General Info

File name

Edwardo resume.doc

Full analysis
https://app.any.run/tasks/1ccb505b-27b7-4f88-b095-0ae625f472ee
Verdict
Malicious activity
Threats:

Dridex is a very evasive and technically complex banking Trojan. Despite being based on a relatively old malware code, it was substantially updated over the years and became capable of using very effective infiltration techniques that make this malware especially dangerous.

Analysis date
5/30/2019, 08:00:51
OS:
Windows 8.1 Professional (build: 9600, 64 bit)
Tags:

macros

macros-on-open

trojan

loader

dridex

Indicators:

MIME:
application/vnd.openxmlformats-officedocument.wordprocessingml.document
File info:
Microsoft Word 2007+
MD5

27d3e9403115ebc394906d266edfc9ac

SHA1

af436ace53070f9eec1ff5049a07b950b2fcd9e5

SHA256

60d5166aebf70bda86e0dd41b777be550ad364cd310cbad41780347b463b2689

SSDEEP

1536:nALxk6rxmqXx6UoRSUNLmoy2+u1b5bWONWU73SgfqxKi:Af9mPDLmoyKjcUu4qxKi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
600 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Who has a link
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 11.0.9600.19078 KB4339093
  • Adobe Acrobat Reader DC MUI (15.007.20033)
  • Adobe Flash Player 27 NPAPI (27.0.0.187)
  • Adobe Flash Player 27 PPAPI (27.0.0.187)
  • CCleaner (5.35)
  • FileZilla Client 3.31.0 (3.31.0)
  • Google Chrome (73.0.3683.75)
  • Google Update Helper (1.3.33.7)
  • Java 8 Update 92 (64-bit) (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft Office Home and Business 2013 - en-us (15.0.4433.1508)
  • Microsoft Visual C++ 2017 Redistributable (x64) - 14.11.25325 (14.11.25325.0)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.11.25325 (14.11.25325.0)
  • Microsoft Visual C++ 2017 x64 Additional Runtime - 14.11.25325 (14.11.25325)
  • Microsoft Visual C++ 2017 x64 Minimum Runtime - 14.11.25325 (14.11.25325)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.11.25325 (14.11.25325)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.11.25325 (14.11.25325)
  • Mozilla Firefox 66.0 (x64 en-US) (66.0)
  • Mozilla Maintenance Service (65.0.2)
  • Notepad++ (64-bit x64) (7.5.1)
  • Office 15 Click-to-Run Extensibility Component (15.0.4433.1508)
  • Office 15 Click-to-Run Licensing Component (15.0.4433.1508)
  • Office 15 Click-to-Run Localization Component (15.0.4433.1508)
  • Opera 12.15 (12.15.1748)
  • Skype™ 7.39 (7.39.102)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (64-bit) (5.60.0)

Hotfixes

  • CameraCodec Package
  • Client LanguagePack Package
  • Embedded EmbeddedLockdown Package TopLevel
  • Foundation Package
  • KB2894856
  • KB2919355
  • KB2920189
  • KB2931358
  • KB2931366
  • KB2932046
  • KB2934018
  • KB2934520
  • KB2937220
  • KB2937592
  • KB2938439
  • KB2938772
  • KB2939153
  • KB2949621
  • KB2954879
  • KB2958262
  • KB2958263
  • KB2961072
  • KB2962140
  • KB2962806
  • KB2965142
  • KB2965500
  • KB2966407
  • KB2967917
  • KB2968599
  • KB2971203
  • KB2973351
  • KB2975061
  • KB2976627
  • KB2976978
  • KB2977629
  • KB2977765
  • KB2978002
  • KB2978041
  • KB2978126
  • KB2978742
  • KB2981580
  • KB2987107
  • KB2989647
  • KB2989930
  • KB2990967
  • KB2994290
  • KB2998527
  • KB3000850
  • KB3001237
  • KB3003057
  • KB3003667
  • KB3004361
  • KB3004365
  • KB3008242
  • KB3011780
  • KB3012235
  • KB3012702
  • KB3013172
  • KB3013410
  • KB3013531
  • KB3013538
  • KB3013791
  • KB3014442
  • KB3015696
  • KB3016074
  • KB3018133
  • KB3019978
  • KB3020370
  • KB3021674
  • KB3022777
  • KB3023222
  • KB3023266
  • KB3024751
  • KB3024755
  • KB3027209
  • KB3029603
  • KB3029606
  • KB3030377
  • KB3030947
  • KB3031044
  • KB3032663
  • KB3033446
  • KB3034348
  • KB3035126
  • KB3036612
  • KB3037579
  • KB3037924
  • KB3038002
  • KB3041857
  • KB3042058
  • KB3042085
  • KB3043812
  • KB3044374
  • KB3044673
  • KB3045634
  • KB3045685
  • KB3045717
  • KB3045719
  • KB3045746
  • KB3045755
  • KB3045992
  • KB3045999
  • KB3046017
  • KB3046480
  • KB3046737
  • KB3047254
  • KB3048043
  • KB3053863
  • KB3054169
  • KB3054256
  • KB3054464
  • KB3055323
  • KB3055343
  • KB3055642
  • KB3056347
  • KB3059316
  • KB3059317
  • KB3060793
  • KB3061493
  • KB3061512
  • KB3062760
  • KB3063843
  • KB3064059
  • KB3067505
  • KB3071663
  • KB3071756
  • KB3074228
  • KB3074548
  • KB3075220
  • KB3076895
  • KB3076949
  • KB3077715
  • KB3078405
  • KB3078676
  • KB3080042
  • KB3080149
  • KB3080800
  • KB3081320
  • KB3082089
  • KB3083992
  • KB3084135
  • KB3086255
  • KB3087041
  • KB3087137
  • KB3087390
  • KB3091297
  • KB3092601
  • KB3092627
  • KB3095701
  • KB3097997
  • KB3098779
  • KB3099834
  • KB3100473
  • KB3100956
  • KB3102939
  • KB3103616
  • KB3103696
  • KB3103699
  • KB3103709
  • KB3108381
  • KB3109103
  • KB3109560
  • KB3109976
  • KB3110329
  • KB3115224
  • KB3115858
  • KB3121261
  • KB3121918
  • KB3126030
  • KB3126033
  • KB3126041
  • KB3126434
  • KB3126587
  • KB3126593
  • KB3128650
  • KB3132080
  • KB3133690
  • KB3133924
  • KB3134815
  • KB3137061
  • KB3137728
  • KB3138378
  • KB3138602
  • KB3138910
  • KB3138962
  • KB3139165
  • KB3139398
  • KB3139914
  • KB3140185
  • KB3140219
  • KB3140222
  • KB3140234
  • KB3144850
  • KB3145384
  • KB3146604
  • KB3146723
  • KB3146751
  • KB3146978
  • KB3147071
  • KB3149157
  • KB3150513
  • KB3153704
  • KB3155178
  • KB3155784
  • KB3156059
  • KB3159398
  • KB3161102
  • KB3161949
  • KB3161958
  • KB3169704
  • KB3170455
  • KB3172614
  • KB3172729
  • KB3173424
  • KB3175024
  • KB3178539
  • KB3179574
  • KB3184143
  • KB3185319
  • KB3186539
  • KB3187754
  • KB4033369
  • KB4034662
  • KB4040972
  • KB4041777
  • KB4054854
  • KB4093110
  • KB4338419
  • KB4338832
  • ProfessionalEdition
  • ProfessionalWMCEdition
  • RollupFix

Behavior activities

MALICIOUS SUSPICIOUS INFO
Downloads executable files from the Internet
  • wmic.exe (PID: 2296)
Downloads executable files from IP
  • wmic.exe (PID: 2296)
Application was dropped or rewritten from another process
  • awMiOFl.exe (PID: 1244)
Creates files in the Windows directory
  • WINWORD.EXE (PID: 932)
  • wmic.exe (PID: 2296)
Removes files from Windows directory
  • wmic.exe (PID: 2296)
Executable content was dropped or overwritten
  • wmic.exe (PID: 2296)
Searches for installed software
  • awMiOFl.exe (PID: 1244)
Creates files in the user directory
  • WINWORD.EXE (PID: 932)
Reads Microsoft Office registry keys
  • WINWORD.EXE (PID: 932)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.docm
|   Word Microsoft Office Open XML Format document (with Macro) (53.6%)
.docx
|   Word Microsoft Office Open XML Format document (24.2%)
.zip
|   Open Packaging Conventions container (18%)
.zip
|   ZIP compressed archive (4.1%)
EXIF
ZIP
ZipRequiredVersion:
20
ZipBitFlag:
0x0006
ZipCompression:
Deflated
ZipModifyDate:
1980:01:01 00:00:00
ZipCRC:
0x746ff8d9
ZipCompressedSize:
445
ZipUncompressedSize:
1635
ZipFileName:
[Content_Types].xml
XML
Template:
Normal.dotm
TotalEditTime:
6 minutes
Pages:
1
Words:
null
Characters:
1
Application:
Microsoft Office Word
DocSecurity:
None
Lines:
1
Paragraphs:
1
ScaleCrop:
No
HeadingPairs
null
null
TitlesOfParts:
null
Company:
home
LinksUpToDate:
No
CharactersWithSpaces:
1
SharedDoc:
No
HyperlinksChanged:
No
AppVersion:
12
Keywords:
null
LastModifiedBy:
pablo.warner
RevisionNumber:
10
CreateDate:
2019:05:22 12:44:00Z
ModifyDate:
2019:05:30 05:22:00Z
XMP
Title:
null
Subject:
null
Creator:
admin
Description:
null

Video and screenshots

Processes

Total processes
51
Monitored processes
5
Malicious processes
1
Suspicious processes
2

Behavior graph

+
start drop and start winword.exe wmic.exe conhost.exe no specs awmiofl.exe conhost.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
932
CMD
"C:\Program Files\Microsoft Office 15\Root\Office15\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\Edwardo resume.doc.docm" /o ""
Path
C:\Program Files\Microsoft Office 15\Root\Office15\WINWORD.EXE
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Microsoft Word
Version
15.0.4433.1506
Modules
Image
c:\program files\microsoft office 15\root\office15\winword.exe
c:\systemroot\system32\ntdll.dll
c:\systemroot\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\program files\microsoft office 15\root\office15\appvisvsubsystems32.dll
c:\program files\microsoft office 15\root\office15\msvcr100.dll
c:\program files\microsoft office 15\root\office15\appvisvstream32.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\rpcrt4.dll
c:\windows\syswow64\userenv.dll
c:\windows\syswow64\shell32.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\ole32.dll
c:\program files\microsoft office 15\root\office15\c2r32.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\sechost.dll
c:\windows\syswow64\sspicli.dll
c:\windows\syswow64\profapi.dll
c:\windows\syswow64\combase.dll
c:\windows\syswow64\shlwapi.dll
c:\windows\syswow64\gdi32.dll
c:\windows\syswow64\cryptbase.dll
c:\windows\syswow64\bcryptprimitives.dll
c:\windows\syswow64\imm32.dll
c:\windows\syswow64\msctf.dll
c:\windows\syswow64\shcore.dll
c:\windows\syswow64\oleaut32.dll
c:\program files\microsoft office 15\root\office15\wwlib.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.18790_none_dae0e7de5bc4763c\gdiplus.dll
c:\program files\microsoft office 15\root\office15\oart.dll
c:\program files\microsoft office 15\root\office15\msvcp100.dll
c:\windows\syswow64\d2d1.dll
c:\program files\microsoft office 15\root\vfs\programfilescommonx86\microsoft shared\office15\mso.dll
c:\windows\syswow64\wtsapi32.dll
c:\windows\syswow64\dwmapi.dll
c:\windows\syswow64\d3d10_1.dll
c:\windows\syswow64\d3d10warp.dll
c:\windows\syswow64\mscoree.dll
c:\program files\microsoft office 15\root\vfs\programfilescommonx86\microsoft shared\office15\riched20.dll
c:\windows\syswow64\nsi.dll
c:\windows\syswow64\rsaenh.dll
c:\windows\syswow64\bcrypt.dll
c:\windows\syswow64\winspool.drv
c:\windows\syswow64\iphlpapi.dll
c:\windows\syswow64\powrprof.dll
c:\windows\syswow64\cfgmgr32.dll
c:\windows\syswow64\msxml6.dll
c:\windows\syswow64\urlmon.dll
c:\windows\syswow64\uxtheme.dll
c:\windows\syswow64\winsta.dll
c:\windows\syswow64\dxgi.dll
c:\windows\syswow64\msi.dll
c:\windows\syswow64\kernel.appcore.dll
c:\windows\syswow64\d3d10_1core.dll
c:\windows\syswow64\windowscodecs.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\syswow64\clbcatq.dll
c:\windows\syswow64\ws2_32.dll
c:\windows\syswow64\cryptsp.dll
c:\windows\syswow64\wininet.dll
c:\windows\syswow64\usp10.dll
c:\program files\microsoft office 15\root\vfs\programfilescommonx86\microsoft shared\vba\vba7.1\1033\vbe7intl.dll
c:\program files\microsoft office 15\root\vfs\programfilescommonx86\microsoft shared\vba\vba7.1\1033\vbeuiintl.dll
c:\windows\syswow64\msimg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.18006_none_a9ec6aab013aafee\comctl32.dll
c:\program files\microsoft office 15\root\vfs\programfilescommonx86\microsoft shared\office15\msptls.dll
c:\windows\syswow64\d3d11.dll
c:\windows\syswow64\dwrite.dll
c:\windows\syswow64\version.dll
c:\windows\syswow64\netprofm.dll
c:\windows\syswow64\sppc.dll
c:\windows\syswow64\npmproxy.dll
c:\windows\syswow64\dnsapi.dll
c:\windows\syswow64\winnsi.dll
c:\windows\syswow64\setupapi.dll
c:\windows\syswow64\propsys.dll
c:\windows\syswow64\xmllite.dll
c:\windows\syswow64\iertutil.dll
c:\windows\syswow64\secur32.dll
c:\windows\syswow64\dcomp.dll
c:\windows\syswow64\bcp47langs.dll
c:\windows\syswow64\winmm.dll
c:\windows\syswow64\winmmbase.dll
c:\windows\syswow64\devobj.dll
c:\program files\microsoft office 15\root\office15\msproof7.dll
c:\windows\syswow64\sxs.dll
c:\program files\microsoft office 15\root\vfs\programfilescommonx86\microsoft shared\vba\vba7.1\vbe7.dll
c:\program files\microsoft office 15\root\vfs\programfilescommonx86\microsoft shared\vba\vba7.1\vbeui.dll
c:\windows\syswow64\wintrust.dll
c:\windows\syswow64\crypt32.dll
c:\windows\syswow64\msasn1.dll
c:\program files\microsoft office 15\root\vfs\systemx86\fm20.dll
c:\program files\microsoft office 15\root\vfs\programfilescommonx86\microsoft shared\vba\vba7.1\vbeuires.dll
c:\windows\syswow64\windows.globalization.dll
c:\windows\syswow64\scrrun.dll
c:\program files\microsoft office 15\root\vfs\systemx86\fm20enu.dll
c:\windows\syswow64\globinputhost.dll
c:\windows\syswow64\mscms.dll
c:\program files\microsoft office 15\root\vfs\programfilescommonx86\microsoft shared\proof\mslid.dll
c:\program files\microsoft office 15\root\office15\msohev.dll
c:\program files\microsoft office 15\root\office15\proof\1033\msgr3en.dll

PID
2296
CMD
wmic os get /format:"C:\\Windows\\Temp\\aXwZvnt48.xsl"
Path
C:\Windows\SysWOW64\Wbem\wmic.exe
Indicators
Parent process
WINWORD.EXE
User
admin
Integrity Level
MEDIUM
Exit code
3221225547
Version:
Company
Microsoft Corporation
Description
WMI Commandline Utility
Version
6.3.9600.16384 (winblue_rtm.130821-1623)
Modules
Image
c:\windows\syswow64\wbem\wmic.exe
c:\systemroot\syswow64\ntdll.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\nsi.dll
c:\windows\syswow64\sspicli.dll
c:\windows\syswow64\sechost.dll
c:\windows\syswow64\clbcatq.dll
c:\windows\syswow64\bcrypt.dll
c:\windows\syswow64\shlwapi.dll
c:\windows\syswow64\wininet.dll
c:\windows\syswow64\profapi.dll
c:\windows\syswow64\msctf.dll
c:\windows\syswow64\rsaenh.dll
c:\windows\syswow64\wbem\fastprox.dll
c:\windows\syswow64\version.dll
c:\windows\syswow64\mpr.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\iphlpapi.dll
c:\windows\syswow64\winnsi.dll
c:\windows\syswow64\rpcrt4.dll
c:\windows\syswow64\bcryptprimitives.dll
c:\windows\syswow64\wbem\wbemprox.dll
c:\windows\syswow64\wbemcomn.dll
c:\windows\syswow64\oleaut32.dll
c:\windows\syswow64\msxml3.dll
c:\windows\syswow64\urlmon.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\gdi32.dll
c:\windows\syswow64\imm32.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\shcore.dll
c:\windows\syswow64\wbem\wbemsvc.dll
c:\systemroot\system32\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\framedynos.dll
c:\windows\syswow64\combase.dll
c:\windows\syswow64\cryptbase.dll
c:\windows\syswow64\kernel.appcore.dll
c:\windows\syswow64\ws2_32.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\iertutil.dll
c:\windows\syswow64\userenv.dll
c:\windows\syswow64\uxtheme.dll
c:\windows\syswow64\dwmapi.dll
c:\windows\syswow64\cryptsp.dll
c:\windows\syswow64\wbem\wmiutils.dll
c:\windows\syswow64\wbem\xml\wmi2xml.dll
c:\windows\syswow64\jscript.dll
c:\windows\syswow64\wshom.ocx
c:\windows\syswow64\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.18006_none_a9ec6aab013aafee\comctl32.dll
c:\windows\syswow64\cfgmgr32.dll
c:\windows\temp\awmiofl.exe
c:\windows\syswow64\setupapi.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.18790_none_dae0e7de5bc4763c\gdiplus.dll
c:\windows\syswow64\playtodevice.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\mswsock.dll
c:\windows\syswow64\ondemandconnroutehelper.dll
c:\windows\syswow64\actxprxy.dll
c:\program files (x86)\common files\system\ado\msado15.dll
c:\windows\syswow64\propsys.dll
c:\windows\syswow64\dlnashext.dll
c:\windows\syswow64\devdispitemprovider.dll
c:\windows\syswow64\wpdshext.dll
c:\windows\syswow64\msdart.dll
c:\windows\syswow64\dnsapi.dll
c:\windows\syswow64\winhttp.dll
c:\windows\syswow64\secur32.dll
c:\program files (x86)\internet explorer\ieproxy.dll
c:\windows\syswow64\scrrun.dll
c:\windows\syswow64\sxs.dll

PID
2236
CMD
\??\C:\Windows\system32\conhost.exe 0xffffffff
Path
C:\Windows\system32\conhost.exe
Indicators
No indicators
Parent process
wmic.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Console Window Host
Version
6.3.9600.16384 (winblue_rtm.130821-1623)
Modules
Image
c:\systemroot\system32\ntdll.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\sechost.dll
c:\windows\system32\dwmapi.dll
c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.18006_none_623f33d3ecbe86e8\comctl32.dll
c:\windows\system32\conhost.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\sspicli.dll

PID
1244
CMD
"C:\Windows\Temp\awMiOFl.exe"
Path
C:\Windows\Temp\awMiOFl.exe
Indicators
Parent process
wmic.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
SPCtl DLL
Version
1, 0, 0, 9
Modules
Image
c:\windows\syswow64\winscard.dll
c:\windows\syswow64\combase.dll
c:\windows\syswow64\devobj.dll
c:\windows\syswow64\sspicli.dll
c:\windows\syswow64\bcryptprimitives.dll
c:\windows\syswow64\msctf.dll
c:\systemroot\system32\ntdll.dll
c:\systemroot\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\oleaut32.dll
c:\windows\syswow64\powrprof.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\rpcrt4.dll
c:\windows\syswow64\sechost.dll
c:\windows\syswow64\cryptbase.dll
c:\windows\syswow64\imm32.dll
c:\windows\temp\awmiofl.exe
c:\windows\system32\user32.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\gdi32.dll
c:\windows\syswow64\cfgmgr32.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\shlwapi.dll
c:\windows\syswow64\shcore.dll
c:\windows\syswow64\iphlpapi.dll
c:\windows\syswow64\nsi.dll
c:\windows\syswow64\winnsi.dll
c:\windows\syswow64\dhcpcsvc.dll
c:\windows\syswow64\ws2_32.dll
c:\windows\syswow64\shell32.dll
c:\windows\syswow64\psapi.dll
c:\windows\syswow64\wininet.dll
c:\windows\syswow64\iertutil.dll
c:\windows\syswow64\userenv.dll
c:\windows\syswow64\profapi.dll
c:\windows\syswow64\cryptsp.dll
c:\windows\syswow64\rsaenh.dll
c:\windows\syswow64\bcrypt.dll
c:\windows\syswow64\ntmarta.dll
c:\windows\syswow64\secur32.dll
c:\windows\syswow64\ondemandconnroutehelper.dll
c:\windows\syswow64\kernel.appcore.dll
c:\windows\syswow64\winhttp.dll
c:\windows\syswow64\crypt32.dll
c:\windows\syswow64\msasn1.dll
c:\windows\syswow64\mswsock.dll
c:\windows\syswow64\clbcatq.dll
c:\windows\syswow64\urlmon.dll
c:\windows\syswow64\dnsapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.18006_none_a9ec6aab013aafee\comctl32.dll
c:\windows\syswow64\schannel.dll
c:\windows\syswow64\wintrust.dll
c:\windows\syswow64\gpapi.dll
c:\windows\syswow64\ncrypt.dll
c:\windows\syswow64\ntasn1.dll
c:\windows\syswow64\cryptnet.dll
c:\windows\syswow64\wldap32.dll
c:\windows\syswow64\dhcpcsvc6.dll
c:\windows\syswow64\webio.dll
c:\windows\syswow64\rasadhlp.dll
c:\windows\syswow64\fwpuclnt.dll
c:\windows\syswow64\cabinet.dll
c:\windows\syswow64\ncryptsslp.dll

PID
588
CMD
\??\C:\Windows\system32\conhost.exe 0xffffffff
Path
C:\Windows\system32\conhost.exe
Indicators
No indicators
Parent process
awMiOFl.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Console Window Host
Version
6.3.9600.16384 (winblue_rtm.130821-1623)
Modules
Image
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctf.dll
c:\windows\system32\sspicli.dll
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\dwmapi.dll
c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.18006_none_623f33d3ecbe86e8\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\sechost.dll
c:\windows\system32\conhost.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\imm32.dll

Registry activity

Total events
2968
Read events
0
Write events
1928
Delete events
38

Modification events

PID
Process
Operation
Key
Name
Value
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\OnPremises
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINT\Metadata
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINT\Thumbnails
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINT
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINTGROUP\Metadata
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINTGROUP\Thumbnails
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINTGROUP
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINT\Metadata
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINT\Thumbnails
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINT
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINTGROUP\Metadata
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINTGROUP\Thumbnails
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINTGROUP
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\OFFOPTIN_DOCSTORAGE_LIMITED\Metadata
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\OFFOPTIN_DOCSTORAGE_LIMITED
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\OFFOPTIN_YOUTUBE\Thumbnails
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\OFFOPTIN_YOUTUBE
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT\Metadata
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT\Thumbnails
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP\Metadata
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP\Thumbnails
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER\Metadata
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER\Thumbnails
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\WLINBOX_SKYDRIVE\Metadata
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\WLINBOX_SKYDRIVE\Thumbnails
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\WLINBOX_SKYDRIVE
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\WLMOUNTED_CONNECT\Thumbnails
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\WLMOUNTED_CONNECT
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\WLMOUNTED_MARKETPLACE\Thumbnails
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\WLMOUNTED_MARKETPLACE
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\WLMOUNTED_SKYDRIVE\Thumbnails
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\WLMOUNTED_SKYDRIVE
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\Resiliency\StartupItems
932
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\WLMOUNTED_SKYDRIVE\Metadata
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\Resiliency\StartupItems
fx9
66783900A40300000100000000000000D17F5ADFBD16D50100000000
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\LanguageResources\EnabledLanguages
1033
Off
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\LanguageResources\EnabledLanguages
1033
On
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\LanguageResources\EnabledLanguages
11274
On
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word
MTTT
A40300006A3C62D9BD16D50100000000
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\Resiliency\StartupItems
i}9
697D3900A40300000400000000000000B1B20FE0BD16D5018C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\Roaming
RoamingConfigurableSettings
B800000000000000803A0900E307050004001E00080001001800AB02000000000000000000000000201C0000201C00008051010080510100805101008051010080F4030080F4030080F403002C01000084030000805101000000000084030000805101000A0000001E0000001E000000000000000000000080510100010000000100000000000000000000000000000000000000008D2700008D2700008D2700010000000A00000080510100000030000000300000003000
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\Roaming
RoamingLastSyncTime
E307050004001E00080001001800AB02
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\Roaming
RoamingLastWriteTime
E307050004001E00080001001800AB02
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
ProxyBypass
1
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
IntranetName
1
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
1
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\Resiliency\StartupItems
w`9
77603900A40300000600000001000000E6E786E0BD16D5018400000002000000740000000400000063003A005C00750073006500720073005C00610064006D0069006E005C0061007000700064006100740061005C006C006F00630061006C005C00740065006D0070005C006500640077006100720064006F00200072006500730075006D0065002E0064006F0063002E0064006F0063006D00000000000000
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache
SysLcid
11274
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT
Capabilities
2051
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT
ConnectMechanism
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT
ServiceOwner
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT
SortOrder
1
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT
CapabilitiesMetadata
<Metadata><DefaultBrowseRelativePath>/Documents</DefaultBrowseRelativePath><DefaultCreateRelativePath>/Documents</DefaultCreateRelativePath><DefaultFolderRelativePath>/Documents</DefaultFolderRelativePath><Type>SharePoint</Type></Metadata>
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT
Name
SkyDrive Pro
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT
ServiceId
ONPREM_SHAREPOINT
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT\Metadata
DefaultBrowseRelativePath
/Documents
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT\Metadata
DefaultCreateRelativePath
/Documents
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT\Metadata
DefaultFolderRelativePath
/Documents
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT\Metadata
Type
SharePoint
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT\Thumbnails
Tcid
18844
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP
Capabilities
16384
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP
ConnectMechanism
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP
ServiceOwner
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP
SortOrder
3
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP
CapabilitiesMetadata
<Metadata><DefaultBrowseRelativePath>/Documents</DefaultBrowseRelativePath><DefaultCreateRelativePath>/Documents</DefaultCreateRelativePath><DefaultFolderRelativePath>/Documents</DefaultFolderRelativePath><Type>SharePoint</Type></Metadata>
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP
Name
SharePoint
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP
ServiceId
ONPREM_SHAREPOINTGROUP
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP\Metadata
DefaultBrowseRelativePath
/Documents
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP\Metadata
DefaultCreateRelativePath
/Documents
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP\Metadata
DefaultFolderRelativePath
/Documents
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP\Metadata
Type
SharePoint
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP\Thumbnails
Tcid
18844
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER
Capabilities
1
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER
ConnectMechanism
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER
ServiceOwner
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER
SortOrder
2
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER
CapabilitiesMetadata
<Metadata><DefaultBrowseRelativePath>/Documents</DefaultBrowseRelativePath><DefaultCreateRelativePath>/Documents</DefaultCreateRelativePath><DefaultFolderRelativePath>/Documents</DefaultFolderRelativePath><Type>SharePoint</Type></Metadata>
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER
Name
Other SharePoint Sites
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER
ServiceId
ONPREM_SHAREPOINT_OTHER
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER\Metadata
DefaultBrowseRelativePath
/Documents
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER\Metadata
DefaultCreateRelativePath
/Documents
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER\Metadata
DefaultFolderRelativePath
/Documents
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER\Metadata
Type
SharePoint
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER\Thumbnails
Tcid
18844
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog
CacheReady
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog
LastRequest
2019-05-30T08:01:25Z
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\Place MRU\Change
ChangeId
1118177864
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\File MRU\Change
ChangeId
1460549464
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog
CacheReady
1
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog
LastUpdate
2019-05-30T08:01:25Z
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\ServicesManagerCache\ServicesCatalog
NextUpdate
2019-05-30T08:04:25Z
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\Resiliency\DocumentRecovery\EB7C3
EB7C3
04000000A40300003900000043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C00540065006D0070005C004500640077006100720064006F00200072006500730075006D0065002E0064006F0063002E0064006F0063006D00120000004500640077006100720064006F00200072006500730075006D0065002E0064006F0063000000000001000000000000000000000000000000C3B70E00C3B70E0000000000DB040000000000000000000000000000000000000000000000000000FFFFFFFF0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF0000000000000000
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\TypeLib\{D1509840-28C1-45C2-9AB8-2767E7FA123C}\2.0
Microsoft Forms 2.0 Object Library
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\TypeLib\{D1509840-28C1-45C2-9AB8-2767E7FA123C}\2.0\FLAGS
6
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\TypeLib\{D1509840-28C1-45C2-9AB8-2767E7FA123C}\2.0\0\win32
C:\Users\admin\AppData\Local\Temp\VBE\MSForms.exd
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\TypeLib\{D1509840-28C1-45C2-9AB8-2767E7FA123C}\2.0\HELPDIR
C:\Users\admin\AppData\Local\Temp\VBE
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
Font
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
Font
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
IDataAutoWrapper
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
IDataAutoWrapper
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
IReturnInteger
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
IReturnInteger
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
IReturnBoolean
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
IReturnBoolean
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
IReturnString
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
IReturnString
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
IReturnSingle
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
IReturnSingle
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
IReturnEffect
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
IControl
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
IControl
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
Controls
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
Controls
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
_UserForm
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
OptionFrameEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
ILabelControl
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
ICommandButton
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
ICommandButton
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
IMdcText
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
IMdcText
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
IMdcList
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
IMdcList
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
IMdcCombo
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
IMdcCombo
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
IMdcCheckBox
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
IMdcCheckBox
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
IMdcOptionButton
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
IMdcOptionButton
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
IMdcToggleButton
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
IMdcToggleButton
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
IScrollbar
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
IScrollbar
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
Tab
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
Tab
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
Tabs
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
Tabs
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
ITabStrip
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
ITabStrip
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
ISpinbutton
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
ISpinbutton
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
IImage
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLSubmitButton
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLImage
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLText
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLHidden
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLSelect
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLTextArea
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
CommandButtonEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
MdcListEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
MdcListEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
MdcComboEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
MdcOptionButtonEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
ScrollbarEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
TabStripEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
SpinbuttonEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
ImageEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
WHTMLControlEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents1
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents2
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents2
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents4
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents5
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents7
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents7
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents9
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
IPage
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
Pages
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
IMultiPage
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
IOptionFrame
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
IOptionFrame
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
ControlEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
ControlEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
FormEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
ILabelControl
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLSubmitButton
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLReset
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLReset
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLCheckbox
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLOption
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLOption
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLText
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLPassword
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLPassword
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLSelect
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
LabelControlEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
CommandButtonEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
MdcTextEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
MdcToggleButtonEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
TabStripEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
SpinbuttonEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
WHTMLControlEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents3
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents4
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents5
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents6
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents9
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents10
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
IPage
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
IMultiPage
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
MultiPageEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
IReturnEffect
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
_UserForm
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
FormEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
OptionFrameEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
IImage
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLImage
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLCheckbox
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLHidden
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLTextArea
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
LabelControlEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
MdcTextEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
MdcComboEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
MdcCheckBoxEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
MdcCheckBoxEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
MdcOptionButtonEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
MdcToggleButtonEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
ScrollbarEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
ImageEvents
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents1
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents3
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents6
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents10
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
Pages
932
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
MultiPageEvents
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@Arial Unicode MS
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@Batang
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@BatangChe
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@DFKai-SB
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@Dotum
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@DotumChe
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@FangSong
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@Gulim
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@GulimChe
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@Gungsuh
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@GungsuhChe
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@KaiTi
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@Malgun Gothic
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@Meiryo
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@Meiryo UI
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@Microsoft JhengHei
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@Microsoft JhengHei Light
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@Microsoft JhengHei UI
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@Microsoft JhengHei UI Light
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@Microsoft YaHei
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@Microsoft YaHei Light
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@Microsoft YaHei UI
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@Microsoft YaHei UI Light
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@MingLiU
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@MingLiU_HKSCS
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@MingLiU_HKSCS-ExtB
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@MingLiU-ExtB
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@MS Gothic
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@MS Mincho
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@MS PGothic
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@MS PMincho
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@MS UI Gothic
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@NSimSun
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@PMingLiU
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@PMingLiU-ExtB
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@SimHei
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@SimSun
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@SimSun-ExtB
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@Yu Gothic
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@Yu Gothic Light
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@Yu Mincho
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@Yu Mincho Demibold
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
@Yu Mincho Light
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Aharoni
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Aldhabi
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Andalus
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Angsana New
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
AngsanaUPC
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Aparajita
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Arabic Typesetting
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Arial
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Arial Black
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Arial Narrow
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Arial Unicode MS
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Batang
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
BatangChe
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Book Antiqua
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Bookman Old Style
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Bookshelf Symbol 7
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Bradley Hand ITC
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Browallia New
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
BrowalliaUPC
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Calibri
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Calibri Light
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Cambria
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Cambria Math
1
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Candara
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Century
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Century Gothic
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Comic Sans MS
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Consolas
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Constantia
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Corbel
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Cordia New
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
CordiaUPC
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Courier New
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
DaunPenh
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
David
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
DFKai-SB
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
DilleniaUPC
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
DokChampa
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Dotum
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
DotumChe
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Ebrima
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Estrangelo Edessa
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
EucrosiaUPC
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Euphemia
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
FangSong
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Franklin Gothic Medium
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
FrankRuehl
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
FreesiaUPC
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Freestyle Script
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
French Script MT
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Gabriola
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Gadugi
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Garamond
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Gautami
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Georgia
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Gisha
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Gulim
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
GulimChe
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Gungsuh
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
GungsuhChe
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Impact
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
IrisUPC
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Iskoola Pota
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
JasmineUPC
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Javanese Text
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Juice ITC
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
KaiTi
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Kalinga
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Kartika
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Khmer UI
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
KodchiangUPC
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Kokila
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Kristen ITC
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Lao UI
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Latha
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Leelawadee
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Leelawadee UI
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Leelawadee UI Semilight
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Levenim MT
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
LilyUPC
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Lucida Console
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Lucida Handwriting
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Lucida Sans Unicode
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Malgun Gothic
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Mangal
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Marlett
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Meiryo
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Meiryo UI
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Microsoft Himalaya
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Microsoft JhengHei
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Microsoft JhengHei Light
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Microsoft JhengHei UI
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Microsoft JhengHei UI Light
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Microsoft New Tai Lue
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Microsoft PhagsPa
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Microsoft Sans Serif
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Microsoft Tai Le
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Microsoft Uighur
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Microsoft YaHei
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Microsoft YaHei Light
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Microsoft YaHei UI
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Microsoft YaHei UI Light
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Microsoft Yi Baiti
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
MingLiU
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
MingLiU_HKSCS
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
MingLiU_HKSCS-ExtB
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
MingLiU-ExtB
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Miriam
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Miriam Fixed
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Mistral
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Mongolian Baiti
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Monotype Corsiva
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
MoolBoran
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
MS Gothic
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
MS Mincho
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
MS Outlook
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
MS PGothic
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
MS PMincho
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
MS Reference Sans Serif
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
MS Reference Specialty
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
MS UI Gothic
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
MT Extra
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
MV Boli
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Myanmar Text
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Narkisim
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Nirmala UI
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Nirmala UI Semilight
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
NSimSun
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Nyala
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Palatino Linotype
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Papyrus
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Plantagenet Cherokee
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
PMingLiU
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
PMingLiU-ExtB
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Pristina
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Raavi
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Rod
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Sakkal Majalla
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Segoe Print
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Segoe Script
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Segoe UI
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Segoe UI Black
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Segoe UI Emoji
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Segoe UI Light
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Segoe UI Semibold
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Segoe UI Semilight
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Segoe UI Symbol
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Shonar Bangla
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Shruti
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
SimHei
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Simplified Arabic
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Simplified Arabic Fixed
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
SimSun
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
SimSun-ExtB
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Sitka Banner
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Sitka Display
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Sitka Heading
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Sitka Small
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Sitka Subheading
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Sitka Text
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Sylfaen
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Symbol
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Tahoma
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Tempus Sans ITC
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Times New Roman
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Traditional Arabic
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Trebuchet MS
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Tunga
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Urdu Typesetting
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Utsaah
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Vani
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Verdana
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Vijaya
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Vrinda
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Webdings
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Wingdings
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Wingdings 2
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Wingdings 3
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Yu Gothic
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Yu Gothic Light
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Yu Mincho
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Yu Mincho Demibold
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\MathFonts
Yu Mincho Light
0
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\Security\Trusted Documents
LastPurgeTime
25986722
932
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\General
LastAutoSavePurgeTime
25986726
2296
wmic.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
ProxyBypass
1
2296
wmic.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
1
2296
wmic.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
IntranetName
1
2296
wmic.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
0
2296
wmic.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000005D000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
2296
wmic.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
CachePrefix
2296
wmic.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
CachePrefix
Visited:
2296
wmic.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2296
wmic.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
CachePrefix
Cookie:
1244
awMiOFl.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Controls Folder\PowerCfg
LastID
5
1244
awMiOFl.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
CachePrefix
Cookie:
1244
awMiOFl.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
IntranetName
1
1244
awMiOFl.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
ProxyBypass
1
1244
awMiOFl.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
0
1244
awMiOFl.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\15\52C64B7E
LanguageList
en-US
1244
awMiOFl.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
CachePrefix
Visited:
1244
awMiOFl.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
1244
awMiOFl.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000005E000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
1244
awMiOFl.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
1
1244
awMiOFl.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
CachePrefix

Files activity

Executable files
2
Suspicious files
2
Text files
1
Unknown types
3

Dropped files

PID
Process
Filename
Type
2296
wmic.exe
C:\windows\temp\awMiOFl.exe
executable
MD5: 4a75d90ba45f0755e0eb7200cadcef6d
SHA256: dcef8ecf6e93d1095cbf2624980edd1aa662c7986256947e79016ea284ce961d
2296
wmic.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\IFB0YWPX\5[1].exe
executable
MD5: 4a75d90ba45f0755e0eb7200cadcef6d
SHA256: dcef8ecf6e93d1095cbf2624980edd1aa662c7986256947e79016ea284ce961d
932
WINWORD.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\2ECCE926.png
––
MD5:  ––
SHA256:  ––
932
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\CVRAC97.tmp.cvr
––
MD5:  ––
SHA256:  ––
1244
awMiOFl.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
binary
MD5: 2c65cbbd4bb4b2011bbf88a9e08c9b8b
SHA256: c663ae9570875eeb5b1a451eafeb2baa75fa0afcd27b5c1f13adb8c79308f026
1244
awMiOFl.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
compressed
MD5: 7eb117d4f238090940dbe43efbcdf1f4
SHA256: a45a77d256628943190f8aa0f4673496d11dba6bc3569796b6f733465fd005e4
932
WINWORD.EXE
C:\Windows\Temp\aXwZvnt48.xsl
xml
MD5: b52d790f96fe1a504939d194c8de4c65
SHA256: 5984fdfdf8f180cd06db7ed978add90d805fedcab9bc1855f5b48a89895d487f
932
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\VBE\MSForms.exd
tlb
MD5: 730a2e4cf3e404b25c184eb1ccfef747
SHA256: e0ca8207bd4f5b5b7a4365c2084534c948519871bc36f34d830fb53272343af5
932
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\~$wardo resume.doc.docm
pgc
MD5: 69411b4f5a81d56c41db0abd39e54ab6
SHA256: 83ab612747ca35209876cc702ca735a311e85feda88282cd94da9681f6ee8420
932
WINWORD.EXE
C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
pgc
MD5: c62f740f1231e6e2d1c8ce104a5291a1
SHA256: 9cdd49c83203901c95c8eddd6b9d72d6bd6712a25fcd172b7214c0b142c21889

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
2
TCP/UDP connections
3
DNS requests
2
Threats
8

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
2296 wmic.exe GET 200 209.141.46.175:80 http://209.141.46.175/5.exe US
executable
malicious
1244 awMiOFl.exe GET 200 13.107.4.50:80 http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?c518e8a7ab1cb476 US
compressed
whitelisted

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
2296 wmic.exe 209.141.46.175:80 FranTech Solutions US malicious
1244 awMiOFl.exe 198.46.157.251:443 ColoCrossing US malicious
1244 awMiOFl.exe 13.107.4.50:80 Microsoft Corporation US whitelisted

DNS requests

Domain IP Reputation
www.microsoft.com 2.21.41.70
whitelisted
ctldl.windowsupdate.com 13.107.4.50
whitelisted

Threats

PID Process Class Message
2296 wmic.exe A Network Trojan was detected ET INFO Executable Download from dotted-quad Host
2296 wmic.exe A Network Trojan was detected ET TROJAN Single char EXE direct download likely trojan (multiple families)
2296 wmic.exe A Network Trojan was detected ET CURRENT_EVENTS Possible Malicious Macro DL EXE Feb 2016
2296 wmic.exe Potential Corporate Privacy Violation ET POLICY PE EXE or DLL Windows file download HTTP
2296 wmic.exe Potentially Bad Traffic ET INFO SUSPICIOUS Dotted Quad Host MZ Response
1244 awMiOFl.exe A Network Trojan was detected ET TROJAN ABUSE.CH SSL Blacklist Malicious SSL certificate detected (Dridex)
1244 awMiOFl.exe A Network Trojan was detected ET TROJAN ABUSE.CH SSL Blacklist Malicious SSL certificate detected (Dridex)
1244 awMiOFl.exe A Network Trojan was detected MALWARE [PTsecurity] Dridex/Feodo SSL connection

Debug output strings

Process Message
–– SHIMVIEW: ShimInfo(Complete)
–– SHIMVIEW: ShimInfo(Complete)
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...
–– Installing...