98
Malicious
This predictive confidence of maliciousness for this sample is 98%.
5c334953fe87a0c6c8115f4b5f1655e005e8b5d5e3bd9903c19a666e3c0c76ef
509.6 kB
2020-08-27 12:07:59
First seen 6 days ago
Microsoft Word

Classification

Full Detail

Ransomware
Low
Trojan
Low
Virus
Medium
Banker
Low
Bot
Low
Rat
Low
Adware
Low
Infostealer
Low
Worm
Low
Spyware
Low

Indicators

Expand All

DeepView™ Indicators
Forced Code Execution
Automatic Sequence Detection
Program Level Indicators
Anti-Analysis
Attempts to repeatedly call a single API many times in order to delay analysis time
Anti-Sandbox
Tries to suspend Cuckoo threads to prevent logging of malicious activity
Anti-Vm
Checks amount of memory in system, this can be used to detect virtual machines that have a low amount of memory available
Checks adapter addresses which can be used to detect virtual network interfaces
Downloader
The process winword.exe wrote an executable file to disk which it then attempted to execute
Dropper
Drops a binary and executes it
Dyndns
Connects to a Dynamic DNS Domain
Generic
One or more potentially interesting buffers were extracted, these generally contain injected code, configuration data, etc.
Creates executable files on the filesystem
One or more of the buffers contains an embedded PE file
Http
Performs some HTTP requests
Injection
Executed a process and injected code into it, probably while unpacking
Network
Performs some DNS requests
Packer
Allocates read-write-execute memory (usually to unpack itself)
Creates a suspicious process
Program-Level-Features
This Word file is detected by OfficeMalScanner as malicious.
Recon
Queries for the computername
Looks up the external IP address
Stealth
A process created a hidden window
Vba
Office has Embedded Executable (Most likely in an OLE Object)
Libraries known to be associated with a CVE were requested (may be False Positive)
Virus
An office file wrote an executable file to disk

Static Analysis


Strings

  • [Content_Types].xml
  • gsllNEb
  • _rels/.rels
  • word/_rels/document.xml.rels
  • word/document.xml
  • word/media/image1.emf
  • |nlsI7
  • word/embeddings/oleObject1.bin
  • FETBeTA
  • C}4@C4Bc4AS
  • oaMr-e
  • r 'r!7"
  • .HEWtCw
  • a9V`%Va5
  • TtE7tG
  • FETBeTA
  • C}4@C4Bc4AS
  • )Wyx}i=
  • ^MNeu|
  • ny3f35
  • W5<okq_
  • o6jX?]5
  • EM$#=ynF
  • yEWsN.*gh
  • ~/LaIfq
  • 1lE7!
  • w'Og~}x
  • 6G2nz~
  • 3>EW{<F
  • 5Jc5i*#p
  • #?>BWS
  • dc[Ty{
  • D|gCk-
  • =b=e/+
  • Upo)C{
  • gn gH#3Prs
  • ^%VJ!I
  • &TZsSkm
  • ![|:qd
  • P*zB[a
  • :`]YQ2
  • (q{vEx|
  • \QT@sZ
  • <'[788
  • Q"ao.b
  • SDP'}[Eu
  • ]M{o?m
  • .kq.y
  • XR`W{*
  • o|x','u
  • ijo>RS
  • l.:qO&L
  • MVIQ-r
  • 58lmi(
  • PP_K44
  • UJG^jh
  • ;KSwg{
  • |*491L
  • /B.'dN
  • aD/nV\
  • ^+|05p'm
  • N\;*5x
  • @$z7.X
  • fF?VhYz"
  • w=S2r:
  • h9^+0
  • 4jq|e3
  • (Mu-,31
  • X.a]+%
  • c2=juG+
  • l$*ljJ
  • M.%2/U
  • 9.;qBD
  • ,{jHV:
  • $~hB(s
  • %FXb^
  • =\X9%2b
  • L!9Bc@|
  • mjJyYlMX
  • %8=#i@p
  • nGHY>J
  • dF;2Os
  • ~*3C~"
  • F)Y-iZ3
  • p$@YoJ
  • (>7A"H
  • |yN#VC
  • {CcoA%
  • Z8Z,Rp
  • $4SoI3e
  • )qLO1E
  • G4(I~7
  • g~c0$(|
  • [5&OU&
  • +J<<yH
  • 0jG~C
  • snL1E^)n s
  • 49z{-A
  • O,`,\m8
  • -l+"y0
  • \(%=g
  • c%?Na/
  • {Oo59Yx:
  • G*\eo4
  • |YfmEA
  • )-lpaJ.
  • -TEl4Px^
  • m" <A+
  • I''cH5
  • <`@zUs
  • xy;4?V
  • =)wZXh
  • 'E@MR}'
  • at/0=3
  • a$=C!]
  • -t%@h~`
  • \X~,k(
  • ('*K;k
  • IZN>xD
  • a{/e;^
  • 8es<Rg
  • RE!(jseL@vB
  • !/3*<[
  • >?QMZ6Q
  • JFwn<-
  • h4r#9b
  • <Kp')CI
  • |(SLmi
  • t?4w4c
  • F\c3/\
  • 7'3nb<
  • `w\W4`S
  • \ICeI)
  • ]>Lzy!
  • FGtpk[
  • avy4y}
  • %2-Ly
  • "F$?YET
  • 0R1cDz_
  • 1\l2@~
  • {{A#u3"B&
  • MFiC6[
  • =!Sytc7
  • <k=c&,Ez
  • b&_6?%
  • qrwz2`R;
  • J"gY3!M
  • P]/EDw
  • OYTQBy
  • Owrkf%6n?(2[
  • i|u2x1#
  • @w.u_jX
  • 8u~!Vy
  • m8XOgY
  • pvh]bSw<
  • =&hsS)
  • $bgNqJf
  • Nw#zvjD|
  • v0hT3B
  • I2hs?6K
  • _NatE8
  • ^Ra|x/we
  • C-n+-x
  • .(sqU+g
  • L[@^`+#
  • FsJ3Js
  • R8,x=g
  • !yg-OV
  • Qoufbj7im
  • lW/G"B
  • .2Qa))Cv0
  • $/p@>P
  • 2rSa)
  • &);.(_
  • E)$[f2=m
  • >AfP3>
  • =IhJ$p
  • Fgg5_B
  • q]t%9]
  • )hKE"j
  • {0{XMe
  • M<s."Y@
  • V&0@g?=Q
  • J5|.T jo
  • ret<3(|
  • d0V1&[x)
  • )6NzBj
  • K,)mBrO
  • %{cjX:
  • 5z5X'j q
  • S:g^!L
  • M'Raf
  • pIdVE!
  • 90Z}!G
  • J5QMOd
  • -sj?1O#
  • OJ?bS-
  • j1hL*rQZ|
  • IK)Y<@p
  • rl^6Bf
  • Gpsk e@4
  • caluwe
  • =bAA95
  • mAP9g
  • g5vc4Z
  • :61Al+e
  • Z U1~H
  • #,:DJR4
  • :MtUNPv
  • 0C<d3qi
  • ,Ov*,@
  • K@As0K
  • <7Odpo
  • :yhW>ey
  • L`na./u
  • LbXPgG
  • `a^<"$F
  • s,|-zF
  • 2[qy'B
  • m@wIf
  • i,Z-x-~!#)([%
  • ?r\wN
  • h%w$pk
  • q+cfHod
  • ,+<)hY
  • O%#5q#
  • sx.OB%o7
  • o<-[Ih~
  • 1w.'}4X
  • uW0_[B
  • 5G~&0i
  • K,P0}Br
  • l*R&WQ
  • UDnnfG
  • .s}<1[
  • .[:fc3a4
  • V2Pi%E
  • [F8ZrP
  • }s7c~;
  • ~'`t,O
  • p[cJV|
  • $3Dc5R
  • T'scZ#
  • #m^E%3@
  • pgz3?g
  • OAJ$EM
  • B]NpG7
  • D+F"~n
  • ^@>i8(
  • 63@}+ke
  • @\W0;G9d
  • ?6NHCF
  • N#?Q|!
  • Eb\!i';9e"
  • t!!gD]
  • >}N{a5
  • k8G$A?
  • {[gsG*
  • f6z,a`
  • GVc,Kj
  • cr80I@
  • &xI&smn
  • (R#bM_
  • VT1$av
  • /j|gQ|}2
  • Y8&%F
  • Y|L7sR
  • !Pk%/SB
  • (,w(Rm
  • gppJ'Cl
  • \~N+`[
  • 'UqQf#
  • m%fO2f
  • PC8`8>
  • 2^@N~kI
  • D@E.w<
  • xx)[}G
  • )FElChd
  • v|:Cy#
  • l!n~8~*
  • pVM9JW
  • OpK5"Iq
  • -Kgqy6
  • 1E{&m6
  • 3am6xUG
  • mR^tsl
  • N]g3.Xr
  • <gCLS8
  • M#yvm=
  • .\@BU;
  • 6"o_.I
  • EjO$*5
  • b^=[Z#
  • Tn~GRC
  • ufW,pt
  • DM|GtA_
  • 9l!+t$
  • :y3^Pb
  • D1O4FD
  • 6g~Kq0
  • 6AwE6]
  • 7$wobk
  • <e`N9W
  • [4+n.c
  • L kc>9]
  • l'_N%s
  • 0"%Fc%
  • 3qv<Ne
  • PB3> 2
  • xp-m3]{
  • **U)Lx
  • ?2}C;ug
  • W#>8nb
  • wa1`0_
  • HV$2c)]_
  • &tu3Dm;a
  • ~QETl&W
  • J4tAx
  • $lq7k\
  • ypb&#/
  • nf2L[!
  • m6V.!lt
  • T6.7etB
  • aJ=G= 5
  • ObF,|&(
  • #Gre`5.
  • uQu|9SkKh
  • d/;.Up
  • Y NYG%}
  • +=FK~*c
  • iT*$r}m#
  • ?r'Zx$
  • Ot&WvF
  • au}6a{
  • d)k.(07H
  • +z&$f~
  • =T*I1@8
  • x$TOQq
  • pIl"70(,S
  • Kd1q7[
  • >Ggi0iY
  • W<|HKz
  • <w):A:${
  • zloNdO
  • GEE)sn{S
  • C^'=Cil/
  • 5qsp8/
  • Cv2uW4
  • lh~[FQo)yk
  • sb3?-{1J
  • v`')]g
  • (T(JFH
  • $'x.3z
  • _fDJRl
  • ogqYh4>VO
  • od_>Da
  • JFH.KO
  • *5'_m/]
  • E`{|)}e^sQ
  • U^\.Oa
  • w>FTI>
  • Fu1(&
  • uAX>T`)E
  • B:`:#}
  • TH3R/E
  • O1at)
  • uA0{3
  • 5X{e3'
  • O];4e6
  • LduA,N
  • 1Lol$2
  • cr-Yd1
  • X(a6l.
  • #Y9Nox
  • q4W`Qo
  • AqY.)g
  • L[N_x;
  • '<&HD3
  • W\%3t<
  • [O?>Y_
  • }27Mg1i
  • S"6`\l
  • dYEpOw2
  • &$\_1w
  • ut;/F~
  • ~a\j9_^H
  • Ts]@jN1)
  • 9o#EBu
  • X)yb\7
  • {\0w>A
  • spM."s
  • +Ky5h:
  • .&<TbZ
  • ?E:y(#
  • S&DP+5
  • ~'Y6m)
  • cf_}T>,G
  • 6qoz9WN
  • ]/p(yT
  • 39st!G
  • kAYD(rv
  • ;'~22d!
  • -<o2DnH
  • t9'dEzi
  • wg_3yW
  • nw'mSs
  • bK$>WB
  • ]#V"9y"
  • ^~ZAyS
  • [~X 9t
  • )~9XRh
  • ,&P{}=bj1<
  • 'VY^x5
  • K0'99x
  • ljCKw:
  • >K#{1I?
  • !6o{Oy
  • #.I\3zKh]
  • x1v6#IL
  • !S><^I
  • aV(wcz
  • }go\^
  • [X$J@k_"t|
  • 3)`Ac~
  • 0Ut*=C
  • 2&3RH?k
  • Nuffq2
  • 664zo!
  • r9\+wSihL
  • e)jODuX$
  • e*3fy(7
  • 83t$KG
  • q^c7}^#l
  • MF@GUDG
  • 4DP`-h*H
  • st?GG6
  • KE~`\S
  • \',VO'v
  • q:ZZI=$
  • jlckU<
  • #W~1da
  • nkCje*
  • '<,|Ij.e
  • :h6O|6"
  • +zZl83
  • q$/ECy
  • =Us8/1
  • UtLF{k
  • k=Gy=`,
  • OIghg<e
  • rb?.,5
  • -i"%l#y
  • diI0FFI
  • Agb#cO-
  • cBTC,9
  • Th*>#Sx
  • qO9$n>!
  • 98hM$F
  • JLBv@$W
  • v+0RpO
  • a)knLt
  • U":.q4
  • JX[,'`
  • XL-C-K
  • _ab*4X5
  • "*f;~~
  • /&2`t>
  • ?#DPS_
  • :c?3~D;v
  • 8;S59ZPO
  • 5b|vS7
  • J1]n$3D
  • #}G1(9
  • 5\t6#~S
  • _Rnuq$u({&>
  • Ioq"F~'
  • 3d9YK
  • ]`NcNZ
  • FvnL#,t6
  • c[":-n
  • hpsb<g
  • {prlB=
  • x&<4cH
  • B~V&^{Th
  • l'Lw+v
  • <MIyoF
  • @a;OE;
  • T/ogJR
  • sv6[o?E4"
  • /\$/j*
  • #5xtSPW1
  • Lb]E(0
  • Sk_3kU.
  • '3}>m]
  • _L9'JO
  • fTJ5k.
  • Wn0UVk
  • dx?VT~%h
  • \3Nq5i:
  • q~#X2o
  • t<kZpvZ
  • $_pG~/
  • ;1;yrr
  • ~n?hL3F
  • m77T<g
  • "MEi()
  • (<YHc_
  • acG0c>
  • D6O>BC
  • e;-qo^
  • Qa<K~q
  • ftJSq,Z
  • "cr^rZr
  • r$[W\@m
  • KN1\b&
  • +Nr/z&;
  • |hQ7Fw
  • L.:93*U
  • BD]!W&H
  • %qR$7p,q
  • "O^qsj<
  • 3tYyj9o
  • 1hK#>nn$
  • H$n&G8^*
  • )Til$n
  • n|]6r:
  • CFkbd{
  • <G4M0;r
  • gf(bf~
  • JXZ+g#f
  • )3~b88
  • dS6a%+M
  • [hi?&-N
  • @Jl:mF
  • FcrQQ`
  • x^.fJn&
  • S]_G_M
  • )J}BER
  • g}<(u[O
  • byO6>/bZn
  • "/x<zY
  • eLp(eQ
  • au?!d\
  • =}}09~
  • avb33,s8U:
  • oSIf}]
  • 0+F{e;
  • JJDVQ*TJ
  • .a$R}I
  • ^\eI{5
  • Ks}nw>
  • =MOj`<b$Z[
  • c1K*\y
  • h:Ol=P
  • N3GlC(
  • d`W,{{
  • #*1U*#
  • a#QQ}@
  • IT[Xb
  • ]HN]>.R
  • %F&H{\f
  • $vib,H
  • }W|?W2l
  • Zg-A##
  • ^2xxg`U+
  • =FHJ,s"
  • S$ElcNU
  • T8-"Q1
  • \)k&Gp
  • D{?dVL
  • ao/0L>
  • czN!"o
  • m,'gkQ7M
  • [??B.~8
  • M$Ri-B=9
  • Kf7%)>
  • XbD'1Q
  • Q`a5Ws
  • 00d>*e
  • ~,}vO`
  • S' .i^
  • `Av6/B\
  • mXW!f
  • [Dyq:W
  • %:KfQ/|
  • DlP1/E
  • }?Bo,p
  • cCf =O
  • bZ]#qP/$
  • :}7T#Z
  • ;L jn(;&
  • l.~Jbyy*&>
  • b8z33,=
  • ZL~~eiS%s
  • wa\[$D
  • 9>v9*/=
  • jN[U:ug
  • +ejx$8#
  • /'Nl-f
  • +?21zW
  • umc9T1
  • yl L@^
  • wn1*mg0
  • e4EDZ2
  • .F8m(o
  • 6/W#2&
  • GDo?#}p
  • |:[Iqa
  • !Efu7G
  • *l?zG=
  • _Vglbb
  • +c3vzE
  • Fle+ez
  • wy~m$V"
  • Uoq7)e
  • f4&k^R*
  • A8X53-?
  • _`GGz")
  • `(Gbq&
  • OlgQ?8
  • =\P(gH
  • Xj)(PK
  • 7sbV87
  • s)~ f?
  • C{Q!Kv
  • ,cn$|!9
  • g2qM.M
  • B%Wp1f
  • &'r;GS;
  • 2svM hD
  • Q3j5u93_
  • Ovt+1{?
  • g/St^1
  • ldUby7
  • F`,)$f>
  • '$Jsq{>
  • vULZKX
  • {sON]:O
  • X-nr_Yl{
  • MmYHn}
  • 45jf3;
  • :]@9IM,
  • W4)Wfp_
  • G'/ op1
  • <|'$4
  • %sj~>b
  • &VaVj6U
  • 3Gy"f0
  • ACC0QYu\
  • w\"y+U
  • 7~tqU{/
  • q:dwpF
  • $pt!a*
  • $d.Tpo
  • v}^rc
  • o(1+<y1
  • j)($:#>T
  • )5BY}6
  • GkH&{o
  • N~h;'#T
  • t|uDcc
  • Y7Vuo8
  • B%>>N%
  • cYK'"y9\
  • #z3kB
  • l{BD_K
  • ^I{Z(G
  • W*'-n0
  • j^Eg"#
  • ^#>n,{
  • eH~;6}O
  • XQM2{?
  • ddvpM<
  • dRHTKD
  • ;;6V";
  • o(mmBs
  • cLh>OV
  • E&n&Qs
  • %S0j8O
  • *.B8\Y
  • sY1OTc
  • 0B%g9hl
  • LXXnKM
  • a?e&*
  • Axn`V
  • t]@yO=f
  • E[vs,c
  • 4Ne-&`
  • S,?pr\6
  • i5wZ_1Hw,
  • DP8=1,=t
  • CcFp&2
  • <|4_EL
  • $4Dp$B
  • g|S/K
  • Fl76qP
  • ~`k7Ob
  • CEf9TSUu
  • c"U,H<q
  • T;i!Y]
  • op2/!/,
  • 3xy2bB~
  • Qt+w _
  • k pi<[
  • 0|7qg3P
  • 'n.$uF"\-
  • s>70nK
  • .aG^]&A
  • A(eD"m=
  • gs>_hd
  • U(U'Nq
  • ,pNFEW
  • c'EbwY]
  • kS:0hI
  • Z|oF Z
  • fRM-h/3
  • CU}VJw
  • OI2lCV'
  • c,!Kq{
  • -dlk_:
  • qu/vh
  • Rx'(sey
  • au`0_?]
  • *=Lta4
  • yj5e#kYa
  • ew9?z4
  • pO1ePm
  • Hg$_>}
  • ^a]oEH_9d
  • r%I$%Va:z1
  • deE)o'4
  • sh)vdXQ
  • F%,[ZK@
  • 4A`=ayK1i)
  • ;FvzTO
  • &yg2Z
  • ap_'}c\
  • ^G_$`
  • {/x`{c4
  • 5QAX;S:
  • {)L|Ni
  • hF8qSZ
  • }E+F}s
  • oOChm!.
  • .g:y<4
  • {Gz0bt;
  • \x+OEc
  • 6A`L#7
  • Jg^35
  • 3'b1m?
  • 8@[U;{.
  • +[H2Va5
  • 27=y6h
  • k+b8u{/
  • >><RB}
  • ^ r`-E
  • .Sxm/K
  • X/BS[9{
  • e_(1SM
  • /MIDAT
  • $n2g7g
  • S1MRf[
  • w2xw""S
  • n<[_^A
  • ^xG8b|
  • jKyX)W.
  • &ee=A9
  • w"=(/-
  • VF;m j
  • &*k2iygI5
  • rJ0[a(Z/gR
  • aH\B4)
  • G0G~).O
  • 7quZ>1
  • mF_P?[NcG;
  • tuf?S"
  • 3%9UH7
  • b\<ZS58
  • .u42w#w
  • .g?FkT
  • )T$)ZE
  • ty'&Yuqa
  • xw0snG
  • &Y*16P
  • g:$3gV1
  • 5zkakT
  • W#/Wa;
  • 3RF<YY
  • oDkKHS
  • Az#];T
  • N(U{Twq
  • I%e*Ta
  • *Y0hF5
  • I.<s|f
  • L+/AXk7
  • ^,$<i!
  • 2YmERe
  • (9A!:M
  • QD(U9[W
  • s?c5xS
  • %Y`/jR
  • $+Zr:?
  • 80V-\f
  • o,`~\`\
  • ZW)7uB
  • *L0WUWu
  • DWVzle
  • Q'<Z@
  • nfR9$6
  • d@;!e
  • ZUlrW8M
  • 1M\Al
  • ;^i5(h
  • ehUTWnA
  • ^tt*:C
  • 9W?0]*
  • DisJap
  • we+>w]
  • op=/!ze
  • ]W%O)r
  • ;nL/q}p
  • "%.kOz0
  • n~}zf7
  • :z]tVtA
  • 52+/kn
  • |YeayEi
  • va2IYQ
  • RuJ^)l
  • 93j.7z
  • -~xfX#
  • Ka-%|(
  • Pqh~:Cq
  • s3qN?g
  • ,^YQ<vIyI!
  • J7ilyY
  • _nfqleE
  • &AO)XS
  • $IS*>X=
  • R|64fDg"
  • XPVT*O
  • !o5XCEhh4
  • z#|JP5
  • 9Sj+u"
  • nD;t7K
  • $-L@K-
  • =\\oM<
  • nLO=xz
  • _{=$=
  • k,#^tr
  • HxzC/)q
  • YmyG~0
  • x>0>6|
  • ,f<t\
  • IGI&]{
  • ~#(hcA
  • aBPb78
  • ''&TOq
  • >T<_iu
  • U}{~zL
  • `!fmqE
  • th6UH&
  • B/^S2Bv
  • Q~CN'"
  • Q'[aZ&
  • \FWl\h
  • word/theme/theme1.xml
  • _N?>}
  • zY(6i4[
  • word/settings.xml
  • G'o$crO
  • word/webSettings.xml
  • |pm*).-]
  • docProps/core.xml
  • word/styles.xml
  • w<j0y
  • 5/e"[c&
  • F4nu~R
  • i5+[MkI
  • g/D{{Ntz
  • q`TyfaTyfaTyfaTyv
  • eR*Etnms
  • !*Ljx(
  • word/fontTable.xml
  • cV0vKG
  • L9xg68p
  • docProps/app.xml
  • [Content_Types].xmlPK
  • _rels/.relsPK
  • word/_rels/document.xml.relsPK
  • word/document.xmlPK
  • word/media/image1.emfPK
  • word/embeddings/oleObject1.binPK
  • word/theme/theme1.xmlPK
  • word/settings.xmlPK
  • word/webSettings.xmlPK
  • docProps/core.xmlPK
  • word/styles.xmlPK
  • word/fontTable.xmlPK
  • docProps/app.xmlPK

Dropped Files


Name
403f314d25f96d8c_specification order 7453214.exe
Size
576.5 kB
Type
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5
2fabf94fbce44b4a2c2b49c99e098d85
SHA1
8a30baa96424d8a7aaba2a48254081e858b021ac
SHA256
403f314d25f96d8c021c153b97dae233b1f218fc1c68c2284e4e16daaff24ddb
SHA512
e8d2116ad0f27479322ff7cbc876dabc2859c2f1b21ad7b95afd8b395ffc1c3c6c1b01129b14e3ba9c9ab44ffee9feca44c54c594de4a89e15f82ed4923e4d05
Ssdeep
12288:qT5QvdzERPTr4ogh57xEgvfiZaBZoiniUZJHSiWzIrEW4:s6GRPPmPf+1PEL

Network


DNS Requests

Domain IP Address Destination Location
checkip.dyndns.org 216.146.43.70 US
freegeoip.app 104.28.5.151 US

HTTP Requests

GET / HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
Host: checkip.dyndns.org

GET / HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
Host: checkip.dyndns.org
Connection: Keep-Alive

Hosts Involved

IP Address Country of Origin
216.146.43.71 US
172.67.188.154 US

Geolocation

Destination Country


US:
100%
AfghanistanAngolaAlbaniaAlandAndorraUnited Arab EmiratesArgentinaArmeniaAntarcticaFr. S. Antarctic LandsAustraliaAustriaAzerbaijanBurundiBelgiumBeninBurkina FasoBangladeshBulgariaBahrainBahamasBosnia and Herz.BelarusBelizeBoliviaBrazilBarbadosBruneiBhutanBotswanaCentral African Rep.CanadaSwitzerlandChileChinaCôte d'IvoireCameroonCyprus U.N. Buffer ZoneDem. Rep. CongoCongoColombiaComorosCape VerdeCosta RicaCubaCuraçaoN. CyprusCyprusCzech Rep.GermanyDjiboutiDominicaDenmarkDominican Rep.AlgeriaEcuadorEgyptEritreaDhekeliaSpainEstoniaEthiopiaFinlandFijiFalkland Is.FranceFaeroe Is.MicronesiaGabonUnited KingdomGeorgiaGhanaGibraltarGuineaGambiaGuinea-BissauEq. GuineaGreeceGrenadaGreenlandGuatemalaGuamGuyanaHong KongHeard I. and McDonald Is.HondurasCroatiaHaitiHungaryIndonesiaIsle of ManIndiaIrelandIranIraqIcelandIsraelItalyJamaicaJordanJapanBaikonurSiachen GlacierKazakhstanKenyaKyrgyzstanCambodiaKiribatiKoreaKosovoKuwaitLao PDRLebanonLiberiaLibyaSaint LuciaLiechtensteinSri LankaLesothoLithuaniaLuxembourgLatviaSt-MartinMoroccoMonacoMoldovaMadagascarMexicoMacedoniaMaliMyanmarMontenegroMongoliaMozambiqueMauritaniaMauritiusMalawiMalaysiaNamibiaNew CaledoniaNigerNigeriaNicaraguaNetherlandsNorwayNepalNew ZealandOmanPakistanPanamaPeruPhilippinesPalauPapua New GuineaPolandPuerto RicoDem. Rep. KoreaPortugalParaguayPalestineFr. PolynesiaQatarRomaniaRussiaRwandaW. SaharaSaudi ArabiaSudanS. SudanSenegalSingaporeS. Geo. and S. Sandw. Is.Solomon Is.Sierra LeoneEl SalvadorSan MarinoSomalilandSomaliaSerbiaSão Tomé and PrincipeSurinameSlovakiaSloveniaSwedenSwazilandSint MaartenSyriaChadTogoThailandTajikistanTurkmenistanTimor-LesteTongaTrinidad and TobagoTunisiaTurkeyTaiwanTanzaniaUgandaUkraineUruguayUnited States Percent of Connections: 100%USNB Guantanamo BayUzbekistanVaticanSt. Vin. and Gren.VenezuelaVietnamVanuatuAkrotiriSamoaYemenSouth AfricaZambiaZimbabwe89%78%67%56%44%33%22%11%0%100%

File


Type
Microsoft Word 2007+
CRC32
21D99AB0
MD5
0b835d7905cb159b62eb3da93c648a19
SHA1
c50222da74c52dec9dfcecdf2124e5e76bfb2bd2
SHA256
5c334953fe87a0c6c8115f4b5f1655e005e8b5d5e3bd9903c19a666e3c0c76ef
SHA512
a1168e0345bbbc49d2be06534ace7987b89ed4e863b4037205fde31c93db84f4cb8fe1304cc0d3e275a26cb8424149a57cbf4c1b6e87811807e1ae3ce3ee870b
Ssdeep
12288:0aR6aUr3QvdbQRD71YKeXX3FE8F5YRWBZAqLiU1Pkh:PYdrs6RD/oX5UFNHh
PEiD
None matched

Behavior Summary


  • C:\Users\Virtual\AppData\Local\Temp\tmp2EDC.tmp
  • C:\Users\Virtual\AppData\Local\Temp\tmp4826.tmp
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\7ca6a7b9413844e82108a9d62f88a2d9\Microsoft.VisualBasic.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\46957030830964165644b52b0696c5d9\System.Configuration.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\55560c2014611e9119f99923c9ebdeef\System.Core.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\032f5fa875be86b577722ddeeee2e51c\System.Data.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\646b4b01cb29986f8e076aa65c9e9753\System.Drawing.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\4dfa27fdd6a4cce26f99585e1c744f9b\System.Management.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\5aac750b35b27770dccb1a43f83cced7\System.Windows.Forms.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d86b080a37c60a872c82b912a2a63dac\System.Xml.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System\52cca48930e580e3189eac47158c20be\System.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll.aux
  • C:\Users\Virtual\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\B03D961B.emf
  • C:\Users\Virtual\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\mso2599.tmp
  • C:\Users\Virtual\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{1297CDE2-F01B-44D4-B3BA-2BF728C0E911}.tmp
  • C:\Users\Virtual\AppData\Local\Temp\Specification Order 7453214.exe
  • C:\Users\Virtual\AppData\Local\Temp\tmp2EDC.tmp
  • C:\Users\Virtual\AppData\Local\Temp\tmp4826.tmp
  • C:\Users\Virtual\AppData\Local\Temp\~$334953fe87a0c6c8115f4b5f1655e005e8b5d5e3bd9903c19a666e3c0c76ef
  • C:\Users\Virtual\AppData\Local\Temp\~WRD0000.tmp
  • \\?\PIPE\wkssvc
  • C:\Users\Virtual\AppData\Local\Temp\tmp2EDC.tmp
  • C:\Users\Virtual\AppData\Local\Temp\tmp4826.tmp
  • C:\
  • C:\Program Files (x86)\
  • C:\Program Files (x86)\Common Files\
  • C:\Program Files (x86)\Common Files\Microsoft Shared\
  • C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSO.DLL
  • C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\OGL.DLL
  • C:\Program Files (x86)\Common Files\Microsoft Shared\TextConv\
  • C:\Program Files (x86)\Common Files\Microsoft Shared\TextConv\MSCONV97.DLL
  • C:\Program Files (x86)\Common Files\Microsoft Shared\TextConv\RECOVR32.CNV
  • C:\Program Files (x86)\Common Files\Microsoft Shared\TextConv\WPFT532.CNV
  • C:\Program Files (x86)\Common Files\Microsoft Shared\TextConv\WPFT632.CNV
  • C:\Program Files (x86)\Common Files\Microsoft Shared\TextConv\Works632.cnv
  • C:\Program Files (x86)\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB
  • C:\Program Files (x86)\Common Files\microsoft shared\
  • C:\Program Files (x86)\Common Files\microsoft shared\VBA\
  • C:\Program Files (x86)\Common Files\microsoft shared\VBA\VBA6\
  • C:\Program Files (x86)\Common Files\microsoft shared\VBA\VBA6\VBE6.DLL
  • C:\Program Files (x86)\Microsoft Office\Office12\
  • C:\Program Files (x86)\Microsoft Office\Office12\ID_00014.DPC
  • C:\Program Files (x86)\Microsoft Office\Office12\MSWORD.OLB
  • C:\Program Files (x86)\Microsoft Office\Office12\STARTUP\
  • C:\Program Files (x86)\Microsoft Office\Office12\Wordcnvpxy.cnv
  • C:\Program Files (x86)\Microsoft Office\Office12\msproof6.dll
  • C:\ProgramData
  • C:\ProgramData\Microsoft
  • C:\ProgramData\Microsoft\Windows
  • C:\ProgramData\Microsoft\Windows\Start Menu
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini
  • C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini
  • C:\Users
  • C:\Users\
  • C:\Users\Public
  • C:\Users\Public\Desktop\desktop.ini
  • C:\Users\Public\Documents\desktop.ini
  • C:\Users\Public\desktop.ini
  • C:\Users\Virtual
  • C:\Users\Virtual\
  • C:\Users\Virtual\AppData
  • C:\Users\Virtual\AppData\
  • C:\Users\Virtual\AppData\Local
  • C:\Users\Virtual\AppData\Local\
  • C:\Users\Virtual\AppData\Local\GDIPFONTCACHEV1.DAT
  • C:\Users\Virtual\AppData\Local\Microsoft\Office\
  • C:\Users\Virtual\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\25926160.emf
  • C:\Users\Virtual\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\B03D961B.emf
  • C:\Users\Virtual\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\BD9B31E1.emf
  • C:\Users\Virtual\AppData\Local\Temp
  • C:\Users\Virtual\AppData\Local\Temp\
  • C:\Users\Virtual\AppData\Local\Temp\5c334953fe87a0c6c8115f4b5f1655e005e8b5d5e3bd9903c19a666e3c0c76ef
  • C:\Users\Virtual\AppData\Local\Temp\Specification Order 7453214.exe
  • C:\Users\Virtual\AppData\Local\Temp\tmp2EDC.tmp
  • C:\Users\Virtual\AppData\Local\Temp\tmp4826.tmp
  • C:\Users\Virtual\AppData\Local\Temp\~WRD0000.tmp
  • C:\Users\Virtual\AppData\Local\Temp\~WRL0001.tmp
  • C:\Users\Virtual\AppData\Roaming
  • C:\Users\Virtual\AppData\Roaming\
  • C:\Users\Virtual\AppData\Roaming\Microsoft
  • C:\Users\Virtual\AppData\Roaming\Microsoft\
  • C:\Users\Virtual\AppData\Roaming\Microsoft\Internet Explorer
  • C:\Users\Virtual\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch
  • C:\Users\Virtual\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
  • C:\Users\Virtual\AppData\Roaming\Microsoft\Office\VB12.pip
  • C:\Users\Virtual\AppData\Roaming\Microsoft\Proof\
  • C:\Users\Virtual\AppData\Roaming\Microsoft\Templates\
  • C:\Users\Virtual\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
  • C:\Users\Virtual\AppData\Roaming\Microsoft\Windows
  • C:\Users\Virtual\AppData\Roaming\Microsoft\Windows\Libraries
  • C:\Users\Virtual\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms
  • C:\Users\Virtual\AppData\Roaming\Microsoft\Windows\Libraries\desktop.ini
  • C:\Users\Virtual\AppData\Roaming\Microsoft\Windows\Network Shortcuts
  • C:\Users\Virtual\AppData\Roaming\Microsoft\Windows\SendTo
  • C:\Users\Virtual\AppData\Roaming\Microsoft\Windows\SendTo\
  • C:\Users\Virtual\AppData\Roaming\Microsoft\Windows\SendTo\Desktop.ini
  • C:\Users\Virtual\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk
  • C:\Users\Virtual\AppData\Roaming\Microsoft\Windows\Start Menu
  • C:\Users\Virtual\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
  • C:\Users\Virtual\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
  • C:\Users\Virtual\AppData\Roaming\Microsoft\Word\STARTUP\
  • C:\Users\Virtual\Documents
  • C:\Windows
  • C:\Windows\
  • C:\Windows\AppPatch\pcamain.sdb
  • C:\Windows\AppPatch\sysmain.sdb
  • C:\Windows\Fonts\arial.ttf
  • C:\Windows\Fonts\arialbd.ttf
  • C:\Windows\Fonts\arialbi.ttf
  • C:\Windows\Fonts\ariali.ttf
  • C:\Windows\Fonts\malgun.ttf
  • C:\Windows\Fonts\micross.ttf
  • C:\Windows\Fonts\msjh.ttf
  • C:\Windows\Fonts\msyh.ttf
  • C:\Windows\Fonts\segoeui.ttf
  • C:\Windows\Fonts\staticcache.dat
  • C:\Windows\Fonts\tahoma.ttf
  • C:\Windows\Globalization\Sorting\sortdefault.nls
  • C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
  • C:\Windows\Microsoft.Net\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
  • C:\Windows\SysWOW64\en-US\KERNELBASE.dll.mui
  • C:\Windows\SysWOW64\gameux.dll
  • C:\Windows\SysWOW64\stdole2.tlb
  • C:\Windows\System32\
  • C:\Windows\System32\EhStorShell.dll
  • C:\Windows\System32\acppage.dll
  • C:\Windows\System32\audiodev.dll
  • C:\Windows\System32\en-US\EhStorShell.dll.mui
  • C:\Windows\System32\en-US\audiodev.dll.mui
  • C:\Windows\System32\en-US\mydocs.dll.mui
  • C:\Windows\System32\en-US\ntshrui.dll.mui
  • C:\Windows\System32\en-US\packager.dll.mui
  • C:\Windows\System32\en-US\sendmail.dll.mui
  • C:\Windows\System32\en-US\syncui.dll.mui
  • C:\Windows\System32\en-US\tzres.dll.mui
  • C:\Windows\System32\en-US\wpdshext.dll.mui
  • C:\Windows\System32\en-US\zipfldr.dll.mui
  • C:\Windows\System32\imageres.dll
  • C:\Windows\System32\msxml3.dll
  • C:\Windows\System32\mydocs.dll
  • C:\Windows\System32\ntshrui.dll
  • C:\Windows\System32\sendmail.dll
  • C:\Windows\System32\syncui.dll
  • C:\Windows\System32\twext.dll
  • C:\Windows\System32\tzres.dll
  • C:\Windows\System32\wpdshext.dll
  • C:\Windows\System32\zipfldr.dll
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\7ca6a7b9413844e82108a9d62f88a2d9\Microsoft.VisualBasic.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\46957030830964165644b52b0696c5d9\System.Configuration.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\55560c2014611e9119f99923c9ebdeef\System.Core.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\032f5fa875be86b577722ddeeee2e51c\System.Data.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\646b4b01cb29986f8e076aa65c9e9753\System.Drawing.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\4dfa27fdd6a4cce26f99585e1c744f9b\System.Management.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\5aac750b35b27770dccb1a43f83cced7\System.Windows.Forms.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d86b080a37c60a872c82b912a2a63dac\System.Xml.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System\52cca48930e580e3189eac47158c20be\System.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll.aux
  • C:\Windows\assembly\pubpol41.dat
  • \\?\PIPE\wkssvc
  • c:\Windows\System32\imageres.dll
  • C:\Users\Virtual\AppData\Local\Temp\Specification Order 7453214.exe -> C:\Users\Virtual\AppData\Roaming\Txvglepem.exe
  • checkip.dyndns.org
  • freegeoip.app
  • C:\Users
  • C:\Users\Virtual
  • C:\Users\Virtual\AppData
  • C:\Users\Virtual\AppData\Local
  • C:\Users\Virtual\AppData\Local\Temp
  • C:\Windows\Microsoft.NET\Framework\*
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\*
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\Sj5\*
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\*
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\*
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\*
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\*
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\*
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\*
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\*
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System\*
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\*
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\z\*
  • HKEY_CLASSES_ROOT\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32
  • HKEY_CLASSES_ROOT\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32
  • HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance
  • HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
  • HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
  • HKEY_CURRENT_USER\Software\Microsoft\Fusion
  • HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Virtual|AppData|Local|Temp|Specification Order 7453214.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Virtual|AppData|Local|Temp|Specification Order 7453214.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AppContext
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\Servicing
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\BidInterface\Loader
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.10.0.Microsoft.JScript__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.10.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.Accessibility__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Configuration.Install__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Configuration__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Core__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Data.SqlXml__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Data__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Deployment__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Drawing__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.EnterpriseServices__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Management__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Numerics__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Runtime.Remoting__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Security__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Transactions__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Windows.Forms__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml.Linq__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.10.0.Microsoft.JScript__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.10.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.Accessibility__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Configuration.Install__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Configuration__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Core__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Data.SqlXml__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Data__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Deployment__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Drawing__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.EnterpriseServices__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Management__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Numerics__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Runtime.Remoting__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Security__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Transactions__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Windows.Forms__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml.Linq__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\Dynamic DST
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-3131157199-1995805048-2727015567-1000\Installer\Assemblies\C:|Users|Virtual|AppData|Local|Temp|Specification Order 7453214.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-3131157199-1995805048-2727015567-1000\Installer\Assemblies\Global
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v4.0.30319
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\SKUs\default
  • HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
  • HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\NGen\Policy\v4.0
  • HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
  • HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v4.0.30319\SKUs\
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
  • HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Specification Order 7453214.exe
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\Schannel
  • \Policy\Standards
  • HKEY_CURRENT_USER\Local Settings\MuiCache\6E\52C64B7E\@%SystemRoot%\system32\dnsapi.dll,-103
  • HKEY_CURRENT_USER\Local Settings\MuiCache\6E\52C64B7E\@%SystemRoot%\system32\p2pcollab.dll,-8042
  • HKEY_CURRENT_USER\Software\Microsoft\GDIPlus\FontCachePath
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{94956483-9236-11e5-a874-806e6f6e6963}\Data
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{94956483-9236-11e5-a874-806e6f6e6963}\Generation
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{94956484-9236-11e5-a874-806e6f6e6963}\Data
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{94956484-9236-11e5-a874-806e6f6e6963}\Generation
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\WpadOverride
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\ChainCacheResyncFiletime
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetPreFetchTriggerPeriodSeconds
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableCANameConstraints
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableMandatoryBasicConstraints
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableUnsupportedCriticalExtensions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableWeakSignatureFlags
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlCountInCert
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalByteCount
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCertCount
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCountPerChain
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxUrlRetrievalByteCount
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index41
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\PageAllocatorSystemHeapIsPrivate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\PageAllocatorUseSystemHeap
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\MaxRpcSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\A15F9333
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service\Enable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\Dynamic DST\2006
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\Dynamic DST\2007
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\Dynamic DST\FirstEntry
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\Dynamic DST\LastEntry
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\MUI_Display
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\MUI_Dlt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\MUI_Std
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\SourcePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ProxySettingsPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AltJit
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\LegacyWPADSupport
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\HWRPortReuseOnSocketBind
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\SchUseStrongCrypto
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASAPI32\ConsoleTracingMask
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASAPI32\EnableConsoleTracing
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASAPI32\EnableFileTracing
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASAPI32\FileDirectory
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASAPI32\FileTracingMask
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASAPI32\MaxFileSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASMANCS\ConsoleTracingMask
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASMANCS\EnableConsoleTracing
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASMANCS\EnableFileTracing
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASMANCS\FileDirectory
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASMANCS\FileTracingMask
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASMANCS\MaxFileSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\LoadAppInit_DLLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\DevicePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ShareCredsWithWinHttp
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp\DisableBranchCache
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp\Tracing\Enabled
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\ComputerName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureDll
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureRoutine
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Capabilities
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Comment
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Name
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\RpcId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\TokenSize
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SQMServiceList\SQMServiceList
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextListCount
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextLockCount
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SecurityProviders
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableMulticast
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableMulticast
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C66F1519-F3E4-4D8E-8465-E178DC1EA3DD}\DhcpDomain
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C66F1519-F3E4-4D8E-8465-E178DC1EA3DD}\DisableAdapterDomainName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C66F1519-F3E4-4D8E-8465-E178DC1EA3DD}\Domain
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C66F1519-F3E4-4D8E-8465-E178DC1EA3DD}\EnableMulticast
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C66F1519-F3E4-4D8E-8465-E178DC1EA3DD}\MaxNumberOfAddressesToRegister
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C66F1519-F3E4-4D8E-8465-E178DC1EA3DD}\QueryAdapterName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C66F1519-F3E4-4D8E-8465-E178DC1EA3DD}\RegisterAdapterName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C66F1519-F3E4-4D8E-8465-E178DC1EA3DD}\RegistrationEnabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C66F1519-F3E4-4D8E-8465-E178DC1EA3DD}\RegistrationMaxAddressCount
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DebugHeapFlags
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagLevel
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagMatchAnyMask
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\OOBEInProgress
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
  • HKEY_CURRENT_USER\Local Settings\MuiCache\6E\52C64B7E\LanguageList
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASAPI32\ConsoleTracingMask
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASAPI32\EnableConsoleTracing
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASAPI32\EnableFileTracing
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASAPI32\FileDirectory
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASAPI32\FileTracingMask
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASAPI32\MaxFileSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASMANCS\ConsoleTracingMask
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASMANCS\EnableConsoleTracing
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASMANCS\EnableFileTracing
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASMANCS\FileDirectory
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASMANCS\FileTracingMask
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Specification Order 7453214_RASMANCS\MaxFileSize
  • RasPbFile

Processes


Name: SpecificationOrder 7453214.exeName: schtasks.exePID: 2720Name: SpecificationOrder 7453214.exeName: SpecificationOrder 7453214.exeName: schtasks.exePID: 836Name: SpecificationOrder 7453214.exeName: WINWORD.EXEPID: 2328System
Process Name PID Parent PID