IOC Report
Quote No 2118013.doc

loading gif

Files

File Path
Type
Category
Malicious
Quote No 2118013.doc
Rich Text Format data, version 1
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\stanmac2.1[1].exe
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
dropped
malicious
C:\Users\user\AppData\Local\Temp\rnixgfly.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\run.dat
data
dropped
malicious
C:\Users\user\AppData\Roaming\ilkqegcy\jfcarlsrvb.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Roaming\word.exe
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{0A4B3911-FEFD-4AA5-A41A-6550C2F96D9E}.tmp
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{D6D5F209-138C-443D-8A21-E23B722EB3AB}.tmp
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{E00A286F-D9E2-457B-B119-BAD556F2C91B}.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\nsl3E1A.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\somvwkehjlp.rt
data
dropped
C:\Users\user\AppData\Local\Temp\vvnwaf.f
data
dropped
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\catalog.dat
data
dropped
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\settings.bin
data
dropped
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\storage.dat
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Quote No 2118013.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Tue Mar 8 15:45:59 2022, mtime=Tue Mar 8 15:45:59 2022, atime=Thu Feb 2 05:33:18 2023, length=715212, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
Generic INItialization configuration [doc]
dropped
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
dropped
C:\Users\user\Desktop\~$ote No 2118013.doc
data
dropped
There are 9 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
"C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
malicious
C:\Users\user\AppData\Roaming\word.exe
C:\Users\user\AppData\Roaming\word.exe
malicious
C:\Users\user\AppData\Local\Temp\rnixgfly.exe
"C:\Users\user\AppData\Local\Temp\rnixgfly.exe" C:\Users\user\AppData\Local\Temp\somvwkehjlp.rt
malicious
C:\Users\user\AppData\Local\Temp\rnixgfly.exe
C:\Users\user\AppData\Local\Temp\rnixgfly.exe
malicious
C:\Users\user\AppData\Roaming\ilkqegcy\jfcarlsrvb.exe
"C:\Users\user\AppData\Roaming\ilkqegcy\jfcarlsrvb.exe" "C:\Users\user\AppData\Local\Temp\rnixgfly.exe" C:\Users\user\AppData\Lo
malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
"C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /Automation -Embedding

URLs

Name
IP
Malicious
http://ask6.awt.com.pk/wordpress//wp-content/stanmac2.1.exeC
unknown
malicious
http://ask6.awt.com.pk/wordpress//wp-content/stanmac2.1.exeS
unknown
malicious
http://ask6.awt.com.pk/wordpress//wp-content/stanmac2.1.exeooC:
unknown
malicious
http://ask6.awt.com.pk/wordpress//wp-content/stanmac2.1.exe
115.186.131.16
malicious
boele.duckdns.org
malicious
http://ask6.awt.com.pk/wordpress//wp-content/stanmac2.1.exedoC:
unknown
malicious
http://ask6.awt.com.pk/wordpress//wp-content/stanmac2.1.exej
unknown
malicious
http://nsis.sf.net/NSIS_ErrorError
unknown
http://google.com
unknown

Domains

Name
IP
Malicious
boele.duckdns.org
45.137.65.132
malicious
ask6.awt.com.pk
115.186.131.16
malicious

IPs

IP
Domain
Country
Malicious
115.186.131.16
ask6.awt.com.pk
Pakistan
malicious
45.137.65.132
boele.duckdns.org
Netherlands
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
xv+
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
nx+
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
az+
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\68C86
68C86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Batang
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Dotum
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@FangSong
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gulim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@NSimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Agency FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aharoni
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Algerian
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Andalus
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Angsana New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
AngsanaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aparajita
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arabic Typesetting
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Narrow
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Rounded MT Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Baskerville Old Face
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Batang
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bauhaus 93
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bell MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB Demi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bernard MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Blackadder ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Poster Compressed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Book Antiqua
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookman Old Style
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookshelf Symbol 7
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bradley Hand ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Britannic Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Broadway
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Browallia New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BrowalliaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Brush Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Californian FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calisto MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria Math
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Candara
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Castellar
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Centaur
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Schoolbook
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Chiller
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Colonna MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Comic Sans MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Consolas
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Constantia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cooper Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Corbel
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cordia New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
CordiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Courier New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Curlz MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DaunPenh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
David
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DilleniaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DokChampa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Dotum
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ebrima
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Edwardian Script ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Elephant
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Engravers MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Bold ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Demi ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Light ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Medium ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Estrangelo Edessa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
EucrosiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Euphemia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FangSong
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Felix Titling
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Footlight MT Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Forte
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Book
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi Cond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Heavy
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium Cond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FrankRuehl
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FreesiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Freestyle Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
French Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gabriola
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Garamond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gautami
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Georgia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gigi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Ext Condensed Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gisha
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gloucester MT Extra Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Old Style
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Stout
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gulim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Haettenschweiler
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harlow Solid Italic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harrington
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
High Tower Text
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Impact
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Imprint MT Shadow
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Informal Roman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
IrisUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Iskoola Pota
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
JasmineUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Jokerman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Juice ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kalinga
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kartika
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Khmer UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KodchiangUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kokila
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kristen ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kunstler Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lao UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Latha
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Leelawadee
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Levenim MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
LilyUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Bright
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Calligraphy
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Console
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Fax
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Handwriting
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Typewriter
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Unicode
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Magneto
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Maiandra GD
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mangal
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Marlett
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Matura MT Script Capitals
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Himalaya
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft New Tai Lue
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft PhagsPa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Tai Le
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Uighur
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Yi Baiti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam Fixed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mistral
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Modern No. 20
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mongolian Baiti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Monotype Corsiva
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MoolBoran
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Outlook
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Specialty
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MT Extra
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MV Boli
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Narkisim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Engraved
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Solid
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
NSimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Nyala
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
OCR A Extended
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Old English Text MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Onyx
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palace Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palatino Linotype
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Papyrus
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Parchment
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua Titling MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Plantagenet Cherokee
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Playbill
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Poor Richard
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Pristina
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Raavi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rage Italic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ravie
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Extra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rod
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sakkal Majalla
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Script MT Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Print
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Semibold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Symbol
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shonar Bangla
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Showcard Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shruti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic Fixed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Snap ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Stencil
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sylfaen
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Symbol
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tahoma
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tempus Sans ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Times New Roman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Traditional Arabic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Trebuchet MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tunga
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed Extra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Utsaah
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vani
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Verdana
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vijaya
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Viner Hand ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vivaldi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vladimir Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vrinda
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Webdings
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wide Latin
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 2
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 3
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\72443
72443
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Place MRU
Max Display
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Max Display
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 1
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 2
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 3
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 4
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 5
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 6
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 7
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 8
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 9
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 10
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 11
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 12
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 13
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 14
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 15
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 16
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 17
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 18
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 19
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 20
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Place MRU
Max Display
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Max Display
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 1
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 2
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 3
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 4
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 5
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 6
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 7
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 8
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 9
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 10
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 11
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 12
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 13
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 14
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 15
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 16
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 17
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 18
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 19
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 20
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Security\Trusted Documents
LastPurgeTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
WORDFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\72443
72443
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\72443
72443
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\72443
72443
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
EquationEditorFilesIntl_1033
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
ryhcwrfexidnfv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
EquationEditorFilesIntl_1033
There are 357 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
380000
direct allocation
page read and write
malicious
328B000
trusted library allocation
page read and write
malicious
400000
system
page execute and read and write
malicious
5000000
trusted library section
page read and write
malicious
603000
heap
page read and write
malicious
2211000
trusted library allocation
page read and write
malicious
1E70000
trusted library section
page read and write
malicious
1EB2000
direct allocation
page execute and read and write
malicious
114000
heap
page read and write
2BC4000
heap
page read and write
258000
heap
page read and write
46A6000
trusted library allocation
page read and write
300000
heap
page read and write
4DD5000
trusted library allocation
page read and write
2C58000
heap
page read and write
56CC000
stack
page read and write
6630000
trusted library allocation
page read and write
65C0000
trusted library section
page read and write
4BC0000
trusted library allocation
page read and write
1A104000
direct allocation
page read and write
56F0000
trusted library allocation
page read and write
35FF000
stack
page read and write
1A110000
direct allocation
page read and write
1A010000
direct allocation
page read and write
558E000
stack
page read and write
56FC000
trusted library allocation
page read and write
427000
unkown
page read and write
1A110000
direct allocation
page read and write
598000
heap
page read and write
326B000
trusted library allocation
page read and write
21C0000
trusted library allocation
page read and write
5898000
heap
page read and write
21C0000
trusted library allocation
page read and write
387000
heap
page read and write
5850000
heap
page read and write
1A170000
direct allocation
page read and write
46B0000
trusted library allocation
page read and write
534000
trusted library section
page readonly
400000
unkown
page readonly
6638000
trusted library allocation
page read and write
4DD0000
trusted library allocation
page read and write
469E000
stack
page read and write
4FFF000
stack
page read and write
307000
heap
page read and write
400000
heap
page read and write
6630000
trusted library allocation
page read and write
28BF000
stack
page read and write
19EB0000
direct allocation
page read and write
2220000
heap
page read and write
69E5000
heap
page read and write
88000
stack
page read and write
410000
unkown
page readonly
1A0F0000
direct allocation
page read and write
1A107000
direct allocation
page read and write
2A0000
heap
page read and write
21C6000
trusted library allocation
page read and write
563000
heap
page read and write
3C6000
heap
page read and write
19EB0000
direct allocation
page read and write
4DF0000
trusted library allocation
page read and write
4BC0000
trusted library allocation
page read and write
89000
stack
page read and write
281A000
trusted library allocation
page read and write
56D0000
unkown
page read and write
5D1F000
stack
page read and write
1A107000
direct allocation
page read and write
6630000
trusted library allocation
page read and write
56B000
heap
page read and write
372F000
heap
page read and write
420000
heap
page read and write
65A0000
trusted library section
page read and write
6600000
trusted library allocation
page read and write
4DE0000
trusted library allocation
page read and write
401000
unkown
page execute read
19F8A000
direct allocation
page read and write
21C0000
trusted library allocation
page read and write
1A101000
direct allocation
page read and write
4DF0000
trusted library allocation
page read and write
65D0000
trusted library section
page read and write
1A101000
direct allocation
page read and write
1A104000
direct allocation
page read and write
84D000
stack
page read and write
56D0000
trusted library allocation
page read and write
6630000
trusted library allocation
page read and write
8B000
stack
page read and write
37D000
heap
page read and write
3656000
trusted library allocation
page read and write
6C9D000
stack
page read and write
4DE8000
trusted library allocation
page read and write
34E3000
trusted library allocation
page read and write
645E000
stack
page read and write
38C000
heap
page read and write
3676000
trusted library allocation
page read and write
46A0000
trusted library allocation
page read and write
567000
heap
page read and write
46B0000
trusted library section
page read and write
3453000
trusted library allocation
page read and write
400000
unkown
page readonly
1A000000
direct allocation
page read and write
540000
heap
page read and write
3FBF000
stack
page read and write
6630000
trusted library allocation
page read and write
382000
heap
page read and write
3523000
trusted library allocation
page read and write
56F0000
trusted library section
page read and write
46A0000
unkown
page read and write
4CD000
stack
page read and write
56F8000
unkown
page read and write
364000
heap
page read and write
400000
unkown
page readonly
2085000
heap
page read and write
8B000
stack
page read and write
230000
trusted library section
page read and write
21C0000
trusted library allocation
page read and write
46A5000
trusted library allocation
page read and write
1A170000
direct allocation
page read and write
379000
heap
page read and write
1A104000
direct allocation
page read and write
4DF0000
trusted library allocation
page read and write
19FF000
stack
page read and write
4BC5000
trusted library allocation
page read and write
4BC0000
trusted library allocation
page read and write
36F0000
heap
page read and write
4BC0000
trusted library allocation
page read and write
4660000
trusted library allocation
page read and write
21C0000
trusted library allocation
page read and write
1EB0000
direct allocation
page execute and read and write
544C000
stack
page read and write
4FBE000
stack
page read and write
5B0000
heap
page read and write
5F1F000
stack
page read and write
5D4000
heap
page read and write
4BC0000
trusted library allocation
page read and write
2C5B000
heap
page read and write
4D8F000
stack
page read and write
6880000
trusted library allocation
page read and write
1A010000
direct allocation
page read and write
21C0000
trusted library allocation
page read and write
4DE0000
trusted library allocation
page read and write
565000
heap
page read and write
1EF0000
trusted library allocation
page read and write
220000
direct allocation
page execute and read and write
46B0000
trusted library allocation
page read and write
6880000
trusted library allocation
page read and write
589D000
heap
page read and write
56D5000
trusted library allocation
page read and write
1D10000
heap
page read and write
410000
unkown
page readonly
24EF000
stack
page read and write
5898000
heap
page read and write
3AEF000
stack
page read and write
58B6000
heap
page read and write
3503000
trusted library allocation
page read and write
38F000
heap
page read and write
5A0000
heap
page read and write
573000
heap
page read and write
6630000
trusted library allocation
page read and write
40A000
unkown
page read and write
69E0000
heap
page read and write
4BC0000
trusted library section
page read and write
19F8D000
direct allocation
page read and write
3D0000
trusted library allocation
page read and write
37A000
heap
page read and write
61D9000
stack
page read and write
4BC0000
trusted library allocation
page read and write
286000
trusted library allocation
page execute and read and write
1A170000
direct allocation
page read and write
282000
trusted library allocation
page read and write
282000
heap
page read and write
330000
direct allocation
page read and write
56F8000
unkown
page read and write
6640000
trusted library allocation
page read and write
280000
trusted library allocation
page read and write
230000
heap
page read and write
631D000
stack
page read and write
1A010000
direct allocation
page read and write
4D4E000
stack
page read and write
5E1D000
stack
page read and write
6630000
trusted library allocation
page read and write
5A3D000
heap
page read and write
43B000
unkown
page readonly
27F0000
trusted library allocation
page read and write
4DF0000
trusted library allocation
page read and write
292000
trusted library allocation
page read and write
1A0F0000
direct allocation
page read and write
38B0000
heap
page read and write
554D000
stack
page read and write
21C0000
trusted library allocation
page read and write
19F8D000
direct allocation
page read and write
2B0000
heap
page read and write
56F0000
unkown
page read and write
2BC8000
heap
page read and write
36F000
stack
page read and write
1A0F0000
direct allocation
page read and write
687F000
stack
page read and write
1A0F0000
direct allocation
page read and write
770000
heap
page read and write
370D000
heap
page read and write
539000
trusted library section
page readonly
4DE0000
trusted library allocation
page read and write
5861000
heap
page read and write
31F000
heap
page read and write
34D3000
trusted library allocation
page read and write
264000
trusted library allocation
page read and write
26D000
trusted library allocation
page execute and read and write
4DF0000
trusted library section
page read and write
270000
heap
page read and write
5872000
heap
page read and write
4BC6000
trusted library allocation
page read and write
46A0000
trusted library allocation
page read and write
589C000
heap
page read and write
43B000
unkown
page readonly
270000
heap
page read and write
1A0F0000
direct allocation
page read and write
36F000
heap
page read and write
4BC5000
trusted library allocation
page read and write
6880000
trusted library allocation
page read and write
1EB0000
heap
page read and write
4BBE000
stack
page read and write
3E0000
heap
page read and write
4DF0000
trusted library allocation
page read and write
1EF5000
trusted library allocation
page read and write
6630000
trusted library allocation
page read and write
36B0000
heap
page read and write
56F000
heap
page read and write
408000
unkown
page readonly
2BC0000
heap
page read and write
6650000
trusted library allocation
page read and write
589F000
heap
page read and write
1EF0000
trusted library allocation
page read and write
375000
heap
page read and write
46C0000
heap
page execute and read and write
4DE0000
trusted library allocation
page execute and read and write
57FE000
stack
page read and write
621C000
stack
page read and write
21C0000
trusted library allocation
page read and write
58A8000
heap
page read and write
6320000
heap
page read and write
6CDC000
stack
page read and write
6A02000
heap
page read and write
34B3000
trusted library allocation
page read and write
4BC0000
trusted library allocation
page read and write
3393000
trusted library allocation
page read and write
1E50000
heap
page read and write
6630000
trusted library allocation
page read and write
56F0000
unkown
page read and write
5C1D000
stack
page read and write
59D0000
trusted library section
page read and write
5810000
heap
page read and write
655F000
stack
page read and write
203E000
stack
page read and write
60D000
heap
page read and write
1A110000
direct allocation
page read and write
589D000
heap
page read and write
260000
heap
page read and write
365000
heap
page read and write
4E00000
heap
page read and write
338000
heap
page read and write
6B5D000
stack
page read and write
4BC0000
trusted library allocation
page read and write
65A0000
trusted library allocation
page read and write
1A000000
direct allocation
page read and write
63A000
heap
page read and write
40C000
unkown
page read and write
2770000
trusted library allocation
page read and write
21C0000
trusted library allocation
page read and write
4DF0000
trusted library allocation
page read and write
4DD2000
trusted library allocation
page read and write
65B0000
trusted library section
page read and write
4DD0000
trusted library allocation
page read and write
692000
heap
page read and write
2422000
trusted library allocation
page read and write
4DD0000
trusted library allocation
page read and write
18E000
stack
page read and write
1A0F0000
direct allocation
page read and write
6570000
trusted library section
page read and write
590B000
heap
page read and write
19F8A000
direct allocation
page read and write
3383000
trusted library allocation
page read and write
6640000
trusted library allocation
page read and write
3433000
trusted library allocation
page read and write
3323000
trusted library allocation
page read and write
3BEF000
stack
page read and write
4DE0000
trusted library allocation
page read and write
6885000
trusted library allocation
page read and write
19F8D000
direct allocation
page read and write
6DDD000
stack
page read and write
1A101000
direct allocation
page read and write
1A010000
direct allocation
page read and write
371000
heap
page read and write
663C000
trusted library allocation
page read and write
401000
unkown
page execute read
186000
stack
page read and write
A2F000
stack
page read and write
33A3000
trusted library allocation
page read and write
2FE000
stack
page read and write
2C3E000
stack
page read and write
4BC6000
trusted library allocation
page read and write
577E000
stack
page read and write
56E7000
trusted library allocation
page read and write
10000
heap
page read and write
372000
heap
page read and write
1A110000
direct allocation
page read and write
21C8000
trusted library allocation
page read and write
6A20000
trusted library allocation
page read and write
4050000
heap
page read and write
1A0F0000
direct allocation
page read and write
5B7000
heap
page read and write
6630000
trusted library allocation
page read and write
3DE000
stack
page read and write
58A7000
heap
page read and write
10000
heap
page read and write
3070000
heap
page read and write
324000
heap
page read and write
1EF0000
trusted library allocation
page read and write
56D0000
trusted library allocation
page read and write
4670000
trusted library allocation
page read and write
1DD8000
trusted library allocation
page read and write
5806000
trusted library allocation
page read and write
6747000
trusted library allocation
page read and write
28A000
trusted library allocation
page execute and read and write
4DF0000
trusted library allocation
page read and write
36E000
heap
page read and write
520000
heap
page read and write
348000
heap
page read and write
4BD4000
heap
page read and write
5800000
trusted library allocation
page read and write
4481000
heap
page read and write
1A010000
direct allocation
page read and write
1A170000
direct allocation
page read and write
3DBD000
stack
page read and write
3677000
trusted library allocation
page read and write
56F0000
trusted library allocation
page read and write
381000
heap
page read and write
6630000
trusted library allocation
page read and write
240000
trusted library allocation
page read and write
414000
unkown
page read and write
6640000
trusted library allocation
page read and write
3483000
trusted library allocation
page read and write
510000
heap
page read and write
589F000
heap
page read and write
1A110000
direct allocation
page read and write
414000
unkown
page write copy
56F6000
trusted library allocation
page read and write
46A0000
trusted library allocation
page read and write
68DD000
stack
page read and write
310000
heap
page read and write
58A0000
heap
page read and write
363C000
stack
page read and write
4DD0000
trusted library allocation
page read and write
3313000
trusted library allocation
page read and write
5800000
trusted library allocation
page read and write
8D000
stack
page read and write
2ABC000
stack
page read and write
437000
unkown
page read and write
4660000
trusted library allocation
page read and write
19F8A000
direct allocation
page read and write
1A104000
direct allocation
page read and write
1A010000
direct allocation
page read and write
33E3000
trusted library allocation
page read and write
410000
unkown
page readonly
19F8A000
direct allocation
page read and write
2732000
trusted library allocation
page read and write
6635000
trusted library allocation
page read and write
10000
heap
page read and write
5883000
heap
page read and write
6590000
trusted library section
page read and write
1EF0000
trusted library allocation
page read and write
3C0000
heap
page read and write
110000
heap
page read and write
220000
trusted library section
page read and write
276C000
trusted library allocation
page read and write
27F1000
heap
page read and write
227B000
trusted library allocation
page read and write
68E000
heap
page read and write
56F0000
trusted library allocation
page read and write
5A2000
heap
page read and write
19F8A000
direct allocation
page read and write
48E000
stack
page read and write
1A000000
direct allocation
page read and write
342000
heap
page read and write
372000
heap
page read and write
3CD000
stack
page read and write
10000
heap
page read and write
436000
heap
page read and write
425000
unkown
page read and write
6880000
trusted library allocation
page read and write
3443000
trusted library allocation
page read and write
7C0000
heap
page read and write
56E0000
trusted library allocation
page read and write
6880000
trusted library allocation
page read and write
3AC3000
trusted library allocation
page read and write
27F0000
trusted library allocation
page read and write
19EB0000
direct allocation
page read and write
4BC0000
trusted library allocation
page read and write
6630000
trusted library allocation
page read and write
21C0000
trusted library allocation
page read and write
2748000
trusted library allocation
page read and write
219F000
stack
page read and write
6F1C000
stack
page read and write
4660000
trusted library allocation
page read and write
360000
heap
page read and write
386F000
stack
page read and write
1ED2000
direct allocation
page execute and read and write
616000
heap
page read and write
7EF40000
trusted library allocation
page execute and read and write
19EB0000
direct allocation
page read and write
616000
heap
page read and write
259E000
trusted library allocation
page read and write
59CC000
stack
page read and write
4DF0000
trusted library allocation
page read and write
69DD000
stack
page read and write
636000
heap
page read and write
1A110000
direct allocation
page read and write
6630000
trusted library allocation
page read and write
19EB0000
direct allocation
page read and write
58C2000
heap
page read and write
587000
heap
page read and write
414000
unkown
page read and write
27F0000
trusted library allocation
page read and write
630000
heap
page read and write
527000
heap
page read and write
6580000
trusted library section
page read and write
6636000
trusted library allocation
page read and write
23CF000
stack
page read and write
3363000
trusted library allocation
page read and write
1E20000
heap
page read and write
6630000
trusted library allocation
page read and write
19F8A000
direct allocation
page read and write
19EB0000
direct allocation
page read and write
1A170000
direct allocation
page read and write
6560000
trusted library allocation
page read and write
19EB0000
direct allocation
page read and write
40A000
unkown
page write copy
2B0000
heap
page read and write
5800000
unkown
page read and write
4670000
trusted library allocation
page read and write
2BCB000
heap
page read and write
547000
heap
page read and write
270000
trusted library allocation
page read and write
1A170000
direct allocation
page read and write
250000
heap
page read and write
4DD0000
trusted library allocation
page read and write
350000
heap
page read and write
4BC0000
trusted library allocation
page read and write
401000
unkown
page execute read
2067000
heap
page read and write
5F6000
heap
page read and write
564000
heap
page read and write
37A000
heap
page read and write
29BF000
stack
page read and write
6638000
trusted library allocation
page read and write
382E000
stack
page read and write
2060000
heap
page read and write
57BC000
stack
page read and write
20D000
stack
page read and write
4DE0000
trusted library allocation
page read and write
3343000
trusted library allocation
page read and write
18C000
stack
page read and write
32E3000
trusted library allocation
page read and write
3EBE000
stack
page read and write
5700000
heap
page read and write
1DF0000
direct allocation
page read and write
534000
heap
page read and write
21C0000
trusted library allocation
page read and write
4BC0000
trusted library allocation
page read and write
1A000000
direct allocation
page read and write
4DF0000
trusted library allocation
page read and write
21C0000
trusted library allocation
page read and write
10000
heap
page read and write
663C000
trusted library allocation
page read and write
4DCC000
stack
page read and write
4D0C000
stack
page read and write
50E000
stack
page read and write
3463000
trusted library allocation
page read and write
1A107000
direct allocation
page read and write
56F0000
trusted library allocation
page read and write
400000
unkown
page readonly
6B9C000
stack
page read and write
517000
heap
page read and write
3403000
trusted library allocation
page read and write
1A107000
direct allocation
page read and write
19F8D000
direct allocation
page read and write
19F8D000
direct allocation
page read and write
1A107000
direct allocation
page read and write
544000
heap
page read and write
27BE000
trusted library allocation
page read and write
34A3000
trusted library allocation
page read and write
4DF0000
trusted library allocation
page read and write
280000
heap
page read and write
1A101000
direct allocation
page read and write
4BC8000
trusted library allocation
page read and write
580000
heap
page read and write
377000
heap
page read and write
264000
heap
page read and write
368000
heap
page read and write
1EF0000
direct allocation
page read and write
465C000
stack
page read and write
5AF000
stack
page read and write
4480000
heap
page read and write
401000
unkown
page execute read
2BFE000
stack
page read and write
400000
unkown
page readonly
540000
heap
page read and write
4DF0000
trusted library allocation
page read and write
4F0C000
stack
page read and write
1A170000
direct allocation
page read and write
2C50000
heap
page read and write
BDE000
stack
page read and write
33C3000
trusted library allocation
page read and write
1F00000
heap
page execute and read and write
4DD0000
trusted library allocation
page read and write
3E0000
trusted library allocation
page execute and read and write
6630000
trusted library allocation
page read and write
350000
heap
page read and write
6610000
trusted library section
page read and write
1A107000
direct allocation
page read and write
414000
unkown
page write copy
6650000
trusted library allocation
page read and write
5A4000
heap
page read and write
376000
heap
page read and write
598C000
stack
page read and write
3303000
trusted library allocation
page read and write
8D000
stack
page read and write
297000
trusted library allocation
page execute and read and write
39E000
stack
page read and write
5A20000
heap
page read and write
5AF000
heap
page read and write
250000
heap
page read and write
388000
heap
page read and write
1A104000
direct allocation
page read and write
23EF000
stack
page read and write
568E000
stack
page read and write
263000
trusted library allocation
page execute and read and write
6740000
trusted library allocation
page read and write
6630000
trusted library allocation
page read and write
4DD0000
trusted library allocation
page read and write
4BC0000
trusted library allocation
page read and write
401000
unkown
page execute read
1A000000
direct allocation
page read and write
2330000
trusted library allocation
page read and write
401000
unkown
page execute read
414000
unkown
page write copy
2806000
trusted library allocation
page read and write
19F8A000
direct allocation
page read and write
850000
heap
page read and write
1A101000
direct allocation
page read and write
56F0000
trusted library allocation
page read and write
346000
heap
page read and write
6740000
trusted library allocation
page read and write
3423000
trusted library allocation
page read and write
4E4000
heap
page read and write
34C3000
trusted library allocation
page read and write
1A110000
direct allocation
page read and write
1A104000
direct allocation
page read and write
58C6000
heap
page read and write
4BD0000
heap
page read and write
3F0000
trusted library allocation
page read and write
56F0000
unkown
page read and write
1A010000
direct allocation
page read and write
32F000
stack
page read and write
29B000
trusted library allocation
page execute and read and write
6E1C000
stack
page read and write
18A000
stack
page read and write
3211000
trusted library allocation
page read and write
4BF2000
heap
page read and write
59E0000
heap
page read and write
3CB0000
heap
page read and write
1A000000
direct allocation
page read and write
18C000
stack
page read and write
408000
unkown
page readonly
6630000
trusted library allocation
page execute and read and write
4DFF000
trusted library allocation
page read and write
1A107000
direct allocation
page read and write
1A104000
direct allocation
page read and write
530000
trusted library section
page readonly
37B000
heap
page read and write
4BC0000
trusted library allocation
page read and write
21C6000
trusted library allocation
page read and write
3B0000
heap
page read and write
3734000
heap
page read and write
260000
heap
page read and write
56F0000
trusted library allocation
page read and write
388000
heap
page read and write
6A5C000
stack
page read and write
27EF000
stack
page read and write
4C7000
heap
page read and write
6640000
heap
page read and write
1A101000
direct allocation
page read and write
19F8D000
direct allocation
page read and write
348000
heap
page read and write
7C7000
heap
page read and write
4660000
trusted library allocation
page read and write
271E000
trusted library allocation
page read and write
18C000
stack
page read and write
376000
heap
page read and write
6620000
trusted library allocation
page read and write
630000
heap
page read and write
6636000
trusted library allocation
page read and write
19F8D000
direct allocation
page read and write
320000
heap
page read and write
400000
unkown
page readonly
6630000
trusted library allocation
page read and write
39EF000
stack
page read and write
59D0000
trusted library allocation
page read and write
38D000
heap
page read and write
601D000
stack
page read and write
372F000
stack
page read and write
560000
heap
page read and write
1A000000
direct allocation
page read and write
607000
heap
page read and write
2C54000
heap
page read and write
4BC0000
trusted library allocation
page read and write
550000
trusted library allocation
page read and write
6BA000
stack
page read and write
451F000
stack
page read and write
46A0000
trusted library allocation
page read and write
21D0000
heap
page execute and read and write
60D000
heap
page read and write
384000
heap
page read and write
10000
heap
page read and write
260000
trusted library allocation
page read and write
33D000
heap
page read and write
410000
unkown
page readonly
461F000
stack
page read and write
401000
unkown
page execute read
677E000
stack
page read and write
58A7000
heap
page read and write
410000
unkown
page readonly
5AD000
heap
page read and write
10000
heap
page read and write
5800000
trusted library allocation
page read and write
1A101000
direct allocation
page read and write
371F000
heap
page read and write
3650000
heap
page read and write
5898000
heap
page read and write
2BBC000
stack
page read and write
36A000
heap
page read and write
26EF000
stack
page read and write
4BC0000
trusted library allocation
page read and write
27D000
trusted library allocation
page execute and read and write
4C0000
heap
page read and write
400000
unkown
page readonly
54F000
stack
page read and write
5AD000
heap
page read and write
56D0000
trusted library section
page read and write
There are 636 hidden memdumps, click here to show them.