| Operation |
Data |
Completion |
Time |
| Section loaded |
Path: \KnownDlls\kernel32.dll Access: write and read and execute Type: unknown Baseaddress:
7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid
|
success or wait |
1955801872 |
| Section loaded |
Path: none Access: query and write and read and execute and extend size Type: reserve
Baseaddress: 7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid
|
success or wait |
1955805653 |
| Section loaded |
Path: \NLS\NlsSectionUnicode Access: read Type: unknown Baseaddress: 270000 Size:
90112 Protection: readonly Mapped to pid: own pid
|
success or wait |
1955809309 |
| Section loaded |
Path: \NLS\NlsSectionLocale Access: read Type: unknown Baseaddress: 290000 Size: 266240
Protection: readonly Mapped to pid: own pid
|
success or wait |
1955810646 |
| Section loaded |
Path: \NLS\NlsSectionSortkey Access: query and read Type: unknown Baseaddress: 2E0000
Size: 266240 Protection: readonly Mapped to pid: own pid
|
success or wait |
1955811750 |
| Section loaded |
Path: \NLS\NlsSectionSortTbls Access: read Type: unknown Baseaddress: 330000 Size:
24576 Protection: readonly Mapped to pid: own pid
|
success or wait |
1955812480 |
| Section loaded |
Path: \NLS\NlsSectionSortkey00000409 Access: read Type: unknown Baseaddress: 330000
Size: 24576 Protection: readonly Mapped to pid: own pid
|
object name not found |
1955813955 |
| Section loaded |
Path: \NLS\NlsSectionSortkey00000409 Access: read Type: unknown Baseaddress: 330000
Size: 24576 Protection: readonly Mapped to pid: own pid
|
object name not found |
1955814315 |
| Section loaded |
Path: \KnownDlls\USER32.dll Access: write and read and execute Type: unknown Baseaddress:
7E410000 Size: 593920 Protection: read write Mapped to pid: own pid
|
success or wait |
1955816902 |
| Section loaded |
Path: \KnownDlls\GDI32.dll Access: write and read and execute Type: unknown Baseaddress:
77F10000 Size: 299008 Protection: read write Mapped to pid: own pid
|
success or wait |
1955818144 |
| Section loaded |
Path: \KnownDlls\ADVAPI32.dll Access: write and read and execute Type: unknown Baseaddress:
77DD0000 Size: 634880 Protection: read write Mapped to pid: own pid
|
success or wait |
1955825207 |
| Section loaded |
Path: \KnownDlls\RPCRT4.dll Access: write and read and execute Type: unknown Baseaddress:
77E70000 Size: 602112 Protection: read write Mapped to pid: own pid
|
success or wait |
1955828697 |
| Section loaded |
Path: \KnownDlls\Secur32.dll Access: write and read and execute Type: unknown Baseaddress:
77FE0000 Size: 69632 Protection: read write Mapped to pid: own pid
|
success or wait |
1955833241 |
| Section loaded |
Path: \KnownDlls\SHELL32.dll Access: write and read and execute Type: unknown Baseaddress:
7C9C0000 Size: 8482816 Protection: read write Mapped to pid: own pid
|
success or wait |
1955839195 |
| Section loaded |
Path: \KnownDlls\msvcrt.dll Access: write and read and execute Type: unknown Baseaddress:
77C10000 Size: 360448 Protection: read write Mapped to pid: own pid
|
success or wait |
1955842982 |
| Section loaded |
Path: \KnownDlls\SHLWAPI.dll Access: write and read and execute Type: unknown Baseaddress:
77F60000 Size: 483328 Protection: read write Mapped to pid: own pid
|
success or wait |
1955848195 |
| Section loaded |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcp80.dll
Access: query and write and read and execute Type: image Baseaddress: 7C420000 Size:
552960 Protection: read write Mapped to pid: own pid
|
success or wait |
1955859403 |
| Section loaded |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcr80.dll
Access: query and write and read and execute Type: image Baseaddress: 78130000 Size:
634880 Protection: read write Mapped to pid: own pid
|
success or wait |
1955863016 |
| Section loaded |
Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit
Baseaddress: 340000 Size: 110592 Protection: execute Mapped to pid: own pid
|
success or wait |
1955875631 |
| Section loaded |
Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit
Baseaddress: 340000 Size: 110592 Protection: execute Mapped to pid: own pid
|
success or wait |
1955878184 |
| Section loaded |
Path: C:\WINDOWS\system32\imm32.dll Access: query and write and read and execute Type:
image Baseaddress: 76390000 Size: 118784 Protection: read write Mapped to pid: own
pid
|
success or wait |
1955880304 |
| Section loaded |
Path: \NLS\NlsSectionCType Access: read Type: unknown Baseaddress: 370000 Size: 12288
Protection: readonly Mapped to pid: own pid
|
success or wait |
1955897260 |
| Section loaded |
Path: C:\WINDOWS\system32\shell32.dll Access: read Type: commit Baseaddress: 940000
Size: 8462336 Protection: readonly Mapped to pid: own pid
|
success or wait |
1955903358 |
| Section loaded |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
Access: write and read and execute Type: commit Baseaddress: 940000 Size: 1056768
Protection: execute Mapped to pid: own pid
|
success or wait |
1955943472 |
| Section loaded |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
Access: query and write and read and execute Type: image Baseaddress: 773D0000 Size:
1060864 Protection: read write Mapped to pid: own pid
|
success or wait |
1955946104 |
| Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: write and read and execute Type: commit
Baseaddress: 390000 Size: 4096 Protection: execute Mapped to pid: own pid
|
success or wait |
1955955632 |
| Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: query and read Type: commit Baseaddress:
390000 Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
1955958518 |
| Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: read Type: commit Baseaddress: 390000
Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
1955960759 |
| Windows found |
Window Name: no string Class Name: AdobeAcrobatSpeedLaunchCmdWnd HWND: 0 |
success |
1956010752 |
| Windows found |
Window Name: no string Class Name: AdobeReaderSpeedLaunchCmdWnd HWND: 0 |
success |
1956011031 |
| Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\Setup Name: EnablePrefetcher |
success or wait |
1956012010 |
| Section loaded |
Path: \KnownDlls\AcroRd32.dll Access: write and read and execute Type: unknown Baseaddress:
390000 Size: 4096 Protection: readonly Mapped to pid: own pid
|
object name not found |
1956012959 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32.dll Access: query and write
and read and execute Type: image Baseaddress: 940000 Size: 20512768 Protection: read
write Mapped to pid: own pid
|
conflicting addresses |
1956014482 |
| Section loaded |
Path: \KnownDlls\WININET.dll Access: write and read and execute Type: unknown Baseaddress:
3D930000 Size: 942080 Protection: read write Mapped to pid: own pid
|
success or wait |
1956445064 |
| Section loaded |
Path: \KnownDlls\Normaliz.dll Access: write and read and execute Type: unknown Baseaddress:
3C0000 Size: 36864 Protection: read write Mapped to pid: own pid
|
conflicting addresses |
1956455582 |
| Section loaded |
Path: \KnownDlls\urlmon.dll Access: write and read and execute Type: unknown Baseaddress:
1CD0000 Size: 1257472 Protection: read write Mapped to pid: own pid
|
conflicting addresses |
1956465278 |
| Section loaded |
Path: \KnownDlls\ole32.dll Access: write and read and execute Type: unknown Baseaddress:
774E0000 Size: 1302528 Protection: read write Mapped to pid: own pid
|
success or wait |
1956504651 |
| Section loaded |
Path: \KnownDlls\OLEAUT32.dll Access: write and read and execute Type: unknown Baseaddress:
77120000 Size: 569344 Protection: read write Mapped to pid: own pid
|
success or wait |
1956520119 |
| Section loaded |
Path: \KnownDlls\iertutil.dll Access: write and read and execute Type: unknown Baseaddress:
3DFD0000 Size: 2002944 Protection: read write Mapped to pid: own pid
|
success or wait |
1956535657 |
| Section loaded |
Path: \KnownDlls\VERSION.dll Access: write and read and execute Type: unknown Baseaddress:
77C00000 Size: 32768 Protection: read write Mapped to pid: own pid
|
success or wait |
1956550999 |
| Section loaded |
Path: \KnownDlls\AGM.dll Access: write and read and execute Type: unknown Baseaddress:
77C00000 Size: 32768 Protection: read write Mapped to pid: own pid
|
object name not found |
1956554713 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\AGM.dll Access: query and write and
read and execute Type: image Baseaddress: 6000000 Size: 5902336 Protection: read write
Mapped to pid: own pid
|
success or wait |
1956558393 |
| Section loaded |
Path: \KnownDlls\CoolType.dll Access: write and read and execute Type: unknown Baseaddress:
6000000 Size: 5902336 Protection: read write Mapped to pid: own pid
|
object name not found |
1956591279 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\CoolType.dll Access: query and write
and read and execute Type: image Baseaddress: 8000000 Size: 2486272 Protection: read
write Mapped to pid: own pid
|
success or wait |
1956592917 |
| Section loaded |
Path: \KnownDlls\USERENV.dll Access: write and read and execute Type: unknown Baseaddress:
769C0000 Size: 737280 Protection: read write Mapped to pid: own pid
|
success or wait |
1956633207 |
| Section loaded |
Path: \KnownDlls\WINMM.dll Access: write and read and execute Type: unknown Baseaddress:
769C0000 Size: 737280 Protection: read write Mapped to pid: own pid
|
object name not found |
1956639446 |
| Section loaded |
Path: C:\WINDOWS\system32\winmm.dll Access: query and write and read and execute Type:
image Baseaddress: 76B40000 Size: 184320 Protection: read write Mapped to pid: own
pid
|
success or wait |
1956641078 |
| Section loaded |
Path: \KnownDlls\BIB.dll Access: write and read and execute Type: unknown Baseaddress:
76B40000 Size: 184320 Protection: read write Mapped to pid: own pid
|
object name not found |
1956647378 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\BIB.dll Access: query and write and
read and execute Type: image Baseaddress: 7000000 Size: 114688 Protection: read write
Mapped to pid: own pid
|
success or wait |
1956649299 |
| Section loaded |
Path: \KnownDlls\ACE.dll Access: write and read and execute Type: unknown Baseaddress:
7000000 Size: 114688 Protection: read write Mapped to pid: own pid
|
object name not found |
1956675094 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\ACE.dll Access: query and write and
read and execute Type: image Baseaddress: 5000000 Size: 798720 Protection: read write
Mapped to pid: own pid
|
success or wait |
1956676668 |
| Windows found |
Window Name: no string Class Name: AdobeAcrobatSpeedLaunchCmdWnd HWND: 0 |
success |
1956916510 |
| Windows found |
Window Name: no string Class Name: AdobeReaderSpeedLaunchCmdWnd HWND: 0 |
success |
1956916794 |
| Section loaded |
Path: C:\WINDOWS\system32\rpcss.dll Access: write and read and execute Type: commit
Baseaddress: 20C0000 Size: 401408 Protection: execute Mapped to pid: own pid
|
success or wait |
1956918468 |
| Section loaded |
Path: C:\WINDOWS\system32\msctf.dll Access: write and read and execute Type: commit
Baseaddress: 20C0000 Size: 299008 Protection: execute Mapped to pid: own pid
|
success or wait |
1957076390 |
| Section loaded |
Path: C:\WINDOWS\system32\msctf.dll Access: query and write and read and execute Type:
image Baseaddress: 74720000 Size: 311296 Protection: read write Mapped to pid: own
pid
|
success or wait |
1957079485 |
| Section loaded |
Path: \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read Type: commit Baseaddress: 74720000 Size: 311296 Protection:
read write Mapped to pid: own pid
|
object name exists |
1957086916 |
| Section loaded |
Path:
\BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-507921405-1960408961-839522115-500SFM.DefaultS-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read and execute and
extend size Type: unknown Baseaddress:
20D0000 Size: 262144 Protection: read write
Mapped to pid: own pid
|
success or wait |
1957096548 |
| Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: write and read and execute Type: commit
Baseaddress: 2110000 Size: 180224 Protection: execute Mapped to pid: own pid
|
success or wait |
1957107992 |
| Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: query and read Type: commit Baseaddress:
2110000 Size: 180224 Protection: readonly Mapped to pid: own pid
|
success or wait |
1957112435 |
| Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: write and read and execute Type: commit
Baseaddress: 2110000 Size: 180224 Protection: execute Mapped to pid: own pid
|
success or wait |
1957118811 |
| Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: query and read Type: commit Baseaddress:
2110000 Size: 180224 Protection: readonly Mapped to pid: own pid
|
success or wait |
1957122960 |
| Section loaded |
Path: \BaseNamedObjects\ShimSharedMemory Access: write Type: unknown Baseaddress:
2110000 Size: 57344 Protection: read write Mapped to pid: own pid
|
success or wait |
1957125951 |
| Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: write and read and execute Type: commit
Baseaddress: 2120000 Size: 180224 Protection: execute Mapped to pid: own pid
|
success or wait |
1957129772 |
| Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: query and write and read and execute
Type: image Baseaddress: 755C0000 Size: 188416 Protection: read write Mapped to pid:
own pid
|
success or wait |
1957133709 |
| Section loaded |
Path: C:\WINDOWS\system32\ieframe.dll Access: write and read and execute Type: commit
Baseaddress: 2120000 Size: 11083776 Protection: execute Mapped to pid: own pid
|
success or wait |
1957167332 |
| Section loaded |
Path: C:\WINDOWS\system32\ieframe.dll Access: query and write and read and execute
Type: image Baseaddress: 3E1C0000 Size: 11096064 Protection: read write Mapped to
pid: own pid
|
success or wait |
1957284019 |
| Section loaded |
Path: C:\WINDOWS\system32\en-us\ieframe.dll.mui Access: query and read Type: commit
Baseaddress: 2130000 Size: 1241088 Protection: write copy Mapped to pid: own pid
|
success or wait |
1957422019 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\RdLang32.DEU Access: write and read
and execute Type: commit Baseaddress: 2120000 Size: 7573504 Protection: execute Mapped
to pid: own pid
|
success or wait |
1957464796 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\RdLang32.DEU Access: query and read
Type: commit Baseaddress: 2120000 Size: 7573504 Protection: readonly Mapped to pid:
own pid
|
success or wait |
1957469008 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\RdLang32.DEU Access: write and read
and execute Type: commit Baseaddress: 2120000 Size: 7573504 Protection: execute Mapped
to pid: own pid
|
success or wait |
1957509206 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\RdLang32.DEU Access: query and read
Type: commit Baseaddress: 2120000 Size: 7573504 Protection: readonly Mapped to pid:
own pid
|
success or wait |
1957511680 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\RdLang32.DEU Access: write and read
and execute Type: commit Baseaddress: 2120000 Size: 7573504 Protection: execute Mapped
to pid: own pid
|
success or wait |
1957540749 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\RdLang32.DEU Access: query and write
and read and execute Type: image Baseaddress: 10000000 Size: 7573504 Protection: read
write Mapped to pid: own pid
|
success or wait |
1957545191 |
| Section loaded |
Path: \KnownDlls\SETUPAPI.dll Access: write and read and execute Type: unknown Baseaddress:
10000000 Size: 7573504 Protection: read write Mapped to pid: own pid
|
object name not found |
1957766725 |
| Section loaded |
Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute
Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid:
own pid
|
success or wait |
1957769585 |
| Section loaded |
Path: C:\WINDOWS\system32\winlogon.exe Access: write and read and execute Type: commit
Baseaddress: 2430000 Size: 507904 Protection: execute Mapped to pid: own pid
|
success or wait |
1958354713 |
| Section loaded |
Path: \KnownDlls\xpsp2res.dll Access: write and read and execute Type: unknown Baseaddress:
2430000 Size: 507904 Protection: execute Mapped to pid: own pid
|
object name not found |
1958362473 |
| Section loaded |
Path: C:\WINDOWS\system32\xpsp2res.dll Access: query and write and read and execute
Type: image Baseaddress: 2430000 Size: 2904064 Protection: read write Mapped to pid:
own pid
|
conflicting addresses |
1958364260 |
| Section loaded |
Path: \KnownDlls\UxTheme.dll Access: write and read and execute Type: unknown Baseaddress:
2430000 Size: 2904064 Protection: read write Mapped to pid: own pid
|
object name not found |
1958538292 |
| Section loaded |
Path: C:\WINDOWS\system32\uxtheme.dll Access: query and write and read and execute
Type: image Baseaddress: 5AD70000 Size: 229376 Protection: read write Mapped to pid:
own pid
|
success or wait |
1958540167 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Annots.api Access: write and
read and execute Type: commit Baseaddress: 2940000 Size: 4857856 Protection: execute
Mapped to pid: own pid
|
success or wait |
1958838027 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Annots.api Access: query and
write and read and execute Type: image Baseaddress: 22100000 Size: 4890624 Protection:
read write Mapped to pid: own pid
|
success or wait |
1958842434 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Annots.DEU Access: write and
read and execute Type: commit Baseaddress: 2950000 Size: 1712128 Protection: execute
Mapped to pid: own pid
|
success or wait |
1958934089 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Annots.DEU Access: query and
read Type: commit Baseaddress: 2950000 Size: 1712128 Protection: readonly Mapped to
pid: own pid
|
success or wait |
1958938131 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Annots.DEU Access: write and
read and execute Type: commit Baseaddress: 2950000 Size: 1712128 Protection: execute
Mapped to pid: own pid
|
success or wait |
1958950035 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Annots.DEU Access: query and
read Type: commit Baseaddress: 2950000 Size: 1712128 Protection: readonly Mapped to
pid: own pid
|
success or wait |
1958952335 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Annots.DEU Access: write and
read and execute Type: commit Baseaddress: 2950000 Size: 1712128 Protection: execute
Mapped to pid: own pid
|
success or wait |
1958958555 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Annots.DEU Access: query and
write and read and execute Type: image Baseaddress: 2950000 Size: 1712128 Protection:
read write Mapped to pid: own pid
|
conflicting addresses |
1958960823 |
| Section loaded |
Path: C:\WINDOWS\system32\ieframe.dll Access: write and read and execute Type: commit
Baseaddress: 2B10000 Size: 11083776 Protection: execute Mapped to pid: own pid
|
success or wait |
1959053357 |
| Section loaded |
Path: C:\WINDOWS\system32\ieframe.dll Access: query and write and read and execute
Type: image Baseaddress: 3E1C0000 Size: 11096064 Protection: read write Mapped to
pid: own pid
|
success or wait |
1959057120 |
| Section loaded |
Path: C:\WINDOWS\system32\en-us\ieframe.dll.mui Access: query and read Type: commit
Baseaddress: 2B20000 Size: 1241088 Protection: write copy Mapped to pid: own pid
|
success or wait |
1959208289 |
| Section loaded |
Path: C:\WINDOWS\system32\ieframe.dll Access: write and read and execute Type: commit
Baseaddress: 2B10000 Size: 11083776 Protection: execute Mapped to pid: own pid
|
success or wait |
1959518715 |
| Section loaded |
Path: C:\WINDOWS\system32\ieframe.dll Access: query and write and read and execute
Type: image Baseaddress: 3E1C0000 Size: 11096064 Protection: read write Mapped to
pid: own pid
|
success or wait |
1959520817 |
| Section loaded |
Path: C:\WINDOWS\system32\en-us\ieframe.dll.mui Access: query and read Type: commit
Baseaddress: 2B20000 Size: 1241088 Protection: write copy Mapped to pid: own pid
|
success or wait |
1959583922 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\SPPlugins\ADMPlugin.apl Access: write
and read and execute Type: commit Baseaddress: 2B10000 Size: 1392640 Protection: execute
Mapped to pid: own pid
|
success or wait |
1959729907 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\SPPlugins\ADMPlugin.apl Access: query
and read Type: commit Baseaddress: 2B10000 Size: 1392640 Protection: readonly Mapped
to pid: own pid
|
success or wait |
1959732657 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\SPPlugins\ADMPlugin.apl Access: write
and read and execute Type: commit Baseaddress: 2B10000 Size: 1392640 Protection: execute
Mapped to pid: own pid
|
success or wait |
1959739834 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\SPPlugins\ADMPlugin.apl Access: query
and write and read and execute Type: image Baseaddress: 4000000 Size: 1413120 Protection:
read write Mapped to pid: own pid
|
success or wait |
1959742431 |
| Section loaded |
Path: \KnownDlls\MSIMG32.dll Access: write and read and execute Type: unknown Baseaddress:
4000000 Size: 1413120 Protection: read write Mapped to pid: own pid
|
object name not found |
1959784099 |
| Section loaded |
Path: C:\WINDOWS\system32\msimg32.dll Access: query and write and read and execute
Type: image Baseaddress: 76380000 Size: 20480 Protection: read write Mapped to pid:
own pid
|
success or wait |
1959786006 |
| Section loaded |
Path: \KnownDlls\CLBCATQ.DLL Access: write and read and execute Type: unknown Baseaddress:
76380000 Size: 20480 Protection: read write Mapped to pid: own pid
|
object name not found |
1960005622 |
| Section loaded |
Path: C:\WINDOWS\system32\clbcatq.dll Access: query and write and read and execute
Type: image Baseaddress: 76FD0000 Size: 520192 Protection: read write Mapped to pid:
own pid
|
success or wait |
1960007783 |
| Section loaded |
Path: \KnownDlls\COMRes.dll Access: write and read and execute Type: unknown Baseaddress:
76FD0000 Size: 520192 Protection: read write Mapped to pid: own pid
|
object name not found |
1960010970 |
| Section loaded |
Path: C:\WINDOWS\system32\comres.dll Access: query and write and read and execute
Type: image Baseaddress: 77050000 Size: 806912 Protection: read write Mapped to pid:
own pid
|
success or wait |
1960013532 |
| Section loaded |
Path: C:\WINDOWS\system32\oleacc.dll Access: write and read and execute Type: commit
Baseaddress: 2B40000 Size: 163840 Protection: execute Mapped to pid: own pid
|
success or wait |
1960088341 |
| Section loaded |
Path: C:\WINDOWS\system32\oleacc.dll Access: query and write and read and execute
Type: image Baseaddress: 74C80000 Size: 180224 Protection: read write Mapped to pid:
own pid
|
success or wait |
1960094577 |
| Section loaded |
Path: \KnownDlls\MSVCP60.dll Access: write and read and execute Type: unknown Baseaddress:
74C80000 Size: 180224 Protection: read write Mapped to pid: own pid
|
object name not found |
1960102487 |
| Section loaded |
Path: C:\WINDOWS\system32\msvcp60.dll Access: query and write and read and execute
Type: image Baseaddress: 76080000 Size: 413696 Protection: read write Mapped to pid:
own pid
|
success or wait |
1960104836 |
| Section loaded |
Path: C:\WINDOWS\system32\oleaccrc.dll Access: query and read Type: commit Baseaddress:
2B40000 Size: 20480 Protection: readonly Mapped to pid: own pid
|
success or wait |
1960146783 |
| Section loaded |
Path: C:\WINDOWS\system32\oleacc.dll Access: query and read Type: commit Baseaddress:
2B50000 Size: 12288 Protection: readonly Mapped to pid: own pid
|
success or wait |
1960184144 |
| Section loaded |
Path: \KnownDlls\Msftedit.dll Access: write and read and execute Type: unknown Baseaddress:
2B50000 Size: 12288 Protection: readonly Mapped to pid: own pid
|
object name not found |
1960312488 |
| Section loaded |
Path: C:\WINDOWS\system32\msftedit.dll Access: query and write and read and execute
Type: image Baseaddress: 4B400000 Size: 548864 Protection: read write Mapped to pid:
own pid
|
success or wait |
1960314003 |
| Section loaded |
Path: C:\WINDOWS\system32\msimtf.dll Access: write and read and execute Type: commit
Baseaddress: 3020000 Size: 159744 Protection: execute Mapped to pid: own pid
|
success or wait |
1960328151 |
| Section loaded |
Path: C:\WINDOWS\system32\msimtf.dll Access: write and read and execute Type: commit
Baseaddress: 3020000 Size: 159744 Protection: execute Mapped to pid: own pid
|
success or wait |
1960330980 |
| Section loaded |
Path: C:\WINDOWS\system32\msimtf.dll Access: write and read and execute Type: commit
Baseaddress: 3020000 Size: 159744 Protection: execute Mapped to pid: own pid
|
success or wait |
1960339409 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\AcroForm.api Access: write
and read and execute Type: commit Baseaddress: 3020000 Size: 10436608 Protection:
execute Mapped to pid: own pid
|
success or wait |
1960817383 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\AcroForm.api Access: query
and write and read and execute Type: image Baseaddress: 20800000 Size: 11550720 Protection:
read write Mapped to pid: own pid
|
success or wait |
1960821059 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Acroform.DEU Access: write
and read and execute Type: commit Baseaddress: 3030000 Size: 999424 Protection: execute
Mapped to pid: own pid
|
success or wait |
1960850314 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Acroform.DEU Access: query
and read Type: commit Baseaddress: 3030000 Size: 999424 Protection: readonly Mapped
to pid: own pid
|
success or wait |
1960851842 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Acroform.DEU Access: write
and read and execute Type: commit Baseaddress: 3030000 Size: 999424 Protection: execute
Mapped to pid: own pid
|
success or wait |
1960854816 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Acroform.DEU Access: query
and read Type: commit Baseaddress: 3030000 Size: 999424 Protection: readonly Mapped
to pid: own pid
|
success or wait |
1960855592 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Acroform.DEU Access: write
and read and execute Type: commit Baseaddress: 3030000 Size: 999424 Protection: execute
Mapped to pid: own pid
|
success or wait |
1960857204 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Acroform.DEU Access: query
and write and read and execute Type: image Baseaddress: 3030000 Size: 999424 Protection:
read write Mapped to pid: own pid
|
conflicting addresses |
1960857997 |
| Section loaded |
Path: C:\WINDOWS\system32\ieframe.dll Access: write and read and execute Type: commit
Baseaddress: 3140000 Size: 11083776 Protection: execute Mapped to pid: own pid
|
success or wait |
1960892129 |
| Section loaded |
Path: C:\WINDOWS\system32\ieframe.dll Access: query and write and read and execute
Type: image Baseaddress: 3E1C0000 Size: 11096064 Protection: read write Mapped to
pid: own pid
|
success or wait |
1960893509 |
| Section loaded |
Path: C:\WINDOWS\system32\en-us\ieframe.dll.mui Access: query and read Type: commit
Baseaddress: 3150000 Size: 1241088 Protection: write copy Mapped to pid: own pid
|
success or wait |
1960935864 |
| Section loaded |
Path: C:\WINDOWS\system32\ieframe.dll Access: write and read and execute Type: commit
Baseaddress: 3140000 Size: 11083776 Protection: execute Mapped to pid: own pid
|
success or wait |
1960951208 |
| Section loaded |
Path: C:\WINDOWS\system32\ieframe.dll Access: query and write and read and execute
Type: image Baseaddress: 3E1C0000 Size: 11096064 Protection: read write Mapped to
pid: own pid
|
success or wait |
1960951962 |
| Section loaded |
Path: C:\WINDOWS\system32\en-us\ieframe.dll.mui Access: query and read Type: commit
Baseaddress: 3150000 Size: 1241088 Protection: write copy Mapped to pid: own pid
|
success or wait |
1960974878 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\EScript.api Access: write
and read and execute Type: commit Baseaddress: 3140000 Size: 1523712 Protection: execute
Mapped to pid: own pid
|
success or wait |
1960984717 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\EScript.api Access: query
and write and read and execute Type: image Baseaddress: 23800000 Size: 1544192 Protection:
read write Mapped to pid: own pid
|
success or wait |
1960986363 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Escript.deu Access: write
and read and execute Type: commit Baseaddress: 3150000 Size: 106496 Protection: execute
Mapped to pid: own pid
|
success or wait |
1961006423 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Escript.deu Access: query
and read Type: commit Baseaddress: 3150000 Size: 106496 Protection: readonly Mapped
to pid: own pid
|
success or wait |
1961008041 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Escript.deu Access: write
and read and execute Type: commit Baseaddress: 3150000 Size: 106496 Protection: execute
Mapped to pid: own pid
|
success or wait |
1961009739 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Escript.deu Access: query
and read Type: commit Baseaddress: 3150000 Size: 106496 Protection: readonly Mapped
to pid: own pid
|
success or wait |
1961010516 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Escript.deu Access: write
and read and execute Type: commit Baseaddress: 3150000 Size: 106496 Protection: execute
Mapped to pid: own pid
|
success or wait |
1961011448 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Escript.deu Access: query
and write and read and execute Type: image Baseaddress: 3150000 Size: 106496 Protection:
read write Mapped to pid: own pid
|
conflicting addresses |
1961012245 |
| Section loaded |
Path: C:\WINDOWS\system32\ieframe.dll Access: write and read and execute Type: commit
Baseaddress: 31C0000 Size: 11083776 Protection: execute Mapped to pid: own pid
|
success or wait |
1961071214 |
| Section loaded |
Path: C:\WINDOWS\system32\ieframe.dll Access: query and write and read and execute
Type: image Baseaddress: 3E1C0000 Size: 11096064 Protection: read write Mapped to
pid: own pid
|
success or wait |
1961072013 |
| Section loaded |
Path: C:\WINDOWS\system32\en-us\ieframe.dll.mui Access: query and read Type: commit
Baseaddress: 31D0000 Size: 1241088 Protection: write copy Mapped to pid: own pid
|
success or wait |
1961099134 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\DigSig.api Access: write and
read and execute Type: commit Baseaddress: 3CD0000 Size: 1282048 Protection: execute
Mapped to pid: own pid
|
success or wait |
1962914576 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\DigSig.api Access: query and
write and read and execute Type: image Baseaddress: 23000000 Size: 1298432 Protection:
read write Mapped to pid: own pid
|
success or wait |
1962916506 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\DigSig.DEU Access: write and
read and execute Type: commit Baseaddress: 31E0000 Size: 274432 Protection: execute
Mapped to pid: own pid
|
success or wait |
1962937887 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\DigSig.DEU Access: query and
read Type: commit Baseaddress: 31E0000 Size: 274432 Protection: readonly Mapped to
pid: own pid
|
success or wait |
1962939491 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\DigSig.DEU Access: write and
read and execute Type: commit Baseaddress: 31E0000 Size: 274432 Protection: execute
Mapped to pid: own pid
|
success or wait |
1962941577 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\DigSig.DEU Access: query and
read Type: commit Baseaddress: 31E0000 Size: 274432 Protection: readonly Mapped to
pid: own pid
|
success or wait |
1962942340 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\DigSig.DEU Access: write and
read and execute Type: commit Baseaddress: 31E0000 Size: 274432 Protection: execute
Mapped to pid: own pid
|
success or wait |
1962943366 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\DigSig.DEU Access: query and
write and read and execute Type: image Baseaddress: 31E0000 Size: 274432 Protection:
read write Mapped to pid: own pid
|
conflicting addresses |
1962944145 |
| Section loaded |
Path: \KnownDlls\AXE8SharedExpat.dll Access: write and read and execute Type: unknown
Baseaddress: 31E0000 Size: 274432 Protection: read write Mapped to pid: own pid
|
object name not found |
1962966882 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\AXE8SharedExpat.dll Access: query and
write and read and execute Type: image Baseaddress: 3240000 Size: 188416 Protection:
read write Mapped to pid: own pid
|
conflicting addresses |
1962968288 |
| Section loaded |
Path: \KnownDlls\AXSLE.dll Access: write and read and execute Type: unknown Baseaddress:
3240000 Size: 188416 Protection: read write Mapped to pid: own pid
|
object name not found |
1962983436 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\AXSLE.dll Access: query and write and
read and execute Type: image Baseaddress: 3CD0000 Size: 622592 Protection: read write
Mapped to pid: own pid
|
conflicting addresses |
1962984448 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\cryptocme2.dll Access: write and read
and execute Type: commit Baseaddress: 3D70000 Size: 401408 Protection: execute Mapped
to pid: own pid
|
success or wait |
1963269326 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\cryptocme2.dll Access: query and write
and read and execute Type: image Baseaddress: 3D70000 Size: 610304 Protection: read
write Mapped to pid: own pid
|
conflicting addresses |
1963271856 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\ccme_base.dll Access: write and read
and execute Type: commit Baseaddress: 3E10000 Size: 479232 Protection: execute Mapped
to pid: own pid
|
success or wait |
1966461823 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\ccme_base.dll Access: query and write
and read and execute Type: image Baseaddress: 3E10000 Size: 483328 Protection: read
write Mapped to pid: own pid
|
conflicting addresses |
1966468008 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\accessibility.DEU Access:
write and read and execute Type: commit Baseaddress: 3E90000 Size: 81920 Protection:
execute Mapped to pid: own pid
|
success or wait |
2054315050 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\accessibility.DEU Access:
query and read Type: commit Baseaddress: 3E90000 Size: 81920 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2054318885 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Accessibility.api Access:
write and read and execute Type: commit Baseaddress: 3E90000 Size: 442368 Protection:
execute Mapped to pid: own pid
|
success or wait |
2054329266 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Accessibility.api Access:
query and read Type: commit Baseaddress: 3E90000 Size: 442368 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2054332804 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Accessibility.api Access:
write and read and execute Type: commit Baseaddress: 3E90000 Size: 442368 Protection:
execute Mapped to pid: own pid
|
success or wait |
2054338600 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Accessibility.api Access:
query and read Type: commit Baseaddress: 3E90000 Size: 442368 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2054342184 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Checkers.DEU Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 192512 Protection: execute
Mapped to pid: own pid
|
success or wait |
2054392561 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Checkers.DEU Access: query
and read Type: commit Baseaddress: 3E90000 Size: 192512 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2054396051 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Checkers.api Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 839680 Protection: execute
Mapped to pid: own pid
|
success or wait |
2054409214 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Checkers.api Access: query
and read Type: commit Baseaddress: 3E90000 Size: 839680 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2054412016 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Checkers.api Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 839680 Protection: execute
Mapped to pid: own pid
|
success or wait |
2054418251 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Checkers.api Access: query
and read Type: commit Baseaddress: 3E90000 Size: 839680 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2054420866 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\DVA.DEU Access: write and
read and execute Type: commit Baseaddress: 32D0000 Size: 20480 Protection: execute
Mapped to pid: own pid
|
success or wait |
2054442853 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\DVA.DEU Access: query and
read Type: commit Baseaddress: 32D0000 Size: 20480 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2054446367 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\DVA.api Access: write and
read and execute Type: commit Baseaddress: 3E90000 Size: 135168 Protection: execute
Mapped to pid: own pid
|
success or wait |
2054449727 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\DVA.api Access: query and
read Type: commit Baseaddress: 3E90000 Size: 135168 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2054452385 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\DVA.api Access: write and
read and execute Type: commit Baseaddress: 3E90000 Size: 135168 Protection: execute
Mapped to pid: own pid
|
success or wait |
2054455746 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\DVA.api Access: query and
read Type: commit Baseaddress: 3E90000 Size: 135168 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2054458396 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\eBook.DEU Access: write and
read and execute Type: commit Baseaddress: 32D0000 Size: 24576 Protection: execute
Mapped to pid: own pid
|
success or wait |
2054462690 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\eBook.DEU Access: query and
read Type: commit Baseaddress: 32D0000 Size: 24576 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2054466971 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\eBook.api Access: write and
read and execute Type: commit Baseaddress: 32D0000 Size: 57344 Protection: execute
Mapped to pid: own pid
|
success or wait |
2054470226 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\eBook.api Access: query and
read Type: commit Baseaddress: 32D0000 Size: 57344 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2054472883 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\eBook.api Access: write and
read and execute Type: commit Baseaddress: 32D0000 Size: 57344 Protection: execute
Mapped to pid: own pid
|
success or wait |
2054475866 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\eBook.api Access: query and
read Type: commit Baseaddress: 32D0000 Size: 57344 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2054478825 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\IA32.DEU Access: write and
read and execute Type: commit Baseaddress: 32D0000 Size: 4096 Protection: execute
Mapped to pid: own pid
|
success or wait |
2054484284 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\IA32.DEU Access: query and
read Type: commit Baseaddress: 32D0000 Size: 4096 Protection: readonly Mapped to pid:
own pid
|
success or wait |
2054487629 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\IA32.api Access: write and
read and execute Type: commit Baseaddress: 3E90000 Size: 94208 Protection: execute
Mapped to pid: own pid
|
success or wait |
2054490416 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\IA32.api Access: query and
read Type: commit Baseaddress: 3E90000 Size: 94208 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2054493314 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\IA32.api Access: write and
read and execute Type: commit Baseaddress: 3E90000 Size: 94208 Protection: execute
Mapped to pid: own pid
|
success or wait |
2054496383 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\IA32.api Access: query and
read Type: commit Baseaddress: 3E90000 Size: 94208 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2054498973 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Hls.deu Access: write and
read and execute Type: commit Baseaddress: 3E90000 Size: 16384 Protection: execute
Mapped to pid: own pid
|
success or wait |
2054509800 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Hls.deu Access: query and
read Type: commit Baseaddress: 3E90000 Size: 16384 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2054513177 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\HLS.api Access: write and
read and execute Type: commit Baseaddress: 3E90000 Size: 53248 Protection: execute
Mapped to pid: own pid
|
success or wait |
2054517320 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\HLS.api Access: query and
read Type: commit Baseaddress: 3E90000 Size: 53248 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2054520808 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\HLS.api Access: write and
read and execute Type: commit Baseaddress: 3E90000 Size: 53248 Protection: execute
Mapped to pid: own pid
|
success or wait |
2054524641 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\HLS.api Access: query and
read Type: commit Baseaddress: 3E90000 Size: 53248 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2054528085 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\makeaccessible.DEU Access:
write and read and execute Type: commit Baseaddress: 3E90000 Size: 90112 Protection:
execute Mapped to pid: own pid
|
success or wait |
2054533632 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\makeaccessible.DEU Access:
query and read Type: commit Baseaddress: 3E90000 Size: 90112 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2054537072 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\MakeAccessible.api Access:
write and read and execute Type: commit Baseaddress: 4160000 Size: 2301952 Protection:
execute Mapped to pid: own pid
|
success or wait |
2054546115 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\MakeAccessible.api Access:
query and read Type: commit Baseaddress: 4160000 Size: 2301952 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2054549865 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\MakeAccessible.api Access:
write and read and execute Type: commit Baseaddress: 4160000 Size: 2301952 Protection:
execute Mapped to pid: own pid
|
success or wait |
2054561914 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\MakeAccessible.api Access:
query and read Type: commit Baseaddress: 4160000 Size: 2301952 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2054564540 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Multimedia.DEU Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 155648 Protection: execute
Mapped to pid: own pid
|
success or wait |
2054574238 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Multimedia.DEU Access: query
and read Type: commit Baseaddress: 3E90000 Size: 155648 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2054578859 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Multimedia.api Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 1409024 Protection: execute
Mapped to pid: own pid
|
success or wait |
2054590678 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Multimedia.api Access: query
and read Type: commit Baseaddress: 3E90000 Size: 1409024 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2054593320 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Multimedia.api Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 1409024 Protection: execute
Mapped to pid: own pid
|
success or wait |
2054601644 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Multimedia.api Access: query
and read Type: commit Baseaddress: 3E90000 Size: 1409024 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2054604313 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\pddom.DEU Access: write and
read and execute Type: commit Baseaddress: 3E90000 Size: 12288 Protection: execute
Mapped to pid: own pid
|
success or wait |
2054612368 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\pddom.DEU Access: query and
read Type: commit Baseaddress: 3E90000 Size: 12288 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2054616521 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\PDDom.api Access: write and
read and execute Type: commit Baseaddress: 3E90000 Size: 401408 Protection: execute
Mapped to pid: own pid
|
success or wait |
2054620117 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\PDDom.api Access: query and
read Type: commit Baseaddress: 3E90000 Size: 401408 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2054623034 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\PDDom.api Access: write and
read and execute Type: commit Baseaddress: 3E90000 Size: 401408 Protection: execute
Mapped to pid: own pid
|
success or wait |
2054627362 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\PDDom.api Access: query and
read Type: commit Baseaddress: 3E90000 Size: 401408 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2054630005 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\PPKLITE.DEU Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 1060864 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055355406 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\PPKLITE.DEU Access: query
and read Type: commit Baseaddress: 3E90000 Size: 1060864 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055367410 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\PPKLite.api Access: write
and read and execute Type: commit Baseaddress: 4160000 Size: 6959104 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055439688 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\PPKLite.api Access: query
and read Type: commit Baseaddress: 4160000 Size: 6959104 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055442463 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\PPKLite.api Access: write
and read and execute Type: commit Baseaddress: 4160000 Size: 6959104 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055473333 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\PPKLite.api Access: query
and read Type: commit Baseaddress: 4160000 Size: 6959104 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055476833 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\ReadOutLoud.DEU Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 16384 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055496505 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\ReadOutLoud.DEU Access: query
and read Type: commit Baseaddress: 3E90000 Size: 16384 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055500532 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\ReadOutLoud.api Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 110592 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055504269 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\ReadOutLoud.api Access: query
and read Type: commit Baseaddress: 3E90000 Size: 110592 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055506933 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\ReadOutLoud.api Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 110592 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055510106 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\ReadOutLoud.api Access: query
and read Type: commit Baseaddress: 3E90000 Size: 110592 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055513515 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\reflow.DEU Access: write and
read and execute Type: commit Baseaddress: 3E90000 Size: 8192 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055518090 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\reflow.DEU Access: query and
read Type: commit Baseaddress: 3E90000 Size: 8192 Protection: readonly Mapped to pid:
own pid
|
success or wait |
2055521552 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\reflow.api Access: write and
read and execute Type: commit Baseaddress: 3E90000 Size: 364544 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055524913 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\reflow.api Access: query and
read Type: commit Baseaddress: 3E90000 Size: 364544 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2055527522 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\reflow.api Access: write and
read and execute Type: commit Baseaddress: 3E90000 Size: 364544 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055531673 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\reflow.api Access: query and
read Type: commit Baseaddress: 3E90000 Size: 364544 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2055534268 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\SaveAsRTF.DEU Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 24576 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055540326 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\SaveAsRTF.DEU Access: query
and read Type: commit Baseaddress: 3E90000 Size: 24576 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055543881 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\SaveAsRTF.api Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 348160 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055548647 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\SaveAsRTF.api Access: query
and read Type: commit Baseaddress: 3E90000 Size: 348160 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055551595 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\SaveAsRTF.api Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 348160 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055555176 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\SaveAsRTF.api Access: query
and read Type: commit Baseaddress: 3E90000 Size: 348160 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055557783 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Search.DEU Access: write and
read and execute Type: commit Baseaddress: 3E90000 Size: 57344 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055562339 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Search.DEU Access: query and
read Type: commit Baseaddress: 3E90000 Size: 57344 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2055566067 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Search.api Access: write and
read and execute Type: commit Baseaddress: 3E90000 Size: 401408 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055578411 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Search.api Access: query and
read Type: commit Baseaddress: 3E90000 Size: 401408 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2055581042 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Search.api Access: write and
read and execute Type: commit Baseaddress: 3E90000 Size: 401408 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055586448 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Search.api Access: query and
read Type: commit Baseaddress: 3E90000 Size: 401408 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2055589117 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Search5.DEU Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 12288 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055595136 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Search5.DEU Access: query
and read Type: commit Baseaddress: 3E90000 Size: 12288 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055598886 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Search5.api Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 90112 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055602500 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Search5.api Access: query
and read Type: commit Baseaddress: 3E90000 Size: 90112 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055605148 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Search5.api Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 90112 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055608224 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Search5.api Access: query
and read Type: commit Baseaddress: 3E90000 Size: 90112 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055610833 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\SendMail.deu Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 28672 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055616340 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\SendMail.deu Access: query
and read Type: commit Baseaddress: 3E90000 Size: 28672 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055619826 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\SendMail.api Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 122880 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055625197 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\SendMail.api Access: query
and read Type: commit Baseaddress: 3E90000 Size: 122880 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055627883 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\SendMail.api Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 122880 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055631103 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\SendMail.api Access: query
and read Type: commit Baseaddress: 3E90000 Size: 122880 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055633706 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Spelling.DEU Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 36864 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055639002 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Spelling.DEU Access: query
and read Type: commit Baseaddress: 3E90000 Size: 36864 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055642587 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Spelling.api Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 274432 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055646512 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Spelling.api Access: query
and read Type: commit Baseaddress: 3E90000 Size: 274432 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055649141 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Spelling.api Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 274432 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055652974 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Spelling.api Access: query
and read Type: commit Baseaddress: 3E90000 Size: 274432 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055655567 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\updater.DEU Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 12288 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055662550 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\updater.DEU Access: query
and read Type: commit Baseaddress: 3E90000 Size: 12288 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055666428 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Updater.api Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 233472 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055670068 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Updater.api Access: query
and read Type: commit Baseaddress: 3E90000 Size: 233472 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055672675 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Updater.api Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 233472 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055676315 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Updater.api Access: query
and read Type: commit Baseaddress: 3E90000 Size: 233472 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055678982 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Weblink.DEU Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 49152 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055684605 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Weblink.DEU Access: query
and read Type: commit Baseaddress: 3E90000 Size: 49152 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055688091 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\weblink.api Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 270336 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055694449 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\weblink.api Access: query
and read Type: commit Baseaddress: 3E90000 Size: 270336 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055697139 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\weblink.api Access: write
and read and execute Type: commit Baseaddress: 3E90000 Size: 270336 Protection: execute
Mapped to pid: own pid
|
success or wait |
2055701734 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\weblink.api Access: query
and read Type: commit Baseaddress: 3E90000 Size: 270336 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2055704384 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\PPKLite.api Access: write
and read and execute Type: commit Baseaddress: 4160000 Size: 6959104 Protection: execute
Mapped to pid: own pid
|
success or wait |
2056246115 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\PPKLite.api Access: query
and write and read and execute Type: image Baseaddress: 28000000 Size: 6983680 Protection:
read write Mapped to pid: own pid
|
success or wait |
2056248513 |
| Section loaded |
Path: \KnownDlls\WSOCK32.dll Access: write and read and execute Type: unknown Baseaddress:
28000000 Size: 6983680 Protection: read write Mapped to pid: own pid
|
object name not found |
2056283452 |
| Section loaded |
Path: C:\WINDOWS\system32\wsock32.dll Access: query and write and read and execute
Type: image Baseaddress: 71AD0000 Size: 36864 Protection: read write Mapped to pid:
own pid
|
success or wait |
2056285094 |
| Section loaded |
Path: \KnownDlls\WS2_32.dll Access: write and read and execute Type: unknown Baseaddress:
71AD0000 Size: 36864 Protection: read write Mapped to pid: own pid
|
object name not found |
2056288514 |
| Section loaded |
Path: C:\WINDOWS\system32\ws2_32.dll Access: query and write and read and execute
Type: image Baseaddress: 71AB0000 Size: 94208 Protection: read write Mapped to pid:
own pid
|
success or wait |
2056290270 |
| Section loaded |
Path: \KnownDlls\WS2HELP.dll Access: write and read and execute Type: unknown Baseaddress:
71AB0000 Size: 94208 Protection: read write Mapped to pid: own pid
|
object name not found |
2056296061 |
| Section loaded |
Path: C:\WINDOWS\system32\ws2help.dll Access: query and write and read and execute
Type: image Baseaddress: 71AA0000 Size: 32768 Protection: read write Mapped to pid:
own pid
|
success or wait |
2056297881 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\PPKLITE.DEU Access: write
and read and execute Type: commit Baseaddress: 3EC0000 Size: 1060864 Protection: execute
Mapped to pid: own pid
|
success or wait |
2056333935 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\PPKLITE.DEU Access: query
and read Type: commit Baseaddress: 3EC0000 Size: 1060864 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2056336205 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\PPKLITE.DEU Access: write
and read and execute Type: commit Baseaddress: 3EC0000 Size: 1060864 Protection: execute
Mapped to pid: own pid
|
success or wait |
2056348099 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\PPKLITE.DEU Access: query
and read Type: commit Baseaddress: 3EC0000 Size: 1060864 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2056350363 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\PPKLITE.DEU Access: write
and read and execute Type: commit Baseaddress: 3EC0000 Size: 1060864 Protection: execute
Mapped to pid: own pid
|
success or wait |
2056354575 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\PPKLITE.DEU Access: query
and write and read and execute Type: image Baseaddress: 3EC0000 Size: 1060864 Protection:
read write Mapped to pid: own pid
|
conflicting addresses |
2056356163 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\CourierStd.otf Access: query
and read Type: commit Baseaddress: 3FE0000 Size: 36864 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2056466377 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\CourierStd.otf Access: query
and read Type: commit Baseaddress: 3FE0000 Size: 36864 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2056476851 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\icucnv36.dll Access: write and read
and execute Type: commit Baseaddress: 4160000 Size: 679936 Protection: execute Mapped
to pid: own pid
|
success or wait |
2056558396 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\icucnv36.dll Access: query and write
and read and execute Type: image Baseaddress: 4A800000 Size: 684032 Protection: read
write Mapped to pid: own pid
|
success or wait |
2056563294 |
| Section loaded |
Path: \KnownDlls\icudt36.dll Access: write and read and execute Type: unknown Baseaddress:
4A800000 Size: 684032 Protection: read write Mapped to pid: own pid
|
object name not found |
2056588763 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\icudt36.dll Access: query and write
and read and execute Type: image Baseaddress: 4AD00000 Size: 94208 Protection: read
write Mapped to pid: own pid
|
success or wait |
2056592728 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\CourierStd-Oblique.otf Access:
query and read Type: commit Baseaddress: 3FE0000 Size: 40960 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2057538196 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\CourierStd-Oblique.otf Access:
query and read Type: commit Baseaddress: 3FE0000 Size: 40960 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2057541887 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\CourierStd-Bold.otf Access:
query and read Type: commit Baseaddress: 3FE0000 Size: 36864 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2057548741 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\CourierStd-Bold.otf Access:
query and read Type: commit Baseaddress: 3FE0000 Size: 36864 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2057552131 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\CourierStd-BoldOblique.otf Access:
query and read Type: commit Baseaddress: 3FE0000 Size: 40960 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2057558509 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\CourierStd-BoldOblique.otf Access:
query and read Type: commit Baseaddress: 3FE0000 Size: 40960 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2057562162 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\SY______.PFB Access: query and
read Type: commit Baseaddress: 3FE0000 Size: 36864 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2057665404 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\AdobePiStd.otf Access: query
and read Type: commit Baseaddress: 4160000 Size: 90112 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2057693277 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\AdobePiStd.otf Access: query
and read Type: commit Baseaddress: 4160000 Size: 90112 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2057696253 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\CMap\Identity-H Access: query and
read Type: commit Baseaddress: 3FE0000 Size: 8192 Protection: readonly Mapped to pid:
own pid
|
success or wait |
2057743629 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\CMap\Identity-V Access: query and
read Type: commit Baseaddress: 3FE0000 Size: 4096 Protection: readonly Mapped to pid:
own pid
|
success or wait |
2057760977 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\CMap\Identity-H Access: query and
read Type: commit Baseaddress: 3FE0000 Size: 8192 Protection: readonly Mapped to pid:
own pid
|
success or wait |
2058487450 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\CMap\Identity-V Access: query and
read Type: commit Baseaddress: 3FE0000 Size: 4096 Protection: readonly Mapped to pid:
own pid
|
success or wait |
2058503346 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\AdobePiStd.otf Access: query
and read Type: commit Baseaddress: 4160000 Size: 90112 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2058564215 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\AdobePiStd.otf Access: query
and read Type: commit Baseaddress: 4160000 Size: 90112 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2058566456 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\CourierStd-Bold.otf Access:
query and read Type: commit Baseaddress: 3FE0000 Size: 36864 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2058603889 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\CourierStd-Bold.otf Access:
query and read Type: commit Baseaddress: 3FE0000 Size: 36864 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2058606158 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\CourierStd-BoldOblique.otf Access:
query and read Type: commit Baseaddress: 3FE0000 Size: 40960 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2058642141 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\CourierStd-BoldOblique.otf Access:
query and read Type: commit Baseaddress: 3FE0000 Size: 40960 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2058644394 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\CourierStd-Oblique.otf Access:
query and read Type: commit Baseaddress: 3FE0000 Size: 40960 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2058680551 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\CourierStd-Oblique.otf Access:
query and read Type: commit Baseaddress: 3FE0000 Size: 40960 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2058682805 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\CourierStd.otf Access: query
and read Type: commit Baseaddress: 3FE0000 Size: 36864 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2058718826 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\CourierStd.otf Access: query
and read Type: commit Baseaddress: 3FE0000 Size: 36864 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2058721067 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MinionPro-Bold.otf Access: query
and read Type: commit Baseaddress: 4160000 Size: 233472 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2058805033 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MinionPro-Bold.otf Access: query
and read Type: commit Baseaddress: 4160000 Size: 233472 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2058807319 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MinionPro-BoldIt.otf Access:
query and read Type: commit Baseaddress: 4160000 Size: 278528 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2058901924 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MinionPro-BoldIt.otf Access:
query and read Type: commit Baseaddress: 4160000 Size: 278528 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2058904203 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MinionPro-It.otf Access: query
and read Type: commit Baseaddress: 4160000 Size: 278528 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2058997464 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MinionPro-It.otf Access: query
and read Type: commit Baseaddress: 4160000 Size: 278528 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2058999740 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MinionPro-Regular.otf Access:
query and read Type: commit Baseaddress: 4160000 Size: 233472 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2059515649 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MinionPro-Regular.otf Access:
query and read Type: commit Baseaddress: 4160000 Size: 233472 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2059522093 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MyriadPro-Bold.otf Access: query
and read Type: commit Baseaddress: 4160000 Size: 98304 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2059713102 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MyriadPro-Bold.otf Access: query
and read Type: commit Baseaddress: 4160000 Size: 98304 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2059719550 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MyriadPro-BoldIt.otf Access:
query and read Type: commit Baseaddress: 4160000 Size: 102400 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2059883164 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MyriadPro-BoldIt.otf Access:
query and read Type: commit Baseaddress: 4160000 Size: 102400 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2059889730 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MyriadPro-It.otf Access: query
and read Type: commit Baseaddress: 4160000 Size: 98304 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2060050805 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MyriadPro-It.otf Access: query
and read Type: commit Baseaddress: 4160000 Size: 98304 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2060057228 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MyriadPro-Regular.otf Access:
query and read Type: commit Baseaddress: 4160000 Size: 98304 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2060962128 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MyriadPro-Regular.otf Access:
query and read Type: commit Baseaddress: 4160000 Size: 98304 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2060968662 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\SY______.PFB Access: query and
read Type: commit Baseaddress: 3FE0000 Size: 36864 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2060995610 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\ZX______.PFB Access: query and
read Type: commit Baseaddress: 4160000 Size: 77824 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2061045288 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\ZY______.PFB Access: query and
read Type: commit Baseaddress: 4160000 Size: 98304 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2061086096 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\CMap\Identity-H Access: query and
read Type: commit Baseaddress: 3FE0000 Size: 8192 Protection: readonly Mapped to pid:
own pid
|
success or wait |
2061441758 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\CMap\Identity-V Access: query and
read Type: commit Baseaddress: 3FE0000 Size: 4096 Protection: readonly Mapped to pid:
own pid
|
success or wait |
2061490225 |
| Section loaded |
Path: \KnownDlls\ATMLIB.dll Access: write and read and execute Type: unknown Baseaddress:
3FE0000 Size: 4096 Protection: readonly Mapped to pid: own pid
|
object name not found |
2061495370 |
| Section loaded |
Path: C:\WINDOWS\system32\atmlib.dll Access: query and write and read and execute
Type: image Baseaddress: 73C20000 Size: 45056 Protection: read write Mapped to pid:
own pid
|
success or wait |
2061500002 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\CourierStd.otf Access: query
and read Type: commit Baseaddress: 3FE0000 Size: 36864 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2061541934 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\CourierStd-Oblique.otf Access:
query and read Type: commit Baseaddress: 3FE0000 Size: 40960 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2061546104 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\CourierStd-Bold.otf Access:
query and read Type: commit Baseaddress: 3FE0000 Size: 36864 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2061550165 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\CourierStd-BoldOblique.otf Access:
query and read Type: commit Baseaddress: 3FE0000 Size: 40960 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2061554225 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\SY______.PFB Access: query and
read Type: commit Baseaddress: 3FE0000 Size: 36864 Protection: readonly Mapped to
pid: own pid
|
success or wait |
2061560877 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\AdobePiStd.otf Access: query
and read Type: commit Baseaddress: 4160000 Size: 90112 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2061571595 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MinionPro-Bold.otf Access: query
and read Type: commit Baseaddress: 4160000 Size: 233472 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2061575643 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MinionPro-BoldIt.otf Access:
query and read Type: commit Baseaddress: 4160000 Size: 278528 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2061579779 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MinionPro-It.otf Access: query
and read Type: commit Baseaddress: 4160000 Size: 278528 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2061583838 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MinionPro-Regular.otf Access:
query and read Type: commit Baseaddress: 4160000 Size: 233472 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2061587884 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MyriadPro-Bold.otf Access: query
and read Type: commit Baseaddress: 4160000 Size: 98304 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2061591916 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MyriadPro-BoldIt.otf Access:
query and read Type: commit Baseaddress: 4160000 Size: 102400 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2061596342 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MyriadPro-It.otf Access: query
and read Type: commit Baseaddress: 4160000 Size: 98304 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2061600759 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Resource\Font\MyriadPro-Regular.otf Access:
query and read Type: commit Baseaddress: 4160000 Size: 98304 Protection: readonly
Mapped to pid: own pid
|
success or wait |
2061604953 |
| Section loaded |
Path: \BaseNamedObjects\Local\UrlZonesSM_Administrator Access: query and write and
read Type: commit Baseaddress: 4160000 Size: 98304 Protection: readonly Mapped to
pid: own pid
|
object name exists |
2063307901 |
| Section loaded |
Path: \KnownDlls\BIBUtils.dll Access: write and read and execute Type: unknown Baseaddress:
4160000 Size: 98304 Protection: readonly Mapped to pid: own pid
|
object name not found |
2081300516 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\BIBUtils.dll Access: query and write
and read and execute Type: image Baseaddress: 4FB0000 Size: 167936 Protection: read
write Mapped to pid: own pid
|
conflicting addresses |
2081303444 |
| Section loaded |
Path: none Access: query and write and read and execute Type: commit Baseaddress:
4FE0000 Size: 65536 Protection: execute and read and write Mapped to pid: own pid
|
success or wait |
2081506206 |
| File created |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Access: read attributes and
synchronize and generic read and generic write Options: synchronous io non alert and
non directory file Attributes: normal Content Overwritten: false
|
success or wait |
2081510170 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 4D 48 82 12 11
12 12 12 16 12 12 12 ED ED 12 12 AA 12 12 12 12 12 12 12 52 12 12 12 12 12 12 12 12
12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 CA
12 12 12 1C 0D A8 1C 12 A6 1B DF 33 AA 13 5E DF 33 46 7A 7B 61 32 62 60 7D 75 60 73
7F 32 71 73 7C 7C 7D 66 32 70 77
|
success or wait |
2081513806 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 70
72 6F 67 72 61 6D 20 63 61 6E 6E 6F 74 20 62 65
|
success or wait |
2081514846 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 47 99 FE AA 06
30 12 12 FA 11 1B 12 12 41 44 45 AB 50 12 12 12 AC 02 22 52 12 9F AF 46 F4 ED ED 9F
97 9A E1 ED ED E1 B7 42 FA A0 17 12 12 91 D6 16 97 D2 1D 96 58 16 12 12 AB 92 12 12
12 21 D2 9F AF A2 E9 ED ED 9F 87 A2 E9 ED ED E1 B9 9F 5F EA D5 57 EA 12 13 12 12 43
40 ED 07 12 32 52 12 99 27 3A 32
|
success or wait |
2081515998 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
55 8B EC B8 14 22 00 00 E8 03 09 00 00 53 56 57 B9 42 00 00 00 BE 10 30 40 00 8D BD
54 E6 FF FF 8D 85 88 F3 FF FF F3 A5 50 E8 B2 05 00 00 83 C4 04 85 C0 0F 84 4A 04 00
00 B9 80 00 00 00 33 C0 8D BD B0 FB FF FF 8D 95 B0 FB FF FF F3 AB 8D 4D F8 C7 45 F8
00 01 00 00 51 52 FF 15 00 20 40 00 8B 35 28 20
|
success or wait |
2081517095 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 52 12 9F 97 E2
EF ED ED 78 12 9F 9F B2 E5 ED ED 42 43 ED C4 FB D1 12 12 12 99 27 92 32 52 12 78 76
ED C4 78 76 ED C4 9F 87 C6 F4 ED ED 40 FA DF 12 12 12 91 D6 16 9B 97 96 E1 ED ED 97
D2 66 CD 9F 97 66 FF ED ED 42 ED 07 9A 32 52 12 97 D2 66 3C 7A 0A 23 52 12 42 ED 07
9E 32 52 12 99 E2 97 E4 66 0E 9F
|
success or wait |
2081517198 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
40 00 8D 85 F0 FD FF FF 6A 00 8D 8D A0 F7 FF FF 50 51 FF D6 E9 C3 00 00 00 8B 35 80
20 40 00 6A 64 FF D6 6A 64 FF D6 8D 95 D4 E6 FF FF 52 E8 CD 00 00 00 83 C4 04 89 85
84 F3 FF FF 85 C0 74 DF 8D 85 74 ED FF FF 50 FF 15 88 20 40 00 85 C0 74 2E 68 18 31
40 00 50 FF 15 8C 20 40 00 8B F0 85 F6 74 1C 8D
|
success or wait |
2081518332 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 36 06 2E 12 12
12 D5 56 36 32 EE 23 52 12 9B 46 36 36 9B 56 36 3A D5 56 36 0A 52 12 12 12 ED C5 99
27 7A 32 52 12 42 ED C4 99 0F 76 32 52 12 78 1D ED C1 99 3F 72 32 52 12 42 ED C7 9F
5E 36 02 43 ED 07 FE 32 52 12 97 D2 66 53 99 46 36 5A 78 52 40 ED C4 99 56 36 5A 78
13 42 ED 07 4E 32 52 12 9F 5E 36
|
success or wait |
2081518433 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
24 14 3C 00 00 00 C7 44 24 20 FC 31 40 00 89 54 24 24 89 44 24 28 C7 44 24 18 40 00
00 00 FF D7 8B 35 68 20 40 00 50 FF D6 8B 1D 64 20 40 00 6A 0F FF D3 8B 2D 60 20 40
00 50 FF D5 8D 4C 24 10 51 FF 15 EC 20 40 00 85 C0 74 41 8B 54 24 48 6A 40 52 FF D6
8B 44 24 48 6A 01 50 FF 15 5C 20 40 00 8D 4C 24
|
success or wait |
2081519485 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 84 34 12 12 12
12 12 12 4E 31 12 12 7A 31 12 12 68 31 12 12 94 31 12 12 88 31 12 12 A2 31 12 12 AE
31 12 12 DA 31 12 12 C6 31 12 12 F2 31 12 12 E0 31 12 12 16 36 12 12 32 36 12 12 22
36 12 12 54 31 12 12 58 36 12 12 4A 36 12 12 7A 36 12 12 64 36 12 12 94 36 12 12 8A
36 12 12 BA 36 12 12 D0 36 12 12
|
success or wait |
2081519585 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
96 26 00 00 00 00 00 00 5C 23 00 00 68 23 00 00 7A 23 00 00 86 23 00 00 9A 23 00 00
B0 23 00 00 BC 23 00 00 C8 23 00 00 D4 23 00 00 E0 23 00 00 F2 23 00 00 04 24 00 00
20 24 00 00 30 24 00 00 46 23 00 00 4A 24 00 00 58 24 00 00 68 24 00 00 76 24 00 00
86 24 00 00 98 24 00 00 A8 24 00 00 C2 24 00 00
|
success or wait |
2081520628 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 61 66 45 12 7E
12 51 60 77 73 66 77 46 7D 7D 7E 7A 77 7E 62 21 20 41 7C 73 62 61 7A 7D 66 12 12 F2
13 55 77 66 44 77 60 61 7B 7D 7C 57 6A 45 12 E7 13 55 7E 7D 70 73 7E 54 60 77 77 12
12 85 11 45 60 7B 66 77 54 7B 7E 77 12 42 12 51 60 77 73 66 77 54 7B 7E 77 45 12 49
10 5E 7D 71 79 40 77 61 7D 67 60
|
success or wait |
2081521567 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
73 74 57 00 6C 00 43 72 65 61 74 65 54 6F 6F 6C 68 65 6C 70 33 32 53 6E 61 70 73 68
6F 74 00 00 E0 01 47 65 74 56 65 72 73 69 6F 6E 45 78 57 00 F5 01 47 6C 6F 62 61 6C
46 72 65 65 00 00 97 03 57 72 69 74 65 46 69 6C 65 00 50 00 43 72 65 61 74 65 46 69
6C 65 57 00 5B 02 4C 6F 63 6B 52 65 73 6F 75 72
|
success or wait |
2081522614 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 12 12 12 12 12
12 12 12 12 12 12 12 12 12 12 12 7F 12 61 12 7C 12 3C 12 7D 12 74 12 74 12 7E 12 7B
12 7C 12 77 12 65 12 77 12 70 12 62 12 73 12 75 12 77 12 3C 12 71 12 7D 12 7F 12 12
12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 7F 12 61 12 7C 12 3C 12 7D
12 74 12 74 12 7E 12 7B 12 7C 12
|
success or wait |
2081522717 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 6D 00 73 00 6E 00 2E 00 6F 00 66 00
66 00 6C 00 69 00 6E 00 65 00 77 00 65 00 62 00 70 00 61 00 67 00 65 00 2E 00 63 00
6F 00 6D 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 6D 00 73 00
6E 00 2E 00 6F 00 66 00 66 00 6C 00 69 00 6E 00
|
success or wait |
2081523742 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 12 12 12 12 12
12 12 12 12 12 12 12 13 12 13 12 B2 12 12 92 32 12 12 92 02 12 12 12 2A 12 12 92 12
12 12 12 12 12 12 12 12 12 12 12 12 12 13 12 74 12 12 12 42 12 12 92 12 12 12 12 12
12 12 12 12 12 12 12 12 12 13 12 13 12 12 12 7A 12 12 92 12 12 12 12 12 12 12 12 12
12 12 12 12 12 13 12 1B 16 12 12
|
success or wait |
2081523842 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
00 00 00 00 00 00 00 00 00 00 00 00 01 00 01 00 A0 00 00 80 20 00 00 80 10 00 00 00
38 00 00 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 66 00 00 00 50 00 00 80
00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 01 00 00 00 68 00 00 80 00 00 00 00
00 00 00 00 00 00 00 00 00 00 01 00 09 04 00 00
|
success or wait |
2081524873 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 12 12 12 12 12
12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12
12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12
12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12 12
12 12 12 12 12 12 12 12 12 12 12
|
success or wait |
2081524972 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
|
success or wait |
2081526041 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 99 3F AE 62 12
02 4B 91 6E 36 06 12 66 5E 44 78 12 ED 66 36 0E FA 46 5E 12 12 ED 66 36 32 FA 05 19
12 12 91 D6 02 ED 66 36 06 ED C7 99 C2 41 9B 46 36 06 ED C7 99 5E 36 02 11 DA 93 EB
ED ED 12 12 6F 15 ED 66 36 06 41 ED C5 ED 66 36 06 FA 35 5E 12 12 99 3F AE 62 12 02
4B 91 6E 36 0A 12 66 5E 44 78 12
|
success or wait |
2081526180 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
8B 2D BC 70 00 10 59 83 7C 24 14 00 74 4C 56 6A 00 FF 74 24 1C E8 54 4C 00 00 FF 74
24 20 E8 17 0B 00 00 83 C4 10 FF 74 24 14 FF D5 8B D0 53 89 54 24 14 FF D5 8B 4C 24
10 03 C8 81 F9 FF FF 00 00 7D 07 FF 74 24 14 53 FF D7 FF 74 24 14 E8 27 4C 00 00 8B
2D BC 70 00 10 59 83 7C 24 18 00 74 4C 56 6A 00
|
success or wait |
2081527288 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 12 12 6F 23 9F
97 E2 EF ED ED 42 ED 67 1A ED 07 A6 62 12 02 ED 57 EA 44 44 44 9F 57 E6 44 42 9F 97
E2 E9 ED ED 42 D5 57 E6 12 10 12 12 ED 67 EA ED 67 EE F9 97 ED 67 EE ED 07 0A 62 12
02 4D 49 4C DB D1 47 99 FE 91 FE 3A 9F 57 EE 42 7A 0B 12 10 12 78 12 7A 2A 97 12 02
7A 10 12 12 92 ED 07 06 62 12 02
|
success or wait |
2081527390 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
00 00 7D 31 8D 85 F0 FD FF FF 50 FF 75 08 FF 15 B4 70 00 10 FF 45 F8 56 56 56 8D 45
F4 56 50 8D 85 F0 FB FF FF 50 C7 45 F4 00 02 00 00 FF 75 F8 FF 75 FC EB 85 FF 75 FC
FF 15 18 70 00 10 5F 5B 5E C9 C3 55 8B EC 83 EC 28 8D 45 FC 50 68 19 00 02 00 6A 00
68 38 85 00 10 68 02 00 00 80 FF 15 14 70 00 10
|
success or wait |
2081528467 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 12 02 43 9F 5F
EA 43 9F 5F E2 43 9F 9F FA BD ED ED 7A 12 5A 12 12 43 78 11 78 22 42 9B 4F E2 9B 4F
EA 9B 4F FA ED C4 97 D2 67 3F 99 57 E2 9F 5F FA 43 9F 5F EA 43 9F 5F E2 17 12 5A 12
12 43 42 9F 97 FA BD ED ED 42 78 11 78 22 ED 67 FE ED C4 97 D2 1D 96 86 13 12 12 7A
8A 9A 12 02 7A 9A 9A 12 02 7A 62
|
success or wait |
2081528567 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
00 10 51 8D 4D F8 51 8D 4D F0 51 8D 8D E8 AF FF FF 68 00 48 00 00 51 6A 03 6A 30 50
89 5D F0 89 5D F8 89 5D E8 FF D6 85 C0 75 2D 8B 45 F0 8D 4D E8 51 8D 4D F8 51 8D 4D
F0 05 00 48 00 00 51 50 8D 85 E8 AF FF FF 50 6A 03 6A 30 FF 75 EC FF D6 85 C0 0F 84
94 01 00 00 68 98 88 00 10 68 88 88 00 10 68 70
|
success or wait |
2081529653 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 9B 4F EA 42 9F
97 FA EF ED ED 42 45 45 7A 86 9B 12 02 ED 67 E2 ED 07 12 62 12 02 97 D2 1D 97 A9 10
12 12 9F 97 FA EF ED ED 7A 06 58 10 02 42 ED 07 22 62 12 02 97 D2 1D 96 B3 10 12 12
9F 97 FA EF ED ED 7A 9A 9B 12 02 42 ED C4 9F 97 FA EF ED ED 42 ED 67 1A ED C4 7A 42
10 12 12 9F 97 8A E9 ED ED 45 42
|
success or wait |
2081529753 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
89 5D F8 50 8D 85 E8 FD FF FF 50 57 57 68 94 89 00 10 FF 75 F0 FF 15 00 70 00 10 85
C0 0F 85 BB 02 00 00 8D 85 E8 FD FF FF 68 14 4A 02 10 50 FF 15 30 70 00 10 85 C0 0F
84 A1 02 00 00 8D 85 E8 FD FF FF 68 88 89 00 10 50 FF D6 8D 85 E8 FD FF FF 50 FF 75
08 FF D6 68 50 02 00 00 8D 85 98 FB FF FF 57 50
|
success or wait |
2081530838 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 12 1D 94 C9 13
12 12 91 D2 1E 9B 57 EE 99 57 EE 41 78 12 99 52 EA 9B 57 FE 9F 97 AA E9 ED ED 42 FA
5B 2E 12 12 91 D6 1E ED 67 FE ED 07 6E 63 12 02 42 9F 97 AA E9 ED ED 7A 02 9E 12 02
42 FA 9B 2E 12 12 45 9F 97 AA E1 ED ED 78 12 42 FA 0E 2E 12 12 9F 97 AA E9 ED ED 42
FA 04 2E 12 12 42 9F 97 AA E9 ED
|
success or wait |
2081530976 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
00 0F 86 DB 01 00 00 83 C0 0C 89 45 FC 8B 45 FC 53 6A 00 8B 40 F8 89 45 EC 8D 85 B8
FB FF FF 50 E8 49 3C 00 00 83 C4 0C FF 75 EC FF 15 7C 71 00 10 50 8D 85 B8 FB FF FF
68 10 8C 00 10 50 E8 89 3C 00 00 57 8D 85 B8 F3 FF FF 6A 00 50 E8 1C 3C 00 00 8D 85
B8 FB FF FF 50 E8 16 3C 00 00 50 8D 85 B8 FB FF
|
success or wait |
2081532070 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: ED ED 42 FA AC
2A 12 12 91 D6 3E 9F 97 AA E1 ED ED 42 ED 67 1A ED C4 ED 57 EA 99 57 E2 99 5F EA 91
57 EE 06 29 1A 1D 90 9D EC ED ED 99 57 E2 42 FA 57 2A 12 12 4B 4D 4C 49 DB D1 47 99
FE 93 FE 86 1B 12 12 41 44 45 21 C9 AB ED 13 12 12 21 D2 9F AF 7C E4 ED ED 99 27 A6
62 12 02 74 9B 8F 7E E4 ED ED 7A
|
success or wait |
2081532170 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
FF FF 50 E8 BE 38 00 00 83 C4 2C 8D 85 B8 F3 FF FF 50 FF 75 08 FF D6 FF 45 F8 8B 45
F0 8B 4D F8 83 45 FC 14 3B 08 0F 82 8F FE FF FF 8B 45 F0 50 E8 45 38 00 00 59 5F 5E
5B C9 C3 55 8B EC 81 EC 94 09 00 00 53 56 57 33 DB B9 FF 01 00 00 33 C0 8D BD 6E F6
FF FF 8B 35 B4 70 00 10 66 89 9D 6C F6 FF FF 68
|
success or wait |
2081533261 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 49 DB D1 47 99
FE 91 FE 26 41 44 45 78 32 ED 67 1A 9F 57 DE 21 E4 42 9B 67 EE FA D7 26 12 12 91 D6
1E 9F 5F EE 9B 67 C2 78 10 4A 43 9F 5F DE 43 44 44 42 9B 57 DE 9B 57 CA FA D8 25 12
12 97 D2 1D 97 8A 12 12 12 2B 67 EE 1D 96 9D 12 12 12 91 5F EA ED AA 12 3A 12 12 42
9B 57 E2 FA 6F 26 12 12 99 EA 4B
|
success or wait |
2081533360 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
5B C9 C3 55 8B EC 83 EC 34 53 56 57 6A 20 FF 75 08 8D 45 CC 33 F6 50 89 75 FC E8 C5
34 00 00 83 C4 0C 8D 4D FC 89 75 D0 6A 02 58 51 8D 4D CC 51 56 56 50 89 45 CC 89 45
D8 E8 CA 37 00 00 85 C0 0F 85 98 00 00 00 39 75 FC 0F 84 8F 00 00 00 83 4D F8 FF B8
00 28 00 00 50 89 45 F0 E8 7D 34 00 00 8B F8 59
|
success or wait |
2081534446 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: E5 EB 91 D0 53
74 9B 05 55 55 ED 5F 1A 67 A4 4D 74 91 36 61 12 7A 1A 10 12 12 9F 97 FA EF ED ED 78
12 42 FA 54 22 12 12 91 D6 1E 9F 97 FA EF ED ED 41 42 ED 07 A2 62 12 02 ED 67 1E 9F
97 FA EF ED ED 42 7A CA 9F 12 02 41 FA 60 22 12 12 91 D6 02 4C 49 DB D1 47 99 FE 93
FE 7E 1A 12 12 41 44 AC ED ED 12
|
success or wait |
2081534545 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
F7 F9 83 C2 41 66 89 17 47 47 FF 4D 08 75 B6 5F 66 83 24 73 00 68 08 02 00 00 8D 85
E8 FD FF FF 6A 00 50 E8 46 30 00 00 83 C4 0C 8D 85 E8 FD FF FF 53 50 FF 15 B0 70 00
10 FF 75 0C 8D 85 E8 FD FF FF 50 68 D8 8D 00 10 53 E8 72 30 00 00 83 C4 10 5E 5B C9
C3 55 8B EC 81 EC 6C 08 00 00 53 56 BE FF FF 00
|
success or wait |
2081535624 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 91 F3 11 91 F2
1D D3 F3 16 19 D3 4B 99 E1 9F AF 76 ED ED ED E1 B7 B6 6E 1C 91 EA 52 6F 1B 98 96 17
76 ED ED ED F9 10 A2 2F 1D AC D2 9B 57 FE 99 D0 D3 FA 1A 99 D8 91 F2 1D D3 FB 04 D3
F2 10 91 F3 11 78 02 19 D3 4B 99 E1 9F AF 32 ED ED ED E1 B7 B6 6E 1C 91 EA 52 6F 1B
98 96 17 32 ED ED ED F9 10 A2 2F
|
success or wait |
2081536172 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
83 E1 03 83 E0 0F C1 E1 04 0B C1 59 8B F3 8D BD 64 FF FF FF F3 A5 A4 7C 0E 83 F8 40
7D 09 8A 84 05 64 FF FF FF EB 02 B0 3D 0F BE C0 89 45 EC 8B C2 C1 E8 08 8B CA 83 E0
0F C1 E9 16 C1 E0 02 83 E1 03 6A 10 0B C1 59 8B F3 8D BD 20 FF FF FF F3 A5 A4 7C 0E
83 F8 40 7D 09 8A 84 05 20 FF FF FF EB 02 B0 3D
|
success or wait |
2081537267 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: ED ED 4B 4B 9F
97 76 F8 ED ED 9F 5F F6 42 7A 12 12 52 16 ED 67 1E ED 67 1A FA BB 1E 12 12 97 D2 1D
96 4F 13 12 12 9F 57 F2 41 42 9F 57 E2 42 7A 17 12 12 32 ED 67 FE D5 57 F2 16 12 12
12 ED 07 62 63 12 02 97 D2 1D 96 25 13 12 12 99 57 E2 52 42 FA 38 3A 12 12 99 EA 4B
29 E9 1D 96 30 13 12 12 99 57 E2
|
success or wait |
2081537368 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
FF FF 59 59 8D 85 64 EA FF FF 8D 4D E4 50 68 00 00 40 04 FF 75 0C FF 75 08 E8 A9 0C
00 00 85 C0 0F 84 5D 01 00 00 8D 45 E0 53 50 8D 45 F0 50 68 05 00 00 20 FF 75 EC C7
45 E0 04 00 00 00 FF 15 70 71 00 10 85 C0 0F 84 37 01 00 00 8B 45 F0 40 50 E8 2A 28
00 00 8B F8 59 3B FB 0F 84 22 01 00 00 8B 45 F0
|
success or wait |
2081538449 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 66 34 41 9F 97
E6 EF ED ED 7A 32 87 10 02 42 ED 07 66 62 12 02 41 9F 97 E6 EF ED ED 7A 0A 81 10 02
42 ED 07 66 62 12 02 44 9F 97 E6 EF ED ED 41 42 FA 2A 36 12 12 9F 97 E6 EF ED ED 42
78 10 ED 27 1A 83 10 02 45 FA 28 E9 ED ED 91 D6 0E 97 D2 66 5E 9F 97 E6 EF ED ED 97
D2 67 16 21 E4 F9 24 9F 97 E6 EF
|
success or wait |
2081538549 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
74 26 53 8D 85 F4 FD FF FF 68 20 95 02 10 50 FF 15 74 70 00 10 53 8D 85 F4 FD FF FF
68 18 93 02 10 50 FF 15 74 70 00 10 56 8D 85 F4 FD FF FF 53 50 E8 38 24 00 00 8D 85
F4 FD FF FF 50 6A 02 FF 35 08 91 02 10 57 E8 3A FB FF FF 83 C4 1C 85 C0 74 4C 8D 85
F4 FD FF FF 85 C0 75 04 33 F6 EB 36 8D 85 F4 FD
|
success or wait |
2081540074 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 96 B7 B7 B7 7A
82 82 12 02 42 B7 FA AE 32 12 12 91 D6 0A 2B 4F E2 D4 57 EE 10 9B 4F FE AD 11 52 12
92 67 14 45 FA 68 30 12 12 99 67 E2 9F 5F FE 43 9F 5F DA 99 14 41 43 41 44 ED 42 2E
29 D1 6F 1E 7A 8A 82 12 02 44 42 FA 77 30 12 12 2B 4F FE 67 14 45 FA 5E 30 12 12 99
57 FE 9F 47 AA 41 40 99 1A 78 13
|
success or wait |
2081540178 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
84 A5 A5 A5 68 90 90 00 10 50 A5 E8 BC 20 00 00 83 C4 18 39 5D F0 C6 45 FC 02 89 5D
EC BF 03 40 00 80 75 06 57 E8 7A 22 00 00 8B 75 F0 8D 4D EC 51 8D 4D C8 8B 06 53 51
53 56 FF 50 3C 3B C3 7D 0C 68 98 90 00 10 56 50 E8 65 22 00 00 39 5D EC 75 06 57 E8
4C 22 00 00 8B 45 EC 8D 55 B8 53 52 8B 08 6A 01
|
success or wait |
2081541307 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 9F 97 9E EF ED
ED 44 42 FA 51 0F 12 12 9A 0A 99 57 1A 4B 99 12 4B 29 57 1E 67 30 2B 4F 02 66 1E 9F
97 9E EF ED ED 42 ED 67 02 ED C5 2B 4F 06 66 1E 9F 97 9E E9 ED ED 42 ED 67 06 ED C5
ED 57 EE 99 57 EE 29 57 EA 1D 90 24 ED ED ED ED 67 E6 ED 07 0A 58 10 02 ED 67 E2 F9
13 45 ED 07 6A 62 12 02 4D 4C 49
|
success or wait |
2081541462 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
8D 85 8C FD FF FF 56 50 E8 43 1D 00 00 88 18 8B 45 08 59 8B 00 59 3B 45 0C 75 22 39
5D 10 74 0C 8D 85 8C FD FF FF 50 FF 75 10 FF D7 39 5D 14 74 0C 8D 85 8C FB FF FF 50
FF 75 14 FF D7 FF 45 FC 8B 45 FC 3B 45 F8 0F 82 36 FF FF FF FF 75 F4 FF 15 18 4A 02
10 FF 75 F0 EB 01 57 FF 15 78 70 00 10 5F 5E 5B
|
success or wait |
2081542607 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 9F 97 AE EF ED
ED 78 ED 42 44 44 ED 07 5E 62 12 02 99 57 E6 42 9F 97 AE E1 ED ED 42 ED 07 A2 62 12
02 9F 97 AE E5 ED ED 42 ED 07 AE 62 12 02 9F 56 12 13 99 2F 72 63 12 02 42 9F 97 AE
E5 ED ED 42 99 57 EA 78 39 ED 62 1A ED C5 9F 97 AE E1 ED ED 42 ED 07 AE 62 12 02 9F
56 12 13 42 9F 97 AE E1 ED ED 42
|
success or wait |
2081542733 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
8D 85 BC FD FF FF 6A FF 50 56 56 FF 15 4C 70 00 10 8B 45 F4 50 8D 85 BC F3 FF FF 50
FF 15 B0 70 00 10 8D 85 BC F7 FF FF 50 FF 15 BC 70 00 10 8D 44 00 01 8B 3D 60 71 00
10 50 8D 85 BC F7 FF FF 50 8B 45 F8 6A 2B FF 70 08 FF D7 8D 85 BC F3 FF FF 50 FF 15
BC 70 00 10 8D 44 00 01 50 8D 85 BC F3 FF FF 50
|
success or wait |
2081543906 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 91 D2 11 36 EE
FA 94 06 12 12 99 D6 45 9B 57 E6 42 74 9B 22 9F 97 AE EF ED ED 78 ED 42 44 44 ED 07
5E 62 12 02 99 57 E6 42 9F 97 AE E1 ED ED 42 ED 07 A2 62 12 02 9F 97 AE E5 ED ED 42
ED 07 AE 62 12 02 9F 56 12 13 99 2F 72 63 12 02 42 9F 97 AE E5 ED ED 42 99 57 EA 78
39 ED 62 1A ED C5 9F 97 AE E1 ED
|
success or wait |
2081544005 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
83 C0 03 24 FC E8 86 14 00 00 8B C4 57 89 45 F4 50 66 89 30 8D 85 BC FD FF FF 6A FF
50 56 56 FF 15 4C 70 00 10 8B 45 F4 50 8D 85 BC F3 FF FF 50 FF 15 B0 70 00 10 8D 85
BC F7 FF FF 50 FF 15 BC 70 00 10 8D 44 00 01 8B 3D 60 71 00 10 50 8D 85 BC F7 FF FF
50 8B 45 F8 6A 2B FF 70 08 FF D7 8D 85 BC F3 FF
|
success or wait |
2081545087 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 13 12 12 12 49
4B 4B D1 47 99 FE 43 91 2F 5E 9C 10 02 12 41 44 45 99 E3 67 17 FA 2B EF ED ED 99 57
1E 9F 5A 0D 99 57 1A D3 FB 17 9B 1C 99 02 9B 44 16 99 42 16 9B 44 1A 99 42 1A 9B 44
1E 99 42 1E 91 FB 16 9B 44 02 1D 96 7B 13 12 12 5B 5B 1D 96 CD 12 12 12 5B 5B 1D 97
D1 13 12 12 99 5A 02 AD 36 48 10
|
success or wait |
2081545187 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
01 00 00 00 5B 59 59 C3 55 8B EC 51 83 3D 4C 8E 02 10 00 53 56 57 8B F1 75 05 E8 39
FD FF FF 8B 45 0C 8D 48 1F 8B 45 08 C1 E9 05 89 0E 8B 10 89 56 04 8B 50 04 89 56 08
8B 50 08 89 56 0C 8B 50 0C 83 E9 04 89 56 10 0F 84 69 01 00 00 49 49 0F 84 DF 00 00
00 49 49 0F 85 C3 01 00 00 8B 48 10 BF 24 5A 02
|
success or wait |
2081546266 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: DB D3 F8 1A 21
26 9F 36 40 10 02 21 4A EA 1D A4 D8 99 C1 21 26 9F 36 5C 10 02 1D A4 5F EA D3 F8 02
21 26 9F 36 58 10 02 1D A4 C0 21 62 EE 99 DC 9B 67 FA D3 FB 0A 99 1E 9F 36 44 10 02
21 1E 87 36 40 10 02 99 47 F2 D3 F8 1A 1D A4 C0 21 1E 87 36 5C 10 02 1D A4 47 CE 21
1E 87 36 58 10 02 21 1A 99 C3 99
|
success or wait |
2081546405 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
C9 C1 EA 08 33 34 8D 24 52 02 10 33 58 F8 0F B6 CA 8B D3 33 34 8D 24 4E 02 10 0F B6
4D F8 C1 EA 10 33 34 8D 24 4A 02 10 0F B6 D2 33 70 FC 8B CE 89 75 E8 C1 E9 18 8B 0C
8D 24 56 02 10 33 0C 95 24 52 02 10 8B 55 E0 C1 EA 08 0F B6 D2 33 0C 95 24 4E 02 10
0F B6 55 DC 33 0C 95 24 4A 02 10 33 08 8B D1 8B
|
success or wait |
2081547492 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: C3 D3 F8 02 21
62 EE 1D A4 C0 99 EC 9B 67 FA D3 FD 0A 99 2E AF 36 44 10 02 21 2E 87 36 40 10 02 99
47 F2 D3 F8 1A 1D A4 C0 21 2E 87 36 5C 10 02 1D A4 C1 21 2E 87 36 58 10 02 99 C4 D3
F8 02 21 2A 9B 6F FE 1D A4 E8 99 C3 99 2E AF 36 40 10 02 D3 F8 1A 1D A4 C0 21 2E 87
36 5C 10 02 99 C1 D3 F8 0A D3 F9
|
success or wait |
2081547592 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
D1 C1 EA 10 33 70 FC 0F B6 D2 8B FE 89 75 E8 C1 EF 18 8B 3C BD 24 56 02 10 33 3C 95
24 52 02 10 8B 55 E0 C1 EA 08 0F B6 D2 33 3C 95 24 4E 02 10 0F B6 D3 33 3C 95 24 4A
02 10 8B D6 C1 EA 10 33 38 89 7D EC 0F B6 FA 8B D1 8B 3C BD 24 52 02 10 C1 EA 08 0F
B6 D2 33 3C 95 24 4E 02 10 8B D3 C1 EA 18 C1 EB
|
success or wait |
2081548678 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 9B 6F FE 99 2E
9F 36 40 10 02 99 5F CE 21 2E 8F 36 5C 10 02 D3 FB 0A 21 2E 9F 36 44 10 02 1D A4 5F
F2 21 2E 9F 36 58 10 02 21 6A 16 9B 6F E2 99 DC 99 67 F2 D3 FB 1A 1D A4 DB D3 FC 0A
99 0E 9F 36 5C 10 02 99 5F CE 21 0E A7 36 44 10 02 91 D2 02 D3 FB 02 1D A4 DB 21 0E
9F 36 40 10 02 1D A4 D8 D3 F8 0A
|
success or wait |
2081548778 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
89 7D EC 8B 3C 8D 24 52 02 10 8B 4D DC 33 3C 9D 24 4E 02 10 C1 E9 18 33 3C 8D 24 56
02 10 0F B6 4D E0 33 3C 8D 24 4A 02 10 33 78 04 89 7D F0 8B CE 8B 75 E0 C1 E9 08 0F
B6 C9 C1 EE 18 8B 1C 8D 24 4E 02 10 8B 4D DC 33 1C B5 24 56 02 10 83 C0 10 C1 E9 10
0F B6 C9 33 1C 8D 24 52 02 10 0F B6 CA C1 EA 18
|
success or wait |
2081549867 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: FB 02 1D A4 DB
21 2E 9F 5E 61 10 02 1D A4 D9 D3 F9 0A 21 2E 9F 5E 79 10 02 99 5F F2 99 0E 8F 5E 65
10 02 D3 FB 02 1D A4 DB 21 6A 1A 21 0E 9F 5E 61 10 02 99 5F CE D3 FB 1A 1D A4 DB 21
0E 9F 5E 7D 10 02 1D A4 D8 21 0E 9F 5E 79 10 02 99 5F E2 21 4A 1E 99 57 1E 9B 6A 1A
9B 22 4D 9B 4A 1E 4C 9B 5A 16 49
|
success or wait |
2081549967 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
E9 10 0F B6 C9 33 3C 8D 4C 73 02 10 0F B6 CB C1 EB 18 33 3C 8D 4C 6B 02 10 8B 4D E0
8B 1C 9D 4C 77 02 10 C1 E9 10 0F B6 C9 33 78 08 33 1C 8D 4C 73 02 10 8B 4D DC C1 E9
08 0F B6 C9 33 1C 8D 4C 6F 02 10 0F B6 CA 33 1C 8D 4C 6B 02 10 8B 4D F0 33 58 0C 8B
45 0C 89 78 08 89 30 5F 89 58 0C 5E 89 48 04 5B
|
success or wait |
2081551039 |
| File read |
Path: C:\Bin Ladens successor.pdf Offset: none Length: 1024 Value: 12 02 ED 37 DE
62 12 02 ED 37 D6 62 12 02 44 99 E3 FA 08 12 12 12 E4 56 36 1A 13 66 15 44 FA A7 EE
ED ED 4B 99 D4 4C D0 16 12 ED 37 06 63 12 02 ED 37 0E 63 12 02 DE DE 9F 5F F6 FB 41
F2 ED ED AA 42 60 12 02 FB F2 EE ED ED DE DE 9F 5F F2 FB 2D F2 ED ED AA 6A 60 12 02
FB DE EE ED ED DE DE 9F 5F E2 FB
|
success or wait |
2081551175 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Offset: none Length: 1024 Value:
00 10 FF 25 CC 70 00 10 FF 25 C4 70 00 10 56 8B F1 E8 1A 00 00 00 F6 44 24 08 01 74
07 56 E8 B5 FC FF FF 59 8B C6 5E C2 04 00 FF 25 14 71 00 10 FF 25 1C 71 00 10 CC CC
8D 4D E4 E9 53 E0 FF FF B8 50 72 00 10 E9 E0 FC FF FF CC CC 8D 4D E0 E9 3F E0 FF FF
B8 78 72 00 10 E9 CC FC FF FF CC CC 8D 4D F0 E9
|
success or wait |
2081552225 |
| Section loaded |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Access: query and write and
read and execute and extend size Type: image Baseaddress: 4FE0000 Size: 65536 Protection:
execute and read and write Mapped to pid: own pid
|
success or wait |
2081577439 |
| Section loaded |
Path: C:\WINDOWS\system32\apphelp.dll Access: write and read and execute Type: commit
Baseaddress: 5FD0000 Size: 126976 Protection: execute Mapped to pid: own pid
|
success or wait |
2081612748 |
| Section loaded |
Path: C:\WINDOWS\system32\apphelp.dll Access: query and write and read and execute
Type: image Baseaddress: 77B40000 Size: 139264 Protection: read write Mapped to pid:
own pid
|
success or wait |
2081615201 |
| Section loaded |
Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 25980000
Size: 1208320 Protection: readonly Mapped to pid: own pid
|
success or wait |
2081620570 |
| Section loaded |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Access: query and read Type:
commit Baseaddress: 4FF0000 Size: 49152 Protection: readonly Mapped to pid: own pid
|
success or wait |
2084254054 |
| Process created |
PID: 4076 Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp Cmdline: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AdobeArm.tmp
Createflags: 0
|
success or wait |
2084256875 |
| File created |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Access: read attributes
and synchronize and generic read and generic write Options: synchronous io non alert
and non directory file Attributes: normal Content Overwritten: false
|
success or wait |
2086065222 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: 25 50 44 46 2D 31 2E 34 0D 25 E2 E3 CF D3 0D 0A 31 35 20 30 20 6F 62 6A
20 3C 3C 2F 4C 69 6E 65 61 72 69 7A 65 64 20 31 2F 4C 20 34 31 36 37 33 2F 4F 20 31
38 2F 45 20 33 33 31 39 34 2F 4E 20 34 2F 54 20 34 31 33 32 36 2F 48 20 5B 20 36 37
36 20 32 30 37 5D 3E 3E 0D 65 6E 64 6F 62 6A 0D 20 20 20 20
|
success or wait |
2086075087 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: 65 64 69 61 42 6F 78 5B 30 20 30 20 35 39 35 20 38 34 32 5D 2F 43 72 6F
70 42 6F 78 5B 30 20 30 20 35 39 35 20 38 34 32 5D 2F 52 65 73 6F 75 72 63 65 73 20
31 39 20 30 20 52 3E 3E 0D 65 6E 64 6F 62 6A 0D 31 39 20 30 20 6F 62 6A 3C 3C 2F 46
6F 6E 74 3C 3C 2F 54 54 31 20 32 30 20 30 20 52 2F 54 54 32
|
success or wait |
2086079717 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: 54 79 70 65 2F 46 6F 6E 74 44 65 73 63 72 69 70 74 6F 72 20 32 36 20 30
20 52 2F 57 69 64 74 68 73 5B 32 35 30 20 30 20 30 20 30 20 30 20 30 20 30 20 30 20
30 20 30 20 30 20 30 20 32 35 30 20 33 33 33 20 32 35 30 20 32 37 38 20 35 30 30 20
35 30 30 20 35 30 30 20 30 20 30 20 35 30 30 20 35 30 30 20
|
success or wait |
2086082915 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: 46 6C 61 67 73 20 33 34 2F 53 74 65 6D 56 20 38 32 2F 43 61 70 48 65 69
67 68 74 20 36 35 36 2F 58 48 65 69 67 68 74 20 30 2F 41 73 63 65 6E 74 20 38 39 31
2F 44 65 73 63 65 6E 74 20 2D 32 31 36 2F 49 74 61 6C 69 63 41 6E 67 6C 65 20 30 2F
46 6F 6E 74 46 61 6D 69 6C 79 28 54 69 6D 65 73 20 4E 65 77
|
success or wait |
2086086543 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: B6 7C 99 9F 17 44 05 4D E1 95 C8 AB 50 EB 43 5C 8B E8 4A F5 E4 E8 3F 23
71 F0 41 5E 64 67 FA 35 94 E9 DA 43 77 C0 B1 3B 7D 8E 8B 9C 55 E8 70 EF 35 03 B1 9E
6B DE 94 A2 BA 09 8D 67 4B FC 69 4A C8 27 2E 28 AB E1 EA 07 BB 75 28 59 A4 DB 49 74
36 3F 94 D3 0C 4C 91 BE 30 03 61 08 A8 1E A2 E7 A3 DE 92 43
|
success or wait |
2086100254 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: 88 25 25 CE 9E 4E 12 EF 4F 90 23 E3 B6 BA A2 9A 90 2C 33 14 C8 2A 01 6C
A1 88 2D 88 A1 BA 33 F9 6C 54 03 2E 94 C9 F2 64 E5 35 B1 82 30 66 4C 1C 37 2A 8A 8D
AA 62 A7 61 AA 12 59 CE 8F C3 8C 17 B1 51 3D 48 91 09 CA 64 8D 19 81 EA CE 16 88 B8
E1 5C 16 53 C4 E5 C5 A0 4B A0 9E CC 8D 27 6B CD BA FD B8 D1
|
success or wait |
2086112743 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: 7A B8 90 71 D9 C5 22 EF 4A 62 C5 64 97 EF 59 53 51 8A DB 90 93 7E C9 4E
AD 81 BF D5 1B 72 BA 41 AA BB 5A 46 6A E4 2C 92 6D 50 7C EB BF 44 52 E5 77 24 71 10
40 DB 19 18 2D A0 19 34 91 1A 49 0D D3 69 FF 0E 46 91 50 68 C9 62 4E E3 A7 35 8D 9F
EC 88 FF 40 A0 DC B5 BF 44 A0 DD A7 04 CA BE 72 46 02 FF A1
|
success or wait |
2086117527 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: 40 DA C3 AB FD 52 80 2A 75 3A F0 35 BC D0 7C 2E BF BF C1 64 12 77 E4 89
81 51 71 21 7C 37 DB DA E5 CE 29 BA E8 80 D2 6B 75 D9 98 BD C3 BE C3 19 DE 43 5E 49
40 9B B3 62 55 BB 5C C4 6B 65 B6 0C 59 67 3E E7 5E D9 37 2F F8 11 C3 19 EA 88 06 33
19 2C 5E 9B 9F D9 B6 84 21 39 B2 E3 A5 91 A2 46 2B FF B1 34
|
success or wait |
2086122293 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: 8C F4 1A 27 2A 35 AD F6 79 89 EE 57 03 81 91 4E 7F 3F 12 EB 4B 53 81 94
31 5D C6 C6 B0 BE E4 4E C3 F8 53 4D 76 4D F1 CE 37 62 AD 7E D7 66 1D 93 EA 30 37 B7
B2 36 48 71 DF 97 5A 16 AC CE 1C C9 C3 E9 D5 4C D7 73 23 8D C0 39 A6 3D E1 F4 D1 F2
BE 4B F4 FB 3D FA 18 EC C5 7A 8D 23 9C 57 F4 AE DF 9B 73 BC
|
success or wait |
2086126528 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: EE 66 37 59 52 96 87 7C D1 2D E5 2E 87 5D 93 26 21 84 97 3C 62 58 B3 0F
12 02 36 8F C5 DE 1B 1E EE 66 F3 A4 8D 8D 0F C2 2B 68 20 6A C2 E5 51 28 86 0A 42 40
2D A1 88 85 B3 C1 C2 46 45 90 F2 B2 8A A0 16 6D AB ED 47 BF 8F AF 1F 54 D1 56 3E 5B
2A 92 ED 9C 73 77 37 9B 7C C0 5F BD CF 99 DF CC 99 33 67 66
|
success or wait |
2086130073 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: AF 61 26 0F C1 61 08 73 FC 4E B2 5B E1 07 A3 78 77 1C E9 81 D7 E1 0D AC
90 B7 E0 18 76 9A E3 78 C6 90 23 88 1D 8D A2 27 38 A6 F1 C7 E1 77 C8 33 2D 8D 3B 05
A7 B1 43 FD 1E DE 85 F7 E0 1C 9C 44 EE 7D FE 3C 83 DC 79 F8 10 3E 82 4F 84 54 A4 3E
80 2B F8 BC 89 37 38 67 56 3D BC 70 C1 FC 79 15 8A 3C D7 57
|
success or wait |
2086141654 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: 83 55 D0 4A 51 C7 4C 4A E1 48 C4 27 DB CE 5A AF 2A 36 2C B5 F9 78 57 C8
34 39 13 7B BF C1 3E 0B F5 66 B2 DB 8F F0 4C DA 12 0C 30 3F 60 AE CC C6 1A ED 45 41
05 CB 36 66 10 55 8A 68 32 5A 48 8E 5A 40 0D 2F 1F C3 CA 11 07 05 31 37 98 40 3E BE
05 19 DA A2 50 25 93 4D 2A D7 2B BC 9C 2D 14 0A C9 34 4C BB
|
success or wait |
2086144987 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: E9 63 F3 A0 07 E7 6A 30 FE C9 F3 0F 22 42 9C 24 4E 3C 8E 07 D5 65 44 A8
D5 DD 83 EF 3A 22 90 CC FA FE 43 F7 E0 7D D6 93 67 FD B8 85 A4 90 5A 5F D7 77 44 36
22 D2 3C 86 31 9D 91 6B B8 27 35 21 B2 0B 0F 21 DB 27 E0 C6 B1 58 21 0B B0 48 56 B3
56 5B 30 4D FC 0D E5 22 D5 8D 09 E2 18 66 18 27 30 44 EC E6
|
success or wait |
2086147639 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: 0F 21 32 C8 7E 92 04 26 61 67 47 98 6B 95 41 9C 68 FF E6 2A B0 99 AC 15
AB F8 4C AB 90 23 36 61 2E 59 2D 26 73 5F 9D CC 7C 12 0E 93 D2 FF 75 1E E7 7A 81 AC
21 D5 A4 4A 1D C6 52 35 91 FD 40 10 4B C8 44 E3 24 B6 C9 31 D8 66 D2 93 4C 7A 53 E0
53 42 DF 08 4C F0 A2 75 00 87 1C F8 FF B3 C6 FC 0E 1E 35 5B
|
success or wait |
2086151287 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: CE 58 C6 58 CA 58 C2 58 CC 58 C4 58 C8 58 C0 98 CF 98 C7 98 CB 98 C3 98
CD 98 C5 98 C9 98 C1 98 CE 98 C6 98 CA 98 C2 98 CC 98 C4 98 C8 98 C0 18 CF 18 C7 18
CB 18 C3 18 CD F8 97 F1 0F E3 6F C6 5F 8C 51 8C 3F 19 23 19 1C 7B 14 C7 1E C5 B1 47
71 EC 51 1C 7B 14 C7 1E C5 B1 47 71 EC 51 1C 7B 14 C7 1E C5
|
success or wait |
2086174862 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: 94 07 E5 74 B0 FC FF 5D 95 C5 AE 8C B6 36 11 4A 83 52 DA 9A FC 47 A3 24
70 6A 6B 55 A1 84 B6 36 16 8A 6B 6B 53 A1 18 9E 15 05 45 B4 35 AF 50 18 6F 16 D2 D6
E4 DF 58 41 6D 4D FE 6F B3 00 C8 8F CF F3 E1 57 C8 0B F2 E0 B2 DC 20 17 2E CB 09 72
80 EC 20 9B B6 26 FF 5B CA 0A B2 E0 CE CC B8 33 13 2E CB 88
|
success or wait |
2086178217 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: DE 86 AC CE 2C 2D 90 D5 10 6C 0D 64 95 55 B6 2A 5D 0C 11 25 6E 0E BA 83
B5 07 C5 5B DC AA 1F 65 4A A9 4C 25 B2 67 AA A7 DB EF 6F 3B E2 50 5D 6D 93 8E B5 83
93 B2 7B 72 51 B7 B9 0F AC 1B 98 B4 ED 9E 54 BD 03 83 7D 53 22 B7 F4 4F 89 16 EC 99
CC 6D 5B 37 30 3B BE 69 62 42 15 35 B5 4D 16 75 F7 DD AD EF
|
success or wait |
2086181545 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: 9A F7 28 F4 7A 67 EF 35 DD A1 52 9B 34 A5 A5 A5 A5 A5 A5 A5 A5 A5 A5 A5
A5 A5 A5 A5 A5 A5 BD D8 94 53 DD C5 5E 57 E6 16 B6 F6 66 6D 57 67 18 89 9A DD AA 65
28 55 EB CA 29 7B 52 75 06 F5 DE 54 6D A3 3E 90 AA ED 6A A7 DC 6B DE 25 63 0E 33 85
5A 7D AA D6 94 53 EB 4E D5 3A F3 A1 54 9D 41 BD 33 55 DB A8
|
success or wait |
2086187269 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: 0A 48 89 C4 55 09 50 53 D7 1A 3E 37 09 5B 20 2C 06 10 09 60 88 C8 BE 9C
CB 22 A0 11 41 50 D4 02 2A 01 E1 29 02 21 06 12 59 92 26 61 A7 48 22 B2 48 2D 56 04
04 17 52 C0 05 A4 A0 22 2A 45 40 2A 6A 61 40 8B F2 1C 90 2A B6 F0 C0 05 05 71 A1 D4
11 DE 0D 4B 4B 7D F3 9E 9D 37 F3 E6 9D 33 77 CE FC DF 7F FE
|
success or wait |
2086190664 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: 48 9C CF 02 AF 08 55 65 A0 9A 8C 8B 80 29 40 1E CB 10 B3 35 08 58 65 96
2F 81 8B E7 EB 1B 4F 56 F1 63 B8 61 85 E6 64 85 5A 39 D8 7D A4 0A BC 58 0C 36 45 4E
3E 0B FC DE 43 0F CD 4E 2C B2 28 68 96 54 21 F7 F5 BC 3A CF ED 0F 8C E9 57 34 2B 0B
FE A1 3D 8F 3C 4C F0 25 8D 7A 9A D8 00 A7 73 83 6D 79 3E C5
|
success or wait |
2086194365 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: 5C F4 E3 4A CB 66 95 BA 40 E3 96 F5 C3 44 17 A7 02 CB 0A 53 E7 33 23 1B
F7 AE 1D 48 57 6B 28 8E F2 67 56 49 52 BE 09 B5 8A F7 7A 5A 74 71 D7 AA E2 2D 7A A8
A2 91 66 49 C5 F0 D7 16 3A 43 AB 8F B0 34 43 03 E5 D8 25 FA 8E BE 99 13 A7 47 0F E3
6E 52 EE 35 FB AF AB CD 4E 6B 5E 39 E2 77 D8 A7 FA C3 E9 A4
|
success or wait |
2086197827 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: A0 42 30 09 30 00 86 80 27 60 0B A8 02 CA 20 E3 86 F0 D9 F0 1D 1A 20 CB
57 81 45 0D C2 A1 DB 96 73 B9 81 31 BB A1 57 B3 D4 65 77 C7 19 19 D1 CF 88 28 85 30
5B F5 17 74 19 4B 36 D8 86 03 F0 65 39 2D E5 A7 C5 33 BB 2F 74 0C D5 19 1B 66 16 73
3F 69 19 9D 4E 5E 32 2E D1 BA AA 29 32 92 B5 AB CF F7 F9 02
|
success or wait |
2086201230 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: 26 E4 A1 06 92 09 A3 20 C7 D7 84 BA 07 86 A2 85 43 EB 0C BD B4 9E 66 37
97 9E 1E 8E 62 A2 61 D8 7C 85 0A 86 80 86 FE AD C4 88 DA 06 6E AD E5 04 85 BF 35 44
A0 A0 73 DB 02 9B EF 37 F8 FD 91 62 00 52 49 56 F2 70 89 86 FF DD 59 2C 88 DF D2 84
09 65 0B 9E 4C 96 0D 44 43 39 DC 06 38 0D 38 41 D9 DC 0D BA
|
success or wait |
2086203570 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: BF 07 07 89 B5 12 43 07 40 CF 16 48 BC 4A 61 11 9E E4 66 BC 9F 86 0D B0
05 8E C2 A7 78 E6 5B 90 DA 06 BB A1 13 F6 01 C5 7F 14 DE 81 4F E0 5B BC 7A 96 EB 1B
60 80 EE 30 24 C3 10 80 C8 37 91 6B 3D 9D F8 86 D1 D3 5E 64 0B 72 43 92 A4 5E 24 62
8E 7C D1 0F FB A2 67 4B C4 DC 13 4E 1E 0C A9 7C 6E 9A F8 21
|
success or wait |
2086248411 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: F9 41 87 3B 31 29 76 B7 2A 57 D7 D0 91 3E 4B 35 D6 67 8D 24 5B AC D4 A1
60 F8 14 22 07 15 96 25 62 A6 99 17 71 39 2B 5F 91 CF C2 BD F5 D3 8E 29 B3 9D 1B 6C
46 49 16 2D 3A 85 65 0B 01 C9 83 1F 52 58 80 02 33 A6 8B B3 2C A3 85 05 92 2C 58 20
A6 86 AB 44 35 18 D5 C7 0E 32 3A 9B B3 88 89 74 6C AA B3 C8
|
success or wait |
2086251733 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: B9 4C F6 71 3E 44 91 8A E7 6F 11 BB 90 3A 8B DA 27 43 47 DE DF B8 80 07
49 6C E3 F1 15 B4 6D 8A 1D 8F 57 5A 8B 7A 16 F1 A1 AE 18 D1 1C 95 80 FE 9C AB 6B 0B
DE C4 B0 80 2F 79 F1 DF F8 62 6B B1 67 BB EF 6B 94 42 9D 3C 83 C5 F7 42 CD 43 1D 59
A0 56 63 A0 46 AE E7 D8 F5 BC 16 3F 76 0F E8 4B 1E 26 A3 82
|
success or wait |
2086255141 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: DE 7A 4E C2 01 6F 3D 97 06 AC E2 1A 25 40 36 E9 1D 0B 9C F9 FC 8D 77 90
66 EB FE 2A 20 E8 07 A7 E8 5E AF B1 DF BA 0C E9 7C 46 2E F8 7D 63 48 DE E9 E3 D4 4D
7F 9D 75 9F 6A 7A 2F DE A7 CF 71 EE 0B 55 FE 5A DB 5D 38 E6 06 59 8E 95 CE C7 9C A3
2B F5 DF D1 D6 89 65 4C 26 85 98 A3 0A 50 18 8A A2 5E C6 FE
|
success or wait |
2086258472 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: C0 88 52 23 E6 1B 51 62 44 B1 11 F3 8C 98 6B 44 91 11 85 46 14 18 91 6F
44 9E 11 B9 46 CC 31 62 B6 11 B3 8C C8 31 22 DB 88 2C 23 66 1A 31 C3 88 4C 23 FE 4B
63 5D 87 37 95 B4 61 18 EF 50 B4 69 A0 81 A4 48 DA 1E DC 5D 83 17 2B 52 68 29 F4 E0
4E A1 B8 04 82 07 0A 2C CB 0A EE EE 1E 74 70 77 77 77 77 77
|
success or wait |
2086276779 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: 3C FB 8A DD 17 F0 19 7C 02 1F 75 86 58 E1 83 CE 50 5F 78 8F DD 3B F0 16
BC C1 B3 D7 D8 BD 02 2F C1 0B 3C 7B 0E 9E E1 F0 29 78 02 1E 83 47 78 E5 21 76 0F B0
BB 8F DD 3D 70 17 DC C1 B3 DB E0 16 0E 6F 82 1B E0 3A B8 86 57 AE 62 77 05 5C D6 E9
1B 0A 97 74 FA 06 C2 45 70 01 87 E7 C1 39 70 16 9C C1 2B A7
|
success or wait |
2086289166 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin Laden s successor.pdf Offset: none Length:
1024 Value: 3F 78 94 CF A3 AA 7A 54 61 8F 4A E2 E7 09 F2 64 F6 F8 07 F6 36 DD 66 2F
9F DB F4 73 D7 75 27 B8 D7 BA 93 96 5D EB BE E3 4E E2 E7 56 01 5B 7E EF 59 EF 76 86
45 88 E1 83 DC D6 A0 88 9E 66 77 B3 87 AF BB D9 AD 7D 57 B3 93 FC 58 1D 5D F1 66 07
5F BC D9 DE 15 67 B6 F3 C5 99 6D 5D 6D CC D6 AE 56 66 4B 57
|
success or wait |
2086292599 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32.exe Access: query and write
and read and execute and extend size Type: image Baseaddress: 4FF0000 Size: 49152
Protection: readonly Mapped to pid: own pid
|
success or wait |
2086358733 |
| Section loaded |
Path: C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32.exe Access: query and read
Type: commit Baseaddress: 7F20000 Size: 352256 Protection: readonly Mapped to pid:
own pid
|
success or wait |
2086367045 |
| Process created |
PID: 1904 Path: C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32.exe Cmdline: C:\Program
Files\Adobe\Reader 9.0\Reader\AcroRd32.exe C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Bin
Laden s successor.pdf Createflags: 0
|
success or wait |
2086371810 |