IOC Report
Xkl0PnD8zFPjfh1.wiz.rtf

loading gif

Files

File Path
Type
Category
Malicious
Xkl0PnD8zFPjfh1.wiz.rtf
Nim source code, Non-ISO extended-ASCII text, with very long lines (65322), with CR line terminators
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\Xkl0PnD8zFPjfh1[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Roaming\wealthcharliebgk.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{CBB6C114-22C0-4E8C-812B-10640C9DABC0}.tmp
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{502A34A8-C460-4074-8066-FA66CCE00E5D}.tmp
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{A0F671BC-384D-4C76-B9D0-6C0270962DCC}.tmp
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{C6543D4A-93B1-45DF-9157-D796FE9EF544}.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\2fgbchjd.wx5.psm1
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\obnb3a4t.cfs.ps1
very short file (no magic)
dropped
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Xkl0PnD8zFPjfh1.wiz.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Fri Aug 11 15:42:08 2023, mtime=Fri Aug 11 15:42:08 2023, atime=Tue Nov 19 16:07:58 2024, length=418646, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
Generic INItialization configuration [folders]
dropped
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\UProof\ExcludeDictionaryEN0409.lex
Unicode text, UTF-16, little-endian text, with no line terminators
dropped
C:\Users\user\Desktop\~$l0PnD8zFPjfh1.wiz.rtf
data
dropped
There are 5 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /Automation -Embedding
malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
"C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
malicious
C:\Users\user\AppData\Roaming\wealthcharliebgk.exe
"C:\Users\user\AppData\Roaming\wealthcharliebgk.exe"
malicious
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\wealthcharliebgk.exe"
malicious
C:\Users\user\AppData\Roaming\wealthcharliebgk.exe
"C:\Users\user\AppData\Roaming\wealthcharliebgk.exe"
malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
"C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
malicious

URLs

Name
IP
Malicious
http://87.120.84.39/txt/Xkl0PnD8zFPjfh1.exe
87.120.84.39
malicious
https://duckduckgo.com/chrome_newtab
unknown
https://duckduckgo.com/ac/?q=
unknown
https://www.google.com/sorry/index?continue=https://www.google.com/search%3Fq%3Dwmf%2B5.1%26oq%3Dwmf
unknown
https://api.telegram.org
unknown
http://crl.entrust.net/server1.crl0
unknown
https://api.telegram.org/bot
unknown
https://www.google.com/search?q=test&oq=test&aqs=chrome..69i57j46j0l3j46j0.427j0j7&sourceid=chrome&i
unknown
http://ocsp.entrust.net03
unknown
http://87.120.84.39/txt/Xkl0PnD8zFPjfh1.exettC:
unknown
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
unknown
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
unknown
http://www.diginotar.nl/cps/pkioverheid0
unknown
http://checkip.dyndns.org
unknown
https://search.yahoo.com/favicon.icohttps://search.yahoo.com/search
unknown
http://87.120.84.39/txt/Xkl0PnD8zFPjfh1.exej
unknown
https://api.telegram.org/bot/sendMessage?chat_id=&text=
unknown
https://reallyfreegeoip.org/xml/8.46.123.75
188.114.97.3
https://api.telegram.org/bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:878411%0D%0ADate%20and%20Time:%2011/20/2024%20/%201:09:14%20AM%0D%0ACountry%20Name:%20United%20States%0D%0A%5B%20878411%20Clicked%20on%20the%20File%20If%20you%20see%20nothing%20this's%20mean%20the%20system%20storage's%20empty.%20%5D
149.154.167.220
https://reallyfreegeoip.org/xml/8.46.123.754
unknown
http://varders.kozow.com:8081
unknown
https://www.google.com/favicon.ico
unknown
http://aborters.duckdns.org:8081
unknown
https://ac.ecosia.org/autocomplete?q=
unknown
https://api.telegram.org/bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:878411%0D%0ADate%20a
unknown
http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
unknown
https://www.google.com/sorry/index
unknown
http://checkip.dyndns.org/
193.122.130.0
https://www.google.com/search?q=wmf
unknown
http://anotherarmy.dns.army:8081
unknown
http://checkip.dyndns.org/q
unknown
http://reallyfreegeoip.org
unknown
https://reallyfreegeoip.org
unknown
https://www.google.com/sorry/index?continue=https://www.google.com/search%3Fq%3Dtest%26oq%3Dtest%26a
unknown
https://www.google.com/search?q=net
unknown
https://www.google.com/sorry/indextest
unknown
http://checkip.dyndns.com
unknown
http://api.telegram.org
unknown
http://ocsp.entrust.net0D
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
https://secure.comodo.com/CPS0
unknown
http://87.120.84.39/txt/Xkl0PnD8zFPjfh1.exeC:
unknown
https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
unknown
http://crl.entrust.net/2048ca.crl0
unknown
https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
unknown
http://51.38.247.67:8081/_send_.php?LCapplication/x-www-form-urlencoded
unknown
https://reallyfreegeoip.org/xml/
unknown
There are 37 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
reallyfreegeoip.org
188.114.97.3
api.telegram.org
149.154.167.220
checkip.dyndns.com
193.122.130.0
checkip.dyndns.org
unknown

IPs

IP
Domain
Country
Malicious
87.120.84.39
unknown
Bulgaria
malicious
132.226.8.169
unknown
United States
149.154.167.220
api.telegram.org
United Kingdom
188.114.97.3
reallyfreegeoip.org
European Union
188.114.96.3
unknown
European Union
193.122.130.0
checkip.dyndns.com
United States
158.101.44.242
unknown
United States
132.226.247.73
unknown
United States

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
v?0
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Outlook\Journaling\Microsoft Word
Enabled
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
|`0
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
+c0
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\2908C
2908C
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Batang
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Dotum
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@FangSong
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gulim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@NSimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Agency FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aharoni
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Algerian
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Andalus
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Angsana New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
AngsanaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aparajita
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arabic Typesetting
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Narrow
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Rounded MT Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Baskerville Old Face
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Batang
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bauhaus 93
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bell MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB Demi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bernard MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Blackadder ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Poster Compressed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Book Antiqua
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookman Old Style
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookshelf Symbol 7
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bradley Hand ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Britannic Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Broadway
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Browallia New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BrowalliaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Brush Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Californian FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calisto MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria Math
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Candara
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Castellar
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Centaur
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Schoolbook
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Chiller
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Colonna MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Comic Sans MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Consolas
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Constantia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cooper Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Corbel
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cordia New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
CordiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Courier New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Curlz MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DaunPenh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
David
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DilleniaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DokChampa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Dotum
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ebrima
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Edwardian Script ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Elephant
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Engravers MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Bold ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Demi ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Light ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Medium ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Estrangelo Edessa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
EucrosiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Euphemia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FangSong
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Felix Titling
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Footlight MT Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Forte
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Book
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi Cond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Heavy
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium Cond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FrankRuehl
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FreesiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Freestyle Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
French Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gabriola
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Garamond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gautami
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Georgia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gigi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Ext Condensed Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gisha
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gloucester MT Extra Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Old Style
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Stout
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gulim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Haettenschweiler
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harlow Solid Italic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harrington
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
High Tower Text
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Impact
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Imprint MT Shadow
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Informal Roman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
IrisUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Iskoola Pota
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
JasmineUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Jokerman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Juice ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kalinga
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kartika
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Khmer UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KodchiangUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kokila
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kristen ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kunstler Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lao UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Latha
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Leelawadee
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Levenim MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
LilyUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Bright
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Calligraphy
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Console
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Fax
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Handwriting
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Typewriter
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Unicode
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Magneto
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Maiandra GD
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mangal
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Marlett
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Matura MT Script Capitals
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Himalaya
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft New Tai Lue
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft PhagsPa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Tai Le
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Uighur
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Yi Baiti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam Fixed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mistral
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Modern No. 20
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mongolian Baiti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Monotype Corsiva
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MoolBoran
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Outlook
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Specialty
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MT Extra
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MV Boli
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Narkisim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Engraved
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Solid
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
NSimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Nyala
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
OCR A Extended
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Old English Text MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Onyx
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palace Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palatino Linotype
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Papyrus
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Parchment
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua Titling MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Plantagenet Cherokee
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Playbill
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Poor Richard
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Pristina
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Raavi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rage Italic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ravie
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Extra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rod
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sakkal Majalla
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Script MT Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Print
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Semibold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Symbol
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shonar Bangla
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Showcard Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shruti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic Fixed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Snap ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Stencil
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sylfaen
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Symbol
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tahoma
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tempus Sans ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Times New Roman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Traditional Arabic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Trebuchet MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tunga
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed Extra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Utsaah
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vani
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Verdana
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vijaya
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Viner Hand ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vivaldi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vladimir Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vrinda
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Webdings
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wide Latin
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 2
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 3
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Security\Trusted Documents
LastPurgeTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
WORDFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
EquationEditorFilesIntl_1033
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus
FontCachePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\wealthcharliebgk_RASAPI32
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\wealthcharliebgk_RASAPI32
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\wealthcharliebgk_RASAPI32
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\wealthcharliebgk_RASAPI32
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\wealthcharliebgk_RASAPI32
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\wealthcharliebgk_RASAPI32
FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\wealthcharliebgk_RASMANCS
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\wealthcharliebgk_RASMANCS
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\wealthcharliebgk_RASMANCS
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\wealthcharliebgk_RASMANCS
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\wealthcharliebgk_RASMANCS
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\wealthcharliebgk_RASMANCS
FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
EquationEditorFilesIntl_1033
There are 330 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
33F1000
trusted library allocation
page read and write
malicious
23F1000
trusted library allocation
page read and write
malicious
402000
remote allocation
page execute and read and write
malicious
558E000
stack
page read and write
F10000
unkown
page readonly
3518000
trusted library allocation
page read and write
35FE000
trusted library allocation
page read and write
66FC000
heap
page read and write
914000
heap
page read and write
69D4000
heap
page read and write
4FBE000
stack
page read and write
5B0E000
stack
page read and write
487000
heap
page read and write
27F000
stack
page read and write
CDC000
stack
page read and write
6374000
heap
page read and write
A0D0000
heap
page read and write
6E57000
heap
page read and write
49BD000
heap
page read and write
870000
trusted library allocation
page read and write
6E14000
heap
page read and write
5B8E000
heap
page read and write
65D1000
heap
page read and write
6348000
heap
page read and write
1D82000
heap
page read and write
6BB5000
heap
page read and write
5072000
heap
page read and write
356A000
trusted library allocation
page read and write
1F84000
heap
page read and write
1FD000
trusted library allocation
page execute and read and write
357C000
stack
page read and write
399000
heap
page read and write
470000
trusted library allocation
page execute and read and write
3B4F000
stack
page read and write
351A000
trusted library allocation
page read and write
576E000
stack
page read and write
26CD000
trusted library allocation
page read and write
65CC000
heap
page read and write
2509000
trusted library allocation
page read and write
2483000
trusted library allocation
page read and write
53FB000
heap
page read and write
64C2000
heap
page read and write
58FE000
stack
page read and write
2686000
trusted library allocation
page read and write
7507000
heap
page read and write
407000
trusted library allocation
page execute and read and write
36C4000
heap
page read and write
4EC0000
heap
page read and write
60A7000
heap
page read and write
74EB000
heap
page read and write
247B000
trusted library allocation
page read and write
631A000
heap
page read and write
5280000
heap
page read and write
202000
trusted library allocation
page read and write
6345000
heap
page read and write
354A000
trusted library allocation
page read and write
26C7000
trusted library allocation
page read and write
8F7000
heap
page read and write
693E000
stack
page read and write
2F0000
trusted library allocation
page read and write
2529000
trusted library allocation
page read and write
61A0000
heap
page read and write
63D6000
heap
page read and write
5CDE000
unkown
page read and write
AFE000
stack
page read and write
36BF000
heap
page read and write
361E000
trusted library allocation
page read and write
555000
heap
page read and write
E3E000
stack
page read and write | page guard
1FC0000
heap
page read and write
69C0000
heap
page read and write
6973000
heap
page read and write
2ED000
stack
page read and write
52E000
heap
page read and write
251D000
trusted library allocation
page read and write
F12000
unkown
page execute read
AAD000
stack
page read and write
289F000
stack
page read and write
4A4000
heap
page read and write
6EA1000
heap
page read and write
346B000
trusted library allocation
page read and write
3558000
trusted library allocation
page read and write
35D8000
trusted library allocation
page read and write
350D000
trusted library allocation
page read and write
5028000
heap
page read and write
585E000
stack
page read and write
65C6000
heap
page read and write
1E3000
trusted library allocation
page execute and read and write
1ED000
trusted library allocation
page execute and read and write
A0CE000
stack
page read and write
88000
stack
page read and write
67FE000
heap
page read and write
6250000
heap
page read and write
61F0000
heap
page read and write
26BA000
trusted library allocation
page read and write
460000
trusted library allocation
page read and write
658D000
heap
page read and write
4870000
heap
page read and write
4FE0000
heap
page read and write
300000
heap
page read and write
259E000
trusted library allocation
page read and write
A6DE000
stack
page read and write
200000
trusted library allocation
page read and write
558F000
stack
page read and write
B9E000
stack
page read and write
24C2000
trusted library allocation
page read and write
378000
stack
page read and write
2630000
trusted library allocation
page read and write
EA0000
heap
page execute and read and write
3604000
trusted library allocation
page read and write
B28000
trusted library allocation
page read and write
4F0000
heap
page read and write
268B000
trusted library allocation
page read and write
55DE000
stack
page read and write
65E000
stack
page read and write
6A3A000
heap
page read and write
5FEE000
stack
page read and write
367D000
stack
page read and write
3A0F000
stack
page read and write
2AF000
stack
page read and write
4F3E000
stack
page read and write
6551000
heap
page read and write
6404000
heap
page read and write
4F7E000
stack
page read and write
548D000
stack
page read and write
E4D000
stack
page read and write
5E0000
trusted library allocation
page execute and read and write
50A2000
heap
page read and write
33F1000
trusted library allocation
page read and write
625B000
heap
page read and write
90E000
stack
page read and write
2673000
trusted library allocation
page read and write
6A81000
heap
page read and write
26B4000
trusted library allocation
page read and write
680000
heap
page read and write
67B8000
heap
page read and write
6D8E000
stack
page read and write
2521000
trusted library allocation
page read and write
69D6000
heap
page read and write
67B000
heap
page read and write
32D000
stack
page read and write
6B79000
heap
page read and write
2590000
trusted library allocation
page read and write
5B59000
heap
page read and write
39CD000
stack
page read and write
3567000
trusted library allocation
page read and write
5612000
heap
page read and write
615E000
stack
page read and write
697B000
heap
page read and write
9FCE000
stack
page read and write
2639000
trusted library allocation
page read and write
850000
trusted library allocation
page execute and read and write
34AC000
trusted library allocation
page read and write
21B000
trusted library allocation
page execute and read and write
260000
heap
page read and write
6546000
heap
page read and write
6C1A000
heap
page read and write
6559000
heap
page read and write
6A58000
heap
page read and write
71BE000
stack
page read and write
6A42000
heap
page read and write
5C0000
trusted library allocation
page execute and read and write
6E65000
heap
page read and write
722E000
heap
page read and write
206000
trusted library allocation
page execute and read and write
1DD0000
direct allocation
page read and write
659E000
heap
page read and write
6632000
heap
page read and write
6612000
heap
page read and write
1EEF000
stack
page read and write
34A0000
trusted library allocation
page read and write
41B000
trusted library allocation
page execute and read and write
646C000
heap
page read and write
A36E000
stack
page read and write | page guard
6BE000
heap
page read and write
18A000
stack
page read and write
1D0000
trusted library allocation
page read and write
6121000
heap
page read and write
24D1000
trusted library allocation
page read and write
25AC000
trusted library allocation
page read and write
62AA000
heap
page read and write
8C0000
trusted library allocation
page read and write
2FD000
trusted library allocation
page execute and read and write
16A000
stack
page read and write
352A000
trusted library allocation
page read and write
402000
trusted library allocation
page read and write
960000
trusted library allocation
page execute and read and write
5F0000
heap
page execute and read and write
6D0000
heap
page read and write
6A7B000
heap
page read and write
483C000
heap
page read and write
3449000
trusted library allocation
page read and write
B0000
heap
page read and write
3A10000
heap
page read and write
1ED000
trusted library allocation
page execute and read and write
65D4000
heap
page read and write
1F0000
trusted library allocation
page read and write
B1F000
stack
page read and write
4D0000
trusted library allocation
page read and write
661E000
stack
page read and write
6859000
heap
page read and write
3421000
trusted library allocation
page read and write
56FE000
stack
page read and write
6812000
heap
page read and write
633C000
heap
page read and write
74E6000
heap
page read and write
300000
heap
page read and write
3EB000
heap
page read and write
2505000
trusted library allocation
page read and write
3850000
heap
page read and write
2515000
trusted library allocation
page read and write
6E90000
heap
page read and write
69F8000
heap
page read and write
6775000
heap
page read and write
26B7000
trusted library allocation
page read and write
C4D000
stack
page read and write
65E5000
heap
page read and write
697E000
heap
page read and write
4E0E000
stack
page read and write
351E000
trusted library allocation
page read and write
417000
trusted library allocation
page execute and read and write
3552000
trusted library allocation
page read and write
89000
stack
page read and write
5086000
heap
page read and write
6625000
heap
page read and write
1E3000
trusted library allocation
page execute and read and write
2542000
trusted library allocation
page read and write
6F8E000
stack
page read and write
35DA000
trusted library allocation
page read and write
5010000
heap
page read and write
34B7000
trusted library allocation
page read and write
4E0000
heap
page read and write
B1E000
stack
page read and write | page guard
58AE000
stack
page read and write
2BC4000
heap
page read and write
72FA000
heap
page read and write
398D000
stack
page read and write
345F000
trusted library allocation
page read and write
5EAE000
stack
page read and write
53C000
heap
page read and write
250D000
trusted library allocation
page read and write
5FFE000
stack
page read and write
6557000
heap
page read and write
CF0000
heap
page read and write
2E8000
stack
page read and write
35D2000
trusted library allocation
page read and write
24CC000
trusted library allocation
page read and write
636A000
heap
page read and write
539E000
stack
page read and write
2BCB000
heap
page read and write
25CD000
trusted library allocation
page read and write
3E8F000
stack
page read and write
64B9000
heap
page read and write
5600000
heap
page read and write
2511000
trusted library allocation
page read and write
6543000
heap
page read and write
2465000
trusted library allocation
page read and write
6C1000
heap
page read and write
287F000
stack
page read and write
6400000
heap
page read and write
6ABF000
stack
page read and write
6619000
heap
page read and write
A36F000
stack
page read and write
307000
heap
page read and write
1D60000
heap
page read and write
297F000
stack
page read and write
51DE000
stack
page read and write
4EBF000
stack
page read and write
4AA0000
heap
page execute and read and write
5D7E000
stack
page read and write
6788000
heap
page read and write
A47F000
stack
page read and write
2496000
trusted library allocation
page read and write
639F000
heap
page read and write
648F000
heap
page read and write
53DE000
stack
page read and write
860000
trusted library allocation
page read and write
34FE000
trusted library allocation
page read and write
257D000
trusted library allocation
page read and write
34B2000
trusted library allocation
page read and write
4EBE000
stack
page read and write | page guard
266D000
trusted library allocation
page read and write
5BD000
stack
page read and write
645F000
heap
page read and write
1E4000
trusted library allocation
page read and write
1FA2000
heap
page read and write
E3F000
stack
page read and write
6315000
heap
page read and write
2525000
trusted library allocation
page read and write
CBE000
stack
page read and write
68EB000
heap
page read and write
63DA000
heap
page read and write
745C000
heap
page read and write
3524000
trusted library allocation
page read and write
6377000
heap
page read and write
3F8000
heap
page read and write
2519000
trusted library allocation
page read and write
2562000
trusted library allocation
page read and write
5047000
heap
page read and write
24AF000
stack
page read and write
330000
heap
page read and write
1CEE000
stack
page read and write
653A000
heap
page read and write
35AC000
trusted library allocation
page read and write
6689000
heap
page read and write
4830000
heap
page read and write
3510000
trusted library allocation
page read and write
5BAF000
heap
page read and write
B10000
heap
page execute and read and write
840000
trusted library section
page read and write
2636000
trusted library allocation
page read and write
5B14000
heap
page read and write
60FF000
stack
page read and write
69BE000
heap
page read and write
3F80000
heap
page read and write
6466000
heap
page read and write
2BDB000
heap
page read and write
24E4000
trusted library allocation
page read and write
2612000
trusted library allocation
page read and write
2678000
trusted library allocation
page read and write
23F1000
trusted library allocation
page read and write
361B000
trusted library allocation
page read and write
324000
heap
page read and write
6A3D000
heap
page read and write
61EE000
heap
page read and write
6351000
heap
page read and write
7503000
heap
page read and write
1E0000
trusted library allocation
page read and write
6597000
heap
page read and write
49A0000
heap
page read and write
4DEE000
stack
page read and write
670B000
heap
page read and write
6A45000
heap
page read and write
212000
trusted library allocation
page read and write
2680000
trusted library allocation
page read and write
18C000
stack
page read and write
62BE000
heap
page read and write
35FC000
trusted library allocation
page read and write
3780000
heap
page read and write
65E0000
heap
page read and write
6C2E000
stack
page read and write
970000
heap
page execute and read and write
66CE000
heap
page read and write
6A03000
heap
page read and write
65E7000
heap
page read and write
26C1000
trusted library allocation
page read and write
6E3A000
heap
page read and write
6A9000
heap
page read and write
3D8F000
stack
page read and write
74F1000
heap
page read and write
529D000
heap
page read and write
3C7000
heap
page read and write
D12000
heap
page read and write
50BE000
stack
page read and write
67CC000
heap
page read and write
24D5000
trusted library allocation
page read and write
5B10000
heap
page read and write
383E000
stack
page read and write
37FC000
stack
page read and write
217000
trusted library allocation
page execute and read and write
52EE000
stack
page read and write
91F000
heap
page read and write
62EE000
stack
page read and write
35F6000
trusted library allocation
page read and write
6BD000
heap
page read and write
3550000
trusted library allocation
page read and write
3526000
trusted library allocation
page read and write
613E000
heap
page read and write
A58E000
stack
page read and write
2618000
trusted library allocation
page read and write
CF4000
heap
page read and write
F10000
unkown
page readonly
24CF000
stack
page read and write
3465000
trusted library allocation
page read and write
390000
trusted library allocation
page read and write
6944000
heap
page read and write
2470000
trusted library allocation
page read and write
8F0000
heap
page read and write
653E000
heap
page read and write
26CA000
trusted library allocation
page read and write
6A6000
heap
page read and write
4D0000
heap
page read and write
2546000
trusted library allocation
page read and write
3548000
trusted library allocation
page read and write
A0000
trusted library allocation
page read and write
6738000
heap
page read and write
6232000
heap
page read and write
1F80000
heap
page read and write
337000
heap
page read and write
450000
trusted library allocation
page read and write
6E8000
heap
page read and write
F12000
unkown
page execute read
51BD000
stack
page read and write
2BC0000
heap
page read and write
65EC000
heap
page read and write
5960000
heap
page read and write
5F4E000
stack
page read and write
499F000
stack
page read and write
3456000
trusted library allocation
page read and write
94F000
stack
page read and write
6650000
heap
page read and write
644000
heap
page read and write
655E000
heap
page read and write
74EE000
stack
page read and write
6A83000
heap
page read and write
35C1000
trusted library allocation
page read and write
646F000
stack
page read and write
2ED000
stack
page read and write
14A000
stack
page read and write
3C4D000
stack
page read and write
658A000
heap
page read and write
4EC8000
heap
page read and write
5D0000
trusted library allocation
page read and write
6A4D000
heap
page read and write
2554000
trusted library allocation
page read and write
48A0000
heap
page read and write
240000
trusted library allocation
page execute and read and write
610E000
heap
page read and write
6994000
heap
page read and write
6A0B000
heap
page read and write
BB0000
heap
page read and write
35C4000
trusted library allocation
page read and write
6E0000
heap
page read and write
34C000
heap
page read and write
64AC000
heap
page read and write
3FE000
stack
page read and write
400000
remote allocation
page execute and read and write
65A0000
heap
page read and write
A20000
trusted library allocation
page execute and read and write
619E000
heap
page read and write
3D4F000
stack
page read and write
6A96000
heap
page read and write
53A0000
heap
page read and write
6A00000
heap
page read and write
4EE6000
heap
page read and write
6D7000
heap
page read and write
FDE000
unkown
page readonly
261D000
trusted library allocation
page read and write
23AF000
stack
page read and write
44EE000
stack
page read and write
10000
heap
page read and write
2536000
trusted library allocation
page read and write
6D66000
heap
page read and write
35CE000
trusted library allocation
page read and write
360C000
trusted library allocation
page read and write
678E000
stack
page read and write
48C2000
heap
page read and write
26AE000
trusted library allocation
page read and write
90000
heap
page read and write
369D000
heap
page read and write
6E50000
heap
page read and write
3453000
trusted library allocation
page read and write
620000
heap
page read and write
65CE000
heap
page read and write
502C000
heap
page read and write
6586000
heap
page read and write
35B2000
trusted library allocation
page read and write
6747000
heap
page read and write
4E9000
heap
page read and write
69C8000
heap
page read and write
5AAE000
stack
page read and write
480000
trusted library allocation
page execute and read and write
69B5000
heap
page read and write
5063000
heap
page read and write
350000
heap
page read and write
2BD8000
heap
page read and write
A50000
trusted library allocation
page execute and read and write
66C0000
heap
page read and write
5B28000
heap
page read and write
6BF5000
heap
page read and write
480000
heap
page read and write
660F000
heap
page read and write
3606000
trusted library allocation
page read and write
736F000
stack
page read and write
2689000
trusted library allocation
page read and write
498C000
stack
page read and write
6370000
heap
page read and write
6891000
heap
page read and write
34F000
heap
page read and write
1D64000
heap
page read and write
64AE000
heap
page read and write
63DD000
heap
page read and write
1FD0000
direct allocation
page read and write
626F000
heap
page read and write
2BD4000
heap
page read and write
2A0000
heap
page read and write
6617000
heap
page read and write
1E0000
trusted library allocation
page read and write
5D3E000
stack
page read and write
24AE000
trusted library allocation
page read and write
3FD000
heap
page read and write
63A5000
heap
page read and write
36AF000
heap
page read and write
5620000
trusted library section
page read and write
215000
trusted library allocation
page execute and read and write
64F000
heap
page read and write
50B6000
heap
page read and write
6454000
heap
page read and write
4FCE000
stack
page read and write
65A5000
heap
page read and write
35CC000
trusted library allocation
page read and write
343000
heap
page read and write
3496000
trusted library allocation
page read and write
61B2000
heap
page read and write
6A8B000
heap
page read and write
48A4000
heap
page read and write
662B000
heap
page read and write
10000
heap
page read and write
6581000
heap
page read and write
462000
trusted library allocation
page read and write
250000
trusted library allocation
page read and write
662F000
heap
page read and write
2BBF000
stack
page read and write
627000
heap
page read and write
6A17000
heap
page read and write
6992000
heap
page read and write
6202000
heap
page read and write
64C7000
heap
page read and write
6F0F000
heap
page read and write
533E000
stack
page read and write
63D0000
heap
page read and write
6342000
heap
page read and write
6985000
heap
page read and write
490000
trusted library allocation
page read and write
2676000
trusted library allocation
page read and write
35DE000
trusted library allocation
page read and write
1E4000
trusted library allocation
page read and write
4FC0000
heap
page read and write
40A000
trusted library allocation
page execute and read and write
62F9000
heap
page read and write
880000
heap
page read and write
412000
trusted library allocation
page read and write
60BF000
heap
page read and write
6A79000
heap
page read and write
10000
heap
page read and write
67D000
heap
page read and write
6B2C000
heap
page read and write
60CE000
heap
page read and write
1D2E000
stack
page read and write
4E4E000
stack
page read and write
639D000
heap
page read and write
5E9E000
stack
page read and write
5F4E000
stack
page read and write
606B000
heap
page read and write
25CF000
trusted library allocation
page read and write
262A000
trusted library allocation
page read and write
64C0000
heap
page read and write
1D50000
heap
page read and write
34F8000
trusted library allocation
page read and write
10000
heap
page read and write
6050000
heap
page read and write
667A000
heap
page read and write
4FDD000
heap
page read and write
34A3000
trusted library allocation
page read and write
5920000
heap
page read and write
3542000
trusted library allocation
page read and write
646E000
stack
page read and write | page guard
60D3000
heap
page read and write
20A000
trusted library allocation
page execute and read and write
63A3000
heap
page read and write
655B000
heap
page read and write
3680000
heap
page read and write
65C8000
heap
page read and write
2BD0000
heap
page read and write
65DE000
heap
page read and write
4ABF000
stack
page read and write
A10000
trusted library allocation
page read and write
1DC0000
heap
page read and write
2BC8000
heap
page read and write
There are 559 hidden memdumps, click here to show them.