
1F90000
unkown
page read and write
clean
900000
unkown
page read and write
clean
1F90000
unkown
page read and write
clean
550000
unkown
page read and write
clean
2C0000
unkown
page read and write
clean
630000
unkown
page read and write
clean
2020000
unkown
page execute and read and write
clean
900000
unkown
page read and write
clean
31C1000
unkown
page read and write
clean
2B8000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
5ADE000
stack
page read and write
clean
552000
unkown
page read and write
clean
620000
unkown
page read and write
clean
6C30000
heap private
page read and write
clean
600000
unkown
page read and write
clean
6C1000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
1D0000
unkown image
page readonly
clean
630000
unkown
page read and write
clean
606000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
114000
unkown
page read and write
clean
409000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
5F6000
unkown
page read and write
clean
41D0000
unkown
page execute and read and write
clean
6C0000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
414000
unkown
page read and write
clean
550000
unkown
page read and write
clean
610000
unkown
page read and write
clean
20D0000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
3D7000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
960000
stack
page read and write
clean
5F6000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
630000
unkown
page read and write
clean
5127000
unkown
page read and write
clean
48B0000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
900000
unkown
page read and write
clean
620000
unkown
page read and write
clean
900000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
1F90000
unkown
page read and write
clean
248000
unkown image
page readonly
clean
2130000
unkown
page read and write
clean
6C5000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
440000
unkown
page read and write
clean
630000
unkown
page read and write
clean
1F90000
unkown
page read and write
clean
5F6000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
336000
unkown
page read and write
clean
900000
unkown
page read and write
clean
330000
unkown
page read and write
clean
330000
unkown
page read and write
clean
6B0000
unkown
page read and write
clean
8F0000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
610000
unkown
page read and write
clean
690000
unkown
page read and write
clean
B40000
unkown image
page readonly
clean
600000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
6D5000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
630000
unkown
page read and write
clean
620000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
5F0000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
4740000
heap private
page execute and read and write
clean
900000
unkown
page read and write
clean
50D1000
unkown
page read and write
clean
8F0000
unkown
page read and write
clean
630000
unkown
page read and write
clean
1B7000
unkown
page execute and read and write
clean
690000
unkown image
page readonly
clean
5F6000
unkown
page read and write
clean
20B0000
unkown
page read and write
clean
51A6000
unkown
page read and write
clean
20D1000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
11D000
unkown
page execute and read and write
clean
690000
unkown
page read and write
clean
95E000
stack
page read and write
clean
8D0000
unkown
page read and write
clean
600000
unkown
page read and write
clean
8F0000
unkown
page read and write
clean
20E0000
unkown
page read and write
clean
4E6D000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
50F7000
unkown
page read and write
clean
8D0000
unkown
page read and write
clean
550000
unkown
page read and write
clean
1FD0000
unkown
page execute and read and write
clean
610000
unkown
page read and write
clean
142000
unkown
page read and write
clean
444000
unkown
page read and write
clean
629000
unkown
page read and write
clean
550000
unkown
page read and write
clean
23EC000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
6DE000
unkown
page read and write
clean
444000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
606000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
310000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
5262000
unkown
page read and write
clean
1CA000
unkown
page read and write
clean
2030000
unkown
page read and write
clean
8E0000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
550000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
600000
unkown
page read and write
clean
6CE000
unkown
page read and write
clean
6CE000
unkown
page read and write
clean
8E0000
unkown
page read and write
clean
3A6000
heap default
page read and write
clean
6F2E000
stack
page read and write
clean
6C0000
unkown
page read and write
clean
550000
unkown
page read and write
clean
702E000
stack
page read and write
clean
555000
unkown
page read and write
clean
6DC000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
1D2000
unkown image
page execute read
clean
620000
unkown
page read and write
clean
580F000
stack
page read and write
clean
608000
unkown
page read and write
clean
619000
unkown
page read and write
clean
600000
unkown
page read and write
clean
444000
unkown
page read and write
clean
540E000
stack
page read and write
clean
690000
unkown
page read and write
clean
20B0000
unkown
page read and write
clean
900000
unkown
page read and write
clean
8D0000
unkown
page read and write
clean
8F0000
unkown
page read and write
clean
440000
unkown
page read and write
clean
432000
unkown
page read and write
clean
8C0000
unkown image
page readonly
clean
630000
unkown
page read and write
clean
5F6000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
A4000
unkown
page read and write
clean
330000
unkown
page read and write
clean
960000
stack
page read and write
clean
47B2000
heap private
page read and write
clean
910000
heap private
page read and write
clean
560000
heap private
page read and write
clean
2B0000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
26CE000
unkown
page read and write
clean
2030000
unkown
page execute and read and write
clean
6D0000
unkown
page read and write
clean
600000
unkown
page read and write
clean
414000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
555000
unkown
page read and write
clean
5060000
stack
page read and write
clean
5B3E000
stack
page read and write
clean
4A4D000
stack
page read and write
clean
32B1000
unkown
page read and write
clean
440000
unkown
page read and write
clean
440000
unkown
page read and write
clean
440000
unkown
page read and write
clean
630000
unkown
page read and write
clean
720000
unkown
page read and write
clean
38A000
heap default
page read and write
clean
6D0000
unkown
page read and write
clean
440000
unkown
page read and write
clean
330000
unkown
page read and write
clean
5F0000
unkown
page read and write
clean
250000
unkown
page execute and read and write
clean
970000
heap private
page execute and read and write
clean
610000
unkown
page read and write
clean
900000
unkown
page read and write
clean
8D0000
unkown
page read and write
clean
336000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
600000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
553000
unkown
page read and write
clean
6D5000
unkown
page read and write
clean
1BA000
unkown
page execute and read and write
clean
6D0000
unkown
page read and write
clean
240F000
unkown
page read and write
clean
417000
unkown
page read and write
clean
8E0000
unkown
page read and write
clean
440000
unkown
page read and write
clean
6CE000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
41C0000
unkown
page read and write
clean
330000
unkown
page read and write
clean
473E000
stack
page read and write
clean
248000
unkown image
page readonly
clean
5F0000
unkown
page read and write
clean
1F90000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
6163000
unkown
page read and write
clean
699E000
stack
page read and write
clean
50F8000
unkown
page read and write
clean
20000
unkown
page read and write
clean
224F000
stack
page read and write
clean
330000
unkown
page read and write
clean
5161000
unkown
page read and write
clean
8E0000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
720000
unkown
page read and write
clean
600000
unkown
page read and write
clean
E0000
unkown image
page read and write
clean
7EFB0000
unkown image
page readonly
clean
2250000
unkown
page read and write
clean
2BE000
stack
page read and write
clean
440000
unkown
page read and write
clean
8E0000
unkown
page read and write
clean
904000
unkown
page read and write
clean
1FE0000
heap private
page execute and read and write
clean
1F90000
unkown
page read and write
clean
555000
unkown
page read and write
clean
720000
unkown
page read and write
clean
47D000
stack
page read and write
clean
5655000
heap private
page read and write
clean
67BE000
unkown
page read and write
clean
440000
unkown
page read and write
clean
600000
unkown
page read and write
clean
610000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
550000
unkown
page read and write
clean
340000
heap default
page read and write
clean
440000
unkown
page read and write
clean
136000
unkown
page execute and read and write
clean
611D000
unkown
page read and write
clean
630000
unkown
page read and write
clean
A3000
unkown
page execute and read and write
clean
600000
unkown
page read and write
clean
8F0000
unkown
page read and write
clean
335000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
20A0000
unkown
page read and write
clean
330000
unkown
page read and write
clean
20A0000
unkown
page read and write
clean
50CD000
stack
page read and write
clean
620000
unkown
page read and write
clean
336000
unkown
page read and write
clean
330000
unkown
page read and write
clean
330000
unkown
page read and write
clean
180000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
4F8C000
stack
page read and write
clean
5F4000
unkown
page read and write
clean
720000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
6B0000
unkown
page read and write
clean
6C91000
heap private
page read and write
clean
2106000
stack
page read and write
clean
8F0000
unkown
page read and write
clean
6CE000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
510000
unkown
page execute and read and write
clean
570D000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
407000
unkown
page read and write
clean
432000
unkown
page read and write
clean
147000
unkown
page execute and read and write
clean
8D0000
unkown
page read and write
clean
5F6000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
550000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
2040000
unkown
page read and write
clean
550000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
1D0000
unkown image
page readonly
clean
5F0000
unkown
page read and write
clean
620000
unkown
page read and write
clean
241C000
unkown
page read and write
clean
620000
unkown
page read and write
clean
2040000
unkown
page read and write
clean
550000
unkown
page read and write
clean
720000
heap default
page read and write
clean
550000
unkown
page read and write
clean
24AF000
unkown
page read and write
clean
5F6000
unkown
page read and write
clean
900000
unkown
page read and write
clean
336000
unkown
page read and write
clean
630000
unkown
page read and write
clean
2040000
unkown
page read and write
clean
335000
unkown
page read and write
clean
6B0000
unkown
page read and write
clean
620000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
720000
unkown
page read and write
clean
42B0000
unkown
page execute and read and write
clean
600000
unkown
page read and write
clean
8E0000
unkown
page read and write
clean
2420000
unkown
page read and write
clean
13A000
unkown
page execute and read and write
clean
60B000
unkown
page read and write
clean
446000
unkown
page read and write
clean
6C0000
unkown
page read and write
clean
8E0000
unkown
page read and write
clean
619000
unkown
page read and write
clean
63BE000
stack
page read and write
clean
4C0000
heap private
page execute and read and write
clean
47D0000
unkown image
page readonly
clean
2040000
unkown
page read and write
clean
5F0000
unkown
page read and write
clean
24A7000
unkown
page read and write
clean
620000
unkown
page read and write
clean
547000
unkown
page read and write
clean
3F0000
unkown image
page readonly
clean
600000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
619000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
555000
unkown
page read and write
clean
550000
unkown
page read and write
clean
8F0000
unkown
page read and write
clean
720000
unkown
page read and write
clean
364000
heap default
page read and write
clean
8F0000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
550000
unkown
page read and write
clean
38D000
heap default
page read and write
clean
600000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
91E000
stack
page read and write | page guard
clean
There are 896 hidden memdumps, click here to show them.