IOC Report

loading gif

Files

File Path
Type
Category
Malicious
PO141021.doc
Rich Text Format data, unknown version
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\goshcj[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Roaming\godsawqop.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{0008E59B-A89A-4382-AC7E-24705A8EB889}.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{773917BE-1BC4-4D2D-91B8-39B324F718F3}.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{7764CFCD-FF48-436A-A353-8D268E618EA5}.tmp
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\PO141021.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Mon Aug 30 20:08:55 2021, mtime=Mon Aug 30 20:08:55 2021, atime=Thu Oct 14 16:35:13 2021, length=104541, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
dropped
clean
C:\Users\user\Desktop\~$141021.doc
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
malicious
C:\Users\user\AppData\Roaming\godsawqop.exe
C:\Users\user\AppData\Roaming\godsawqop.exe
malicious
C:\Users\user\AppData\Roaming\godsawqop.exe
C:\Users\user\AppData\Roaming\godsawqop.exe
malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
'C:\Program Files\Microsoft Office\Office14\WINWORD.EXE' /Automation -Embedding
clean

URLs

Name
IP
Malicious
http://milkhost.ru/trasper/goshcj.exe
95.216.94.72
malicious
http://127.0.0.1:HTTP/1.1
unknown
clean
http://DynDns.comDynDNS
unknown
clean
http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
https://api.telegram.org/bot1923392915:AAHa8aKPuVKh5L9QUsA47Z5cQ-J2e00kH0Y/
unknown
clean
https://4hCltxiPdhpdC.com
unknown
clean
https://api.telegram.org
unknown
clean
http://crl.entrust.net/server1.crl0
unknown
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
unknown
clean
http://ocsp.entrust.net03
unknown
clean
http://mZWVLr.com
unknown
clean
https://api.telegram.org/bot1923392915:AAHa8aKPuVKh5L9QUsA47Z5cQ-J2e00kH0Y/sendDocumentdocument-----
unknown
clean
https://api.telegram.orgP
unknown
clean
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
unknown
clean
https://api.telegram.org/bot1923392915:AAHa8aKPuVKh5L9QUsA47Z5cQ-J2e00kH0Y/sendDocument
149.154.167.220
clean
http://www.%s.comPA
unknown
clean
http://www.diginotar.nl/cps/pkioverheid0
unknown
clean
http://api.telegram.org
unknown
clean
http://ocsp.entrust.net0D
unknown
clean
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
clean
https://secure.comodo.com/CPS0
unknown
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
unknown
clean
http://crl.entrust.net/2048ca.crl0
unknown
clean
There are 14 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
milkhost.ru
95.216.94.72
malicious
api.telegram.org
149.154.167.220
clean

IPs

IP
Domain
Country
Malicious
95.216.94.72
milkhost.ru
Germany
malicious
149.154.167.220
api.telegram.org
United Kingdom
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
i &
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
q!&
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
q#&
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\342E9
342E9
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Arial Unicode MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Batang
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@BatangChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DFKai-SB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Dotum
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DotumChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@FangSong
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gulim
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GulimChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gungsuh
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GungsuhChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@KaiTi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Malgun Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft JhengHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft YaHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Mincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PGothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PMincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS UI Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@NSimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Agency FB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aharoni
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Algerian
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Andalus
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Angsana New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
AngsanaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aparajita
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arabic Typesetting
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Black
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Narrow
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Rounded MT Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Unicode MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Baskerville Old Face
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Batang
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BatangChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bauhaus 93
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bell MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB Demi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bernard MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Blackadder ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Black
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Poster Compressed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Book Antiqua
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookman Old Style
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookshelf Symbol 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bradley Hand ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Britannic Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Broadway
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Browallia New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BrowalliaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Brush Script MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Californian FB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calisto MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria Math
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Candara
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Castellar
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Centaur
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Schoolbook
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Chiller
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Colonna MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Comic Sans MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Consolas
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Constantia
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cooper Black
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Corbel
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cordia New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
CordiaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Courier New
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Curlz MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DaunPenh
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
David
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DFKai-SB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DilleniaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DokChampa
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Dotum
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DotumChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ebrima
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Edwardian Script ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Elephant
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Engravers MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Bold ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Demi ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Light ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Medium ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Estrangelo Edessa
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
EucrosiaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Euphemia
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FangSong
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Felix Titling
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Footlight MT Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Forte
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Book
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi Cond
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Heavy
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium Cond
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FrankRuehl
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FreesiaUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Freestyle Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
French Script MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gabriola
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Garamond
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gautami
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Georgia
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gigi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Ext Condensed Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gisha
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gloucester MT Extra Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Old Style
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Stout
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gulim
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GulimChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gungsuh
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GungsuhChe
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Haettenschweiler
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harlow Solid Italic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harrington
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
High Tower Text
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Impact
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Imprint MT Shadow
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Informal Roman
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
IrisUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Iskoola Pota
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
JasmineUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Jokerman
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Juice ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KaiTi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kalinga
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kartika
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Khmer UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KodchiangUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kokila
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kristen ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kunstler Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lao UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Latha
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Leelawadee
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Levenim MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
LilyUPC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Bright
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Calligraphy
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Console
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Fax
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Handwriting
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Typewriter
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Unicode
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Magneto
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Maiandra GD
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Malgun Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mangal
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Marlett
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Matura MT Script Capitals
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Himalaya
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft JhengHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft New Tai Lue
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft PhagsPa
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Sans Serif
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Tai Le
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Uighur
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft YaHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Yi Baiti
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam Fixed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mistral
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Modern No. 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mongolian Baiti
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Monotype Corsiva
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MoolBoran
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Mincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Outlook
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PGothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PMincho
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Sans Serif
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Specialty
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS UI Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MT Extra
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MV Boli
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Narkisim
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Engraved
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Solid
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
NSimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Nyala
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
OCR A Extended
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Old English Text MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Onyx
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palace Script MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palatino Linotype
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Papyrus
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Parchment
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua Titling MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Plantagenet Cherokee
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Playbill
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Poor Richard
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Pristina
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Raavi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rage Italic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ravie
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Extra Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rod
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sakkal Majalla
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Script MT Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Print
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Light
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Semibold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Symbol
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shonar Bangla
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Showcard Gothic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shruti
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimHei
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic Fixed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun-ExtB
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Snap ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Stencil
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sylfaen
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Symbol
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tahoma
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tempus Sans ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Times New Roman
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Traditional Arabic
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Trebuchet MS
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tunga
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed Extra Bold
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Utsaah
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vani
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Verdana
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vijaya
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Viner Hand ITC
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vivaldi
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vladimir Script
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vrinda
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Webdings
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wide Latin
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\3B71F
3B71F
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
WORDFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\3B71F
3B71F
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Data
Settings
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Options
ZoomApp
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTF
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTA
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
EquationEditorFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\godsawqop_RASAPI32
EnableFileTracing
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\godsawqop_RASAPI32
EnableConsoleTracing
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\godsawqop_RASAPI32
FileTracingMask
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\godsawqop_RASAPI32
ConsoleTracingMask
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\godsawqop_RASAPI32
MaxFileSize
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\godsawqop_RASAPI32
FileDirectory
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\godsawqop_RASMANCS
EnableFileTracing
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\godsawqop_RASMANCS
EnableConsoleTracing
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\godsawqop_RASMANCS
FileTracingMask
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\godsawqop_RASMANCS
ConsoleTracingMask
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\godsawqop_RASMANCS
MaxFileSize
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\godsawqop_RASMANCS
FileDirectory
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
clean
There are 332 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
402000
unkown
page execute and read and write
malicious
32EA000
unkown
page read and write
malicious
256A000
unkown
page read and write
malicious
24E1000
unkown
page read and write
malicious
640000
unkown
page read and write
clean
330000
unkown
page read and write
clean
7B9000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
7F0000
unkown
page read and write
clean
43E000
unkown
page read and write
clean
3C0000
unkown
page read and write
clean
22E1000
unkown
page read and write
clean
430000
unkown
page read and write
clean
470000
unkown
page read and write
clean
7A5000
unkown
page read and write
clean
49B8000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
640000
unkown
page read and write
clean
185000
unkown
page execute and read and write
clean
500000
unkown
page read and write
clean
450000
unkown
page read and write
clean
460000
unkown
page read and write
clean
201D000
stack
page read and write
clean
2F0000
unkown
page read and write
clean
7F0000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
314000
unkown
page read and write
clean
324000
unkown
page read and write
clean
342000
unkown image
page execute read
clean
470000
unkown
page read and write
clean
430000
unkown
page read and write
clean
340000
unkown image
page readonly
clean
70000
unkown image
page read and write
clean
430000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
310000
unkown
page read and write
clean
640000
unkown
page read and write
clean
500000
unkown
page read and write
clean
53B0000
heap private
page read and write
clean
870000
unkown
page read and write
clean
490000
unkown
page read and write
clean
7A7000
unkown
page read and write
clean
306000
unkown
page read and write
clean
440000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
306000
unkown
page read and write
clean
16D000
unkown
page execute and read and write
clean
310000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
4EF3000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
3C9000
unkown
page read and write
clean
430000
unkown
page read and write
clean
192000
unkown
page read and write
clean
435000
unkown
page read and write
clean
320000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
320000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
7F0000
unkown
page read and write
clean
430000
unkown
page read and write
clean
202A000
unkown
page read and write
clean
870000
unkown
page read and write
clean
7A5000
unkown
page read and write
clean
430000
unkown
page read and write
clean
460000
unkown
page read and write
clean
65DE000
stack
page read and write
clean
870000
unkown
page read and write
clean
7F0000
unkown
page read and write
clean
326000
unkown
page read and write
clean
510000
unkown
page read and write
clean
890000
unkown
page read and write
clean
140000
unkown image
page read and write
clean
3C0000
unkown
page read and write
clean
1C0000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
624000
heap default
page read and write
clean
750000
unkown
page read and write
clean
314000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
875000
unkown
page read and write
clean
2F8000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
470000
unkown
page read and write
clean
460000
unkown
page read and write
clean
430000
unkown
page read and write
clean
18A000
unkown
page execute and read and write
clean
3E0000
unkown
page read and write
clean
7F0000
unkown
page read and write
clean
430000
unkown
page read and write
clean
306000
unkown
page read and write
clean
300000
unkown
page read and write
clean
870000
unkown
page read and write
clean
4E9B000
unkown
page read and write
clean
320000
unkown
page read and write
clean
A4000
unkown
page read and write
clean
430000
unkown
page read and write
clean
7EE000
stack
page read and write
clean
336000
unkown
page read and write
clean
54E5000
heap private
page read and write
clean
45BE000
unkown
page read and write
clean
300000
unkown
page read and write
clean
7F0000
unkown
page read and write
clean
326000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
7A5000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
810000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
430000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
22A0000
heap private
page read and write
clean
1FD0000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
163000
unkown
page execute and read and write
clean
870000
unkown
page read and write
clean
322000
unkown
page read and write
clean
316000
unkown
page read and write
clean
490000
unkown
page read and write
clean
43E000
unkown
page read and write
clean
553D000
unkown
page read and write
clean
342000
unkown image
page execute read
clean
7F0000
unkown
page read and write
clean
650000
unkown
page execute and read and write
clean
7A5000
unkown
page read and write
clean
326000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
3C9000
unkown
page read and write
clean
887000
heap private
page read and write
clean
4F2D000
unkown
page read and write
clean
197000
unkown
page execute and read and write
clean
520000
heap default
page read and write
clean
769000
heap default
page read and write
clean
320000
unkown
page read and write
clean
25C9000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
871000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
340000
unkown image
page readonly
clean
7F0000
unkown
page read and write
clean
870000
unkown
page read and write
clean
480000
unkown
page execute and read and write
clean
310000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
460000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
460000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
22C0000
unkown
page read and write
clean
43E000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
3C0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
300000
unkown
page read and write
clean
130000
unkown image
page read and write
clean
B0000
unkown
page read and write
clean
460000
unkown
page read and write
clean
23CF000
stack
page read and write
clean
2F5000
unkown
page read and write
clean
229F000
stack
page read and write
clean
470000
unkown
page read and write
clean
440000
unkown
page read and write
clean
4990000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
450000
unkown
page read and write
clean
7F0000
unkown
page read and write
clean
430000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
4F0000
unkown
page read and write
clean
330000
unkown
page read and write
clean
440000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
650000
unkown
page read and write
clean
330000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
510000
unkown
page read and write
clean
4E9D000
unkown
page read and write
clean
470000
unkown
page read and write
clean
90C000
stack
page read and write
clean
593E000
stack
page read and write
clean
90000
unkown
page read and write
clean
326000
unkown
page read and write
clean
570000
unkown
page execute and read and write
clean
5240000
stack
page read and write
clean
326000
unkown
page read and write
clean
440000
unkown
page read and write
clean
314000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
5320000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
2310000
stack
page read and write
clean
3E0000
unkown
page read and write
clean
4E80000
unkown
page read and write
clean
4EF5000
unkown
page read and write
clean
724000
heap default
page read and write
clean
6A4F000
unkown
page read and write
clean
43E000
unkown
page read and write
clean
872000
unkown
page read and write
clean
3C9000
unkown
page read and write
clean
430000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
25D1000
unkown
page read and write
clean
890000
unkown
page read and write
clean
4AEE000
stack
page read and write
clean
470000
unkown
page read and write
clean
314000
unkown
page read and write
clean
480000
unkown
page read and write
clean
4E8C000
unkown
page read and write
clean
640000
unkown
page read and write
clean
AD000
unkown
page execute and read and write
clean
430000
unkown
page read and write
clean
586E000
stack
page read and write
clean
500000
unkown
page execute and read and write
clean
890000
unkown
page read and write
clean
310000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
10A000
unkown
page read and write
clean
314000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7F0000
unkown
page read and write
clean
430000
unkown
page read and write
clean
430000
unkown
page read and write
clean
574E000
stack
page read and write
clean
7B9000
unkown
page read and write
clean
440000
unkown
page read and write
clean
430000
unkown
page read and write
clean
320000
unkown
page read and write
clean
320000
unkown
page read and write
clean
320000
unkown
page read and write
clean
320000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
336000
unkown
page read and write
clean
3C0000
unkown
page read and write
clean
874000
unkown
page read and write
clean
53D5000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
330000
unkown
page read and write
clean
3C9000
unkown
page read and write
clean
800000
unkown
page read and write
clean
22E0000
unkown
page read and write
clean
320000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
510000
unkown
page read and write
clean
3C9000
unkown
page read and write
clean
306000
unkown
page read and write
clean
460000
unkown
page read and write
clean
7C3000
unkown
page read and write
clean
43E000
unkown
page read and write
clean
2130000
unkown
page read and write
clean
430000
unkown
page read and write
clean
2340000
heap private
page execute and read and write
clean
300000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
330000
unkown
page read and write
clean
7C0000
unkown
page read and write
clean
330000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
2616000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
490000
unkown
page read and write
clean
600000
heap default
page read and write
clean
910000
unkown
page read and write
clean
330000
unkown
page read and write
clean
6EF000
stack
page read and write
clean
430000
unkown
page read and write
clean
480000
unkown
page read and write
clean
BD000
unkown
page execute and read and write
clean
3D0000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
640000
unkown
page read and write
clean
874000
unkown
page read and write
clean
800000
unkown
page execute and read and write
clean
430000
unkown
page read and write
clean
452000
unkown
page read and write
clean
300000
unkown
page read and write
clean
7E7000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
430000
unkown
page read and write
clean
7F0000
unkown
page read and write
clean
470000
unkown
page read and write
clean
2654000
unkown
page read and write
clean
707000
heap default
page read and write
clean
4F72000
unkown
page read and write
clean
2D0000
unkown
page execute and read and write
clean
2FB000
unkown
page read and write
clean
490000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
3C0000
unkown
page read and write
clean
870000
unkown
page read and write
clean
8C0000
unkown
page read and write
clean
430000
unkown
page read and write
clean
870000
unkown
page read and write
clean
3C9000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
870000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
430000
unkown
page read and write
clean
870000
unkown
page read and write
clean
7B9000
unkown
page read and write
clean
310000
unkown
page read and write
clean
340000
unkown image
page readonly
clean
4F72000
unkown
page read and write
clean
310000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
332000
unkown
page read and write
clean
970000
unkown image
page readonly
clean
316000
unkown
page read and write
clean
3C0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
320000
unkown
page read and write
clean
2020000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
212E000
stack
page read and write
clean
18B000
unkown
page execute and read and write
clean
330000
unkown
page read and write
clean
1FD0000
unkown
page read and write
clean
306000
unkown
page read and write
clean
316000
unkown
page read and write
clean
4B0000
heap private
page execute and read and write
clean
430000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
4E60000
heap private
page execute and read and write
clean
340000
unkown image
page readonly
clean
5A2000
heap private
page read and write
clean
23CE000
stack
page read and write | page guard
clean
8B0000
unkown image
page readonly
clean
2F5000
unkown
page read and write
clean
79D000
heap default
page read and write
clean
7A5000
unkown
page read and write
clean
85E000
stack
page read and write
clean
79E000
stack
page read and write
clean
450000
unkown
page read and write
clean
7F6000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
300000
unkown
page read and write
clean
5DAC000
unkown
page read and write
clean
337000
unkown
page read and write
clean
B60000
heap private
page execute and read and write
clean
310000
unkown
page read and write
clean
584000
heap private
page read and write
clean
46BF000
stack
page read and write
clean
7EFDF000
unkown
page read and write
clean
314000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
2D0000
unkown
page execute and read and write
clean
430000
unkown
page read and write
clean
2020000
unkown
page execute and read and write
clean
430000
unkown
page read and write
clean
2300000
stack
page read and write
clean
2F0000
unkown
page read and write
clean
2C7000
unkown
page read and write
clean
7F0000
unkown
page read and write
clean
336000
unkown
page read and write
clean
870000
unkown
page read and write
clean
330000
unkown
page read and write
clean
470000
unkown
page read and write
clean
7A5000
unkown
page read and write
clean
306000
unkown
page read and write
clean
4E0000
heap default
page read and write
clean
330000
unkown
page read and write
clean
310000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
470000
unkown
page read and write
clean
4F0000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
7B9000
unkown
page read and write
clean
430000
unkown
page read and write
clean
480000
unkown
page read and write
clean
3B8000
unkown image
page readonly
clean
3D0000
unkown
page read and write
clean
320000
unkown
page read and write
clean
64E000
heap default
page read and write
clean
54BE000
stack
page read and write
clean
870000
unkown
page read and write
clean
440000
unkown
page read and write
clean
316000
unkown
page read and write
clean
3C0000
unkown
page read and write
clean
330000
unkown
page read and write
clean
CA000
unkown
page execute and read and write
clean
490000
unkown
page read and write
clean
7A9000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
2F0000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
480000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
182000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
4F0000
unkown
page execute and read and write
clean
7A0000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
457D000
stack
page read and write
clean
810000
unkown
page read and write
clean
316000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
326000
unkown
page read and write
clean
490000
unkown
page read and write
clean
440000
unkown
page read and write
clean
6F0000
unkown
page read and write
clean
326000
unkown
page read and write
clean
69D000
stack
page read and write
clean
7F0000
unkown
page read and write
clean
490000
unkown
page read and write
clean
470000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
7F5000
unkown
page read and write
clean
7A5000
unkown
page read and write
clean
860000
unkown
page execute and read and write
clean
22F0000
unkown
page read and write
clean
44C000
unkown
page read and write
clean
890000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
672E000
stack
page read and write
clean
3C0000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
84E000
stack
page read and write
clean
7E7000
unkown
page read and write
clean
460000
unkown
page read and write
clean
8A2000
heap private
page read and write
clean
640000
unkown
page read and write
clean
BA0000
unkown image
page readonly
clean
330000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
5A8000
unkown
page read and write
clean
310000
unkown
page read and write
clean
890000
unkown
page read and write
clean
310000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
150000
unkown
page read and write
clean
1FD0000
unkown
page read and write
clean
3C0000
unkown
page read and write
clean
430000
unkown
page read and write
clean
580000
heap private
page read and write
clean
50CD000
stack
page read and write
clean
3C0000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
440000
unkown
page read and write
clean
460000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
320000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
326000
unkown
page read and write
clean
22C5000
unkown
page read and write
clean
4EC5000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
74A000
heap default
page read and write
clean
450000
unkown
page read and write
clean
7B9000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
430000
unkown
page read and write
clean
510000
unkown
page execute and read and write
clean
1FD0000
unkown
page read and write
clean
310000
unkown
page read and write
clean
440000
unkown
page read and write
clean
3C0000
unkown image
page readonly
clean
300000
unkown
page read and write
clean
3C9000
unkown
page read and write
clean
430000
unkown
page read and write
clean
42E0000
unkown image
page readonly
clean
326000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
AA000
unkown
page read and write
clean
43E000
unkown
page read and write
clean
5371000
unkown
page read and write
clean
7B9000
unkown
page read and write
clean
3D9000
unkown
page read and write
clean
261C000
unkown
page read and write
clean
3F0000
unkown image
page readonly
clean
50000
unkown image
page readonly
clean
44E000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
870000
unkown
page read and write
clean
800000
unkown
page read and write
clean
440000
unkown
page read and write
clean
7F0000
unkown
page read and write
clean
860000
unkown
page read and write
clean
314000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
800000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
460000
unkown
page read and write
clean
20000
heap private
page read and write
clean
300000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
6A0000
unkown
page execute and read and write
clean
62FE000
stack
page read and write
clean
3D0000
unkown
page read and write
clean
A3000
unkown
page execute and read and write
clean
7EFB0000
unkown image
page readonly
clean
314000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
460000
unkown
page read and write
clean
452D000
stack
page read and write
clean
7F0000
unkown
page read and write
clean
4F0000
unkown
page read and write
clean
326000
unkown
page read and write
clean
80B000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
870000
unkown
page read and write
clean
510000
unkown
page read and write
clean
187000
unkown
page execute and read and write
clean
450000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
182000
unkown
page read and write
clean
7F0000
unkown
page read and write
clean
480000
unkown
page read and write
clean
310000
unkown
page read and write
clean
4F72000
unkown
page read and write
clean
450000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
2190000
unkown image
page readonly
clean
3C9000
unkown
page read and write
clean
560000
unkown image
page read and write
clean
870000
unkown
page read and write
clean
450000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
309000
unkown
page read and write
clean
490000
unkown
page read and write
clean
7A5000
unkown
page read and write
clean
314000
unkown
page read and write
clean
3C9000
unkown
page read and write
clean
300000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
7A5000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
2E0000
unkown
page read and write
clean
430000
unkown
page read and write
clean
890000
unkown
page read and write
clean
C2000
unkown
page read and write
clean
324000
unkown
page read and write
clean
499B000
unkown
page read and write
clean
890000
unkown
page read and write
clean
3D9000
unkown
page read and write
clean
AF0000
unkown image
page readonly
clean
700000
heap default
page read and write
clean
25CF000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
8A0000
heap private
page read and write
clean
330000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
810000
unkown
page read and write
clean
4F2E000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
8A8000
heap private
page read and write
clean
440000
unkown
page read and write
clean
330000
unkown
page read and write
clean
6C8E000
stack
page read and write
clean
314000
unkown
page read and write
clean
480000
unkown
page read and write
clean
306000
unkown
page read and write
clean
3B8000
unkown image
page readonly
clean
4A0000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
640000
unkown
page read and write
clean
460000
unkown
page read and write
clean
460000
unkown
page read and write
clean
450000
unkown
page read and write
clean
7F0000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
324000
unkown
page read and write
clean
870000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
261E000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7A0000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
880000
heap private
page read and write
clean
7F0000
unkown
page read and write
clean
870000
unkown
page read and write
clean
480000
unkown
page read and write
clean
330000
unkown
page read and write
clean
920000
unkown
page read and write
clean
5321000
unkown
page read and write
clean
460000
unkown
page read and write
clean
310000
unkown
page read and write
clean
640000
heap default
page read and write
clean
7B9000
heap default
page read and write
clean
4B9E000
stack
page read and write
clean
2F5000
unkown
page read and write
clean
330000
unkown
page read and write
clean
3D9000
unkown
page read and write
clean
490000
unkown
page read and write
clean
22EC000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
20000
unkown
page read and write
clean
870000
unkown
page read and write
clean
480000
unkown
page read and write
clean
7A5000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
340000
unkown image
page readonly
clean
800000
unkown
page read and write
clean
320000
unkown
page read and write
clean
4EF3000
unkown
page read and write
clean
870000
unkown
page read and write
clean
4E9C000
unkown
page read and write
clean
320000
unkown
page read and write
clean
330000
unkown
page read and write
clean
480000
unkown
page read and write
clean
460000
unkown
page read and write
clean
170000
unkown
page read and write
clean
330000
unkown
page read and write
clean
430000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
3C0000
unkown
page read and write
clean
7EF30000
unkown
page execute and read and write
clean
3E0000
unkown
page read and write
clean
2643000
unkown
page read and write
clean
440000
unkown
page read and write
clean
803000
unkown
page read and write
clean
800000
unkown
page read and write
clean
884000
heap private
page read and write
clean
810000
unkown
page read and write
clean
3C9000
unkown
page read and write
clean
7A5000
unkown
page read and write
clean
440000
unkown
page read and write
clean
533E000
stack
page read and write
clean
7B1000
heap default
page read and write
clean
7F0000
unkown
page read and write
clean
860000
unkown
page read and write
clean
3C0000
unkown
page read and write
clean
320000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
400000
unkown
page execute and read and write
clean
2270000
unkown
page read and write
clean
3C0000
unkown
page read and write
clean
4F80000
heap private
page execute and read and write
clean
2F0000
unkown
page read and write
clean
470000
unkown
page read and write
clean
1FD0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2150000
heap private
page read and write
clean
3C0000
unkown
page read and write
clean
5520000
unkown
page read and write
clean
930000
unkown
page read and write
clean
450000
unkown
page read and write
clean
436000
unkown
page read and write
clean
490000
unkown
page read and write
clean
430000
unkown
page read and write
clean
740000
heap default
page read and write
clean
484C000
stack
page read and write
clean
3C0000
unkown
page read and write
clean
870000
unkown
page read and write
clean
342000
unkown image
page execute read
clean
34E1000
unkown
page read and write
clean
330000
unkown
page read and write
clean
870000
unkown
page read and write
clean
480000
unkown
page read and write
clean
2020000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
187000
unkown
page execute and read and write
clean
870000
unkown
page read and write
clean
340000
unkown image
page readonly
clean
25D4000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
440000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
870000
unkown
page read and write
clean
44D000
unkown
page read and write
clean
850000
unkown
page read and write
clean
305000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7F5000
unkown
page read and write
clean
440000
unkown
page read and write
clean
2140000
unkown
page read and write
clean
860000
unkown
page read and write
clean
880000
heap private
page read and write
clean
4EF3000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
3B8000
unkown image
page readonly
clean
300000
unkown
page read and write
clean
870000
unkown
page read and write
clean
306000
unkown
page read and write
clean
490000
unkown
page read and write
clean
470000
unkown
page read and write
clean
430000
unkown
page read and write
clean
4EC4000
unkown
page read and write
clean
310000
unkown
page read and write
clean
330000
unkown
page read and write
clean
430000
unkown
page read and write
clean
450000
unkown
page read and write
clean
43E000
unkown
page read and write
clean
430000
unkown
page read and write
clean
430000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
5460000
stack
page read and write
clean
310000
unkown
page execute and read and write
clean
3D9000
unkown
page read and write
clean
336000
unkown
page read and write
clean
342000
unkown image
page execute read
clean
7A0000
unkown
page read and write
clean
800000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
6C4000
heap default
page read and write
clean
310000
unkown
page read and write
clean
960000
heap private
page read and write
clean
7A0000
unkown
page read and write
clean
870000
unkown
page read and write
clean
450000
unkown
page read and write
clean
17D000
unkown
page execute and read and write
clean
324000
unkown
page read and write
clean
74D000
heap default
page read and write
clean
22D0000
unkown
page read and write
clean
330000
unkown
page read and write
clean
22D0000
unkown
page read and write
clean
22C0000
unkown
page read and write
clean
430000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
4A5000
unkown
page read and write
clean
320000
unkown
page read and write
clean
300000
unkown
page read and write
clean
440000
unkown
page read and write
clean
A40000
unkown image
page readonly
clean
800000
unkown
page read and write
clean
430000
unkown
page read and write
clean
430000
unkown
page read and write
clean
480000
unkown
page read and write
clean
73D000
stack
page read and write
clean
7A5000
unkown
page read and write
clean
300000
heap private
page execute and read and write
clean
5502000
heap private
page read and write
clean
3D0000
unkown
page read and write
clean
870000
unkown
page read and write
clean
6F3000
heap default
page read and write
clean
4EF3000
unkown
page read and write
clean
800000
unkown
page read and write
clean
430000
unkown
page read and write
clean
6B5F000
stack
page read and write
clean
2F0000
unkown
page read and write
clean
32E1000
unkown
page read and write
clean
BD0000
unkown image
page readonly
clean
7A2000
unkown
page read and write
clean
306000
unkown
page read and write
clean
3C0000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
450000
unkown
page read and write
clean
A30000
unkown image
page readonly
clean
450000
unkown
page read and write
clean
44BE000
stack
page read and write
clean
5280000
stack
page read and write
clean
480000
unkown
page read and write
clean
4DDE000
stack
page read and write
clean
490000
unkown
page read and write
clean
7B9000
unkown
page read and write
clean
3C0000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
440000
unkown
page read and write
clean
43E000
unkown
page read and write
clean
450000
unkown
page read and write
clean
810000
unkown
page read and write
clean
470000
unkown
page read and write
clean
43E000
unkown
page read and write
clean
300000
unkown
page read and write
clean
25C7000
unkown
page read and write
clean
43E000
unkown
page read and write
clean
320000
unkown
page read and write
clean
4E83000
unkown
page read and write
clean
164000
unkown
page read and write
clean
430000
unkown
page read and write
clean
3D8000
unkown
page read and write
clean
640000
unkown
page read and write
clean
4C7E000
stack
page read and write
clean
430000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
42E000
stack
page read and write
clean
430000
unkown
page read and write
clean
490000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
531E000
stack
page read and write
clean
430000
unkown
page read and write
clean
19B000
unkown
page execute and read and write
clean
430000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
470000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
3C0000
unkown
page read and write
clean
450000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
607000
heap default
page read and write
clean
24DF000
stack
page read and write
clean
3D0000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
6F0000
unkown
page execute and read and write
clean
3E0000
unkown
page read and write
clean
43E000
unkown
page read and write
clean
2020000
unkown
page read and write
clean
800000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
54E0000
heap private
page read and write
clean
2614000
unkown
page read and write
clean
490000
unkown
page read and write
clean
2021000
unkown
page read and write
clean
2F8000
unkown
page read and write
clean
2650000
unkown
page read and write
clean
2130000
unkown image
page readonly
clean
470000
unkown
page read and write
clean
460000
unkown
page read and write
clean
460000
unkown
page read and write
clean
3D9000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
480000
unkown
page read and write
clean
500000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
C0000
unkown
page read and write
clean
33B000
unkown
page read and write
clean
3C0000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
490000
unkown
page read and write
clean
51F0000
stack
page read and write
clean
330000
unkown
page read and write
clean
430000
unkown
page read and write
clean
640000
unkown
page read and write
clean
4E81000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
5372000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
310000
unkown
page read and write
clean
470000
unkown
page read and write
clean
440000
unkown
page read and write
clean
430000
unkown
page read and write
clean
440000
unkown
page read and write
clean
450000
unkown
page read and write
clean
307000
unkown
page read and write
clean
870000
unkown
page read and write
clean
49FB000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
2E0000
unkown
page read and write
clean
310000
unkown
page read and write
clean
326000
unkown
page read and write
clean
324000
unkown
page read and write
clean
2633000
unkown
page read and write
clean
336000
unkown
page read and write
clean
430000
unkown
page read and write
clean
C6000
unkown
page execute and read and write
clean
2620000
unkown
page read and write
clean
870000
unkown
page read and write
clean
490000
unkown
page read and write
clean
5FE000
stack
page read and write
clean
6FF000
heap default
page read and write
clean
4E9B000
unkown
page read and write
clean
7F0000
unkown
page read and write
clean
450000
unkown
page read and write
clean
310000
unkown
page read and write
clean
460000
unkown
page read and write
clean
7C2000
unkown
page read and write
clean
330000
unkown
page read and write
clean
1FD0000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
800000
unkown image
page readonly
clean
300000
unkown
page read and write
clean
5A5D000
stack
page read and write
clean
49BF000
stack
page read and write
clean
3D0000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
5BA0000
stack
page read and write
clean
3C0000
unkown
page read and write
clean
5DB0000
unkown image
page readonly
clean
7A2000
unkown
page read and write
clean
3C9000
unkown
page read and write
clean
870000
unkown
page read and write
clean
314000
unkown
page read and write
clean
490000
unkown
page read and write
clean
1FD0000
unkown
page read and write
clean
7A5000
unkown
page read and write
clean
53D5000
unkown
page read and write
clean
480000
unkown
page read and write
clean
320000
unkown
page read and write
clean
22BE000
stack
page read and write
clean
450000
unkown
page read and write
clean
803000
unkown
page read and write
clean
2C7000
unkown
page read and write
clean
800000
unkown
page read and write
clean
5A60000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
480000
unkown
page read and write
clean
470000
unkown
page read and write
clean
3B8000
unkown image
page readonly
clean
2F5000
unkown
page read and write
clean
229E000
stack
page read and write | page guard
clean
640000
unkown
page read and write
clean
2270000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
480000
unkown
page read and write
clean
There are 894 hidden memdumps, click here to show them.