| Operation |
Data |
Completion |
Time |
| Section loaded |
Path: \KnownDlls\kernel32.dll Access: write and read and execute Type: unknown Baseaddress:
7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid
|
success or wait |
472355140 |
| Section loaded |
Path: unknown Access: query and write and read and execute and extend size Type: reserve
Baseaddress: 7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid
|
success or wait |
472358708 |
| Section loaded |
Path: \NLS\NlsSectionUnicode Access: read Type: unknown Baseaddress: 260000 Size:
90112 Protection: readonly Mapped to pid: own pid
|
success or wait |
472360500 |
| Section loaded |
Path: \NLS\NlsSectionLocale Access: read Type: unknown Baseaddress: 280000 Size: 266240
Protection: readonly Mapped to pid: own pid
|
success or wait |
472361494 |
| Section loaded |
Path: \NLS\NlsSectionSortkey Access: query and read Type: unknown Baseaddress: 2D0000
Size: 266240 Protection: readonly Mapped to pid: own pid
|
success or wait |
472362610 |
| Section loaded |
Path: \NLS\NlsSectionSortTbls Access: read Type: unknown Baseaddress: 320000 Size:
24576 Protection: readonly Mapped to pid: own pid
|
success or wait |
472363044 |
| Section loaded |
Path: \NLS\NlsSectionSortkey00000409 Access: read Type: unknown Baseaddress: 320000
Size: 24576 Protection: readonly Mapped to pid: own pid
|
object name not found |
472363603 |
| Section loaded |
Path: \NLS\NlsSectionSortkey00000409 Access: read Type: unknown Baseaddress: 320000
Size: 24576 Protection: readonly Mapped to pid: own pid
|
object name not found |
472363739 |
| Section loaded |
Path: \KnownDlls\ADVAPI32.dll Access: write and read and execute Type: unknown Baseaddress:
77DD0000 Size: 634880 Protection: read write Mapped to pid: own pid
|
success or wait |
472376570 |
| Section loaded |
Path: \KnownDlls\RPCRT4.dll Access: write and read and execute Type: unknown Baseaddress:
77E70000 Size: 602112 Protection: read write Mapped to pid: own pid
|
success or wait |
472378397 |
| Section loaded |
Path: \KnownDlls\Secur32.dll Access: write and read and execute Type: unknown Baseaddress:
77FE0000 Size: 69632 Protection: read write Mapped to pid: own pid
|
success or wait |
472381481 |
| Section loaded |
Path: \KnownDlls\GDI32.dll Access: write and read and execute Type: unknown Baseaddress:
77F10000 Size: 299008 Protection: read write Mapped to pid: own pid
|
success or wait |
472387567 |
| Section loaded |
Path: \KnownDlls\USER32.dll Access: write and read and execute Type: unknown Baseaddress:
7E410000 Size: 593920 Protection: read write Mapped to pid: own pid
|
success or wait |
472389658 |
| Section loaded |
Path: \KnownDlls\ole32.dll Access: write and read and execute Type: unknown Baseaddress:
774E0000 Size: 1302528 Protection: read write Mapped to pid: own pid
|
success or wait |
472397426 |
| Section loaded |
Path: \KnownDlls\msvcrt.dll Access: write and read and execute Type: unknown Baseaddress:
77C10000 Size: 360448 Protection: read write Mapped to pid: own pid
|
success or wait |
472400454 |
| Section loaded |
Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit
Baseaddress: 410000 Size: 110592 Protection: execute Mapped to pid: own pid
|
success or wait |
472417334 |
| Section loaded |
Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit
Baseaddress: 410000 Size: 110592 Protection: execute Mapped to pid: own pid
|
success or wait |
472420028 |
| Section loaded |
Path: C:\WINDOWS\system32\imm32.dll Access: query and write and read and execute Type:
image Baseaddress: 76390000 Size: 118784 Protection: read write Mapped to pid: own
pid
|
success or wait |
472420828 |
| Section loaded |
Path: \NLS\NlsSectionCType Access: read Type: unknown Baseaddress: 850000 Size: 12288
Protection: readonly Mapped to pid: own pid
|
success or wait |
472471361 |
| Memory attributes changed |
PID: 296 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30B4D000
Length: 1000 New Protection: page readonly New Protection: page read and write
|
success or wait |
472482133 |
| Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager Name: CommonFilesDir |
success or wait |
472482382 |
| Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Access: write
and read and execute Type: commit Baseaddress: 860000 Size: 12218368 Protection: execute
Mapped to pid: own pid
|
success or wait |
472494565 |
| Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Access: query
and write and read and execute Type: image Baseaddress: 30C90000 Size: 12263424 Protection:
read write Mapped to pid: own pid
|
success or wait |
472499481 |
| Section loaded |
Path: \BaseNamedObjects\ShimSharedMemory Access: write Type: unknown Baseaddress:
870000 Size: 57344 Protection: read write Mapped to pid: own pid
|
success or wait |
472535007 |
| Section loaded |
Path: \KnownDlls\psapi.dll Access: write and read and execute Type: unknown Baseaddress:
870000 Size: 57344 Protection: read write Mapped to pid: own pid
|
object name not found |
472558649 |
| Section loaded |
Path: C:\WINDOWS\system32\psapi.dll Access: query and write and read and execute Type:
image Baseaddress: 76BF0000 Size: 45056 Protection: read write Mapped to pid: own
pid
|
success or wait |
472559320 |
| Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\1033\WWINTL.DLL Access: write and
read and execute Type: commit Baseaddress: 8D0000 Size: 774144 Protection: execute
Mapped to pid: own pid
|
success or wait |
472603393 |
| Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\1033\WWINTL.DLL Access: query and
read Type: commit Baseaddress: 8D0000 Size: 774144 Protection: readonly Mapped to
pid: own pid
|
success or wait |
472605059 |
| Section loaded |
Path: \BaseNamedObjects\PrimaryWord11SharedMemoryArea Access: read Type: unknown Baseaddress:
9C0000 Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
472615117 |
| Section loaded |
Path: \BaseNamedObjects\PrimaryWord11CommandLine Access: read Type: unknown Baseaddress:
9C0000 Size: 4096 Protection: readonly Mapped to pid: own pid
|
object name not found |
472617212 |
| Section loaded |
Path: \BaseNamedObjects\PrimaryWord11CommandLine Access: query and write and read
Type: commit Baseaddress: 9C0000 Size: 4096 Protection: read write Mapped to pid:
own pid
|
success or wait |
472617337 |
| Message posted |
HWND: A00D0 Message: 45B WParam: 0 LParam: 0 |
success |
472617634 |
| Section loaded |
Path: \BaseNamedObjects\Local\Mso97SharedDg19211106360 Access: query and write and
read and execute and extend size Type: unknown Baseaddress: A20000 Size: 126976 Protection:
read write Mapped to pid: own pid
|
success or wait |
490482960 |
| Section loaded |
Path: \KnownDlls\uxtheme.dll Access: write and read and execute Type: unknown Baseaddress:
A20000 Size: 126976 Protection: read write Mapped to pid: own pid
|
object name not found |
490484978 |
| Section loaded |
Path: C:\WINDOWS\system32\uxtheme.dll Access: query and write and read and execute
Type: image Baseaddress: 5AD70000 Size: 229376 Protection: read write Mapped to pid:
own pid
|
success or wait |
490486741 |
| Section loaded |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
Access: write and read and execute Type: commit Baseaddress: A40000 Size: 1056768
Protection: execute Mapped to pid: own pid
|
success or wait |
490536549 |
| Section loaded |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
Access: query and write and read and execute Type: image Baseaddress: 773D0000 Size:
1060864 Protection: read write Mapped to pid: own pid
|
success or wait |
490539040 |
| Section loaded |
Path: \KnownDlls\SHLWAPI.dll Access: write and read and execute Type: unknown Baseaddress:
77F60000 Size: 483328 Protection: read write Mapped to pid: own pid
|
success or wait |
490544098 |
| Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: write and read and execute Type: commit
Baseaddress: A40000 Size: 4096 Protection: execute Mapped to pid: own pid
|
success or wait |
490554135 |
| Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: query and read Type: commit Baseaddress:
A40000 Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
490556936 |
| Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: read Type: commit Baseaddress: A40000
Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
490559103 |
| Window created |
Window Name: OpusApp Class Name: OpusApp |
success |
490595605 |
| Section loaded |
Path: C:\WINDOWS\system32\msctf.dll Access: write and read and execute Type: commit
Baseaddress: A60000 Size: 299008 Protection: execute Mapped to pid: own pid
|
success or wait |
490597115 |
| Section loaded |
Path: C:\WINDOWS\system32\msctf.dll Access: query and write and read and execute Type:
image Baseaddress: 74720000 Size: 311296 Protection: read write Mapped to pid: own
pid
|
success or wait |
490599884 |
| Section loaded |
Path: \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read Type: commit Baseaddress: 74720000 Size: 311296 Protection:
read write Mapped to pid: own pid
|
object name exists |
490606904 |
| Section loaded |
Path:
\BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-507921405-1960408961-839522115-500SFM.DefaultS-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read and execute and
extend size Type: unknown Baseaddress:
A60000 Size: 262144 Protection: read write
Mapped to pid: own pid
|
success or wait |
490616159 |
| Section loaded |
Path: \KnownDlls\version.dll Access: write and read and execute Type: unknown Baseaddress:
77C00000 Size: 32768 Protection: read write Mapped to pid: own pid
|
success or wait |
490619763 |
| Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: write and read and execute Type: commit
Baseaddress: AA0000 Size: 180224 Protection: execute Mapped to pid: own pid
|
success or wait |
490624865 |
| Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: query and read Type: commit Baseaddress:
AA0000 Size: 180224 Protection: readonly Mapped to pid: own pid
|
success or wait |
490627781 |
| Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: write and read and execute Type: commit
Baseaddress: AA0000 Size: 180224 Protection: execute Mapped to pid: own pid
|
success or wait |
490631462 |
| Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: query and read Type: commit Baseaddress:
AA0000 Size: 180224 Protection: readonly Mapped to pid: own pid
|
success or wait |
490633859 |
| Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: write and read and execute Type: commit
Baseaddress: AA0000 Size: 180224 Protection: execute Mapped to pid: own pid
|
success or wait |
490637492 |
| Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: query and write and read and execute
Type: image Baseaddress: 755C0000 Size: 188416 Protection: read write Mapped to pid:
own pid
|
success or wait |
490639943 |
| Section loaded |
Path: \BaseNamedObjects\PrimaryWord11SharedMemoryArea Access: read Type: unknown Baseaddress:
755C0000 Size: 188416 Protection: read write Mapped to pid: own pid
|
success or wait |
490653155 |
| Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\1033\MSOINTL.DLL Access:
write and read and execute Type: commit Baseaddress: AB0000 Size: 1753088 Protection:
execute Mapped to pid: own pid
|
success or wait |
490655382 |
| Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\1033\MSOINTL.DLL Access:
query and read Type: commit Baseaddress: AB0000 Size: 1753088 Protection: readonly
Mapped to pid: own pid
|
success or wait |
490657843 |
| Section loaded |
Path: \BaseNamedObjects\Local\Mso97SharedDg20321106360 Access: query and write and
read and execute and extend size Type: unknown Baseaddress: C60000 Size: 126976 Protection:
read write Mapped to pid: own pid
|
success or wait |
490660511 |
| Section loaded |
Path: \KnownDlls\msi.dll Access: write and read and execute Type: unknown Baseaddress:
C60000 Size: 126976 Protection: read write Mapped to pid: own pid
|
object name not found |
490675067 |
| Section loaded |
Path: C:\WINDOWS\system32\msi.dll Access: query and write and read and execute Type:
image Baseaddress: 7D1E0000 Size: 2867200 Protection: read write Mapped to pid: own
pid
|
success or wait |
490676795 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Office\11.0\Word
Name: MTTT
|
success or wait |
490907523 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Office\11.0\Word
Name: MTTT
|
success or wait |
490908016 |
| Windows hook set |
Module: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE TID: 268 Hook ID: FFFFFFFF |
success |
491161788 |
| Section loaded |
Path: C:\WINDOWS\system32\rpcss.dll Access: write and read and execute Type: commit
Baseaddress: D00000 Size: 401408 Protection: execute Mapped to pid: own pid
|
success or wait |
491165979 |
| Section loaded |
Path: \KnownDlls\SHELL32.dll Access: write and read and execute Type: unknown Baseaddress:
7C9C0000 Size: 8482816 Protection: read write Mapped to pid: own pid
|
success or wait |
491428207 |
| Section loaded |
Path: C:\WINDOWS\system32\shell32.dll Access: read Type: commit Baseaddress: D00000
Size: 8462336 Protection: readonly Mapped to pid: own pid
|
success or wait |
491439891 |
| Section loaded |
Path: \KnownDlls\comctl32.dll Access: write and read and execute Type: unknown Baseaddress:
5D090000 Size: 630784 Protection: read write Mapped to pid: own pid
|
success or wait |
491478482 |
| Section loaded |
Path: C:\WINDOWS\system32\comctl32.dll Access: read Type: commit Baseaddress: D00000
Size: 618496 Protection: readonly Mapped to pid: own pid
|
success or wait |
491489359 |
| Window created |
Window Name: _WwC Class Name: _WwC |
success |
491669376 |
| Window created |
Window Name: _WwF Class Name: _WwF |
success |
493162833 |
| Windows found |
Window Name: no string Class Name: MSOBALLOON HWND: 0 |
success |
493186051 |
| Windows found |
Window Name: no string Class Name: MsoHelp10 HWND: 0 |
success |
493186346 |
| Windows found |
Window Name: no string Class Name: AgentAnim HWND: 0 |
success |
493186645 |
| Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\RICHED20.DLL Access:
write and read and execute Type: commit Baseaddress: DB0000 Size: 966656 Protection:
execute Mapped to pid: own pid
|
success or wait |
493201863 |
| Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\RICHED20.DLL Access:
query and write and read and execute Type: image Baseaddress: 39700000 Size: 962560
Protection: read write Mapped to pid: own pid
|
success or wait |
493204814 |
| Section loaded |
Path: \KnownDlls\OLEAUT32.dll Access: write and read and execute Type: unknown Baseaddress:
77120000 Size: 569344 Protection: read write Mapped to pid: own pid
|
success or wait |
493211815 |
| Section loaded |
Path: C:\WINDOWS\system32\msimtf.dll Access: write and read and execute Type: commit
Baseaddress: E30000 Size: 159744 Protection: execute Mapped to pid: own pid
|
success or wait |
493224884 |
| Section loaded |
Path: C:\WINDOWS\system32\msimtf.dll Access: write and read and execute Type: commit
Baseaddress: E30000 Size: 159744 Protection: execute Mapped to pid: own pid
|
success or wait |
493228585 |
| Section loaded |
Path: C:\WINDOWS\system32\msimtf.dll Access: write and read and execute Type: commit
Baseaddress: E30000 Size: 159744 Protection: execute Mapped to pid: own pid
|
success or wait |
493232211 |
| Section loaded |
Path: C:\WINDOWS\system32\msimtf.dll Access: write and read and execute Type: commit
Baseaddress: E30000 Size: 159744 Protection: execute Mapped to pid: own pid
|
success or wait |
493235791 |
| Section loaded |
Path: \KnownDlls\CLBCATQ.DLL Access: write and read and execute Type: unknown Baseaddress:
E30000 Size: 159744 Protection: execute Mapped to pid: own pid
|
object name not found |
493244502 |
| Section loaded |
Path: C:\WINDOWS\system32\clbcatq.dll Access: query and write and read and execute
Type: image Baseaddress: 76FD0000 Size: 520192 Protection: read write Mapped to pid:
own pid
|
success or wait |
493246322 |
| Section loaded |
Path: \KnownDlls\COMRes.dll Access: write and read and execute Type: unknown Baseaddress:
76FD0000 Size: 520192 Protection: read write Mapped to pid: own pid
|
object name not found |
493249285 |
| Section loaded |
Path: C:\WINDOWS\system32\comres.dll Access: query and write and read and execute
Type: image Baseaddress: 77050000 Size: 806912 Protection: read write Mapped to pid:
own pid
|
success or wait |
493250099 |
| Section loaded |
Path: \KnownDlls\VERSION.dll Access: write and read and execute Type: unknown Baseaddress:
77C00000 Size: 32768 Protection: read write Mapped to pid: own pid
|
success or wait |
493252549 |
| Section loaded |
Path: \BaseNamedObjects\CTF.AsmListCache.FMPDefaultS-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read and execute and extend size Type: unknown Baseaddress:
E50000 Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
493323038 |
| Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\INK\SKCHUI.DLL Access: write
and read and execute Type: commit Baseaddress: E50000 Size: 368640 Protection: execute
Mapped to pid: own pid
|
success or wait |
493403349 |
| Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\INK\SKCHUI.DLL Access: query
and write and read and execute Type: image Baseaddress: 10000000 Size: 372736 Protection:
read write Mapped to pid: own pid
|
success or wait |
493406768 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.GCompartListSFM.DefaultS-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read Type: reserve Baseaddress: 10000000 Size: 372736
Protection: read write Mapped to pid: own pid
|
object name exists |
493700570 |
| Section loaded |
Path: \KnownDlls\SETUPAPI.dll Access: write and read and execute Type: unknown Baseaddress:
10000000 Size: 372736 Protection: read write Mapped to pid: own pid
|
object name not found |
493729144 |
| Section loaded |
Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute
Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid:
own pid
|
success or wait |
493731173 |
| Section loaded |
Path: \BaseNamedObjects\DfSharedHeap325F0 Access: query and write and read Type: reserve
Baseaddress: FE0000 Size: 4194304 Protection: read write Mapped to pid: own pid
|
success or wait |
494274527 |
| Section loaded |
Path: \BaseNamedObjects\DFMap0-206324 Access: query and write and read Type: commit
Baseaddress: 13E0000 Size: 524288 Protection: read write Mapped to pid: own pid
|
success or wait |
494278108 |
| Section loaded |
Path: \BaseNamedObjects\DfRoot0000325F0 Access: query and write and read Type: commit
Baseaddress: 1460000 Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
494279930 |
| Section loaded |
Path: \BaseNamedObjects\DFMap0-206340 Access: query and write and read Type: commit
Baseaddress: 1470000 Size: 524288 Protection: read write Mapped to pid: own pid
|
success or wait |
494293730 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~$4.doc Offset: none Length: 54 Value: 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
|
success or wait |
494305304 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~$4.doc Offset: none Length: 108 Value: 00
00 00 00 04 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 48 00 00 00 00 00 3E 00 02
02 00 00 06 00 09 00 34 00 00 00 00 00 90 00 90 00 00 00 00 00 0F 00 00 00 FF FF FF
00 00 00 00 00 00 00 14 00 14 00 00 00 00 00 00 00 02 63 78 00 C8 00 00 00 00 00 14
00 00 00 00 00 90 00 90 00 80 00 16 00 00 00
|
success or wait |
494306548 |
| Section loaded |
Path: \KnownDlls\USERENV.dll Access: write and read and execute Type: unknown Baseaddress:
769C0000 Size: 737280 Protection: read write Mapped to pid: own pid
|
success or wait |
494332243 |
| Section loaded |
Path: \BaseNamedObjects\Local\MSO_Formal11106360_S-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read and execute and extend size Type: unknown Baseaddress:
14F0000 Size: 8192 Protection: read write Mapped to pid: own pid
|
success or wait |
494377832 |
| Section loaded |
Path: \BaseNamedObjects\Local\MSO_AdHoc11106360_S-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read and execute and extend size Type: unknown Baseaddress:
1500000 Size: 8192 Protection: read write Mapped to pid: own pid
|
success or wait |
494380322 |
| Window created |
Window Name: _WwB Class Name: _WwB |
success |
494389102 |
| Window created |
Window Name: _WwG Class Name: _WwG |
success |
494395128 |
| Window created |
Window Name: 6.0.2600.6028!ScrollBar Class Name: SCROLLBAR |
success |
494398455 |
| Window created |
Window Name: _WwC Class Name: _WwC |
success |
494400283 |
| Window created |
Window Name: 6.0.2600.6028!ScrollBar Class Name: SCROLLBAR |
success |
494644714 |
| Window created |
Window Name: _WwC Class Name: _WwC |
success |
494760182 |
| Window created |
Window Name: _WwC Class Name: _WwC |
success |
494761352 |
| Window created |
Window Name: _WwC Class Name: _WwC |
success |
494762879 |
| Section loaded |
Path: \BaseNamedObjects\Local\Mso97SharedDg19521106360 Access: query and write and
read and execute and extend size Type: unknown Baseaddress: 1560000 Size: 126976 Protection:
read write Mapped to pid: own pid
|
success or wait |
494837280 |
| Section loaded |
Path: \BaseNamedObjects\Local\Mso97SharedDg19531106360 Access: query and write and
read and execute and extend size Type: unknown Baseaddress: 1560000 Size: 126976 Protection:
read write Mapped to pid: own pid
|
success or wait |
494838290 |
| Section loaded |
Path: C:\WINDOWS\system32\msimtf.dll Access: write and read and execute Type: commit
Baseaddress: 1580000 Size: 159744 Protection: execute Mapped to pid: own pid
|
success or wait |
494841728 |
| Message posted |
HWND: 10176 Message: C141 WParam: 0 LParam: 0 |
success |
494848792 |
| Section loaded |
Path: \BaseNamedObjects\Global\RotHintTable Access: read Type: unknown Baseaddress:
1580000 Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
494862047 |
| Section loaded |
Path: C:\WINDOWS\system32\winlogon.exe Access: write and read and execute Type: commit
Baseaddress: 1590000 Size: 507904 Protection: execute Mapped to pid: own pid
|
success or wait |
494863690 |
| Section loaded |
Path: \KnownDlls\xpsp2res.dll Access: write and read and execute Type: unknown Baseaddress:
1590000 Size: 507904 Protection: execute Mapped to pid: own pid
|
object name not found |
494865152 |
| Section loaded |
Path: C:\WINDOWS\system32\xpsp2res.dll Access: query and write and read and execute
Type: image Baseaddress: 1590000 Size: 2904064 Protection: read write Mapped to pid:
own pid
|
conflicting addresses |
494865829 |
| Message posted |
HWND: 10176 Message: 45F WParam: 0 LParam: 0 |
success |
494896024 |
| Windows enumerated |
Desktop: 0 Parent: 4004A Enum Children: true TID: 0 HWNDs: 30050, 30052, 30054, 30064,
10066, 10068, 10072, 1007e, 10082, 1, 5a5ad5d5, 5a, 0, 0, 0
|
success or wait |
494899691 |
| Windows found |
Window Name: no string Class Name: MSOBALLOON HWND: 0 |
success |
494901769 |
| Windows found |
Window Name: no string Class Name: AgentAnim HWND: 0 |
success |
494902024 |
| Windows found |
Window Name: no string Class Name: MSOBALLOON HWND: 0 |
success |
494902285 |
| Windows found |
Window Name: no string Class Name: MsoHelp10 HWND: 0 |
success |
494902404 |
| Windows found |
Window Name: no string Class Name: AgentAnim HWND: 0 |
success |
494902525 |
| Section loaded |
Path: \KnownDlls\SXS.DLL Access: write and read and execute Type: unknown Baseaddress:
1590000 Size: 2904064 Protection: read write Mapped to pid: own pid
|
object name not found |
495049322 |
| Section loaded |
Path: C:\WINDOWS\system32\sxs.dll Access: query and write and read and execute Type:
image Baseaddress: 7E720000 Size: 720896 Protection: read write Mapped to pid: own
pid
|
success or wait |
495050004 |
| Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 594 HWNDs: 1019c, 10198, 10196, 10194,
10192, 1, 10072, 1007e, 10082, 1, 5a5ad5d5, 5a, 0, 0, 0
|
success or wait |
495070106 |
| Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 594 HWNDs: 1019c, 10198, 10196, 10194,
10192, 1, 10072, 1007e, 10082, 1, 5a5ad5d5, 5a, 0, 0, 0
|
success or wait |
495070342 |
| Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 594 HWNDs: 1019c, 10198, 10196, 10194,
10192, 1, 10072, 1007e, 10082, 1, 5a5ad5d5, 5a, 0, 0, 0
|
success or wait |
495070514 |
| Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 594 HWNDs: 1019c, 10198, 10196, 10194,
10192, 1, 10072, 1007e, 10082, 1, 5a5ad5d5, 5a, 0, 0, 0
|
success or wait |
495070699 |
| Message posted |
HWND: 10176 Message: C141 WParam: 0 LParam: 0 |
success |
495070926 |
| Section loaded |
Path: \BaseNamedObjects\Local\Mso97SharedDg19521106360 Access: query and write and
read and execute and extend size Type: unknown Baseaddress: 1A80000 Size: 126976 Protection:
read write Mapped to pid: own pid
|
success or wait |
495085781 |
| Windows found |
Window Name: no string Class Name: MSOBALLOON HWND: 0 |
success |
495095091 |
| Windows found |
Window Name: no string Class Name: MsoHelp10 HWND: 0 |
success |
495095220 |
| Windows found |
Window Name: no string Class Name: AgentAnim HWND: 0 |
success |
495095348 |
| Section loaded |
Path: C:\WINDOWS\system32\msimtf.dll Access: write and read and execute Type: commit
Baseaddress: 1AA0000 Size: 159744 Protection: execute Mapped to pid: own pid
|
success or wait |
495097612 |
| Message posted |
HWND: 101B8 Message: 402 WParam: 0 LParam: 0 |
success |
495135653 |
| Section loaded |
Path: \KnownDlls\MSIMG32.dll Access: write and read and execute Type: unknown Baseaddress:
1AA0000 Size: 159744 Protection: execute Mapped to pid: own pid
|
object name not found |
495156145 |
| Section loaded |
Path: C:\WINDOWS\system32\msimg32.dll Access: query and write and read and execute
Type: image Baseaddress: 76380000 Size: 20480 Protection: read write Mapped to pid:
own pid
|
success or wait |
495156908 |
| Section loaded |
Path: \KnownDlls\LINKINFO.dll Access: write and read and execute Type: unknown Baseaddress:
76380000 Size: 20480 Protection: read write Mapped to pid: own pid
|
object name not found |
495240588 |
| Section loaded |
Path: C:\WINDOWS\system32\linkinfo.dll Access: query and write and read and execute
Type: image Baseaddress: 76980000 Size: 32768 Protection: read write Mapped to pid:
own pid
|
success or wait |
495241214 |
| Section loaded |
Path: \KnownDlls\ntshrui.dll Access: write and read and execute Type: unknown Baseaddress:
76980000 Size: 32768 Protection: read write Mapped to pid: own pid
|
object name not found |
495297659 |
| Section loaded |
Path: C:\WINDOWS\system32\ntshrui.dll Access: query and write and read and execute
Type: image Baseaddress: 76990000 Size: 151552 Protection: read write Mapped to pid:
own pid
|
success or wait |
495299280 |
| Section loaded |
Path: \KnownDlls\ATL.DLL Access: write and read and execute Type: unknown Baseaddress:
76990000 Size: 151552 Protection: read write Mapped to pid: own pid
|
object name not found |
495303527 |
| Section loaded |
Path: C:\WINDOWS\system32\atl.dll Access: query and write and read and execute Type:
image Baseaddress: 76B20000 Size: 69632 Protection: read write Mapped to pid: own
pid
|
success or wait |
495304230 |
| Section loaded |
Path: \KnownDlls\NETAPI32.dll Access: write and read and execute Type: unknown Baseaddress:
76B20000 Size: 69632 Protection: read write Mapped to pid: own pid
|
object name not found |
495321818 |
| Section loaded |
Path: C:\WINDOWS\system32\netapi32.dll Access: query and write and read and execute
Type: image Baseaddress: 5B860000 Size: 348160 Protection: read write Mapped to pid:
own pid
|
success or wait |
495322515 |
| Section loaded |
Path: C:\WINDOWS\system32\ntshrui.dll Access: read Type: commit Baseaddress: 1AB0000
Size: 143360 Protection: readonly Mapped to pid: own pid
|
success or wait |
495345293 |
| Section loaded |
Path: unknown Access: query and write and read Type: commit Baseaddress: 1AB0000 Size:
4096 Protection: read write Mapped to pid: own pid
|
success or wait |
495396506 |
| Section loaded |
Path: unknown Access: query and write and read Type: commit Baseaddress: 1AB0000 Size:
4096 Protection: read write Mapped to pid: own pid
|
success or wait |
497070083 |
| Section loaded |
Path: unknown Access: query and write and read Type: commit Baseaddress: 1AB0000 Size:
4096 Protection: read write Mapped to pid: own pid
|
success or wait |
497074691 |
| Section loaded |
Path: unknown Access: query and write and read Type: commit Baseaddress: 1AB0000 Size:
4096 Protection: read write Mapped to pid: own pid
|
success or wait |
497082052 |
| Section loaded |
Path: unknown Access: query and write and read Type: commit Baseaddress: 1AB0000 Size:
4096 Protection: read write Mapped to pid: own pid
|
success or wait |
497285876 |
| Section loaded |
Path: unknown Access: query and write and read Type: commit Baseaddress: 1AB0000 Size:
4096 Protection: read write Mapped to pid: own pid
|
success or wait |
497311159 |
| Section loaded |
Path: unknown Access: query and write and read Type: commit Baseaddress: 1AB0000 Size:
4096 Protection: read write Mapped to pid: own pid
|
success or wait |
497320229 |
| Section loaded |
Path: unknown Access: query and write and read Type: commit Baseaddress: 1AB0000 Size:
4096 Protection: read write Mapped to pid: own pid
|
success or wait |
497322467 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB..JOJAC Access: query and
write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
498796180 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.Shared.SFM.AJH Access: query and write and read and
execute and extend size Type: unknown Baseaddress: 1AF0000 Size: 524288 Protection:
read write Mapped to pid: own pid
|
success or wait |
498797414 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.B.JOJAC Access: query and
write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
498797831 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.C.JOJAC Access: query and
write and read Type: commit Baseaddress: 1AD0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
498798188 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.D.JOJAC Access: query and
write and read Type: commit Baseaddress: 1B70000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
498798532 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.E.JOJAC Access: query and
write and read Type: commit Baseaddress: 1B80000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
498798871 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.F.JOJAC Access: query and
write and read Type: commit Baseaddress: 1B90000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
498799216 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.G.JOJAC Access: query and
write and read Type: commit Baseaddress: 1BA0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
498799560 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.H.JOJAC Access: query and
write and read Type: commit Baseaddress: 1BB0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
498799906 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.I.JOJAC Access: query and
write and read Type: commit Baseaddress: 1BC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
498800254 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.J.JOJAC Access: query and
write and read Type: commit Baseaddress: 1BD0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
498800603 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.K.JOJAC Access: query and
write and read Type: commit Baseaddress: 1BE0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
498800953 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.L.JOJAC Access: query and
write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
498802348 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.M.JOJAC Access: query and
write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
498804301 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.N.JOJAC Access: query and
write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
498805641 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.O.JOJAC Access: query and
write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
498807051 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.P.JOJAC Access: query and
write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
498808408 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.AB.JOJAC Access: query
and write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
498809764 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.BB.JOJAC Access: query
and write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
498811172 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.CB.JOJAC Access: query
and write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
498812528 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.DB.JOJAC Access: query
and write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
498813922 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.EB.JOJAC Access: query
and write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
498815330 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.AJH.O.JOJAC Access: query and
write and read and execute and extend size Type: unknown Baseaddress: 1AC0000 Size:
4096 Protection: read write Mapped to pid: own pid
|
success or wait |
498817329 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.AJH.P.JOJAC Access: query and
write and read and execute and extend size Type: unknown Baseaddress: 1AC0000 Size:
4096 Protection: read write Mapped to pid: own pid
|
success or wait |
498817717 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.AJH.AB.JOJAC Access: query
and write and read and execute and extend size Type: unknown Baseaddress: 1AC0000
Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
498818044 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.AJH.BB.JOJAC Access: query
and write and read and execute and extend size Type: unknown Baseaddress: 1AC0000
Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
498818366 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.AJH.CB.JOJAC Access: query
and write and read and execute and extend size Type: unknown Baseaddress: 1AC0000
Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
498818689 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.AJH.DB.JOJAC Access: query
and write and read and execute and extend size Type: unknown Baseaddress: 1AC0000
Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
498819012 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.AJH.EB.JOJAC Access: query
and write and read and execute and extend size Type: unknown Baseaddress: 1AC0000
Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
498819334 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.AJH.FB.JOJAC Access: query
and write and read and execute and extend size Type: unknown Baseaddress: 1AC0000
Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
498819657 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.AJH.GB.JOJAC Access: query
and write and read and execute and extend size Type: unknown Baseaddress: 1AC0000
Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
498819979 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.AJH.HB.JOJAC Access: query
and write and read and execute and extend size Type: unknown Baseaddress: 1AC0000
Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
498820576 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.FB.ELKAC Access: query
and write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
499524699 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.GB.ELKAC Access: query
and write and read Type: commit Baseaddress: 1AD0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
499525056 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.HB.ELKAC Access: query
and write and read Type: commit Baseaddress: 1B70000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
499525406 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.IB.ELKAC Access: query
and write and read Type: commit Baseaddress: 1B80000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
499525750 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.JB.ELKAC Access: query
and write and read Type: commit Baseaddress: 1B90000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
499526093 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.KB.ELKAC Access: query
and write and read Type: commit Baseaddress: 1BA0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
499526437 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.LB.ELKAC Access: query
and write and read Type: commit Baseaddress: 1BB0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
499526780 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.MB.ELKAC Access: query
and write and read Type: commit Baseaddress: 1BC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
499527122 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.NB.ELKAC Access: query
and write and read Type: commit Baseaddress: 1BD0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
499527468 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.OB.ELKAC Access: query
and write and read Type: commit Baseaddress: 1BE0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
499527820 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.PB.ELKAC Access: query
and write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
499529307 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.AC.ELKAC Access: query
and write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
499531175 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.BC.ELKAC Access: query
and write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
499532514 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.CC.ELKAC Access: query
and write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
499533861 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.DC.ELKAC Access: query
and write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
499535267 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.EC.ELKAC Access: query
and write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
499536619 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.FC.ELKAC Access: query
and write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
499537967 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.GC.ELKAC Access: query
and write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
499539380 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.HC.ELKAC Access: query
and write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
499540737 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MAB.IC.ELKAC Access: query
and write and read Type: commit Baseaddress: 1AC0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
499542087 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.AJH.IB.ELKAC Access: query
and write and read and execute and extend size Type: unknown Baseaddress: 1AC0000
Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
499544438 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.AJH.JB.ELKAC Access: query
and write and read and execute and extend size Type: unknown Baseaddress: 1AC0000
Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
499544857 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.AJH.KB.ELKAC Access: query
and write and read and execute and extend size Type: unknown Baseaddress: 1AC0000
Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
499545214 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.AJH.LB.ELKAC Access: query
and write and read and execute and extend size Type: unknown Baseaddress: 1AC0000
Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
499545709 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.AJH.MB.ELKAC Access: query
and write and read and execute and extend size Type: unknown Baseaddress: 1AC0000
Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
499546053 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.AJH.NB.ELKAC Access: query
and write and read and execute and extend size Type: unknown Baseaddress: 1AC0000
Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
499546698 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.AJH.OB.ELKAC Access: query
and write and read and execute and extend size Type: unknown Baseaddress: 1AC0000
Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
499547036 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.AJH.PB.ELKAC Access: query
and write and read and execute and extend size Type: unknown Baseaddress: 1AC0000
Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
499547361 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.AJH.AC.ELKAC Access: query
and write and read and execute and extend size Type: unknown Baseaddress: 1AC0000
Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
499547683 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.AJH.BC.ELKAC Access: query
and write and read and execute and extend size Type: unknown Baseaddress: 1AC0000
Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
499548254 |
| Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\FNAME.DLL Access: write and read and
execute Type: commit Baseaddress: 1AC0000 Size: 126976 Protection: execute Mapped
to pid: own pid
|
success or wait |
501803665 |
| Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\FNAME.DLL Access: query and write and
read and execute Type: image Baseaddress: 37320000 Size: 135168 Protection: read write
Mapped to pid: own pid
|
success or wait |
501807913 |
| Section loaded |
Path: \KnownDlls\WINSPOOL.DRV Access: write and read and execute Type: unknown Baseaddress:
37320000 Size: 135168 Protection: read write Mapped to pid: own pid
|
object name not found |
501819004 |
| Section loaded |
Path: C:\WINDOWS\system32\winspool.drv Access: query and write and read and execute
Type: image Baseaddress: 73000000 Size: 155648 Protection: read write Mapped to pid:
own pid
|
success or wait |
501820517 |
| Section loaded |
Path: \KnownDlls\OLEACC.dll Access: write and read and execute Type: unknown Baseaddress:
73000000 Size: 155648 Protection: read write Mapped to pid: own pid
|
object name not found |
501827877 |
| Section loaded |
Path: C:\WINDOWS\system32\oleacc.dll Access: query and write and read and execute
Type: image Baseaddress: 74C80000 Size: 180224 Protection: read write Mapped to pid:
own pid
|
success or wait |
501829798 |
| Section loaded |
Path: \KnownDlls\MSVCP60.dll Access: write and read and execute Type: unknown Baseaddress:
74C80000 Size: 180224 Protection: read write Mapped to pid: own pid
|
object name not found |
501837133 |
| Section loaded |
Path: C:\WINDOWS\system32\msvcp60.dll Access: query and write and read and execute
Type: image Baseaddress: 76080000 Size: 413696 Protection: read write Mapped to pid:
own pid
|
success or wait |
501838814 |
| Section loaded |
Path: C:\WINDOWS\system32\oleaccrc.dll Access: query and read Type: commit Baseaddress:
1AD0000 Size: 20480 Protection: readonly Mapped to pid: own pid
|
success or wait |
501860487 |
| Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\FNAME.DLL Access: query and read Type:
commit Baseaddress: 1C70000 Size: 49152 Protection: readonly Mapped to pid: own pid
|
success or wait |
501911842 |
| Section loaded |
Path: C:\WINDOWS\system32\stdole2.tlb Access: query and read Type: commit Baseaddress:
1C80000 Size: 16384 Protection: readonly Mapped to pid: own pid
|
success or wait |
501928970 |
| Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\1033\STINTL.DLL Access: write and read
and execute Type: commit Baseaddress: 1C90000 Size: 20480 Protection: execute Mapped
to pid: own pid
|
success or wait |
501937238 |
| Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\1033\STINTL.DLL Access: query and write
and read and execute Type: image Baseaddress: 374B0000 Size: 24576 Protection: read
write Mapped to pid: own pid
|
success or wait |
501941219 |
| Thread created |
PID: 296 TID: 1800 EIP: 7C8106F9 Imagepath: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
Injected: false
|
success or wait |
502433527 |
| Thread resumed |
TID: 1800 PID: 296 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE |
success or wait |
502433804 |
| Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSPELL3.DLL Access: write
and read and execute Type: commit Baseaddress: 1EA0000 Size: 86016 Protection: execute
Mapped to pid: own pid
|
success or wait |
503173981 |
| Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSPELL3.DLL Access: query
and write and read and execute Type: image Baseaddress: 3F000000 Size: 86016 Protection:
read write Mapped to pid: own pid
|
success or wait |
503178230 |
| Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSP3EN.LEX Access: query
and read Type: commit Baseaddress: 1EB0000 Size: 364544 Protection: readonly Mapped
to pid: own pid
|
success or wait |
505429842 |
| Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\MSLID.DLL Access: write
and read and execute Type: commit Baseaddress: 1F10000 Size: 536576 Protection: execute
Mapped to pid: own pid
|
success or wait |
505439243 |
| Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\MSLID.DLL Access: query
and write and read and execute Type: image Baseaddress: 507C0000 Size: 540672 Protection:
read write Mapped to pid: own pid
|
success or wait |
505443992 |
| Section loaded |
Path: \BaseNamedObjects\DfSharedHeap33678 Access: query and write and read Type: reserve
Baseaddress: 2320000 Size: 4194304 Protection: read write Mapped to pid: own pid
|
success or wait |
505647734 |
| File other operation |
Disposition: PositionInformation Data : Offset: 0 Path: C:\Documents and Settings\Administrator\Application
Data\Microsoft\Proof\CUSTOM.DIC
|
success or wait |
505649701 |
| File write |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\~$CUSTOM.DIC
Offset: none Length: 54 Value: 0D 48 61 6E 75 65 6C 65 20 42 61 73 65 72 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00
|
success or wait |
505651821 |
| File write |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\~$CUSTOM.DIC
Offset: none Length: 108 Value: 0D 00 48 00 61 00 6E 00 75 00 65 00 6C 00 65 00 20
00 42 00 61 00 73 00 65 00 72 00 00 00 00 00 08 00 00 00 02 00 48 00 42 00 00 00 61
00 00 00 09 00 00 00 0F 00 00 00 05 00 00 00 16 00 00 00 09 00 00 00 01 00 1C 2E D3
00 04 A4 2E D3 00 02 FC 2E D3 00 09 54 FC 8C 00 01 A0 FC 8C 00 08 FC FD 8C 00 0D
|
success or wait |
505652294 |
| File other operation |
Disposition: PositionInformation Data : Offset: 0 Path: C:\Documents and Settings\Administrator\Application
Data\Microsoft\Proof\CUSTOM.DIC
|
success or wait |
505655606 |
| File deleted |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\~$CUSTOM.DIC |
success or wait |
505656739 |
| File deleted |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\CUSTOM.DIC |
success or wait |
505658171 |
| File moved |
New path: unknown Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\~WRI0000 |
success or wait |
505659753 |
| Section loaded |
Path: \BaseNamedObjects\DfSharedHeap3369A Access: query and write and read Type: reserve
Baseaddress: 2320000 Size: 4194304 Protection: read write Mapped to pid: own pid
|
success or wait |
505660748 |
| Section loaded |
Path: \BaseNamedObjects\DfSharedHeap336AD Access: query and write and read Type: reserve
Baseaddress: 2320000 Size: 4194304 Protection: read write Mapped to pid: own pid
|
success or wait |
505665712 |
| File other operation |
Disposition: PositionInformation Data : Offset: 0 Path: C:\Documents and Settings\Administrator\Application
Data\Microsoft\Proof\CUSTOM.DIC
|
success or wait |
505667699 |
| File write |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\~$CUSTOM.DIC
Offset: none Length: 54 Value: 0D 48 61 6E 75 65 6C 65 20 42 61 73 65 72 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00
|
success or wait |
505669501 |
| File write |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\~$CUSTOM.DIC
Offset: none Length: 108 Value: 0D 00 48 00 61 00 6E 00 75 00 65 00 6C 00 65 00 20
00 42 00 61 00 73 00 65 00 72 00 00 00 00 00 08 00 00 00 02 00 48 00 42 00 00 00 61
00 00 00 09 00 00 00 0F 00 00 00 05 00 00 00 16 00 00 00 09 00 00 00 01 00 1C 2E D3
00 04 A4 2E D3 00 02 FC 2E D3 00 09 54 FC 8C 00 01 A0 FC 8C 00 08 FC FD 8C 00 0D
|
success or wait |
505670248 |
| File other operation |
Disposition: PositionInformation Data : Offset: 0 Path: C:\Documents and Settings\Administrator\Application
Data\Microsoft\Proof\CUSTOM.DIC
|
success or wait |
505670626 |
| File deleted |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\~$CUSTOM.DIC |
success or wait |
505671770 |
| File other operation |
Disposition: PositionInformation Data : Offset: 0 Path: C:\Documents and Settings\Administrator\Application
Data\Microsoft\Proof\CUSTOM.DIC
|
success or wait |
505674167 |
| File other operation |
Disposition: PositionInformation Data : Offset: 0 Path: C:\Documents and Settings\Administrator\Application
Data\Microsoft\Proof\CUSTOM.DIC
|
success or wait |
505678473 |
| Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\1033\MSGR3EN.DLL Access:
write and read and execute Type: commit Baseaddress: 2320000 Size: 3346432 Protection:
execute Mapped to pid: own pid
|
success or wait |
505747927 |
| Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\1033\MSGR3EN.DLL Access:
query and write and read and execute Type: image Baseaddress: 3F100000 Size: 3346432
Protection: read write Mapped to pid: own pid
|
success or wait |
505749487 |
| Message posted |
HWND: 10176 Message: C141 WParam: 0 LParam: 0 |
success |
506242420 |
| Message posted |
HWND: 10176 Message: C141 WParam: 0 LParam: 0 |
success |
506521867 |
| Message posted |
HWND: 10176 Message: C141 WParam: 0 LParam: 0 |
success |
506572531 |
| Message posted |
HWND: 10176 Message: C141 WParam: 0 LParam: 0 |
success |
506801343 |
| Message posted |
HWND: 10176 Message: C141 WParam: 0 LParam: 0 |
success |
506917942 |
| Message posted |
HWND: 10176 Message: C141 WParam: 0 LParam: 0 |
success |
506981770 |
| Message posted |
HWND: 10176 Message: C141 WParam: 0 LParam: 0 |
success |
507589571 |
| Message posted |
HWND: 10176 Message: C141 WParam: 0 LParam: 0 |
success |
507637926 |
| Message posted |
HWND: 10176 Message: C141 WParam: 0 LParam: 0 |
success |
507657754 |
| Message posted |
HWND: 10176 Message: C141 WParam: 0 LParam: 0 |
success |
507696464 |
| Message posted |
HWND: 10176 Message: C141 WParam: 0 LParam: 0 |
success |
507728734 |
| Message posted |
HWND: 10176 Message: C141 WParam: 0 LParam: 0 |
success |
507763189 |
| Message posted |
HWND: 10176 Message: C141 WParam: 0 LParam: 0 |
success |
507825459 |
| Message posted |
HWND: 10176 Message: C141 WParam: 0 LParam: 0 |
success |
508027309 |
| Thread created |
PID: 296 TID: 236 EIP: 7C8106F9 Imagepath: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
Injected: false
|
success or wait |
522514599 |
| Thread resumed |
TID: 236 PID: 296 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE |
success or wait |
522515316 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\unidrvui.dll Access: write and read
and execute Type: commit Baseaddress: 2B10000 Size: 745472 Protection: execute Mapped
to pid: own pid
|
success or wait |
522633679 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\unidrvui.dll Access: query and write
and read and execute Type: image Baseaddress: 7E5A0000 Size: 761856 Protection: read
write Mapped to pid: own pid
|
success or wait |
522638248 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2B10000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
522662126 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2B20000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
522678602 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2B20000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
522681392 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
522685568 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2B10000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
522706820 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2B20000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
522715428 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2B20000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
522717684 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
522719983 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2B10000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
522733826 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2B20000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
522742112 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2B20000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
522744791 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
522747012 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdrv.dll Access: write and read
and execute Type: commit Baseaddress: 2B10000 Size: 765952 Protection: execute Mapped
to pid: own pid
|
success or wait |
522765795 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdrv.dll Access: query and write
and read and execute Type: image Baseaddress: 3F500000 Size: 786432 Protection: read
write Mapped to pid: own pid
|
success or wait |
522768107 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2B20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
522783577 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2B30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
522793775 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2B30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
522796137 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
522798520 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2B20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
522814486 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2B30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
522823214 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2B30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
522825551 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
522827919 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2F20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
522848346 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2F30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
522857318 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2F30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
522859765 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
522862250 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2F20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
522877036 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2F30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
522885644 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2F30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
522888479 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
522890956 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2F20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
522905870 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2F30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
522914399 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2F30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
522916834 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
522919309 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2F20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
522938138 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2F30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
522948173 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2F30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
522950588 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
522953063 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2F20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
522968873 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2F30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
522977367 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2F30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
522979803 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
522982275 |
| Section loaded |
Path: C:\WINDOWS\system32\fontsub.dll Access: write and read and execute Type: commit
Baseaddress: 2F20000 Size: 81920 Protection: execute Mapped to pid: own pid
|
success or wait |
523009678 |
| Section loaded |
Path: C:\WINDOWS\system32\fontsub.dll Access: query and write and read and execute
Type: image Baseaddress: 69310000 Size: 94208 Protection: read write Mapped to pid:
own pid
|
success or wait |
523013270 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2F20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
523035435 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2F30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
523043938 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2F30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
523046295 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
523048679 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2F20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
523062704 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2F30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
523070124 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2F30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
523072447 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
523074824 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2F20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
523088795 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2F30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
523097110 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2F30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
523099654 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
523102379 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2F20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
523156349 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2F30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
523164623 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2F30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
523166905 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
523169223 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2F20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
523188169 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2F30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
523196431 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2F30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
523198727 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
523201037 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2F20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
523214815 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2F30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
523223084 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2F30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
523225357 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
523227674 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2F20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
523248229 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2F30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
523256575 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2F30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
523258944 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
523261305 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2F20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
523275299 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2F30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
523284168 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2F30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
523286589 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
523288974 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2F20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
523304272 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2F30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
523312868 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2F30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
523315484 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
523318234 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2F20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
523333537 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2F30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
523341931 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2F30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
523344462 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
523346939 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2F20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
523362613 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2F30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
523371214 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2F30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
523373738 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
523376330 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2F20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
523394715 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2F30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
523403375 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2F30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
523429375 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
523431876 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2F20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
523446693 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2F30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
523455349 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2F30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
523457985 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
523476963 |
| Section loaded |
Path: C:\WINDOWS\system32\fontsub.dll Access: write and read and execute Type: commit
Baseaddress: 2F20000 Size: 81920 Protection: execute Mapped to pid: own pid
|
success or wait |
523494024 |
| Section loaded |
Path: C:\WINDOWS\system32\fontsub.dll Access: query and write and read and execute
Type: image Baseaddress: 69310000 Size: 94208 Protection: read write Mapped to pid:
own pid
|
success or wait |
523496691 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2F20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
523504583 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2F30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
523513024 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2F30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
523515357 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
523517561 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2F20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
523531647 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2F30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
523540097 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2F30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
523542441 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
523544821 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2F20000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
523558865 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2F30000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
523567637 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2F30000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
523569999 |
| Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
523572780 |
| Section loaded |
Path: C:\Program Files\Common Files\System\ado\msadox.dll Access: write and read and
execute Type: commit Baseaddress: 1D90000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
531421658 |
| Section loaded |
Path: C:\Program Files\Common Files\System\ado\msadox.dll Access: query and read Type:
commit Baseaddress: 1D90000 Size: 200704 Protection: readonly Mapped to pid: own pid
|
success or wait |
531425462 |
| Section loaded |
Path: C:\Program Files\Common Files\System\ado\msadox.dll Access: write and read and
execute Type: commit Baseaddress: 1D90000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
531429866 |
| Section loaded |
Path: C:\Program Files\Common Files\System\ado\msadox.dll Access: query and read Type:
commit Baseaddress: 1D90000 Size: 200704 Protection: readonly Mapped to pid: own pid
|
success or wait |
531431976 |
| Section loaded |
Path: C:\Program Files\Messenger\msmsgs.exe Access: write and read and execute Type:
commit Baseaddress: 2B20000 Size: 1695744 Protection: execute Mapped to pid: own pid
|
success or wait |
531448606 |
| Section loaded |
Path: C:\Program Files\Messenger\msmsgs.exe Access: query and read Type: commit Baseaddress:
2B20000 Size: 1695744 Protection: readonly Mapped to pid: own pid
|
success or wait |
531452550 |
| Section loaded |
Path: C:\Program Files\Messenger\msmsgs.exe Access: write and read and execute Type:
commit Baseaddress: 2B20000 Size: 1695744 Protection: execute Mapped to pid: own pid
|
success or wait |
531468107 |
| Section loaded |
Path: C:\Program Files\Messenger\msmsgs.exe Access: query and read Type: commit Baseaddress:
2B20000 Size: 1695744 Protection: readonly Mapped to pid: own pid
|
success or wait |
531470228 |
| Message posted |
HWND: 2017C Message: 402 WParam: 0 LParam: 0 |
success |
549816878 |
| Message posted |
HWND: 2017C Message: 402 WParam: 0 LParam: 0 |
success |
549849168 |
| Message posted |
HWND: 2017C Message: 402 WParam: 0 LParam: 0 |
success |
550375178 |
| Message posted |
HWND: 101B6 Message: 402 WParam: 0 LParam: 0 |
success |
550619698 |
| Message posted |
HWND: 101B6 Message: 402 WParam: 0 LParam: 0 |
success |
562736260 |
| Message posted |
HWND: 2017C Message: 402 WParam: 0 LParam: 0 |
success |
575167317 |
| Message posted |
HWND: 101B6 Message: 402 WParam: 0 LParam: 0 |
success |
575368955 |
| Message posted |
HWND: 101B6 Message: 402 WParam: 0 LParam: 0 |
success |
587548030 |
| Message posted |
HWND: 2017C Message: 402 WParam: 0 LParam: 0 |
success |
600708778 |
| Message posted |
HWND: 2017C Message: 402 WParam: 0 LParam: 0 |
success |
600748468 |
| Message posted |
HWND: 2017C Message: 402 WParam: 0 LParam: 0 |
success |
613570676 |
| Message posted |
HWND: 101B6 Message: 402 WParam: 0 LParam: 0 |
success |
613811322 |
| Message posted |
HWND: 101B6 Message: 402 WParam: 0 LParam: 0 |
success |
625854965 |
| Message posted |
HWND: 2017C Message: 402 WParam: 0 LParam: 0 |
success |
688220306 |
| Message posted |
HWND: 2017C Message: 402 WParam: 0 LParam: 0 |
success |
688707957 |
| Message posted |
HWND: 101B6 Message: 402 WParam: 0 LParam: 0 |
success |
688909149 |
| Section loaded |
Path: \BaseNamedObjects\MSCTF.Shared.SFM.MAB Access: query and write and read Type:
reserve Baseaddress: 1D90000 Size: 524288 Protection: read write Mapped to pid: own
pid
|
success or wait |
691542707 |
| Message posted |
HWND: 2017C Message: 402 WParam: 0 LParam: 0 |
success |
701046757 |
| Message posted |
HWND: 2017C Message: 402 WParam: 0 LParam: 0 |
success |
752183198 |
| Message posted |
HWND: 2017C Message: 402 WParam: 0 LParam: 0 |
success |
789956247 |
| Message posted |
HWND: 101B6 Message: 402 WParam: 0 LParam: 0 |
success |
790821212 |
| Message posted |
HWND: 10180 Message: 402 WParam: 0 LParam: 0 |
success |
815804142 |