| Operation | Data | Completion | Time |
| Process terminated | PID: not known Path: not known | success or wait | 1059158966 |
| Section loaded | Path: \KnownDlls\kernel32.dll Access: write and read and execute Type: unknown Baseaddress: 7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid | success or wait | 966287139 |
| Section loaded | Path: \NLS\NlsSectionUnicode Access: read Type: unknown Baseaddress: 1D0000 Size: 90112 Protection: readonly Mapped to pid: own pid | success or wait | 966292686 |
| Section loaded | Path: \NLS\NlsSectionLocale Access: read Type: unknown Baseaddress: 1F0000 Size: 266240 Protection: readonly Mapped to pid: own pid | success or wait | 966293250 |
| Section loaded | Path: \NLS\NlsSectionSortkey Access: query and read Type: unknown Baseaddress: 240000 Size: 266240 Protection: readonly Mapped to pid: own pid | success or wait | 966293741 |
| Section loaded | Path: \NLS\NlsSectionSortTbls Access: read Type: unknown Baseaddress: 290000 Size: 24576 Protection: readonly Mapped to pid: own pid | success or wait | 966294031 |
| Section loaded | Path: \KnownDlls\ADVAPI32.dll Access: write and read and execute Type: unknown Baseaddress: 77DD0000 Size: 634880 Protection: read write Mapped to pid: own pid | success or wait | 966295334 |
| Section loaded | Path: \KnownDlls\RPCRT4.dll Access: write and read and execute Type: unknown Baseaddress: 77E70000 Size: 598016 Protection: read write Mapped to pid: own pid | success or wait | 966296683 |
| Section loaded | Path: \KnownDlls\Secur32.dll Access: write and read and execute Type: unknown Baseaddress: 77FE0000 Size: 69632 Protection: read write Mapped to pid: own pid | success or wait | 966298283 |
| Section loaded | Path: C:\WINDOWS\system32\browseui.dll Access: query and write and read and execute Type: image Baseaddress: 75F80000 Size: 1036288 Protection: read write Mapped to pid: own pid | success or wait | 966303725 |
| Section loaded | Path: \KnownDlls\GDI32.dll Access: write and read and execute Type: unknown Baseaddress: 77F10000 Size: 299008 Protection: read write Mapped to pid: own pid | success or wait | 966306535 |
| Section loaded | Path: \KnownDlls\USER32.dll Access: write and read and execute Type: unknown Baseaddress: 7E410000 Size: 593920 Protection: read write Mapped to pid: own pid | success or wait | 966307733 |
| Section loaded | Path: \KnownDlls\msvcrt.dll Access: write and read and execute Type: unknown Baseaddress: 77C10000 Size: 360448 Protection: read write Mapped to pid: own pid | success or wait | 966310863 |
| Section loaded | Path: \KnownDlls\ole32.dll Access: write and read and execute Type: unknown Baseaddress: 774E0000 Size: 1298432 Protection: read write Mapped to pid: own pid | success or wait | 966312633 |
| Section loaded | Path: \KnownDlls\SHLWAPI.dll Access: write and read and execute Type: unknown Baseaddress: 77F60000 Size: 483328 Protection: read write Mapped to pid: own pid | success or wait | 966315291 |
| Section loaded | Path: \KnownDlls\OLEAUT32.dll Access: write and read and execute Type: unknown Baseaddress: 77120000 Size: 569344 Protection: read write Mapped to pid: own pid | success or wait | 966319048 |
| Section loaded | Path: C:\WINDOWS\system32\shdocvw.dll Access: query and write and read and execute Type: image Baseaddress: 7E290000 Size: 1511424 Protection: read write Mapped to pid: own pid | success or wait | 966321992 |
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and write and read and execute Type: image Baseaddress: 77A80000 Size: 610304 Protection: read write Mapped to pid: own pid | success or wait | 966325503 |
| Section loaded | Path: C:\WINDOWS\system32\msasn1.dll Access: query and write and read and execute Type: image Baseaddress: 77B20000 Size: 73728 Protection: read write Mapped to pid: own pid | success or wait | 966329424 |
| Section loaded | Path: C:\WINDOWS\system32\cryptui.dll Access: query and write and read and execute Type: image Baseaddress: 754D0000 Size: 524288 Protection: read write Mapped to pid: own pid | success or wait | 966333839 |
| Section loaded | Path: C:\WINDOWS\system32\netapi32.dll Access: query and write and read and execute Type: image Baseaddress: 5B860000 Size: 348160 Protection: read write Mapped to pid: own pid | success or wait | 966353202 |
| Section loaded | Path: \KnownDlls\VERSION.dll Access: write and read and execute Type: unknown Baseaddress: 77C00000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 966356291 |
| Section loaded | Path: \KnownDlls\WININET.dll Access: write and read and execute Type: unknown Baseaddress: 3D930000 Size: 942080 Protection: read write Mapped to pid: own pid | success or wait | 966357569 |
| Section loaded | Path: \KnownDlls\Normaliz.dll Access: write and read and execute Type: unknown Baseaddress: 400000 Size: 36864 Protection: read write Mapped to pid: own pid | success or wait | 966360343 |
| Section loaded | Path: \KnownDlls\urlmon.dll Access: write and read and execute Type: unknown Baseaddress: 78130000 Size: 1253376 Protection: read write Mapped to pid: own pid | success or wait | 966362508 |
| Section loaded | Path: \KnownDlls\iertutil.dll Access: write and read and execute Type: unknown Baseaddress: 3DFD0000 Size: 1998848 Protection: read write Mapped to pid: own pid | success or wait | 966367828 |
| Section loaded | Path: C:\WINDOWS\system32\wintrust.dll Access: query and write and read and execute Type: image Baseaddress: 76C30000 Size: 188416 Protection: read write Mapped to pid: own pid | success or wait | 966373957 |
| Section loaded | Path: \KnownDlls\IMAGEHLP.dll Access: write and read and execute Type: unknown Baseaddress: 76C90000 Size: 163840 Protection: read write Mapped to pid: own pid | success or wait | 966375648 |
| Section loaded | Path: \KnownDlls\WLDAP32.dll Access: write and read and execute Type: unknown Baseaddress: 76F60000 Size: 180224 Protection: read write Mapped to pid: own pid | success or wait | 966379287 |
| Section loaded | Path: \KnownDlls\SHELL32.dll Access: write and read and execute Type: unknown Baseaddress: 7C9C0000 Size: 8482816 Protection: read write Mapped to pid: own pid | success or wait | 966382892 |
| Section loaded | Path: C:\WINDOWS\system32\uxtheme.dll Access: query and write and read and execute Type: image Baseaddress: 5AD70000 Size: 229376 Protection: read write Mapped to pid: own pid | success or wait | 966387233 |
| Section loaded | Path: C:\WINDOWS\system32\shimeng.dll Access: query and write and read and execute Type: image Baseaddress: 5CB70000 Size: 155648 Protection: read write Mapped to pid: own pid | success or wait | 966390350 |
| Section loaded | Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 2B0000 Size: 1208320 Protection: readonly Mapped to pid: own pid | success or wait | 966392324 |
| Section loaded | Path: C:\WINDOWS\AppPatch\acgenral.dll Access: write and read and execute Type: commit Baseaddress: 410000 Size: 1855488 Protection: execute Mapped to pid: own pid | success or wait | 966397048 |
| Section loaded | Path: C:\WINDOWS\AppPatch\acgenral.dll Access: write and read and execute Type: commit Baseaddress: 410000 Size: 1855488 Protection: execute Mapped to pid: own pid | success or wait | 966397975 |
| Section loaded | Path: C:\WINDOWS\AppPatch\acgenral.dll Access: query and write and read and execute Type: image Baseaddress: 6F880000 Size: 1875968 Protection: read write Mapped to pid: own pid | success or wait | 966398753 |
| Section loaded | Path: C:\WINDOWS\system32\winmm.dll Access: query and write and read and execute Type: image Baseaddress: 76B40000 Size: 184320 Protection: read write Mapped to pid: own pid | success or wait | 966400974 |
| Section loaded | Path: C:\WINDOWS\system32\msacm32.dll Access: query and write and read and execute Type: image Baseaddress: 77BE0000 Size: 86016 Protection: read write Mapped to pid: own pid | success or wait | 966403909 |
| Section loaded | Path: \KnownDlls\USERENV.dll Access: write and read and execute Type: unknown Baseaddress: 769C0000 Size: 737280 Protection: read write Mapped to pid: own pid | success or wait | 966406478 |
| Section loaded | Path: \NLS\NlsSectionCType Access: read Type: unknown Baseaddress: 410000 Size: 12288 Protection: readonly Mapped to pid: own pid | success or wait | 966409803 |
| Section loaded | Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit Baseaddress: 380000 Size: 110592 Protection: execute Mapped to pid: own pid | success or wait | 966430266 |
| Section loaded | Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit Baseaddress: 380000 Size: 110592 Protection: execute Mapped to pid: own pid | success or wait | 966431257 |
| Section loaded | Path: C:\WINDOWS\system32\imm32.dll Access: query and write and read and execute Type: image Baseaddress: 76390000 Size: 118784 Protection: read write Mapped to pid: own pid | success or wait | 966432027 |
| Section loaded | Path: C:\WINDOWS\system32\browseui.dll Access: read Type: commit Baseaddress: 870000 Size: 1028096 Protection: readonly Mapped to pid: own pid | success or wait | 966443944 |
| Section loaded | Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll Access: write and read and execute Type: commit Baseaddress: 870000 Size: 1056768 Protection: execute Mapped to pid: own pid | success or wait | 966461984 |
| Section loaded | Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll Access: query and write and read and execute Type: image Baseaddress: 773D0000 Size: 1060864 Protection: read write Mapped to pid: own pid | success or wait | 966463048 |
| Section loaded | Path: C:\WINDOWS\WindowsShell.Manifest Access: write and read and execute Type: commit Baseaddress: 3B0000 Size: 4096 Protection: execute Mapped to pid: own pid | success or wait | 966467714 |
| Section loaded | Path: unknown Access: unknown Type: unknown Baseaddress: 3B0000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 966468947 |
| Section loaded | Path: unknown Access: unknown Type: unknown Baseaddress: 3B0000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 966469815 |
| Section loaded | Path: C:\WINDOWS\system32\riched20.dll Access: query and write and read and execute Type: image Baseaddress: 74E30000 Size: 446464 Protection: read write Mapped to pid: own pid | success or wait | 966529256 |
| Section loaded | Path: C:\WINDOWS\system32\shdocvw.dll Access: read Type: commit Baseaddress: AB0000 Size: 1499136 Protection: readonly Mapped to pid: own pid | success or wait | 966536565 |
| Section loaded | Path: C:\WINDOWS\system32\shell32.dll Access: read Type: commit Baseaddress: 1100000 Size: 8462336 Protection: readonly Mapped to pid: own pid | success or wait | 966559281 |
| Section loaded | Path: \KnownDlls\comctl32.dll Access: write and read and execute Type: unknown Baseaddress: 5D090000 Size: 630784 Protection: read write Mapped to pid: own pid | success or wait | 966573952 |
| Section loaded | Path: C:\WINDOWS\system32\comctl32.dll Access: read Type: commit Baseaddress: AD0000 Size: 618496 Protection: readonly Mapped to pid: own pid | success or wait | 966578199 |
| Section loaded | Path: none Access: query and write and read and execute and extend size Type: commit Baseaddress: B50000 Size: 98304 Protection: execute and read and write Mapped to pid: own pid | success or wait | 966629926 |
| Thread context set | TID: 668 PID: 772 DR0: 0 DR1: 0 DR2: 0 DR3: 7C90D51E DR7: 40 EIP: 0 EFLAGS: 0 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 966630888 |
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and write and read and execute Type: image Baseaddress: 71AB0000 Size: 94208 Protection: read write Mapped to pid: own pid | success or wait | 966658364 |
| Section loaded | Path: C:\WINDOWS\system32\ws2help.dll Access: query and write and read and execute Type: image Baseaddress: 71AA0000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 966660944 |
| Thread delayed | Time: 1 TID: 1640 | success or wait | 966689812 |
| File deleted | Path: C:\Documents and Settings\Administrator\Desktop\contacts_053.exe | success or wait | 970225533 |
| File opened | Path: ACPI#PNP0303#2&da1a3ff&0 Access: synchronize Options: 10000 | object name not found | 970226897 |
| Privilege adjusted | Privilege: Debug On or off: on | success or wait | 970227088 |
| System info queried | Type: ProcessInformation | info length mismatch | 970227243 |
| System info queried | Type: ProcessInformation | success or wait | 970229851 |
| Privilege adjusted | Privilege: Tcb On or off: on | success or wait | 970232374 |
| Section loaded | Path: C:\WINDOWS\system32\mswsock.dll Access: write and read and execute Type: commit Baseaddress: B80000 Size: 245760 Protection: execute Mapped to pid: own pid | success or wait | 970233250 |
| Section loaded | Path: C:\WINDOWS\system32\mswsock.dll Access: query and write and read and execute Type: image Baseaddress: 71A50000 Size: 258048 Protection: read write Mapped to pid: own pid | success or wait | 970236238 |
| Section loaded | Path: C:\WINDOWS\system32\hnetcfg.dll Access: query and write and read and execute Type: image Baseaddress: 662B0000 Size: 360448 Protection: read write Mapped to pid: own pid | success or wait | 970241894 |
| Section loaded | Path: C:\WINDOWS\system32\wshtcpip.dll Access: write and read and execute Type: commit Baseaddress: 90000 Size: 20480 Protection: execute Mapped to pid: own pid | success or wait | 970255196 |
| Section loaded | Path: C:\WINDOWS\system32\wshtcpip.dll Access: query and write and read and execute Type: image Baseaddress: 71A90000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 970257090 |
| File opened | Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alert | success or wait | 970262782 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc Name: InstallDate | success or wait | 970263258 |
| File deleted | Path: C:\Documents and Settings\Administrator\wevtapi.dll | object name not found | 970265744 |
| File deleted | Path: C:\Documents and Settings\Administrator\taskmgr.exe | object name not found | 970265938 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc Name: MachineGuid | success or wait | 970266260 |
| Key value set | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: u Type: Dword Data: 68 | success or wait | 970276512 |
| Key value set | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: cid Type: Other Data: 97 BA 42 0F 98 88 93 72 | success or wait | 970277211 |
| Privilege adjusted | Privilege: Create Symbolic Link On or off: on | not all assigned | 970279228 |
| File opened | Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alert | success or wait | 970282008 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: InstallDate | success or wait | 970282381 |
| File opened | Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alert | success or wait | 970284512 |
| File opened | Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alert | success or wait | 970285756 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: InstallDate | success or wait | 970286136 |
| File opened | Path: C:\WINDOWS\system Access: read attributes Options: no options | success or wait | 970288722 |
| File created | Path: C:\WINDOWS\$NtUninstallKB22351$ Access: read data or list directory and write data or add file and append data or add subdirectory or create pipe instance and read ea and write ea and read attributes and write attributes and read control and synchronize Options: directory file and synchronous io non alert Attributes: hidden and system | success or wait | 970289297 |
| File opened | Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alert | success or wait | 970292945 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: InstallDate | success or wait | 970293562 |
| File control set | Path: C:\WINDOWS\$NtUninstallKB22351$ Control Code: set compression Input Buffer: 0100 | success or wait | 970295209 |
| File opened | Path: C:\WINDOWS\$NtUninstallKB22351$\1740621400 Access: read data or list directory and write data or add file and append data or add subdirectory or create pipe instance and read ea and write ea and execute or traverse and delete child and read attributes and write attributes and delete and read control and write dac and write owner and synchronize Options: synchronous io non alert and open reparse point Attributes: none | success or wait | 970302044 |
| File control set | Path: C:\WINDOWS\$NtUninstallKB22351$\1740621400 Control Code: set reparse point Input Buffer: 0C0000A0740000000000320034003200000000005C004400650076006900630065005C0073007600630068006F00730074002E006500780065005C0073006500740075007000000063003A005C00770069006E0064006F00770073005C00730079007300740065006D00330032005C00730065007400750070000000 | success or wait | 970303878 |
| File opened | Path: C:\WINDOWS\$NtUninstallKB22351$\3522328898 Access: read data or list directory and write data or add file and append data or add subdirectory or create pipe instance and read ea and write ea and read attributes and write attributes and read control and synchronize Options: directory file and synchronous io non alert Attributes: hidden and system | success or wait | 970304401 |
| File opened | Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alert | success or wait | 970305873 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: InstallDate | success or wait | 970306449 |
| File opened | Path: C:\WINDOWS\$NtUninstallKB22351$\:SummaryInformation Access: read data or list directory and write data or add file and append data or add subdirectory or create pipe instance and read ea and write ea and execute or traverse and delete child and read attributes and write attributes and delete and read control and write dac and write owner and synchronize Options: synchronous io non alert and open reparse point Attributes: none | success or wait | 970308742 |
| File control set | Path: C:\WINDOWS\$NtUninstallKB22351$:SummaryInformation Control Code: set reparse point Input Buffer: 0C0000A0660000000000240026003200000000005C004400650076006900630065005C006E0075006C006C005C0073006500740075007000000063003A005C00770069006E0064006F00770073005C00730079007300740065006D00330032005C00730065007400750070000000 | success or wait | 970309996 |
| File created | Path: C:\WINDOWS\$NtUninstallKB22351$\3522328898\U Access: synchronize Options: directory file Attributes: none | success or wait | 970319212 |
| File opened | Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alert | success or wait | 970320792 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: InstallDate | success or wait | 970321291 |
| File created | Path: C:\WINDOWS\$NtUninstallKB22351$\3522328898\L Access: synchronize Options: directory file Attributes: none | success or wait | 970323694 |
| File other operation | Disposition: BasicInformation Data : Creation Time: 08:27 05-05-1796 Last Access Time: 08:43 15-05-1771 Last Write Time: 21:32 12-08-1810 Change Time: 21:32 12-08-1810 File Attributes: hidden and system Path: C:\WINDOWS\$NtUninstallKB22351$ | success or wait | 970324680 |
| File opened | Path: C:\WINDOWS\$NtUninstallKB22351$ Access: write dac Options: directory file and open reparse point | success or wait | 970325440 |
| File opened | Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alert | success or wait | 970329929 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: InstallDate | success or wait | 970330272 |
| System info queried | Type: ModuleInformation | info length mismatch | 970332307 |
| System info queried | Type: ModuleInformation | success or wait | 970334718 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970336821 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970337061 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970337293 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970337476 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970337652 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970337836 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970338014 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970338197 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970338369 |
| File opened | Path: C:\WINDOWS\system32\drivers\i8042prt.sys Access: write owner Options: open reparse point | success or wait | 970338535 |
| File opened | Path: C:\WINDOWS\system32\drivers\i8042prt.sys Access: write owner Options: open reparse point | success or wait | 970339976 |
| File opened | Path: C:\WINDOWS\system32\drivers\i8042prt.sys Access: write owner Options: open reparse point | success or wait | 970342115 |
| File read | Path: C:\WINDOWS\system32\drivers\i8042prt.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 | success or wait | 970342380 |
| File read | Path: C:\WINDOWS\system32\drivers\i8042prt.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 | success or wait | 970342884 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970343204 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970343380 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970343547 |
| File opened | Path: C:\WINDOWS\system32\drivers\cdrom.sys Access: write owner Options: open reparse point | success or wait | 970343693 |
| File opened | Path: C:\WINDOWS\system32\drivers\cdrom.sys Access: write owner Options: open reparse point | success or wait | 970344416 |
| File opened | Path: C:\WINDOWS\system32\drivers\cdrom.sys Access: write owner Options: open reparse point | success or wait | 970345216 |
| File read | Path: C:\WINDOWS\system32\drivers\cdrom.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 | success or wait | 970345491 |
| File read | Path: C:\WINDOWS\system32\drivers\cdrom.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 | success or wait | 970345869 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970346197 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970346436 |
| File opened | Path: C:\WINDOWS\system32\drivers\intelppm.sys Access: write owner Options: open reparse point | success or wait | 970346595 |
| File opened | Path: C:\WINDOWS\system32\drivers\intelppm.sys Access: write owner Options: open reparse point | success or wait | 970347510 |
| File opened | Path: C:\WINDOWS\system32\drivers\intelppm.sys Access: write owner Options: open reparse point | success or wait | 970348164 |
| File read | Path: C:\WINDOWS\system32\drivers\intelppm.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 | success or wait | 970348418 |
| File read | Path: C:\WINDOWS\system32\drivers\intelppm.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 | success or wait | 970349228 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970349567 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970349743 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970349919 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970350110 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970350291 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970350568 |
| File opened | Path: C:\WINDOWS\system32\drivers\termdd.sys Access: write owner Options: open reparse point | success or wait | 970350715 |
| File opened | Path: C:\WINDOWS\system32\drivers\termdd.sys Access: write owner Options: open reparse point | success or wait | 970351439 |
| File opened | Path: C:\WINDOWS\system32\drivers\termdd.sys Access: write owner Options: open reparse point | success or wait | 970352078 |
| File read | Path: C:\WINDOWS\system32\drivers\termdd.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 | success or wait | 970352419 |
| File read | Path: C:\WINDOWS\system32\drivers\termdd.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 | success or wait | 970352773 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970353094 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970353256 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970353423 |
| File opened | Path: C:\WINDOWS\system32\drivers\ipsec.sys Access: write owner Options: open reparse point | success or wait | 970353583 |
| File opened | Path: C:\WINDOWS\system32\drivers\ipsec.sys Access: write owner Options: open reparse point | success or wait | 970354430 |
| File opened | Path: C:\WINDOWS\system32\drivers\ipsec.sys Access: write owner Options: open reparse point | success or wait | 970355073 |
| File read | Path: C:\WINDOWS\system32\drivers\ipsec.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 | success or wait | 970355324 |
| File read | Path: C:\WINDOWS\system32\drivers\ipsec.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 | success or wait | 970355677 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970356112 |
| File opened | Path: C:\WINDOWS\system32\drivers\tcpip.sys Access: write owner Options: open reparse point | success or wait | 970356266 |
| File opened | Path: C:\WINDOWS\system32\drivers\tcpip.sys Access: write owner Options: open reparse point | success or wait | 970357020 |
| File opened | Path: C:\WINDOWS\system32\drivers\tcpip.sys Access: write owner Options: open reparse point | success or wait | 970357692 |
| File read | Path: C:\WINDOWS\system32\drivers\tcpip.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 | success or wait | 970358218 |
| File read | Path: C:\WINDOWS\system32\drivers\tcpip.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 | success or wait | 970358596 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970358899 |
| File opened | Path: C:\WINDOWS\system32\drivers\netbt.sys Access: write owner Options: open reparse point | success or wait | 970359043 |
| File opened | Path: C:\WINDOWS\system32\drivers\netbt.sys Access: write owner Options: open reparse point | success or wait | 970359881 |
| File opened | Path: C:\WINDOWS\system32\drivers\netbt.sys Access: write owner Options: open reparse point | success or wait | 970360537 |
| File read | Path: C:\WINDOWS\system32\drivers\netbt.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 | success or wait | 970360790 |
| File read | Path: C:\WINDOWS\system32\drivers\netbt.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 | success or wait | 970361139 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970361580 |
| File opened | Path: C:\WINDOWS\system32\drivers\afd.sys Access: write owner Options: open reparse point | success or wait | 970361758 |
| File opened | Path: C:\WINDOWS\system32\drivers\afd.sys Access: write owner Options: open reparse point | success or wait | 970362538 |
| File opened | Path: C:\WINDOWS\system32\drivers\afd.sys Access: write owner Options: open reparse point | success or wait | 970363326 |
| File read | Path: C:\WINDOWS\system32\drivers\afd.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E8 00 00 00 | success or wait | 970363693 |
| File read | Path: C:\WINDOWS\system32\drivers\afd.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E8 00 00 00 | success or wait | 970364082 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970364462 |
| File opened | Path: C:\WINDOWS\system32\drivers\netbios.sys Access: write owner Options: open reparse point | success or wait | 970364622 |
| File opened | Path: C:\WINDOWS\system32\drivers\netbios.sys Access: write owner Options: open reparse point | success or wait | 970365490 |
| File opened | Path: C:\WINDOWS\system32\drivers\netbios.sys Access: write owner Options: open reparse point | success or wait | 970366224 |
| File read | Path: C:\WINDOWS\system32\drivers\netbios.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 | success or wait | 970366498 |
| File read | Path: C:\WINDOWS\system32\drivers\netbios.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 | success or wait | 970366880 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970367324 |
| File opened | Path: C:\WINDOWS\system32\drivers\VBoxSF.sys Access: write owner Options: open reparse point | success or wait | 970367482 |
| File opened | Path: C:\WINDOWS\system32\drivers\VBoxSF.sys Access: write owner Options: open reparse point | success or wait | 970368774 |
| File opened | Path: C:\WINDOWS\system32\drivers\VBoxSF.sys Access: write owner Options: open reparse point | success or wait | 970371333 |
| File read | Path: C:\WINDOWS\system32\drivers\VBoxSF.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 F0 00 00 00 | success or wait | 970371605 |
| File read | Path: C:\WINDOWS\system32\drivers\VBoxSF.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 F0 00 00 00 | success or wait | 970371957 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970372259 |
| File opened | Path: C:\WINDOWS\system32\drivers\rdbss.sys Access: write owner Options: open reparse point | success or wait | 970372510 |
| File opened | Path: C:\WINDOWS\system32\drivers\rdbss.sys Access: write owner Options: open reparse point | success or wait | 970373249 |
| File opened | Path: C:\WINDOWS\system32\drivers\rdbss.sys Access: write owner Options: open reparse point | success or wait | 970373889 |
| File read | Path: C:\WINDOWS\system32\drivers\rdbss.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E8 00 00 00 | success or wait | 970374141 |
| File read | Path: C:\WINDOWS\system32\drivers\rdbss.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E8 00 00 00 | success or wait | 970374607 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970374898 |
| File opened | Path: C:\WINDOWS\system32\drivers\mrxsmb.sys Access: write owner Options: open reparse point | success or wait | 970375057 |
| File opened | Path: C:\WINDOWS\system32\drivers\mrxsmb.sys Access: write owner Options: open reparse point | success or wait | 970375765 |
| File opened | Path: C:\WINDOWS\system32\drivers\mrxsmb.sys Access: write owner Options: open reparse point | success or wait | 970376514 |
| File read | Path: C:\WINDOWS\system32\drivers\mrxsmb.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 | success or wait | 970376768 |
| File read | Path: C:\WINDOWS\system32\drivers\mrxsmb.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 | success or wait | 970377118 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970377423 |
| File opened | Path: C:\WINDOWS\system32\drivers\Fips.SYS Access: write owner Options: open reparse point | success or wait | 970377570 |
| File opened | Path: C:\WINDOWS\system32\drivers\Fips.SYS Access: write owner Options: open reparse point | success or wait | 970378720 |
| File opened | Path: C:\WINDOWS\system32\drivers\Fips.SYS Access: write owner Options: open reparse point | success or wait | 970379417 |
| File read | Path: C:\WINDOWS\system32\drivers\fips.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 | success or wait | 970379676 |
| File read | Path: C:\WINDOWS\system32\drivers\fips.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 | success or wait | 970380111 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970380423 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970380611 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: Start | success or wait | 970380796 |
| File opened | Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alert | success or wait | 970381684 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{677540da-d7f5-bb7f-efc6-f7ab3c6a1278} Name: InstallDate | success or wait | 970382069 |
| Section loaded | Path: \.mrxsmb Access: query and write and read and execute and extend size Type: commit Baseaddress: C30000 Size: 458752 Protection: read write Mapped to pid: own pid | success or wait | 970384534 |
| File opened | Path: C:\WINDOWS\system32\drivers\mrxsmb.sys Access: write owner Options: open reparse point | success or wait | 970384682 |
| File read | Path: C:\WINDOWS\system32\drivers\mrxsmb.sys Offset: 0 Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 | success or wait | 970384966 |
| File opened | Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alert | success or wait | 970963595 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion Name: InstallDate | success or wait | 970964186 |
| File opened | Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alert | success or wait | 970971677 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion Name: InstallDate | success or wait | 970972317 |
| Key value set | Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.mrxsmb Name: Type Type: Dword Data: 1 | success or wait | 970975199 |
| Key value set | Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.mrxsmb Name: Start Type: Dword Data: 3 | success or wait | 970976291 |
| Key value set | Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.mrxsmb Name: ImagePath Type: String Data: \* | success or wait | 970977358 |
| System info queried | Type: ProcessInformation | info length mismatch | 970978564 |
| System info queried | Type: ProcessInformation | success or wait | 970981591 |
| Section loaded | Path: none Access: query and write and read and execute and extend size Type: reserve Baseaddress: C30000 Size: 262144 Protection: read write Mapped to pid: own pid | success or wait | 970984430 |
| Memory allocated | PID: 772 Path: C:\WINDOWS\explorer.exe Base: C30000 Length: 6F858 Allocation Type: null Protection: page read and write | success or wait | 970984555 |
| Section loaded | Path: none Access: query and write and read and execute and extend size Type: reserve Baseaddress: C30000 Size: 262144 Protection: read write Mapped to pid: 608 | conflicting addresses | 972480582 |
| Section loaded | Path: none Access: query and write and read and execute and extend size Type: reserve Baseaddress: AB0000 Size: 262144 Protection: read write Mapped to pid: 608 | success or wait | 972527621 |
| Thread resumed | TID: 404 PID: 608 Path: C:\WINDOWS\system32\winlogon.exe | success or wait | 972576779 |
| Thread suspended | TID: 1572 PID: 608 Path: C:\WINDOWS\system32\winlogon.exe | success or wait | 972579573 |
| Thread suspended | TID: 1576 PID: 608 Path: C:\WINDOWS\system32\winlogon.exe | success or wait | 972580543 |
| Thread suspended | TID: 1580 PID: 608 Path: C:\WINDOWS\system32\winlogon.exe | success or wait | 972581640 |
| File opened | Path: C:\WINDOWS\system32\drivers\mrxsmb.sys Access: write owner Options: open reparse point | success or wait | 972582560 |
| File control set | Path: C:\WINDOWS\system32\drivers\mrxsmb.sys Control Code: set compression Input Buffer: 0000 | success or wait | 972582868 |
| Section loaded | Path: C:\WINDOWS\system32\drivers\mrxsmb.sys Access: write and read Type: commit Baseaddress: C30000 Size: 458752 Protection: read write Mapped to pid: own pid | success or wait | 972583156 |
| Symbolic link created | Symbolic link name: \* File path: C:\WINDOWS\system32\drivers\mrxsmb.sys | success or wait | 972601520 |
| File opened | Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alert | success or wait | 972602604 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion Name: InstallDate | success or wait | 972603078 |
| Driver loaded | Service Name: \registry\MACHINE\SYSTEM\CurrentControlSet\services\.mrxsmb | success or wait | 972605494 |
| File opened | Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alert | success or wait | 972958367 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion Name: InstallDate | success or wait | 972958805 |
| Thread suspended | TID: 1580 PID: 608 Path: C:\WINDOWS\system32\winlogon.exe | success or wait | 972961199 |
| Thread suspended | TID: 1576 PID: 608 Path: C:\WINDOWS\system32\winlogon.exe | success or wait | 972961323 |
| Thread suspended | TID: 1572 PID: 608 Path: C:\WINDOWS\system32\winlogon.exe | success or wait | 972961437 |
| Section loaded | Path: \.mrxsmb Access: query and write and read and execute and extend size Type: commit Baseaddress: C30000 Size: 458752 Protection: readonly Mapped to pid: own pid | success or wait | 972961567 |
| File created | Path: ACPI#PNP0303#2&da1a3ff&0\L\gkaiogto Access: append data or add subdirectory or create pipe instance and synchronize Options: synchronous io non alert Attributes: none | success or wait | 972961784 |
| File write | Path: \L\gkaiogto Offset: 0 Length: 455424 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 70 72 6F 67 72 61 6D 20 63 61 6E 6E 6F 74 20 62 65 20 72 75 6E 20 69 6E 20 44 4F 53 20 6D 6F 64 65 2E 0D 0D 0A 24 00 00 00 00 00 00 00 5E B2 BD 26 1A D3 D3 75 1A D3 D3 75 1A D3 D3 75 1A D3 D2 75 56 D2 D3 75 D9 DC 8E 75 11 D3 D3 75 D9 DC DC 75 1F D3 D3 75 D9 DC 8F 75 1B D3 D3 75 D9 DC 8D 75 1B D3 D3 75 D9 DC 8C 75 76 D3 D3 75 D9 DC 89 75 1B D3 D3 75 52 69 63 68 1A D3 D3 75 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 0B 00 5C 53 19 4B 00 00 00 00 00 00 00 00 E0 00 0E 01 0B 01 07 0A 80 28 06 | success or wait | 973193071 |
| File opened | Path: ACPI#PNP0303#2&da1a3ff&0\{1B372133-BFFA-4dba-9CCF-5474BED6A9F6} Access: append data or add subdirectory or create pipe instance and synchronize Options: synchronous io non alert Attributes: none | success or wait | 973398816 |
| File write | Path: \{1B372133-BFFA-4dba-9CCF-5474BED6A9F6} Offset: none Length: 2048 Value: 4C CE 1D 73 2D C6 CA D1 B8 09 DB 19 2D C6 CA D1 58 B0 7A E3 2D C6 CA D1 CB 43 36 84 2D C6 CA D1 29 61 6D 85 2D C6 CA D1 98 0E E8 69 2D C6 CA D1 56 37 EF 66 2D C6 CA D1 7B C9 62 63 2D C6 CA D1 DC 75 65 E3 2D C6 CA D1 A4 84 9A 50 2D C6 CA D1 44 C0 12 E2 2D C6 CA D1 54 FC 31 AA 2D C6 CA D1 56 7B C1 AD 2D C6 CA D1 63 FE B1 F1 2D C6 CA D1 62 A5 83 DD 2D C6 CA D1 48 D1 3F 33 2D C6 CA D1 5A A9 23 BD 2D C6 CA D1 A3 01 E6 CC 2D C6 CA D1 C8 5C 42 08 2D C6 CA D1 62 0F 88 F4 2D C6 CA D1 C9 EB 84 0C 2D C6 CA D1 45 89 A0 17 2D C6 CA D1 55 98 71 2F 2C C6 CA D1 BE 19 76 F3 2C C6 CA D1 47 C0 A5 CB 2C C6 CA D1 BE A0 85 BF 2C C6 CA D1 18 F7 9E D6 2C C6 CA D1 D8 33 BC F1 2C C6 CA D1 42 8D 17 43 2C C6 CA D1 62 D3 CB 46 2C C6 CA D1 BA 0C 96 A9 2C C6 CA D1 44 79 A2 97 2C C6 CA | success or wait | 973401317 |
| File opened | Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alert | success or wait | 973411617 |
| File created | Path: C:\WINDOWS\system32\drivers\1254331455.sys Access: append data or add subdirectory or create pipe instance and synchronize Options: synchronous io non alert Attributes: none | success or wait | 973412437 |
| File write | Path: C:\WINDOWS\system32\drivers\1254331455.sys Offset: none Length: 17408 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E8 00 00 00 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 70 72 6F 67 72 61 6D 20 63 61 6E 6E 6F 74 20 62 65 20 72 75 6E 20 69 6E 20 44 4F 53 20 6D 6F 64 65 2E 0D 0D 0A 24 00 00 00 00 00 00 00 B9 CF 0B 33 FD AE 65 60 FD AE 65 60 FD AE 65 60 7E A6 6A 60 FE AE 65 60 7E A6 38 60 EC AE 65 60 FD AE 64 60 12 AE 65 60 7E A6 39 60 FC AE 65 60 73 A6 3A 60 EE AE 65 60 7E A6 3B 60 FC AE 65 60 7E A6 3F 60 FC AE 65 60 52 69 63 68 FD AE 65 60 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 05 00 FC 4F 1D 4E 00 00 00 00 00 00 00 00 E0 00 02 | success or wait | 973429258 |
| Key value set | Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\1254331455 Name: Start Type: Dword Data: 3 | success or wait | 973430770 |
| Key value set | Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\1254331455 Name: Type Type: Dword Data: 1 | success or wait | 973431258 |
| Key value set | Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\1254331455 Name: ErrorControl Type: Dword Data: 1 | success or wait | 973431715 |
| Key value set | Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\1254331455 Name: DisplayName Type: String Data: Virtual Bus for Microsoft ACPI-Compliant System | success or wait | 973432051 |
| Key value set | Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000 Name: Service Type: String Data: 1254331455 | success or wait | 973433534 |
| Key value set | Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000 Name: ClassGUID Type: String Data: {4D36E97D-E325-11CE-BFC1-08002BE10318} | success or wait | 973433911 |
| Key value set | Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000 Name: Class Type: String Data: System | success or wait | 973434580 |
| Key value set | Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000 Name: DeviceDesc Type: String Data: PCI bus | success or wait | 973434915 |
| Key value set | Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000 Name: Mfg Type: String Data: Technologies Inc | success or wait | 973435708 |
| Key value set | Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000 Name: LocationInformation Type: String Data: on Microsoft ACPI-Compliant System | success or wait | 973436211 |
| Key value set | Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP2103\0000 Name: ConfigFlags Type: Dword Data: 0 | success or wait | 973437206 |
| File opened | Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alert | success or wait | 984025783 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion Name: InstallDate | success or wait | 984026328 |
| File opened | Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alert | success or wait | 984065618 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion Name: InstallDate | success or wait | 984066049 |
| File opened | Path: C:\WINDOWS Access: read data or list directory and read ea and read attributes and read control and synchronize Options: synchronous io non alert | success or wait | 984078680 |
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion Name: InstallDate | success or wait | 984079060 |