IOC Report
V3g2Pfu707.docx

loading gif

Files

File Path
Type
Category
Malicious
V3g2Pfu707.docx
Microsoft OOXML
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\exploit[1].htm
HTML document, ASCII text, with very long lines, with CRLF line terminators
downloaded
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\42A30EFB.htm
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\6B087DC1.htm
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\FSD-CNRY.FSD
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\FSD-{95873921-7BBD-4EBD-8008-620874EEAE52}.FSD
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\FSF-CTBL.FSF
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSD-CNRY.FSD
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSD-{55CA3E23-CD6A-4540-AFBA-3E4A75CEA258}.FSD
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSF-{0E1EEE64-E8C6-4E2A-9759-63CF07FD8988}.FSF
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\83357E0C.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 581x1278, frames 3
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\8F1DC677.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 220x220, segment length 16, baseline, precision 8, 1268x951, frames 3
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{6245E340-9A7D-4D8C-95F3-E607A94CA060}.tmp
Composite Document File V2 Document, Cannot read section info
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{6A4592DE-D21D-4642-AE77-FFCC3AAD3185}.tmp
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{F19FE166-8B13-4DD0-BB8B-900FB9050402}.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\mso563B.tmp
GIF image data, version 89a, 15 x 15
dropped
C:\Users\user\AppData\Local\Temp\{918117C9-F5EE-4EA7-AC8B-621A6E7B7534}
data
dropped
C:\Users\user\AppData\Local\Temp\{C46AD554-98E1-4325-9E00-58DC273C73AD}
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\V3g2Pfu707.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Tue Mar 8 15:45:51 2022, mtime=Tue Mar 8 15:45:51 2022, atime=Thu Jun 16 20:14:10 2022, length=520148, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
dropped
C:\Users\user\Desktop\~$g2Pfu707.docx
data
dropped
There are 12 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /Automation -Embedding

IPs

IP
Domain
Country
Malicious
101.33.231.81
unknown
China
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
z)1
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
1*1
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
`-1
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache
Version
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache\http://101.33.231.81:62563/
EnableBHO
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Arial
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Courier New
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Symbol
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Wingdings
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Batang
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
SimSun
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
PMingLiU
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Dotum
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
SimHei
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gulim
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Century
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Angsana New
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Cordia New
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Mangal
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Latha
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Sylfaen
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Vrinda
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Raavi
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Shruti
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gautami
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Tunga
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Estrangelo Edessa
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Cambria Math
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Tahoma
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Marlett
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@Batang
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
DaunPenh
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
DokChampa
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Euphemia
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Vani
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@Gulim
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@Dotum
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Impact
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Iskoola Pota
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Kalinga
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Kartika
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Khmer UI
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Lao UI
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Lucida Console
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Microsoft Himalaya
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@PMingLiU
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
PMingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@PMingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Mongolian Baiti
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MV Boli
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Microsoft New Tai Lue
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Nyala
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Microsoft PhagsPa
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Plantagenet Cherokee
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Segoe Script
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Segoe UI
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Segoe UI Semibold
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Segoe UI Light
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Segoe UI Symbol
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@SimSun
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
NSimSun
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@NSimSun
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
SimSun-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@SimSun-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Microsoft Tai Le
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Shonar Bangla
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Microsoft Yi Baiti
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Microsoft Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Aparajita
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Ebrima
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gisha
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Kokila
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Leelawadee
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Microsoft Uighur
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MoolBoran
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Utsaah
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Vijaya
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Andalus
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Arabic Typesetting
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Simplified Arabic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Simplified Arabic Fixed
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Sakkal Majalla
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Traditional Arabic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Aharoni
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
David
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
FrankRuehl
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Levenim MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Miriam
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Miriam Fixed
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Narkisim
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Rod
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
FangSong
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@FangSong
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@SimHei
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
AngsanaUPC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Browallia New
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
BrowalliaUPC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
CordiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
DilleniaUPC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
EucrosiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
FreesiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
IrisUPC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
JasmineUPC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
KodchiangUPC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
LilyUPC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Lucida Sans Unicode
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Arial Black
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Candara
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Comic Sans MS
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Consolas
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Constantia
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Corbel
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Franklin Gothic Medium
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Georgia
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Palatino Linotype
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Segoe Print
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Trebuchet MS
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Verdana
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Webdings
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Calibri Light
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Wingdings 2
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Wingdings 3
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Book Antiqua
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Century Gothic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Arial Narrow
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Garamond
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Monotype Corsiva
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Algerian
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Baskerville Old Face
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Bauhaus 93
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Bell MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Berlin Sans FB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Bernard MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Bodoni MT Poster Compressed
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Britannic Bold
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Broadway
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Brush Script MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Californian FB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Centaur
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Chiller
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Colonna MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Cooper Black
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Footlight MT Light
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Freestyle Script
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Harlow Solid Italic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Harrington
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
High Tower Text
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Jokerman
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Juice ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Kristen ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Kunstler Script
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Lucida Bright
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Lucida Calligraphy
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Lucida Fax
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Lucida Handwriting
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Magneto
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Matura MT Script Capitals
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Mistral
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Modern No. 20
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Niagara Engraved
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Niagara Solid
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Old English Text MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Onyx
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Parchment
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Playbill
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Poor Richard
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Ravie
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Informal Roman
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Showcard Gothic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Snap ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Stencil
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Tempus Sans ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Viner Hand ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Vivaldi
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Vladimir Script
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Wide Latin
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Pristina
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Papyrus
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
French Script MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Bradley Hand ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Bookman Old Style
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Berlin Sans FB Demi
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MT Extra
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MS Outlook
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Bookshelf Symbol 7
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MS Reference Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MS Reference Specialty
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Haettenschweiler
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Tw Cen MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Tw Cen MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Script MT Bold
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Rockwell Extra Bold
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Rockwell Condensed
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Rockwell
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Rage Italic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Perpetua Titling MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Perpetua
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Palace Script MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
OCR A Extended
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Maiandra GD
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Lucida Sans Typewriter
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Lucida Sans
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Imprint MT Shadow
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Goudy Stout
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Goudy Old Style
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gloucester MT Extra Condensed
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gill Sans Ultra Bold Condensed
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gill Sans Ultra Bold
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gill Sans MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gill Sans MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gill Sans MT Ext Condensed Bold
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gigi
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Franklin Gothic Medium Cond
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Franklin Gothic Heavy
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Franklin Gothic Demi Cond
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Franklin Gothic Demi
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Franklin Gothic Book
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Forte
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Felix Titling
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Eras Medium ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Eras Light ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Eras Demi ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Eras Bold ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Engravers MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Elephant
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Edwardian Script ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Curlz MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Copperplate Gothic Light
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Copperplate Gothic Bold
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Century Schoolbook
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Castellar
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Calisto MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Bodoni MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Bodoni MT Black
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Bodoni MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Blackadder ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Arial Rounded MT Bold
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Agency FB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gabriola
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Tw Cen MT Condensed Extra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\69CEB
69CEB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Batang
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Dotum
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@FangSong
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gulim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@NSimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Agency FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aharoni
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Algerian
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Andalus
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Angsana New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
AngsanaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aparajita
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arabic Typesetting
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Narrow
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Rounded MT Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Baskerville Old Face
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Batang
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bauhaus 93
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bell MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB Demi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bernard MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Blackadder ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Poster Compressed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Book Antiqua
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookman Old Style
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookshelf Symbol 7
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bradley Hand ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Britannic Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Broadway
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Browallia New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BrowalliaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Brush Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Californian FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calisto MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria Math
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Candara
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Castellar
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Centaur
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Schoolbook
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Chiller
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Colonna MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Comic Sans MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Consolas
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Constantia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cooper Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Corbel
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cordia New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
CordiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Courier New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Curlz MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DaunPenh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
David
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DilleniaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DokChampa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Dotum
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ebrima
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Edwardian Script ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Elephant
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Engravers MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Bold ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Demi ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Light ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Medium ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Estrangelo Edessa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
EucrosiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Euphemia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FangSong
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Felix Titling
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Footlight MT Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Forte
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Book
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi Cond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Heavy
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium Cond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FrankRuehl
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FreesiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Freestyle Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
French Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gabriola
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Garamond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gautami
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Georgia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gigi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Ext Condensed Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gisha
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gloucester MT Extra Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Old Style
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Stout
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gulim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Haettenschweiler
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harlow Solid Italic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harrington
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
High Tower Text
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Impact
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Imprint MT Shadow
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Informal Roman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
IrisUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Iskoola Pota
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
JasmineUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Jokerman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Juice ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kalinga
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kartika
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Khmer UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KodchiangUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kokila
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kristen ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kunstler Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lao UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Latha
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Leelawadee
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Levenim MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
LilyUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Bright
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Calligraphy
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Console
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Fax
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Handwriting
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Typewriter
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Unicode
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Magneto
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Maiandra GD
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mangal
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Marlett
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Matura MT Script Capitals
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Himalaya
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft New Tai Lue
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft PhagsPa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Tai Le
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Uighur
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Yi Baiti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam Fixed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mistral
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Modern No. 20
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mongolian Baiti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Monotype Corsiva
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MoolBoran
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Outlook
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Specialty
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MT Extra
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\71FDF
71FDF
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
WORDFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\71FDF
71FDF
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Data
Settings
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Options
ZoomApp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTF
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTA
There are 520 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
29D0000
heap
page read and write
490000
heap
page read and write
2315000
heap
page read and write
FB000
stack
page read and write
2310000
heap
page read and write
224F000
stack
page read and write
2B0E000
stack
page read and write
1AE000
heap
page read and write
1CD000
heap
page read and write
27EB000
stack
page read and write
16E000
heap
page read and write
2D8000
heap
page read and write
2A0000
heap
page read and write
130000
heap
page read and write
208E000
stack
page read and write
1D5000
heap
page read and write
28CC000
stack
page read and write
2D6000
heap
page read and write
2D3F000
stack
page read and write
2FD000
heap
page read and write
195000
heap
page read and write
2F8000
heap
page read and write
29CE000
stack
page read and write
49E000
heap
page read and write
234B000
heap
page read and write
1FF0000
heap
page read and write
2E8000
heap
page read and write
10000
heap
page read and write
137000
heap
page read and write
1A0000
heap
page read and write
2150000
heap
page read and write
2B50000
heap
page read and write
494000
heap
page read and write
1BD000
heap
page read and write
20D0000
heap
page read and write
There are 25 hidden memdumps, click here to show them.