IOC Report
0mvOExDB0u

loading gif

Files

File Path
Type
Category
Malicious
0mvOExDB0u.docx
Microsoft OOXML
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\dkm[1].htm
HTML document, ASCII text, with very long lines
downloaded
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\71E1C088.htm
HTML document, ASCII text, with very long lines
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\BA0768EA.htm
HTML document, ASCII text, with very long lines
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\FSD-CNRY.FSD
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\FSD-{CC68C536-9CD4-4A67-8EC7-4282F7DE8CCB}.FSD
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\FSF-CTBL.FSF
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSD-CNRY.FSD
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSD-{1B2D91C0-F32B-418D-958E-39DD37B1A090}.FSD
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSF-{0E1EEE64-E8C6-4E2A-9759-63CF07FD8988}.FSF
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{54C3BB41-4824-4D76-9814-5AB27D135E39}.tmp
Composite Document File V2 Document, Cannot read section info
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{99A334A3-9CCE-497E-9069-C0103D350D75}.tmp
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{F116EB59-8281-4971-8EDA-A57BD55E7891}.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\{6985C587-9066-4354-83B5-3F5856D587EC}
data
dropped
C:\Users\user\AppData\Local\Temp\{F4295DCF-A5E4-4365-A8E0-DC8DE21141CB}
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\0mvOExDB0u.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Aug 18 16:23:00 2022, mtime=Thu Aug 18 16:23:00 2022, atime=Thu Aug 18 16:23:11 2022, length=13980, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\UProof\ExcludeDictionaryEN0409.lex
Little-endian UTF-16 Unicode text, with no line terminators
dropped
C:\Users\user\Desktop\~$vOExDB0u.docx
data
dropped
There are 10 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /Automation -Embedding

URLs

Name
IP
Malicious
https://zaloapp.duckdns.org/dkm.htmlyX
unknown
malicious
https://zaloapp.duckdns.org/dkm.html
34.126.146.169

Domains

Name
IP
Malicious
zaloapp.duckdns.org
34.126.146.169

IPs

IP
Domain
Country
Malicious
34.126.146.169
zaloapp.duckdns.org
United States

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
ut0
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
mu0
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
+x0
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache
Version
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache
Count
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache\https://zaloapp.duckdns.org/
Type
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache\https://zaloapp.duckdns.org/
Protocol
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache\https://zaloapp.duckdns.org/
Version
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache\https://zaloapp.duckdns.org/
Flags
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache\https://zaloapp.duckdns.org/
CobaltMajorVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache\https://zaloapp.duckdns.org/
CobaltMinorVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache\https://zaloapp.duckdns.org/
MsDavExt
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache\https://zaloapp.duckdns.org/
Expiration
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache\https://zaloapp.duckdns.org/
EnableBHO
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Arial
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Courier New
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Symbol
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Wingdings
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Batang
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
SimSun
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
PMingLiU
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Dotum
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
SimHei
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gulim
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Century
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Angsana New
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Cordia New
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Mangal
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Latha
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Sylfaen
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Vrinda
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Raavi
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Shruti
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gautami
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Tunga
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Estrangelo Edessa
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Cambria Math
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Tahoma
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Marlett
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@Batang
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
DaunPenh
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
DokChampa
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Euphemia
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Vani
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@Gulim
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@Dotum
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Impact
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Iskoola Pota
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Kalinga
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Kartika
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Khmer UI
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Lao UI
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Lucida Console
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Microsoft Himalaya
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@PMingLiU
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
PMingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@PMingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Mongolian Baiti
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MV Boli
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Microsoft New Tai Lue
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Nyala
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Microsoft PhagsPa
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Plantagenet Cherokee
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Segoe Script
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Segoe UI
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Segoe UI Semibold
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Segoe UI Light
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Segoe UI Symbol
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@SimSun
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
NSimSun
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@NSimSun
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
SimSun-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@SimSun-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Microsoft Tai Le
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Shonar Bangla
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Microsoft Yi Baiti
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Microsoft Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Aparajita
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Ebrima
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gisha
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Kokila
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Leelawadee
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Microsoft Uighur
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MoolBoran
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Utsaah
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Vijaya
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Andalus
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Arabic Typesetting
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Simplified Arabic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Simplified Arabic Fixed
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Sakkal Majalla
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Traditional Arabic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Aharoni
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
David
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
FrankRuehl
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Levenim MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Miriam
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Miriam Fixed
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Narkisim
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Rod
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
FangSong
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@FangSong
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@SimHei
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
AngsanaUPC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Browallia New
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
BrowalliaUPC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
CordiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
DilleniaUPC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
EucrosiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
FreesiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
IrisUPC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
JasmineUPC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
KodchiangUPC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
LilyUPC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Lucida Sans Unicode
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Arial Black
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Candara
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Comic Sans MS
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Consolas
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Constantia
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Corbel
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Franklin Gothic Medium
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Georgia
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Palatino Linotype
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Segoe Print
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Trebuchet MS
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Verdana
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Webdings
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Calibri Light
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
@Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Wingdings 2
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Wingdings 3
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Book Antiqua
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Century Gothic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Arial Narrow
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Garamond
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Monotype Corsiva
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Algerian
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Baskerville Old Face
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Bauhaus 93
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Bell MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Berlin Sans FB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Bernard MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Bodoni MT Poster Compressed
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Britannic Bold
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Broadway
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Brush Script MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Californian FB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Centaur
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Chiller
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Colonna MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Cooper Black
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Footlight MT Light
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Freestyle Script
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Harlow Solid Italic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Harrington
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
High Tower Text
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Jokerman
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Juice ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Kristen ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Kunstler Script
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Lucida Bright
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Lucida Calligraphy
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Lucida Fax
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Lucida Handwriting
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Magneto
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Matura MT Script Capitals
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Mistral
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Modern No. 20
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Niagara Engraved
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Niagara Solid
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Old English Text MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Onyx
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Parchment
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Playbill
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Poor Richard
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Ravie
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Informal Roman
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Showcard Gothic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Snap ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Stencil
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Tempus Sans ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Viner Hand ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Vivaldi
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Vladimir Script
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Wide Latin
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Pristina
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Papyrus
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
French Script MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Bradley Hand ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Bookman Old Style
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Berlin Sans FB Demi
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MT Extra
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MS Outlook
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Bookshelf Symbol 7
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MS Reference Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
MS Reference Specialty
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Haettenschweiler
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Tw Cen MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Tw Cen MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Script MT Bold
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Rockwell Extra Bold
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Rockwell Condensed
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Rockwell
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Rage Italic
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Perpetua Titling MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Perpetua
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Palace Script MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
OCR A Extended
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Maiandra GD
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Lucida Sans Typewriter
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Lucida Sans
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Imprint MT Shadow
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Goudy Stout
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Goudy Old Style
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gloucester MT Extra Condensed
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gill Sans Ultra Bold Condensed
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gill Sans Ultra Bold
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gill Sans MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gill Sans MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gill Sans MT Ext Condensed Bold
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gigi
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Franklin Gothic Medium Cond
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Franklin Gothic Heavy
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Franklin Gothic Demi Cond
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Franklin Gothic Demi
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Franklin Gothic Book
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Forte
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Felix Titling
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Eras Medium ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Eras Light ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Eras Demi ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Eras Bold ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Engravers MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Elephant
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Edwardian Script ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Curlz MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Copperplate Gothic Light
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Copperplate Gothic Bold
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Century Schoolbook
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Castellar
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Calisto MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Bodoni MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Bodoni MT Black
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Bodoni MT
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Blackadder ITC
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Arial Rounded MT Bold
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Agency FB
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Gabriola
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Panose
Tw Cen MT Condensed Extra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\70473
70473
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Batang
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Dotum
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@FangSong
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gulim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@NSimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Agency FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aharoni
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Algerian
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Andalus
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Angsana New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
AngsanaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aparajita
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arabic Typesetting
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Narrow
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Rounded MT Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Baskerville Old Face
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Batang
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bauhaus 93
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bell MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB Demi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bernard MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Blackadder ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Poster Compressed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Book Antiqua
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookman Old Style
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookshelf Symbol 7
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bradley Hand ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Britannic Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Broadway
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Browallia New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BrowalliaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Brush Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Californian FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calisto MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria Math
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Candara
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Castellar
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Centaur
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Schoolbook
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Chiller
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Colonna MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Comic Sans MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Consolas
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Constantia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cooper Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Corbel
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cordia New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
CordiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Courier New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Curlz MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DaunPenh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
David
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DilleniaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DokChampa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Dotum
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ebrima
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Edwardian Script ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Elephant
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Engravers MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Bold ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Demi ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Light ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Medium ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Estrangelo Edessa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
EucrosiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Euphemia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FangSong
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Felix Titling
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Footlight MT Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Forte
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Book
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi Cond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Heavy
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium Cond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FrankRuehl
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FreesiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Freestyle Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
French Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gabriola
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Garamond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gautami
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Georgia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gigi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Ext Condensed Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gisha
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gloucester MT Extra Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Old Style
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Stout
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gulim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Haettenschweiler
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harlow Solid Italic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harrington
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
High Tower Text
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Impact
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Imprint MT Shadow
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Informal Roman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
IrisUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Iskoola Pota
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
JasmineUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Jokerman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Juice ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kalinga
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kartika
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Khmer UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KodchiangUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kokila
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kristen ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kunstler Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lao UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Latha
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Leelawadee
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Levenim MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
LilyUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Bright
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Calligraphy
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Console
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Fax
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Handwriting
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Typewriter
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Unicode
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Magneto
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Maiandra GD
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mangal
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Marlett
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Matura MT Script Capitals
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Himalaya
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft New Tai Lue
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft PhagsPa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Tai Le
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Uighur
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Yi Baiti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam Fixed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mistral
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Modern No. 20
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mongolian Baiti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Monotype Corsiva
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MoolBoran
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\77CBE
77CBE
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
WORDFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\77CBE
77CBE
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Data
Settings
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Options
ZoomApp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTF
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTA
There are 531 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
584000
heap
page read and write
2D7000
heap
page read and write
30F000
heap
page read and write
1EE5000
heap
page read and write
1EE0000
heap
page read and write
170000
heap
page read and write
418000
heap
page read and write
346000
heap
page read and write
100000
heap
page read and write
10000
heap
page read and write
398000
heap
page read and write
1B8000
heap
page read and write
1BC000
heap
page read and write
408000
heap
page read and write
1CD000
heap
page read and write
2810000
heap
page read and write
1CB000
stack
page read and write
2120000
heap
page read and write
17D000
heap
page read and write
30E000
heap
page read and write
2BE0000
heap
page read and write
10E000
heap
page read and write
2B7E000
stack
page read and write
390000
heap
page read and write
3E8000
heap
page read and write
510000
heap
page read and write
2750000
heap
page read and write
2A1B000
stack
page read and write
2B1E000
stack
page read and write
164000
heap
page read and write
AB000
stack
page read and write
A0000
heap
page read and write
1A6000
heap
page read and write
297000
heap
page read and write
33E000
heap
page read and write
1DB000
heap
page read and write
1FDB000
heap
page read and write
284000
heap
page read and write
288B000
stack
page read and write
232C000
stack
page read and write
2BC0000
heap
page read and write
A7000
heap
page read and write
2D0000
heap
page read and write
514000
heap
page read and write
10000
heap
page read and write
2040000
heap
page read and write
295F000
stack
page read and write
10000
heap
page read and write
2CE000
heap
page read and write
276C000
stack
page read and write
376000
heap
page read and write
2BAE000
stack
page read and write
332000
heap
page read and write
371000
heap
page read and write
2D4F000
stack
page read and write
39D000
heap
page read and write
235F000
stack
page read and write
406000
heap
page read and write
215B000
heap
page read and write
2D0F000
stack
page read and write
13E000
heap
page read and write
192000
heap
page read and write
2125000
heap
page read and write
218F000
stack
page read and write
1F1B000
heap
page read and write
2760000
heap
page read and write
16B000
heap
page read and write
33F000
heap
page read and write
2DFF000
stack
page read and write
3C6000
heap
page read and write
220F000
stack
page read and write
39D000
heap
page read and write
2260000
heap
page read and write
428000
heap
page read and write
28E000
heap
page read and write
2B10000
heap
page read and write
390000
heap
page read and write
3D8000
heap
page read and write
28D0000
heap
page read and write
2F6000
heap
page read and write
2A0000
heap
page read and write
10000
heap
page read and write
29FC000
stack
page read and write
35B000
heap
page read and write
153000
heap
page read and write
22C0000
heap
page read and write
246F000
stack
page read and write
2810000
heap
page read and write
2A50000
heap
page read and write
242F000
stack
page read and write
2B50000
heap
page read and write
207B000
heap
page read and write
1FA0000
heap
page read and write
2F6000
heap
page read and write
51E000
heap
page read and write
2A20000
heap
page read and write
3ED000
heap
page read and write
336000
heap
page read and write
22DD000
stack
page read and write
2A6B000
stack
page read and write
1C8000
heap
page read and write
344000
heap
page read and write
2FD000
heap
page read and write
2C5E000
stack
page read and write
2AFF000
stack
page read and write
31F000
heap
page read and write
2A9F000
stack
page read and write
130000
heap
page read and write
298C000
stack
page read and write
23CC000
stack
page read and write
2DBF000
stack
page read and write
28B000
stack
page read and write
FB000
stack
page read and write
14B000
heap
page read and write
2130000
heap
page read and write
2E90000
heap
page read and write
340000
heap
page read and write
218B000
stack
page read and write
334000
heap
page read and write
31D000
heap
page read and write
290000
heap
page read and write
DE000
heap
page read and write
280000
heap
page read and write
14F000
heap
page read and write
228E000
stack
page read and write
135000
heap
page read and write
166000
heap
page read and write
2CE000
heap
page read and write
388000
heap
page read and write
1FA5000
heap
page read and write
2E10000
heap
page read and write
221B000
stack
page read and write
287B000
stack
page read and write
58E000
heap
page read and write
2080000
heap
page read and write
188000
heap
page read and write
2C0F000
stack
page read and write
280E000
stack
page read and write
29EE000
stack
page read and write
107000
heap
page read and write
33E000
heap
page read and write
33D000
heap
page read and write
370000
heap
page read and write
42D000
heap
page read and write
2A0000
heap
page read and write
1A8000
heap
page read and write
2780000
heap
page read and write
334000
heap
page read and write
378000
heap
page read and write
4F0000
heap
page read and write
580000
heap
page read and write
21A0000
heap
page read and write
290000
heap
page read and write
30FF000
stack
page read and write
388000
heap
page read and write
300000
heap
page read and write
16E000
heap
page read and write
2EAF000
stack
page read and write
378000
heap
page read and write
308000
heap
page read and write
26FC000
stack
page read and write
181000
heap
page read and write
376000
heap
page read and write
237C000
stack
page read and write
10000
heap
page read and write
22B000
stack
page read and write
330000
heap
page read and write
239F000
stack
page read and write
291B000
stack
page read and write
340000
heap
page read and write
2C30000
heap
page read and write
229D000
stack
page read and write
2AF0000
heap
page read and write
234F000
stack
page read and write
220D000
stack
page read and write
3C8000
heap
page read and write
3D0000
heap
page read and write
2045000
heap
page read and write
2D9F000
stack
page read and write
2C1E000
stack
page read and write
2FDF000
stack
page read and write
2880000
heap
page read and write
2E2F000
stack
page read and write
241E000
stack
page read and write
398000
heap
page read and write
273B000
stack
page read and write
330000
heap
page read and write
355000
heap
page read and write
302000
heap
page read and write
297000
heap
page read and write
32E000
heap
page read and write
106000
heap
page read and write
There are 182 hidden memdumps, click here to show them.