Joebox - Abstract Analysis File 2738
General information
Joebox version:4.1.3
Start time:13:33:47
Start date:26/07/2011
Overall analysis duration:0h 3m 11s
Target binary file name:contacts_053.exe
Target script file name:default.jbs
Number of analysed new started processes analysed:3
Number of new started drivers analysed:2
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:1
Errors:
    Summary
    • SQL strings found in memory and binary data
    • Printf formating strings found in memory and binary data
    • Binary contains paths to debug symbols
    • Spawns processes
    • Queries a list of all running processes
    • Queries a list of all running drivers
    • Creates windows services
    • Creates files inside the system directory
    • Creates files inside the driver directory
    • Creates driver files
    • Infects executable files (uses memory mapped files)
    C:\WINDOWS\system32\drivers\mrxsmb.sys
    • Spawns drivers
    • Writes to foreign memory regions
    • Binary may include packed or crypted data
    • Modifies the context of a thread in another process (thread injection)
    • Maps a DLL or memory area into another process
    • Modifies IRP (I/O request packets) handlers (IRP hooks)
    • Registers kernel notifiers (kernel callbacks)
    • Allocates memory in foreign processes
    Static File Information
    PE Information
    General
    Entrypoint:0x401019L.text
    Imagebase:0x400000L
    Time stamp:0x4E204F4B [Fri Jul 15 14:31:39 2011 UTC]
    Subsystem:windows gui
    TLS callbacks:
    Resources
    NameRVA addressSizeType
    English0x6d778L0x658Lump; data
    English0x6de40L0x6fcLump; data
    English0x6e578L0xa50Lump; data
    English0x6efe0L0x128Lump; data
    English0x6d5d0L0xa4Lump; data
    English0x6d678L0xfeLump; data
    English0x6f3f0L0x98Lump; data
    English0x6f530L0x30Lump; data
    English0x6f560L0x28Lump; data
    English0x6f500L0x30Lump; data
    English0x6f4d0L0x2eLump; data
    English0x6e558L0x20Lump; Hitachi SH big-endian COFF object, not stripped
    English0x6f488L0x48Lump; data
    English0x6dde8L0x58Lump; data
    English0x6e540L0x14Lump; MS Windows icon resource - 1 icon
    English0x6ddd0L0x14Lump; MS Windows icon resource - 1 icon
    English0x6efc8L0x14Lump; MS Windows icon resource - 1 icon
    English0x6f108L0x2e4Lump; data
    Imports
    DLLImport
    kernel32.dllSetFilePointer, SetStdHandle, SetFileAttributesW, VerSetConditionMask, SetEnvironmentVariableA, RtlZeroMemory, CloseHandle, RtlUnwind, RtlMoveMemory, RtlFillMemory, RtlCaptureStackBackTrace, RtlCaptureContext, ResetEvent, SetSystemPowerState
    user32.dllSetLayeredWindowAttributes, SetUserObjectInformationA, ClientToScreen, SetSysColors
    gdi32.dllSetDCBrushColor, ResizePalette, EnumFontsA, CreateEllipticRgn, SetSystemPaletteUse, SetTextJustification, SetMetaRgn
    shlwapi.dllPathSkipRootA
    shell32.dllSHCreateDirectory
    inseng.dllGetICifFileFromFile
    Exports
    E3BnbuqhATEn9, ESbOWj, LzJuYUgw, O3jvQO8iY1L7k0, Wfw, Y8Nw9cF6wpocSmjYyWq, ZzltM61vCaLREurSm, f5nOhW, jyPsVRE81Qye
    Sections
    NameVirtual addressVirtual sizeRaw sizeentropy
    .text0x1000L0x2c61bL0x2c800L6.07186136679
    .rdata0x2e000L0x39fL0x400L1.89794523196
    .data0x2f000L0x3c0e3L0x4e00L5.58781790769
    .idata0x6c000L0x735L0x800L3.04730653555
    .rsrc0x6d000L0x2ce0L0x2e00L5.03890674427
    .reloc0x70000L0x949L0xa00L3.48181001246
    Version Infos
    DescriptionData
    FileVersion5.918.84
    InternalNamevxkeoqjxms
    ProductVersion5.918.84
    LegalCopyrightp9!9x3o0 qow.AR
    FileDescriptionV.q,Ix DDoq827 nyP7
    CompanyNamewna5z9 LO0ekX
    ProductNameecvLRJHM7 LzpkNHNe 9
    OriginalFilenamevxkeoqjxms
    Translation0x0000 0x04b0
    Possible Origin
    Language of compilation systemCountry where language is spokenMap
    EnglishUnited States
    String Analysis
    SQL
    String valueSource
    INSERT INTO AuthMonitor (BUILDLAB,CARD,CERTISSUER,DC,DOMAIN,MACHINENAME,READER,SESSION,STATUS,STOPWATCH,TIMESTAMP,UNLOCK,USERNAME) VALUES (?,?,?,?,?,?,?,?,?,?,?,?,?)winlogon.exe
    Formattings for printf style functions
    String valueSource
    %s\%s\%s\%s\%sexplorer.exe, winlogon.exe
    \registry\MACHINE\SYSTEM\CurrentControlSet\services\%Scontacts_053.exe
    %f7A{[contacts_053.exe, explorer.exe
    GET /%s HTTP/1.0contacts_053.exe
    GET /stat2.php?w=%u&i=%s&a=%u HTTP/1.1contacts_053.exe
    u%fPfShwinlogon.exe
    %ls %lsexplorer.exe, winlogon.exe
    y%pY2d|contacts_053.exe
    8Uf4E%iPcontacts_053.exe
    %iwM2iwwinlogon.exe
    %s\%s\%s\%s\%s\%sexplorer.exe, winlogon.exe
    l*",%pHcontacts_053.exe
    \systemroot\$NtUninstallKB%u$contacts_053.exe
    \??\%s\%x%xcontacts_053.exe
    Assertion failed: %s, file %s, line %dcontacts_053.exe, explorer.exe, winlogon.exe
    %d %d %d %dexplorer.exe, winlogon.exe
    \registry\MACHINE\SYSTEM\CurrentControlSet\Services\%ucontacts_053.exe
    6nN@g%oP*winlogon.exe
    GET /bad.php?w=%u&fail=%u&i=%s HTTP/1.0contacts_053.exe
    User-Agent: Opera/6 (Windows NT %u.%u; U; LangID=%x; x86)contacts_053.exe
    \registry\MACHINE\SYSTEM\CurrentControlSet\services\%scontacts_053.exe
    Host: %scontacts_053.exe
    %user%winlogon.exe
    DragDrop%lxcontacts_053.exe, explorer.exe, winlogon.exe
    %s\%x%xcontacts_053.exe
    <%p>%xcontacts_053.exe
    mXE4%lwinlogon.exe
    User-Agent: Opera/6 (Windows NT %u.%u; U; LangID=%x; x64)contacts_053.exe
    %xsuIpZcontacts_053.exe
    \systemroot\system32\drivers\%u.syscontacts_053.exe
    ache%OLK*contacts_053.exe, winlogon.exe
    u%fRQfSwinlogon.exe
    v%x;zO|V~fImT?contacts_053.exe
    WX?k%ocontacts_053.exe
    Debug symbol paths
    String valueSource
    Z:\xampp\htdocs\project-727,Permutation\stable\tmp\PDBSIG.pdbcontacts_053.exe
    Analysis Overview
    Startup
    • system is xp
    • contacts_053.exe (PID: 656 MD5: 5FD25E5B07DCEF95B5A33788F587CCB1)
      • explorer.exe (PID: 772 MD5: 12896823FB95BFB3DC9B46BCAEDC9923)
        • winlogon.exe (PID: 608 MD5: ED0EF0A136DEC83DF69F04118870003E)
        • 1254331455.SYS (PID: 4 MD5: 88473C7FF4698E92BC7177415E14D666)
    • * (PID: 4 MD5: C7C653B9CE1B9177200372816B560E64)
    • svchost.exe (PID: 1560 MD5: )
    • cleanup
    Global Network Data
    All TCP
    TimestampSource PortDest PortSource IPDest IP
    Jul 26, 2011 14:34:00.585518000 W. Europe Daylight Time11248010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:00.720641000 W. Europe Daylight Time11258010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:00.721391000 W. Europe Daylight Time11268010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:00.722412000 W. Europe Daylight Time11278010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:00.775388000 W. Europe Daylight Time11288010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:00.791016000 W. Europe Daylight Time11298010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:00.852992000 W. Europe Daylight Time11308010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:01.223633000 W. Europe Daylight Time11318010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:01.255955000 W. Europe Daylight Time11328010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:01.281301000 W. Europe Daylight Time11338010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:01.503160000 W. Europe Daylight Time11348010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:01.655450000 W. Europe Daylight Time11358010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:03.496781000 W. Europe Daylight Time11248010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:03.934055000 W. Europe Daylight Time11258010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:04.152805000 W. Europe Daylight Time11268010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:04.268050000 W. Europe Daylight Time11278010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:04.371555000 W. Europe Daylight Time11288010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:04.777868000 W. Europe Daylight Time11298010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:04.777971000 W. Europe Daylight Time11308010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:04.778017000 W. Europe Daylight Time11318010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:04.778061000 W. Europe Daylight Time11328010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:04.778104000 W. Europe Daylight Time11338010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:04.778140000 W. Europe Daylight Time11348010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:04.887852000 W. Europe Daylight Time11358010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:06.473346000 W. Europe Daylight Time11368010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:06.473887000 W. Europe Daylight Time11378010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:06.474442000 W. Europe Daylight Time11388010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:09.371764000 W. Europe Daylight Time11368010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:09.371893000 W. Europe Daylight Time11378010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:09.371939000 W. Europe Daylight Time11388010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:09.700734000 W. Europe Daylight Time11248010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:10.027902000 W. Europe Daylight Time11258010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:10.028006000 W. Europe Daylight Time11268010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:10.028049000 W. Europe Daylight Time11278010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:10.028089000 W. Europe Daylight Time11288010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:10.028125000 W. Europe Daylight Time11298010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:10.793643000 W. Europe Daylight Time11308010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:10.793766000 W. Europe Daylight Time11318010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:10.793811000 W. Europe Daylight Time11328010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:10.793854000 W. Europe Daylight Time11338010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:10.793905000 W. Europe Daylight Time11348010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:10.903010000 W. Europe Daylight Time11358010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:15.387394000 W. Europe Daylight Time11368010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:15.387521000 W. Europe Daylight Time11378010.0.2.1569.50.212.157
    Jul 26, 2011 14:34:15.387565000 W. Europe Daylight Time11388010.0.2.1569.50.212.157
    Hooks
    IRP Handler
    Handler FunctionDriverAddressType
    IRP_MJ_SET_VOLUME_INFORMATION\Driver\1254331455FF8F32FCnew
    IRP_MJ_QUERY_QUOTA\Driver\1254331455FF8F32FCnew
    IRP_MJ_PNP\Driver\1254331455FF8F32FCnew
    IRP_MJ_CREATE_MAILSLOT\Driver\1254331455FF8F32FCnew
    IRP_MJ_POWER\Driver\1254331455FF8F32FCnew
    IRP_MJ_DEVICE_CONTROL\Driver\1254331455FF8F32FCnew
    IRP_MJ_READ\Driver\1254331455FF8F32FCnew
    IRP_MJ_DIRECTORY_CONTROL\Driver\1254331455FF8F32FCnew
    IRP_MJ_QUERY_VOLUME_INFORMATION\Driver\1254331455FF8F32FCnew
    IRP_MJ_SET_SECURITY\Driver\1254331455FF8F32FCnew
    IRP_MJ_WRITE\Driver\1254331455FF8F32FCnew
    IRP_MJ_LOCK_CONTROL\Driver\1254331455FF8F32FCnew
    IRP_MJ_CLEANUP\Driver\1254331455FF8F32FCnew
    IRP_MJ_CLOSE\Driver\1254331455FF8F32FCnew
    IRP_MJ_INTERNAL_DEVICE_CONTROL\Driver\1254331455FF8F32FCnew
    IRP_MJ_CREATE\Driver\1254331455FF8F32FCnew
    IRP_MJ_CREATE_NAMED_PIPE\Driver\1254331455FF8F32FCnew
    IRP_MJ_SET_INFORMATION\Driver\1254331455FF8F32FCnew
    IRP_MJ_DEVICE_CHANGE\Driver\1254331455FF8F32FCnew
    IRP_MJ_QUERY_EA\Driver\1254331455FF8F32FCnew
    IRP_MJ_FILE_SYSTEM_CONTROL\Driver\1254331455FF8F32FCnew
    IRP_MJ_FLUSH_BUFFERS\Driver\1254331455FF8F32FCnew
    IRP_MJ_SET_EA\Driver\1254331455FF8F32FCnew
    IRP_MJ_SYSTEM_CONTROL\Driver\1254331455FF8F32FCnew
    IRP_MJ_QUERY_SECURITY\Driver\1254331455FF8F32FCnew
    IRP_MJ_SET_QUOTA\Driver\1254331455FF8F32FCnew
    IRP_MJ_QUERY_INFORMATION\Driver\1254331455FF8F32FCnew
    IRP_MJ_SHUTDOWN\Driver\1254331455FF8F32FCnew
    New Devices
    DriverDeviceAttached to (lower)Attached to (upper)
    \Driver\1254331455\Device\svchost.exe
    \Driver\1254331455\Device\{BF4B1315-B293-4d02-BBFE-42EF72DD1C8E}
    Device Extensions
    DriverDeviceExtension BeforeExtension After
    \Driver\Disk\Device\Harddisk0\DR000 00 00 03 81 AC 1A B8 81 AF 9B 58 81 AC 1B 70 81 AF 94 D0 00 00 00 01 00 00 00 03 81 AC 1A B8 FF B4 6D 78 81 AC 1B 70 81 AF 94 D0 00 00 00 01
    Kernel Callback Routines
    NotifierAddress
    RegistryFF8F260E
    ShutdownFF8F32FC
    Analysis File: contacts_053.exe PID: 656 Parent PID: 904
    Sections
    General
    Start time:04:48:55
    Start date:26/07/2011
    Path:C:\Documents and Settings\Administrator\Desktop\contacts_053.exe
    Commandline:not known
    Imagebase:0x400000
    File size:221022 bytes
    MD5 hash:5FD25E5B07DCEF95B5A33788F587CCB1
    File Activities:
    File opened
    File PathAccessOptionsCompletionCountSource Address
    C:\Documents and Settings\Administrator\Desktop\contacts_053.exedeleteno optionssuccess or wait1401450
    Section Activities:
    Section loaded by Windows
    File PathAccessTypeBaseSizeMapped to pidProtectionCompletionCountSource Address
    \KnownDlls\kernel32.dllwrite and read and executeunknown7C8000001007616own pidread writesuccess or wait1
    \NLS\NlsSectionUnicodereadunknown26000090112own pidreadonlysuccess or wait1
    \NLS\NlsSectionLocalereadunknown280000266240own pidreadonlysuccess or wait1
    \NLS\NlsSectionSortkeyquery and readunknown2D0000266240own pidreadonlysuccess or wait1
    \NLS\NlsSectionSortTblsreadunknown32000024576own pidreadonlysuccess or wait1
    \KnownDlls\user32.dllwrite and read and executeunknown7E410000593920own pidread writesuccess or wait1
    \KnownDlls\GDI32.dllwrite and read and executeunknown77F10000299008own pidread writesuccess or wait1
    \KnownDlls\shlwapi.dllwrite and read and executeunknown77F60000483328own pidread writesuccess or wait1
    \KnownDlls\ADVAPI32.dllwrite and read and executeunknown77DD0000634880own pidread writesuccess or wait1
    \KnownDlls\RPCRT4.dllwrite and read and executeunknown77E70000598016own pidread writesuccess or wait1
    \KnownDlls\Secur32.dllwrite and read and executeunknown77FE000069632own pidread writesuccess or wait1
    \KnownDlls\msvcrt.dllwrite and read and executeunknown77C10000360448own pidread writesuccess or wait1
    \KnownDlls\shell32.dllwrite and read and executeunknown7C9C00008482816own pidread writesuccess or wait1
    C:\WINDOWS\system32\inseng.dllquery and write and read and executeimage61000000110592own pidread writesuccess or wait1
    \KnownDlls\OLEAUT32.dllwrite and read and executeunknown77120000569344own pidread writesuccess or wait1
    \KnownDlls\ole32.dllwrite and read and executeunknown774E00001298432own pidread writesuccess or wait1
    \KnownDlls\urlmon.dllwrite and read and executeunknown781300001253376own pidread writesuccess or wait1
    \KnownDlls\iertutil.dllwrite and read and executeunknown3DFD00001998848own pidread writesuccess or wait1
    \KnownDlls\WININET.dllwrite and read and executeunknown3D930000942080own pidread writesuccess or wait1
    \KnownDlls\Normaliz.dllwrite and read and executeunknown33000036864own pidread writeimage not at base1
    \KnownDlls\Normaliz.dllwrite and read and executeunknown33000036864own pidread writeconflicting addresses1
    C:\WINDOWS\system32\advpack.dllquery and write and read and executeimage65000000188416own pidread writesuccess or wait1
    \KnownDlls\VERSION.dllwrite and read and executeunknown77C0000032768own pidread writesuccess or wait1
    C:\WINDOWS\system32\setupapi.dllquery and write and read and executeimage77920000995328own pidread writesuccess or wait1
    C:\WINDOWS\system32\imm32.dllwrite and read and executecommit340000110592own pidexecutesuccess or wait2
    C:\WINDOWS\system32\imm32.dllquery and write and read and executeimage76390000118784own pidread writesuccess or wait1
    \NLS\NlsSectionCTypereadunknown37000012288own pidreadonlysuccess or wait1
    C:\WINDOWS\system32\shell32.dllreadcommit9600008462336own pidreadonlysuccess or wait1
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dllwrite and read and executecommit9600001056768own pidexecutesuccess or wait1
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dllquery and write and read and executeimage773D00001060864own pidread writesuccess or wait1
    C:\WINDOWS\WindowsShell.Manifestwrite and read and executecommit3900004096own pidexecutesuccess or wait1
    unknownunknownunknown3900004096own pidreadonlysuccess or wait2
    \KnownDlls\comctl32.dllwrite and read and executeunknown5D090000630784own pidread writesuccess or wait1
    C:\WINDOWS\system32\comctl32.dllreadcommit960000618496own pidreadonlysuccess or wait1
    Section loaded by program
    File PathAccessTypeBaseSizeMapped to pidProtectionCompletionCountSource Address
    \BaseNamedObjects\ShimSharedMemorywriteunknownCA000057344own pidread writesuccess or wait140136C
    C:\WINDOWS\system32\apphelp.dllwrite and read and executecommitCB0000126976own pidexecutesuccess or wait140136C
    C:\WINDOWS\system32\apphelp.dllquery and write and read and executeimage77B40000139264own pidread writesuccess or wait140136C
    C:\WINDOWS\AppPatch\sysmain.sdbreadcommitCB00001208320own pidreadonlysuccess or wait140136C
    C:\WINDOWS\explorer.exewrite and read and executecommitDE00001036288own pidexecutesuccess or wait240136C
    unknownunknownunknownDE00001036288own pidreadonlysuccess or wait240136C
    unknownunknownunknownCB00001036288own pidreadonlysuccess or wait140136C
    Registry Activities:
    Key value queried
    Key PathNameCompletionCountSource Address
    HKEY_LOCAL_MACHINE\SYSTEM\SetupMachineGuidsuccess or wait14010D9
    Process Activities:
    Process started
    PIDFilepathCmdlineFlagsCompletionCountSource Address
    772C:\WINDOWS\explorer.exeA4*suspendedsuccess or wait140136C
    Process terminated
    PIDFilepathCompletionCountSource Address
    not knownnot knownsuccess or wait1401458
    656C:\Documents and Settings\Administrator\Desktop\contacts_053.exesuccess or wait0401458
    Thread Activities:
    Thread context set
    TIDPIDDR0DR1DR2DR3DR7EFLAGSEIPCompletionCountSource Address
    6687720000020090000success or wait140137D
    Thread resumed
    TIDPIDCompletionCountSource Address
    668772success or wait140137D
    Memory Activities:
    Memory written
    PIDFilepathBaseLengthValueCompletionCountSource Address
    772C:\WINDOWS\explorer.exe900008892864 A1 18 00 00 00 8D 88 A8 01 00 00 83 39 00 75 08 8D 90 18 0F 00 00 89 11 8B 40 30 8B 40 0C 8B 40 1C FF 74 24 04 83 E8 10 FF 70 18 E8 64 03 00 00 C2 0C 00 8B 00 8B 09 3B C8 76 04 83 C8 FF C3 1B C0 F7 D8 C3 55 8B EC 64 A1 18 00 00 00 8B 48 2C 8B 45 08 53 56 8B 71 04 57 33 FF BB 8A DE 67 35 8A 10 6B DB 21 88 55 0B 0F BE D2 33 DA 40 80 7D 0B 00 75 EC 8D 04 3E D1 E8 8B 54 C1 08 3B D3 74 16 73 05 8D 78 01 EB 02 8B F0 3B FE 72 E6 33 C0 5F 5E 5B 5D C2 04 00 8B 44 C1 0C 03 01 EB F1 55 8B EC 81 EC CC 02 00 00 56 57 6A 10 58 E8 4D 5A 01 00 8B 75 10 83 3E 00 74 29 33 C0 8D BD 34 FD FF FF B9 B3 00 00 00 F3 AB 8D 85 34 FD FF FF 50 6A FE C7 85 34 FD FF FF 10 00 01 00 E8 62 58 01 00 59 59 6A 10 58 E8 14 5A 01 00 E8 67 59 01 00 EB 0B 81 38 78 56 4F 23 74 18 8B 40 04 85 success or wait140137D
    Memory allocated
    PIDFilepathBaseLengthProtectionCompletionCountSource Address
    656C:\Documents and Settings\Administrator\Desktop\contacts_053.exeB6000012FE74page read and writesuccess or wait1422475
    656C:\Documents and Settings\Administrator\Desktop\contacts_053.exe3E000012FE74page read and writesuccess or wait1422507
    656C:\Documents and Settings\Administrator\Desktop\contacts_053.exe3F000012FE74page read and writesuccess or wait1422475
    656C:\Documents and Settings\Administrator\Desktop\contacts_053.exeB9000012FE74page read and writesuccess or wait1422507
    656C:\Documents and Settings\Administrator\Desktop\contacts_053.exeBA000012FF0Cpage read and writesuccess or wait1422A96
    656C:\Documents and Settings\Administrator\Desktop\contacts_053.exeBC000012FE84page read and writesuccess or wait2421FEA
    656C:\Documents and Settings\Administrator\Desktop\contacts_053.exeBC000012FEFCpage execute and read and writesuccess or wait1422EB1
    656C:\Documents and Settings\Administrator\Desktop\contacts_053.exeBF000012FCECpage execute and read and writesuccess or wait1423241
    656C:\Documents and Settings\Administrator\Desktop\contacts_053.exeC2000012FF00page execute and read and writesuccess or wait1423A41
    772C:\WINDOWS\explorer.exe9000012FE5Cpage execute and read and writesuccess or wait140137D
    Memory attributes changed
    PIDFilepathBaseLengthNew ProtectionOld ProtectionCompletionCountSource Address
    656C:\Documents and Settings\Administrator\Desktop\contacts_053.exe4000002B000page execute and read and writepage readonlysuccess or wait1423B25
    656C:\Documents and Settings\Administrator\Desktop\contacts_053.exe415B781000page execute and read and writepage execute and read and writesuccess or wait1401450
    Chronological sections
    OperationDataCompletionTime
    Section loadedPath: \KnownDlls\kernel32.dll Access: write and read and execute Type: unknown Baseaddress: 7C800000 Size: 1007616 Protection: read write Mapped to pid: own pidsuccess or wait964960620
    Section loadedPath: \NLS\NlsSectionUnicode Access: read Type: unknown Baseaddress: 260000 Size: 90112 Protection: readonly Mapped to pid: own pidsuccess or wait964964823
    Section loadedPath: \NLS\NlsSectionLocale Access: read Type: unknown Baseaddress: 280000 Size: 266240 Protection: readonly Mapped to pid: own pidsuccess or wait964965311
    Section loadedPath: \NLS\NlsSectionSortkey Access: query and read Type: unknown Baseaddress: 2D0000 Size: 266240 Protection: readonly Mapped to pid: own pidsuccess or wait964965953
    Section loadedPath: \NLS\NlsSectionSortTbls Access: read Type: unknown Baseaddress: 320000 Size: 24576 Protection: readonly Mapped to pid: own pidsuccess or wait964966220
    Section loadedPath: \KnownDlls\user32.dll Access: write and read and execute Type: unknown Baseaddress: 7E410000 Size: 593920 Protection: read write Mapped to pid: own pidsuccess or wait964968638
    Section loadedPath: \KnownDlls\GDI32.dll Access: write and read and execute Type: unknown Baseaddress: 77F10000 Size: 299008 Protection: read write Mapped to pid: own pidsuccess or wait964969048
    Section loadedPath: \KnownDlls\shlwapi.dll Access: write and read and execute Type: unknown Baseaddress: 77F60000 Size: 483328 Protection: read write Mapped to pid: own pidsuccess or wait964972068
    Section loadedPath: \KnownDlls\ADVAPI32.dll Access: write and read and execute Type: unknown Baseaddress: 77DD0000 Size: 634880 Protection: read write Mapped to pid: own pidsuccess or wait964972596
    Section loadedPath: \KnownDlls\RPCRT4.dll Access: write and read and execute Type: unknown Baseaddress: 77E70000 Size: 598016 Protection: read write Mapped to pid: own pidsuccess or wait964973774
    Section loadedPath: \KnownDlls\Secur32.dll Access: write and read and execute Type: unknown Baseaddress: 77FE0000 Size: 69632 Protection: read write Mapped to pid: own pidsuccess or wait964975436
    Section loadedPath: \KnownDlls\msvcrt.dll Access: write and read and execute Type: unknown Baseaddress: 77C10000 Size: 360448 Protection: read write Mapped to pid: own pidsuccess or wait964978519
    Section loadedPath: \KnownDlls\shell32.dll Access: write and read and execute Type: unknown Baseaddress: 7C9C0000 Size: 8482816 Protection: read write Mapped to pid: own pidsuccess or wait964982077
    Section loadedPath: C:\WINDOWS\system32\inseng.dll Access: query and write and read and execute Type: image Baseaddress: 61000000 Size: 110592 Protection: read write Mapped to pid: own pidsuccess or wait964989437
    Section loadedPath: \KnownDlls\OLEAUT32.dll Access: write and read and execute Type: unknown Baseaddress: 77120000 Size: 569344 Protection: read write Mapped to pid: own pidsuccess or wait964993307
    Section loadedPath: \KnownDlls\ole32.dll Access: write and read and execute Type: unknown Baseaddress: 774E0000 Size: 1298432 Protection: read write Mapped to pid: own pidsuccess or wait964995092
    Section loadedPath: \KnownDlls\urlmon.dll Access: write and read and execute Type: unknown Baseaddress: 78130000 Size: 1253376 Protection: read write Mapped to pid: own pidsuccess or wait964998557
    Section loadedPath: \KnownDlls\iertutil.dll Access: write and read and execute Type: unknown Baseaddress: 3DFD0000 Size: 1998848 Protection: read write Mapped to pid: own pidsuccess or wait965002087
    Section loadedPath: \KnownDlls\WININET.dll Access: write and read and execute Type: unknown Baseaddress: 3D930000 Size: 942080 Protection: read write Mapped to pid: own pidsuccess or wait965005123
    Section loadedPath: \KnownDlls\Normaliz.dll Access: write and read and execute Type: unknown Baseaddress: 330000 Size: 36864 Protection: read write Mapped to pid: own pidimage not at base965007842
    Section loadedPath: \KnownDlls\Normaliz.dll Access: write and read and execute Type: unknown Baseaddress: 330000 Size: 36864 Protection: read write Mapped to pid: own pidconflicting addresses965008651
    Section loadedPath: C:\WINDOWS\system32\advpack.dll Access: query and write and read and execute Type: image Baseaddress: 65000000 Size: 188416 Protection: read write Mapped to pid: own pidsuccess or wait965015295
    Section loadedPath: \KnownDlls\VERSION.dll Access: write and read and execute Type: unknown Baseaddress: 77C00000 Size: 32768 Protection: read write Mapped to pid: own pidsuccess or wait965025439
    Section loadedPath: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pidsuccess or wait965027862
    Section loadedPath: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit Baseaddress: 340000 Size: 110592 Protection: execute Mapped to pid: own pidsuccess or wait965037906
    Section loadedPath: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit Baseaddress: 340000 Size: 110592 Protection: execute Mapped to pid: own pidsuccess or wait965039019
    Section loadedPath: C:\WINDOWS\system32\imm32.dll Access: query and write and read and execute Type: image Baseaddress: 76390000 Size: 118784 Protection: read write Mapped to pid: own pidsuccess or wait965040096
    Section loadedPath: \NLS\NlsSectionCType Access: read Type: unknown Baseaddress: 370000 Size: 12288 Protection: readonly Mapped to pid: own pidsuccess or wait965049220
    Section loadedPath: C:\WINDOWS\system32\shell32.dll Access: read Type: commit Baseaddress: 960000 Size: 8462336 Protection: readonly Mapped to pid: own pidsuccess or wait965052635
    Section loadedPath: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll Access: write and read and execute Type: commit Baseaddress: 960000 Size: 1056768 Protection: execute Mapped to pid: own pidsuccess or wait965070633
    Section loadedPath: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll Access: query and write and read and execute Type: image Baseaddress: 773D0000 Size: 1060864 Protection: read write Mapped to pid: own pidsuccess or wait965071543
    Section loadedPath: C:\WINDOWS\WindowsShell.Manifest Access: write and read and execute Type: commit Baseaddress: 390000 Size: 4096 Protection: execute Mapped to pid: own pidsuccess or wait965075314
    Section loadedPath: unknown Access: unknown Type: unknown Baseaddress: 390000 Size: 4096 Protection: readonly Mapped to pid: own pidsuccess or wait965076781
    Section loadedPath: unknown Access: unknown Type: unknown Baseaddress: 390000 Size: 4096 Protection: readonly Mapped to pid: own pidsuccess or wait965077951
    Section loadedPath: \KnownDlls\comctl32.dll Access: write and read and execute Type: unknown Baseaddress: 5D090000 Size: 630784 Protection: read write Mapped to pid: own pidsuccess or wait965093648
    Section loadedPath: C:\WINDOWS\system32\comctl32.dll Access: read Type: commit Baseaddress: 960000 Size: 618496 Protection: readonly Mapped to pid: own pidsuccess or wait965100939
    Memory allocatedPID: 656 Path: C:\Documents and Settings\Administrator\Desktop\contacts_053.exe Base: B60000 Length: 12FE74 Allocation Type: null Protection: page read and writesuccess or wait965899937
    Memory allocatedPID: 656 Path: C:\Documents and Settings\Administrator\Desktop\contacts_053.exe Base: 3E0000 Length: 12FE74 Allocation Type: null Protection: page read and writesuccess or wait965904731
    Memory allocatedPID: 656 Path: C:\Documents and Settings\Administrator\Desktop\contacts_053.exe Base: 3F0000 Length: 12FE74 Allocation Type: null Protection: page read and writesuccess or wait965905055
    Memory allocatedPID: 656 Path: C:\Documents and Settings\Administrator\Desktop\contacts_053.exe Base: B90000 Length: 12FE74 Allocation Type: null Protection: page read and writesuccess or wait965905291
    Memory allocatedPID: 656 Path: C:\Documents and Settings\Administrator\Desktop\contacts_053.exe Base: BA0000 Length: 12FF0C Allocation Type: null Protection: page read and writesuccess or wait965905494
    Memory allocatedPID: 656 Path: C:\Documents and Settings\Administrator\Desktop\contacts_053.exe Base: BC0000 Length: 12FE84 Allocation Type: null Protection: page read and writesuccess or wait965905600
    Memory allocatedPID: 656 Path: C:\Documents and Settings\Administrator\Desktop\contacts_053.exe Base: BC0000 Length: 12FE84 Allocation Type: null Protection: page read and writesuccess or wait965916636
    Memory allocatedPID: 656 Path: C:\Documents and Settings\Administrator\Desktop\contacts_053.exe Base: BC0000 Length: 12FEFC Allocation Type: null Protection: page execute and read and writesuccess or wait965939056
    Memory allocatedPID: 656 Path: C:\Documents and Settings\Administrator\Desktop\contacts_053.exe Base: BF0000 Length: 12FCEC Allocation Type: null Protection: page execute and read and writesuccess or wait965944869
    Memory allocatedPID: 656 Path: C:\Documents and Settings\Administrator\Desktop\contacts_053.exe Base: C20000 Length: 12FF00 Allocation Type: null Protection: page execute and read and writesuccess or wait965947236
    Memory attributes changedPID: 656 Path: C:\Documents and Settings\Administrator\Desktop\contacts_053.exe Base: 400000 Length: 2B000 New Protection: page execute and read and write New Protection: page readonlysuccess or wait965952939
    Key value queriedPath: HKEY_LOCAL_MACHINE\SYSTEM\Setup Name: MachineGuidsuccess or wait965954223
    Memory attributes changedPID: 656 Path: C:\Documents and Settings\Administrator\Desktop\contacts_053.exe Base: 415B78 Length: 1000 New Protection: page execute and read and write New Protection: page execute and read and writesuccess or wait965954741
    File opened Path: C:\Documents and Settings\Administrator\Desktop\contacts_053.exe Access: delete Options: no optionssuccess or wait965954905
    Section loadedPath: \BaseNamedObjects\ShimSharedMemory Access: write Type: unknown Baseaddress: CA0000 Size: 57344 Protection: read write Mapped to pid: own pidsuccess or wait965956347
    Section loadedPath: C:\WINDOWS\system32\apphelp.dll Access: write and read and execute Type: commit Baseaddress: CB0000 Size: 126976 Protection: execute Mapped to pid: own pidsuccess or wait965957595
    Section loadedPath: C:\WINDOWS\system32\apphelp.dll Access: query and write and read and execute Type: image Baseaddress: 77B40000 Size: 139264 Protection: read write Mapped to pid: own pidsuccess or wait965958554
    Section loadedPath: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: CB0000 Size: 1208320 Protection: readonly Mapped to pid: own pidsuccess or wait965960336
    Section loadedPath: C:\WINDOWS\explorer.exe Access: write and read and execute Type: commit Baseaddress: DE0000 Size: 1036288 Protection: execute Mapped to pid: own pidsuccess or wait965968804
    Section loadedPath: unknown Access: unknown Type: unknown Baseaddress: DE0000 Size: 1036288 Protection: readonly Mapped to pid: own pidsuccess or wait965970787
    Section loadedPath: C:\WINDOWS\explorer.exe Access: write and read and execute Type: commit Baseaddress: DE0000 Size: 1036288 Protection: execute Mapped to pid: own pidsuccess or wait965975802
    Section loadedPath: unknown Access: unknown Type: unknown Baseaddress: DE0000 Size: 1036288 Protection: readonly Mapped to pid: own pidsuccess or wait965976692
    Section loadedPath: unknown Access: unknown Type: unknown Baseaddress: CB0000 Size: 1036288 Protection: readonly Mapped to pid: own pidsuccess or wait965989363
    Process createdPID: 772 Path: C:\WINDOWS\explorer.exe Cmdline: A4* Createflags: suspendedsuccess or wait965992331
    Memory allocatedPID: 772 Path: C:\WINDOWS\explorer.exe Base: 90000 Length: 12FE5C Allocation Type: null Protection: page execute and read and writesuccess or wait966252935
    Memory writtenPID: 772 Path: C:\WINDOWS\explorer.exe Base: 90000 Length: 88928 Value: 64 A1 18 00 00 00 8D 88 A8 01 00 00 83 39 00 75 08 8D 90 18 0F 00 00 89 11 8B 40 30 8B 40 0C 8B 40 1C FF 74 24 04 83 E8 10 FF 70 18 E8 64 03 00 00 C2 0C 00 8B 00 8B 09 3B C8 76 04 83 C8 FF C3 1B C0 F7 D8 C3 55 8B EC 64 A1 18 00 00 00 8B 48 2C 8B 45 08 53 56 8B 71 04 57 33 FF BB 8A DE 67 35 8A 10 6B DB 21 88 55 0B 0F BE D2 33 DA 40 80 7D 0B 00 75 EC 8D 04 3E D1 E8 8B 54 C1 08 3B D3 74 16 73 05 8D 78 01 EB 02 8B F0 3B FE 72 E6 33 C0 5F 5E 5B 5D C2 04 00 8B 44 C1 0C 03 01 EB F1 55 8B EC 81 EC CC 02 00 00 56 57 6A 10 58 E8 4D 5A 01 00 8B 75 10 83 3E 00 74 29 33 C0 8D BD 34 FD FF FF B9 B3 00 00 00 F3 AB 8D 85 34 FD FF FF 50 6A FE C7 85 34 FD FF FF 10 00 01 00 E8 62 58 01 00 59 59 6A 10 58 E8 14 5A 01 00 E8 67 59 01 00 EB 0B 81 38 78 56 4F 23 74 18 8B 40 04 85 success or wait966265898
    Thread context setTID: 668 PID: 772 DR0: 0 DR1: 0 DR2: 0 DR3: 0 DR7: 0 EIP: 90000 EFLAGS: 200 Imagepath: C:\WINDOWS\explorer.exesuccess or wait966281113
    Thread resumedTID: 668 PID: 772 Path: C:\WINDOWS\explorer.exesuccess or wait966281972
    Process terminated PID: not known Path: not knownsuccess or wait966284824
    Analysis File: explorer.exe PID: 772 Parent PID: 656
    Sections
    General
    Start time:04:48:55
    Start date:26/07/2011
    Path:C:\WINDOWS\explorer.exe
    Commandline:A4*
    Imagebase:0x1000000
    File size:1033728 bytes
    MD5 hash:12896823FB95BFB3DC9B46BCAEDC9923
    File Activities:
    File opened
    File PathAccessOptionsCompletionCountSource Address
    ACPI#PNP0303#2&da1a3ff&0synchronize10000object name not found1B54332
    C:\WINDOWSread data or list directory and read ea and read attributes and read control and synchronizesynchronous io non alertsuccess or wait17B51DE2
    C:\WINDOWS\systemread attributesno optionssuccess or wait1B53981
    C:\WINDOWS\$NtUninstallKB22351$\1740621400read data or list directory and write data or add file and append data or add subdirectory or create pipe instance and read ea and write ea and execute or traverse and delete child and read attributes and write attributes and delete and read control and write dac and write owner and synchronizesynchronous io non alert and open reparse pointsuccess or wait1B537B6
    C:\WINDOWS\$NtUninstallKB22351$\3522328898read data or list directory and write data or add file and append data or add subdirectory or create pipe instance and read ea and write ea and read attributes and write attributes and read control and synchronizedirectory file and synchronous io non alertsuccess or wait1B53981
    C:\WINDOWS\$NtUninstallKB22351$\:SummaryInformationread data or list directory and write data or add file and append data or add subdirectory or create pipe instance and read ea and write ea and execute or traverse and delete child and read attributes and write attributes and delete and read control and write dac and write owner and synchronizesynchronous io non alert and open reparse pointsuccess or wait1B53820
    C:\WINDOWS\$NtUninstallKB22351$write dacdirectory file and open reparse pointsuccess or wait1B53981
    C:\WINDOWS\system32\drivers\i8042prt.syswrite owneropen reparse pointsuccess or wait3B53125
    C:\WINDOWS\system32\drivers\cdrom.syswrite owneropen reparse pointsuccess or wait3B53125
    C:\WINDOWS\system32\drivers\intelppm.syswrite owneropen reparse pointsuccess or wait3B53125
    C:\WINDOWS\system32\drivers\termdd.syswrite owneropen reparse pointsuccess or wait3B53125
    C:\WINDOWS\system32\drivers\ipsec.syswrite owneropen reparse pointsuccess or wait3B53125
    C:\WINDOWS\system32\drivers\tcpip.syswrite owneropen reparse pointsuccess or wait3B53125
    C:\WINDOWS\system32\drivers\netbt.syswrite owneropen reparse pointsuccess or wait3B53125
    C:\WINDOWS\system32\drivers\afd.syswrite owneropen reparse pointsuccess or wait3B53125
    C:\WINDOWS\system32\drivers\netbios.syswrite owneropen reparse pointsuccess or wait3B53125
    C:\WINDOWS\system32\drivers\VBoxSF.syswrite owneropen reparse pointsuccess or wait3B53125
    C:\WINDOWS\system32\drivers\rdbss.syswrite owneropen reparse pointsuccess or wait3B53125
    C:\WINDOWS\system32\drivers\mrxsmb.syswrite owneropen reparse pointsuccess or wait5B53125
    C:\WINDOWS\system32\drivers\Fips.SYSwrite owneropen reparse pointsuccess or wait3B53125
    ACPI#PNP0303#2&da1a3ff&0\{1B372133-BFFA-4dba-9CCF-5474BED6A9F6}append data or add subdirectory or create pipe instance and synchronizesynchronous io non alertsuccess or wait1B51F1B
    File created
    File PathAccessAttributesOptionsCompletionCountSource Address
    C:\WINDOWS\$NtUninstallKB22351$read data or list directory and write data or add file and append data or add subdirectory or create pipe instance and read ea and write ea and read attributes and write attributes and read control and synchronizehidden and systemdirectory file and synchronous io non alertsuccess or wait1B53981
    C:\WINDOWS\$NtUninstallKB22351$\3522328898\Usynchronizenonedirectory filesuccess or wait1B53981
    C:\WINDOWS\$NtUninstallKB22351$\3522328898\Lsynchronizenonedirectory filesuccess or wait1B53981
    ACPI#PNP0303#2&da1a3ff&0\L\gkaiogtoappend data or add subdirectory or create pipe instance and synchronizenonesynchronous io non alertsuccess or wait1B539A0
    C:\WINDOWS\system32\drivers\1254331455.sysappend data or add subdirectory or create pipe instance and synchronizenonesynchronous io non alertsuccess or wait1B53A02
    File deleted
    File PathCompletionCountSource Address
    C:\Documents and Settings\Administrator\Desktop\contacts_053.exesuccess or wait1B5432B
    C:\Documents and Settings\Administrator\wevtapi.dllobject name not found1B5406B
    C:\Documents and Settings\Administrator\taskmgr.exeobject name not found1B5407E
    File written
    File PathOffsetLengthValueCompletionCountSource Address
    \L\gkaiogto04554244D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 70 72 6F 67 72 61 6D 20 63 61 6E 6E 6F 74 20 62 65 20 72 75 6E 20 69 6E 20 44 4F 53 20 6D 6F 64 65 2E 0D 0D 0A 24 00 00 00 00 00 00 00 5E B2 BD 26 1A D3 D3 75 1A D3 D3 75 1A D3 D3 75 1A D3 D2 75 56 D2 D3 75 D9 DC 8E 75 11 D3 D3 75 D9 DC DC 75 1F D3 D3 75 D9 DC 8F 75 1B D3 D3 75 D9 DC 8D 75 1B D3 D3 75 D9 DC 8C 75 76 D3 D3 75 D9 DC 89 75 1B D3 D3 75 52 69 63 68 1A D3 D3 75 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 0B 00 5C 53 19 4B 00 00 00 00 00 00 00 00 E0 00 0E 01 0B 01 07 0A 80 28 06 success or wait1B539A0
    \{1B372133-BFFA-4dba-9CCF-5474BED6A9F6}none20484C CE 1D 73 2D C6 CA D1 B8 09 DB 19 2D C6 CA D1 58 B0 7A E3 2D C6 CA D1 CB 43 36 84 2D C6 CA D1 29 61 6D 85 2D C6 CA D1 98 0E E8 69 2D C6 CA D1 56 37 EF 66 2D C6 CA D1 7B C9 62 63 2D C6 CA D1 DC 75 65 E3 2D C6 CA D1 A4 84 9A 50 2D C6 CA D1 44 C0 12 E2 2D C6 CA D1 54 FC 31 AA 2D C6 CA D1 56 7B C1 AD 2D C6 CA D1 63 FE B1 F1 2D C6 CA D1 62 A5 83 DD 2D C6 CA D1 48 D1 3F 33 2D C6 CA D1 5A A9 23 BD 2D C6 CA D1 A3 01 E6 CC 2D C6 CA D1 C8 5C 42 08 2D C6 CA D1 62 0F 88 F4 2D C6 CA D1 C9 EB 84 0C 2D C6 CA D1 45 89 A0 17 2D C6 CA D1 55 98 71 2F 2C C6 CA D1 BE 19 76 F3 2C C6 CA D1 47 C0 A5 CB 2C C6 CA D1 BE A0 85 BF 2C C6 CA D1 18 F7 9E D6 2C C6 CA D1 D8 33 BC F1 2C C6 CA D1 42 8D 17 43 2C C6 CA D1 62 D3 CB 46 2C C6 CA D1 BA 0C 96 A9 2C C6 CA D1 44 79 A2 97 2C C6 CA success or wait1B51F1B
    C:\WINDOWS\system32\drivers\1254331455.sysnone174084D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E8 00 00 00 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 70 72 6F 67 72 61 6D 20 63 61 6E 6E 6F 74 20 62 65 20 72 75 6E 20 69 6E 20 44 4F 53 20 6D 6F 64 65 2E 0D 0D 0A 24 00 00 00 00 00 00 00 B9 CF 0B 33 FD AE 65 60 FD AE 65 60 FD AE 65 60 7E A6 6A 60 FE AE 65 60 7E A6 38 60 EC AE 65 60 FD AE 64 60 12 AE 65 60 7E A6 39 60 FC AE 65 60 73 A6 3A 60 EE AE 65 60 7E A6 3B 60 FC AE 65 60 7E A6 3F 60 FC AE 65 60 52 69 63 68 FD AE 65 60 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 05 00 FC 4F 1D 4E 00 00 00 00 00 00 00 00 E0 00 02 success or wait1B53A02
    File read
    File PathOffsetLengthValueCompletionCountSource Address
    C:\WINDOWS\system32\drivers\i8042prt.sys0644D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 success or wait2B539A0
    C:\WINDOWS\system32\drivers\cdrom.sys0644D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 success or wait2B539A0
    C:\WINDOWS\system32\drivers\intelppm.sys0644D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 success or wait2B539A0
    C:\WINDOWS\system32\drivers\termdd.sys0644D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 success or wait2B539A0
    C:\WINDOWS\system32\drivers\ipsec.sys0644D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 success or wait2B539A0
    C:\WINDOWS\system32\drivers\tcpip.sys0644D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 success or wait2B539A0
    C:\WINDOWS\system32\drivers\netbt.sys0644D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 success or wait2B539A0
    C:\WINDOWS\system32\drivers\afd.sys0644D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E8 00 00 00 success or wait2B539A0
    C:\WINDOWS\system32\drivers\netbios.sys0644D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 success or wait2B539A0
    C:\WINDOWS\system32\drivers\VBoxSF.sys0644D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 F0 00 00 00 success or wait2B539A0
    C:\WINDOWS\system32\drivers\rdbss.sys0644D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E8 00 00 00 success or wait2B539A0
    C:\WINDOWS\system32\drivers\mrxsmb.sys0644D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 success or wait3B539A0
    C:\WINDOWS\system32\drivers\fips.sys0644D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 success or wait2B539A0
    Other file operations
    File PathDispositionDataAscii DataCompletionCountSource Address
    C:\WINDOWS\$NtUninstallKB22351$Ctrl code set: set compression01 00 ..success or wait1B53981
    C:\WINDOWS\$NtUninstallKB22351$\1740621400Ctrl code set: set reparse point0C 00 00 A0 74 00 00 00 00 00 32 00 34 00 32 00 00 00 00 00 5C 00 44 00 65 00 76 00 69 00 63 00 65 00 5C 00 73 00 76 00 63 00 68 00 6F 00 73 00 74 00 2E 00 65 00 78 00 65 00 5C 00 73 00 65 00 74 00 75 00 70 00 00 00 63 00 3A 00 5C 00 77 00 69 00 6E 00 64 00 6F 00 77 00 73 00 5C 00 73 00 79 00 73 00 74 00 65 00 6D 00 33 00 32 00 5C 00 73 00 65 00 74 00 75 00 70 00 00 00 ....t.....2.4.2.....\.D.e.v.i.c.e.\.s.v.c.h.o.s.t...e.x.e.\.s.e.t.u.p...c.:.\.w.i.n.d.o.w.s.\.s.y.s.t.e.m.3.2.\.s.e.t.u.p...success or wait1B537B6
    C:\WINDOWS\$NtUninstallKB22351$:SummaryInformationCtrl code set: set reparse point0C 00 00 A0 66 00 00 00 00 00 24 00 26 00 32 00 00 00 00 00 5C 00 44 00 65 00 76 00 69 00 63 00 65 00 5C 00 6E 00 75 00 6C 00 6C 00 5C 00 73 00 65 00 74 00 75 00 70 00 00 00 63 00 3A 00 5C 00 77 00 69 00 6E 00 64 00 6F 00 77 00 73 00 5C 00 73 00 79 00 73 00 74 00 65 00 6D 00 33 00 32 00 5C 00 73 00 65 00 74 00 75 00 70 00 00 00 ....f.....$.&.2.....\.D.e.v.i.c.e.\.n.u.l.l.\.s.e.t.u.p...c.:.\.w.i.n.d.o.w.s.\.s.y.s.t.e.m.3.2.\.s.e.t.u.p...success or wait1B53820
    C:\WINDOWS\$NtUninstallKB22351$BasicInformationCreation Time: 08:27 05-05-1796 Last Access Time: 08:43 15-05-1771 Last Write Time: 21:32 12-08-1810 Change Time: 21:32 12-08-1810 File Attributes: hidden and systemsuccess or wait1B53981
    C:\WINDOWS\system32\drivers\mrxsmb.sysCtrl code set: set compression00 00 ..success or wait1B5338C
    C:\WINDOWS\system32\drivers\mrxsmb.sysSymbolicLinkCreateSymbolic link name: \*success or wait1B5338C
    Section Activities:
    Section loaded by Windows
    File PathAccessTypeBaseSizeMapped to pidProtectionCompletionCountSource Address
    \KnownDlls\kernel32.dllwrite and read and executeunknown7C8000001007616own pidread writesuccess or wait1
    \NLS\NlsSectionUnicodereadunknown1D000090112own pidreadonlysuccess or wait1
    \NLS\NlsSectionLocalereadunknown1F0000266240own pidreadonlysuccess or wait1
    \NLS\NlsSectionSortkeyquery and readunknown240000266240own pidreadonlysuccess or wait1
    \NLS\NlsSectionSortTblsreadunknown29000024576own pidreadonlysuccess or wait1
    \KnownDlls\ADVAPI32.dllwrite and read and executeunknown77DD0000634880own pidread writesuccess or wait1
    \KnownDlls\RPCRT4.dllwrite and read and executeunknown77E70000598016own pidread writesuccess or wait1
    \KnownDlls\Secur32.dllwrite and read and executeunknown77FE000069632own pidread writesuccess or wait1
    C:\WINDOWS\system32\browseui.dllquery and write and read and executeimage75F800001036288own pidread writesuccess or wait1
    \KnownDlls\GDI32.dllwrite and read and executeunknown77F10000299008own pidread writesuccess or wait1
    \KnownDlls\USER32.dllwrite and read and executeunknown7E410000593920own pidread writesuccess or wait1
    \KnownDlls\msvcrt.dllwrite and read and executeunknown77C10000360448own pidread writesuccess or wait1
    \KnownDlls\ole32.dllwrite and read and executeunknown774E00001298432own pidread writesuccess or wait1
    \KnownDlls\SHLWAPI.dllwrite and read and executeunknown77F60000483328own pidread writesuccess or wait1
    \KnownDlls\OLEAUT32.dllwrite and read and executeunknown77120000569344own pidread writesuccess or wait1
    C:\WINDOWS\system32\shdocvw.dllquery and write and read and executeimage7E2900001511424own pidread writesuccess or wait1
    C:\WINDOWS\system32\crypt32.dllquery and write and read and executeimage77A80000610304own pidread writesuccess or wait1
    C:\WINDOWS\system32\msasn1.dllquery and write and read and executeimage77B2000073728own pidread writesuccess or wait1
    C:\WINDOWS\system32\cryptui.dllquery and write and read and executeimage754D0000524288own pidread writesuccess or wait1
    C:\WINDOWS\system32\netapi32.dllquery and write and read and executeimage5B860000348160own pidread writesuccess or wait1
    \KnownDlls\VERSION.dllwrite and read and executeunknown77C0000032768own pidread writesuccess or wait1
    \KnownDlls\WININET.dllwrite and read and executeunknown3D930000942080own pidread writesuccess or wait1
    \KnownDlls\Normaliz.dllwrite and read and executeunknown40000036864own pidread writesuccess or wait1
    \KnownDlls\urlmon.dllwrite and read and executeunknown781300001253376own pidread writesuccess or wait1
    \KnownDlls\iertutil.dllwrite and read and executeunknown3DFD00001998848own pidread writesuccess or wait1
    C:\WINDOWS\system32\wintrust.dllquery and write and read and executeimage76C30000188416own pidread writesuccess or wait1
    \KnownDlls\IMAGEHLP.dllwrite and read and executeunknown76C90000163840own pidread writesuccess or wait1
    \KnownDlls\WLDAP32.dllwrite and read and executeunknown76F60000180224own pidread writesuccess or wait1
    \KnownDlls\SHELL32.dllwrite and read and executeunknown7C9C00008482816own pidread writesuccess or wait1
    C:\WINDOWS\system32\uxtheme.dllquery and write and read and executeimage5AD70000229376own pidread writesuccess or wait1
    C:\WINDOWS\system32\shimeng.dllquery and write and read and executeimage5CB70000155648own pidread writesuccess or wait1
    C:\WINDOWS\AppPatch\sysmain.sdbreadcommit2B00001208320own pidreadonlysuccess or wait1
    C:\WINDOWS\AppPatch\acgenral.dllwrite and read and executecommit4100001855488own pidexecutesuccess or wait2
    C:\WINDOWS\AppPatch\acgenral.dllquery and write and read and executeimage6F8800001875968own pidread writesuccess or wait1
    C:\WINDOWS\system32\winmm.dllquery and write and read and executeimage76B40000184320own pidread writesuccess or wait1
    C:\WINDOWS\system32\msacm32.dllquery and write and read and executeimage77BE000086016own pidread writesuccess or wait1
    \KnownDlls\USERENV.dllwrite and read and executeunknown769C0000737280own pidread writesuccess or wait1
    \NLS\NlsSectionCTypereadunknown41000012288own pidreadonlysuccess or wait1
    C:\WINDOWS\system32\imm32.dllwrite and read and executecommit380000110592own pidexecutesuccess or wait2
    C:\WINDOWS\system32\imm32.dllquery and write and read and executeimage76390000118784own pidread writesuccess or wait1
    C:\WINDOWS\system32\browseui.dllreadcommit8700001028096own pidreadonlysuccess or wait1
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dllwrite and read and executecommit8700001056768own pidexecutesuccess or wait1
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dllquery and write and read and executeimage773D00001060864own pidread writesuccess or wait1
    C:\WINDOWS\WindowsShell.Manifestwrite and read and executecommit3B00004096own pidexecutesuccess or wait1
    unknownunknownunknown3B00004096own pidreadonlysuccess or wait2
    C:\WINDOWS\system32\riched20.dllquery and write and read and executeimage74E30000446464own pidread writesuccess or wait1
    C:\WINDOWS\system32\shdocvw.dllreadcommitAB00001499136own pidreadonlysuccess or wait1
    C:\WINDOWS\system32\shell32.dllreadcommit11000008462336own pidreadonlysuccess or wait1
    \KnownDlls\comctl32.dllwrite and read and executeunknown5D090000630784own pidread writesuccess or wait1
    C:\WINDOWS\system32\comctl32.dllreadcommitAD0000618496own pidreadonlysuccess or wait1
    Section loaded by program
    File PathAccessTypeBaseSizeMapped to pidProtectionCompletionCountSource Address
    nonequery and write and read and execute and extend sizecommitB5000098304own pidexecute and read and writesuccess or wait19046F
    C:\WINDOWS\system32\ws2_32.dllquery and write and read and executeimage71AB000094208own pidread writesuccess or wait190314
    C:\WINDOWS\system32\ws2help.dllquery and write and read and executeimage71AA000032768own pidread writesuccess or wait190314
    C:\WINDOWS\system32\mswsock.dllwrite and read and executecommitB80000245760own pidexecutesuccess or wait1B520A7
    C:\WINDOWS\system32\mswsock.dllquery and write and read and executeimage71A50000258048own pidread writesuccess or wait1B520A7
    C:\WINDOWS\system32\hnetcfg.dllquery and write and read and executeimage662B0000360448own pidread writesuccess or wait1B520A7
    C:\WINDOWS\system32\wshtcpip.dllwrite and read and executecommit9000020480own pidexecutesuccess or wait1B520A7
    C:\WINDOWS\system32\wshtcpip.dllquery and write and read and executeimage71A9000032768own pidread writesuccess or wait1B520A7
    \.mrxsmbquery and write and read and execute and extend sizecommitC30000458752own pidread writesuccess or wait1B539A0
    nonequery and write and read and execute and extend sizereserveC30000262144own pidread writesuccess or wait1B52A8A
    nonequery and write and read and execute and extend sizereserveC30000262144608read writeconflicting addresses1B52A9C
    nonequery and write and read and execute and extend sizereserveAB0000262144608read writesuccess or wait1B52A9C
    C:\WINDOWS\system32\drivers\mrxsmb.syswrite and readcommitC30000458752own pidread writesuccess or wait1B5338C
    \.mrxsmbquery and write and read and execute and extend sizecommitC30000458752own pidreadonlysuccess or wait1B539A0
    Registry Activities:
    Key value set
    Key PathNameTypeDataCompletionCountSource Address
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278}uDword68success or wait1B51ED3
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278}cidOther97 BA 42 0F 98 88 93 72 success or wait1B51ED3
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.mrxsmbTypeDword1success or wait1B5338C
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.mrxsmbStartDword3success or wait1B5338C
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.mrxsmbImagePathString\*success or wait1B5338C
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\1254331455StartDword3success or wait1B54607
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\1254331455TypeDword1success or wait1B54607
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\1254331455ErrorControlDword1success or wait1B54607
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\1254331455DisplayNameStringVirtual Bus for Microsoft ACPI-Compliant Systemsuccess or wait1B54607
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000ServiceString1254331455success or wait1B54613
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000ClassGUIDString{4D36E97D-E325-11CE-BFC1-08002BE10318}success or wait1B54613
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000ClassStringSystemsuccess or wait1B54613
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000DeviceDescStringPCI bussuccess or wait1B54613
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000MfgStringTechnologies Incsuccess or wait1B54613
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000LocationInformationStringon Microsoft ACPI-Compliant Systemsuccess or wait1B54613
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000ConfigFlagsDword0success or wait1B54613
    Key value queried
    Key PathNameCompletionCountSource Address
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RpcInstallDatesuccess or wait1B51DE2
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RpcMachineGuidsuccess or wait1B51D10
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278}InstallDatesuccess or wait7B51DE2
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278}Startsuccess or wait7B530EF
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278}Startsuccess or wait2B530EF
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278}Startsuccess or wait13B530EF
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278}Startsuccess or wait12B530EF
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersionInstallDatesuccess or wait7B51DE2
    Process Activities:
    Process terminated
    PIDFilepathCompletionCountSource Address
    not knownnot knownsuccess or wait1B52045
    772C:\WINDOWS\explorer.exesuccess or wait0B52045
    Thread Activities:
    Thread context set
    TIDPIDDR0DR1DR2DR3DR7EFLAGSEIPCompletionCountSource Address
    6687720007C90D51E4000success or wait19046F
    Thread resumed
    TIDPIDCompletionCountSource Address
    404608success or wait1B52A9C
    Thread suspended
    TIDPIDCompletionCountSource Address
    1572608success or wait2B52AAF
    1576608success or wait2B52AAF
    1580608success or wait2B52AAF
    Thread delayed
    TIDDelayCompletionCountSource Address
    16401s success or wait1B5432B
    Memory Activities:
    Memory allocated
    PIDFilepathBaseLengthProtectionCompletionCountSource Address
    772C:\WINDOWS\explorer.exeC300006F858page read and writesuccess or wait1B52A8A
    Driver Activities:
    Driver loaded
    Service name pathCompletionCountSource Address
    \registry\MACHINE\SYSTEM\CurrentControlSet\services\.mrxsmbsuccess or wait1B5338C
    System Activities:
    System information queried
    System info classCompletionCountSource Address
    ProcessInformationinfo length mismatch1B5436F
    ProcessInformationsuccess or wait1B5436F
    ModuleInformationinfo length mismatch1B539A0
    ModuleInformationsuccess or wait1B539A0
    ProcessInformationinfo length mismatch1B52D32
    ProcessInformationsuccess or wait1B52D32
    Chronological sections
    OperationDataCompletionTime
    Process terminated PID: not known Path: not knownsuccess or wait1059158966
    Section loadedPath: \KnownDlls\kernel32.dll Access: write and read and execute Type: unknown Baseaddress: 7C800000 Size: 1007616 Protection: read write Mapped to pid: own pidsuccess or wait966287139
    Section loadedPath: \NLS\NlsSectionUnicode Access: read Type: unknown Baseaddress: 1D0000 Size: 90112 Protection: readonly Mapped to pid: own pidsuccess or wait966292686
    Section loadedPath: \NLS\NlsSectionLocale Access: read Type: unknown Baseaddress: 1F0000 Size: 266240 Protection: readonly Mapped to pid: own pidsuccess or wait966293250
    Section loadedPath: \NLS\NlsSectionSortkey Access: query and read Type: unknown Baseaddress: 240000 Size: 266240 Protection: readonly Mapped to pid: own pidsuccess or wait966293741
    Section loadedPath: \NLS\NlsSectionSortTbls Access: read Type: unknown Baseaddress: 290000 Size: 24576 Protection: readonly Mapped to pid: own pidsuccess or wait966294031
    Section loadedPath: \KnownDlls\ADVAPI32.dll Access: write and read and execute Type: unknown Baseaddress: 77DD0000 Size: 634880 Protection: read write Mapped to pid: own pidsuccess or wait966295334
    Section loadedPath: \KnownDlls\RPCRT4.dll Access: write and read and execute Type: unknown Baseaddress: 77E70000 Size: 598016 Protection: read write Mapped to pid: own pidsuccess or wait966296683
    Section loadedPath: \KnownDlls\Secur32.dll Access: write and read and execute Type: unknown Baseaddress: 77FE0000 Size: 69632 Protection: read write Mapped to pid: own pidsuccess or wait966298283
    Section loadedPath: C:\WINDOWS\system32\browseui.dll Access: query and write and read and execute Type: image Baseaddress: 75F80000 Size: 1036288 Protection: read write Mapped to pid: own pidsuccess or wait966303725
    Section loadedPath: \KnownDlls\GDI32.dll Access: write and read and execute Type: unknown Baseaddress: 77F10000 Size: 299008 Protection: read write Mapped to pid: own pidsuccess or wait966306535
    Section loadedPath: \KnownDlls\USER32.dll Access: write and read and execute Type: unknown Baseaddress: 7E410000 Size: 593920 Protection: read write Mapped to pid: own pidsuccess or wait966307733
    Section loadedPath: \KnownDlls\msvcrt.dll Access: write and read and execute Type: unknown Baseaddress: 77C10000 Size: 360448 Protection: read write Mapped to pid: own pidsuccess or wait966310863
    Section loadedPath: \KnownDlls\ole32.dll Access: write and read and execute Type: unknown Baseaddress: 774E0000 Size: 1298432 Protection: read write Mapped to pid: own pidsuccess or wait966312633
    Section loadedPath: \KnownDlls\SHLWAPI.dll Access: write and read and execute Type: unknown Baseaddress: 77F60000 Size: 483328 Protection: read write Mapped to pid: own pidsuccess or wait966315291
    Section loadedPath: \KnownDlls\OLEAUT32.dll Access: write and read and execute Type: unknown Baseaddress: 77120000 Size: 569344 Protection: read write Mapped to pid: own pidsuccess or wait966319048
    Section loadedPath: C:\WINDOWS\system32\shdocvw.dll Access: query and write and read and execute Type: image Baseaddress: 7E290000 Size: 1511424 Protection: read write Mapped to pid: own pidsuccess or wait966321992
    Section loadedPath: C:\WINDOWS\system32\crypt32.dll Access: query and write and read and execute Type: image Baseaddress: 77A80000 Size: 610304 Protection: read write Mapped to pid: own pidsuccess or wait966325503
    Section loadedPath: C:\WINDOWS\system32\msasn1.dll Access: query and write and read and execute Type: image Baseaddress: 77B20000 Size: 73728 Protection: read write Mapped to pid: own pidsuccess or wait966329424
    Section loadedPath: C:\WINDOWS\system32\cryptui.dll Access: query and write and read and execute Type: image Baseaddress: 754D0000 Size: 524288 Protection: read write Mapped to pid: own pidsuccess or wait966333839
    Section loadedPath: C:\WINDOWS\system32\netapi32.dll Access: query and write and read and execute Type: image Baseaddress: 5B860000 Size: 348160 Protection: read write Mapped to pid: own pidsuccess or wait966353202
    Section loadedPath: \KnownDlls\VERSION.dll Access: write and read and execute Type: unknown Baseaddress: 77C00000 Size: 32768 Protection: read write Mapped to pid: own pidsuccess or wait966356291
    Section loadedPath: \KnownDlls\WININET.dll Access: write and read and execute Type: unknown Baseaddress: 3D930000 Size: 942080 Protection: read write Mapped to pid: own pidsuccess or wait966357569
    Section loadedPath: \KnownDlls\Normaliz.dll Access: write and read and execute Type: unknown Baseaddress: 400000 Size: 36864 Protection: read write Mapped to pid: own pidsuccess or wait966360343
    Section loadedPath: \KnownDlls\urlmon.dll Access: write and read and execute Type: unknown Baseaddress: 78130000 Size: 1253376 Protection: read write Mapped to pid: own pidsuccess or wait966362508
    Section loadedPath: \KnownDlls\iertutil.dll Access: write and read and execute Type: unknown Baseaddress: 3DFD0000 Size: 1998848 Protection: read write Mapped to pid: own pidsuccess or wait966367828
    Section loadedPath: C:\WINDOWS\system32\wintrust.dll Access: query and write and read and execute Type: image Baseaddress: 76C30000 Size: 188416 Protection: read write Mapped to pid: own pidsuccess or wait966373957
    Section loadedPath: \KnownDlls\IMAGEHLP.dll Access: write and read and execute Type: unknown Baseaddress: 76C90000 Size: 163840 Protection: read write Mapped to pid: own pidsuccess or wait966375648
    Section loadedPath: \KnownDlls\WLDAP32.dll Access: write and read and execute Type: unknown Baseaddress: 76F60000 Size: 180224 Protection: read write Mapped to pid: own pidsuccess or wait966379287
    Section loadedPath: \KnownDlls\SHELL32.dll Access: write and read and execute Type: unknown Baseaddress: 7C9C0000 Size: 8482816 Protection: read write Mapped to pid: own pidsuccess or wait966382892
    Section loadedPath: C:\WINDOWS\system32\uxtheme.dll Access: query and write and read and execute Type: image Baseaddress: 5AD70000 Size: 229376 Protection: read write Mapped to pid: own pidsuccess or wait966387233
    Section loadedPath: C:\WINDOWS\system32\shimeng.dll Access: query and write and read and execute Type: image Baseaddress: 5CB70000 Size: 155648 Protection: read write Mapped to pid: own pidsuccess or wait966390350
    Section loadedPath: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 2B0000 Size: 1208320 Protection: readonly Mapped to pid: own pidsuccess or wait966392324
    Section loadedPath: C:\WINDOWS\AppPatch\acgenral.dll Access: write and read and execute Type: commit Baseaddress: 410000 Size: 1855488 Protection: execute Mapped to pid: own pidsuccess or wait966397048
    Section loadedPath: C:\WINDOWS\AppPatch\acgenral.dll Access: write and read and execute Type: commit Baseaddress: 410000 Size: 1855488 Protection: execute Mapped to pid: own pidsuccess or wait966397975
    Section loadedPath: C:\WINDOWS\AppPatch\acgenral.dll Access: query and write and read and execute Type: image Baseaddress: 6F880000 Size: 1875968 Protection: read write Mapped to pid: own pidsuccess or wait966398753
    Section loadedPath: C:\WINDOWS\system32\winmm.dll Access: query and write and read and execute Type: image Baseaddress: 76B40000 Size: 184320 Protection: read write Mapped to pid: own pidsuccess or wait966400974
    Section loadedPath: C:\WINDOWS\system32\msacm32.dll Access: query and write and read and execute Type: image Baseaddress: 77BE0000 Size: 86016 Protection: read write Mapped to pid: own pidsuccess or wait966403909
    Section loadedPath: \KnownDlls\USERENV.dll Access: write and read and execute Type: unknown Baseaddress: 769C0000 Size: 737280 Protection: read write Mapped to pid: own pidsuccess or wait966406478
    Section loadedPath: \NLS\NlsSectionCType Access: read Type: unknown Baseaddress: 410000 Size: 12288 Protection: readonly Mapped to pid: own pidsuccess or wait966409803
    Section loadedPath: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit Baseaddress: 380000 Size: 110592 Protection: execute Mapped to pid: own pidsuccess or wait966430266
    Section loadedPath: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit Baseaddress: 380000 Size: 110592 Protection: execute Mapped to pid: own pidsuccess or wait966431257
    Section loadedPath: C:\WINDOWS\system32\imm32.dll Access: query and write and read and execute Type: image Baseaddress: 76390000 Size: 118784 Protection: read write Mapped to pid: own pidsuccess or wait966432027
    Section loadedPath: C:\WINDOWS\system32\browseui.dll Access: read Type: commit Baseaddress: 870000 Size: 1028096 Protection: readonly Mapped to pid: own pidsuccess or wait966443944
    Section loadedPath: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll Access: write and read and execute Type: commit Baseaddress: 870000 Size: 1056768 Protection: execute Mapped to pid: own pidsuccess or wait966461984
    Section loadedPath: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll Access: query and write and read and execute Type: image Baseaddress: 773D0000 Size: 1060864 Protection: read write Mapped to pid: own pidsuccess or wait966463048
    Section loadedPath: C:\WINDOWS\WindowsShell.Manifest Access: write and read and execute Type: commit Baseaddress: 3B0000 Size: 4096 Protection: execute Mapped to pid: own pidsuccess or wait966467714
    Section loadedPath: unknown Access: unknown Type: unknown Baseaddress: 3B0000 Size: 4096 Protection: readonly Mapped to pid: own pidsuccess or wait966468947
    Section loadedPath: unknown Access: unknown Type: unknown Baseaddress: 3B0000 Size: 4096 Protection: readonly Mapped to pid: own pidsuccess or wait966469815
    Section loadedPath: C:\WINDOWS\system32\riched20.dll Access: query and write and read and execute Type: image Baseaddress: 74E30000 Size: 446464 Protection: read write Mapped to pid: own pidsuccess or wait966529256
    Section loadedPath: C:\WINDOWS\system32\shdocvw.dll Access: read Type: commit Baseaddress: AB0000 Size: 1499136 Protection: readonly Mapped to pid: own pidsuccess or wait966536565
    Section loadedPath: C:\WINDOWS\system32\shell32.dll Access: read Type: commit Baseaddress: 1100000 Size: 8462336 Protection: readonly Mapped to pid: own pidsuccess or wait966559281
    Section loadedPath: \KnownDlls\comctl32.dll Access: write and read and execute Type: unknown Baseaddress: 5D090000 Size: 630784 Protection: read write Mapped to pid: own pidsuccess or wait966573952
    Section loadedPath: C:\WINDOWS\system32\comctl32.dll Access: read Type: commit Baseaddress: AD0000 Size: 618496 Protection: readonly Mapped to pid: own pidsuccess or wait966578199
    Section loadedPath: none Access: query and write and read and execute and extend size Type: commit Baseaddress: B50000 Size: 98304 Protection: execute and read and write Mapped to pid: own pidsuccess or wait966629926
    Thread context setTID: 668 PID: 772 DR0: 0 DR1: 0 DR2: 0 DR3: 7C90D51E DR7: 40 EIP: 0 EFLAGS: 0 Imagepath: C:\WINDOWS\explorer.exesuccess or wait966630888
    Section loadedPath: C:\WINDOWS\system32\ws2_32.dll Access: query and write and read and execute Type: image Baseaddress: 71AB0000 Size: 94208 Protection: read write Mapped to pid: own pidsuccess or wait966658364
    Section loadedPath: C:\WINDOWS\system32\ws2help.dll Access: query and write and read and execute Type: image Baseaddress: 71AA0000 Size: 32768 Protection: read write Mapped to pid: own pidsuccess or wait966660944
    Thread delayedTime: 1 TID: 1640success or wait966689812
    File deletedPath: C:\Documents and Settings\Administrator\Desktop\contacts_053.exesuccess or wait970225533
    File opened Path: ACPI#PNP0303#2&da1a3ff&0 Access: synchronize Options: 10000object name not found970226897
    Privilege adjustedPrivilege: Debug On or off: onsuccess or wait970227088
    System info queriedType: ProcessInformationinfo length mismatch970227243
    System info queriedType: ProcessInformationsuccess or wait970229851
    Privilege adjustedPrivilege: Tcb On or off: onsuccess or wait970232374
    Section loadedPath: C:\WINDOWS\system32\mswsock.dll Access: write and read and execute Type: commit Baseaddress: B80000 Size: 245760 Protection: execute Mapped to pid: own pidsuccess or wait970233250
    Section loadedPath: C:\WINDOWS\system32\mswsock.dll Access: query and write and read and execute Type: image Baseaddress: 71A50000 Size: 258048 Protection: read write Mapped to pid: own pidsuccess or wait970236238
    Section loadedPath: C:\WINDOWS\system32\hnetcfg.dll Access: query and write and read and execute Type: image Baseaddress: 662B0000 Size: 360448 Protection: read write Mapped to pid: own pidsuccess or wait970241894
    Section loadedPath: C:\WINDOWS\system32\wshtcpip.dll Access: write and read and execute Type: commit Baseaddress: 90000 Size: 20480 Protection: execute Mapped to pid: own pidsuccess or wait970255196
    Section loadedPath: C:\WINDOWS\system32\wshtcpip.dll Access: query and write and read and execute Type: image Baseaddress: 71A90000 Size: 32768 Protection: read write Mapped to pid: own pidsuccess or wait970257090
    File opened Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alertsuccess or wait970262782
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc Name: InstallDatesuccess or wait970263258
    File deletedPath: C:\Documents and Settings\Administrator\wevtapi.dllobject name not found970265744
    File deletedPath: C:\Documents and Settings\Administrator\taskmgr.exeobject name not found970265938
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc Name: MachineGuidsuccess or wait970266260
    Key value setPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: u Type: Dword Data: 68success or wait970276512
    Key value setPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: cid Type: Other Data: 97 BA 42 0F 98 88 93 72 success or wait970277211
    Privilege adjustedPrivilege: Create Symbolic Link On or off: onnot all assigned970279228
    File opened Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alertsuccess or wait970282008
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: InstallDatesuccess or wait970282381
    File opened Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alertsuccess or wait970284512
    File opened Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alertsuccess or wait970285756
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: InstallDatesuccess or wait970286136
    File opened Path: C:\WINDOWS\system Access: read attributes Options: no optionssuccess or wait970288722
    File createdPath: C:\WINDOWS\$NtUninstallKB22351$ Access: read data or list directory and write data or add file and append data or add subdirectory or create pipe instance and read ea and write ea and read attributes and write attributes and read control and synchronize Options: directory file and synchronous io non alert Attributes: hidden and systemsuccess or wait970289297
    File opened Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alertsuccess or wait970292945
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: InstallDatesuccess or wait970293562
    File control set Path: C:\WINDOWS\$NtUninstallKB22351$ Control Code: set compression Input Buffer: 0100success or wait970295209
    File openedPath: C:\WINDOWS\$NtUninstallKB22351$\1740621400 Access: read data or list directory and write data or add file and append data or add subdirectory or create pipe instance and read ea and write ea and execute or traverse and delete child and read attributes and write attributes and delete and read control and write dac and write owner and synchronize Options: synchronous io non alert and open reparse point Attributes: nonesuccess or wait970302044
    File control set Path: C:\WINDOWS\$NtUninstallKB22351$\1740621400 Control Code: set reparse point Input Buffer: 0C0000A0740000000000320034003200000000005C004400650076006900630065005C0073007600630068006F00730074002E006500780065005C0073006500740075007000000063003A005C00770069006E0064006F00770073005C00730079007300740065006D00330032005C00730065007400750070000000success or wait970303878
    File openedPath: C:\WINDOWS\$NtUninstallKB22351$\3522328898 Access: read data or list directory and write data or add file and append data or add subdirectory or create pipe instance and read ea and write ea and read attributes and write attributes and read control and synchronize Options: directory file and synchronous io non alert Attributes: hidden and systemsuccess or wait970304401
    File opened Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alertsuccess or wait970305873
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: InstallDatesuccess or wait970306449
    File openedPath: C:\WINDOWS\$NtUninstallKB22351$\:SummaryInformation Access: read data or list directory and write data or add file and append data or add subdirectory or create pipe instance and read ea and write ea and execute or traverse and delete child and read attributes and write attributes and delete and read control and write dac and write owner and synchronize Options: synchronous io non alert and open reparse point Attributes: nonesuccess or wait970308742
    File control set Path: C:\WINDOWS\$NtUninstallKB22351$:SummaryInformation Control Code: set reparse point Input Buffer: 0C0000A0660000000000240026003200000000005C004400650076006900630065005C006E0075006C006C005C0073006500740075007000000063003A005C00770069006E0064006F00770073005C00730079007300740065006D00330032005C00730065007400750070000000success or wait970309996
    File createdPath: C:\WINDOWS\$NtUninstallKB22351$\3522328898\U Access: synchronize Options: directory file Attributes: nonesuccess or wait970319212
    File opened Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alertsuccess or wait970320792
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: InstallDatesuccess or wait970321291
    File createdPath: C:\WINDOWS\$NtUninstallKB22351$\3522328898\L Access: synchronize Options: directory file Attributes: nonesuccess or wait970323694
    File other operationDisposition: BasicInformation Data : Creation Time: 08:27 05-05-1796 Last Access Time: 08:43 15-05-1771 Last Write Time: 21:32 12-08-1810 Change Time: 21:32 12-08-1810 File Attributes: hidden and system Path: C:\WINDOWS\$NtUninstallKB22351$success or wait970324680
    File opened Path: C:\WINDOWS\$NtUninstallKB22351$ Access: write dac Options: directory file and open reparse pointsuccess or wait970325440
    File opened Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alertsuccess or wait970329929
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: InstallDatesuccess or wait970330272
    System info queriedType: ModuleInformationinfo length mismatch970332307
    System info queriedType: ModuleInformationsuccess or wait970334718
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970336821
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970337061
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970337293
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970337476
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970337652
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970337836
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970338014
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970338197
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970338369
    File opened Path: C:\WINDOWS\system32\drivers\i8042prt.sys Access: write owner Options: open reparse pointsuccess or wait970338535
    File opened Path: C:\WINDOWS\system32\drivers\i8042prt.sys Access: write owner Options: open reparse pointsuccess or wait970339976
    File opened Path: C:\WINDOWS\system32\drivers\i8042prt.sys Access: write owner Options: open reparse pointsuccess or wait970342115
    File readPath: C:\WINDOWS\system32\drivers\i8042prt.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 success or wait970342380
    File readPath: C:\WINDOWS\system32\drivers\i8042prt.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 success or wait970342884
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970343204
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970343380
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970343547
    File opened Path: C:\WINDOWS\system32\drivers\cdrom.sys Access: write owner Options: open reparse pointsuccess or wait970343693
    File opened Path: C:\WINDOWS\system32\drivers\cdrom.sys Access: write owner Options: open reparse pointsuccess or wait970344416
    File opened Path: C:\WINDOWS\system32\drivers\cdrom.sys Access: write owner Options: open reparse pointsuccess or wait970345216
    File readPath: C:\WINDOWS\system32\drivers\cdrom.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 success or wait970345491
    File readPath: C:\WINDOWS\system32\drivers\cdrom.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 success or wait970345869
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970346197
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970346436
    File opened Path: C:\WINDOWS\system32\drivers\intelppm.sys Access: write owner Options: open reparse pointsuccess or wait970346595
    File opened Path: C:\WINDOWS\system32\drivers\intelppm.sys Access: write owner Options: open reparse pointsuccess or wait970347510
    File opened Path: C:\WINDOWS\system32\drivers\intelppm.sys Access: write owner Options: open reparse pointsuccess or wait970348164
    File readPath: C:\WINDOWS\system32\drivers\intelppm.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 success or wait970348418
    File readPath: C:\WINDOWS\system32\drivers\intelppm.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 success or wait970349228
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970349567
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970349743
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970349919
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970350110
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970350291
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970350568
    File opened Path: C:\WINDOWS\system32\drivers\termdd.sys Access: write owner Options: open reparse pointsuccess or wait970350715
    File opened Path: C:\WINDOWS\system32\drivers\termdd.sys Access: write owner Options: open reparse pointsuccess or wait970351439
    File opened Path: C:\WINDOWS\system32\drivers\termdd.sys Access: write owner Options: open reparse pointsuccess or wait970352078
    File readPath: C:\WINDOWS\system32\drivers\termdd.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 success or wait970352419
    File readPath: C:\WINDOWS\system32\drivers\termdd.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 success or wait970352773
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970353094
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970353256
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970353423
    File opened Path: C:\WINDOWS\system32\drivers\ipsec.sys Access: write owner Options: open reparse pointsuccess or wait970353583
    File opened Path: C:\WINDOWS\system32\drivers\ipsec.sys Access: write owner Options: open reparse pointsuccess or wait970354430
    File opened Path: C:\WINDOWS\system32\drivers\ipsec.sys Access: write owner Options: open reparse pointsuccess or wait970355073
    File readPath: C:\WINDOWS\system32\drivers\ipsec.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 success or wait970355324
    File readPath: C:\WINDOWS\system32\drivers\ipsec.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 success or wait970355677
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970356112
    File opened Path: C:\WINDOWS\system32\drivers\tcpip.sys Access: write owner Options: open reparse pointsuccess or wait970356266
    File opened Path: C:\WINDOWS\system32\drivers\tcpip.sys Access: write owner Options: open reparse pointsuccess or wait970357020
    File opened Path: C:\WINDOWS\system32\drivers\tcpip.sys Access: write owner Options: open reparse pointsuccess or wait970357692
    File readPath: C:\WINDOWS\system32\drivers\tcpip.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 success or wait970358218
    File readPath: C:\WINDOWS\system32\drivers\tcpip.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 success or wait970358596
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970358899
    File opened Path: C:\WINDOWS\system32\drivers\netbt.sys Access: write owner Options: open reparse pointsuccess or wait970359043
    File opened Path: C:\WINDOWS\system32\drivers\netbt.sys Access: write owner Options: open reparse pointsuccess or wait970359881
    File opened Path: C:\WINDOWS\system32\drivers\netbt.sys Access: write owner Options: open reparse pointsuccess or wait970360537
    File readPath: C:\WINDOWS\system32\drivers\netbt.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 success or wait970360790
    File readPath: C:\WINDOWS\system32\drivers\netbt.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 success or wait970361139
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970361580
    File opened Path: C:\WINDOWS\system32\drivers\afd.sys Access: write owner Options: open reparse pointsuccess or wait970361758
    File opened Path: C:\WINDOWS\system32\drivers\afd.sys Access: write owner Options: open reparse pointsuccess or wait970362538
    File opened Path: C:\WINDOWS\system32\drivers\afd.sys Access: write owner Options: open reparse pointsuccess or wait970363326
    File readPath: C:\WINDOWS\system32\drivers\afd.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E8 00 00 00 success or wait970363693
    File readPath: C:\WINDOWS\system32\drivers\afd.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E8 00 00 00 success or wait970364082
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970364462
    File opened Path: C:\WINDOWS\system32\drivers\netbios.sys Access: write owner Options: open reparse pointsuccess or wait970364622
    File opened Path: C:\WINDOWS\system32\drivers\netbios.sys Access: write owner Options: open reparse pointsuccess or wait970365490
    File opened Path: C:\WINDOWS\system32\drivers\netbios.sys Access: write owner Options: open reparse pointsuccess or wait970366224
    File readPath: C:\WINDOWS\system32\drivers\netbios.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 success or wait970366498
    File readPath: C:\WINDOWS\system32\drivers\netbios.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 success or wait970366880
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970367324
    File opened Path: C:\WINDOWS\system32\drivers\VBoxSF.sys Access: write owner Options: open reparse pointsuccess or wait970367482
    File opened Path: C:\WINDOWS\system32\drivers\VBoxSF.sys Access: write owner Options: open reparse pointsuccess or wait970368774
    File opened Path: C:\WINDOWS\system32\drivers\VBoxSF.sys Access: write owner Options: open reparse pointsuccess or wait970371333
    File readPath: C:\WINDOWS\system32\drivers\VBoxSF.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 F0 00 00 00 success or wait970371605
    File readPath: C:\WINDOWS\system32\drivers\VBoxSF.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 F0 00 00 00 success or wait970371957
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970372259
    File opened Path: C:\WINDOWS\system32\drivers\rdbss.sys Access: write owner Options: open reparse pointsuccess or wait970372510
    File opened Path: C:\WINDOWS\system32\drivers\rdbss.sys Access: write owner Options: open reparse pointsuccess or wait970373249
    File opened Path: C:\WINDOWS\system32\drivers\rdbss.sys Access: write owner Options: open reparse pointsuccess or wait970373889
    File readPath: C:\WINDOWS\system32\drivers\rdbss.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E8 00 00 00 success or wait970374141
    File readPath: C:\WINDOWS\system32\drivers\rdbss.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E8 00 00 00 success or wait970374607
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970374898
    File opened Path: C:\WINDOWS\system32\drivers\mrxsmb.sys Access: write owner Options: open reparse pointsuccess or wait970375057
    File opened Path: C:\WINDOWS\system32\drivers\mrxsmb.sys Access: write owner Options: open reparse pointsuccess or wait970375765
    File opened Path: C:\WINDOWS\system32\drivers\mrxsmb.sys Access: write owner Options: open reparse pointsuccess or wait970376514
    File readPath: C:\WINDOWS\system32\drivers\mrxsmb.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 success or wait970376768
    File readPath: C:\WINDOWS\system32\drivers\mrxsmb.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 success or wait970377118
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970377423
    File opened Path: C:\WINDOWS\system32\drivers\Fips.SYS Access: write owner Options: open reparse pointsuccess or wait970377570
    File opened Path: C:\WINDOWS\system32\drivers\Fips.SYS Access: write owner Options: open reparse pointsuccess or wait970378720
    File opened Path: C:\WINDOWS\system32\drivers\Fips.SYS Access: write owner Options: open reparse pointsuccess or wait970379417
    File readPath: C:\WINDOWS\system32\drivers\fips.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 success or wait970379676
    File readPath: C:\WINDOWS\system32\drivers\fips.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 success or wait970380111
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970380423
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970380611
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Startsuccess or wait970380796
    File opened Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alertsuccess or wait970381684
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: InstallDatesuccess or wait970382069
    Section loadedPath: \.mrxsmb Access: query and write and read and execute and extend size Type: commit Baseaddress: C30000 Size: 458752 Protection: read write Mapped to pid: own pidsuccess or wait970384534
    File opened Path: C:\WINDOWS\system32\drivers\mrxsmb.sys Access: write owner Options: open reparse pointsuccess or wait970384682
    File readPath: C:\WINDOWS\system32\drivers\mrxsmb.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 success or wait970384966
    File opened Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alertsuccess or wait970963595
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion Name: InstallDatesuccess or wait970964186
    File opened Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alertsuccess or wait970971677
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion Name: InstallDatesuccess or wait970972317
    Key value setPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.mrxsmb Name: Type Type: Dword Data: 1success or wait970975199
    Key value setPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.mrxsmb Name: Start Type: Dword Data: 3success or wait970976291
    Key value setPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.mrxsmb Name: ImagePath Type: String Data: \*success or wait970977358
    System info queriedType: ProcessInformationinfo length mismatch970978564
    System info queriedType: ProcessInformationsuccess or wait970981591
    Section loadedPath: none Access: query and write and read and execute and extend size Type: reserve Baseaddress: C30000 Size: 262144 Protection: read write Mapped to pid: own pidsuccess or wait970984430
    Memory allocatedPID: 772 Path: C:\WINDOWS\explorer.exe Base: C30000 Length: 6F858 Allocation Type: null Protection: page read and writesuccess or wait970984555
    Section loadedPath: none Access: query and write and read and execute and extend size Type: reserve Baseaddress: C30000 Size: 262144 Protection: read write Mapped to pid: 608conflicting addresses972480582
    Section loadedPath: none Access: query and write and read and execute and extend size Type: reserve Baseaddress: AB0000 Size: 262144 Protection: read write Mapped to pid: 608success or wait972527621
    Thread resumedTID: 404 PID: 608 Path: C:\WINDOWS\system32\winlogon.exesuccess or wait972576779
    Thread suspendedTID: 1572 PID: 608 Path: C:\WINDOWS\system32\winlogon.exesuccess or wait972579573
    Thread suspendedTID: 1576 PID: 608 Path: C:\WINDOWS\system32\winlogon.exesuccess or wait972580543
    Thread suspendedTID: 1580 PID: 608 Path: C:\WINDOWS\system32\winlogon.exesuccess or wait972581640
    File opened Path: C:\WINDOWS\system32\drivers\mrxsmb.sys Access: write owner Options: open reparse pointsuccess or wait972582560
    File control set Path: C:\WINDOWS\system32\drivers\mrxsmb.sys Control Code: set compression Input Buffer: 0000success or wait972582868
    Section loadedPath: C:\WINDOWS\system32\drivers\mrxsmb.sys Access: write and read Type: commit Baseaddress: C30000 Size: 458752 Protection: read write Mapped to pid: own pidsuccess or wait972583156
    Symbolic link createdSymbolic link name: \* File path: C:\WINDOWS\system32\drivers\mrxsmb.syssuccess or wait972601520
    File opened Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alertsuccess or wait972602604
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion Name: InstallDatesuccess or wait972603078
    Driver loadedService Name: \registry\MACHINE\SYSTEM\CurrentControlSet\services\.mrxsmbsuccess or wait972605494
    File opened Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alertsuccess or wait972958367
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion Name: InstallDatesuccess or wait972958805
    Thread suspendedTID: 1580 PID: 608 Path: C:\WINDOWS\system32\winlogon.exesuccess or wait972961199
    Thread suspendedTID: 1576 PID: 608 Path: C:\WINDOWS\system32\winlogon.exesuccess or wait972961323
    Thread suspendedTID: 1572 PID: 608 Path: C:\WINDOWS\system32\winlogon.exesuccess or wait972961437
    Section loadedPath: \.mrxsmb Access: query and write and read and execute and extend size Type: commit Baseaddress: C30000 Size: 458752 Protection: readonly Mapped to pid: own pidsuccess or wait972961567
    File createdPath: ACPI#PNP0303#2&da1a3ff&0\L\gkaiogto Access: append data or add subdirectory or create pipe instance and synchronize Options: synchronous io non alert Attributes: nonesuccess or wait972961784
    File writePath: \L\gkaiogto Offset: 0 Length: 455424 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 70 72 6F 67 72 61 6D 20 63 61 6E 6E 6F 74 20 62 65 20 72 75 6E 20 69 6E 20 44 4F 53 20 6D 6F 64 65 2E 0D 0D 0A 24 00 00 00 00 00 00 00 5E B2 BD 26 1A D3 D3 75 1A D3 D3 75 1A D3 D3 75 1A D3 D2 75 56 D2 D3 75 D9 DC 8E 75 11 D3 D3 75 D9 DC DC 75 1F D3 D3 75 D9 DC 8F 75 1B D3 D3 75 D9 DC 8D 75 1B D3 D3 75 D9 DC 8C 75 76 D3 D3 75 D9 DC 89 75 1B D3 D3 75 52 69 63 68 1A D3 D3 75 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 0B 00 5C 53 19 4B 00 00 00 00 00 00 00 00 E0 00 0E 01 0B 01 07 0A 80 28 06 success or wait973193071
    File openedPath: ACPI#PNP0303#2&da1a3ff&0\{1B372133-BFFA-4dba-9CCF-5474BED6A9F6} Access: append data or add subdirectory or create pipe instance and synchronize Options: synchronous io non alert Attributes: nonesuccess or wait973398816
    File writePath: \{1B372133-BFFA-4dba-9CCF-5474BED6A9F6} Offset: none Length: 2048 Value: 4C CE 1D 73 2D C6 CA D1 B8 09 DB 19 2D C6 CA D1 58 B0 7A E3 2D C6 CA D1 CB 43 36 84 2D C6 CA D1 29 61 6D 85 2D C6 CA D1 98 0E E8 69 2D C6 CA D1 56 37 EF 66 2D C6 CA D1 7B C9 62 63 2D C6 CA D1 DC 75 65 E3 2D C6 CA D1 A4 84 9A 50 2D C6 CA D1 44 C0 12 E2 2D C6 CA D1 54 FC 31 AA 2D C6 CA D1 56 7B C1 AD 2D C6 CA D1 63 FE B1 F1 2D C6 CA D1 62 A5 83 DD 2D C6 CA D1 48 D1 3F 33 2D C6 CA D1 5A A9 23 BD 2D C6 CA D1 A3 01 E6 CC 2D C6 CA D1 C8 5C 42 08 2D C6 CA D1 62 0F 88 F4 2D C6 CA D1 C9 EB 84 0C 2D C6 CA D1 45 89 A0 17 2D C6 CA D1 55 98 71 2F 2C C6 CA D1 BE 19 76 F3 2C C6 CA D1 47 C0 A5 CB 2C C6 CA D1 BE A0 85 BF 2C C6 CA D1 18 F7 9E D6 2C C6 CA D1 D8 33 BC F1 2C C6 CA D1 42 8D 17 43 2C C6 CA D1 62 D3 CB 46 2C C6 CA D1 BA 0C 96 A9 2C C6 CA D1 44 79 A2 97 2C C6 CA success or wait973401317
    File opened Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alertsuccess or wait973411617
    File createdPath: C:\WINDOWS\system32\drivers\1254331455.sys Access: append data or add subdirectory or create pipe instance and synchronize Options: synchronous io non alert Attributes: nonesuccess or wait973412437
    File writePath: C:\WINDOWS\system32\drivers\1254331455.sys Offset: none Length: 17408 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E8 00 00 00 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 70 72 6F 67 72 61 6D 20 63 61 6E 6E 6F 74 20 62 65 20 72 75 6E 20 69 6E 20 44 4F 53 20 6D 6F 64 65 2E 0D 0D 0A 24 00 00 00 00 00 00 00 B9 CF 0B 33 FD AE 65 60 FD AE 65 60 FD AE 65 60 7E A6 6A 60 FE AE 65 60 7E A6 38 60 EC AE 65 60 FD AE 64 60 12 AE 65 60 7E A6 39 60 FC AE 65 60 73 A6 3A 60 EE AE 65 60 7E A6 3B 60 FC AE 65 60 7E A6 3F 60 FC AE 65 60 52 69 63 68 FD AE 65 60 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 05 00 FC 4F 1D 4E 00 00 00 00 00 00 00 00 E0 00 02 success or wait973429258
    Key value setPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\1254331455 Name: Start Type: Dword Data: 3success or wait973430770
    Key value setPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\1254331455 Name: Type Type: Dword Data: 1success or wait973431258
    Key value setPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\1254331455 Name: ErrorControl Type: Dword Data: 1success or wait973431715
    Key value setPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\1254331455 Name: DisplayName Type: String Data: Virtual Bus for Microsoft ACPI-Compliant Systemsuccess or wait973432051
    Key value setPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000 Name: Service Type: String Data: 1254331455success or wait973433534
    Key value setPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000 Name: ClassGUID Type: String Data: {4D36E97D-E325-11CE-BFC1-08002BE10318}success or wait973433911
    Key value setPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000 Name: Class Type: String Data: Systemsuccess or wait973434580
    Key value setPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000 Name: DeviceDesc Type: String Data: PCI bussuccess or wait973434915
    Key value setPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000 Name: Mfg Type: String Data: Technologies Incsuccess or wait973435708
    Key value setPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000 Name: LocationInformation Type: String Data: on Microsoft ACPI-Compliant Systemsuccess or wait973436211
    Key value setPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000 Name: ConfigFlags Type: Dword Data: 0success or wait973437206
    File opened Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alertsuccess or wait984025783
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion Name: InstallDatesuccess or wait984026328
    File opened Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alertsuccess or wait984065618
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion Name: InstallDatesuccess or wait984066049
    File opened Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alertsuccess or wait984078680
    Key value queriedPath: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion Name: InstallDatesuccess or wait984079060
    Analysis File: winlogon.exe PID: 608 Parent PID: 772
    Sections
    General
    Start time:04:48:57
    Start date:26/07/2011
    Path:C:\WINDOWS\system32\winlogon.exe
    Commandline:winlogon.exe
    Imagebase:0x1000000
    File size:507904 bytes
    MD5 hash:ED0EF0A136DEC83DF69F04118870003E
    Section Activities:
    Section loaded by Windows
    File PathAccessTypeBaseSizeMapped to pidProtectionCompletionCountSource Address
    C:\WINDOWS\system32\msctf.dllwrite and read and executecommit15D0000299008own pidexecutesuccess or wait1
    Section loaded by program
    File PathAccessTypeBaseSizeMapped to pidProtectionCompletionCountSource Address
    Chronological sections
    OperationDataCompletionTime
    Section loadedPath: C:\WINDOWS\system32\msctf.dll Access: write and read and execute Type: commit Baseaddress: 15D0000 Size: 299008 Protection: execute Mapped to pid: own pidsuccess or wait972578889
    Analysis File: * PID: 4 Parent PID: -1
    Sections
    General
    Start time:04:48:57
    Start date:26/07/2011
    Path:\*
    Commandline:not known
    Imagebase:
    File size:455424 bytes
    MD5 hash:C7C653B9CE1B9177200372816B560E64
    File Activities:
    File opened
    File PathAccessOptionsCompletionCountSource Address
    C:\WINDOWS\AppPatch\drvmain.sdbgeneric readno optionssuccess or wait1
    Section Activities:
    Section loaded by Windows
    File PathAccessTypeBaseSizeMapped to pidProtectionCompletionCountSource Address
    Section loaded by program
    File PathAccessTypeBaseSizeMapped to pidProtectionCompletionCountSource Address
    C:\WINDOWS\AppPatch\drvmain.sdbreadcommit4000012288own pidreadonlysuccess or wait1
    Registry Activities:
    Key value set
    Key PathNameTypeDataCompletionCountSource Address
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_.MRXSMB\0000\ControlActiveServiceString.mrxsmbsuccess or wait1
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.mrxsmb\EnumCountDword1success or wait1
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.mrxsmb\EnumNextInstanceDword1success or wait1
    Key value queried
    Key PathNameCompletionCountSource Address
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.mrxsmb\EnumCountobject name not found1
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.mrxsmbImagePathsuccess or wait1
    Driver Activities:
    Device created
    Device nameDevice typeCompletionCountSource Address
    \??\ACPI#PNP0303#2&da1a3ff&0unknownsuccess or wait1
    Chronological sections
    OperationDataCompletionTime
    Key value queriedPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.mrxsmb\Enum Name: Countobject name not found972829718
    Key value setPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_.MRXSMB\0000\Control Name: ActiveService Type: String Data: .mrxsmbsuccess or wait972838566
    Key value setPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.mrxsmb\Enum Name: Count Type: Dword Data: 1success or wait972838752
    Key value setPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.mrxsmb\Enum Name: NextInstance Type: Dword Data: 1success or wait972838897
    Key value queriedPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.mrxsmb Name: ImagePathsuccess or wait972839040
    File opened Path: C:\WINDOWS\AppPatch\drvmain.sdb Access: generic read Options: no optionssuccess or wait972839239
    Section loadedPath: C:\WINDOWS\AppPatch\drvmain.sdb Access: read Type: commit Baseaddress: 40000 Size: 12288 Protection: readonly Mapped to pid: own pidsuccess or wait972839839
    Device createdDevice Name: \??\ACPI#PNP0303#2&da1a3ff&0 Device Type: unknownsuccess or wait972862045
    Analysis File: 1254331455.SYS PID: 4 Parent PID: -1
    Sections
    General
    Start time:04:49:00
    Start date:26/07/2011
    Path:C:\WINDOWS\System32\Drivers\1254331455.SYS
    Commandline:not known
    Imagebase:
    File size:17408 bytes
    MD5 hash:88473C7FF4698E92BC7177415E14D666
    File Activities:
    File opened
    File PathAccessOptionsCompletionCountSource Address
    C:\WINDOWS\AppPatch\drvmain.sdbgeneric readno optionssuccess or wait1
    Section Activities:
    Section loaded by Windows
    File PathAccessTypeBaseSizeMapped to pidProtectionCompletionCountSource Address
    Section loaded by program
    File PathAccessTypeBaseSizeMapped to pidProtectionCompletionCountSource Address
    C:\WINDOWS\AppPatch\drvmain.sdbreadcommit4000012288own pidreadonlysuccess or wait1
    Registry Activities:
    Key value set
    Key PathNameTypeDataCompletionCountSource Address
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000\ControlActiveServiceString1254331455success or wait1
    Key value queried
    Key PathNameCompletionCountSource Address
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\1254331455\EnumCountsuccess or wait1
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000ConfigFlagssuccess or wait1
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000Legacyobject name not found1
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\1254331455ImagePathobject name not found1
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000Countsuccess or wait1
    Chronological sections
    OperationDataCompletionTime
    Key value queriedPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\1254331455\Enum Name: Countsuccess or wait981160532
    Key value queriedPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000 Name: ConfigFlagssuccess or wait981161973
    Key value queriedPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000 Name: Legacyobject name not found981162429
    Key value setPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000\Control Name: ActiveService Type: String Data: 1254331455success or wait981162829
    Key value queriedPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\1254331455 Name: ImagePathobject name not found981163119
    File opened Path: C:\WINDOWS\AppPatch\drvmain.sdb Access: generic read Options: no optionssuccess or wait981163318
    Section loadedPath: C:\WINDOWS\AppPatch\drvmain.sdb Access: read Type: commit Baseaddress: 40000 Size: 12288 Protection: readonly Mapped to pid: own pidsuccess or wait981163896
    Key value queriedPath: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000 Name: Countsuccess or wait981174751
    Analysis File: svchost.exe PID: 1560 Parent PID: 652
    Sections
    General
    Start time:04:49:00
    Start date:26/07/2011
    Path:\Device\svchost.exe
    Commandline:not known
    Imagebase:0x400000
    File size: bytes
    MD5 hash:
    Section Activities:
    Section loaded by Windows
    File PathAccessTypeBaseSizeMapped to pidProtectionCompletionCountSource Address
    \KnownDlls\kernel32.dllwrite and read and executeunknown7C8000001007616own pidread writesuccess or wait1
    \NLS\NlsSectionUnicodereadunknown26000090112own pidreadonlysuccess or wait1
    \NLS\NlsSectionLocalereadunknown280000266240own pidreadonlysuccess or wait1
    \NLS\NlsSectionSortkeyquery and readunknown2D0000266240own pidreadonlysuccess or wait1
    \NLS\NlsSectionSortTblsreadunknown32000024576own pidreadonlysuccess or wait1
    Section loaded by program
    File PathAccessTypeBaseSizeMapped to pidProtectionCompletionCountSource Address
    Chronological sections
    OperationDataCompletionTime
    Section loadedPath: \KnownDlls\kernel32.dll Access: write and read and execute Type: unknown Baseaddress: 7C800000 Size: 1007616 Protection: read write Mapped to pid: own pidsuccess or wait982137316
    Section loadedPath: \NLS\NlsSectionUnicode Access: read Type: unknown Baseaddress: 260000 Size: 90112 Protection: readonly Mapped to pid: own pidsuccess or wait982142935
    Section loadedPath: \NLS\NlsSectionLocale Access: read Type: unknown Baseaddress: 280000 Size: 266240 Protection: readonly Mapped to pid: own pidsuccess or wait982143766
    Section loadedPath: \NLS\NlsSectionSortkey Access: query and read Type: unknown Baseaddress: 2D0000 Size: 266240 Protection: readonly Mapped to pid: own pidsuccess or wait982144463
    Section loadedPath: \NLS\NlsSectionSortTbls Access: read Type: unknown Baseaddress: 320000 Size: 24576 Protection: readonly Mapped to pid: own pidsuccess or wait982144881
    Copyright 2010 Joe Security | All rights reserved | www.joebox.org | www.joedoc.org | This page is optimized for firefox - 1024x786