Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Common Name: QMPersNum |
object name not found |
1000064920 |
Message posted |
HWND: 11013E Message: 400 WParam: 47806 LParam: 2000556 |
success |
1000737068 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Common Name: QMPersNum |
object name not found |
1000849539 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Common Name: QMEnable |
object name not found |
1000851407 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Common Name: QMEnable |
object name not found |
1000852177 |
File other op |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~WRF0000.tmp New path: Disposition: BasicInformation
Data : Creation Time: 01:00 01-01-1601 Last Access Time: 01:00 01-01-1601 Last Write
Time: 09:41 24-01-2012 Change Time: 01:00 01-01-1601 File Attributes: none
|
success or wait |
1000852877 |
File other op |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~WRF0000.tmp New path: Disposition: PositionInformation
Data : Offset: 2560
|
success or wait |
1001074893 |
File other op |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~WRF0000.tmp New path: Disposition: EndOfFileInformation
Data : unknown
|
success or wait |
1001076000 |
File other op |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~WRF0000.tmp New path: Disposition: AllocationInformation
Data : unknown
|
success or wait |
1001077338 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~WRF0000.tmp Access: read attributes and
delete Options: non directory file and open for backup ident and open reparse point
Overwritten: false
|
success or wait |
1001079366 |
File deleted |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~WRF0000.tmp New path: Disposition: Data
:
|
success or wait |
1001183983 |
Process terminated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE |
success or wait |
1001520235 |
Message posted |
TID: 6C4 Message: C0D3 WParam: 0 LParam: 1144 |
success |
1002196601 |
Message posted |
TID: 6C4 Message: C0D4 WParam: 0 LParam: 1144 |
success |
1002416205 |
Message posted |
TID: 6C4 Message: C0D4 WParam: 0 LParam: 1144 |
success |
1002417208 |
Message posted |
TID: 6C4 Message: C0D4 WParam: 0 LParam: 1144 |
success |
1002418013 |
Message posted |
TID: 6C4 Message: C0D4 WParam: 0 LParam: 1144 |
success |
1002418700 |
Message posted |
TID: 6C4 Message: C0D4 WParam: 0 LParam: 1144 |
success |
1002526420 |
Message posted |
TID: 6C4 Message: C0D4 WParam: 0 LParam: 1144 |
success |
1002639659 |
Process information queried |
PID: 1680 Info Class: Cookie |
success or wait |
1003538691 |
Process information queried |
PID: 1680 Info Class: Cookie |
success or wait |
1003644788 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
Name: DisableMetaFiles
|
object name not found |
1003757304 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager Name: CWDIllegalInDLLSearch |
object name not found |
591718659 |
System info queried |
Type: BasicInformation |
success or wait |
591722960 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 140000
Length: 12FB14 Allocation Type: unknown Protection: page read and write
|
success or wait |
591832120 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 140000
Length: 12FB18 Allocation Type: unknown Protection: page read and write
|
success or wait |
591833968 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 141000
Length: 12F7F4 Allocation Type: unknown Protection: page read and write
|
success or wait |
591837048 |
System info queried |
Type: BasicInformation |
success or wait |
591942300 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 240000
Length: 12FB14 Allocation Type: unknown Protection: page read and write
|
success or wait |
591943152 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 240000
Length: 12FB18 Allocation Type: unknown Protection: page read and write
|
success or wait |
591943847 |
File opened |
Path: C:\WINDOWS\system32\ Access: execute or traverse and synchronize Options: directory
file and synchronous io non alert Overwritten: false
|
success or wait |
592055463 |
File control set |
Path: C:\WINDOWS\system32 Control Code: 90028 Input Buffer: |
success or wait |
592056108 |
Section loaded |
Path: \KnownDlls\kernel32.dll Access: write and read and execute Type: unknown Baseaddress:
7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid
|
success or wait |
592164622 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C801000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
592277640 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C801000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
592278960 |
Process information queried |
PID: 1680 Info Class: Cookie |
success or wait |
592389790 |
System info queried |
Type: RangeStartInformation |
success or wait |
592391199 |
System info queried |
Type: BasicInformation |
success or wait |
592392327 |
Section loaded |
Path: unknown Access: query and write and read and execute and extend size Type: reserve
Baseaddress: 7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid
|
success or wait |
592499933 |
System info queried |
Type: BasicInformation |
success or wait |
592501168 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 250000
Length: 12F340 Allocation Type: unknown Protection: page read and write
|
success or wait |
592612957 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server Name: TSAppCompat |
success or wait |
592614147 |
Section loaded |
Path: \NLS\NlsSectionUnicode Access: read Type: unknown Baseaddress: 260000 Size:
90112 Protection: readonly Mapped to pid: own pid
|
success or wait |
592785894 |
Section loaded |
Path: \NLS\NlsSectionLocale Access: read Type: unknown Baseaddress: 280000 Size: 266240
Protection: readonly Mapped to pid: own pid
|
success or wait |
592894321 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 143000
Length: 12F21C Allocation Type: unknown Protection: page read and write
|
success or wait |
593010890 |
Section loaded |
Path: \NLS\NlsSectionSortkey Access: query and read Type: unknown Baseaddress: 2D0000
Size: 266240 Protection: readonly Mapped to pid: own pid
|
success or wait |
593012800 |
Section loaded |
Path: \NLS\NlsSectionSortTbls Access: read Type: unknown Baseaddress: 320000 Size:
24576 Protection: readonly Mapped to pid: own pid
|
success or wait |
593121087 |
Section loaded |
Path: \NLS\NlsSectionSortkey00000409 Access: read Type: unknown Baseaddress: unknown
Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
593227953 |
Section loaded |
Path: \NLS\NlsSectionSortkey00000409 Access: read Type: unknown Baseaddress: unknown
Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
593338617 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 251000
Length: 12F168 Allocation Type: unknown Protection: page read and write
|
success or wait |
593339231 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE.2.Manifest Access: read
data or list directory and read ea and execute or traverse and read attributes and
read control and synchronize Options: synchronous io non alert and non directory file
Overwritten: false
|
object name not found |
593451026 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE.2.Config Access: read
data or list directory and read ea and execute or traverse and read attributes and
read control and synchronize Options: synchronous io non alert and non directory file
Overwritten: false
|
object name not found |
593453357 |
Section loaded |
Path: \KnownDlls\ADVAPI32.dll Access: write and read and execute Type: unknown Baseaddress:
77DD0000 Size: 634880 Protection: read write Mapped to pid: own pid
|
success or wait |
593563033 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77DD1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
593678317 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77DD1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
593793222 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77DD1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
593793344 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77DD1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
593793557 |
Section loaded |
Path: \KnownDlls\RPCRT4.dll Access: write and read and execute Type: unknown Baseaddress:
77E70000 Size: 602112 Protection: read write Mapped to pid: own pid
|
success or wait |
593900194 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77E71000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
594013134 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77E71000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
594014043 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77E71000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
594014697 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77E71000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
594126254 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77E71000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
594127350 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77E71000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
594128270 |
Section loaded |
Path: \KnownDlls\Secur32.dll Access: write and read and execute Type: unknown Baseaddress:
77FE0000 Size: 69632 Protection: read write Mapped to pid: own pid
|
success or wait |
594234396 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77FE1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
594345284 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77FE1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
594345441 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77FE1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
594461498 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77FE1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
594461795 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77FE1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
594462054 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77FE1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
594574015 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77E71000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
594576179 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77E71000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
594576630 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77DD1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
594684681 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77DD1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
594685835 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
594686704 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
594793590 |
Section loaded |
Path: \KnownDlls\GDI32.dll Access: write and read and execute Type: unknown Baseaddress:
77F10000 Size: 299008 Protection: read write Mapped to pid: own pid
|
success or wait |
594795505 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F11000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
594910273 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F11000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
594910490 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F11000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
595016311 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F11000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
595016463 |
Section loaded |
Path: \KnownDlls\USER32.dll Access: write and read and execute Type: unknown Baseaddress:
7E410000 Size: 593920 Protection: read write Mapped to pid: own pid
|
success or wait |
595017257 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7E411000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
595241653 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7E411000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
595242244 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7E411000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
595242651 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7E411000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
595352263 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7E411000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
595353020 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7E411000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
595353713 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F11000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
595464207 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F11000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
595464843 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
595465316 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
595577060 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
595578365 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
595579527 |
Section loaded |
Path: \KnownDlls\ole32.dll Access: write and read and execute Type: unknown Baseaddress:
774E0000 Size: 1302528 Protection: read write Mapped to pid: own pid
|
success or wait |
595688848 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
595801861 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
595802935 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
595803774 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
595915862 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
595916940 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
595918598 |
Section loaded |
Path: \KnownDlls\msvcrt.dll Access: write and read and execute Type: unknown Baseaddress:
77C10000 Size: 360448 Protection: read write Mapped to pid: own pid
|
success or wait |
596024295 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77C11000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
596135115 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77C11000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
596135998 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77C11000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
596248347 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77C11000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
596248647 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
596249004 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
596359481 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
596361119 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
596362471 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
596472571 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
596473953 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
596476097 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
596587528 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
596589050 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
596590412 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
596700099 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
596700287 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
596700395 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
596806029 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 144000
Length: 12F894 Allocation Type: unknown Protection: page read and write
|
success or wait |
596921124 |
Process information queried |
PID: 1680 Info Class: ImageInformation |
success or wait |
597030244 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server Name: TSAppCompat |
success or wait |
597031358 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server Name: TSAppCompat |
success or wait |
597145176 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server Name: TSUserEnabled |
success or wait |
597147003 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Name:
LeakTrack
|
object name not found |
597256065 |
System info queried |
Type: BasicInformation |
success or wait |
597365325 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager Name: SafeDllSearchMode |
object name not found |
597365793 |
File opened |
Path: C:\WINDOWS\system32\IMM32.DLL Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
597480660 |
Section loaded |
Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit
Baseaddress: 410000 Size: 110592 Protection: execute Mapped to pid: own pid
|
success or wait |
597481232 |
File opened |
Path: C:\WINDOWS\system32\IMM32.DLL Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
597593956 |
Section loaded |
Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit
Baseaddress: 410000 Size: 110592 Protection: execute Mapped to pid: own pid
|
success or wait |
597705329 |
File opened |
Path: C:\WINDOWS\system32\IMM32.DLL Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
597817347 |
Section loaded |
Path: C:\WINDOWS\system32\imm32.dll Access: query and write and read and execute Type:
image Baseaddress: 76390000 Size: 118784 Protection: read write Mapped to pid: own
pid
|
success or wait |
597819299 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Name: TransparentEnabled
|
success or wait |
597926926 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76391000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
598152578 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76391000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
598264209 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76391000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
598265465 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76391000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
598266524 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76391000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
598373278 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76391000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
598375452 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76391000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
598377204 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76391000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
598490679 |
System info queried |
Type: BasicInformation |
success or wait |
598491006 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
Name: DisableMetaFiles
|
object name not found |
598491678 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Name:
AppInit_DLLs
|
success or wait |
598598977 |
System info queried |
Type: BasicInformation |
success or wait |
598708573 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 840000
Length: 12F91C Allocation Type: unknown Protection: page read and write
|
success or wait |
598709109 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 840000
Length: 12F920 Allocation Type: unknown Protection: page read and write
|
success or wait |
598709592 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 841000
Length: 12F5FC Allocation Type: unknown Protection: page read and write
|
success or wait |
598820846 |
Section loaded |
Path: \NLS\NlsSectionCType Access: read Type: unknown Baseaddress: 850000 Size: 12288
Protection: readonly Mapped to pid: own pid
|
success or wait |
598821929 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 843000
Length: 12F6B8 Allocation Type: unknown Protection: page read and write
|
success or wait |
598936369 |
Process information queried |
PID: 1680 Info Class: Cookie |
success or wait |
598937719 |
Process information queried |
PID: 1680 Info Class: Cookie |
success or wait |
599043939 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 166000
Length: 12F5BC Allocation Type: unknown Protection: page read and write
|
success or wait |
599044622 |
File opened |
Path: \Device\KsecDD Access: read data or list directory and synchronize Options:
synchronous io alert Overwritten: false
|
success or wait |
599045559 |
System info queried |
Type: BasicInformation |
success or wait |
599161233 |
System info queried |
Type: ProcessorInformation |
success or wait |
599162162 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager Name: CriticalSectionTimeout |
success or wait |
599270405 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole Name: RWLockResourceTimeOut |
object name not found |
599271227 |
System info queried |
Type: BasicInformation |
success or wait |
599381901 |
System info queried |
Type: ProcessorInformation |
success or wait |
599382802 |
System info queried |
Type: BasicInformation |
success or wait |
599491457 |
System info queried |
Type: ProcessorInformation |
success or wait |
599492895 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface Name: InterfaceHelperDisableAll |
object name not found |
599494152 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface Name: InterfaceHelperDisableAllForOle32 |
object name not found |
599603905 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface Name: InterfaceHelperDisableTypeLib |
object name not found |
599604322 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00020400-0000-0000-C000-000000000046}
Name: InterfaceHelperDisableAll
|
object name not found |
599714458 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00020400-0000-0000-C000-000000000046}
Name: InterfaceHelperDisableAllForOle32
|
object name not found |
599714576 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30B51000
Length: 1000 New Protection: page readonly Old Protection: page read and write
|
success or wait |
599829490 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion Name: CommonFilesDir |
success or wait |
599940866 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll Access: execute
or traverse and synchronize Options: synchronous io non alert and non directory file
Overwritten: false
|
success or wait |
600107957 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Access: write
and read and execute Type: commit Baseaddress: 860000 Size: 12242944 Protection: execute
Mapped to pid: own pid
|
success or wait |
600110094 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll Access: execute
or traverse and synchronize Options: synchronous io non alert and non directory file
Overwritten: false
|
success or wait |
600218970 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Access: query
and write and read and execute Type: image Baseaddress: 30C90000 Size: 12288000 Protection:
read write Mapped to pid: own pid
|
success or wait |
600329668 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll.2.Manifest
Access: read data or list directory and read ea and execute or traverse and read attributes
and read control and synchronize Options: synchronous io non alert and non directory
file Overwritten: false
|
object name not found |
600566529 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll.2.Config Access:
read data or list directory and read ea and execute or traverse and read attributes
and read control and synchronize Options: synchronous io non alert and non directory
file Overwritten: false
|
object name not found |
600779104 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
601003930 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
601112688 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
601112836 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
601113083 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
601228921 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
601229677 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
601230105 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
601337780 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
601339366 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
601340819 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
601449955 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
601450932 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
601451739 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
601560923 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\mso.dll Name: CheckAppHelp
|
success or wait |
601902246 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\AppCompatibility
Name: DisableAppCompat
|
object name not found |
601905836 |
Section loaded |
Path: \BaseNamedObjects\ShimSharedMemory Access: write Type: unknown Baseaddress:
870000 Size: 57344 Protection: read write Mapped to pid: own pid
|
success or wait |
602008408 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 3165B000
Length: 1000 New Protection: page readonly Old Protection: page read and write
|
success or wait |
602795002 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
603133304 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 167000
Length: 12E3C8 Allocation Type: unknown Protection: page read and write
|
success or wait |
603134444 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
603135522 |
Directory Information Queried |
Path: C:\Disposition: BothDirectoryInformation Filemask: Program Files Data : abstraction.selector.functions.gen.NtFunc$FunctionData@78e185
|
success or wait |
603245966 |
File opened |
Path: C:\Program Files\ Access: read data or list directory and synchronize Options:
directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
603248575 |
Directory Information Queried |
Path: C:\Program FilesDisposition: BothDirectoryInformation Filemask: Microsoft Office
Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1df471
|
success or wait |
603350773 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
603351225 |
Mutant created |
Name: \BaseNamedObjects\Local\Mutex_MSOSharedMem |
success or wait |
603578961 |
System info queried |
Type: BasicInformation |
success or wait |
603910470 |
System info queried |
Type: ProcessorInformation |
success or wait |
603910568 |
Process information queried |
PID: 1680 Info Class: Cookie |
success or wait |
604138840 |
Process information queried |
PID: 1680 Info Class: Cookie |
success or wait |
604250827 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 880000
Length: 12F8C0 Allocation Type: unknown Protection: page no access
|
success or wait |
604692511 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 880000
Length: 12F8C0 Allocation Type: unknown Protection: page read and write
|
success or wait |
604692637 |
Key created |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency |
success or wait |
605143291 |
Key created |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems |
success or wait |
605262993 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems Name:
?K
|
object name not found |
605263826 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems Name:
?K Type: binary Data: 3F 4B 14 00 90 06 00 00 01 00 00 00 00 00 00 00 00 00 00 00
Old data:
|
success or wait |
605369785 |
Foreground Window Got |
HWND: 10084 |
success |
605371493 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
605479818 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
605480625 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\General Name: InstalledOnWin2k |
success or wait |
606597225 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: UserData |
success or wait |
606598925 |
Process information queried |
PID: 1680 Info Class: Times |
success or wait |
606709318 |
Process information queried |
PID: 1680 Info Class: Times |
success or wait |
606710422 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Common Name: QMStrMax |
object name not found |
606712082 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 890000
Length: 12F8CC Allocation Type: unknown Protection: page no access
|
success or wait |
606818830 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 890000
Length: 12F8CC Allocation Type: unknown Protection: page read and write
|
success or wait |
606819340 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: QMStudyID |
object name not found |
607044478 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 891000
Length: 12F85C Allocation Type: unknown Protection: page read and write
|
success or wait |
607044972 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8A0000
Length: 12F888 Allocation Type: unknown Protection: page no access
|
success or wait |
607045786 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8A0000
Length: 12F888 Allocation Type: unknown Protection: page read and write
|
success or wait |
607155838 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B0000
Length: 12F810 Allocation Type: unknown Protection: page no access
|
success or wait |
607156838 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B0000
Length: 12F810 Allocation Type: unknown Protection: page read and write
|
success or wait |
607157661 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: UserData |
success or wait |
607434404 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\LanguageResources Name:
SKULanguage
|
success or wait |
607435848 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: InstallLanguage |
success or wait |
607544926 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: UILanguage |
success or wait |
607545279 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: HelpLanguage |
success or wait |
607545471 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: ExeMode |
object name not found |
607658018 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: WinXPLanguagePatch |
success or wait |
607658760 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: PreviousInstallLanguage |
success or wait |
607881804 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: WebLocale |
success or wait |
607994945 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: LangTuneUp |
success or wait |
607995888 |
Key value replaced with new |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: 2055
Type: unicode Data: On Old data: Off
|
success or wait |
608784827 |
Key value replaced with new |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: 2055
Type: unicode Data: Off Old data: On
|
success or wait |
608889479 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Name: OfficeUILanguage |
success or wait |
608891880 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Name: OfficeUILanguage |
success or wait |
609001427 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: InstallFonts |
object name not found |
609002850 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\1033\wwintl.dll Access: execute
or traverse and synchronize Options: synchronous io non alert and non directory file
Overwritten: false
|
success or wait |
609228957 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\1033\WWINTL.DLL Access: write and
read and execute Type: commit Baseaddress: 8C0000 Size: 774144 Protection: execute
Mapped to pid: own pid
|
success or wait |
609229413 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\1033\wwintl.dll Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file Attributes: none Content Overwritten: true
|
success or wait |
609334978 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\1033\WWINTL.DLL Access: query and
read Type: commit Baseaddress: 8C0000 Size: 774144 Protection: readonly Mapped to
pid: own pid
|
success or wait |
609450273 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: UILanguage |
success or wait |
609670992 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale Name: 00000401 |
success or wait |
609785323 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale Name: 0000040D |
success or wait |
609786761 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale Name: 0000041E |
success or wait |
609787993 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale Name: 0000042A |
success or wait |
609894053 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale Name: 00000439 |
success or wait |
609894428 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale Name: 00000420 |
success or wait |
609894795 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale Name: 00000429 |
success or wait |
610008485 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 168000
Length: 12F274 Allocation Type: unknown Protection: page read and write
|
success or wait |
610793374 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 980000
Length: 12F45C Allocation Type: unknown Protection: page read and write
|
success or wait |
610907836 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 980000
Length: 12F458 Allocation Type: unknown Protection: page read and write
|
success or wait |
610909083 |
System info queried |
Type: PerformanceInformation |
success or wait |
610910125 |
Process information queried |
PID: 1680 Info Class: QuotaLimits |
success or wait |
611018194 |
Process information queried |
PID: 1680 Info Class: VmCounters |
success or wait |
611018316 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9A0000
Length: 12F164 Allocation Type: unknown Protection: page no access
|
success or wait |
611236997 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9A0000
Length: 12F164 Allocation Type: unknown Protection: page read and write
|
success or wait |
611237507 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: ASKFORPRINTERPICTURE |
object name not found |
611911071 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B1000
Length: 12F110 Allocation Type: unknown Protection: page read and write
|
success or wait |
611912176 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B2000
Length: 12F0E0 Allocation Type: unknown Protection: page read and write
|
success or wait |
611913552 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B3000
Length: 12F088 Allocation Type: unknown Protection: page read and write
|
success or wait |
612024858 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B4000
Length: 12F0CC Allocation Type: unknown Protection: page read and write
|
success or wait |
612027144 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9B0000
Length: 12F114 Allocation Type: unknown Protection: page no access
|
success or wait |
612027774 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9B0000
Length: 12F114 Allocation Type: unknown Protection: page read and write
|
success or wait |
612132681 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9C0000
Length: 12F118 Allocation Type: unknown Protection: page no access
|
success or wait |
612135399 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9C0000
Length: 12F118 Allocation Type: unknown Protection: page read and write
|
success or wait |
612136402 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: CACHESIZE |
object name not found |
612359536 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9D0000
Length: 12F258 Allocation Type: unknown Protection: page no access
|
success or wait |
612364466 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9D0000
Length: 12F258 Allocation Type: unknown Protection: page read and write
|
success or wait |
612468222 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9C1000
Length: 12F0F8 Allocation Type: unknown Protection: page read and write
|
success or wait |
612470815 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9F0000
Length: 12F258 Allocation Type: unknown Protection: page no access
|
success or wait |
612471801 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9F0000
Length: 12F258 Allocation Type: unknown Protection: page read and write
|
success or wait |
612582598 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9C2000
Length: 12F208 Allocation Type: unknown Protection: page read and write
|
success or wait |
612584814 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9C3000
Length: 12EC38 Allocation Type: unknown Protection: page read and write
|
success or wait |
612808189 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B5000
Length: 12EC98 Allocation Type: unknown Protection: page read and write
|
success or wait |
612808389 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: UserTemplates |
object name not found |
612808788 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Name: AppData
|
success or wait |
612914401 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: Templates |
success or wait |
613139152 |
Process information queried |
PID: 1680 Info Class: DeviceMap |
success or wait |
613251502 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: A00000
Length: 12C1E8 Allocation Type: unknown Protection: page no access
|
success or wait |
613362770 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: A00000
Length: 12C1E8 Allocation Type: unknown Protection: page read and write
|
success or wait |
613363294 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 881000
Length: 12D924 Allocation Type: unknown Protection: page read and write
|
success or wait |
613589801 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: A00000
Length: 12D8BC Allocation Type: unknown Protection: page no access
|
success or wait |
613590849 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: A00000
Length: 12D8BC Allocation Type: unknown Protection: page read and write
|
success or wait |
613699022 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B6000
Length: 12E000 Allocation Type: unknown Protection: page read and write
|
success or wait |
613701381 |
Section loaded |
Path: \BaseNamedObjects\Local\Mso97SharedDg19211106568_S-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read and execute and extend size Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
613929301 |
Section loaded |
Path: \BaseNamedObjects\Local\Mso97SharedDg19211106568_S-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read Type: reserve Baseaddress: A10000 Size: 126976 Protection:
read write Mapped to pid: own pid
|
success or wait |
614036127 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: A10000
Length: 12ECFC Allocation Type: unknown Protection: page read and write
|
success or wait |
614148284 |
Mutant created |
Name: \BaseNamedObjects\Local\Mso97SharedDg19211106568_S-1-5-21-507921405-1960408961-839522115-500Mutex |
success or wait |
614148437 |
Section loaded |
Path: \KnownDlls\uxtheme.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
614259009 |
File opened |
Path: C:\WINDOWS\system32\uxtheme.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
614261078 |
Section loaded |
Path: C:\WINDOWS\system32\uxtheme.dll Access: query and write and read and execute
Type: image Baseaddress: 5AD70000 Size: 229376 Protection: read write Mapped to pid:
own pid
|
success or wait |
614262180 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5AD71000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
614538010 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5AD71000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
614538226 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5AD71000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
614648580 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5AD71000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
614649887 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5AD71000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
614650938 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5AD71000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
614764159 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5AD71000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
614764334 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5AD71000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
614764500 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5AD71000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
614872896 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5AD71000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
614874102 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\ThemeManager Name: Compositing |
object name not found |
614984483 |
Key value queried |
Path: HKEY_USERS\Control Panel\Desktop Name: LameButtonText |
object name not found |
615208914 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Internet Explorer\Settings Name: Anchor Color |
success or wait |
615655735 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Internet Explorer\Settings Name: Anchor Color
Visited
|
success or wait |
615657912 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoClearTypeNW |
object name not found |
615660998 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9A1000
Length: 12F254 Allocation Type: unknown Protection: page read and write
|
success or wait |
615768138 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: FontInfoCache |
buffer overflow |
615769465 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: FontInfoCache |
buffer overflow |
615992880 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: FontInfoCache |
buffer overflow |
615995427 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 169000
Length: 12E9A4 Allocation Type: unknown Protection: page read and write
|
success or wait |
615997952 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: FontInfoCache |
success or wait |
616107534 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: UseOfficeUIFont |
object name not found |
616110238 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9A2000
Length: 12EC98 Allocation Type: unknown Protection: page read and write
|
success or wait |
616110741 |
Key value queried |
Path: HKEY_USERS\Control Panel\International Name: iCountry |
success or wait |
616326719 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: UseNTWordDefPgSzBehavior |
object name not found |
616326932 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: UseAlternateTOCDelimiter |
object name not found |
616443393 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: UpdateAllNumpages |
object name not found |
616443689 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: AlternateReplaceAllMethodBehaviour |
object name not found |
616443965 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: FieldCalcSecurityLevel |
object name not found |
616553658 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Wizards Name: PageSize |
success or wait |
616553939 |
Key value queried |
Path: HKEY_USERS\Control Panel\International Name: iMeasure |
success or wait |
616774214 |
Key value queried |
Path: HKEY_USERS\Control Panel\International Name: iTimePrefix |
success or wait |
616776089 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: DOC-EXTENSION |
object name not found |
616888678 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: DOT-EXTENSION |
object name not found |
616890103 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: BAK-EXTENSION |
object name not found |
617000802 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: BitmapMemory |
object name not found |
617111948 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: MessageBeeps |
object name not found |
617112224 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: EnableSubDocPutSaved |
object name not found |
617226144 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: FavorWord97ListIndents |
object name not found |
617226996 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: DoNotConfirmConverterSecurity |
object name not found |
617227257 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: WordRTFOutPathPref |
object name not found |
617337132 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: CalcDataFieldOnOpen |
object name not found |
617337663 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: SlowShading |
object name not found |
617338201 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: HideFileNotSavedDlg |
object name not found |
617448874 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NumberingGapUL |
object name not found |
617450019 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: AlternateRevisionStepThrough |
object name not found |
617558419 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: BlockDocCloseDuringCmdExec |
object name not found |
617559353 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: EnsurePrintLongVertCell |
object name not found |
617560143 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: AlternativeLongTablesLayout |
object name not found |
617668768 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: BulletProofOnCorruption |
object name not found |
617669007 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: EnsureFlagsOfProtectedDocForVbaSel |
object name not found |
617669252 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Data Name: Settings |
buffer overflow |
617780635 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Data Name: Settings |
buffer overflow |
617781966 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Data Name: Settings |
success or wait |
617782521 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B7000
Length: 12F064 Allocation Type: unknown Protection: page read and write
|
success or wait |
618004368 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoSmartTagRecognition |
object name not found |
618675544 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoSmartTagActions |
object name not found |
618676786 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: DefaultFormat |
object name not found |
618677787 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: BackgroundSave |
object name not found |
618788087 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: BackgroundOpen |
object name not found |
618789323 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: BackgroundPrint |
object name not found |
618790351 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: PlainTextAutoFormat |
object name not found |
618901428 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Outlook\Options\Calendar Name: Text
Direction
|
success or wait |
618902485 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Outlook\Options\Calendar Name: Text
Direction
|
success or wait |
618902666 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: NoTrack |
object name not found |
619010554 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: Bidi Spelling |
object name not found |
619010733 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: AutoSpell |
object name not found |
619010898 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: AutoGrammar |
object name not found |
619128082 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoLiveScrolling |
object name not found |
619128386 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoFontMRUList |
object name not found |
619128739 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: InsertFloating |
object name not found |
619237307 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
NoRecentDocsHistory
|
object name not found |
619239830 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: WordName |
success or wait |
619242598 |
File opened |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
Access: execute or traverse and synchronize Options: directory file and synchronous
io non alert Overwritten: false
|
success or wait |
619350504 |
File opened |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\Comctl32.dll
Access: execute or traverse and synchronize Options: synchronous io non alert and
non directory file Overwritten: false
|
success or wait |
619351877 |
Section loaded |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
Access: write and read and execute Type: commit Baseaddress: A30000 Size: 1056768
Protection: execute Mapped to pid: own pid
|
success or wait |
619353074 |
File opened |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\Comctl32.dll
Access: execute or traverse and synchronize Options: synchronous io non alert and
non directory file Overwritten: false
|
success or wait |
619579444 |
Section loaded |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
Access: query and write and read and execute Type: image Baseaddress: 773D0000 Size:
1060864 Protection: read write Mapped to pid: own pid
|
success or wait |
619580029 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
619794224 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
619795717 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
619796928 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
619905308 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
619905464 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
619905634 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
620017901 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
620019187 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
620020231 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
620130596 |
Section loaded |
Path: \KnownDlls\SHLWAPI.dll Access: write and read and execute Type: unknown Baseaddress:
77F60000 Size: 483328 Protection: read write Mapped to pid: own pid
|
success or wait |
620131098 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F61000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
620244355 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F61000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
620245318 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F61000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
620354631 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F61000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
620356911 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F61000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
620358216 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F61000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
620465554 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F61000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
620466131 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F61000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
620466659 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F61000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
620576582 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F61000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
620577482 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
620577650 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
620691304 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
620691455 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
620691636 |
File opened |
Path: C:\WINDOWS\WindowsShell.Manifest Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
620801159 |
Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: write and read and execute Type: commit
Baseaddress: A30000 Size: 4096 Protection: execute Mapped to pid: own pid
|
success or wait |
620801604 |
File opened |
Path: C:\WINDOWS\WindowsShell.Manifest Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
620917065 |
Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: query and read Type: commit Baseaddress:
A30000 Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
621029781 |
File opened |
Path: C:\WINDOWS\WindowsShell.Manifest Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
621141056 |
Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: read Type: commit Baseaddress: A30000
Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
621143268 |
File opened |
Path: C:\WINDOWS\WindowsShell.Config Access: read data or list directory and read
ea and execute or traverse and read attributes and read control and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
object name not found |
621247928 |
Key value queried |
Path: HKEY_USERS\Control Panel\Desktop Name: SmoothScroll |
object name not found |
621475695 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
EnableBalloonTips
|
object name not found |
621587182 |
Window created |
Window Name: OpusApp Class Name: OpusApp HWND: E0154 |
success |
621755131 |
File opened |
Path: C:\WINDOWS\system32\MSCTF.dll Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
621755752 |
Section loaded |
Path: C:\WINDOWS\system32\msctf.dll Access: write and read and execute Type: commit
Baseaddress: A50000 Size: 299008 Protection: execute Mapped to pid: own pid
|
success or wait |
621863116 |
File opened |
Path: C:\WINDOWS\system32\MSCTF.dll Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
621976238 |
Section loaded |
Path: C:\WINDOWS\system32\msctf.dll Access: query and write and read and execute Type:
image Baseaddress: 74720000 Size: 311296 Protection: read write Mapped to pid: own
pid
|
success or wait |
621977068 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 74721000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
622199619 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 74721000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
622200337 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 74721000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
622310845 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 74721000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
622311823 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 74721000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
622312638 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 74721000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
622422224 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 74721000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
622422477 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 74721000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
622423235 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 74721000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
622534501 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 74721000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
622535399 |
Process information queried |
PID: 1680 Info Class: Wow64Information |
success or wait |
622536465 |
Section loaded |
Path: \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read Type: commit Baseaddress: unknown Size: unknown Protection:
unknown Mapped to pid: unknown
|
object name exists |
622653297 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\SystemShared Name: CUAS |
success or wait |
622762657 |
Mutant created |
Name: \BaseNamedObjects\CTF.LBES.MutexDefaultS-1-5-21-507921405-1960408961-839522115-500 |
object name exists |
622765092 |
Mutant created |
Name: \BaseNamedObjects\CTF.Compart.MutexDefaultS-1-5-21-507921405-1960408961-839522115-500 |
object name exists |
622870956 |
Mutant created |
Name: \BaseNamedObjects\CTF.Asm.MutexDefaultS-1-5-21-507921405-1960408961-839522115-500 |
object name exists |
622872168 |
Mutant created |
Name: \BaseNamedObjects\CTF.Layouts.MutexDefaultS-1-5-21-507921405-1960408961-839522115-500 |
object name exists |
622873172 |
Mutant created |
Name: \BaseNamedObjects\CTF.TMD.MutexDefaultS-1-5-21-507921405-1960408961-839522115-500 |
object name exists |
622981607 |
Key value queried |
Path: HKEY_USERS\Keyboard Layout\Toggle Name: Language Hotkey |
success or wait |
622982532 |
Key value queried |
Path: HKEY_USERS\Keyboard Layout\Toggle Name: Language Hotkey |
success or wait |
622982771 |
Key value queried |
Path: HKEY_USERS\Keyboard Layout\Toggle Name: Layout Hotkey |
success or wait |
623098134 |
Key value queried |
Path: HKEY_USERS\Keyboard Layout\Toggle Name: Layout Hotkey |
success or wait |
623099615 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF Name: EnableAnchorContext |
object name not found |
623208216 |
Mutant created |
Name: \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-507921405-1960408961-839522115-500MUTEX.DefaultS-1-5-21-507921405-1960408961-839522115-500 |
object name exists |
623210055 |
Section loaded |
Path: \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-507921405-1960408961-839522115-500SFM.DefaultS-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read and execute and extend size Type: unknown Baseaddress:
A50000 Size: 262144 Protection: read write Mapped to pid: own pid
|
success or wait |
623318880 |
Windows hook set |
Module: C:\WINDOWS\system32\MSCTF.dll TID: 1144 Hook ID: keyboard |
success |
623430857 |
Windows hook set |
Module: C:\WINDOWS\system32\MSCTF.dll TID: 1144 Hook ID: mouse |
success |
623431785 |
Message sent |
HWND: E0154 Message: NCCREATE WParam: 0 LParam: 1239824 |
success |
623542455 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IMM Name: Ime
File
|
success or wait |
623543928 |
Section loaded |
Path: \KnownDlls\version.dll Access: write and read and execute Type: unknown Baseaddress:
77C00000 Size: 32768 Protection: read write Mapped to pid: own pid
|
success or wait |
623652705 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77C01000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
623766758 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77C01000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
623767343 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77C01000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
623767822 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77C01000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
623878002 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
623880193 |
File opened |
Path: C:\WINDOWS\system32\msctfime.ime Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
623881441 |
Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: write and read and execute Type: commit
Baseaddress: A90000 Size: 180224 Protection: execute Mapped to pid: own pid
|
success or wait |
623989164 |
File opened |
Path: C:\WINDOWS\system32\msctfime.ime Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
624104274 |
Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: query and read Type: commit Baseaddress:
A90000 Size: 180224 Protection: readonly Mapped to pid: own pid
|
success or wait |
624105722 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
624325072 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 16A000
Length: 12DF24 Allocation Type: unknown Protection: page read and write
|
success or wait |
624325918 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
624326676 |
File opened |
Path: C:\WINDOWS\system32\msctfime.ime Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
624442724 |
Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: write and read and execute Type: commit
Baseaddress: A90000 Size: 180224 Protection: execute Mapped to pid: own pid
|
success or wait |
624443798 |
File opened |
Path: C:\WINDOWS\system32\msctfime.ime Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
624554892 |
Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: query and read Type: commit Baseaddress:
A90000 Size: 180224 Protection: readonly Mapped to pid: own pid
|
success or wait |
624668974 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
624774080 |
File opened |
Path: C:\WINDOWS\system32\msctfime.ime Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
624884708 |
Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: write and read and execute Type: commit
Baseaddress: A90000 Size: 180224 Protection: execute Mapped to pid: own pid
|
success or wait |
624885612 |
File opened |
Path: C:\WINDOWS\system32\msctfime.ime Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
625108646 |
Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: query and write and read and execute
Type: image Baseaddress: 755C0000 Size: 188416 Protection: read write Mapped to pid:
own pid
|
success or wait |
625110469 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
625224460 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
625336508 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
625336687 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
625336881 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
625443497 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
625444207 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
625444667 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
625555545 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
625556801 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
625557346 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
625667745 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
625669149 |
Message sent |
HWND: 1200DC Message: NCCREATE WParam: 0 LParam: 1239796 |
success |
625671853 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\CTF Name: Disable Thread Input Manager |
object name not found |
625779290 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\SystemShared Name: CUAS |
success or wait |
625891469 |
Message sent |
HWND: E0154 Message: NCCALCSIZE WParam: 0 LParam: 1239864 |
error |
626116488 |
Message sent |
HWND: E0154 Message: WINDOWPOSCHANGING WParam: 0 LParam: 1239844 |
error |
626116959 |
Message sent |
HWND: E0154 Message: NCCALCSIZE WParam: 1 LParam: 1239800 |
error |
626226157 |
Section loaded |
Path: \BaseNamedObjects\PrimaryWord11SharedMemoryArea Access: read Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
626228315 |
Section loaded |
Path: \BaseNamedObjects\PrimaryWord11SharedMemoryArea Access: query and write and
read Type: commit Baseaddress: 10F0000 Size: 4096 Protection: read write Mapped to
pid: own pid
|
success or wait |
626229343 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: A90000
Length: 12EA10 Allocation Type: unknown Protection: page no access
|
success or wait |
626343711 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: A90000
Length: 12EA10 Allocation Type: unknown Protection: page read and write
|
success or wait |
626344498 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\office11\1033\msointl.dll Access:
execute or traverse and synchronize Options: synchronous io non alert and non directory
file Overwritten: false
|
success or wait |
626455193 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\1033\MSOINTL.DLL Access:
write and read and execute Type: commit Baseaddress: AA0000 Size: 1753088 Protection:
execute Mapped to pid: own pid
|
success or wait |
626457093 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\office11\1033\msointl.dll Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file Attributes: none Content Overwritten: true
|
success or wait |
626561474 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\1033\MSOINTL.DLL Access:
query and read Type: commit Baseaddress: AA0000 Size: 1753088 Protection: readonly
Mapped to pid: own pid
|
success or wait |
626676642 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: ScreenReaderPresent |
object name not found |
626792517 |
Section loaded |
Path: \BaseNamedObjects\Local\Mso97SharedDg20321106568_S-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read and execute and extend size Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
626901729 |
Section loaded |
Path: \BaseNamedObjects\Local\Mso97SharedDg20321106568_S-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read Type: reserve Baseaddress: C50000 Size: 126976 Protection:
read write Mapped to pid: own pid
|
success or wait |
627011011 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: C50000
Length: 12EB50 Allocation Type: unknown Protection: page read and write
|
success or wait |
627012647 |
Mutant created |
Name: \BaseNamedObjects\Local\Mso97SharedDg20321106568_S-1-5-21-507921405-1960408961-839522115-500Mutex |
success or wait |
627125982 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: UseAlternateShowUIMethodForFtpSession |
object name not found |
627126507 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: MaxCachedStreamSize |
object name not found |
627126719 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: ShowOtherTablesInDataSrc |
object name not found |
627232210 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: HypAlternateResolveToRel |
object name not found |
627232520 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: RepairSmartTags |
object name not found |
627233333 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: AddressBookNameMax4096 |
object name not found |
627346678 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: ShowDispNameInToolTip |
object name not found |
627347145 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: LastUILang |
object name not found |
627347616 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: LastUILang |
object name not found |
627457524 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Name: OfficeUILanguage |
success or wait |
627458984 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Name: OfficeUILanguage |
success or wait |
627460194 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: AcbControl |
object name not found |
627568134 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: AcbOn |
object name not found |
627569020 |
System info queried |
Type: PerformanceInformation |
success or wait |
627791476 |
Process information queried |
PID: 1680 Info Class: QuotaLimits |
success or wait |
627791790 |
Process information queried |
PID: 1680 Info Class: VmCounters |
success or wait |
627792499 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: C70000
Length: 12F0CC Allocation Type: unknown Protection: page no access
|
success or wait |
627903560 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: C70000
Length: 12F0CC Allocation Type: unknown Protection: page read and write
|
success or wait |
627904056 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: C80000
Length: 12F0C0 Allocation Type: unknown Protection: page no access
|
success or wait |
627904874 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: C80000
Length: 12F0C0 Allocation Type: unknown Protection: page read and write
|
success or wait |
628015873 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Research\Translation Name:
CurrentProvider
|
success or wait |
628018380 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Research\Translation Name:
MaxWords
|
object name not found |
628019379 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Research\Translation Name:
MaxWordsJapan
|
object name not found |
628131175 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Research\Translation Name:
UseOnline
|
object name not found |
628132426 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Research\Translation Name:
PreferOffline
|
object name not found |
628134165 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Research\Translation Name:
PreferOffline
|
object name not found |
628240118 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Research\Translation Name:
UseMT
|
object name not found |
628242274 |
File opened |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
Access: execute or traverse and synchronize Options: directory file and synchronous
io non alert Overwritten: false
|
success or wait |
628245189 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
RestrictRun
|
object name not found |
628350881 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Word11.pip
Access: read attributes and synchronize and generic read Options: sequential only
and synchronous io non alert and non directory file and open no recall Attributes:
none Content Overwritten: true
|
success or wait |
628351876 |
File read |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Word11.pip
Offset: unknown Length: 12 Value: 19 00 04 00 19 00 19 00 8C 06 00 00
|
success or wait |
628466217 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B7000
Length: 12EE34 Allocation Type: unknown Protection: page read and write
|
success or wait |
628577066 |
File read |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Word11.pip
Offset: unknown Length: 1676 Value: 68 00 00 00 88 05 00 00 80 06 00 00 88 06 00 00
71 DA CC 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
|
success or wait |
628689445 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 1400E2 |
success |
632886175 |
Message sent |
HWND: 1400E2 Message: NCCREATE WParam: 0 LParam: 1239976 |
success |
632886879 |
Message sent |
HWND: 1400E2 Message: NCCALCSIZE WParam: 0 LParam: 1240016 |
error |
632887882 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: C90000
Length: 12F12C Allocation Type: unknown Protection: page no access
|
success or wait |
633000402 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: C90000
Length: 12F12C Allocation Type: unknown Protection: page read and write
|
success or wait |
633001487 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: Sound |
object name not found |
633108006 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: CA0000
Length: 12F258 Allocation Type: unknown Protection: page no access
|
success or wait |
633220546 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: CA0000
Length: 12F258 Allocation Type: unknown Protection: page read and write
|
success or wait |
633332624 |
Process information queried |
PID: 1680 Info Class: Times |
success or wait |
633333321 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: MTTT |
object name not found |
633333863 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: MTTT |
object name not found |
633445261 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: MTTT |
object name not found |
633445828 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: MTTT Type: binary Data:
90 06 00 00 9C A7 97 C1 73 DA CC 01 00 00 00 00 Old data:
|
success or wait |
633446341 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\BaseSuite Name: 1EBDE4BC9A514630B5412561FA45CCC5 |
success or wait |
633557189 |
Key value queried |
Path: HKEY_USERS\Control Panel\International Name: NumShape |
success or wait |
633559036 |
Windows hook set |
Module: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE TID: 1144 Hook ID:
FFFFFFFF
|
success |
633667991 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows NT\CurrentVersion\Windows Name: Device |
success or wait |
633668731 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows NT\CurrentVersion\Devices Name: Microsoft
XPS Document Writer
|
success or wait |
633669420 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: ScreenReaderPresent |
object name not found |
633785958 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Messaging Subsystem Name: MAPIX |
success or wait |
633787880 |
File opened |
Path: C:\WINDOWS\system32\rpcss.dll Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
633893774 |
Section loaded |
Path: C:\WINDOWS\system32\rpcss.dll Access: write and read and execute Type: commit
Baseaddress: CC0000 Size: 401408 Protection: execute Mapped to pid: own pid
|
success or wait |
633894234 |
System info queried |
Type: BasicInformation |
success or wait |
634116916 |
System info queried |
Type: BasicInformation |
success or wait |
634118085 |
System info queried |
Type: BasicInformation |
success or wait |
634119060 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 16B000
Length: 12EB74 Allocation Type: unknown Protection: page read and write
|
success or wait |
634453261 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 11013E |
success |
639257775 |
Message sent |
HWND: 11013E Message: NCCREATE WParam: 0 LParam: 1239140 |
success |
639258795 |
Message sent |
HWND: 11013E Message: NCCALCSIZE WParam: 0 LParam: 1239180 |
error |
639371174 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoRereg |
object name not found |
639372875 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020906-0000-0000-C000-000000000046}\LocalServer32
Name: NULL
|
success or wait |
639593192 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
639593671 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
639593727 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
639705799 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
639706017 |
Directory Information Queried |
Path: C:\Disposition: BothDirectoryInformation Filemask: Program Files Data : abstraction.selector.functions.gen.NtFunc$FunctionData@78e185
|
success or wait |
639706361 |
File opened |
Path: C:\Program Files\ Access: read data or list directory and synchronize Options:
directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
639819029 |
Directory Information Queried |
Path: C:\Program FilesDisposition: BothDirectoryInformation Filemask: Microsoft Office
Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1df471
|
success or wait |
639819641 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
639930342 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Word.Document\CurVer Name: NULL |
success or wait |
640042099 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: GlobalDotName |
object name not found |
640043844 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B8000
Length: 12D1CC Allocation Type: unknown Protection: page read and write
|
success or wait |
640264571 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B8000
Length: 12D184 Allocation Type: unknown Protection: page read and write
|
success or wait |
640266656 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B8000
Length: 12D1E8 Allocation Type: unknown Protection: page read and write
|
success or wait |
640267668 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
640378693 |
Directory Information Queried |
Path: C:\Program Files\Microsoft Office\OFFICE11Disposition: BothDirectoryInformation
Filemask: Normal.dot Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9b3e5e
|
no such file |
640379793 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B8000
Length: 12D67C Allocation Type: unknown Protection: page read and write
|
success or wait |
640487704 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B8000
Length: 12D67C Allocation Type: unknown Protection: page read and write
|
success or wait |
640487923 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B8000
Length: 12D1CC Allocation Type: unknown Protection: page read and write
|
success or wait |
640488191 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B8000
Length: 12D184 Allocation Type: unknown Protection: page read and write
|
success or wait |
640605183 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Templates\
Access: read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
640605901 |
Directory Information Queried |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\TemplatesDisposition:
BothDirectoryInformation Filemask: Normal.dot Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ba640
|
success or wait |
640606501 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B8000
Length: 12D0F8 Allocation Type: unknown Protection: page read and write
|
success or wait |
640714271 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: A01000
Length: 12D6B0 Allocation Type: unknown Protection: page read and write
|
success or wait |
640715702 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.3\0\win32
Name: NULL
|
success or wait |
641281294 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\office11\riched20.dll Access:
execute or traverse and synchronize Options: synchronous io non alert and non directory
file Overwritten: false
|
success or wait |
641382985 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\RICHED20.DLL Access:
write and read and execute Type: commit Baseaddress: CC0000 Size: 966656 Protection:
execute Mapped to pid: own pid
|
success or wait |
641383490 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\office11\riched20.dll Access:
execute or traverse and synchronize Options: synchronous io non alert and non directory
file Overwritten: false
|
success or wait |
641608622 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\RICHED20.DLL Access:
query and write and read and execute Type: image Baseaddress: 39700000 Size: 962560
Protection: read write Mapped to pid: own pid
|
success or wait |
641609284 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 397CD000
Length: 1000 New Protection: page read and write Old Protection: page readonly
|
success or wait |
641722710 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 397CD000
Length: 1000 New Protection: page readonly Old Protection: page read and write
|
success or wait |
641833473 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 397CD000
Length: 1000 New Protection: page read and write Old Protection: page readonly
|
success or wait |
641834910 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 397CD000
Length: 1000 New Protection: page readonly Old Protection: page read and write
|
success or wait |
641836084 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 397CD000
Length: 1000 New Protection: page read and write Old Protection: page readonly
|
success or wait |
641942782 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 397CD000
Length: 1000 New Protection: page readonly Old Protection: page read and write
|
success or wait |
641943373 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 397CD000
Length: 1000 New Protection: page read and write Old Protection: page readonly
|
success or wait |
641943882 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 397CD000
Length: 1000 New Protection: page readonly Old Protection: page read and write
|
success or wait |
642053904 |
System info queried |
Type: BasicInformation |
success or wait |
642054881 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: CC0000
Length: 12E3AC Allocation Type: unknown Protection: page read and write
|
success or wait |
642055038 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: CC0000
Length: 12E3B0 Allocation Type: unknown Protection: page read and write
|
success or wait |
642166559 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: CC1000
Length: 12E08C Allocation Type: unknown Protection: page read and write
|
success or wait |
642167128 |
Section loaded |
Path: \KnownDlls\OLEAUT32.dll Access: write and read and execute Type: unknown Baseaddress:
77120000 Size: 569344 Protection: read write Mapped to pid: own pid
|
success or wait |
642167611 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
642390983 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
642392036 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
642392857 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
642502800 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
642504228 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
642505465 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
642615345 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
642617369 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
642619019 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
642725249 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
642725416 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
642725569 |
Section loaded |
Path: \KnownDlls\SXS.DLL Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
642838493 |
File opened |
Path: C:\WINDOWS\system32\SXS.DLL Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
642839156 |
Section loaded |
Path: C:\WINDOWS\system32\sxs.dll Access: query and write and read and execute Type:
image Baseaddress: 7E720000 Size: 720896 Protection: read write Mapped to pid: own
pid
|
success or wait |
642949408 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7E721000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
643065550 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7E721000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
643066589 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7E721000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
643176878 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7E721000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
643177774 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7E721000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
643178468 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7E721000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
643286287 |
System info queried |
Type: BasicInformation |
success or wait |
643287403 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: D00000
Length: 12E588 Allocation Type: unknown Protection: page read and write
|
success or wait |
643287567 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: D00000
Length: 12E58C Allocation Type: unknown Protection: page read and write
|
success or wait |
643400352 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: D01000
Length: 12E268 Allocation Type: unknown Protection: page read and write
|
success or wait |
643400567 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 16F000
Length: 12E370 Allocation Type: unknown Protection: page read and write
|
success or wait |
643400849 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 170000
Length: 12E370 Allocation Type: unknown Protection: page read and write
|
success or wait |
643511374 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 171000
Length: 12E370 Allocation Type: unknown Protection: page read and write
|
success or wait |
643512868 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 190112 |
success |
647646874 |
Message sent |
HWND: 190112 Message: NCCREATE WParam: 0 LParam: 1236396 |
success |
647647062 |
Message sent |
HWND: 190112 Message: NCCALCSIZE WParam: 0 LParam: 1236436 |
error |
647647222 |
System info queried |
Type: BasicInformation |
success or wait |
647647576 |
System info queried |
Type: BasicInformation |
success or wait |
647760523 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc Name: MaxRpcSize |
object name not found |
647761641 |
System time queried |
Time: 129718680210000000 |
success or wait |
647873776 |
System info queried |
Type: PerformanceInformation |
success or wait |
647875534 |
Process information queried |
PID: 1680 Info Class: QuotaLimits |
success or wait |
647982923 |
Process information queried |
PID: 1680 Info Class: VmCounters |
success or wait |
647984020 |
File opened |
Path: C:\WINDOWS\system32\winlogon.exe Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
647985174 |
Section loaded |
Path: C:\WINDOWS\system32\winlogon.exe Access: write and read and execute Type: commit
Baseaddress: D10000 Size: 507904 Protection: execute Mapped to pid: own pid
|
success or wait |
648097422 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 172000
Length: 12D660 Allocation Type: unknown Protection: page read and write
|
success or wait |
648433586 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole Name: MaximumAllowedAllocationSize |
object name not found |
648544676 |
Section loaded |
Path: \KnownDlls\xpsp2res.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
648653555 |
File opened |
Path: C:\WINDOWS\system32\xpsp2res.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
648653896 |
Section loaded |
Path: C:\WINDOWS\system32\xpsp2res.dll Access: query and write and read and execute
Type: image Baseaddress: D10000 Size: 2904064 Protection: read write Mapped to pid:
own pid
|
conflicting addresses |
648654317 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole Name: DefaultAccessPermission |
object name not found |
648881526 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName
Name: ComputerName
|
success or wait |
648991265 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 173000
Length: 12D83C Allocation Type: unknown Protection: page read and write
|
success or wait |
649104000 |
File opened |
Path: \pipe\lsarpc Access: read attributes and synchronize and generic read and generic
write Options: non directory file Attributes: none Content Overwritten: true
|
success or wait |
649106971 |
File other op |
Path: \lsarpc New path: Disposition: PipeInformation Data : unknown |
success or wait |
649108373 |
File other op |
Path: \lsarpc New path: Disposition: CompletionInformation Data : unknown |
success or wait |
649214049 |
File write |
Path: \lsarpc Offset: 0 Length: 72 Value: 05 00 0B 03 10 00 00 00 48 00 00 00 01 00
00 00 B8 10 B8 10 00 00 00 00 01 00 00 00 00 00 01 00 78 57 34 12 34 12 CD AB EF 00
01 23 45 67 89 AB 00 00 00 00 04 5D 88 8A EB 1C C9 11 9F E8 08 00 2B 10 48 60 02 00
00 00
|
success or wait |
649215191 |
File read |
Path: \lsarpc Offset: 0 Length: 1024 Value: 05 00 0C 03 10 00 00 00 44 00 00 00 01
00 00 00 B8 10 B8 10 5F 17 00 00 0C 00 5C 50 49 50 45 5C 6C 73 61 73 73 00 00 00 01
00 00 00 00 00 00 00 04 5D 88 8A EB 1C C9 11 9F E8 08 00 2B 10 48 60 02 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00
|
success or wait |
649216243 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ........@.......(.....,......................................... |
pending |
649328325 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ........t.......\.....9.....h.F...P@..\../,..................................CF..w.tC..2............................ |
pending |
649329022 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ........,...................h.F...P@..\../,. |
pending |
649329539 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName
Name: ComputerName
|
success or wait |
649442293 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: FE0000
Length: 12DC80 Allocation Type: unknown Protection: page read and write
|
success or wait |
649553386 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 10DE000
Length: 12DC7C Allocation Type: unknown Protection: page read and write
|
success or wait |
649662514 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 10DE000
Length: 1000 New Protection: page read and write and page guard Old Protection: page
read and write
|
success or wait |
649665837 |
Thread created |
PID: 1680 TID: 116 EIP: 7C8106F9 EAX: 77E76C7D Imagepath: C:\Program Files\Microsoft
Office\OFFICE11\WINWORD.EXE
|
success or wait |
649667272 |
Thread resumed |
TID: 116 PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE |
success or wait |
649773187 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 174000
Length: 12DFEC Allocation Type: unknown Protection: page read and write
|
success or wait |
649773807 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 175000
Length: 12DEF4 Allocation Type: unknown Protection: page read and write
|
success or wait |
649886493 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 176000
Length: 10DF9E0 Allocation Type: unknown Protection: page read and write
|
success or wait |
649887838 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 10E0000
Length: 12DE54 Allocation Type: unknown Protection: page read and write
|
success or wait |
649891195 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 11DE000
Length: 12DE50 Allocation Type: unknown Protection: page read and write
|
success or wait |
649996956 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 11DE000
Length: 1000 New Protection: page read and write and page guard Old Protection: page
read and write
|
success or wait |
649997471 |
Thread created |
PID: 1680 TID: 960 EIP: 7C8106F9 EAX: 774FE4DF Imagepath: C:\Program Files\Microsoft
Office\OFFICE11\WINWORD.EXE
|
success or wait |
649998762 |
Thread resumed |
TID: 960 PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE |
success or wait |
650112747 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 198000
Length: 12E170 Allocation Type: unknown Protection: page read and write
|
success or wait |
650114011 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 199000
Length: 11DF9E0 Allocation Type: unknown Protection: page read and write
|
success or wait |
650223193 |
Thread delayed |
Time: -60 TID: 960 |
success or wait |
650225257 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: Com+Enabled |
success or wait |
650230111 |
Section loaded |
Path: \KnownDlls\CLBCATQ.DLL Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
650231080 |
File opened |
Path: C:\WINDOWS\system32\CLBCATQ.DLL Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
650231652 |
Section loaded |
Path: C:\WINDOWS\system32\clbcatq.dll Access: query and write and read and execute
Type: image Baseaddress: 76FD0000 Size: 520192 Protection: read write Mapped to pid:
own pid
|
success or wait |
650232305 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
650444608 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
650444857 |
Section loaded |
Path: \KnownDlls\COMRes.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
650559794 |
File opened |
Path: C:\WINDOWS\system32\COMRes.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
650560281 |
Section loaded |
Path: C:\WINDOWS\system32\comres.dll Access: query and write and read and execute
Type: image Baseaddress: 77050000 Size: 806912 Protection: read write Mapped to pid:
own pid
|
success or wait |
650560785 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77051000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
650781621 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77051000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
650783141 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
650784375 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
650892098 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
650893243 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
650894214 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
651005459 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
651007874 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
651009856 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
651117345 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
651117641 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
651118353 |
Section loaded |
Path: \KnownDlls\VERSION.dll Access: write and read and execute Type: unknown Baseaddress:
77C00000 Size: 32768 Protection: read write Mapped to pid: own pid
|
success or wait |
651227514 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77C01000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
651341140 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77C01000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
651342098 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77C01000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
651452073 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77C01000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
651453612 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole Name: MinimumFreeMemPercentageToCreateProcess |
object name not found |
651456736 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole Name: MinimumFreeMemPercentageToCreateObject |
object name not found |
651565151 |
Process information queried |
PID: 1680 Info Class: Wow64Information |
success or wait |
651566573 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: Com+Enabled |
success or wait |
651674652 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
651787675 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 1BB000
Length: 12E6FC Allocation Type: unknown Protection: page read and write
|
success or wait |
651791027 |
System info queried |
Type: BasicInformation |
success or wait |
651899744 |
System info queried |
Type: ProcessorInformation |
success or wait |
651900937 |
File opened |
Path: C:\WINDOWS\Registration\R000000000010.clb Access: read attributes and synchronize
and generic read Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
651901976 |
File other op |
Path: C:\WINDOWS\Registration\R000000000010.clb New path: Disposition: PositionInformation
Data : Offset: 23472
|
success or wait |
652010386 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 1BC000
Length: 12E674 Allocation Type: unknown Protection: page read and write
|
success or wait |
652012981 |
File other op |
Path: C:\WINDOWS\Registration\R000000000010.clb New path: Disposition: PositionInformation
Data : Offset: 0
|
success or wait |
652015740 |
File read |
Path: C:\WINDOWS\Registration\R000000000010.clb Offset: unknown Length: 23472 Value:
43 4F 4D 2B 01 00 00 00 01 00 12 00 24 00 00 00 00 01 01 00 63 00 00 00 00 00 00 01
01 00 00 00 00 01 10 00 00 00 00 00 C0 00 00 00 00 00 00 46 0E 00 00 00 30 01 00 00
58 04 00 00 33 5F 30 00 88 05 00 00 0C 00 00 00 33 5F 31 00 94 05 00 00 EC 02 00 00
33 5F 32 00 80 08 00 00 3C 00 00 00 33 5F 33 00
|
success or wait |
652121298 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 844000
Length: 12E6D0 Allocation Type: unknown Protection: page read and write
|
success or wait |
652132695 |
Memory allocated |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 846000
Length: 12E7C0 Allocation Type: unknown Protection: page read and write
|
success or wait |
652233101 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
652234061 |
System info queried |
Type: BasicInformation |
success or wait |
652349272 |
System info queried |
Type: ProcessorInformation |
success or wait |
652350752 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000209FF-0000-0000-C000-000000000046}\InprocServer32
Name: InprocServer32
|
object name not found |
652574330 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000209FF-0000-0000-C000-000000000046}\LocalServer32
Name: LocalServer32
|
success or wait |
652797706 |
Section loaded |
Path: \KnownDlls\msi.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
652907204 |
File opened |
Path: C:\WINDOWS\system32\msi.dll Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
652907546 |
Section loaded |
Path: C:\WINDOWS\system32\msi.dll Access: query and write and read and execute Type:
image Baseaddress: 7D1E0000 Size: 2867200 Protection: read write Mapped to pid: own
pid
|
success or wait |
652907966 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7D1E2000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
653133807 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7D1E2000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
653134139 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7D1E2000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
653134350 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7D1E2000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
653242048 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7D1E2000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
653243918 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7D1E2000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
653245520 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7D1E2000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
653352971 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7D1E2000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
653354129 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7D1E2000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
653355089 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7D1E2000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
653463722 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7D1E2000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
653463888 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7D1E2000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
653464053 |
Process information queried |
PID: 1680 Info Class: Wow64Information |
success or wait |
653578099 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Group Policy\AppMgmt Name:
{90110409-6000-11D3-8CFE-0150048383C9}
|
object name not found |
653579403 |
Process information queried |
PID: 1680 Info Class: Wow64Information |
success or wait |
653691946 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer Name: Debug |
object name not found |
653692909 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer Name: DisableUserInstalls |
object name not found |
653803697 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: WORDFiles
|
success or wait |
653912061 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
654024896 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
654138954 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
success or wait |
654139179 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
654139601 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
654253235 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
654253957 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A453DD12EE71CEF49A4EB2A8684FB83A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
654362864 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
654365002 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
654472903 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5861C19D5F3D8C8439408F306F31034A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
654473961 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
654583351 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
654584475 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\311714883E93F274A838DDB012991F9D
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
654585487 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
654697336 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
654697548 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\72E940125B15C02498F17C8F91EADC14
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
654806059 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
654806417 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
654923512 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\16EFE5D0815A2D11A92E0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
654923921 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
655031815 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
655033762 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\41AE703BF87339947BDCC4715F97EFED
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
655035441 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
655148010 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
655149785 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: ProductFiles
|
success or wait |
655255014 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
655257707 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
655365795 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
success or wait |
655367158 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EAE1CE3652AD1140BB010C68A730687
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
655368074 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
655480442 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
655481508 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\379E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
655593278 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
655596728 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
655701011 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1650EACF3C291D11A92C0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
655701290 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
655812841 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
655813057 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19C2DC6651A24AD4BB2DE51C70F5C3E0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
655813332 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
655927150 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
656037964 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
656040289 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
656150955 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DBA0D1302088D1E44B6F7E0DC6732662
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
656152550 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
656261333 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
656262547 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2516E66D0FE30B64EB1CDE1F52E7C357
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
656263635 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
656374289 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
656375262 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
656486976 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
656487701 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
656595745 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
656595984 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE6545E80813C4542A70D28194279382
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
656596258 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
656709984 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
656711005 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
656822168 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A27DD755B98E23499AA660C6A835D0C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
656824767 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
656934059 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
656935197 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86FBBBBDC3EB97D4989B210DB8D577D2
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
657043965 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
657044385 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
657157001 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19A12162A748EF94E899C354C0912213
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
657157562 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
657269628 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
657270776 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
657383205 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
657384684 |
Process information queried |
PID: 1680 Info Class: DefaultHardErrorMode |
success or wait |
657495625 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles
|
success or wait |
657714991 |
Key value replaced with new |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles Type: dword Data: 1077411848 Old data: 1077411847
|
success or wait |
657715605 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000209FF-0000-0000-C000-000000000046}\InprocServer32
Name: NULL
|
object name not found |
657830186 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000209FF-0000-0000-C000-000000000046}\InprocHandler32
Name: NULL
|
success or wait |
658052142 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 12EE000
Length: 1000 New Protection: page read and write and page guard Old Protection: page
read and write
|
success or wait |
658390635 |
Thread created |
PID: 1680 TID: 776 EIP: 7C8106F9 EAX: 77E76C7D Imagepath: C:\Program Files\Microsoft
Office\OFFICE11\WINWORD.EXE
|
success or wait |
658498842 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
658499490 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
658501425 |
Thread resumed |
TID: 776 PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE |
success or wait |
658611877 |
System info queried |
Type: BasicInformation |
success or wait |
658836450 |
Message posted |
HWND: 11013E Message: 400 WParam: 47806 LParam: 1462916 |
success |
658837520 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000209FE-0000-0000-C000-000000000046}\LocalServer32
Name: LocalServer32
|
success or wait |
658839646 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Group Policy\AppMgmt Name:
{90110409-6000-11D3-8CFE-0150048383C9}
|
object name not found |
658840810 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: WORDFiles
|
success or wait |
659059223 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
659062100 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
659170533 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
success or wait |
659171737 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
659172968 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A453DD12EE71CEF49A4EB2A8684FB83A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
659392879 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5861C19D5F3D8C8439408F306F31034A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
659506583 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\311714883E93F274A838DDB012991F9D
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
659620288 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\72E940125B15C02498F17C8F91EADC14
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
659842210 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\16EFE5D0815A2D11A92E0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
659953959 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\41AE703BF87339947BDCC4715F97EFED
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
660065342 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: ProductFiles
|
success or wait |
660293340 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
660293824 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
660402822 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
success or wait |
660403966 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EAE1CE3652AD1140BB010C68A730687
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
660405265 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\379E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
660622855 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1650EACF3C291D11A92C0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
660737710 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19C2DC6651A24AD4BB2DE51C70F5C3E0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
660850823 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
660962848 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
661074753 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DBA0D1302088D1E44B6F7E0DC6732662
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
661185320 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2516E66D0FE30B64EB1CDE1F52E7C357
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
661298821 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
661520368 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
661521918 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE6545E80813C4542A70D28194279382
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
661634939 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
661856063 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A27DD755B98E23499AA660C6A835D0C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
661857163 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86FBBBBDC3EB97D4989B210DB8D577D2
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
662078261 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19A12162A748EF94E899C354C0912213
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
662192463 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
662418467 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles
|
success or wait |
662749581 |
Key value replaced with new |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles Type: dword Data: 1077411850 Old data: 1077411849
|
success or wait |
662751043 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000209FE-0000-0000-C000-000000000046}\InprocHandler32
Name: NULL
|
success or wait |
662972754 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
663199414 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
663201077 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000209F0-0000-0000-C000-000000000046}\InprocServer32
Name: InprocServer32
|
object name not found |
663643934 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000209F0-0000-0000-C000-000000000046}\InprocServer32
Name: NULL
|
object name not found |
663868430 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000209F0-0000-0000-C000-000000000046}
Name: AppID
|
object name not found |
664094468 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
664318782 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
664427493 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000209F1-0000-0000-C000-000000000046}\InprocServer32
Name: InprocServer32
|
object name not found |
664654887 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000209F1-0000-0000-C000-000000000046}\InprocServer32
Name: NULL
|
object name not found |
664877903 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000209F1-0000-0000-C000-000000000046}
Name: AppID
|
object name not found |
665101913 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
665323352 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
665435895 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000209F4-0000-0000-C000-000000000046}\InprocServer32
Name: InprocServer32
|
object name not found |
665657689 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000209F4-0000-0000-C000-000000000046}\InprocServer32
Name: NULL
|
object name not found |
665880914 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000209F4-0000-0000-C000-000000000046}
Name: AppID
|
object name not found |
666107298 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
666331062 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
666439530 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000209F5-0000-0000-C000-000000000046}\InprocServer32
Name: InprocServer32
|
object name not found |
666667029 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000209F5-0000-0000-C000-000000000046}\InprocServer32
Name: NULL
|
object name not found |
666889554 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000209F5-0000-0000-C000-000000000046}
Name: AppID
|
object name not found |
667111028 |
Section loaded |
Path: \KnownDlls\SHELL32.dll Access: write and read and execute Type: unknown Baseaddress:
7C9C0000 Size: 8482816 Protection: read write Mapped to pid: own pid
|
success or wait |
667336617 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
667450123 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
667560105 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
667561968 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
667564211 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
667671534 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
667672166 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
667672642 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
667782257 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
667783382 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
667783818 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
667895357 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
667895800 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
667896208 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
668006228 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
668007698 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
668009024 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\Setup Name: SystemSetupInProgress |
success or wait |
668118379 |
File opened |
Path: C:\WINDOWS\system32\SHELL32.dll Access: read data or list directory and read
ea and execute or traverse and read attributes and read control and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
668122987 |
Section loaded |
Path: C:\WINDOWS\system32\shell32.dll Access: read Type: commit Baseaddress: 12F0000
Size: 8462336 Protection: readonly Mapped to pid: own pid
|
success or wait |
668229546 |
File opened |
Path: C:\WINDOWS\system32\SHELL32.dll.124.Manifest Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
668230235 |
File opened |
Path: C:\WINDOWS\system32\SHELL32.dll.124.Config Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
668348163 |
File opened |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
Access: execute or traverse and synchronize Options: directory file and synchronous
io non alert Overwritten: false
|
success or wait |
668363938 |
Section loaded |
Path: \KnownDlls\comctl32.dll Access: write and read and execute Type: unknown Baseaddress:
5D090000 Size: 630784 Protection: read write Mapped to pid: own pid
|
success or wait |
668364628 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5D091000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
668566664 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5D091000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
668567957 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5D091000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
668569005 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5D091000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
668677632 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5D091000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
668680159 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5D091000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
668681634 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5D091000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
668789806 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5D091000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
668790365 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5D091000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
668790882 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5D091000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
668902297 |
System info queried |
Type: BasicInformation |
success or wait |
668904261 |
File opened |
Path: C:\WINDOWS\system32\comctl32.dll Access: read data or list directory and read
ea and execute or traverse and read attributes and read control and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
669124130 |
Section loaded |
Path: C:\WINDOWS\system32\comctl32.dll Access: read Type: commit Baseaddress: 1300000
Size: 618496 Protection: readonly Mapped to pid: own pid
|
success or wait |
669124612 |
File opened |
Path: C:\WINDOWS\system32\comctl32.dll.124.Manifest Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
669241617 |
File opened |
Path: C:\WINDOWS\system32\comctl32.dll.124.Config Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
669242233 |
Process information queried |
PID: 1680 Info Class: SessionInformation |
success or wait |
669351994 |
Key value queried |
Path: HKEY_USERS\Control Panel\Desktop Name: SmoothScroll |
object name not found |
669463203 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: ScriptAnchorVis |
object name not found |
670362508 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Proofing Tools Name: FormatConsistencyWavyUnderlineColor |
object name not found |
670581785 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Toolbars Name: BtnSize |
object name not found |
670693281 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Toolbars Name: Transparency |
object name not found |
670805031 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Toolbars Name: AdaptiveMenus |
object name not found |
670805260 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Toolbars Name: AutoExpandMenus |
object name not found |
670805462 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Toolbars Name: Tooltips |
object name not found |
670913890 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Toolbars\Settings Name: Microsoft
Office Word AWDropdownHidden
|
object name not found |
671031376 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Data Name: Toolbars |
buffer overflow |
671031914 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Data Name: Toolbars |
buffer overflow |
671590815 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Data Name: Toolbars |
success or wait |
671697934 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Toolbars\Settings Name: Microsoft
Office Word
|
success or wait |
672263520 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Toolbars\Settings Name: Microsoft
Office Word
|
success or wait |
672369066 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: GlobalDotName |
object name not found |
672594478 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
672596001 |
Directory Information Queried |
Path: C:\Program Files\Microsoft Office\OFFICE11Disposition: BothDirectoryInformation
Filemask: Normal.dot Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9b3e5e
|
no such file |
672703628 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Templates\
Access: read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
672704317 |
Directory Information Queried |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\TemplatesDisposition:
BothDirectoryInformation Filemask: Normal.dot Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ba640
|
success or wait |
672820115 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems Name:
S
|
object name not found |
673264914 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems Name:
S Type: binary Data: 53 15 15 00 90 06 00 00 04 00 00 00 00 00 00 00 BE 00 00 00
01 00 00 00 B6 00 00 00 57 00 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00
6E 00 74 00 73 00 20 00 61 00 6E 00 64 00 20 00 53 00 65 00 74 00 74 00 69 00 6E 00
67 00 73 00 5C 00 41 00 64 00 6D 00 69 00 6E 00 69 00 73 00 74 00 72 00 61 00 74 00
6F 00 72 00 5C 00 41 00 70 00 70 00 6C 00 69 00 63 00 61 00 74 00 69 00 6F 00 6E 00
20 00 44 00 61 00 74 00 61 00 5C 00 4D 00 69 00 63 00 72 00 6F 00 73 00 6F 00 66 00
74 00 5C 00 54 00 65 00 6D 00 70 00 6C 00 61 00 74 00 65 00 73 00 5C 00 4E 00 6F 00
72 00 6D 00 61 00 6C 00 2E 00 64 00 6F 00 74 00 00 00 00 00 00 00 Old data:
|
success or wait |
673265838 |
Section loaded |
Path: \BaseNamedObjects\DfSharedHeap150FE5 Access: query and write and read Type:
reserve Baseaddress: 13B0000 Size: 4194304 Protection: read write Mapped to pid: own
pid
|
success or wait |
673380285 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Templates\Normal.dot
Access: read attributes and synchronize and generic read and generic write Options:
synchronous io non alert and non directory file Attributes: normal Content Overwritten:
true
|
success or wait |
673710432 |
System info queried |
Type: PerformanceInformation |
success or wait |
673711649 |
Process information queried |
PID: 1680 Info Class: QuotaLimits |
success or wait |
673711920 |
Process information queried |
PID: 1680 Info Class: VmCounters |
success or wait |
673823244 |
Section loaded |
Path: \BaseNamedObjects\DFMap0-1380330 Access: query and write and read Type: commit
Baseaddress: 17B0000 Size: 524288 Protection: read write Mapped to pid: own pid
|
success or wait |
673823699 |
Section loaded |
Path: \BaseNamedObjects\DfRoot000150FE5 Access: query and write and read Type: commit
Baseaddress: 1390000 Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
674270650 |
File created |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFFF7.tmp Access: read attributes and delete
and synchronize and generic read and generic write Options: synchronous io non alert
and non directory file and delete on close Attributes: temporary Content Overwritten:
true
|
success or wait |
674494042 |
File other op |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFFF7.tmp New path: Disposition: PositionInformation
Data : Offset: 512
|
success or wait |
674609341 |
File other op |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFFF7.tmp New path: Disposition: EndOfFileInformation
Data : unknown
|
success or wait |
674610128 |
File other op |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFFF7.tmp New path: Disposition: AllocationInformation
Data : unknown
|
success or wait |
674720114 |
File other op |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFFF7.tmp New path: Disposition: PositionInformation
Data : Offset: 0
|
success or wait |
674721661 |
System info queried |
Type: PerformanceInformation |
success or wait |
674831715 |
Process information queried |
PID: 1680 Info Class: QuotaLimits |
success or wait |
674834346 |
Process information queried |
PID: 1680 Info Class: VmCounters |
success or wait |
674836209 |
Section loaded |
Path: \BaseNamedObjects\DFMap0-1380356 Access: query and write and read Type: commit
Baseaddress: 1830000 Size: 524288 Protection: read write Mapped to pid: own pid
|
success or wait |
674940919 |
File created |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Templates\~$Normal.dot
Access: read attributes and synchronize and generic write Options: synchronous io
non alert and non directory file and open no recall Attributes: hidden Content Overwritten:
true
|
success or wait |
675727033 |
File write |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Templates\~$Normal.dot
Offset: unknown Length: 54 Value: 0D 48 61 6E 75 65 6C 65 20 42 61 73 65 72 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
|
success or wait |
675838580 |
File write |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Templates\~$Normal.dot
Offset: unknown Length: 108 Value: 0D 00 48 00 61 00 6E 00 75 00 65 00 6C 00 65 00
20 00 42 00 61 00 73 00 65 00 72 00 00 00 00 00 1E 00 00 00 0D 00 48 00 61 00 6E 00
75 00 65 00 6C 00 65 00 20 00 42 00 61 00 73 00 65 00 72 00 00 00 00 00 1E 00 00 00
01 00 00 00 01 00 00 00 0E 00 00 00 10 00 00 00 3E 03 00 00 E2 03 FF 00 00 00 50 00
|
success or wait |
675841500 |
Key value deleted |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems Keyname:
S
|
success or wait |
677962553 |
Key value queried |
Path: HKEY_USERS\Control Panel\International Name: NumShape |
success or wait |
678413552 |
Window created |
Window Name: _WwC Class Name: _WwC HWND: F010A |
success |
678521107 |
Message sent |
HWND: F010A Message: NCCREATE WParam: 0 LParam: 1238660 |
success |
678521507 |
Window shown |
HWND: F010A CMD: show normal |
error |
678522218 |
Window created |
Window Name: _WwF Class Name: _WwF HWND: 1400DE |
success |
678746417 |
Message sent |
HWND: 1400DE Message: NCCREATE WParam: 0 LParam: 1238700 |
success |
678747129 |
Message sent |
HWND: 1400DE Message: NCCALCSIZE WParam: 0 LParam: 1238752 |
error |
678856753 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: UseAlternateForegroundWindowDetectionMethod |
object name not found |
678859194 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: UseSpaceAsTextDelimiter |
object name not found |
678860404 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: AlternateTableHeightLayout |
object name not found |
678968618 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: AdjustSdtCaSmart |
object name not found |
678968879 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: MMDataSrcHeuristic |
object name not found |
678969114 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: DontJumpForegroundInDDEExec |
object name not found |
679081674 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: DisableODSOUIInDataSrc |
object name not found |
679081884 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: UseTempCopyForNonLocDoc |
object name not found |
679082089 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: KeepUISpecModeAtVbaEnd |
object name not found |
679195675 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: UseAlternatePageNumberFormat |
object name not found |
679195893 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: AlternateStyleCopyPasteNoOverwrite |
object name not found |
679196099 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
679533710 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
679642022 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020906-0000-0000-C000-000000000046}\InprocServer32
Name: InprocServer32
|
object name not found |
679863048 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020906-0000-0000-C000-000000000046}\LocalServer32
Name: LocalServer32
|
success or wait |
679978203 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Group Policy\AppMgmt Name:
{90110409-6000-11D3-8CFE-0150048383C9}
|
object name not found |
680089715 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: WORDFiles
|
success or wait |
680202763 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
680314715 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
680316071 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
success or wait |
680423272 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
680424122 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A453DD12EE71CEF49A4EB2A8684FB83A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
680538646 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5861C19D5F3D8C8439408F306F31034A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
680757759 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\311714883E93F274A838DDB012991F9D
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
680869816 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\72E940125B15C02498F17C8F91EADC14
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
680986005 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\16EFE5D0815A2D11A92E0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
681207007 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\41AE703BF87339947BDCC4715F97EFED
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
681322317 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: ProductFiles
|
success or wait |
681431956 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
681544060 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
681544320 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
success or wait |
681652971 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EAE1CE3652AD1140BB010C68A730687
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
681653500 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\379E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
681767781 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1650EACF3C291D11A92C0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
681989002 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19C2DC6651A24AD4BB2DE51C70F5C3E0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
682100744 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
682214467 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
682214998 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DBA0D1302088D1E44B6F7E0DC6732662
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
682437992 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2516E66D0FE30B64EB1CDE1F52E7C357
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
682552590 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
682666693 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
682775669 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE6545E80813C4542A70D28194279382
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
682885608 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
683000368 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A27DD755B98E23499AA660C6A835D0C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
683109509 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86FBBBBDC3EB97D4989B210DB8D577D2
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
683219076 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19A12162A748EF94E899C354C0912213
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
683443574 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
683669182 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles
|
success or wait |
683898155 |
Key value replaced with new |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles Type: dword Data: 1077411852 Old data: 1077411851
|
success or wait |
684004223 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020906-0000-0000-C000-000000000046}\InprocServer32
Name: NULL
|
object name not found |
684119189 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020906-0000-0000-C000-000000000046}\InprocHandler32
Name: NULL
|
success or wait |
684337226 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
684564753 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
684565215 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020906-0000-0000-C000-000000000046}\InprocServer32
Name: InprocServer32
|
object name not found |
684790375 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020906-0000-0000-C000-000000000046}\LocalServer32
Name: LocalServer32
|
success or wait |
685010691 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Group Policy\AppMgmt Name:
{90110409-6000-11D3-8CFE-0150048383C9}
|
object name not found |
685123257 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: WORDFiles
|
success or wait |
685232272 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
685350242 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
685350551 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
success or wait |
685351158 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
685457338 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A453DD12EE71CEF49A4EB2A8684FB83A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
685569596 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5861C19D5F3D8C8439408F306F31034A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
685681010 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\311714883E93F274A838DDB012991F9D
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
685905459 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\72E940125B15C02498F17C8F91EADC14
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
686018817 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\16EFE5D0815A2D11A92E0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
686127990 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\41AE703BF87339947BDCC4715F97EFED
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
686407356 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: ProductFiles
|
success or wait |
686520602 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
686631304 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
686633145 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
success or wait |
686634674 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EAE1CE3652AD1140BB010C68A730687
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
686743949 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\379E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
686857000 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1650EACF3C291D11A92C0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
686968973 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19C2DC6651A24AD4BB2DE51C70F5C3E0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
687191514 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
687302276 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
687302886 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DBA0D1302088D1E44B6F7E0DC6732662
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
687416648 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2516E66D0FE30B64EB1CDE1F52E7C357
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
687637757 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
687753424 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
687754653 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE6545E80813C4542A70D28194279382
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
687973837 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
688084741 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A27DD755B98E23499AA660C6A835D0C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
688196937 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86FBBBBDC3EB97D4989B210DB8D577D2
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
688309358 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19A12162A748EF94E899C354C0912213
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
688422119 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
688649617 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles
|
success or wait |
688984286 |
Key value replaced with new |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles Type: dword Data: 1077411853 Old data: 1077411852
|
success or wait |
688985522 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020906-0000-0000-C000-000000000046}\InprocServer32
Name: NULL
|
object name not found |
689205412 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020906-0000-0000-C000-000000000046}\InprocHandler32
Name: NULL
|
success or wait |
689317831 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
689435859 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
689544401 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020907-0000-0000-C000-000000000046}\LocalServer32
Name: LocalServer32
|
success or wait |
689874357 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Group Policy\AppMgmt Name:
{90110409-6000-11D3-8CFE-0150048383C9}
|
object name not found |
689874997 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: WORDFiles
|
success or wait |
690100910 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
690101797 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
690211033 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
success or wait |
690211816 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
690212718 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A453DD12EE71CEF49A4EB2A8684FB83A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
690433735 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5861C19D5F3D8C8439408F306F31034A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
690548302 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\311714883E93F274A838DDB012991F9D
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
690664684 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\72E940125B15C02498F17C8F91EADC14
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
690882165 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\16EFE5D0815A2D11A92E0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
690993208 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\41AE703BF87339947BDCC4715F97EFED
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
691109069 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: ProductFiles
|
success or wait |
691332079 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
691334669 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
691442360 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
success or wait |
691443430 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EAE1CE3652AD1140BB010C68A730687
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
691444646 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\379E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
691664359 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1650EACF3C291D11A92C0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
691777234 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19C2DC6651A24AD4BB2DE51C70F5C3E0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
691889911 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
692001861 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
692113259 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DBA0D1302088D1E44B6F7E0DC6732662
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
692224441 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2516E66D0FE30B64EB1CDE1F52E7C357
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
692337587 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
692564918 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
692566566 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE6545E80813C4542A70D28194279382
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
692672567 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
692895892 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A27DD755B98E23499AA660C6A835D0C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
692896803 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86FBBBBDC3EB97D4989B210DB8D577D2
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
693120124 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19A12162A748EF94E899C354C0912213
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
693233495 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
693454281 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles
|
success or wait |
693846305 |
Key value replaced with new |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles Type: dword Data: 1077411855 Old data: 1077411854
|
success or wait |
693847010 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020907-0000-0000-C000-000000000046}\InprocHandler32
Name: NULL
|
success or wait |
694071219 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
694294695 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
694406326 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020907-0000-0000-C000-000000000046}\LocalServer32
Name: LocalServer32
|
success or wait |
694632096 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Group Policy\AppMgmt Name:
{90110409-6000-11D3-8CFE-0150048383C9}
|
object name not found |
694742482 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: WORDFiles
|
success or wait |
694855707 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
694967258 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
694968441 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
success or wait |
695077142 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
695078676 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A453DD12EE71CEF49A4EB2A8684FB83A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
695188906 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5861C19D5F3D8C8439408F306F31034A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
695412821 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\311714883E93F274A838DDB012991F9D
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
695526797 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\72E940125B15C02498F17C8F91EADC14
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
695640477 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\16EFE5D0815A2D11A92E0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
695860372 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\41AE703BF87339947BDCC4715F97EFED
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
695970984 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: ProductFiles
|
success or wait |
696085827 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
696196932 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
696198335 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
success or wait |
696308643 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EAE1CE3652AD1140BB010C68A730687
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
696309822 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\379E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
696419635 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1650EACF3C291D11A92C0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
696642700 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19C2DC6651A24AD4BB2DE51C70F5C3E0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
696756388 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
696866585 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
696866860 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DBA0D1302088D1E44B6F7E0DC6732662
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
697093069 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2516E66D0FE30B64EB1CDE1F52E7C357
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
697205031 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
697318076 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
697427166 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE6545E80813C4542A70D28194279382
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
697539528 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
697652139 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A27DD755B98E23499AA660C6A835D0C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
697760753 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86FBBBBDC3EB97D4989B210DB8D577D2
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
697876109 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19A12162A748EF94E899C354C0912213
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
698097745 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
698320972 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles
|
success or wait |
698547633 |
Key value replaced with new |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles Type: dword Data: 1077411856 Old data: 1077411855
|
success or wait |
698655353 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020907-0000-0000-C000-000000000046}\InprocHandler32
Name: NULL
|
success or wait |
698882789 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: AddIns |
success or wait |
698991713 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Word\Addins\WebPage.Connect Name: LoadBehavior |
success or wait |
699215639 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
699217634 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Word\Addins\WebPage.Connect Name: FileName |
object name not found |
699327094 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Word\Addins\WordEEFonts.Connect Name: LoadBehavior |
success or wait |
699550233 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WordEEFonts.Connect\Clsid Name: NULL |
success or wait |
699550625 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Word\Addins\WordEEFonts.Connect Name: FriendlyName |
success or wait |
699663883 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAD90BC7-5321-4048-939A-694B0A274C02}\InprocServer32
Name: NULL
|
success or wait |
699780575 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Word\Addins\WebPage.Connect Name: LoadBehavior |
success or wait |
699997965 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Word\Addins\WebPage.Connect Name: FileName |
object name not found |
700110783 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Word\Addins\WordEEFonts.Connect Name: LoadBehavior |
success or wait |
700111813 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WordEEFonts.Connect\Clsid Name: NULL |
success or wait |
700224283 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Word\Addins\WordEEFonts.Connect Name: FriendlyName |
success or wait |
700335739 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAD90BC7-5321-4048-939A-694B0A274C02}\InprocServer32
Name: NULL
|
success or wait |
700449690 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\CTF Name: Disable Thread Input Manager |
object name not found |
700672954 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{1188450c-fdab-47ae-80d8-c9633f71be64}\LanguageProfile\0x00000000\{63800dac-e7ca-4df9-9a5c-20765055488d}
Name: Enable
|
success or wait |
700949537 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\LanguageProfile\0x00000409\{09EA4E4B-46CE-4469-B450-0DE76A435BBB}
Name: Enable
|
success or wait |
701061670 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\LanguageProfile\0x00000807\{09EA4E4B-46CE-4469-B450-0DE76A435BBB}
Name: Enable
|
success or wait |
701177878 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\LanguageProfile\0x0000ffff\{09EA4E4B-46CE-4469-B450-0DE76A435BBB}
Name: Enable
|
success or wait |
701287493 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{EB030009-6D26-11D3-B0F4-00C04F60B2A1}\LanguageProfile\0x00000009\{5ACC0009-C1BE-441D-8F1C-BE3A99988A1A}
Name: Enable
|
object name not found |
701512188 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
702185537 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
702297564 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\InProcServer32
Name: InprocServer32
|
object name not found |
702518105 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\InProcServer32
Name: NULL
|
success or wait |
702742893 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}
Name: AppID
|
object name not found |
702969579 |
Process information queried |
PID: 1680 Info Class: SessionInformation |
success or wait |
703187755 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\InProcServer32
Name: ThreadingModel
|
success or wait |
703302107 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\CTF Name: Disable Thread Input Manager |
object name not found |
703522426 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{1188450c-fdab-47ae-80d8-c9633f71be64}\LanguageProfile\0x00000000\{63800dac-e7ca-4df9-9a5c-20765055488d}
Name: Enable
|
success or wait |
703636870 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\LanguageProfile\0x00000409\{09EA4E4B-46CE-4469-B450-0DE76A435BBB}
Name: Enable
|
success or wait |
703859145 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\LanguageProfile\0x00000807\{09EA4E4B-46CE-4469-B450-0DE76A435BBB}
Name: Enable
|
success or wait |
703970997 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{EB030009-6D26-11D3-B0F4-00C04F60B2A1}\LanguageProfile\0x00000009\{5ACC0009-C1BE-441D-8F1C-BE3A99988A1A}
Name: Enable
|
object name not found |
704087013 |
Window created |
Window Name: CicMarshalWndClass Class Name: CicMarshalWndClass HWND: 1700D6 |
success |
704529093 |
Message sent |
HWND: 1700D6 Message: NCCREATE WParam: 0 LParam: 1238784 |
success |
704530139 |
Message sent |
HWND: 1700D6 Message: NCCALCSIZE WParam: 0 LParam: 1238848 |
error |
704641443 |
Key value queried |
Path: HKEY_USERS\Keyboard Layout\Toggle Name: Language Hotkey |
success or wait |
704752477 |
Key value queried |
Path: HKEY_USERS\Keyboard Layout\Toggle Name: Language Hotkey |
success or wait |
704753943 |
Key value queried |
Path: HKEY_USERS\Keyboard Layout\Toggle Name: Layout Hotkey |
success or wait |
704755159 |
Key value queried |
Path: HKEY_USERS\Keyboard Layout\Toggle Name: Layout Hotkey |
success or wait |
704865935 |
Section loaded |
Path: \BaseNamedObjects\CTF.AsmListCache.FMPDefaultS-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read and execute and extend size Type: unknown Baseaddress:
18C0000 Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
704867002 |
Message posted |
TID: 6C4 Message: C0D4 WParam: 0 LParam: 1144 |
success |
704984536 |
Message posted |
TID: 6C4 Message: C0D4 WParam: 0 LParam: 1144 |
success |
705090680 |
Message posted |
TID: 6C4 Message: C0D4 WParam: 0 LParam: 1144 |
success |
705200390 |
Message posted |
TID: 6C4 Message: C0D4 WParam: 0 LParam: 1144 |
success |
705312199 |
Message posted |
TID: 6C4 Message: C0D4 WParam: 0 LParam: 1144 |
success |
705425079 |
Message posted |
TID: 6C4 Message: C0D4 WParam: 0 LParam: 1144 |
success |
705537057 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Item\{5130A009-5540-4FCF-97EB-AAD33FC0EE09}
Name: Description
|
success or wait |
705540372 |
Message posted |
TID: 6C4 Message: C0D4 WParam: 0 LParam: 1144 |
success |
705652297 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Item\{7AE86BB7-262C-431E-9111-C974B6B7CAC3}
Name: Description
|
success or wait |
705759745 |
Message posted |
TID: 6C4 Message: C0D4 WParam: 0 LParam: 1144 |
success |
705870972 |
Message posted |
TID: 6C4 Message: C0D4 WParam: 0 LParam: 1144 |
success |
705982189 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Item\{C6DEBC0A-F2B2-4F17-930E-CA9FAFF4CD04}
Name: Description
|
success or wait |
705982583 |
Message posted |
TID: 6C4 Message: C0D4 WParam: 0 LParam: 1144 |
success |
706207361 |
Message posted |
TID: 6C4 Message: C0D4 WParam: 0 LParam: 1144 |
success |
706318566 |
Key value queried |
Path: HKEY_USERS\Keyboard Layout\Toggle Name: Language Hotkey |
success or wait |
706319502 |
Key value queried |
Path: HKEY_USERS\Keyboard Layout\Toggle Name: Language Hotkey |
success or wait |
706429846 |
Key value queried |
Path: HKEY_USERS\Keyboard Layout\Toggle Name: Layout Hotkey |
success or wait |
706430482 |
Key value queried |
Path: HKEY_USERS\Keyboard Layout\Toggle Name: Layout Hotkey |
success or wait |
706431067 |
Message posted |
TID: 6C4 Message: C0D4 WParam: 0 LParam: 1144 |
success |
706541663 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
706654312 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
706656730 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F6240000-66DA-4DCD-B1AF-5C59D05C44D5}\InProcServer32
Name: InprocServer32
|
success or wait |
706881655 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Group Policy\AppMgmt Name:
{90110409-6000-11D3-8CFE-0150048383C9}
|
object name not found |
706990414 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: HandWritingFiles
|
success or wait |
707101384 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: HandWritingFiles
|
buffer overflow |
707216918 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: HandWritingFiles
|
buffer overflow |
707217221 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: HandWritingFiles
|
success or wait |
707325802 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\26A1D654F1CD2C5419F0CFBDD0EC5426
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
707327430 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\77A6C50B0818FF24C9A3CA8C5C840F62
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
707440917 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305DFB6E53A387B4AB5B5907DEED8FC1
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
707661752 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9ABF7A34E07A0F846B40A1CD3B6B7622
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
707773130 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C35B6345B31CD48A1931D60F67FE57
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
707885698 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D7D0EE1FCB8897C43BEA70BDE543DBC8
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
708169709 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E5056F83DF210DB479948618407D5B25
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
708277394 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E5056F83DF210DB479948618407D5B25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
708278515 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{EB030009-6D26-11D3-B0F4-00C04F60B2A1}\LanguageProfile\0x00000009\{5ACF0009-C1BE-441D-8F1C-BE3A99988A1A}
Name: IconFile
|
success or wait |
708390648 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C9421C9BDD484A4CBF9A48F1D92A11E
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
708499257 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: CiceroFiles
|
success or wait |
708612961 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: CiceroFiles
|
buffer overflow |
708723735 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: CiceroFiles
|
buffer overflow |
708725465 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: CiceroFiles
|
success or wait |
708726874 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\05806B5C18291C44CA6A30A473464181
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
708836095 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\44E6413DF93B16D439DC7042D1898218
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
708949126 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7C9F46774DBF2F846999DB0CBD86FE9C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
709061734 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED699B319D85EE944BCABC3C645DA72E
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
709175127 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E756F3931A7D36D41910807B21EF2DEF
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
709283293 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9952CE8A6F4347F429B435E5522D4D83
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
709396244 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4446BF3DB74EE0448B293239261DB133
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
709506476 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B52B2F43E7E9C1A49B133B59F721FD61
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
709730462 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ADFA829F04F7E9949A3C18C5E7FB15B6
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
709846097 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9ACCB00205ED3804B8253CAA152165A4
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
709956658 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C732F8EB832D9E74095F45793F710C32
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
710065576 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: SHAREDFiles
|
success or wait |
710179074 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: SHAREDFiles
|
success or wait |
710289187 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: SHAREDFiles
|
success or wait |
710289496 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
710401496 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: ProductFiles
|
success or wait |
710404036 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
710515883 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
710517235 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
success or wait |
710625091 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EAE1CE3652AD1140BB010C68A730687
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
710626750 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\379E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
710737688 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1650EACF3C291D11A92C0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
710962285 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19C2DC6651A24AD4BB2DE51C70F5C3E0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
711075348 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
711192652 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
711193891 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DBA0D1302088D1E44B6F7E0DC6732662
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
711409374 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2516E66D0FE30B64EB1CDE1F52E7C357
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
711522124 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
711637322 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
711743670 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE6545E80813C4542A70D28194279382
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
711856023 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
711968641 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A27DD755B98E23499AA660C6A835D0C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
712078986 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86FBBBBDC3EB97D4989B210DB8D577D2
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
712197139 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19A12162A748EF94E899C354C0912213
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
712415452 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305DFB6E53A387B4AB5B5907DEED8FC1
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
712640670 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: HandWritingFiles
|
success or wait |
712973956 |
Key value replaced with new |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: HandWritingFiles Type: dword Data: 1077411842 Old data: 1077411841
|
success or wait |
712974258 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F6240000-66DA-4DCD-B1AF-5C59D05C44D5}
Name: AppID
|
object name not found |
713312046 |
Process information queried |
PID: 1680 Info Class: SessionInformation |
success or wait |
713423703 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F6240000-66DA-4DCD-B1AF-5C59D05C44D5}\InProcServer32
Name: ThreadingModel
|
success or wait |
713645912 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\INK\SKCHUI.DLL Access: execute
or traverse and synchronize Options: synchronous io non alert and non directory file
Overwritten: false
|
success or wait |
713760288 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\INK\SKCHUI.DLL Access: write
and read and execute Type: commit Baseaddress: 18C0000 Size: 368640 Protection: execute
Mapped to pid: own pid
|
success or wait |
713868631 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\INK\SKCHUI.DLL Access: execute
or traverse and synchronize Options: synchronous io non alert and non directory file
Overwritten: false
|
success or wait |
713983738 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\INK\SKCHUI.DLL Access: query
and write and read and execute Type: image Baseaddress: 10000000 Size: 372736 Protection:
read write Mapped to pid: own pid
|
success or wait |
713984928 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 1003E000
Length: 1000 New Protection: page read and write Old Protection: page readonly
|
success or wait |
714209823 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 1003E000
Length: 1000 New Protection: page readonly Old Protection: page read and write
|
success or wait |
714211925 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 1003E000
Length: 1000 New Protection: page read and write Old Protection: page readonly
|
success or wait |
714316164 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 1003E000
Length: 1000 New Protection: page readonly Old Protection: page read and write
|
success or wait |
714316886 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 1003E000
Length: 1000 New Protection: page read and write Old Protection: page readonly
|
success or wait |
714317446 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 1003E000
Length: 1000 New Protection: page readonly Old Protection: page read and write
|
success or wait |
714429378 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 1003E000
Length: 1000 New Protection: page read and write Old Protection: page readonly
|
success or wait |
714430625 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 1003E000
Length: 1000 New Protection: page readonly Old Protection: page read and write
|
success or wait |
714431136 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 1003E000
Length: 1000 New Protection: page read and write Old Protection: page readonly
|
success or wait |
714541066 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 1003E000
Length: 1000 New Protection: page readonly Old Protection: page read and write
|
success or wait |
714542468 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 1003E000
Length: 1000 New Protection: page read and write Old Protection: page readonly
|
success or wait |
714543654 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 1003E000
Length: 1000 New Protection: page readonly Old Protection: page read and write
|
success or wait |
714653248 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 1003E000
Length: 1000 New Protection: page read and write Old Protection: page readonly
|
success or wait |
714654532 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 1003E000
Length: 1000 New Protection: page readonly Old Protection: page read and write
|
success or wait |
714655610 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 1003E000
Length: 1000 New Protection: page read and write Old Protection: page readonly
|
success or wait |
714767215 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 1003E000
Length: 1000 New Protection: page readonly Old Protection: page read and write
|
success or wait |
714769154 |
System info queried |
Type: BasicInformation |
success or wait |
714771019 |
Process information queried |
PID: 1680 Info Class: Cookie |
success or wait |
715102386 |
Process information queried |
PID: 1680 Info Class: Cookie |
success or wait |
715103240 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\MSHandwritingTIP\sketch Name: BLeftHanded |
object name not found |
715213760 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\MSHandwritingTIP\sketch Name: nDrawWidth |
object name not found |
715216366 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\MSHandwritingTIP\sketch Name: clrForeColor |
object name not found |
715326012 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\MSHandwritingTIP\sketch Name: BLargeButtons |
object name not found |
715491193 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
715494110 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
715604333 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33C53A50-F456-4884-B049-85FD643ECFED}\InProcServer32
Name: InprocServer32
|
object name not found |
715830842 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33C53A50-F456-4884-B049-85FD643ECFED}\InProcServer32
Name: NULL
|
success or wait |
716049827 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33C53A50-F456-4884-B049-85FD643ECFED}
Name: AppID
|
object name not found |
716277330 |
Process information queried |
PID: 1680 Info Class: SessionInformation |
success or wait |
716498245 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33C53A50-F456-4884-B049-85FD643ECFED}\InProcServer32
Name: ThreadingModel
|
success or wait |
716613322 |
Window created |
Window Name: CiceroUIWndFrame Class Name: CiceroUIWndFrame HWND: 1700B0 |
success |
716838918 |
Message sent |
HWND: 1700B0 Message: NCCREATE WParam: 0 LParam: 1238344 |
success |
716945079 |
Message sent |
HWND: 1700B0 Message: NCCALCSIZE WParam: 0 LParam: 1238408 |
error |
716945601 |
Window created |
Window Name: CiceroUIWndFrame Class Name: CiceroUIWndFrame HWND: 1D00FA |
success |
716946403 |
Message sent |
HWND: 1D00FA Message: NCCREATE WParam: 0 LParam: 1238328 |
success |
717057139 |
Message sent |
HWND: 1D00FA Message: NCCALCSIZE WParam: 0 LParam: 1238392 |
error |
717057891 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\MSHandwritingTIP\sketch Name: CLSIDOtherTIP |
object name not found |
717059187 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\MSHandwritingTIP\sketch Name: RectWindowPosition |
success or wait |
717169309 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\MSHandwritingTIP\sketch Name: RectWindowPosition |
success or wait |
717169844 |
Message sent |
HWND: 1700B0 Message: WINDOWPOSCHANGING WParam: 0 LParam: 1239456 |
error |
717280384 |
Message sent |
HWND: 1700B0 Message: NCCALCSIZE WParam: 1 LParam: 1239412 |
error |
717280480 |
Message sent |
HWND: 1700B0 Message: WINDOWPOSCHANGING WParam: 0 LParam: 1239440 |
error |
717396098 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 1A012E |
success |
722538857 |
Message sent |
HWND: 1A012E Message: NCCREATE WParam: 0 LParam: 1238356 |
success |
722539210 |
Message sent |
HWND: 1A012E Message: NCCALCSIZE WParam: 0 LParam: 1238396 |
error |
722708260 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\MSHandwritingTIP\sketch Name: BShowTipVersion |
object name not found |
722708663 |
Message sent |
HWND: 1A012E Message: CANCELMODE WParam: 0 LParam: 0 |
error |
722818581 |
Message posted |
TID: 6C4 Message: C0D4 WParam: 0 LParam: 1144 |
success |
722818788 |
Mutant created |
Name: \BaseNamedObjects\MSCTF.GCompartListMUTEX.DefaultS-1-5-21-507921405-1960408961-839522115-500 |
object name exists |
723042187 |
Section loaded |
Path: \BaseNamedObjects\MSCTF.GCompartListSFM.DefaultS-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read Type: reserve Baseaddress: unknown Size: unknown
Protection: unknown Mapped to pid: unknown
|
object name exists |
723044290 |
Window shown |
HWND: F010A CMD: show normal |
success |
723377118 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: QuickPreview |
object name not found |
723377731 |
Window shown |
HWND: F010A CMD: show normal |
success |
723490607 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Name: Local AppData
|
success or wait |
723712192 |
Key value replaced with same |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Name: Local AppData Type: unicode Data: C:\Documents and Settings\Administrator\Local
Settings\Application Data Old data:
|
success or wait |
723824475 |
File opened |
Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Schemas\MS
Word_restart.xml Access: read attributes and delete Options: non directory file and
open for backup ident and open reparse point Overwritten: false
|
object path not found |
724049095 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: STARTUP-PATH |
object name not found |
724051360 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: Startup |
success or wait |
724160807 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Word\STARTUP\
Access: read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
724498186 |
Directory Information Queried |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Word\STARTUPDisposition:
BothDirectoryInformation Filemask: * Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13fc437
|
success or wait |
724498647 |
Directory Information Queried |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Word\STARTUPDisposition:
BothDirectoryInformation Filemask: unknown Data : abstraction.selector.functions.gen.NtFunc$FunctionData@16b340a
|
success or wait |
724723918 |
Directory Information Queried |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Word\STARTUPDisposition:
BothDirectoryInformation Filemask: unknown Data : abstraction.selector.functions.gen.NtFunc$FunctionData@125bbd3
|
no more files |
724724028 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\STARTUP\ Access: read data or list
directory and synchronize Options: directory file and synchronous io non alert and
open for backup ident Overwritten: false
|
success or wait |
724837153 |
Directory Information Queried |
Path: C:\Program Files\Microsoft Office\OFFICE11\STARTUPDisposition: BothDirectoryInformation
Filemask: * Data : abstraction.selector.functions.gen.NtFunc$FunctionData@4e37fb
|
success or wait |
724838178 |
Directory Information Queried |
Path: C:\Program Files\Microsoft Office\OFFICE11\STARTUPDisposition: BothDirectoryInformation
Filemask: unknown Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13d556f
|
success or wait |
724945000 |
Directory Information Queried |
Path: C:\Program Files\Microsoft Office\OFFICE11\STARTUPDisposition: BothDirectoryInformation
Filemask: unknown Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b4268b
|
no more files |
724947058 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: VolumePref |
object name not found |
725166773 |
Process information queried |
PID: 1680 Info Class: Times |
success or wait |
725167825 |
Key value deleted |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems Keyname:
?K
|
success or wait |
725169496 |
Key deleted |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems |
success or wait |
725282838 |
Key deleted |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency |
success or wait |
725393454 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: FirstRun |
success or wait |
725615081 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\UserInfo Name: UserName |
success or wait |
725728046 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\UserInfo Name: UserInitials |
success or wait |
725728473 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\UserInfo Name: Company |
success or wait |
725842756 |
Process information queried |
PID: 1680 Info Class: Times |
success or wait |
725846879 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Common Name: QMEnable |
object name not found |
725847075 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Common Name: QMEnable |
object name not found |
725951168 |
Message posted |
HWND: E0154 Message: 45F WParam: 0 LParam: 0 |
success |
725952821 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
725955653 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
726063811 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000209FF-0000-0000-C000-000000000046}\InprocServer32
Name: InprocServer32
|
object name not found |
726288726 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000209FF-0000-0000-C000-000000000046}\LocalServer32
Name: LocalServer32
|
success or wait |
726510040 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Group Policy\AppMgmt Name:
{90110409-6000-11D3-8CFE-0150048383C9}
|
object name not found |
726512817 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: WORDFiles
|
success or wait |
726733288 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
726736344 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
726845177 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
success or wait |
726846893 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
726848574 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A453DD12EE71CEF49A4EB2A8684FB83A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
727070385 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5861C19D5F3D8C8439408F306F31034A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
727186607 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\311714883E93F274A838DDB012991F9D
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
727298703 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\72E940125B15C02498F17C8F91EADC14
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
727517388 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\16EFE5D0815A2D11A92E0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
727630325 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\41AE703BF87339947BDCC4715F97EFED
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
727744405 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: ProductFiles
|
success or wait |
727964206 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
727966658 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
728074974 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
success or wait |
728075566 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EAE1CE3652AD1140BB010C68A730687
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
728076427 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\379E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
728304193 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1650EACF3C291D11A92C0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
728413879 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19C2DC6651A24AD4BB2DE51C70F5C3E0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
728527056 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
728635178 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
728747079 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DBA0D1302088D1E44B6F7E0DC6732662
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
728860876 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2516E66D0FE30B64EB1CDE1F52E7C357
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
728974557 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
729194477 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
729194818 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE6545E80813C4542A70D28194279382
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
729308323 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
729530050 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A27DD755B98E23499AA660C6A835D0C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
729533614 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86FBBBBDC3EB97D4989B210DB8D577D2
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
729753373 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19A12162A748EF94E899C354C0912213
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
729865998 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
730150548 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles
|
success or wait |
730480896 |
Key value replaced with new |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles Type: dword Data: 1077411858 Old data: 1077411857
|
success or wait |
730481869 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000209FF-0000-0000-C000-000000000046}\InprocServer32
Name: NULL
|
object name not found |
730595698 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000209FF-0000-0000-C000-000000000046}\InprocHandler32
Name: NULL
|
success or wait |
730818363 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00020400-0000-0000-C000-000000000046}\ProxyStubClsid32
Name: NULL
|
success or wait |
731153438 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
731266066 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
731375106 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32
Name: InprocServer32
|
object name not found |
731598944 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32
Name: NULL
|
success or wait |
731823520 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}
Name: AppID
|
object name not found |
732049585 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
732271944 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
732273157 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32
Name: InprocServer32
|
object name not found |
732498632 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32
Name: NULL
|
success or wait |
732724174 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}
Name: AppID
|
object name not found |
733053456 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
733277259 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
733280612 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32
Name: InprocServer32
|
object name not found |
733504888 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32
Name: NULL
|
success or wait |
733730178 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}
Name: AppID
|
object name not found |
734060228 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32
Name: ThreadingModel
|
success or wait |
734288894 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: DelayLV |
object name not found |
734954898 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm Name: |
success or wait |
737473956 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\htmlfile\shell\Edit\command Name: |
success or wait |
737697187 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\htmlfile\shell\Print\command Name: |
success or wait |
737921262 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42042206-2D85-11D3-8CFF-005004838597}\Version\11
Name:
|
success or wait |
737927046 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42042206-2D85-11D3-8CFF-005004838597}\Version\11
Name:
|
success or wait |
738143586 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mht Name: |
success or wait |
738591748 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mhtmlfile\shell\Edit\command Name: |
success or wait |
738593637 |
Message posted |
HWND: 11013E Message: 400 WParam: 47806 LParam: 1462916 |
success |
738715182 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mhtmlfile\shell\Print\command Name: |
success or wait |
738715792 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42042206-2D85-11D3-8CFF-005004838597}\Version\11
Name:
|
success or wait |
738816586 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42042206-2D85-11D3-8CFF-005004838597}\Version\11
Name:
|
success or wait |
739040943 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020905-0000-0000-C000-000000000046}\8.3\0\win32
Name: NULL
|
success or wait |
740156353 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and random access Attributes: none Content Overwritten: true
|
success or wait |
740380658 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 0
|
success or wait |
740382274 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00
40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 B8 00 00 00
|
success or wait |
740383207 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 0
|
success or wait |
740606242 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 184
|
success or wait |
740606343 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
4 Value: 50 45 00 00
|
success or wait |
740714924 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
20 Value: 4C 01 02 00 19 E9 0F 3F 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
740715055 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 432
|
success or wait |
740715171 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
40 Value: 2E 72 73 72 63 00 00 00 98 06 0A 00 00 10 00 00 00 08 0A 00 00 02 00 00
00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40
|
success or wait |
740832357 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 472
|
success or wait |
740832619 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 512
|
success or wait |
740832813 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
16 Value: 00 00 00 00 00 00 00 00 00 00 00 00 01 00 01 00
|
success or wait |
740939812 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
8 Value: A0 00 00 80 20 00 00 80
|
success or wait |
740941847 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 536
|
success or wait |
740943512 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 672
|
success or wait |
741053087 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
2 Value: 07 00
|
success or wait |
741055286 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
14 Value: 54 00 59 00 50 00 45 00 4C 00 49 00 42 00
|
success or wait |
741057100 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 536
|
success or wait |
741163170 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 472
|
success or wait |
741164619 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 472
|
success or wait |
741165807 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 544
|
success or wait |
741274694 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
16 Value: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00
|
success or wait |
741275582 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 560
|
success or wait |
741276370 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
8 Value: 01 00 00 00 50 00 00 80
|
success or wait |
741389933 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 472
|
success or wait |
741390758 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 472
|
success or wait |
741391447 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 592
|
success or wait |
741499752 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
16 Value: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00
|
success or wait |
741500927 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
8 Value: 09 04 00 00 80 00 00 00
|
success or wait |
741501911 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 472
|
success or wait |
741609816 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 640
|
success or wait |
741609919 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
16 Value: B0 10 00 00 44 01 0A 00 00 00 00 00 00 00 00 00
|
success or wait |
741610013 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Access: query and read
Type: commit Baseaddress: 1A50000 Size: 659456 Protection: readonly Mapped to pid:
own pid
|
success or wait |
741721731 |
System info queried |
Type: BasicInformation |
success or wait |
741721879 |
System info queried |
Type: ProcessorInformation |
success or wait |
741721983 |
Message posted |
HWND: 11013E Message: 400 WParam: 47806 LParam: 1462916 |
success |
742732278 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\General Name: Data |
success or wait |
742740655 |
File opened |
Path: C:\DOCUME~1\ALLUSE~1\APPLIC~1\MICROS~1\OFFICE\DATA\OPA11.BAK Access: read attributes
and synchronize and generic read Options: sequential only and synchronous io non alert
and non directory file and open reparse point Attributes: none Content Overwritten:
true
|
success or wait |
742741101 |
File created |
Path: C:\DOCUME~1\ALLUSE~1\APPLIC~1\MICROS~1\OFFICE\DATA\opa11.dat Access: read attributes
and delete and synchronize and generic write Options: sequential only and synchronous
io non alert and non directory file Attributes: archive Content Overwritten: true
|
object name collision |
742741730 |
File opened |
Path: C:\DOCUME~1\ALLUSE~1\APPLIC~1\MICROS~1\OFFICE\DATA\opa11.dat Access: write
attributes and synchronize Options: synchronous io non alert and open for backup ident
and open reparse point Overwritten: false
|
success or wait |
742842264 |
File other op |
Path: C:\DOCUME~1\ALLUSE~1\APPLIC~1\MICROS~1\OFFICE\DATA\opa11.dat New path: Disposition:
BasicInformation Data : Creation Time: 01:00 01-01-1601 Last Access Time: 01:00 01-01-1601
Last Write Time: 01:00 01-01-1601 Change Time: 01:00 01-01-1601 File Attributes: archive
and temporary
|
success or wait |
742844009 |
File opened |
Path: C:\DOCUME~1\ALLUSE~1\APPLIC~1\MICROS~1\OFFICE\DATA\opa11.dat Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and random access Attributes: normal Content Overwritten: true
|
success or wait |
742953694 |
File other op |
Path: C:\DOCUME~1\ALLUSE~1\APPLIC~1\MICROS~1\OFFICE\DATA\opa11.dat New path: Disposition:
PositionInformation Data : Offset: 0
|
success or wait |
743067421 |
File read |
Path: C:\DOCUME~1\ALLUSE~1\APPLIC~1\MICROS~1\OFFICE\DATA\opa11.dat Offset: unknown
Length: 8200 Value: 02 AB 1B 8F D1 D4 FE 68 A2 DB EA C7 E5 28 02 7E DB 3B 1F FA FD
11 53 96 8F 67 D0 D6 29 AF 27 91 64 6F 5D 8C 2B A8 2B F1 E9 6A 6C A5 A1 29 47 81 8C
0A 60 4C 01 C6 73 F4 B9 77 78 55 29 29 48 32 A9 19 BD 20 AE 2F FD AC 6D 17 DB FA B4
9D 92 58 A9 B6 71 A2 0E 8F 20 8A 6F 51 91 92 32 B2 33 BE 60 30 4B F8
|
success or wait |
743067677 |
File opened |
Path: C:\DOCUME~1\ALLUSE~1\APPLIC~1\MICROS~1\OFFICE\DATA\opa11.dat Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and random access Attributes: normal Content Overwritten: true
|
success or wait |
743180730 |
File other op |
Path: C:\DOCUME~1\ALLUSE~1\APPLIC~1\MICROS~1\OFFICE\DATA\opa11.dat New path: Disposition:
PositionInformation Data : Offset: 0
|
success or wait |
743182242 |
File read |
Path: C:\DOCUME~1\ALLUSE~1\APPLIC~1\MICROS~1\OFFICE\DATA\opa11.dat Offset: unknown
Length: 8200 Value: 02 AB 1B 8F D1 D4 FE 68 A2 DB EA C7 E5 28 02 7E DB 3B 1F FA FD
11 53 96 8F 67 D0 D6 29 AF 27 91 64 6F 5D 8C 2B A8 2B F1 E9 6A 6C A5 A1 29 47 81 8C
0A 60 4C 01 C6 73 F4 B9 77 78 55 29 29 48 32 A9 19 BD 20 AE 2F FD AC 6D 17 DB FA B4
9D 92 58 A9 B6 71 A2 0E 8F 20 8A 6F 51 91 92 32 B2 33 BE 60 30 4B F8
|
success or wait |
743182862 |
File other op |
Path: C:\DOCUME~1\ALLUSE~1\APPLIC~1\MICROS~1\OFFICE\DATA\opa11.dat New path: Disposition:
PositionInformation Data : Offset: 8200
|
success or wait |
743296711 |
File read |
Path: C:\DOCUME~1\ALLUSE~1\APPLIC~1\MICROS~1\OFFICE\DATA\opa11.dat Offset: unknown
Length: 6 Value: 0E AB 1B 8F C2 D4
|
success or wait |
743297678 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\InstallRoot Name: InstallCount |
success or wait |
743513375 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Licensing Name: 1EBDE4BC9A514630B5412561FA45CCC5 |
buffer overflow |
743513706 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Licensing Name: 1EBDE4BC9A514630B5412561FA45CCC5 |
buffer overflow |
743513934 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Licensing Name: 1EBDE4BC9A514630B5412561FA45CCC5 |
success or wait |
743625577 |
Key value deleted |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Licensing Keyname: 1EBDE4BC9A514630B5412561FA45CCC5 |
success or wait |
743626491 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: WORDFiles
|
success or wait |
744073235 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
744075927 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
744185687 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
success or wait |
744185886 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
744186276 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A453DD12EE71CEF49A4EB2A8684FB83A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
744295445 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5861C19D5F3D8C8439408F306F31034A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
744412221 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\311714883E93F274A838DDB012991F9D
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
744412780 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\72E940125B15C02498F17C8F91EADC14
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
744577614 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\16EFE5D0815A2D11A92E0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
744686237 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\41AE703BF87339947BDCC4715F97EFED
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
744686651 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: ProductFiles
|
success or wait |
744803068 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
744912640 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
744913519 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
success or wait |
744914251 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EAE1CE3652AD1140BB010C68A730687
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
745025387 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\379E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
745028070 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1650EACF3C291D11A92C0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
745136654 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19C2DC6651A24AD4BB2DE51C70F5C3E0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
745251522 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
745252246 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
745358104 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DBA0D1302088D1E44B6F7E0DC6732662
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
745358554 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2516E66D0FE30B64EB1CDE1F52E7C357
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
745472111 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
745583358 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
745584712 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE6545E80813C4542A70D28194279382
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
745694156 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
745696088 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A27DD755B98E23499AA660C6A835D0C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
745806742 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86FBBBBDC3EB97D4989B210DB8D577D2
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
745918680 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19A12162A748EF94E899C354C0912213
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
745919157 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\9040110900063D11C8EF10054038389C
Name: ProductName
|
success or wait |
746148691 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Registration\{90110409-6000-11D3-8CFE-0150048383C9}
Name: DigitalProductID
|
buffer overflow |
746257990 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Registration\{90110409-6000-11D3-8CFE-0150048383C9}
Name: DigitalProductID
|
success or wait |
746259172 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\1033\id_011.dpc Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: none Content Overwritten: true
|
success or wait |
746589163 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\1033\ID_011.DPC Offset: unknown Length:
575 Value: 4D 10 B1 97 70 ED 41 A7 18 C6 A0 30 FA E4 CA 9C 8B 05 18 82 F8 0F FE CF
CF FB A8 BA 01 1E 74 D0 91 F9 C1 07 18 87 24 9A DE 4A 61 67 12 00 63 63 64 87 E3 11
82 80 0F 0E 75 EF E7 44 3D 12 8E 09 50 E2 3A 7D CB 9B EE B9 1B 52 A8 34 CF E6 7D BC
CA 68 CC E3 38 34 82 28 9D 21 A3 C7 A8 89 7D EF 88 1B EC 8B
|
success or wait |
746590296 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\General Name: AuditMode |
object name not found |
746815871 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\General Name: AuditMode |
object name not found |
747039495 |
System info queried |
Type: BasicInformation |
success or wait |
747040870 |
System info queried |
Type: ProcessorInformation |
success or wait |
747041814 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Registration\{90110409-6000-11D3-8CFE-0150048383C9}
Name: WordName
|
success or wait |
747596148 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: WordName |
success or wait |
747597780 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: Viewer |
object name not found |
747819473 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Registration\{90110409-6000-11D3-8CFE-0150048383C9}
Name: DigitalProductID
|
buffer overflow |
747820234 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Registration\{90110409-6000-11D3-8CFE-0150048383C9}
Name: DigitalProductID
|
success or wait |
747820788 |
Key value replaced with same |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\InstallRoot\UE Name: {90110409-6000-11D3-8CFE-0150048383C9}
Type: binary Data: 12 79 FE 79 2F 8E AC BC 4E 6F C4 64 EF 9A 1A 37 Old data:
|
success or wait |
748044719 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
748266133 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
748382043 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32
Name: InprocServer32
|
object name not found |
748606811 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32
Name: NULL
|
success or wait |
748831903 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}
Name: AppID
|
object name not found |
749053413 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Common Name: QMEnable |
object name not found |
749496944 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Common Name: QMEnable |
object name not found |
749497154 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Common Name: QMPromptCount |
object name not found |
749497355 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Common Name: QMLastPrompt |
success or wait |
749497562 |
Mutant created |
Name: \BaseNamedObjects\Local\SqmSysTray |
success or wait |
749612062 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 200110 |
success |
754699558 |
Message sent |
HWND: 200110 Message: NCCREATE WParam: 0 LParam: 1238640 |
success |
754813655 |
Message sent |
HWND: 200110 Message: NCCALCSIZE WParam: 0 LParam: 1238680 |
error |
754815836 |
Message posted |
HWND: 11013E Message: 400 WParam: 47806 LParam: 1462916 |
success |
754824270 |
Windows found |
Window Name: NULL Class Name: Shell_TrayWnd HWND: 3004E |
success |
755146175 |
Message sent |
HWND: 3004E Message: COPYDATA WParam: 2097424 LParam: 1239300 |
success |
755147244 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\ProductVersion Name:
LastProduct
|
success or wait |
755259444 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\Config\{90110409-6000-11D3-8CFE-0150048383C9}
Name: InstallType
|
success or wait |
755260733 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\Config\{90110409-6000-11D3-8CFE-0150048383C9}
Name: SourceType
|
success or wait |
755369258 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\Config\{90110409-6000-11D3-8CFE-0150048383C9}
Name: Upgrade
|
success or wait |
755370423 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\Config\{90110409-6000-11D3-8CFE-0150048383C9}
Name: OODS
|
success or wait |
755371390 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\Config\{90110409-6000-11D3-8CFE-0150048383C9}
Name: Location
|
success or wait |
755483920 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\Config\{90110409-6000-11D3-8CFE-0150048383C9}
Name: PIDKEY
|
success or wait |
755485098 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\Config\{90110409-6000-11D3-8CFE-0150048383C9}
Name: LocalCache
|
success or wait |
755486073 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Access\InstallRoot Name: Path |
success or wait |
755707676 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Excel\InstallRoot Name: Path |
success or wait |
755710662 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Outlook\InstallRoot Name:
Path
|
success or wait |
755928360 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\PowerPoint\InstallRoot Name:
Path
|
success or wait |
756040056 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Publisher\InstallRoot Name:
Path
|
success or wait |
756155933 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Word\InstallRoot Name: Path |
success or wait |
756264995 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\InfoPath\InstallRoot Name:
Path
|
success or wait |
756606186 |
System info queried |
Type: BasicInformation |
success or wait |
756608601 |
System info queried |
Type: ProcessorInformation |
success or wait |
756714570 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Name: ~MHz |
success or wait |
756714899 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: GlobalDotName |
object name not found |
757608817 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: GlobalDotName |
object name not found |
758054035 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: UserTemplates |
object name not found |
759341574 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: Templates |
success or wait |
759343191 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
HideFileExt
|
success or wait |
759564344 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
HideFileExt
|
success or wait |
759565560 |
Section loaded |
Path: \BaseNamedObjects\Global\RotHintTable Access: read Type: unknown Baseaddress:
1B40000 Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
760575928 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: DoNotDismissFileNewTaskPane |
object name not found |
760578636 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Toolbars\Settings Name: Microsoft
Office Word AWDropdownHidden
|
object name not found |
760684785 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Data Name: Toolbars |
buffer overflow |
760685616 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Data Name: Toolbars |
buffer overflow |
760794072 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Data Name: Toolbars |
success or wait |
760794281 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Toolbars\Settings Name: Microsoft
Office Word
|
success or wait |
761022293 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Toolbars\Settings Name: Microsoft
Office Word
|
success or wait |
761131370 |
Window placement got |
HWND: E0154 CMD: show maximized |
success |
761135358 |
Window placement got |
HWND: E0154 CMD: show maximized |
success |
761243462 |
Message sent |
HWND: F010A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1222624 |
error |
761244478 |
Message sent |
HWND: F010A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1222624 |
error |
761245318 |
Window created |
Window Name: _WwB Class Name: _WwB HWND: 2200B6 |
success |
761465301 |
Message sent |
HWND: 2200B6 Message: NCCREATE WParam: 0 LParam: 1221500 |
success |
761466101 |
Message sent |
HWND: 2200B6 Message: NCCALCSIZE WParam: 0 LParam: 1221540 |
error |
761583117 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: DoNotDismissFileNewTaskPane |
object name not found |
761694864 |
Window created |
Window Name: _WwG Class Name: _WwG HWND: 1A011A |
success |
762025734 |
Message sent |
HWND: 1A011A Message: NCCREATE WParam: 0 LParam: 1220848 |
success |
762136634 |
Message sent |
HWND: 1A011A Message: NCCALCSIZE WParam: 0 LParam: 1220888 |
error |
762137191 |
Message sent |
HWND: 1A011A Message: SETTEXT WParam: 0 LParam: 1222968 |
success |
762138548 |
Window created |
Window Name: 6.0.2600.6028!ScrollBar Class Name: SCROLLBAR HWND: D011C |
success |
762365826 |
Message sent |
HWND: D011C Message: NCCREATE WParam: 0 LParam: 1220696 |
success |
762472539 |
Message sent |
HWND: D011C Message: NCCALCSIZE WParam: 0 LParam: 1220764 |
error |
762473573 |
Window created |
Window Name: _WwC Class Name: _WwC HWND: 1C014C |
success |
762474812 |
Message sent |
HWND: 1C014C Message: NCCREATE WParam: 0 LParam: 1220408 |
success |
762583784 |
Message sent |
HWND: 1C014C Message: NCCALCSIZE WParam: 0 LParam: 1220460 |
error |
762584615 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Toolbars\Settings Name: Microsoft
Office Word AWDropdownHidden
|
object name not found |
762699888 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\CTF Name: Disable Thread Input Manager |
object name not found |
762808678 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\LanguageProfile\0x00000409\{09EA4E4B-46CE-4469-B450-0DE76A435BBB}
Name: Enable
|
success or wait |
762810108 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\LanguageProfile\0x00000807\{09EA4E4B-46CE-4469-B450-0DE76A435BBB}
Name: Enable
|
success or wait |
762924834 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\LanguageProfile\0x0000ffff\{09EA4E4B-46CE-4469-B450-0DE76A435BBB}
Name: Enable
|
success or wait |
763035144 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 1E010E |
success |
767395202 |
Message sent |
HWND: 1E010E Message: NCCREATE WParam: 0 LParam: 1220008 |
success |
767509951 |
Message sent |
HWND: 1E010E Message: NCCALCSIZE WParam: 0 LParam: 1220048 |
error |
767510269 |
Message sent |
HWND: 1E010E Message: NCCALCSIZE WParam: 1 LParam: 1222272 |
error |
767736902 |
Window created |
Window Name: 6.0.2600.6028!ScrollBar Class Name: SCROLLBAR HWND: 1D00E6 |
success |
767737867 |
Message sent |
HWND: D011C Message: NCCREATE WParam: 0 LParam: 1220696 |
success |
767738314 |
Message sent |
HWND: D011C Message: NCCALCSIZE WParam: 0 LParam: 1220764 |
error |
767847048 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 180142 |
success |
773048272 |
Message sent |
HWND: 180142 Message: NCCREATE WParam: 0 LParam: 1220004 |
success |
773048577 |
Message sent |
HWND: 180142 Message: NCCALCSIZE WParam: 0 LParam: 1220044 |
error |
773155801 |
Message sent |
HWND: 180142 Message: NCCALCSIZE WParam: 1 LParam: 1222268 |
error |
773158994 |
Window created |
Window Name: _WwC Class Name: _WwC HWND: 1800FE |
success |
773160760 |
Message sent |
HWND: 1800FE Message: NCCALCSIZE WParam: 0 LParam: 1220456 |
error |
773266957 |
Window created |
Window Name: _WwC Class Name: _WwC HWND: 13010C |
success |
773267819 |
Message sent |
HWND: 13010C Message: NCCREATE WParam: 0 LParam: 1220412 |
success |
773268174 |
Message sent |
HWND: 13010C Message: NCCALCSIZE WParam: 0 LParam: 1220464 |
error |
773379997 |
Window created |
Window Name: _WwC Class Name: _WwC HWND: 1F0150 |
success |
773384224 |
Message sent |
HWND: 13010C Message: NCCREATE WParam: 0 LParam: 1220412 |
success |
773385465 |
Message sent |
HWND: 13010C Message: NCCALCSIZE WParam: 0 LParam: 1220464 |
error |
773490489 |
Message sent |
HWND: 1A011A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1222448 |
error |
773493468 |
Message sent |
HWND: 1A011A Message: NCCALCSIZE WParam: 1 LParam: 1222404 |
error |
773604667 |
Message sent |
HWND: 1F0150 Message: WINDOWPOSCHANGING WParam: 0 LParam: 1222448 |
error |
773605744 |
Message sent |
HWND: 1F0150 Message: NCCALCSIZE WParam: 1 LParam: 1222404 |
error |
773606640 |
Message sent |
HWND: 1F0150 Message: WINDOWPOSCHANGING WParam: 0 LParam: 1222448 |
error |
773715887 |
Message sent |
HWND: 1F0150 Message: NCCALCSIZE WParam: 1 LParam: 1222404 |
error |
773717634 |
Message sent |
HWND: 1F0150 Message: WINDOWPOSCHANGING WParam: 0 LParam: 1222448 |
error |
773719069 |
Message sent |
HWND: 1F0150 Message: NCCALCSIZE WParam: 1 LParam: 1222404 |
error |
773825806 |
Message sent |
HWND: 1F0150 Message: WINDOWPOSCHANGING WParam: 0 LParam: 1222448 |
error |
773825948 |
Message sent |
HWND: 1F0150 Message: NCCALCSIZE WParam: 1 LParam: 1222404 |
error |
773826104 |
Message sent |
HWND: 1A011A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1222448 |
error |
773937655 |
Message sent |
HWND: 1A011A Message: NCCALCSIZE WParam: 1 LParam: 1222404 |
error |
773937799 |
Message sent |
HWND: 1A011A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1222448 |
error |
773937940 |
Message sent |
HWND: 1A011A Message: NCCALCSIZE WParam: 1 LParam: 1222404 |
error |
774053248 |
Window shown |
HWND: D011C CMD: show normal |
error |
775169568 |
Window shown |
HWND: 1D00E6 CMD: show normal |
error |
775170026 |
Window shown |
HWND: 180142 CMD: show normal |
error |
775170133 |
Window shown |
HWND: 1E010E CMD: show normal |
error |
775280812 |
Section loaded |
Path: \BaseNamedObjects\Local\Mso97SharedDg19521106568_S-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read and execute and extend size Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
776627606 |
Section loaded |
Path: \BaseNamedObjects\Local\Mso97SharedDg19521106568_S-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read Type: reserve Baseaddress: 1B80000 Size: 126976 Protection:
read write Mapped to pid: own pid
|
success or wait |
776627886 |
Mutant created |
Name: \BaseNamedObjects\Local\Mso97SharedDg19521106568_S-1-5-21-507921405-1960408961-839522115-500Mutex |
success or wait |
776740477 |
Window shown |
HWND: 13010C CMD: show normal |
error |
776849898 |
Window shown |
HWND: 1F0150 CMD: show normal |
error |
776851930 |
Window created |
Window Name: CLIPBRDWNDCLASS Class Name: CLIPBRDWNDCLASS HWND: 1200E4 |
success |
776962280 |
Message sent |
HWND: 1200E4 Message: NCCREATE WParam: 0 LParam: 1221312 |
success |
776963655 |
Message sent |
HWND: 1200E4 Message: NCCALCSIZE WParam: 0 LParam: 1221352 |
error |
776966555 |
Message sent |
HWND: 2200B6 Message: SETICON WParam: 1 LParam: 3932639 |
error |
777070657 |
Message sent |
HWND: 2200B6 Message: SETICON WParam: 0 LParam: 3867003 |
error |
777072063 |
Message sent |
HWND: 2200B6 Message: NCACTIVATE WParam: 1 LParam: 0 |
success |
777073068 |
Window shown |
HWND: D011C CMD: show normal |
success |
777204034 |
Window shown |
HWND: 1D00E6 CMD: show normal |
success |
777204139 |
Window shown |
HWND: 180142 CMD: show normal |
success |
777204233 |
Window shown |
HWND: 1E010E CMD: show normal |
success |
777405641 |
Window shown |
HWND: 13010C CMD: show normal |
success |
777406151 |
Window shown |
HWND: 1F0150 CMD: show normal |
success |
777406251 |
Message sent |
HWND: 1A011A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1223372 |
error |
777518885 |
Message sent |
HWND: 1F0150 Message: WINDOWPOSCHANGING WParam: 0 LParam: 1223372 |
error |
777519029 |
Message sent |
HWND: 1F0150 Message: WINDOWPOSCHANGING WParam: 0 LParam: 1223372 |
error |
777519162 |
Message sent |
HWND: 1F0150 Message: WINDOWPOSCHANGING WParam: 0 LParam: 1223372 |
error |
777630122 |
Message sent |
HWND: 1F0150 Message: WINDOWPOSCHANGING WParam: 0 LParam: 1223372 |
error |
777630561 |
Message sent |
HWND: 1A011A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1223372 |
error |
777630963 |
Message sent |
HWND: 1A011A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1223372 |
error |
777741594 |
Window shown |
HWND: D011C CMD: show normal |
success |
777743521 |
Window shown |
HWND: 1D00E6 CMD: show normal |
success |
777744540 |
Window shown |
HWND: 180142 CMD: show normal |
success |
777853657 |
Window shown |
HWND: 1E010E CMD: show normal |
success |
777855654 |
Window shown |
HWND: 13010C CMD: show normal |
success |
777857290 |
Window shown |
HWND: 1F0150 CMD: show normal |
success |
777965867 |
Window shown |
HWND: F010A CMD: show normal |
success |
777967045 |
Window shown |
HWND: 2200B6 CMD: show normal |
error |
777967996 |
Window shown |
HWND: 1A011A CMD: show normal |
error |
778076443 |
Window shown |
HWND: 13010C CMD: show |
success |
778076553 |
Window shown |
HWND: 1F0150 CMD: show |
success |
778076646 |
Message sent |
HWND: 2200B6 Message: SETTEXT WParam: 0 LParam: 1223006 |
success |
778191417 |
Message sent |
HWND: E0154 Message: SETTEXT WParam: 0 LParam: 1221932 |
success |
778191631 |
Message posted |
HWND: E0154 Message: C159 WParam: 0 LParam: 0 |
success |
778191888 |
Window shown |
HWND: F010A CMD: show normal |
success |
778300156 |
Window shown |
HWND: D011C CMD: show normal |
success |
778300258 |
Window shown |
HWND: 1D00E6 CMD: show normal |
success |
778300352 |
Window shown |
HWND: 180142 CMD: show normal |
success |
778412626 |
Window shown |
HWND: 1E010E CMD: show normal |
success |
778414114 |
Window shown |
HWND: 13010C CMD: show normal |
success |
778415342 |
Window shown |
HWND: 1F0150 CMD: show normal |
success |
778524716 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Common\Smart Tag Name: DisableDocumentAssemblies |
object name not found |
778815338 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\BaseSuite Name: 1EBDE4BC9A514630B5412561FA45CCC5 |
success or wait |
778815657 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: DefaultTheme(Documents) |
object name not found |
779252877 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: NoTTP |
object name not found |
779475941 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common Name: VbaOff |
object name not found |
780152812 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: VbaOff |
object name not found |
780153720 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\InstallProperties
Name: WindowsInstaller
|
success or wait |
780373887 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\InstallProperties
Name: WindowsInstaller
|
success or wait |
780709915 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: WORDFiles
|
success or wait |
781047064 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
781047431 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
781153466 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
success or wait |
781154026 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
781154741 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A453DD12EE71CEF49A4EB2A8684FB83A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
781267030 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5861C19D5F3D8C8439408F306F31034A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
781377980 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\311714883E93F274A838DDB012991F9D
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
781380542 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\72E940125B15C02498F17C8F91EADC14
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
781490121 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\16EFE5D0815A2D11A92E0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
781600663 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\41AE703BF87339947BDCC4715F97EFED
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
781601826 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: ProductFiles
|
success or wait |
781712696 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
781826851 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
781827368 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
success or wait |
781827814 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EAE1CE3652AD1140BB010C68A730687
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
781943028 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\379E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
781943412 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1650EACF3C291D11A92C0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
782053953 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19C2DC6651A24AD4BB2DE51C70F5C3E0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
782162831 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
782167010 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
782271300 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DBA0D1302088D1E44B6F7E0DC6732662
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
782271695 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2516E66D0FE30B64EB1CDE1F52E7C357
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
782386506 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
782497755 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
782498744 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE6545E80813C4542A70D28194279382
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
782720944 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
782722718 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A27DD755B98E23499AA660C6A835D0C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
782724298 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86FBBBBDC3EB97D4989B210DB8D577D2
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
782837164 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19A12162A748EF94E899C354C0912213
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
782837525 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles
|
success or wait |
783170022 |
Key value replaced with new |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles Type: dword Data: 1077411859 Old data: 1077411858
|
success or wait |
783171002 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EAE1CE3652AD1140BB010C68A730687
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
783393141 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: ProductFiles
|
success or wait |
783616466 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
783726909 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
783728223 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
success or wait |
783729311 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EAE1CE3652AD1140BB010C68A730687
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
783843180 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\379E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
783845220 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1650EACF3C291D11A92C0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
783952861 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19C2DC6651A24AD4BB2DE51C70F5C3E0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
784061217 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
784062277 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
784174300 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DBA0D1302088D1E44B6F7E0DC6732662
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
784175669 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2516E66D0FE30B64EB1CDE1F52E7C357
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
784288197 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
784399712 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
784401227 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE6545E80813C4542A70D28194279382
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
784511717 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
784514991 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A27DD755B98E23499AA660C6A835D0C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
784627402 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86FBBBBDC3EB97D4989B210DB8D577D2
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
784732281 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19A12162A748EF94E899C354C0912213
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
784732666 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: ProductFiles
|
success or wait |
785068578 |
Key value replaced with new |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: ProductFiles Type: dword Data: 1077411842 Old data: 1077411841
|
success or wait |
785069400 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: VBAFiles
|
success or wait |
785184715 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: VBAFiles
|
buffer overflow |
785291842 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: VBAFiles
|
buffer overflow |
785292083 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: VBAFiles
|
success or wait |
785406519 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0020F700D33C1D112897000CF42C6133
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
785407138 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0020F700D33C1D112897000CF42C6133
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
785407492 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\359E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
785519150 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1C1B74D56F7A1D11A9CC0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
785631386 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1C1B74D56F7A1D11A9CC0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
785632650 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4EEF86DD963C1D111A37000A9CA05BF0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
785741534 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2EEF86DD963C1D111A37000A9CA05BF0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
785745540 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A457B2D1A9DC1D112897000CF42C6133
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
785853777 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1178400169C22D11A9790006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
786022111 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: SHAREDFiles
|
success or wait |
786022844 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: SHAREDFiles
|
success or wait |
786135359 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: SHAREDFiles
|
success or wait |
786136211 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
786245064 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: ProductFiles
|
success or wait |
786247380 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
786359854 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
786360560 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
success or wait |
786471483 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EAE1CE3652AD1140BB010C68A730687
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
786473529 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\379E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
786579987 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1650EACF3C291D11A92C0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
786580842 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19C2DC6651A24AD4BB2DE51C70F5C3E0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
786692888 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
786804350 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
786805986 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DBA0D1302088D1E44B6F7E0DC6732662
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
786915173 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2516E66D0FE30B64EB1CDE1F52E7C357
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
786916293 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
787028333 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
787029280 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE6545E80813C4542A70D28194279382
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
787138576 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
787250330 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A27DD755B98E23499AA660C6A835D0C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
787252449 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86FBBBBDC3EB97D4989B210DB8D577D2
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
787364511 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19A12162A748EF94E899C354C0912213
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
787475042 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VBA Name: Vbe6DllPath |
success or wait |
787809866 |
File opened |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
788033849 |
Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: write and read and execute
Type: commit Baseaddress: 1BB0000 Size: 2482176 Protection: execute Mapped to pid:
own pid
|
success or wait |
788035675 |
File opened |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: read attributes and
synchronize and generic read Options: synchronous io non alert and non directory file
Attributes: none Content Overwritten: true
|
success or wait |
788371890 |
Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: query and read Type:
commit Baseaddress: 1BB0000 Size: 2482176 Protection: readonly Mapped to pid: own
pid
|
success or wait |
788372308 |
File opened |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
788930227 |
Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: write and read and execute
Type: commit Baseaddress: 1BB0000 Size: 2482176 Protection: execute Mapped to pid:
own pid
|
success or wait |
788930623 |
File opened |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: read attributes and
synchronize and generic read Options: synchronous io non alert and non directory file
Attributes: none Content Overwritten: true
|
success or wait |
789156535 |
Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: query and read Type:
commit Baseaddress: 1BB0000 Size: 2482176 Protection: readonly Mapped to pid: own
pid
|
success or wait |
789157063 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Components\029E403DA86A1D115B5B0006799C897E
Name: vbe.dll_6.0
|
success or wait |
789381039 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: VBAFiles
|
success or wait |
789488469 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: VBAFiles
|
buffer overflow |
789491891 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: VBAFiles
|
buffer overflow |
789599748 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: VBAFiles
|
success or wait |
789600358 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0020F700D33C1D112897000CF42C6133
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
789601550 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0020F700D33C1D112897000CF42C6133
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
789712199 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\359E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
789714477 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1C1B74D56F7A1D11A9CC0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
789828042 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1C1B74D56F7A1D11A9CC0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
789830225 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4EEF86DD963C1D111A37000A9CA05BF0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
789934813 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2EEF86DD963C1D111A37000A9CA05BF0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
790047093 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A457B2D1A9DC1D112897000CF42C6133
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
790047493 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1178400169C22D11A9790006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
790162208 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: SHAREDFiles
|
success or wait |
790273949 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: SHAREDFiles
|
success or wait |
790275815 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: SHAREDFiles
|
success or wait |
790386248 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
790388307 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: ProductFiles
|
success or wait |
790494236 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
790496079 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
790607394 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
success or wait |
790608760 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EAE1CE3652AD1140BB010C68A730687
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
790610248 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\379E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
790721067 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1650EACF3C291D11A92C0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
790829325 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19C2DC6651A24AD4BB2DE51C70F5C3E0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
790831506 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
790945041 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
790946247 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DBA0D1302088D1E44B6F7E0DC6732662
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
791057196 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2516E66D0FE30B64EB1CDE1F52E7C357
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
791167418 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
791169622 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
791276975 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE6545E80813C4542A70D28194279382
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
791279972 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
791389478 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A27DD755B98E23499AA660C6A835D0C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
791502178 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86FBBBBDC3EB97D4989B210DB8D577D2
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
791504520 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19A12162A748EF94E899C354C0912213
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
791615835 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\359E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
791836724 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: VBAFiles
|
object name not found |
792063824 |
Key value set |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: VBAFiles Type: dword Data: 1077411841 Old data:
|
success or wait |
792066064 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\vbe6.dll Access: execute
or traverse and synchronize Options: synchronous io non alert and non directory file
Overwritten: false
|
success or wait |
792177455 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6.DLL Access: write
and read and execute Type: commit Baseaddress: 1BB0000 Size: 2482176 Protection: execute
Mapped to pid: own pid
|
success or wait |
792284105 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\vbe6.dll Access: read
attributes and synchronize and generic read Options: synchronous io non alert and
non directory file Attributes: none Content Overwritten: true
|
success or wait |
792400139 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6.DLL Access: query
and read Type: commit Baseaddress: 1BB0000 Size: 2482176 Protection: readonly Mapped
to pid: own pid
|
success or wait |
792402476 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\vbe6.dll Access: execute
or traverse and synchronize Options: synchronous io non alert and non directory file
Overwritten: false
|
success or wait |
792622746 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6.DLL Access: write
and read and execute Type: commit Baseaddress: 1BB0000 Size: 2482176 Protection: execute
Mapped to pid: own pid
|
success or wait |
792736343 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\vbe6.dll Access: read
attributes and synchronize and generic read Options: synchronous io non alert and
non directory file Attributes: none Content Overwritten: true
|
success or wait |
792845390 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6.DLL Access: query
and read Type: commit Baseaddress: 1BB0000 Size: 2482176 Protection: readonly Mapped
to pid: own pid
|
success or wait |
792847413 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Security Name: AccessVBOM |
success or wait |
793460017 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VBA Name: Vbe6DllPath |
success or wait |
793681966 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VBA Name: Vbe6DllPath |
success or wait |
793682243 |
File opened |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
793794607 |
Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: write and read and execute
Type: commit Baseaddress: 1BB0000 Size: 2482176 Protection: execute Mapped to pid:
own pid
|
success or wait |
793795466 |
File opened |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
794017498 |
Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: query and write and
read and execute Type: image Baseaddress: 65000000 Size: 2490368 Protection: read
write Mapped to pid: own pid
|
success or wait |
794018631 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 65001000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
794578991 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 65001000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
794689009 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 65001000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
794689961 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 65001000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
794690911 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 65001000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
794801031 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 65001000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
794802319 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 65001000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
794803321 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 65001000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
794914309 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 65001000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
794914719 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 65001000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
794915015 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 65001000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
795026126 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 65001000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
795027026 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\vbe6.dll Name: CheckAppHelp
|
success or wait |
795028009 |
System info queried |
Type: BasicInformation |
success or wait |
795186963 |
File opened |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\1033\VBE6INTL.DLL Access: execute or
traverse and synchronize Options: synchronous io non alert and non directory file
Overwritten: false
|
success or wait |
796371828 |
Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\1033\VBE6INTL.DLL Access: write and read
and execute Type: commit Baseaddress: 1FC0000 Size: 159744 Protection: execute Mapped
to pid: own pid
|
success or wait |
796373093 |
File opened |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\1033\VBE6INTL.DLL Access: execute or
traverse and synchronize Options: synchronous io non alert and non directory file
Overwritten: false
|
success or wait |
796702560 |
Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\1033\VBE6INTL.DLL Access: query and write
and read and execute Type: image Baseaddress: 65300000 Size: 159744 Protection: read
write Mapped to pid: own pid
|
success or wait |
796703311 |
Window created |
Window Name: ThunderMain Class Name: ThunderMain HWND: 1300E0 |
success |
797261368 |
Message sent |
HWND: 1300E0 Message: NCCREATE WParam: 0 LParam: 1237372 |
success |
797261559 |
Message sent |
HWND: 1300E0 Message: NCCALCSIZE WParam: 0 LParam: 1237432 |
error |
797373738 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage Name: 932 |
success or wait |
797375589 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage Name: 949 |
success or wait |
797485137 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage Name: 950 |
success or wait |
797486946 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage Name: 936 |
success or wait |
797488484 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: DoNotDismissFileNewTaskPane |
object name not found |
798157869 |
Window created |
Window Name: OpusApp Class Name: OpusApp HWND: 140140 |
success |
798269653 |
Message sent |
HWND: 140140 Message: NCCREATE WParam: 0 LParam: 1236404 |
success |
798270858 |
Message sent |
HWND: 140140 Message: NCCALCSIZE WParam: 0 LParam: 1236444 |
error |
798273439 |
Message sent |
HWND: 140140 Message: WINDOWPOSCHANGING WParam: 0 LParam: 1236424 |
error |
798275003 |
Message sent |
HWND: 140140 Message: NCCALCSIZE WParam: 1 LParam: 1236380 |
error |
798379244 |
Message sent |
HWND: F010A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1233244 |
error |
798379594 |
Message sent |
HWND: F010A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1233244 |
error |
798494809 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Toolbars\Settings Name: Microsoft
Office Word AWDropdownHidden
|
object name not found |
798495750 |
Window created |
Window Name: _WwC Class Name: _WwC HWND: 1300EC |
success |
798830959 |
Message sent |
HWND: 1300EC Message: NCCREATE WParam: 0 LParam: 1236352 |
success |
798831337 |
Window created |
Window Name: _WwF Class Name: _WwF HWND: 100104 |
success |
798944731 |
Message sent |
HWND: 100104 Message: NCCREATE WParam: 0 LParam: 1236392 |
success |
798944889 |
Message sent |
HWND: 100104 Message: NCCALCSIZE WParam: 0 LParam: 1236444 |
error |
798945034 |
Message sent |
HWND: 1300EC Message: WINDOWPOSCHANGING WParam: 0 LParam: 1238164 |
error |
799050496 |
Message sent |
HWND: 1300EC Message: WINDOWPOSCHANGING WParam: 0 LParam: 1238164 |
error |
799051306 |
Window created |
Window Name: _WwB Class Name: _WwB HWND: C0100 |
success |
799163915 |
Message sent |
HWND: C0100 Message: NCCREATE WParam: 0 LParam: 1237040 |
success |
799164247 |
Message sent |
HWND: C0100 Message: NCCALCSIZE WParam: 0 LParam: 1237080 |
error |
799164721 |
Message sent |
HWND: 140140 Message: SETTEXT WParam: 0 LParam: 806367728 |
success |
799276924 |
Window created |
Window Name: _WwG Class Name: _WwG HWND: 90126 |
success |
799278248 |
Message sent |
HWND: 90126 Message: NCCREATE WParam: 0 LParam: 1236388 |
success |
799278851 |
Message sent |
HWND: 90126 Message: NCCALCSIZE WParam: 0 LParam: 1236428 |
error |
799386678 |
Message sent |
HWND: 90126 Message: SETTEXT WParam: 0 LParam: 1238508 |
success |
799387668 |
Window created |
Window Name: 6.0.2600.6028!ScrollBar Class Name: SCROLLBAR HWND: 90144 |
success |
799498691 |
Message sent |
HWND: 90144 Message: NCCREATE WParam: 0 LParam: 1236604 |
success |
799499657 |
Message sent |
HWND: 90144 Message: NCCALCSIZE WParam: 0 LParam: 1236672 |
error |
799501145 |
Window created |
Window Name: _WwC Class Name: _WwC HWND: 70132 |
success |
799610677 |
Message sent |
HWND: 70132 Message: NCCREATE WParam: 0 LParam: 1236316 |
success |
799610840 |
Message sent |
HWND: 70132 Message: NCCALCSIZE WParam: 0 LParam: 1236368 |
error |
799610997 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 310108 |
success |
805037928 |
Message sent |
HWND: 310108 Message: NCCREATE WParam: 0 LParam: 1235916 |
success |
805038151 |
Message sent |
HWND: 310108 Message: NCCALCSIZE WParam: 0 LParam: 1235956 |
error |
805038323 |
Message sent |
HWND: 310108 Message: NCCALCSIZE WParam: 1 LParam: 1238180 |
error |
805147845 |
Window created |
Window Name: 6.0.2600.6028!ScrollBar Class Name: SCROLLBAR HWND: F0106 |
success |
805149781 |
Message sent |
HWND: 90144 Message: NCCREATE WParam: 0 LParam: 1236604 |
success |
805150359 |
Message sent |
HWND: 90144 Message: NCCALCSIZE WParam: 0 LParam: 1236672 |
error |
805151112 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: B00F0 |
success |
810516212 |
Message sent |
HWND: B00F0 Message: NCCREATE WParam: 0 LParam: 1235912 |
success |
810516418 |
Message sent |
HWND: B00F0 Message: NCCALCSIZE WParam: 0 LParam: 1235952 |
error |
810516590 |
Message sent |
HWND: B00F0 Message: NCCALCSIZE WParam: 1 LParam: 1238176 |
error |
810517184 |
Window created |
Window Name: _WwC Class Name: _WwC HWND: E00B4 |
success |
810634030 |
Message sent |
HWND: E00B4 Message: NCCALCSIZE WParam: 0 LParam: 1236364 |
error |
810634277 |
Window created |
Window Name: _WwC Class Name: _WwC HWND: 10014A |
success |
810634624 |
Message sent |
HWND: 10014A Message: NCCREATE WParam: 0 LParam: 1236328 |
success |
810635137 |
Message sent |
HWND: 10014A Message: NCCALCSIZE WParam: 0 LParam: 1236380 |
error |
810742186 |
Message sent |
HWND: 2200B6 Message: SETICON WParam: 1 LParam: 3932639 |
error |
810856705 |
Message sent |
HWND: 2200B6 Message: SETICON WParam: 0 LParam: 3867003 |
error |
810860289 |
Window shown |
HWND: 90144 CMD: show normal |
error |
810861813 |
Window shown |
HWND: F0106 CMD: show normal |
error |
810963858 |
Window shown |
HWND: B00F0 CMD: show normal |
error |
810963972 |
Window shown |
HWND: 310108 CMD: show normal |
error |
810964764 |
Window shown |
HWND: 10014A CMD: show normal |
error |
811076893 |
Message sent |
HWND: 90126 Message: WINDOWPOSCHANGING WParam: 0 LParam: 1238912 |
error |
811077499 |
Message sent |
HWND: 90126 Message: NCCALCSIZE WParam: 1 LParam: 1238868 |
error |
811078583 |
Message sent |
HWND: 10014A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1238912 |
error |
811188750 |
Message sent |
HWND: 10014A Message: NCCALCSIZE WParam: 1 LParam: 1238868 |
error |
811190047 |
Message sent |
HWND: 10014A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1238912 |
error |
811191125 |
Message sent |
HWND: 10014A Message: NCCALCSIZE WParam: 1 LParam: 1238868 |
error |
811300711 |
Message sent |
HWND: 10014A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1238912 |
error |
811302609 |
Message sent |
HWND: 10014A Message: NCCALCSIZE WParam: 1 LParam: 1238868 |
error |
811304183 |
Message sent |
HWND: 90126 Message: WINDOWPOSCHANGING WParam: 0 LParam: 1238912 |
error |
811411258 |
Message sent |
HWND: 90126 Message: NCCALCSIZE WParam: 1 LParam: 1238868 |
error |
811411662 |
Message sent |
HWND: 90126 Message: WINDOWPOSCHANGING WParam: 0 LParam: 1238912 |
error |
811411796 |
Message sent |
HWND: 90126 Message: NCCALCSIZE WParam: 1 LParam: 1238868 |
error |
811523767 |
Window shown |
HWND: 90144 CMD: show normal |
success |
811524088 |
Window shown |
HWND: F0106 CMD: show normal |
success |
811524189 |
Window shown |
HWND: B00F0 CMD: show normal |
success |
811635364 |
Window shown |
HWND: 310108 CMD: show normal |
success |
811636789 |
Window shown |
HWND: 10014A CMD: show normal |
success |
811637428 |
Window shown |
HWND: F010A CMD: show normal |
success |
811747195 |
Window shown |
HWND: 90126 CMD: show normal |
error |
811748503 |
Window shown |
HWND: 10014A CMD: show |
success |
811749513 |
Window shown |
HWND: 1300EC CMD: show normal |
error |
812198648 |
Window shown |
HWND: 90144 CMD: show normal |
success |
812199521 |
Window shown |
HWND: F0106 CMD: show normal |
success |
812306133 |
Window shown |
HWND: B00F0 CMD: show normal |
success |
812306236 |
Window shown |
HWND: 310108 CMD: show normal |
success |
812306657 |
Window shown |
HWND: 10014A CMD: show normal |
success |
812424058 |
Window shown |
HWND: C0100 CMD: hide |
error |
812424320 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~WRF0000.tmp Access: read data or list directory
and read ea and read attributes and read control and synchronize Options: no options
Attributes: normal Content Overwritten: true
|
object name not found |
812425534 |
Section loaded |
Path: \BaseNamedObjects\DfSharedHeap151A40 Access: query and write and read Type:
reserve Baseaddress: 2000000 Size: 4194304 Protection: read write Mapped to pid: own
pid
|
success or wait |
812533199 |
File created |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~WRF0000.tmp Access: read attributes and
synchronize and generic read and generic write Options: synchronous io non alert and
non directory file Attributes: normal Content Overwritten: true
|
success or wait |
812644557 |
File other op |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~WRF0000.tmp New path: Disposition: PositionInformation
Data : Offset: 512
|
success or wait |
812756085 |
File other op |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~WRF0000.tmp New path: Disposition: EndOfFileInformation
Data : unknown
|
success or wait |
812757312 |
File other op |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~WRF0000.tmp New path: Disposition: AllocationInformation
Data : unknown
|
success or wait |
812758964 |
File other op |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~WRF0000.tmp New path: Disposition: PositionInformation
Data : Offset: 0
|
success or wait |
812868026 |
System info queried |
Type: PerformanceInformation |
success or wait |
812869562 |
Process information queried |
PID: 1680 Info Class: QuotaLimits |
success or wait |
812870984 |
Process information queried |
PID: 1680 Info Class: VmCounters |
success or wait |
812980832 |
Section loaded |
Path: \BaseNamedObjects\DFMap0-1382989 Access: query and write and read Type: commit
Baseaddress: 2400000 Size: 524288 Protection: read write Mapped to pid: own pid
|
success or wait |
812981730 |
Section loaded |
Path: \BaseNamedObjects\DfRoot000151A40 Access: query and write and read Type: commit
Baseaddress: 2480000 Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
813092575 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020905-0000-0000-C000-000000000046}\8.3\0\win32
Name: NULL
|
success or wait |
814998880 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{000204EF-0000-0000-C000-000000000046}\4.0\9\win32
Name: NULL
|
success or wait |
815717788 |
File opened |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: read attributes and
synchronize and generic read Options: synchronous io non alert and non directory file
and random access Attributes: none Content Overwritten: true
|
success or wait |
816059575 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 0
|
success or wait |
816061389 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 64 Value:
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 80 00 00 00
|
success or wait |
816165853 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 0
|
success or wait |
816167498 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 128
|
success or wait |
816168673 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 4 Value:
50 45 00 00
|
success or wait |
816276907 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 20 Value:
4C 01 04 00 A6 9B B2 40 00 00 00 00 00 00 00 00 E0 00 02 23
|
success or wait |
816277062 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 376
|
success or wait |
816277323 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 40 Value:
2E 74 65 78 74 00 00 00 7C C7 21 00 00 10 00 00 00 D0 21 00 00 10 00 00 00 00 00 00
00 00 00 00 00 00 00 00 20 00 00 60
|
success or wait |
816390977 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 40 Value:
2E 64 61 74 61 00 00 00 18 C4 00 00 00 E0 21 00 00 B0 00 00 00 E0 21 00 00 00 00 00
00 00 00 00 00 00 00 00 40 00 00 C0
|
success or wait |
816391984 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 40 Value:
2E 72 73 72 63 00 00 00 98 E7 01 00 00 B0 22 00 00 F0 01 00 00 90 22 00 00 00 00 00
00 00 00 00 00 00 00 00 40 00 00 40
|
success or wait |
816392341 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 496
|
success or wait |
816502589 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2265088
|
success or wait |
816503534 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 16 Value:
00 00 00 00 EA 06 B2 40 00 00 00 00 01 00 09 00
|
success or wait |
816504314 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 8 Value:
40 18 00 80 60 00 00 80
|
success or wait |
816613395 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2265112
|
success or wait |
816615118 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2271296
|
success or wait |
816617093 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 2 Value:
07 00
|
success or wait |
816727793 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 14 Value:
54 00 59 00 50 00 45 00 4C 00 49 00 42 00
|
success or wait |
816728523 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2265112
|
success or wait |
816729127 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 496
|
success or wait |
816842589 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 496
|
success or wait |
816842711 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2265184
|
success or wait |
816842825 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 16 Value:
00 00 00 00 EA 06 B2 40 00 00 00 00 00 00 02 00
|
success or wait |
816948255 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2265200
|
success or wait |
816948632 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 8 Value:
01 00 00 00 E0 04 00 80
|
success or wait |
816948957 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 496
|
success or wait |
817061102 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 496
|
success or wait |
817061629 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2266336
|
success or wait |
817062109 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 16 Value:
00 00 00 00 EA 06 B2 40 00 00 00 00 00 00 01 00
|
success or wait |
817172538 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 8 Value:
09 04 00 00 80 10 00 00
|
success or wait |
817173058 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 496
|
success or wait |
817173513 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2269312
|
success or wait |
817284014 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 16 Value:
F8 DD 23 00 40 B9 00 00 00 00 00 00 00 00 00 00
|
success or wait |
817284778 |
Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: query and read Type:
commit Baseaddress: 24D0000 Size: 98304 Protection: readonly Mapped to pid: own pid
|
success or wait |
817285465 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32
Name: NULL
|
success or wait |
818404032 |
File opened |
Path: C:\WINDOWS\system32\stdole2.tlb Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file and random access
Attributes: none Content Overwritten: true
|
success or wait |
818406920 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 0
|
success or wait |
818515672 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 64 Value: 4D 5A 90 00
03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
C0 00 00 00
|
success or wait |
818517830 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 0
|
success or wait |
818519714 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 192
|
success or wait |
818631499 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 4 Value: 50 45 00 00
|
success or wait |
818631654 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 20 Value: 4C 01 01 00
CE 29 02 48 00 00 00 00 00 00 00 00 E0 00 0F 21
|
success or wait |
818631833 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 440
|
success or wait |
818738412 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 40 Value: 2E 72 73 72
63 00 00 00 60 3E 00 00 00 10 00 00 00 40 00 00 00 02 00 00 00 00 00 00 00 00 00 00
00 00 00 00 40 00 00 40
|
success or wait |
818739037 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 480
|
success or wait |
818739748 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 512
|
success or wait |
818852048 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 16 Value: 00 00 00 00
00 00 00 00 00 00 00 00 01 00 01 00
|
success or wait |
818852541 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 8 Value: A0 00 00 80
20 00 00 80
|
success or wait |
818853616 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 536
|
success or wait |
818963031 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 672
|
success or wait |
818963496 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 2 Value: 07 00 |
success or wait |
818963924 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 14 Value: 54 00 59 00
50 00 45 00 4C 00 49 00 42 00
|
success or wait |
819075487 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 536
|
success or wait |
819076182 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 480
|
success or wait |
819076745 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 480
|
success or wait |
819185828 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 544
|
success or wait |
819186383 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 16 Value: 00 00 00 00
00 00 00 00 00 00 00 00 00 00 01 00
|
success or wait |
819186891 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 560
|
success or wait |
819297422 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 8 Value: 01 00 00 00
50 00 00 80
|
success or wait |
819297898 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 480
|
success or wait |
819298326 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 480
|
success or wait |
819411907 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 592
|
success or wait |
819412857 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 16 Value: 00 00 00 00
00 00 00 00 00 00 00 00 00 00 01 00
|
success or wait |
819413158 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 8 Value: 09 04 00 00
80 00 00 00
|
success or wait |
819523370 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 480
|
success or wait |
819524519 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 640
|
success or wait |
819525457 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 16 Value: B0 10 00 00
40 3A 00 00 00 00 00 00 00 00 00 00
|
success or wait |
819636298 |
Section loaded |
Path: C:\WINDOWS\system32\stdole2.tlb Access: query and read Type: commit Baseaddress:
24F0000 Size: 16384 Protection: readonly Mapped to pid: own pid
|
success or wait |
819637685 |
Key created |
Path: HKEY_USERS\Software\Microsoft\VBA |
success or wait |
820082121 |
Key created |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0 |
success or wait |
820087464 |
Key created |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common |
success or wait |
820195849 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: RequireDeclaration |
object name not found |
820306014 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: CompileOnDemand |
object name not found |
820307978 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: NotifyUserBeforeStateLoss |
object name not found |
820310384 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: BackGroundCompile |
object name not found |
820421303 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: BreakOnAllErrors |
object name not found |
820421492 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: BreakOnServerErrors |
object name not found |
820421674 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32
Name: NULL
|
success or wait |
821426638 |
File opened |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL\3 Access: read attributes and
synchronize and generic read Options: synchronous io non alert and non directory file
and random access Attributes: none Content Overwritten: true
|
object path not found |
821649608 |
File opened |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: read attributes and
synchronize and generic read Options: synchronous io non alert and non directory file
and random access Attributes: none Content Overwritten: true
|
success or wait |
821761440 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 0
|
success or wait |
821761912 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 64 Value:
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 80 00 00 00
|
success or wait |
821762016 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 0
|
success or wait |
821873914 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 128
|
success or wait |
821874473 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 4 Value:
50 45 00 00
|
success or wait |
821874934 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 20 Value:
4C 01 04 00 A6 9B B2 40 00 00 00 00 00 00 00 00 E0 00 02 23
|
success or wait |
821985235 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 376
|
success or wait |
821986437 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 40 Value:
2E 74 65 78 74 00 00 00 7C C7 21 00 00 10 00 00 00 D0 21 00 00 10 00 00 00 00 00 00
00 00 00 00 00 00 00 00 20 00 00 60
|
success or wait |
821988015 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 40 Value:
2E 64 61 74 61 00 00 00 18 C4 00 00 00 E0 21 00 00 B0 00 00 00 E0 21 00 00 00 00 00
00 00 00 00 00 00 00 00 40 00 00 C0
|
success or wait |
822095857 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 40 Value:
2E 72 73 72 63 00 00 00 98 E7 01 00 00 B0 22 00 00 F0 01 00 00 90 22 00 00 00 00 00
00 00 00 00 00 00 00 00 40 00 00 40
|
success or wait |
822096991 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 496
|
success or wait |
822097921 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2265088
|
success or wait |
822213475 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 16 Value:
00 00 00 00 EA 06 B2 40 00 00 00 00 01 00 09 00
|
success or wait |
822213609 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 8 Value:
40 18 00 80 60 00 00 80
|
success or wait |
822213760 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2265112
|
success or wait |
822317651 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2271296
|
success or wait |
822318218 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 2 Value:
07 00
|
success or wait |
822318788 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 14 Value:
54 00 59 00 50 00 45 00 4C 00 49 00 42 00
|
success or wait |
822431183 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2265112
|
success or wait |
822431681 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 496
|
success or wait |
822432105 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 496
|
success or wait |
822541569 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2265184
|
success or wait |
822542062 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 16 Value:
00 00 00 00 EA 06 B2 40 00 00 00 00 00 00 02 00
|
success or wait |
822542510 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2265200
|
success or wait |
822653921 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 8 Value:
01 00 00 00 E0 04 00 80
|
success or wait |
822655648 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 8 Value:
03 00 00 00 F8 04 00 80
|
success or wait |
822657095 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 496
|
success or wait |
822765616 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 496
|
success or wait |
822766149 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2266360
|
success or wait |
822766649 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 16 Value:
00 00 00 00 EA 06 B2 40 00 00 00 00 00 00 01 00
|
success or wait |
822877112 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 8 Value:
09 04 00 00 90 10 00 00
|
success or wait |
822877267 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 496
|
success or wait |
822877408 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2269328
|
success or wait |
822991530 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 16 Value:
00 AE 23 00 54 0F 00 00 00 00 00 00 00 00 00 00
|
success or wait |
822991786 |
Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: query and read Type:
commit Baseaddress: 2570000 Size: 40960 Protection: readonly Mapped to pid: own pid
|
success or wait |
822992075 |
File created |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\VBE Access: read data or list directory and
synchronize Options: directory file and synchronous io non alert and open for backup
ident Attributes: normal Content Overwritten: true
|
success or wait |
823437745 |
Process information queried |
PID: 1680 Info Class: DeviceMap |
success or wait |
824108150 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
824221259 |
Directory Information Queried |
Path: C:\Disposition: BothDirectoryInformation Filemask: Documents and Settings Data
: abstraction.selector.functions.gen.NtFunc$FunctionData@4e76b4
|
success or wait |
824222529 |
File opened |
Path: C:\Documents and Settings\ Access: read data or list directory and synchronize
Options: directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
824331755 |
Directory Information Queried |
Path: C:\Documents and SettingsDisposition: BothDirectoryInformation Filemask: Administrator
Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1533b2c
|
success or wait |
824332546 |
File opened |
Path: C:\Documents and Settings\Administrator\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
824444028 |
Directory Information Queried |
Path: C:\Documents and Settings\AdministratorDisposition: BothDirectoryInformation
Filemask: Application Data Data : abstraction.selector.functions.gen.NtFunc$FunctionData@151d6cb
|
success or wait |
824445621 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\ Access: read data
or list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
824555438 |
Directory Information Queried |
Path: C:\Documents and Settings\Administrator\Application DataDisposition: BothDirectoryInformation
Filemask: Microsoft Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ecda50
|
success or wait |
824556861 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
824666609 |
Directory Information Queried |
Path: C:\Documents and Settings\Administrator\Application Data\MicrosoftDisposition:
BothDirectoryInformation Filemask: Templates Data : abstraction.selector.functions.gen.NtFunc$FunctionData@f0f6ac
|
success or wait |
824667066 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020905-0000-0000-C000-000000000046}\8.3\0\win32
Name: NULL
|
success or wait |
825564420 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.3\0\win32
Name: NULL
|
success or wait |
826346816 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Access: read
attributes and synchronize and generic read Options: synchronous io non alert and
non directory file and random access Attributes: none Content Overwritten: true
|
success or wait |
826570352 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL New path:
Disposition: PositionInformation Data : Offset: 0
|
success or wait |
826687225 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00
00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 40 01 00 00
|
success or wait |
826687318 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL New path:
Disposition: PositionInformation Data : Offset: 0
|
success or wait |
826687574 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL New path:
Disposition: PositionInformation Data : Offset: 320
|
success or wait |
826794407 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 4 Value: 50 45 00 00
|
success or wait |
826795840 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 20 Value: 4C 01 05 00 F6 8E E1 42 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
826797701 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL New path:
Disposition: PositionInformation Data : Offset: 568
|
success or wait |
826904671 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 40 Value: 2E 74 65 78 74 00 00 00 F9 47 97 00 00 10 00 00 00 48 97 00 00 04
00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60
|
success or wait |
826905539 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 40 Value: 2E 64 61 74 61 00 00 00 98 43 05 00 00 60 97 00 00 AC 04 00 00 4C
97 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0
|
success or wait |
826906291 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 40 Value: 2E 63 64 61 74 61 00 00 04 00 00 00 00 B0 9C 00 00 02 00 00 00 F8
9B 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0
|
success or wait |
827015564 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 40 Value: 2E 72 73 72 63 00 00 00 E0 D6 10 00 00 C0 9C 00 00 D8 10 00 00 FA
9B 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40
|
success or wait |
827015730 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL New path:
Disposition: PositionInformation Data : Offset: 728
|
success or wait |
827016505 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL New path:
Disposition: PositionInformation Data : Offset: 10222080
|
success or wait |
827128473 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 16 Value: 00 00 00 00 00 00 00 00 00 00 00 00 03 00 0E 00
|
success or wait |
827129323 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 8 Value: B6 6A 00 80 98 00 00 80
|
success or wait |
827352502 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL New path:
Disposition: PositionInformation Data : Offset: 10222104
|
success or wait |
827354235 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL New path:
Disposition: PositionInformation Data : Offset: 10249398
|
success or wait |
827355640 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 2 Value: 03 00
|
success or wait |
827465185 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL New path:
Disposition: PositionInformation Data : Offset: 10222104
|
success or wait |
827576528 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 8 Value: E0 6C 00 80 20 01 00 80
|
success or wait |
827686696 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL New path:
Disposition: PositionInformation Data : Offset: 10222112
|
success or wait |
827686819 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL New path:
Disposition: PositionInformation Data : Offset: 10249952
|
success or wait |
827686914 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 2 Value: 07 00
|
success or wait |
827803867 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 14 Value: 54 00 59 00 50 00 45 00 4C 00 49 00 42 00
|
success or wait |
827803979 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL New path:
Disposition: PositionInformation Data : Offset: 10222112
|
success or wait |
827804089 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL New path:
Disposition: PositionInformation Data : Offset: 728
|
success or wait |
827912928 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL New path:
Disposition: PositionInformation Data : Offset: 728
|
success or wait |
827913219 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL New path:
Disposition: PositionInformation Data : Offset: 10222368
|
success or wait |
827913487 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 16 Value: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00
|
success or wait |
828023024 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL New path:
Disposition: PositionInformation Data : Offset: 10222384
|
success or wait |
828023732 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 8 Value: 01 00 00 00 90 14 00 80
|
success or wait |
828024310 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL New path:
Disposition: PositionInformation Data : Offset: 728
|
success or wait |
828136377 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL New path:
Disposition: PositionInformation Data : Offset: 728
|
success or wait |
828136750 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL New path:
Disposition: PositionInformation Data : Offset: 10227344
|
success or wait |
828137093 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 16 Value: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00
|
success or wait |
828246037 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 8 Value: 09 04 00 00 98 48 00 00
|
success or wait |
828360949 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL New path:
Disposition: PositionInformation Data : Offset: 728
|
success or wait |
828476527 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL New path:
Disposition: PositionInformation Data : Offset: 10240664
|
success or wait |
828476641 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 16 Value: 20 E9 A9 00 A4 AA 03 00 00 00 00 00 00 00 00 00
|
success or wait |
828476747 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Access: query
and read Type: commit Baseaddress: 25C0000 Size: 249856 Protection: readonly Mapped
to pid: own pid
|
success or wait |
828585848 |
Foreground Window Got |
HWND: 10084 |
success |
829254755 |
Foreground Window Got |
HWND: 10084 |
success |
829256174 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{000204EF-0000-0000-C000-000000000046}\4.0\9\win32
Name: NULL
|
success or wait |
831267349 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020905-0000-0000-C000-000000000046}\8.3\0\win32
Name: NULL
|
success or wait |
831938400 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32
Name: NULL
|
success or wait |
833396076 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.3\0\win32
Name: NULL
|
success or wait |
834405185 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
835184478 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
835295771 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32
Name: InprocServer32
|
object name not found |
835520373 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32
Name: NULL
|
success or wait |
835745160 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}
Name: AppID
|
object name not found |
835964917 |
Message sent |
HWND: 1A012E Message: CANCELMODE WParam: 0 LParam: 0 |
error |
836303476 |
Window shown |
HWND: 13010C CMD: show |
success |
836529856 |
Window shown |
HWND: 1F0150 CMD: show |
success |
836529951 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate Name:
BytesPerSec
|
object name not found |
836530957 |
System info queried |
Type: CurrentTimeZoneInformation |
success or wait |
836531120 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Build |
success or wait |
836806156 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version |
success or wait |
836807251 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Common Name: QMEnable |
object name not found |
836919706 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Common Name: QMEnable |
object name not found |
836920874 |
System info queried |
Type: PerformanceInformation |
success or wait |
836922343 |
Process information queried |
PID: 1680 Info Class: QuotaLimits |
success or wait |
836923218 |
Process information queried |
PID: 1680 Info Class: VmCounters |
success or wait |
836923817 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm Name: NULL |
success or wait |
837141655 |
File opened |
Path: C:\WINDOWS\system32 Access: read data or list directory and synchronize Options:
directory file and synchronous io non alert and open for free space query Overwritten:
false
|
success or wait |
837142531 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Common Name: QMInternalUID |
object name not found |
837144044 |
Message posted |
HWND: 11013E Message: 400 WParam: 47806 LParam: 1462916 |
success |
837254344 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0002E157-0000-0000-C000-000000000046}\5.3\0\win32
Name: NULL
|
buffer overflow |
838037818 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0002E157-0000-0000-C000-000000000046}\5.3\0\win32
Name: NULL
|
success or wait |
838038769 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file and random access Attributes: none Content Overwritten: true
|
success or wait |
838153612 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB New path:
Disposition: PositionInformation Data : Offset: 0
|
success or wait |
838260093 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB Offset:
unknown Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00
00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 00
|
success or wait |
838371219 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB New path:
Disposition: PositionInformation Data : Offset: 0
|
success or wait |
838375125 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB New path:
Disposition: PositionInformation Data : Offset: 128
|
success or wait |
838485964 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB Offset:
unknown Length: 4 Value: 50 45 00 00
|
success or wait |
838486118 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB Offset:
unknown Length: 20 Value: 4C 01 02 00 9F 9C 00 3F 00 00 00 00 00 00 00 00 E0 00 0E
21
|
success or wait |
838486263 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB New path:
Disposition: PositionInformation Data : Offset: 376
|
success or wait |
838595007 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB Offset:
unknown Length: 40 Value: 2E 72 73 72 63 00 00 00 08 86 00 00 00 10 00 00 00 90 00
00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40
|
success or wait |
838596122 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB New path:
Disposition: PositionInformation Data : Offset: 416
|
success or wait |
838597166 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB New path:
Disposition: PositionInformation Data : Offset: 4096
|
success or wait |
838708916 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB Offset:
unknown Length: 16 Value: 00 00 00 00 9F 9C 00 3F 00 00 00 00 01 00 01 00
|
success or wait |
838710228 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB Offset:
unknown Length: 8 Value: A0 00 00 80 20 00 00 80
|
success or wait |
838818919 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB New path:
Disposition: PositionInformation Data : Offset: 4120
|
success or wait |
838819925 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB New path:
Disposition: PositionInformation Data : Offset: 4256
|
success or wait |
838820745 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB Offset:
unknown Length: 2 Value: 07 00
|
success or wait |
838928893 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB Offset:
unknown Length: 14 Value: 54 00 59 00 50 00 45 00 4C 00 49 00 42 00
|
success or wait |
838929044 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB New path:
Disposition: PositionInformation Data : Offset: 4120
|
success or wait |
838929194 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB New path:
Disposition: PositionInformation Data : Offset: 416
|
success or wait |
839043348 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB New path:
Disposition: PositionInformation Data : Offset: 416
|
success or wait |
839043521 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB New path:
Disposition: PositionInformation Data : Offset: 4128
|
success or wait |
839044306 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB Offset:
unknown Length: 16 Value: 00 00 00 00 9F 9C 00 3F 00 00 00 00 00 00 01 00
|
success or wait |
839153033 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB New path:
Disposition: PositionInformation Data : Offset: 4144
|
success or wait |
839154167 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB Offset:
unknown Length: 8 Value: 01 00 00 00 50 00 00 80
|
success or wait |
839155083 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB New path:
Disposition: PositionInformation Data : Offset: 416
|
success or wait |
839267433 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB New path:
Disposition: PositionInformation Data : Offset: 416
|
success or wait |
839268211 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB New path:
Disposition: PositionInformation Data : Offset: 4176
|
success or wait |
839268860 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB Offset:
unknown Length: 16 Value: 00 00 00 00 9F 9C 00 3F 00 00 00 00 00 00 01 00
|
success or wait |
839377887 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB Offset:
unknown Length: 8 Value: 09 04 00 00 80 00 00 00
|
success or wait |
839379422 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB New path:
Disposition: PositionInformation Data : Offset: 416
|
success or wait |
839380686 |
File other op |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB New path:
Disposition: PositionInformation Data : Offset: 4224
|
success or wait |
839489241 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB Offset:
unknown Length: 16 Value: B0 10 00 00 6C 80 00 00 00 00 00 00 00 00 00 00
|
success or wait |
839489762 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6EXT.OLB Access:
query and read Type: commit Baseaddress: 2600000 Size: 40960 Protection: readonly
Mapped to pid: own pid
|
success or wait |
839490306 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: MdiMaximized |
object name not found |
840165040 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 1400E8 |
success |
845250987 |
Message sent |
HWND: 1400E8 Message: NCCREATE WParam: 0 LParam: 1238584 |
success |
845251959 |
Message sent |
HWND: 1400E8 Message: NCCALCSIZE WParam: 0 LParam: 1238624 |
error |
845253343 |
Window created |
Window Name: mdiclient Class Name: mdiclient HWND: 14014E |
success |
845362391 |
Message sent |
HWND: 14014E Message: NCCREATE WParam: 0 LParam: 1238568 |
success |
845363125 |
Message sent |
HWND: 1400E8 Message: NCCALCSIZE WParam: 0 LParam: 1238624 |
error |
845364225 |
Message posted |
HWND: 14014E Message: 3F WParam: 0 LParam: 0 |
success |
845365244 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: B0120 |
success |
850733657 |
Message sent |
HWND: B0120 Message: NCCREATE WParam: 0 LParam: 1238536 |
success |
850734214 |
Message sent |
HWND: B0120 Message: NCCALCSIZE WParam: 0 LParam: 1238576 |
error |
850735000 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: UILanguage |
success or wait |
850848835 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
RestrictRun
|
object name not found |
850956084 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\VB11.pip
Access: read attributes and synchronize and generic read Options: sequential only
and synchronous io non alert and non directory file and open no recall Attributes:
none Content Overwritten: true
|
object name not found |
851068569 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\VB11.pip
Access: read attributes and synchronize and generic read Options: sequential only
and synchronous io non alert and non directory file and open no recall Attributes:
none Content Overwritten: true
|
object name not found |
851183586 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: GridWidth |
object name not found |
851350674 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: GridHeight |
object name not found |
851459483 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: ShowGrid |
object name not found |
851569266 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: AlignToGrid |
object name not found |
851570497 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: SaveBeforeRun |
object name not found |
851681006 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: ShowToolTips |
object name not found |
851798751 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: CollapseWindows |
object name not found |
851799070 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: UpgradeVBX |
object name not found |
851907716 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: ReadOnlyMode |
object name not found |
852017470 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: BackgroundProjectLoad |
object name not found |
852019361 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 2000F8 |
success |
856492907 |
Window created |
Window Name: SysTreeView32 Class Name: SysTreeView32 HWND: 15012C |
success |
856609510 |
Key value queried |
Path: HKEY_USERS\Control Panel\Desktop Name: SmoothScroll |
object name not found |
856939383 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
Name: Tahoma
|
object name not found |
857279136 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
Name: Tahoma
|
object name not found |
857388932 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: FolderView |
object name not found |
857499916 |
Message posted |
HWND: 15012C Message: 2100 WParam: 0 LParam: 0 |
success |
857611827 |
Message posted |
HWND: 15012C Message: 2100 WParam: 0 LParam: 0 |
success |
857835798 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: Tool |
object name not found |
858175012 |
Window created |
Window Name: ToolsPalette Class Name: ToolsPalette HWND: 20246 |
success |
858282666 |
Message sent |
HWND: 14014E Message: NCCREATE WParam: 0 LParam: 1238568 |
success |
858283369 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 60258 |
success |
863262334 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 6023C |
success |
868912330 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: PropertiesWindow |
object name not found |
869028595 |
Window created |
Window Name: ComboBox Class Name: ComboBox HWND: 60240 |
success |
869029049 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 6023E |
success |
873158720 |
Message posted |
HWND: 6023E Message: SIZE WParam: 0 LParam: 0 |
success |
873383519 |
Window shown |
HWND: 6023E CMD: hide |
success |
873387698 |
Window shown |
HWND: 6023E CMD: hide |
error |
873389244 |
Window shown |
HWND: 6023E CMD: hide |
error |
873495725 |
Window created |
Window Name: SysTabControl32 Class Name: SysTabControl32 HWND: 801DA |
success |
873496651 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
Name: Tahoma
|
object name not found |
873831543 |
Window created |
Window Name: ListBox Class Name: ListBox HWND: 201F0 |
success |
873834436 |
Window created |
Window Name: Button Class Name: Button HWND: 201EE |
success |
873944834 |
Window created |
Window Name: Edit Class Name: Edit HWND: 201EC |
success |
874053021 |
Window created |
Window Name: ListBox Class Name: ListBox HWND: 201EA |
success |
874165475 |
Message posted |
HWND: 201EA Message: SIZE WParam: 0 LParam: 0 |
success |
874167283 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: UI |
object name not found |
874281978 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Toolbars\Settings Name: Microsoft
Visual Basic AWDropdownHidden
|
object name not found |
874392456 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Toolbars\Settings Name: Microsoft
Visual Basic AWDropdownHidden
|
object name not found |
874502888 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 201E8 |
success |
879876909 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 201E6 |
success |
885073107 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 201E4 |
success |
890161326 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 201E2 |
success |
895531050 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 201E0 |
success |
901011803 |
Window shown |
HWND: 201E6 CMD: show no activate |
error |
901909844 |
Window shown |
HWND: 201E6 CMD: show no activate |
success |
901910590 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: Dock |
object name not found |
902025285 |
Window shown |
HWND: 201E6 CMD: show no activate |
success |
902357841 |
Window shown |
HWND: 6023E CMD: hide |
error |
902689588 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 140116 |
success |
908287740 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 201DE |
success |
913820221 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 601DC |
success |
919251820 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 301AE |
success |
924559108 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0002E157-0000-0000-C000-000000000046}\5.3\0\win32
Name: NULL
|
buffer overflow |
925009398 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0002E157-0000-0000-C000-000000000046}\5.3\0\win32
Name: NULL
|
success or wait |
925121106 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: CtlsShowSelected |
object name not found |
925346720 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: DsnShowSelected |
object name not found |
925453226 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: MainWindow |
object name not found |
925565815 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
925792258 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
925905144 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32
Name: InprocServer32
|
object name not found |
926126121 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32
Name: NULL
|
success or wait |
926349511 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}
Name: AppID
|
object name not found |
926573746 |
Foreground Window Got |
HWND: 10084 |
success |
927023854 |
Message posted |
HWND: 11013E Message: 400 WParam: 47806 LParam: 1462916 |
success |
927584549 |
Key value queried |
Path: HKEY_USERS\Control Panel\International\Geo Name: Nation |
success or wait |
928363311 |
Message posted |
HWND: 11013E Message: 400 WParam: 47806 LParam: 2000556 |
success |
928588827 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 201D8 |
success |
933342767 |
Window placement got |
HWND: 201D8 CMD: show normal |
success |
933455871 |
Window placement got |
HWND: 201D8 CMD: show normal |
success |
933457033 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: AutoIndent |
object name not found |
935019031 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: FullModuleView |
object name not found |
935019327 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: IndicatorBar |
object name not found |
935131948 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: SyntaxChecking |
object name not found |
935132450 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: EndProcLine |
object name not found |
935132927 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: DragDropInEditor |
object name not found |
935245151 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: AutoStatement2 |
object name not found |
935246066 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: AutoQuickTips2 |
object name not found |
935246853 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: AutoValueTips2 |
object name not found |
935359349 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: TabWidth |
object name not found |
935360305 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: OBSearchHeight |
object name not found |
935361131 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: OBGroupMembers |
object name not found |
935468448 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: CodeForeColors |
object name not found |
935469183 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: CodeBackColors |
object name not found |
935469830 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: IndicatorColors |
object name not found |
935577068 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: FontCharSet |
object name not found |
935577367 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: FontHeight |
object name not found |
935577655 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: FontFace |
object name not found |
935690778 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows NT\CurrentVersion\Windows Name: DragMinDist |
object name not found |
936364609 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows NT\CurrentVersion\Windows Name: DragDelay |
object name not found |
936476727 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows NT\CurrentVersion\Windows Name: DragScrollInset |
object name not found |
936588383 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows NT\CurrentVersion\Windows Name: DragScrollDelay |
object name not found |
936589734 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows NT\CurrentVersion\Windows Name: DragScrollInterval |
object name not found |
936702628 |
Window created |
Window Name: tooltips_class32 Class Name: tooltips_class32 HWND: 201D6 |
success |
937150216 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
Name: Tahoma
|
object name not found |
937261101 |
Window created |
Window Name: tooltips_class32 Class Name: tooltips_class32 HWND: 201D4 |
success |
937371324 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
Name: Tahoma
|
object name not found |
937481633 |
Window created |
Window Name: ComboBox Class Name: ComboBox HWND: 201D2 |
success |
937590424 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 201D0 |
success |
942680052 |
Message posted |
HWND: 201D0 Message: SIZE WParam: 0 LParam: 0 |
success |
942681335 |
Window shown |
HWND: 201D0 CMD: hide |
success |
942791846 |
Window shown |
HWND: 201D0 CMD: hide |
error |
942792247 |
Window created |
Window Name: ComboBox Class Name: ComboBox HWND: 201CA |
success |
943016160 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 201CC |
success |
948328520 |
Message posted |
HWND: 201CC Message: SIZE WParam: 0 LParam: 0 |
success |
948446323 |
Window shown |
HWND: 201CC CMD: hide |
success |
948446918 |
Window shown |
HWND: 201CC CMD: hide |
error |
948553544 |
Window created |
Window Name: SCROLLBAR Class Name: SCROLLBAR HWND: 201CE |
success |
948557108 |
Window created |
Window Name: SCROLLBAR Class Name: SCROLLBAR HWND: 201C8 |
success |
948558769 |
Window created |
Window Name: SCROLLBAR Class Name: SCROLLBAR HWND: 201C6 |
success |
948666931 |
Window created |
Window Name: SCROLLBAR Class Name: SCROLLBAR HWND: 201C4 |
success |
948669353 |
Window created |
Window Name: ObtbarWndClass Class Name: ObtbarWndClass HWND: 201C2 |
success |
948671404 |
Window shown |
HWND: 201D2 CMD: show |
error |
949114153 |
Window shown |
HWND: 201CA CMD: show |
error |
949224112 |
Window placement got |
HWND: 201D8 CMD: show normal |
success |
949335938 |
Window shown |
HWND: 201D0 CMD: hide |
error |
949450941 |
Window shown |
HWND: 201CC CMD: hide |
error |
949677131 |
Window shown |
HWND: 201D0 CMD: hide |
error |
950120396 |
Window shown |
HWND: 201CC CMD: hide |
error |
950348725 |
Window shown |
HWND: 201D2 CMD: show |
success |
950567015 |
Window shown |
HWND: 201CA CMD: show |
success |
950567133 |
Window shown |
HWND: 201D8 CMD: show |
error |
950567346 |
Message posted |
HWND: 15012C Message: 2100 WParam: 0 LParam: 0 |
success |
950680663 |
Message posted |
HWND: 11013E Message: 400 WParam: 47806 LParam: 1462916 |
success |
950795713 |
Message posted |
HWND: 11013E Message: 400 WParam: 47806 LParam: 2000556 |
success |
951015776 |
Message posted |
HWND: 11013E Message: 400 WParam: 47806 LParam: 1462916 |
success |
952362949 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\72.tmp Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
954090245 |
Section loaded |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\72.tmp Access: write and read and execute
Type: commit Baseaddress: 2660000 Size: 24576 Protection: execute Mapped to pid: own
pid
|
success or wait |
954204650 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\72.tmp Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
954317966 |
Section loaded |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\72.tmp Access: query and write and read and
execute Type: image Baseaddress: 2660000 Size: 49152 Protection: read write Mapped
to pid: own pid
|
conflicting addresses |
954318901 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 2661000
Length: 4000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
954540713 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 2667000
Length: 1000 New Protection: page read and write Old Protection: page readonly
|
success or wait |
954541423 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 2669000
Length: 1000 New Protection: page read and write Old Protection: page readonly
|
success or wait |
954542019 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 266B000
Length: 1000 New Protection: page read and write Old Protection: page readonly
|
success or wait |
954655271 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 2661000
Length: 4000 New Protection: page execute Old Protection: page read and write
|
success or wait |
954875477 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 2667000
Length: 1000 New Protection: page readonly Old Protection: page read and write
|
success or wait |
954875870 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 2669000
Length: 1000 New Protection: page readonly Old Protection: page write copy
|
success or wait |
954876223 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 266B000
Length: 1000 New Protection: page readonly Old Protection: page write copy
|
success or wait |
954988583 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 266A000
Length: 1000 New Protection: page read and write Old Protection: page write copy
|
success or wait |
954990256 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 266A000
Length: 1000 New Protection: page write copy Old Protection: page read and write
|
success or wait |
955098279 |
Section loaded |
Path: \KnownDlls\ws2_32.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
956641069 |
File opened |
Path: C:\WINDOWS\system32\ws2_32.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
956641448 |
Section loaded |
Path: C:\WINDOWS\system32\ws2_32.dll Access: query and write and read and execute
Type: image Baseaddress: 71AB0000 Size: 94208 Protection: read write Mapped to pid:
own pid
|
success or wait |
956641899 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 71AB1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
956834095 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 71AB1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
956835375 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 71AB1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
956943034 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 71AB1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
956945345 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 71AB1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
956947993 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 71AB1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
957053710 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 71AB1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
957053885 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 71AB1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
957054051 |
Section loaded |
Path: \KnownDlls\WS2HELP.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
957168233 |
File opened |
Path: C:\WINDOWS\system32\WS2HELP.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
957169267 |
Section loaded |
Path: C:\WINDOWS\system32\ws2help.dll Access: query and write and read and execute
Type: image Baseaddress: 71AA0000 Size: 32768 Protection: read write Mapped to pid:
own pid
|
success or wait |
957169735 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 71AA1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
957390631 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 71AA1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
957391855 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 71AA1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
957392833 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 71AA1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
957503610 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 71AA1000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
957504666 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 71AA1000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
957505865 |
System info queried |
Type: BasicInformation |
success or wait |
957614715 |
System info queried |
Type: ProcessorInformation |
success or wait |
957615255 |
Section loaded |
Path: \KnownDlls\iphlpapi.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
958008510 |
File opened |
Path: C:\WINDOWS\system32\iphlpapi.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
958010158 |
Section loaded |
Path: C:\WINDOWS\system32\iphlpapi.dll Access: query and write and read and execute
Type: image Baseaddress: 76D60000 Size: 102400 Protection: read write Mapped to pid:
own pid
|
success or wait |
958011634 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76D61000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
958232035 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76D61000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
958232434 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76D61000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
958340139 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76D61000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
958340453 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76D61000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
958340717 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76D61000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
958454648 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76D61000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
958455131 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76D61000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
958456179 |
System info queried |
Type: BasicInformation |
success or wait |
958565343 |
File opened |
Path: \Device\Tcp Access: generic execute Options: no options Attributes: normal Content
Overwritten: true
|
success or wait |
958678494 |
File opened |
Path: \Device\Tcp Access: generic execute Options: no options Attributes: normal Content
Overwritten: true
|
success or wait |
958787822 |
File opened |
Path: \Device\Ip Access: generic execute Options: no options Attributes: normal Content
Overwritten: true
|
success or wait |
958788530 |
File opened |
Path: \Device\Ip Access: generic execute Options: no options Attributes: normal Content
Overwritten: true
|
success or wait |
958789176 |
File opened |
Path: Ip Access: read attributes and synchronize and generic execute Options: non
directory file Attributes: normal Content Overwritten: true
|
success or wait |
958899496 |
Section loaded |
Path: unknown Access: query and write and read and execute Type: commit Baseaddress:
90000 Size: 4096 Protection: execute and read and write Mapped to pid: 1744
|
success or wait |
961673549 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager Name: SafeProcessSearchMode |
object name not found |
961752672 |
File opened |
Path: C:\WINDOWS\system32\svchost.exe Access: read data or list directory and execute
or traverse and read attributes and synchronize Options: synchronous io non alert
and non directory file Overwritten: false
|
success or wait |
961753269 |
Section loaded |
Path: C:\WINDOWS\system32\svchost.exe Access: query and write and read and execute
and extend size Type: image Baseaddress: 90000 Size: 4096 Protection: execute and
read and write Mapped to pid: 1744
|
success or wait |
961869758 |
File opened |
Path: C:\WINDOWS\system32\Apphelp.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
961870276 |
Section loaded |
Path: C:\WINDOWS\system32\apphelp.dll Access: write and read and execute Type: commit
Baseaddress: 2680000 Size: 126976 Protection: execute Mapped to pid: own pid
|
success or wait |
961981114 |
File opened |
Path: C:\WINDOWS\system32\Apphelp.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
962090233 |
Section loaded |
Path: C:\WINDOWS\system32\apphelp.dll Access: query and write and read and execute
Type: image Baseaddress: 77B40000 Size: 139264 Protection: read write Mapped to pid:
own pid
|
success or wait |
962091675 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77B41000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
962314349 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77B41000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
962315053 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77B41000
Length: 1000 New Protection: page read and write Old Protection: page execute read
|
success or wait |
962315592 |
Memory attributes changed |
PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77B41000
Length: 1000 New Protection: page execute read Old Protection: page read and write
|
success or wait |
962425449 |
File opened |
Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file Attributes:
normal Content Overwritten: true
|
success or wait |
962427676 |
Section loaded |
Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 2680000
Size: 1208320 Protection: readonly Mapped to pid: own pid
|
success or wait |
962429651 |
File opened |
Path: C:\WINDOWS\AppPatch\systest.sdb Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file Attributes:
normal Content Overwritten: true
|
object name not found |
962538660 |
System info queried |
Type: ProcessorInformation |
success or wait |
962539011 |
Process information queried |
PID: 1680 Info Class: Wow64Information |
success or wait |
962647894 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\WPA\MediaCenter Name: Installed |
success or wait |
962649007 |
File opened |
Path: \Device\NamedPipe\ShimViewer Access: write data or add file and append data
or add subdirectory or create pipe instance and write ea and write attributes and
read control and synchronize Options: no options Attributes: normal Content Overwritten:
true
|
object name not found |
962760946 |
File opened |
Path: C:\WINDOWS\system32\ Access: execute or traverse and synchronize Options: directory
file and synchronous io non alert Overwritten: false
|
success or wait |
962762068 |
Directory Information Queried |
Path: C:\WINDOWS\system32Disposition: BothDirectoryInformation Filemask: svchost.exe
Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1d29ee4
|
success or wait |
962763142 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
962877103 |
Directory Information Queried |
Path: C:\Disposition: BothDirectoryInformation Filemask: WINDOWS Data : abstraction.selector.functions.gen.NtFunc$FunctionData@bda96b
|
success or wait |
962984022 |
File opened |
Path: C:\WINDOWS\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
962985179 |
Directory Information Queried |
Path: C:\WINDOWSDisposition: BothDirectoryInformation Filemask: system32 Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1bdb02e
|
success or wait |
963097546 |
File opened |
Path: C:\WINDOWS\system32\ Access: execute or traverse and synchronize Options: directory
file and synchronous io non alert Overwritten: false
|
success or wait |
963102637 |
Directory Information Queried |
Path: C:\WINDOWS\system32Disposition: BothDirectoryInformation Filemask: svchost.exe
Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1d29ee4
|
success or wait |
963206942 |
Process information queried |
PID: 1680 Info Class: DeviceMap |
success or wait |
963320625 |
File opened |
Path: C:\WINDOWS\system32\svchost.exe Access: read data or list directory and execute
or traverse and read attributes and synchronize Options: synchronous io non alert
and non directory file Overwritten: false
|
success or wait |
963656143 |
Section loaded |
Path: C:\WINDOWS\system32\svchost.exe Access: write and read and execute Type: commit
Baseaddress: 27B0000 Size: 16384 Protection: execute Mapped to pid: own pid
|
success or wait |
963770527 |
File opened |
Path: C:\WINDOWS\system32\svchost.exe Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
963884169 |
Section loaded |
Path: C:\WINDOWS\system32\svchost.exe Access: query and read Type: commit Baseaddress:
27B0000 Size: 16384 Protection: readonly Mapped to pid: own pid
|
success or wait |
963991887 |
File opened |
Path: C:\WINDOWS\system32\svchost.exe Access: read data or list directory and execute
or traverse and read attributes and synchronize Options: synchronous io non alert
and non directory file Overwritten: false
|
success or wait |
964220969 |
Section loaded |
Path: C:\WINDOWS\system32\svchost.exe Access: write and read and execute Type: commit
Baseaddress: 27B0000 Size: 16384 Protection: execute Mapped to pid: own pid
|
success or wait |
964222814 |
File opened |
Path: C:\WINDOWS\system32\svchost.exe Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
964436719 |
Section loaded |
Path: C:\WINDOWS\system32\svchost.exe Access: query and read Type: commit Baseaddress:
27B0000 Size: 16384 Protection: readonly Mapped to pid: own pid
|
success or wait |
964437186 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
964666375 |
Directory Information Queried |
Path: C:\Disposition: BothDirectoryInformation Filemask: WINDOWS Data : abstraction.selector.functions.gen.NtFunc$FunctionData@bda96b
|
success or wait |
964773519 |
File opened |
Path: C:\WINDOWS\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
964775736 |
Directory Information Queried |
Path: C:\WINDOWSDisposition: BothDirectoryInformation Filemask: system32 Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1bdb02e
|
success or wait |
964884177 |
File opened |
Path: C:\WINDOWS\system32\ Access: execute or traverse and synchronize Options: directory
file and synchronous io non alert Overwritten: false
|
success or wait |
964884624 |
Directory Information Queried |
Path: C:\WINDOWS\system32Disposition: BothDirectoryInformation Filemask: svchost.exe
Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1d29ee4
|
success or wait |
964996989 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Name: TransparentEnabled
|
success or wait |
965221048 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Name: AuthenticodeEnabled
|
success or wait |
965222435 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Name: Levels
|
object name not found |
965331806 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}
Name: ItemData
|
success or wait |
965332866 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}
Name: SaferFlags
|
success or wait |
965443313 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}
Name: ItemData
|
success or wait |
965560262 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}
Name: HashAlg
|
success or wait |
965560577 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}
Name: ItemSize
|
success or wait |
965560897 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}
Name: SaferFlags
|
success or wait |
965669007 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}
Name: ItemData
|
success or wait |
965671676 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}
Name: HashAlg
|
success or wait |
965779812 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}
Name: ItemSize
|
success or wait |
965781669 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}
Name: SaferFlags
|
success or wait |
965783223 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}
Name: ItemData
|
success or wait |
965893343 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}
Name: HashAlg
|
success or wait |
965894508 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}
Name: ItemSize
|
success or wait |
966003212 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}
Name: SaferFlags
|
success or wait |
966004524 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}
Name: ItemData
|
success or wait |
966117640 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}
Name: HashAlg
|
success or wait |
966117954 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}
Name: ItemSize
|
success or wait |
966118242 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}
Name: SaferFlags
|
success or wait |
966226315 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}
Name: ItemData
|
success or wait |
966226851 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}
Name: HashAlg
|
success or wait |
966343761 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}
Name: ItemSize
|
success or wait |
966344186 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}
Name: SaferFlags
|
success or wait |
966344599 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Name: DefaultLevel
|
success or wait |
967013986 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Name: PolicyScope
|
success or wait |
967233448 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
967347283 |
Directory Information Queried |
Path: C:\Disposition: BothDirectoryInformation Filemask: WINDOWS Data : abstraction.selector.functions.gen.NtFunc$FunctionData@bda96b
|
success or wait |
967457546 |
File opened |
Path: C:\WINDOWS\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
967460266 |
Directory Information Queried |
Path: C:\WINDOWSDisposition: BothDirectoryInformation Filemask: system32 Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1bdb02e
|
success or wait |
967570503 |
File opened |
Path: C:\WINDOWS\system32\ Access: execute or traverse and synchronize Options: directory
file and synchronous io non alert Overwritten: false
|
success or wait |
967573603 |
Directory Information Queried |
Path: C:\WINDOWS\system32Disposition: BothDirectoryInformation Filemask: svchost.exe
Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1d29ee4
|
success or wait |
967681917 |
Section loaded |
Path: C:\WINDOWS\system32\svchost.exe Access: query and read Type: commit Baseaddress:
2680000 Size: 16384 Protection: readonly Mapped to pid: own pid
|
success or wait |
967793011 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Name: Cache
|
buffer overflow |
967908116 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Name: Cache
|
success or wait |
968016108 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Name: LogFileName
|
object name not found |
968134106 |
System info queried |
Type: WatchdogTimerHandler |
success or wait |
968244149 |
Process created |
PID: 1744 Path: C:\WINDOWS\system32\svchost.exe Cmdline: svchost.exe Createflags:
none
|
success or wait |
968352187 |
Process information queried |
PID: 1744 Info Class: BasicInformation |
success or wait |
968354960 |
Memory read |
PID: 1744 Path: C:\WINDOWS\system32\svchost.exe Base: 7FFDC008 Length: 4 Value: 00
00 00 01
|
success or wait |
968355579 |
File opened |
Path: C:\WINDOWS\system32\svchost.exe.Manifest Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
968464467 |
Memory read |
PID: 1744 Path: C:\WINDOWS\system32\svchost.exe Base: 1000000 Length: 4096 Value:
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 E0 00 00 00 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 70
72 6F 67 72 61 6D 20 63 61 6E 6E 6F 74 20 62 65 20 72 75 6E 20 69 6E 20 44 4F 53 20
6D 6F 64 65 2E 0D 0D 0A 24 00 00 00 00 00 00 00 FC A9 F5 66 B8 C8 9B 35 B8 C8 9B 35
B8 C8 9B 35 7B C7 FB 35 B9 C8 9B 35 7B C7 C6 35 B1 C8 9B 35 B8 C8 9A 35 E7 C8 9B 35
7B C7 C5 35 B9 C8 9B 35 7B C7 C4 35 B4 C8 9B 35 7B C7 C1 35 B9 C8 9B 35 52 69 63 68
B8 C8 9B 35 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
50 45 00 00 4C 01 03 00 C0 5B 02 48 00 00 00 00 00 00 00 00 E0 00 0F 01 0B 01 07 0A
00 2C 00
|
success or wait |
968465095 |
Memory read |
PID: 1744 Path: C:\WINDOWS\system32\svchost.exe Base: 1005000 Length: 256 Value: 00
00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 10 00 00 00 18 00 00 80 00 00 00 00 00
00 00 00 00 00 00 00 00 00 01 00 01 00 00 00 30 00 00 80 00 00 00 00 00 00 00 00 00
00 00 00 00 00 01 00 09 04 00 00 48 00 00 00 60 50 00 00 A8 03 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 A8 03 34 00 00 00 56 00 53 00 5F 00 56 00 45 00 52
00 53 00 49 00 4F 00 4E 00 5F 00 49 00 4E 00 46 00 4F 00 00 00 00 00 BD 04 EF FE 00
00 01 00 01 00 05 00 88 15 28 0A 01 00 05 00 88 15 28 0A 3F 00 00 00 00 00 00 00 04
00 04 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 03 00 00 01 00 53 00 74
00 72 00 69 00 6E 00 67 00 46 00 69 00 6C 00 65 00 49 00 6E 00 66 00 6F 00 00 00 E4
02 00 00 01 00 30 00 34 00 30 00 39 00 30 00 34 00 42 00 30 00 00 00 4C 00 16 00 01
00 43
|
success or wait |
968577156 |
Process information queried |
PID: 1744 Info Class: BasicInformation |
success or wait |
968691220 |
Memory allocated |
PID: 1744 Path: C:\WINDOWS\system32\svchost.exe Base: 10000 Length: 12CD64 Allocation
Type: unknown Protection: page read and write
|
success or wait |
968803521 |
Memory written |
PID: 1744 Path: C:\WINDOWS\system32\svchost.exe Base: 10000 Length: 2026 Value: 3D
00 3A 00 3A 00 3D 00 3A 00 3A 00 5C 00 00 00 3D 00 5A 00 3A 00 3D 00 5A 00 3A 00 5C
00 00 00 41 00 4C 00 4C 00 55 00 53 00 45 00 52 00 53 00 50 00 52 00 4F 00 46 00 49
00 4C 00 45 00 3D 00 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74
00 73 00 20 00 61 00 6E 00 64 00 20 00 53 00 65 00 74 00 74 00 69 00 6E 00 67 00 73
00 5C 00 41 00 6C 00 6C 00 20 00 55 00 73 00 65 00 72 00 73 00 00 00 41 00 50 00 50
00 44 00 41 00 54 00 41 00 3D 00 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65
00 6E 00 74 00 73 00 20 00 61 00 6E 00 64 00 20 00 53 00 65 00 74 00 74 00 69 00 6E
00 67 00 73 00 5C 00 41 00 64 00 6D 00 69 00 6E 00 69 00 73 00 74 00 72 00 61 00 74
00 6F 00 72 00 5C 00 41 00 70 00 70 00 6C 00 69 00 63 00 61 00 74 00 69 00 6F 00 6E
00 20
|
success or wait |
968806566 |
Memory allocated |
PID: 1744 Path: C:\WINDOWS\system32\svchost.exe Base: 20000 Length: 12CD64 Allocation
Type: unknown Protection: page read and write
|
success or wait |
968914554 |
Memory written |
PID: 1744 Path: C:\WINDOWS\system32\svchost.exe Base: 20000 Length: 1620 Value: 00
10 00 00 54 06 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 28 00 08 02 90 02 00 00 00 00 00 00 FC 00 FE 00 98 04 00 00 3E
00 40 00 98 05 00 00 16 00 18 00 D8 05 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 3E
00 40 00 F0 05 00 00 1E 00 20 00 30 06 00 00 00 00 02 00 50 06 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00
|
success or wait |
968916803 |
Memory written |
PID: 1744 Path: C:\WINDOWS\system32\svchost.exe Base: 7FFDC010 Length: 4 Value: 00
00 02 00
|
success or wait |
968917928 |
Memory allocated |
PID: 1744 Path: C:\WINDOWS\system32\svchost.exe Base: 30000 Length: 12CD64 Allocation
Type: unknown Protection: page read and write
|
success or wait |
969022840 |
Memory written |
PID: 1744 Path: C:\WINDOWS\system32\svchost.exe Base: 30000 Length: 388 Value: 53
00 68 00 69 00 6D 00 45 00 6E 00 67 00 2E 00 64 00 6C 00 6C 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 84 01 00 00 AB ED 0D AC 26 04 07 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 11 11 11 11 11 11 11 11 11
11 11 11 11 11 11 11 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00
|
success or wait |
969023672 |
Memory written |
PID: 1744 Path: C:\WINDOWS\system32\svchost.exe Base: 7FFDC1E8 Length: 4 Value: 00
00 03 00
|
success or wait |
969023890 |
Memory allocated |
PID: 1744 Path: C:\WINDOWS\system32\svchost.exe Base: 40000 Length: 12CFD0 Allocation
Type: unknown Protection: page read and write
|
success or wait |
969137849 |
Memory allocated |
PID: 1744 Path: C:\WINDOWS\system32\svchost.exe Base: 7B000 Length: 12CFCC Allocation
Type: unknown Protection: page read and write
|
success or wait |
969138193 |
Memory attributes changed |
PID: 1744 Path: C:\WINDOWS\system32\svchost.exe Base: 7B000 Length: 1000 New Protection:
page read and write and page guard Old Protection: page read and write
|
success or wait |
969138512 |
Thread created |
PID: 1744 TID: 1076 EIP: 7C810705 EAX: 1002509 Imagepath: C:\WINDOWS\system32\svchost.exe |
success or wait |
969248625 |
Message posted |
TID: 6C4 Message: C0D3 WParam: 0 LParam: 960 |
success |
976965594 |
Thread terminated |
TID: 960 PID: 1680 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE |
unknown |
976966092 |
Thread apc queued |
TID: 1076 PID: 1744 Imagepath: C:\WINDOWS\system32\svchost.exe Injected: true |
success or wait |
978196064 |
Thread apc queued |
TID: 1076 PID: 1744 Imagepath: C:\WINDOWS\system32\svchost.exe Injected: true |
success or wait |
978197418 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\72.tmp Access: read attributes and synchronize
and generic read Options: sequential only and synchronous io non alert and non directory
file and open reparse point Attributes: none Content Overwritten: true
|
success or wait |
978199532 |
File created |
Path: C:\WINDOWS\system32\hyli.igo Access: read attributes and delete and synchronize
and generic write Options: sequential only and synchronous io non alert and non directory
file Attributes: archive Content Overwritten: true
|
success or wait |
978200749 |
File other op |
Path: C:\WINDOWS\system32\hyli.igo New path: Disposition: EndOfFileInformation
Data : unknown
|
success or wait |
978315111 |
Section loaded |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\72.tmp Access: query and write and read and
execute and extend size Type: commit Baseaddress: 10E0000 Size: 24576 Protection:
readonly Mapped to pid: own pid
|
success or wait |
978316506 |
File write |
Path: C:\WINDOWS\system32\hyli.igo Offset: unknown Length: 21504 Value: 4D 5A 90 00
03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
80 00 00 00 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 70 72 6F 67 72
61 6D 20 63 61 6E 6E 6F 74 20 62 65
|
success or wait |
978435282 |
File other op |
Path: C:\WINDOWS\system32\hyli.igo New path: Disposition: BasicInformation Data
: Creation Time: 01:00 01-01-1601 Last Access Time: 01:00 01-01-1601 Last Write Time:
09:39 24-01-2012 Change Time: 09:39 24-01-2012 File Attributes: none
|
success or wait |
978436086 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Name:
Shell
|
success or wait |
978646908 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Name:
Shell
|
success or wait |
978647134 |
Key value replaced with new |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Name:
Shell Type: unicode Data: Explorer.exe rundll32.exe hyli.igo atkhnt Old data: Explorer.exe
|
success or wait |
978762882 |
Message posted |
HWND: 11013E Message: 400 WParam: 47806 LParam: 2000556 |
success |
978990594 |
Message posted |
HWND: E0154 Message: 45A WParam: 2 LParam: 0 |
success |
979762342 |
Message posted |
HWND: E0154 Message: C159 WParam: 0 LParam: 0 |
success |
981719649 |
Window destroyed |
HWND: 1D00E6 |
success |
981835043 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 201D6, 1D00FA, 1700B0, 1A012E,
190112, 1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 201D4, 201CC, 201D0
|
success or wait |
981835329 |
Window destroyed |
HWND: D011C |
success |
981835949 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 201D6, 1D00FA, 1700B0, 1A012E,
190112, 1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 201D4, 201CC, 201D0
|
success or wait |
981836193 |
Window destroyed |
HWND: 13010C |
success |
981943136 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 201D6, 1D00FA, 1700B0, 1A012E,
190112, 1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 201D4, 201CC, 201D0
|
success or wait |
982056110 |
Window destroyed |
HWND: 1F0150 |
success |
982056917 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 201D6, 1D00FA, 1700B0, 1A012E,
190112, 1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 201D4, 201CC, 201D0
|
success or wait |
982057223 |
Window destroyed |
HWND: 1800FE |
success |
982058179 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 201D6, 1D00FA, 1700B0, 1A012E,
190112, 1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 201D4, 201CC, 201D0
|
success or wait |
982058445 |
Window destroyed |
HWND: 1C014C |
success |
982166789 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 201D6, 1D00FA, 1700B0, 1A012E,
190112, 1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 201D4, 201CC, 201D0
|
success or wait |
982279217 |
Window destroyed |
HWND: 180142 |
success |
982397263 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 201D6, 1D00FA, 1700B0, 1A012E,
190112, 1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 201D4, 201CC, 201D0
|
success or wait |
982504597 |
Window destroyed |
HWND: 1E010E |
success |
982506880 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 201D6, 1D00FA, 1700B0, 1A012E,
190112, 1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 201D4, 201CC, 201D0
|
success or wait |
982508065 |
Window destroyed |
HWND: 1A011A |
success |
982509631 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 201D6, 1D00FA, 1700B0, 1A012E,
190112, 1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 201D4, 201CC, 201D0
|
success or wait |
982510122 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Common Name: QMEnable |
object name not found |
982614388 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Common Name: QMEnable |
object name not found |
982727744 |
Window shown |
HWND: 201D8 CMD: hide |
success |
982728945 |
Window shown |
HWND: 201D2 CMD: hide |
success |
982731283 |
Window shown |
HWND: 201CA CMD: hide |
success |
982731838 |
Window placement got |
HWND: 201D8 CMD: show normal |
success |
982841865 |
Window shown |
HWND: 201D0 CMD: hide |
error |
983064284 |
Window shown |
HWND: 201CC CMD: hide |
error |
983286295 |
Window destroyed |
HWND: 201D8 |
success |
983396894 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 201D6, 1D00FA, 1700B0, 1A012E,
190112, 1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 201D4, 201CC, 201D0
|
success or wait |
983514192 |
Window destroyed |
HWND: 201C2 |
success |
983514499 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 201D6, 1D00FA, 1700B0, 1A012E,
190112, 1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 201D4, 201CC, 201D0
|
success or wait |
983514635 |
Window destroyed |
HWND: 201D6 |
success |
983514920 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 201D6, 1D00FA, 1700B0, 1A012E,
190112, 1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 201D4, 201CC, 201D0
|
success or wait |
983515055 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 201D6, 1D00FA, 1700B0, 1A012E,
190112, 1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 201D4, 201CC, 201D0
|
success or wait |
983515329 |
Window destroyed |
HWND: 201D2 |
success |
983733343 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 1D00FA, 1700B0, 1A012E,
190112, 1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 201D4, 201CC, 201D0, 6023E
|
success or wait |
983733723 |
Window destroyed |
HWND: 201D0 |
success |
983734426 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 1D00FA, 1700B0, 1A012E,
190112, 1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 201D4, 201CC, 201D0, 6023E
|
success or wait |
983734754 |
Window destroyed |
HWND: 201CA |
success |
983735702 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 1D00FA, 1700B0, 1A012E,
190112, 1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 201D4, 201CC, 6023E, 6023C
|
success or wait |
983735901 |
Window destroyed |
HWND: 201CC |
success |
983956387 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 1D00FA, 1700B0, 1A012E,
190112, 1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 201D4, 201CC, 6023E, 6023C
|
success or wait |
983956493 |
Window destroyed |
HWND: 201D4 |
success |
983956754 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 1D00FA, 1700B0, 1A012E,
190112, 1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 201D4, 6023E, 6023C, 1400E8
|
success or wait |
983956822 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 1D00FA, 1700B0, 1A012E,
190112, 1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 201D4, 6023E, 6023C, 1400E8
|
success or wait |
983956980 |
Window shown |
HWND: 201EC CMD: hide |
error |
984295320 |
Window shown |
HWND: 201EE CMD: hide |
error |
984407319 |
Window shown |
HWND: 201EC CMD: hide |
error |
984408982 |
Window shown |
HWND: 201EE CMD: hide |
error |
984409295 |
Message sent |
HWND: 1A012E Message: CANCELMODE WParam: 0 LParam: 0 |
error |
984630739 |
Message sent |
HWND: 1A012E Message: CANCELMODE WParam: 0 LParam: 0 |
error |
984964717 |
Window destroyed |
HWND: 2200B6 |
success |
985079912 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 1D00FA, 1700B0, 1A012E,
190112, 1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 6023E, 6023C, 1400E8, 140140
|
success or wait |
985080136 |
Message posted |
HWND: E0154 Message: CLOSE WParam: 17 LParam: 0 |
success |
985081232 |
Window shown |
HWND: 201EC CMD: hide |
error |
985186626 |
Window shown |
HWND: 201EE CMD: hide |
error |
985299360 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Data Name: Toolbars |
buffer overflow |
985303364 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Data Name: Toolbars |
buffer overflow |
985411160 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Data Name: Toolbars |
success or wait |
985524373 |
Key value replaced with new |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Data Name: Toolbars Type: binary
Data: 49 00 00 00 6B 01 00 00 39 00 00 00 02 01 FF FF 09 00 00 00 00 00 00 00 00 00
12 00 00 01 01 01 01 00 00 FA FF 00 00 FD FF 1E 00 6F 00 5C 01 6F 00 01 00 01 01 00
00 FA FF 00 00 FD FF 1E 00 6F 00 5C 01 6F 00 01 00 01 01 00 00 FA FF 00 00 FD FF 1E
00 6F 00 5C 01 6F 00 01 00 01 01 00 00 FA FF 00 00 FD FF 1E 00 6F 00 5C 01 6F 00 01
00 01 01 00 00 FA FF 00 00 FD FF 1E 00 6F 00 5C 01 6F 00 00 00 00 00 00 00 03 30 02
01 FF FF 0A 00 00 00 00 00 00 00 00 00 12 00 00 01 01 01 01 92 01 F9 FF 20 03 FD FF
1E 00 6F 00 5C 01 6F 00 01 00 01 01 92 01 F9 FF 20 03 FD FF 1E 00 6F 00 5C 01 6F 00
01 00 01 01 92 01 F9 FF 20 03 FD FF 1E 00 6F 00 5C 01 6F 00 01 00 01 01 92 01 F9 FF
20 03 FD FF 1E 00 6F 00 5C 01 6F 00 01 00 01 01 92 01 F9 FF 20 03 FD FF 1E 00 6F 00
5C 01 6F 00 01 00 00 00 00 00 03 30 02 01 FF FF EE 01 00 00 00 00 00 00 00 00 12 00
00 04 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 73 01 6F 00 04 00 01 FE 00 00 00
00 00 00 00 00 1E 00 6F 00 73 01 6F 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F
00 73 01 6F 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 73 01 6F 00 04 00 01
FE 00 00 00 00 00 00 00 00 1E 00 6F 00 73 01 6F 00 02 00 00 00 01 00 03 30 02 01 FF
FF 0C 00 00 00 00 00 00 00 00 00 12 00 00 01 02 01 FE 00 00 00 00 00 00 00 00 1E 00
6F 00 5F 00 6F 00 01 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5F 00 6F 00 01 02
01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5F 00 6F 00 01 02 01 FE 00 00 00 00 00 00
00 00 1E 00 6F 00 5F 00 6F 00 01 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5F 00
6F 00 03 00 00 00 01 00 03 30 02 01 FF FF 0D 00 00 00 00 00 00 00 00 00 12 00 00 03
02 03 FE 00 00 00 00 00 00 00 00 1E 00 D8 01 E3 02 D8 01 03 02 03 FE 00 00 00 00 00
00 00 00 1E 00 D8 01 E3 02 D8 01 03 02 03 FE 00 00 00 00 00 00 00 00 1E 00 D8 01 E3
02 D8 01 03 02 03 FE 00 00 00 00 00 00 00 00 1E 00 D8 01 E3 02 D8 01 03 02 03 FE 00
00 00 00 00 00 00 00 1E 00 D8 01 E3 02 D8 01 04 00 00 00 01 00 03 30 02 01 FF FF 0F
00 00 00 00 00 00 00 00 00 12 00 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00
5C 01 6F 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 04 00 01 FE
00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 04 00 01 FE 00 00 00 00 00 00 00 00
1E 00 6F 00 5C 01 6F 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00
05 00 00 00 01 00 03 30 02 01 FF FF 0E 00 00 00 08 01 00 00 00 00 12 00 00 04 00 01
FE 00 00 00 00 00 00 00 00 C4 01 D8 01 02 03 D8 01 04 00 01 FE 00 00 00 00 00 00 00
00 C4 01 D8 01 02 03 D8 01 04 01 01 FE 00 00 00 00 00 00 00 00 C4 01 D8 01 02 03 D8
01 04 01 01 FE 00 00 00 00 00 00 00 00 C4 01 D8 01 02 03 D8 01 04 01 01 FE 00 00 00
00 00 00 00 00 C4 01 D8 01 02 03 D8 01 06 00 00 00 01 00 03 30 02 01 FF FF 10 00 00
00 00 00 00 00 00 00 12 00 00 04 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01
6F 00 04 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 04 02 01 FE 00 00
00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 04 02 01 FE 00 00 00 00 00 00 00 00 1E 00
6F 00 5C 01 6F 00 04 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 07 00
00 00 01 00 03 30 02 01 FF FF 64 00 00 00 00 00 00 00 00 00 12 00 00 04 00 01 FE 00
00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E
00 6F 00 5C 01 6F 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 04
00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 04 00 01 FE 00 00 00 00 00
00 00 00 1E 00 6F 00 5C 01 6F 00 08 00 00 00 01 00 03 30 02 01 FF FF 65 00 00 00 00
00 00 00 00 00 12 00 00 04 02 01 FE 00 00 00 00 00 00 00 00 1E 00 A1 00 5C 01 A1 00
04 02 01 FE 00 00 00 00 00 00 00 00 1E 00 A1 00 5C 01 A1 00 04 02 01 FE 00 00 00 00
00 00 00 00 1E 00 A1 00 5C 01 A1 00 04 02 01 FE 00 00 00 00 00 00 00 00 1E 00 A1 00
5C 01 A1 00 04 02 01 FE 00 00 00 00 00 00 00 00 1E 00 A1 00 5C 01 A1 00 09 00 00 00
01 00 03 30 02 01 FF FF 13 00 00 00 00 00 00 00 00 00 12 00 00 01 02 01 FE 00 00 00
00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F
00 5C 01 6F 00 01 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 02 01
FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 02 01 FE 00 00 00 00 00 00 00
00 1E 00 6F 00 5C 01 6F 00 0A 00 00 00 01 00 03 30 02 01 FF FF 16 00 00 00 00 00 00
00 00 00 12 00 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 00
01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00 00 00 00 00 00
00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01
6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 0B 00 00 00 01 00
03 30 02 01 FF FF 15 00 00 00 00 01 00 00 00 00 12 00 00 04 00 01 FE 00 00 00 00 00
00 00 00 1E 00 6F 00 5C 01 6F 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C
01 6F 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 04 00 01 FE 00
00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E
00 6F 00 5C 01 6F 00 0C 00 00 00 01 00 03 30 02 01 FF FF 1F 00 00 00 08 01 00 00 00
00 12 00 00 04 02 01 FE 00 00 00 00 00 00 00 00 2D 00 27 01 F2 02 27 01 04 02 01 FE
00 00 00 00 00 00 00 00 2D 00 27 01 F2 02 27 01 04 02 01 FE 00 00 00 00 00 00 00 00
2D 00 27 01 F2 02 27 01 04 02 01 FE 00 00 00 00 00 00 00 00 2D 00 27 01 F2 02 27 01
04 02 01 FE 00 00 00 00 00 00 00 00 2D 00 27 01 F2 02 27 01 0D 00 00 00 01 00 03 30
02 01 FF FF 17 00 00 00 00 00 00 00 00 00 12 00 00 01 00 01 FE 00 00 00 00 00 00 00
00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F
00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00 00 00
00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F
00 5C 01 6F 00 0E 00 00 00 01 00 03 30 02 01 FF FF 18 00 00 00 00 00 00 00 00 00 12
00 00 01 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 01 01 FE 00 00
00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 02 01 FE 00 00 00 00 00 00 00 00 1E 00
6F 00 5C 01 6F 00 01 01 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 02
01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 0F 00 00 00 01 00 03 30 02 01
FF FF 1A 00 00 00 00 00 00 00 00 00 12 00 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E
00 6F 00 5C 01 6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01
00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00 00 00 00 00
00 00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C
01 6F 00 10 00 00 00 01 00 03 30 02 01 FF FF 23 00 00 00 00 00 00 00 00 00 12 00 00
01 02 01 01 00 00 FB FF 00 00 FD FF 1E 00 6F 00 5C 01 6F 00 01 02 01 01 00 00 00 00
00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 02 01 01 00 00 00 00 00 00 00 00 1E 00 6F 00
5C 01 6F 00 01 02 01 01 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 02 01 01
00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 14 00 00 00 01 00 03 30 02 01 FF FF
24 00 00 00 00 00 00 00 00 00 12 00 00 01 02 01 01 00 00 FC FF 00 00 FD FF 1E 00 6F
00 5C 01 6F 00 01 02 01 01 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 02 01
01 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 02 01 01 00 00 00 00 00 00 00
00 1E 00 6F 00 5C 01 6F 00 01 02 01 01 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F
00 15 00 00 00 01 00 03 30 02 01 FF FF 18 02 00 00 00 01 00 00 00 00 12 00 00 01 00
01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00 00 00 00 00 00
00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01
6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00 00
00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 16 00 00 00 01 00 03 30 02 01 FF FF 84 00
00 00 00 00 00 00 00 00 12 00 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C
01 6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00
00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E
00 6F 00 5C 01 6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 1A
00 00 00 01 00 03 30 02 01 FF FF BD 00 00 00 00 00 00 00 00 00 12 00 00 01 02 01 FE
00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 02 01 FE 00 00 00 00 00 00 00 00
1E 00 6F 00 5C 01 6F 00 01 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00
01 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 01 01 FE 00 00 00 00
00 00 00 00 1E 00 6F 00 5C 01 6F 00 1B 00 00 00 01 00 03 30 02 01 FF FF 8B 00 00 00
00 00 00 00 00 00 12 00 00 04 02 03 FE 00 00 00 00 00 00 00 00 82 00 CE 01 61 02 CE
01 04 02 03 FE 00 00 00 00 00 00 00 00 82 00 CE 01 61 02 CE 01 04 02 03 FE 00 00 00
00 00 00 00 00 82 00 CE 01 61 02 CE 01 04 02 03 FE 00 00 00 00 00 00 00 00 82 00 CE
01 61 02 CE 01 04 02 03 FE 00 00 00 00 00 00 00 00 82 00 CE 01 61 02 CE 01 1C 00 00
00 01 00 03 30 02 01 FF FF A9 00 00 00 00 01 00 00 00 00 12 00 00 04 00 03 FE 00 00
00 00 00 00 00 00 72 01 CE 01 B0 02 CE 01 04 00 03 FE 00 00 00 00 00 00 00 00 72 01
CE 01 B0 02 CE 01 04 00 03 FE 00 00 00 00 00 00 00 00 72 01 CE 01 B0 02 CE 01 04 00
03 FE 00 00 00 00 00 00 00 00 72 01 CE 01 B0 02 CE 01 04 00 03 FE 00 00 00 00 00 00
00 00 72 01 CE 01 B0 02 CE 01 1D 00 00 00 01 00 03 30 02 01 FF FF A7 00 00 00 00 01
00 00 00 00 12 00 00 04 00 03 FE 00 00 00 00 00 00 00 00 72 01 92 01 B0 02 92 01 04
00 03 FE 00 00 00 00 00 00 00 00 72 01 92 01 B0 02 92 01 04 00 03 FE 00 00 00 00 00
00 00 00 72 01 92 01 B0 02 92 01 04 00 03 FE 00 00 00 00 00 00 00 00 72 01 92 01 B0
02 92 01 04 00 03 FE 00 00 00 00 00 00 00 00 72 01 92 01 B0 02 92 01 1E 00 00 00 01
00 03 30 02 01 FF FF 8C 00 00 00 00 00 00 00 00 00 12 00 00 04 02 03 FE 00 00 00 00
00 00 00 00 96 01 6F 00 02 03 6F 00 04 02 03 FE 00 00 00 00 00 00 00 00 96 01 6F 00
02 03 6F 00 04 02 03 FE 00 00 00 00 00 00 00 00 96 01 6F 00 02 03 6F 00 04 02 03 FE
00 00 00 00 00 00 00 00 96 01 6F 00 02 03 6F 00 04 02 03 FE 00 00 00 00 00 00 00 00
96 01 6F 00 02 03 6F 00 1F 00 00 00 01 00 03 30 02 01 FF FF 9F 05 00 00 00 01 00 00
00 00 12 00 00 04 02 03 FE 00 00 00 00 00 00 00 00 C4 01 AB 00 02 03 AB 00 04 02 03
FE 00 00 00 00 00 00 00 00 C4 01 AB 00 02 03 AB 00 04 02 03 FE 00 00 00 00 00 00 00
00 C4 01 AB 00 02 03 AB 00 04 02 03 FE 00 00 00 00 00 00 00 00 C4 01 AB 00 02 03 AB
00 04 02 03 FE 00 00 00 00 00 00 00 00 C4 01 AB 00 02 03 AB 00 20 00 00 00 01 00 03
30 02 01 FF FF 8E 05 00 00 00 01 00 00 00 00 12 00 00 04 02 03 FE 00 00 00 00 00 00
00 00 D5 00 AB 00 58 02 AB 00 04 02 03 FE 00 00 00 00 00 00 00 00 D5 00 AB 00 58 02
AB 00 04 02 03 FE 00 00 00 00 00 00 00 00 D5 00 AB 00 58 02 AB 00 04 02 03 FE 00 00
00 00 00 00 00 00 D5 00 AB 00 58 02 AB 00 04 02 03 FE 00 00 00 00 00 00 00 00 D5 00
AB 00 58 02 AB 00 21 00 00 00 01 00 03 30 02 01 FF FF 9B 05 00 00 00 01 00 00 00 00
12 00 00 04 02 03 FE 00 00 00 00 00 00 00 00 7F 01 AB 00 02 03 AB 00 04 02 03 FE 00
00 00 00 00 00 00 00 7F 01 AB 00 02 03 AB 00 04 02 03 FE 00 00 00 00 00 00 00 00 7F
01 AB 00 02 03 AB 00 04 02 03 FE 00 00 00 00 00 00 00 00 7F 01 AB 00 02 03 AB 00 04
02 03 FE 00 00 00 00 00 00 00 00 7F 01 AB 00 02 03 AB 00 22 00 00 00 01 00 03 30 02
01 FF FF 8E 00 00 00 00 00 00 00 00 00 12 00 00 01 02 01 FE 00 00 00 00 00 00 00 00
1E 00 6F 00 FD 01 6F 00 01 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 FD 01 6F 00
01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 FD 01 6F 00 01 02 01 FE 00 00 00 00
00 00 00 00 1E 00 6F 00 FD 01 6F 00 01 01 01 01 2C 01 00 00 E8 02 1A 00 1E 00 6F 00
FD 01 6F 00 23 00 00 00 01 00 03 30 02 01 FF FF 19 02 00 00 08 01 00 00 00 00 12 00
00 04 02 01 FE 00 00 00 00 00 00 00 00 09 02 6F 00 02 03 6F 00 04 02 01 FE 00 00 00
00 00 00 00 00 09 02 6F 00 02 03 6F 00 04 02 01 FE 00 00 00 00 00 00 00 00 09 02 6F
00 02 03 6F 00 04 02 01 FE 00 00 00 00 00 00 00 00 09 02 6F 00 02 03 6F 00 04 02 01
FE 00 00 00 00 00 00 00 00 09 02 6F 00 02 03 6F 00 24 00 00 00 01 00 03 30 02 01 FF
FF F6 01 00 00 00 01 00 00 00 00 12 00 00 04 02 01 FE 00 00 00 00 00 00 00 00 AA 02
D8 01 02 03 D8 01 04 02 01 FE 00 00 00 00 00 00 00 00 AA 02 D8 01 02 03 D8 01 04 02
01 FE 00 00 00 00 00 00 00 00 AA 02 D8 01 02 03 D8 01 04 02 01 FE 00 00 00 00 00 00
00 00 AA 02 D8 01 02 03 D8 01 04 02 01 FE 00 00 00 00 00 00 00 00 AA 02 D8 01 02 03
D8 01 25 00 00 00 01 00 03 30 02 01 FF FF F4 00 00 00 00 00 00 00 00 00 12 00 00 04
00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5F 00 6F 00 04 00 01 FE 00 00 00 00 00
00 00 00 1E 00 6F 00 5F 00 6F 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5F
00 6F 00 04 00 01 FE 00 00 00 Old data: 49 00 00 00 6B 01 00 00 39 00 00 00 02 01
FF FF 09 00 00 00 00 00 00 00 00 00 12 00 00 01 01 01 01 00 00 FA FF 00 00 FD FF 1E
00 6F 00 5C 01 6F 00 01 00 01 01 00 00 18 00 F2 02 32 00 1E 00 6F 00 5C 01 6F 00 01
00 01 01 00 00 18 00 F2 02 32 00 1E 00 6F 00 5C 01 6F 00 01 00 01 01 00 00 18 00 F2
02 32 00 1E 00 6F 00 5C 01 6F 00 01 00 01 01 00 00 18 00 F2 02 32 00 1E 00 6F 00 5C
01 6F 00 00 00 00 00 00 00 03 30 02 01 FF FF 0A 00 00 00 00 00 00 00 00 00 12 00 00
01 01 01 01 92 01 F9 FF 20 03 FD FF 1E 00 6F 00 5C 01 6F 00 01 00 01 01 92 01 18 00
50 04 32 00 1E 00 6F 00 5C 01 6F 00 01 00 01 01 92 01 18 00 50 04 32 00 1E 00 6F 00
5C 01 6F 00 01 00 01 01 92 01 18 00 50 04 32 00 1E 00 6F 00 5C 01 6F 00 01 00 01 01
92 01 18 00 50 04 32 00 1E 00 6F 00 5C 01 6F 00 01 00 00 00 00 00 03 30 02 01 FF FF
EE 01 00 00 00 00 00 00 00 00 12 00 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F
00 73 01 6F 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 73 01 6F 00 04 00 01
FE 00 00 00 00 00 00 00 00 1E 00 6F 00 73 01 6F 00 04 00 01 FE 00 00 00 00 00 00 00
00 1E 00 6F 00 73 01 6F 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 73 01 6F
00 02 00 00 00 01 00 03 30 02 01 FF FF 0C 00 00 00 00 00 00 00 00 00 12 00 00 01 02
01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5F 00 6F 00 01 02 01 FE 00 00 00 00 00 00
00 00 1E 00 6F 00 5F 00 6F 00 01 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5F 00
6F 00 01 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5F 00 6F 00 01 02 01 FE 00 00
00 00 00 00 00 00 1E 00 6F 00 5F 00 6F 00 03 00 00 00 01 00 03 30 02 01 FF FF 0D 00
00 00 00 00 00 00 00 00 12 00 00 03 02 03 FE 00 00 00 00 00 00 00 00 1E 00 D8 01 E3
02 D8 01 03 02 03 FE 00 00 00 00 00 00 00 00 1E 00 D8 01 E3 02 D8 01 03 02 03 FE 00
00 00 00 00 00 00 00 1E 00 D8 01 E3 02 D8 01 03 02 03 FE 00 00 00 00 00 00 00 00 1E
00 D8 01 E3 02 D8 01 03 02 03 FE 00 00 00 00 00 00 00 00 1E 00 D8 01 E3 02 D8 01 04
00 00 00 01 00 03 30 02 01 FF FF 0F 00 00 00 00 00 00 00 00 00 12 00 00 04 00 01 FE
00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 04 00 01 FE 00 00 00 00 00 00 00 00
1E 00 6F 00 5C 01 6F 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00
04 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 04 00 01 FE 00 00 00 00
00 00 00 00 1E 00 6F 00 5C 01 6F 00 05 00 00 00 01 00 03 30 02 01 FF FF 0E 00 00 00
08 01 00 00 00 00 12 00 00 04 00 01 FE 00 00 00 00 00 00 00 00 C4 01 D8 01 02 03 D8
01 04 00 01 FE 00 00 00 00 00 00 00 00 C4 01 D8 01 02 03 D8 01 04 01 01 FE 00 00 00
00 00 00 00 00 C4 01 D8 01 02 03 D8 01 04 01 01 FE 00 00 00 00 00 00 00 00 C4 01 D8
01 02 03 D8 01 04 01 01 FE 00 00 00 00 00 00 00 00 C4 01 D8 01 02 03 D8 01 06 00 00
00 01 00 03 30 02 01 FF FF 10 00 00 00 00 00 00 00 00 00 12 00 00 04 02 01 FE 00 00
00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 04 02 01 FE 00 00 00 00 00 00 00 00 1E 00
6F 00 5C 01 6F 00 04 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 04 02
01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 04 02 01 FE 00 00 00 00 00 00
00 00 1E 00 6F 00 5C 01 6F 00 07 00 00 00 01 00 03 30 02 01 FF FF 64 00 00 00 00 00
00 00 00 00 12 00 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 04
00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 04 00 01 FE 00 00 00 00 00
00 00 00 1E 00 6F 00 5C 01 6F 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C
01 6F 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 08 00 00 00 01
00 03 30 02 01 FF FF 65 00 00 00 00 00 00 00 00 00 12 00 00 04 02 01 FE 00 00 00 00
00 00 00 00 1E 00 A1 00 5C 01 A1 00 04 02 01 FE 00 00 00 00 00 00 00 00 1E 00 A1 00
5C 01 A1 00 04 02 01 FE 00 00 00 00 00 00 00 00 1E 00 A1 00 5C 01 A1 00 04 02 01 FE
00 00 00 00 00 00 00 00 1E 00 A1 00 5C 01 A1 00 04 02 01 FE 00 00 00 00 00 00 00 00
1E 00 A1 00 5C 01 A1 00 09 00 00 00 01 00 03 30 02 01 FF FF 13 00 00 00 00 00 00 00
00 00 12 00 00 01 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 02 01
FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 02 01 FE 00 00 00 00 00 00 00
00 1E 00 6F 00 5C 01 6F 00 01 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F
00 01 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 0A 00 00 00 01 00 03
30 02 01 FF FF 16 00 00 00 00 00 00 00 00 00 12 00 00 01 00 01 FE 00 00 00 00 00 00
00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01
6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00 00
00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00
6F 00 5C 01 6F 00 0B 00 00 00 01 00 03 30 02 01 FF FF 15 00 00 00 00 01 00 00 00 00
12 00 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 04 00 01 FE 00
00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E
00 6F 00 5C 01 6F 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 04
00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 0C 00 00 00 01 00 03 30 02
01 FF FF 1F 00 00 00 08 01 00 00 00 00 12 00 00 04 02 01 FE 00 00 00 00 00 00 00 00
2D 00 27 01 F2 02 27 01 04 02 01 FE 00 00 00 00 00 00 00 00 2D 00 27 01 F2 02 27 01
04 02 01 FE 00 00 00 00 00 00 00 00 2D 00 27 01 F2 02 27 01 04 02 01 FE 00 00 00 00
00 00 00 00 2D 00 27 01 F2 02 27 01 04 02 01 FE 00 00 00 00 00 00 00 00 2D 00 27 01
F2 02 27 01 0D 00 00 00 01 00 03 30 02 01 FF FF 17 00 00 00 00 00 00 00 00 00 12 00
00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00 00 00
00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F
00 5C 01 6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 00 01
FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 0E 00 00 00 01 00 03 30 02 01 FF
FF 18 00 00 00 00 00 00 00 00 00 12 00 00 01 02 01 FE 00 00 00 00 00 00 00 00 1E 00
6F 00 5C 01 6F 00 01 01 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 02
01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 01 01 FE 00 00 00 00 00 00
00 00 1E 00 6F 00 5C 01 6F 00 01 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01
6F 00 0F 00 00 00 01 00 03 30 02 01 FF FF 1A 00 00 00 00 00 00 00 00 00 12 00 00 01
00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00 00 00 00 00
00 00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C
01 6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00
00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 10 00 00 00 01 00 03 30 02 01 FF FF 23
00 00 00 00 00 00 00 00 00 12 00 00 01 02 01 01 00 00 FB FF 00 00 FD FF 1E 00 6F 00
5C 01 6F 00 01 02 01 01 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 02 01 01
00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 02 01 01 00 00 00 00 00 00 00 00
1E 00 6F 00 5C 01 6F 00 01 02 01 01 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00
14 00 00 00 01 00 03 30 02 01 FF FF 24 00 00 00 00 00 00 00 00 00 12 00 00 01 02 01
01 00 00 FC FF 00 00 FD FF 1E 00 6F 00 5C 01 6F 00 01 02 01 01 00 00 00 00 00 00 00
00 1E 00 6F 00 5C 01 6F 00 01 02 01 01 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F
00 01 02 01 01 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 02 01 01 00 00 00
00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 15 00 00 00 01 00 03 30 02 01 FF FF 18 02 00
00 00 01 00 00 00 00 12 00 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01
6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00 00
00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00
6F 00 5C 01 6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 16 00
00 00 01 00 03 30 02 01 FF FF 84 00 00 00 00 00 00 00 00 00 12 00 00 01 00 01 FE 00
00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E
00 6F 00 5C 01 6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01
00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 00 01 FE 00 00 00 00 00
00 00 00 1E 00 6F 00 5C 01 6F 00 1A 00 00 00 01 00 03 30 02 01 FF FF BD 00 00 00 00
00 00 00 00 00 12 00 00 01 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00
01 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 02 01 FE 00 00 00 00
00 00 00 00 1E 00 6F 00 5C 01 6F 00 01 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00
5C 01 6F 00 01 01 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5C 01 6F 00 1B 00 00 00
01 00 03 30 02 01 FF FF 8B 00 00 00 00 00 00 00 00 00 12 00 00 04 02 03 FE 00 00 00
00 00 00 00 00 82 00 CE 01 61 02 CE 01 04 02 03 FE 00 00 00 00 00 00 00 00 82 00 CE
01 61 02 CE 01 04 02 03 FE 00 00 00 00 00 00 00 00 82 00 CE 01 61 02 CE 01 04 02 03
FE 00 00 00 00 00 00 00 00 82 00 CE 01 61 02 CE 01 04 02 03 FE 00 00 00 00 00 00 00
00 82 00 CE 01 61 02 CE 01 1C 00 00 00 01 00 03 30 02 01 FF FF A9 00 00 00 00 01 00
00 00 00 12 00 00 04 00 03 FE 00 00 00 00 00 00 00 00 72 01 CE 01 B0 02 CE 01 04 00
03 FE 00 00 00 00 00 00 00 00 72 01 CE 01 B0 02 CE 01 04 00 03 FE 00 00 00 00 00 00
00 00 72 01 CE 01 B0 02 CE 01 04 00 03 FE 00 00 00 00 00 00 00 00 72 01 CE 01 B0 02
CE 01 04 00 03 FE 00 00 00 00 00 00 00 00 72 01 CE 01 B0 02 CE 01 1D 00 00 00 01 00
03 30 02 01 FF FF A7 00 00 00 00 01 00 00 00 00 12 00 00 04 00 03 FE 00 00 00 00 00
00 00 00 72 01 92 01 B0 02 92 01 04 00 03 FE 00 00 00 00 00 00 00 00 72 01 92 01 B0
02 92 01 04 00 03 FE 00 00 00 00 00 00 00 00 72 01 92 01 B0 02 92 01 04 00 03 FE 00
00 00 00 00 00 00 00 72 01 92 01 B0 02 92 01 04 00 03 FE 00 00 00 00 00 00 00 00 72
01 92 01 B0 02 92 01 1E 00 00 00 01 00 03 30 02 01 FF FF 8C 00 00 00 00 00 00 00 00
00 12 00 00 04 02 03 FE 00 00 00 00 00 00 00 00 96 01 6F 00 02 03 6F 00 04 02 03 FE
00 00 00 00 00 00 00 00 96 01 6F 00 02 03 6F 00 04 02 03 FE 00 00 00 00 00 00 00 00
96 01 6F 00 02 03 6F 00 04 02 03 FE 00 00 00 00 00 00 00 00 96 01 6F 00 02 03 6F 00
04 02 03 FE 00 00 00 00 00 00 00 00 96 01 6F 00 02 03 6F 00 1F 00 00 00 01 00 03 30
02 01 FF FF 9F 05 00 00 00 01 00 00 00 00 12 00 00 04 02 03 FE 00 00 00 00 00 00 00
00 C4 01 AB 00 02 03 AB 00 04 02 03 FE 00 00 00 00 00 00 00 00 C4 01 AB 00 02 03 AB
00 04 02 03 FE 00 00 00 00 00 00 00 00 C4 01 AB 00 02 03 AB 00 04 02 03 FE 00 00 00
00 00 00 00 00 C4 01 AB 00 02 03 AB 00 04 02 03 FE 00 00 00 00 00 00 00 00 C4 01 AB
00 02 03 AB 00 20 00 00 00 01 00 03 30 02 01 FF FF 8E 05 00 00 00 01 00 00 00 00 12
00 00 04 02 03 FE 00 00 00 00 00 00 00 00 D5 00 AB 00 58 02 AB 00 04 02 03 FE 00 00
00 00 00 00 00 00 D5 00 AB 00 58 02 AB 00 04 02 03 FE 00 00 00 00 00 00 00 00 D5 00
AB 00 58 02 AB 00 04 02 03 FE 00 00 00 00 00 00 00 00 D5 00 AB 00 58 02 AB 00 04 02
03 FE 00 00 00 00 00 00 00 00 D5 00 AB 00 58 02 AB 00 21 00 00 00 01 00 03 30 02 01
FF FF 9B 05 00 00 00 01 00 00 00 00 12 00 00 04 02 03 FE 00 00 00 00 00 00 00 00 7F
01 AB 00 02 03 AB 00 04 02 03 FE 00 00 00 00 00 00 00 00 7F 01 AB 00 02 03 AB 00 04
02 03 FE 00 00 00 00 00 00 00 00 7F 01 AB 00 02 03 AB 00 04 02 03 FE 00 00 00 00 00
00 00 00 7F 01 AB 00 02 03 AB 00 04 02 03 FE 00 00 00 00 00 00 00 00 7F 01 AB 00 02
03 AB 00 22 00 00 00 01 00 03 30 02 01 FF FF 8E 00 00 00 00 00 00 00 00 00 12 00 00
01 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 FD 01 6F 00 01 02 01 FE 00 00 00 00
00 00 00 00 1E 00 6F 00 FD 01 6F 00 01 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00
FD 01 6F 00 01 02 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 FD 01 6F 00 01 01 01 01
2C 01 00 00 E8 02 1A 00 1E 00 6F 00 FD 01 6F 00 23 00 00 00 01 00 03 30 02 01 FF FF
19 02 00 00 08 01 00 00 00 00 12 00 00 04 02 01 FE 00 00 00 00 00 00 00 00 09 02 6F
00 02 03 6F 00 04 02 01 FE 00 00 00 00 00 00 00 00 09 02 6F 00 02 03 6F 00 04 02 01
FE 00 00 00 00 00 00 00 00 09 02 6F 00 02 03 6F 00 04 02 01 FE 00 00 00 00 00 00 00
00 09 02 6F 00 02 03 6F 00 04 02 01 FE 00 00 00 00 00 00 00 00 09 02 6F 00 02 03 6F
00 24 00 00 00 01 00 03 30 02 01 FF FF F6 01 00 00 00 01 00 00 00 00 12 00 00 04 02
01 FE 00 00 00 00 00 00 00 00 AA 02 D8 01 02 03 D8 01 04 02 01 FE 00 00 00 00 00 00
00 00 AA 02 D8 01 02 03 D8 01 04 02 01 FE 00 00 00 00 00 00 00 00 AA 02 D8 01 02 03
D8 01 04 02 01 FE 00 00 00 00 00 00 00 00 AA 02 D8 01 02 03 D8 01 04 02 01 FE 00 00
00 00 00 00 00 00 AA 02 D8 01 02 03 D8 01 25 00 00 00 01 00 03 30 02 01 FF FF F4 00
00 00 00 00 00 00 00 00 12 00 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5F
00 6F 00 04 00 01 FE 00 00 00 00 00 00 00 00 1E 00 6F 00 5F 00 6F 00 04 00 01 FE 00
00 00 00 00 00 00 00 1E 00 6F
|
success or wait |
985665925 |
Key value replaced with new |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Toolbars\Settings Name: Microsoft
Office Word Type: binary Data: 01 01 00 00 00 00 00 00 01 00 05 00 00 00 02 01 FF
FF 8F 05 00 00 01 00 18 00 00 00 12 00 00 02 02 02 00 00 00 00 00 CE 00 00 00 EB 00
64 00 B3 01 3C 02 02 00 02 FE 00 00 00 00 CE 00 00 00 EB 00 64 00 B3 01 3C 02 02 00
02 FE 00 00 00 00 CE 00 00 00 EB 00 64 00 B3 01 3C 02 02 00 02 FE 00 00 00 00 CE 00
00 00 EB 00 64 00 B3 01 3C 02 02 00 02 FE 00 00 00 00 CE 00 00 00 EB 00 64 00 B3 01
3C 02 Old data: 01 01 00 00 00 00 00 00 01 00 05 00 00 00 02 01 FF FF 8F 05 00 00
01 00 18 00 00 00 12 00 00 02 02 02 00 00 00 00 00 CE 00 00 00 EB 00 64 00 B3 01 3C
02 02 00 02 FE 00 00 00 00 CE 00 E4 01 EB 00 64 00 B3 01 3C 02 02 00 02 FE 00 00 00
00 CE 00 E4 01 EB 00 64 00 B3 01 3C 02 02 00 02 FE 00 00 00 00 CE 00 E4 01 EB 00 64
00 B3 01 3C 02 02 00 02 FE 00 00 00 00 CE 00 E4 01 EB 00 64 00 B3 01 3C 02
|
success or wait |
985861582 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: Bidi Spelling |
object name not found |
985978463 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: AutoSpell |
object name not found |
986195059 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: AutoGrammar |
object name not found |
986195554 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: DefaultFormat |
object name not found |
986196010 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: BackgroundSave |
object name not found |
986196441 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: BackgroundPrint |
object name not found |
986196846 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: PlainTextAutoFormat |
object name not found |
986197230 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: InsertFloating |
object name not found |
986417987 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Data Name: Settings |
buffer overflow |
986419329 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Data Name: Settings |
buffer overflow |
986419748 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Data Name: Settings |
success or wait |
986420131 |
Key value replaced with new |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Data Name: Settings Type: binary
Data: A8 00 1C 03 20 01 00 00 5C 01 00 00 04 00 00 00 08 00 00 00 08 00 00 00 08 00
00 00 08 00 00 00 08 00 00 00 08 00 00 00 0C 00 00 00 06 00 00 00 06 00 00 00 06 00
00 00 06 00 00 00 06 00 00 00 06 00 00 00 00 00 00 00 06 00 00 00 06 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 06 00 00 00 1C 00 00 00 1C 00 00 00 02 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 48 00 00 00 04 00 00 00 04 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 04 00 00 00 06 00 00 00 69 EC 08 5B 44 8C 04 BD B0 01
AC 40 F9 50 00 00 00 E0 30 90 00 00 02 00 0A 00 2D 00 42 00 00 00 42 00 00 00 58 02
00 00 9B 01 00 00 00 00 04 06 03 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 04
A7 01 00 04 37 00 C8 00 98 04 01 80 FF FF 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 74 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 01 00 06 00 00 00 0D 00 00 00 0C 02 00 03 00 00 05 02 00 00 00 00 00 00
E0 01 02 00 00 00 12 00 00 00 00 60 30 90 BA 00 94 00 64 00 00 00 00 00 00 FF 00 00
FF 00 00 00 00 00 00 FF 01 00 00 00 11 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00
74 C3 10 0E 00 00 00 00 00 00 0A 00 00 00 00 00 00 00 03 0A 00 00 00 00 E4 04 00 00
1D 4C 1A 00 00 00 00 00 00 00 18 00 50 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 0D 00 00 00 00 00 00 00 00 00 00 00 00 D4 94 46 00 D4 94 46 01 00
00 00 63 63 19 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00
20 00 64 00 00 00 63 63 20 00 64 00 00 00 63 63 21 00 19 00 00 00 63 63 20 00 64 00
00 00 63 63 20 00 64 00 00 00 63 01 20 00 64 00 00 00 63 01 64 00 00 00 90 02 00 00
02 00 00 01 01 01 01 01 01 01 00 01 01 01 01 01 01 00 01 01 01 00 01 00 01 00 01 01
01 01 01 01 00 02 00 03 01 03 01 03 01 03 00 03 01 02 00 03 01 03 01 03 01 03 01 00
00 23 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01
01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01
01 01 01 01 01 01 01 01 01 02 01 01 01 01 01 01 01 02 01 01 01 01 01 01 01 01 01 01
01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01
01 01 01 01 01 01 01 03 01 01 01 01 01 01 01 01 01 01 01 01 01 FF FF CF FF FF FF 00
00 86 02 FF FF 00 00 86 02 FF FF 00 00 86 02 FF FF 00 00 0C 00 FF FF 00 00 01 00 FF
FF 00 00 01 00 FF FF 00 00 01 00 48 00 42 00 00 00 48 00 61 00 6E 00 75 00 65 00 6C
00 65 00 20 00 42 00 61 00 73 00 65 00 72 00 00 00 48 00 61 00 6E 00 75 00 65 00 6C
00 65 00 20 00 42 00 61 00 73 00 65 00 72 00 00 00 00 00 87 FF FF 03 00 00 3E 00 02
02 00 00 06 00 09 00 34 00 00 00 00 00 90 00 90 00 00 00 00 00 0F 00 00 00 FF FF FF
00 00 00 00 00 00 00 14 00 14 00 00 00 00 00 00 00 02 63 78 00 C8 00 00 00 00 00 14
00 00 00 00 00 90 00 90 00 80 00 00 00 08 00 00 00 08 00 FF FF 00 00 04 00 00 00 00
00 Old data: A8 00 1C 03 20 01 00 00 5C 01 00 00 04 00 00 00 08 00 00 00 08 00 00
00 08 00 00 00 08 00 00 00 08 00 00 00 08 00 00 00 0C 00 00 00 06 00 00 00 06 00 00
00 06 00 00 00 06 00 00 00 06 00 00 00 06 00 00 00 00 00 00 00 06 00 00 00 06 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 06 00 00 00 1C 00 00 00 1C 00 00 00 02 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 48 00 00 00 04 00 00 00 04 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 00 06 00 00 00 69 EC 08 5B 44 8C 04
BD B0 01 AC 40 F9 50 00 00 00 E0 30 90 00 00 01 00 0A 00 2D 00 42 00 00 00 42 00 00
00 58 02 00 00 9B 01 00 00 00 00 04 06 03 00 00 00 00 00 01 00 00 00 00 00 00 00 00
00 00 04 A7 01 00 04 37 00 C8 00 98 04 01 80 FF FF 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 74 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 01 00 06 00 00 00 0D 00 00 00 0C 02 00 03 00 00 05 02 00 00 00
00 00 00 E0 01 02 00 00 00 12 00 00 00 00 60 30 90 BA 00 94 00 64 00 00 00 00 00 00
FF 00 00 FF 00 00 00 00 00 00 FF 01 00 00 00 11 30 00 00 00 00 00 00 00 00 00 00 00
00 00 00 74 C3 10 0E 00 00 00 00 00 00 0A 00 00 00 00 00 00 00 03 0A 00 00 00 00 E4
04 00 00 1D 4C 1A 00 00 00 00 00 00 00 18 00 50 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 0D 00 00 00 00 00 00 00 00 00 00 00 00 D4 94 46 00 D4 94
46 01 00 00 00 63 63 19 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03
00 00 00 20 00 64 00 00 00 63 63 20 00 64 00 00 00 63 63 21 00 19 00 00 00 63 63 20
00 64 00 00 00 63 63 20 00 64 00 00 00 63 01 20 00 64 00 00 00 63 01 64 00 00 00 90
02 00 00 02 00 00 01 01 01 01 01 01 01 00 01 01 01 01 01 01 00 01 01 01 00 01 00 01
00 01 01 01 01 01 01 00 02 00 03 01 03 01 03 01 03 00 03 01 02 00 03 01 03 01 03 01
03 01 00 00 23 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01
01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01
01 01 01 01 01 01 01 01 01 01 01 01 02 01 01 01 01 01 01 01 02 01 01 01 01 01 01 01
01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01
01 01 01 01 01 01 01 01 01 01 03 01 01 01 01 01 01 01 01 01 01 01 01 01 FF FF CF FF
FF FF 00 00 86 02 FF FF 00 00 86 02 FF FF 00 00 86 02 FF FF 00 00 0C 00 FF FF 00 00
01 00 FF FF 00 00 01 00 FF FF 00 00 01 00 48 00 42 00 00 00 48 00 61 00 6E 00 75 00
65 00 6C 00 65 00 20 00 42 00 61 00 73 00 65 00 72 00 00 00 48 00 61 00 6E 00 75 00
65 00 6C 00 65 00 20 00 42 00 61 00 73 00 65 00 72 00 00 00 00 00 87 FF FF 03 00 00
3E 00 02 02 00 00 06 00 09 00 34 00 00 00 00 00 90 00 90 00 00 00 00 00 0F 00 00 00
FF FF FF 00 00 00 00 00 00 00 14 00 14 00 00 00 00 00 00 00 02 63 78 00 C8 00 00 00
00 00 14 00 00 00 00 00 90 00 90 00 80 00 00 00 08 00 00 00 08 00 FF FF 00 00 04 00
00 00 00 00
|
success or wait |
986434318 |
Message posted |
TID: 6C4 Message: C0D4 WParam: 0 LParam: 1144 |
success |
986642855 |
Key value replaced with same |
Path: HKEY_USERS\Software\Microsoft\MSHandwritingTIP\sketch Name: BWasOpenLastTime
Type: unicode Data: 0 Old data:
|
success or wait |
986646032 |
Key value replaced with same |
Path: HKEY_USERS\Software\Microsoft\MSHandwritingTIP\sketch Name: BDocked Type: unicode
Data: 0 Old data:
|
success or wait |
986865335 |
Key value replaced with new |
Path: HKEY_USERS\Software\Microsoft\MSHandwritingTIP\sketch Name: RectWindowPosition
Type: unicode Data: 496,306,800,572 Old data: 496,307,800,572
|
success or wait |
986866263 |
Message posted |
TID: 6C4 Message: C0D4 WParam: 0 LParam: 1144 |
success |
986976669 |
Window destroyed |
HWND: 1A012E |
success |
986977549 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 1D00FA, 1700B0, 1A012E,
190112, 1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 6023E, 6023C, 1400E8, 140140
|
success or wait |
986977691 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 1D00FA, 1700B0, 1A012E,
190112, 1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 6023E, 6023C, 1400E8, 140140
|
success or wait |
986977927 |
Window destroyed |
HWND: 1700B0 |
success |
986978478 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 1D00FA, 1700B0, 190112,
1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 6023E, 6023C, 1400E8, 140140, 1300E0
|
success or wait |
986978615 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 1D00FA, 1700B0, 190112,
1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 6023E, 6023C, 1400E8, 140140, 1300E0
|
success or wait |
987089302 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 1D00FA, 1700B0, 190112,
1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 6023E, 6023C, 1400E8, 140140, 1300E0
|
success or wait |
987202288 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 1D00FA, 1700B0, 190112,
1400E2, E0154, 201EA, 140116, 201DE, 601DC, 301AE, 6023E, 6023C, 1400E8, 140140, 1300E0
|
success or wait |
987203212 |
Window destroyed |
HWND: 1300EC |
success |
987313752 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, E0154, 201EA,
140116, 201DE, 601DC, 301AE, 6023E, 6023C, 1400E8, 140140, 1300E0, 200110, 1200DC
|
success or wait |
987314018 |
Window destroyed |
HWND: 100104 |
success |
987314631 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, E0154, 201EA,
140116, 201DE, 601DC, 301AE, 6023E, 6023C, 1400E8, 140140, 1300E0, 200110, 1200DC
|
success or wait |
987314866 |
Window destroyed |
HWND: 140140 |
success |
987424443 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, E0154, 201EA,
140116, 201DE, 601DC, 301AE, 6023E, 6023C, 1400E8, 140140, 1300E0, 200110, 1200DC
|
success or wait |
987536901 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, E0154, 201EA,
140116, 201DE, 601DC, 301AE, 6023E, 6023C, 1400E8, 140140, 1300E0, 200110, 1200DC
|
success or wait |
987537290 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, E0154, 201EA,
140116, 201DE, 601DC, 301AE, 6023E, 6023C, 1400E8, 140140, 1300E0, 200110, 1200DC
|
success or wait |
987537643 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, E0154, 201EA,
140116, 201DE, 601DC, 301AE, 6023E, 6023C, 1400E8, 140140, 1300E0, 200110, 1200DC
|
success or wait |
987537973 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: PropertiesWindow |
object name not found |
987538427 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: PropertiesWindow Type: unicode
Data: 4 23 180 400 1 Old data:
|
success or wait |
987538748 |
Window destroyed |
HWND: E0154 |
success |
987767878 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, E0154, 201EA,
140116, 201DE, 601DC, 301AE, 6023E, 1400E8, 1300E0, 200110, 1200DC, 1, 1200DC
|
success or wait |
987768011 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, E0154, 201EA,
140116, 201DE, 601DC, 301AE, 6023E, 1400E8, 1300E0, 200110, 1200DC, 1, 1200DC
|
success or wait |
987985695 |
Window shown |
HWND: 201EC CMD: hide |
error |
987992726 |
Window shown |
HWND: 201EE CMD: hide |
error |
988095064 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: MainWindow |
object name not found |
988881574 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: MainWindow Type: unicode
Data: 0 0 0 0 1 Old data:
|
success or wait |
988882115 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: MdiMaximized |
object name not found |
988883586 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: MdiMaximized Type: unicode
Data: 0 Old data:
|
success or wait |
989102636 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: Dock Type: binary Data: 02
00 4C 01 05 00 08 00 04 00 1E 00 FC 03 FC 02 FF 02 01 01 04 00 1E 00 B8 00 FC 02 FF
02 00 01 04 00 1E 00 B8 00 2F 01 05 00 00 01 04 00 35 01 B8 00 FC 02 01 00 00 01 BE
00 1E 00 FC 03 FC 02 FF 02 00 01 BE 00 1E 00 FC 03 FC 02 FF 02 01 01 BE 00 1E 00 FC
03 FC 02 00 00 00 01 BB 03 5E 00 FC 03 FC 02 06 00 00 00 D3 00 AF 01 09 03 32 02 FF
03 01 00 D3 00 AF 01 09 03 32 02 04 00 00 00 93 01 AF 01 09 03 32 02 03 00 00 00 D3
00 AF 01 09 03 32 02 02 00 00 00 21 00 72 01 6C 02 12 02 FF 03 01 00 21 00 72 01 E8
00 12 02 04 00 00 00 EE 00 72 01 A9 01 12 02 03 00 00 00 AF 01 72 01 6C 02 12 02 02
00 00 00 F8 02 81 00 AC 03 01 01 05 00 00 00 59 00 30 02 0D 01 4B 03 01 00 00 00 3A
03 BC 00 79 03 1F 02 06 00 00 00 16 00 16 00 D9 01 C4 00 04 00 01 00 2C 00 2C 00 EB
01 E3 00 03 00 01 00 42 00 42 00 3B 02 F7 00 02 00 01 00 00 00 00 00 00 00 00 00 08
00 00 00 58 00 57 00 37 01 FF 01 01 00 01 00 00 00 00 00 00 00 00 00 06 00 01 00 6E
00 6E 00 7F 01 52 01 05 00 01 00 00 00 00 00 00 00 00 00 00 00 01 00 Old data:
|
success or wait |
989104272 |
Window destroyed |
HWND: 140116 |
success |
989105753 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, 201EA, 140116,
201DE, 601DC, 301AE, 6023E, 1400E8, 1300E0, 200110, 1200DC, 1, 1, 1200DC
|
success or wait |
989105968 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, 201EA, 140116,
201DE, 601DC, 301AE, 6023E, 1400E8, 1300E0, 200110, 1200DC, 1, 1, 1200DC
|
success or wait |
989214263 |
Window destroyed |
HWND: 60258 |
success |
989326391 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, 201EA, 201DE,
601DC, 301AE, 6023E, 1400E8, 1300E0, 200110, 1200DC, 1, 1, 1, 1200DC
|
success or wait |
989326528 |
Window destroyed |
HWND: 201EA |
success |
989326759 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, 201EA, 201DE,
601DC, 301AE, 6023E, 1400E8, 1300E0, 200110, 1200DC, 1, 1, 1, 1200DC
|
success or wait |
989326907 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, 201EA, 201DE,
601DC, 301AE, 6023E, 1400E8, 1300E0, 200110, 1200DC, 1, 1, 1, 1200DC
|
success or wait |
989327291 |
Window destroyed |
HWND: 6023E |
success |
989440404 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, 201DE, 601DC,
301AE, 6023E, 1400E8, 1300E0, 200110, 1200DC, 1, 1, 1, 1, 1200DC
|
success or wait |
989552409 |
Window destroyed |
HWND: 601DC |
success |
989554801 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, 201DE, 601DC,
301AE, 1400E8, 1300E0, 200110, 1200DC, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
989555182 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, 201DE, 601DC,
301AE, 1400E8, 1300E0, 200110, 1200DC, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
989555820 |
Window destroyed |
HWND: 20246 |
success |
989664663 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, 201DE, 301AE,
1400E8, 1300E0, 200110, 1200DC, 1, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
989775455 |
Window destroyed |
HWND: 301AE |
success |
989778734 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, 201DE, 301AE,
1400E8, 1300E0, 200110, 1200DC, 1, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
989779595 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, 201DE, 301AE,
1400E8, 1300E0, 200110, 1200DC, 1, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
989781053 |
Window destroyed |
HWND: 2000F8 |
success |
989782727 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, 201DE, 1400E8,
1300E0, 200110, 1200DC, 1, 1, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
989783234 |
Window destroyed |
HWND: 201DE |
success |
989998155 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, 201DE, 1400E8,
1300E0, 200110, 1200DC, 1, 1, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
989998397 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, 201DE, 1400E8,
1300E0, 200110, 1200DC, 1, 1, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
989998814 |
Window destroyed |
HWND: 14014E |
success |
989999329 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, 1400E8,
1300E0, 200110, 1200DC, 1, 1, 1, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
989999530 |
Window destroyed |
HWND: 1400E8 |
success |
990109190 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, 1400E8,
1300E0, 200110, 1200DC, 1, 1, 1, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
990222910 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, 1400E8,
1300E0, 200110, 1200DC, 1, 1, 1, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
990224336 |
Window destroyed |
HWND: 1300E0 |
success |
990226108 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, 1300E0,
200110, 1200DC, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
990226607 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, 1300E0,
200110, 1200DC, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
990227445 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: FolderView |
object name not found |
990228396 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: FolderView Type: unicode
Data: 1 Old data:
|
success or wait |
990449710 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: Tool Type: binary Data: 00
00 00 00 07 00 00 00 47 65 6E 65 72 61 6C 00 FF FF FF FF FF FF FF FF Old data:
|
success or wait |
990450345 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: CtlsShowSelected |
object name not found |
990450946 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: CtlsShowSelected Type: unicode
Data: 0 Old data:
|
success or wait |
990451202 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: DsnShowSelected |
object name not found |
990670992 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: DsnShowSelected Type: unicode
Data: 0 Old data:
|
success or wait |
990671540 |
File created |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\VB11.pip
Access: read attributes and synchronize and generic write Options: sequential only
and synchronous io non alert and non directory file and open no recall Attributes:
none Content Overwritten: true
|
success or wait |
990672895 |
File write |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\VB11.pip
Offset: unknown Length: 12 Value: 19 00 04 00 19 00 19 00 84 00 00 00
|
success or wait |
990781535 |
File write |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\VB11.pip
Offset: unknown Length: 100 Value: 68 00 00 00 70 00 00 00 78 00 00 00 80 00 00 00
73 DA CC 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
|
success or wait |
990784142 |
File write |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\VB11.pip
Offset: unknown Length: 8 Value: 04 00 00 00 00 00 00 00
|
success or wait |
990892395 |
File write |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\VB11.pip
Offset: unknown Length: 8 Value: 04 00 00 00 00 00 00 00
|
success or wait |
991006023 |
File write |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\VB11.pip
Offset: unknown Length: 8 Value: 04 00 00 00 00 00 00 00
|
success or wait |
991007502 |
File write |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\VB11.pip
Offset: unknown Length: 8 Value: 04 00 00 00 00 00 00 00
|
success or wait |
991008736 |
Thread delayed |
Time: 0 TID: 1144 |
success or wait |
991456817 |
Process information queried |
PID: 1680 Info Class: Cookie |
success or wait |
991571259 |
Process information queried |
PID: 1680 Info Class: Cookie |
success or wait |
991571634 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion Name: CommonFilesDir |
success or wait |
991573816 |
File opened |
Path: C:\Program Files\Common Files\system\ado\msadox.dll Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
991901125 |
Section loaded |
Path: C:\Program Files\Common Files\System\ado\msadox.dll Access: write and read and
execute Type: commit Baseaddress: 10F0000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
991902301 |
File opened |
Path: C:\Program Files\Common Files\system\ado\msadox.dll Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file Attributes: none Content Overwritten: true
|
success or wait |
992012713 |
Section loaded |
Path: C:\Program Files\Common Files\System\ado\msadox.dll Access: query and read Type:
commit Baseaddress: 10F0000 Size: 200704 Protection: readonly Mapped to pid: own pid
|
success or wait |
992014560 |
File opened |
Path: C:\Program Files\Common Files\system\ado\msadox.dll Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
992240801 |
Section loaded |
Path: C:\Program Files\Common Files\System\ado\msadox.dll Access: write and read and
execute Type: commit Baseaddress: 10F0000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
992241244 |
File opened |
Path: C:\Program Files\Common Files\system\ado\msadox.dll Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file Attributes: none Content Overwritten: true
|
success or wait |
992461423 |
Section loaded |
Path: C:\Program Files\Common Files\System\ado\msadox.dll Access: query and read Type:
commit Baseaddress: 10F0000 Size: 200704 Protection: readonly Mapped to pid: own pid
|
success or wait |
992462066 |
File opened |
Path: C:\WINDOWS\system32\oleacc.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
992684266 |
Section loaded |
Path: C:\WINDOWS\system32\oleacc.dll Access: write and read and execute Type: commit
Baseaddress: 10F0000 Size: 163840 Protection: execute Mapped to pid: own pid
|
success or wait |
992684914 |
File opened |
Path: C:\WINDOWS\system32\oleacc.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file Attributes: none Content
Overwritten: true
|
success or wait |
992906111 |
Section loaded |
Path: C:\WINDOWS\system32\oleacc.dll Access: query and read Type: commit Baseaddress:
10F0000 Size: 163840 Protection: readonly Mapped to pid: own pid
|
success or wait |
992906477 |
File opened |
Path: C:\WINDOWS\system32\oleacc.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
993356023 |
Section loaded |
Path: C:\WINDOWS\system32\oleacc.dll Access: write and read and execute Type: commit
Baseaddress: 10F0000 Size: 163840 Protection: execute Mapped to pid: own pid
|
success or wait |
993358124 |
File opened |
Path: C:\WINDOWS\system32\oleacc.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file Attributes: none Content
Overwritten: true
|
success or wait |
993465052 |
Section loaded |
Path: C:\WINDOWS\system32\oleacc.dll Access: query and read Type: commit Baseaddress:
10F0000 Size: 163840 Protection: readonly Mapped to pid: own pid
|
success or wait |
993578380 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Common Name: QmIMID |
object name not found |
993688690 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Security Name: DontTrustInstalledFiles |
object name not found |
994360001 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MessengerService Name: InstallationDirectory |
success or wait |
994472522 |
File opened |
Path: C:\Program Files\Messenger\msmsgs.exe Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
994920667 |
Section loaded |
Path: C:\Program Files\Messenger\msmsgs.exe Access: write and read and execute Type:
commit Baseaddress: 1BA0000 Size: 1695744 Protection: execute Mapped to pid: own pid
|
success or wait |
994922774 |
File opened |
Path: C:\Program Files\Messenger\msmsgs.exe Access: read attributes and synchronize
and generic read Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
995146936 |
Section loaded |
Path: C:\Program Files\Messenger\msmsgs.exe Access: query and read Type: commit Baseaddress:
1BA0000 Size: 1695744 Protection: readonly Mapped to pid: own pid
|
success or wait |
995147657 |
File opened |
Path: C:\Program Files\Messenger\msmsgs.exe Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
995481295 |
Section loaded |
Path: C:\Program Files\Messenger\msmsgs.exe Access: write and read and execute Type:
commit Baseaddress: 1BA0000 Size: 1695744 Protection: execute Mapped to pid: own pid
|
success or wait |
995482424 |
File opened |
Path: C:\Program Files\Messenger\msmsgs.exe Access: read attributes and synchronize
and generic read Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
995706036 |
Section loaded |
Path: C:\Program Files\Messenger\msmsgs.exe Access: query and read Type: commit Baseaddress:
1BA0000 Size: 1695744 Protection: readonly Mapped to pid: own pid
|
success or wait |
995707056 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: CustomizableAlertBaseURL |
object name not found |
995927134 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Registration\{90110409-6000-11D3-8CFE-0150048383C9}
Name: ProductID
|
success or wait |
995927456 |
Window destroyed |
HWND: 1400E2 |
success |
995927802 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, 200110,
1200DC, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
995927912 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1400E2, 200110,
1200DC, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
996151825 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Security Name: AccessVBOM |
success or wait |
996152661 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Templates\~$Normal.dot
Access: read attributes and synchronize and generic read and generic write Options:
synchronous io non alert and non directory file and open no recall Attributes: normal
Content Overwritten: true
|
success or wait |
996377055 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Templates\~$Normal.dot
Access: read attributes and delete Options: non directory file and open for backup
ident and open reparse point Overwritten: false
|
success or wait |
996387822 |
File deleted |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Templates\~$Normal.dot
New path: Disposition: Data :
|
success or wait |
996484647 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Name: Cache
|
success or wait |
996601764 |
Key value replaced with same |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Name: Cache Type: unicode Data: C:\Documents and Settings\Administrator\Local Settings\Temporary
Internet Files Old data:
|
success or wait |
996826079 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Toolbars Name: BtnSize |
object name not found |
996831794 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Toolbars Name: Transparency |
object name not found |
997495768 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Toolbars Name: AdaptiveMenus |
object name not found |
997496627 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Toolbars Name: AutoExpandMenus |
object name not found |
997497354 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Toolbars Name: Tooltips |
object name not found |
997497975 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Research\Translation Name:
CurrentProvider
|
success or wait |
997499017 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Research\Translation Name:
CurrentProvider
|
success or wait |
997716147 |
Windows found |
Window Name: NULL Class Name: Shell_TrayWnd HWND: 3004E |
success |
997716613 |
Window destroyed |
HWND: 200110 |
success |
997827523 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 200110, 1200DC,
1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
997940930 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 200110, 1200DC,
1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
997941388 |
Window destroyed |
HWND: 1200E4 |
success |
997942455 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1200DC, 1, 1, 1,
1, 1, 1, 1, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
997942656 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1200DC, 1, 1, 1,
1, 1, 1, 1, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
997943007 |
Window destroyed |
HWND: 190112 |
success |
998164600 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1200DC, 1, 1, 1,
1, 1, 1, 1, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
998164857 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1200DC, 1, 1, 1,
1, 1, 1, 1, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
998165308 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1200DC, 1, 1, 1,
1, 1, 1, 1, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
998165837 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1200DC, 1, 1, 1,
1, 1, 1, 1, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
998166232 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 478 HWNDs: 190112, 1200DC, 1, 1, 1,
1, 1, 1, 1, 1, 1, 1, 1, 1, 1200DC
|
success or wait |
998166690 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Name: Local AppData
|
success or wait |
998505677 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: MTTF |
success or wait |
998612965 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: MTTF |
success or wait |
998615113 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: MTTF |
success or wait |
998616362 |
Key value replaced with new |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: MTTF Type: dword Data:
142 Old data: 23
|
success or wait |
998617439 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: MTTA |
success or wait |
998618729 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: MTTA |
success or wait |
998722517 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: MTTA |
success or wait |
999620072 |
Key value replaced with new |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: MTTA Type: dword Data:
142 Old data: 23
|
success or wait |
999620821 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: MTTT |
success or wait |
999730004 |
Key value deleted |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Keyname: MTTT |
success or wait |
999842762 |
Process information queried |
PID: 1680 Info Class: Times |
success or wait |
999844989 |